Skip to content

cgr.dev (Chainguard public images) blocked by the enforced proxy egress allowlist #279

Description

@mnl

Chainguard public images blocked by enforced proxy egress allowlist

Hosted Dependabot docker version updates for the public cgr.dev/chainguard/wolfi-base image have failed since proxy-egress-enforce was enabled for the job. The updater reports private_source_authentication_failure, but the proxy returns 403 before the request reaches the registry.

Reproduction and observed evidence

The repository is mnl/httpd-ecs. Its Dockerfile uses:

FROM cgr.dev/chainguard/wolfi-base:latest@sha256:b6bfe8564bb0630778b04df06b42e78acf221e9540703cfc03d040ab7f91e357 AS base

Dependabot checks Docker updates daily. There is no registries: configuration or registry credential; the job definition lists only a git_source credential for github.com.

Both the September 28 run and September 29 run fail on the first registry request:

HEAD https://cgr.dev:443/v2/chainguard/wolfi-base/manifests/latest
* egress not allowlisted cgr.dev
403 https://cgr.dev:443/v2/chainguard/wolfi-base/manifests/latest
Remote response: Forbidden
Handled error whilst updating chainguard/wolfi-base:
  private_source_authentication_failure {source: "cgr.dev"}

The September 25 run succeeded. It also logged * egress not allowlisted cgr.dev, but the proxy allowed the anonymous registry authentication flow to continue and the manifest request returned HTTP 200.

The successful job had proxy-egress-observe: true and no proxy-egress-enforce flag. Both failed jobs have proxy-egress-observe: true and proxy-egress-enforce: true. The proxy image changed from v2.0.20260923170141 in the successful run to v2.0.20260926055441 in the failed runs. Both failures used repository commit dcc1ad8950f56785ebab4c6aaf67eab85966fc2f.

Dependabot job IDs: 1594435461 and 1597244211.

Expected behavior

Hosted Dependabot should be able to check digest updates for publicly readable Chainguard images without private registry credentials. Please allowlist cgr.dev for Docker update jobs while keeping egress enforcement enabled. The resulting error should identify a proxy egress denial rather than a registry authentication failure.

Related issues

  • dependabot/proxy#264 reports the same failure class for other public OCI registries and was closed after a fix for those hosts.
  • dependabot/proxy#277 reports the same regression for registry.access.redhat.com. cgr.dev appears to be another public registry missing from the enforced allowlist.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Type

    No type

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions