Skip to content

registry.access.redhat.com (Red Hat UBI) blocked by the enforced proxy egress allowlist #277

Description

@ranveer-avhad-veeam

Red Hat's public registry blocked by the enforced proxy egress allowlist

Hosted Dependabot docker version updates for Red Hat Universal Base Images (UBI) from
registry.access.redhat.com have failed since proxy-egress-enforce was enabled for the job. The
updater reports private_source_authentication_failure, but the proxy's egress allowlist returns the
403 and the request never reaches Red Hat.

Reproduction and observed evidence

Hosted run in a private repository, 2026-09-29 07:02 UTC. There is no registries: configuration, and
the job's only credential is git_source for github.com.

  • Dockerfile: FROM registry.access.redhat.com/ubi9/ubi-minimal:9.8-1790074235
  • dependabot.yml: package-ecosystem: docker, schedule.interval: daily

Proxy image: ghcr.io/dependabot/proxy:v2.0.20260929055832@sha256:45fa12e4fdbeb668d70389b231fe60ce9ef755949f52c64828b9ecbc14f2305f,
created 2026-09-29T05:59Z, after #276 was merged.

proxy | [014] GET https://registry.access.redhat.com:443/v2/ubi9/ubi-minimal/tags/list
proxy | [014] * egress not allowlisted registry.access.redhat.com
[014] 403 https://registry.access.redhat.com:443/v2/ubi9/ubi-minimal/tags/list
[014] Remote response: Forbidden
updater | Handled error whilst updating ubi9/ubi-minimal: private_source_authentication_failure {source: "registry.access.redhat.com"}

The same job succeeded on 2026-09-25, when its experiments had proxy-egress-observe but not
proxy-egress-enforce. That run logged * egress not allowlisted registry.access.redhat.com for each
request, and Red Hat answered each with HTTP 200. Apart from Dependabot's job API, the proxy saw requests
only to github.com and registry.access.redhat.com, with no redirects:

  • GET /v2/ubi9/ubi-minimal/tags/list, plus 27 paginated ?last= pages
  • HEAD /v2/ubi9/ubi-minimal/manifests/<ref> (2 requests)

Independent checks on 2026-09-29 confirmed anonymous access. GET https://registry.access.redhat.com/v2/
returns HTTP 200 with no WWW-Authenticate challenge, and tags/list returns 200, so there is no token
service to allowlist. Blob downloads from this registry 302-redirect to cdn01.quay.io, but the
version-update job made no blob requests.

Expected behavior

Hosted Dependabot should be able to discover updates for public UBI images without private registry
credentials. Please add registry.access.redhat.com to the built-in Docker allowlist, for example in the
"Vendor-operated public OCI registries that allow anonymous pulls" block added in #276. Otherwise, please
document a supported credential-free docker-registry configuration for this host. Keep egress
enforcement enabled.

This request covers only the anonymous registry. It does not cover registry.redhat.io, Red Hat's
authenticated registry, which returns 401 without a Red Hat login.

Relevant source

  • func NewEgressAllowlistHandler(cfg *config.Config, env config.ProxyEnvSettings, metricSender MetricSender) *EgressAllowlistHandler {
    allowed := append([]string(nil), githubInfraDomains...)
    allowed = append(allowed, sharedRegistryDomains...)
    allowed = append(allowed, allEcosystemDomains...)
    return &EgressAllowlistHandler{
    observe: cfg.Experiments.Enabled(egressObserveExperiment),
    enforce: cfg.Experiments.Enabled(egressEnforceExperiment),
    allowed: allowed,
    dynamicHosts: dynamicHosts(cfg.Credentials),
    metrics: metricSender,
    }
    }
  • docker: &docker_registries
    - registry-1.docker.io
    - auth.docker.io
    - index.docker.io
    - registry.hub.docker.com
    - hub.docker.com
    - production.cloudflare.docker.com
    - production.cloudfront.docker.com
    - ghcr.io
    - mcr.microsoft.com
    - quay.io
    - public.ecr.aws
    - lscr.io
    - .gcr.io
    - .pkg.dev
    # Vendor-operated public OCI registries that allow anonymous pulls.
    # docker.getcollate.io fronts Docker Hub via Scarf, so its token service is
    # auth.docker.io above and its blobs land on the Docker Hub CDN hosts above.
    - docker.getcollate.io
    # Elastic's registry, its anonymous token service, and the R2 bucket its
    # blob downloads 307-redirect to. The bucket host embeds Elastic's own
    # Cloudflare account hash, so it is exact only: a glob over
    # *.r2.cloudflarestorage.com would match every Cloudflare tenant.
    - docker.elastic.co
    - docker-auth.elastic.co
    - docker-registry-production.d24a988e385e0074d717b6bdaea58f0d.r2.cloudflarestorage.com
    docker_compose: *docker_registries

The handler accepts built-in domains plus exact dynamic hosts from configured credentials. At this
revision, which includes #276, the built-in Docker list doesn't contain registry.access.redhat.com.
Because the job has no registry credentials, it gets no dynamic host for it either.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions