Since proxy-egress-enforce was enabled, pip updates using a private packagecloud registry fail with private_source_authentication_failure.
packagecloud.io is configured under registries:, so the proxy allows it. But packagecloud 302-redirects every file download to a signed CloudFront URL on d3fo0g5hm7lbuv.cloudfront.net, and the proxy blocks that:
[042] 302 https://packagecloud.io:443/<org>/<repo>/pypi/packages/<pkg>.whl.metadata
[044] GET https://d3fo0g5hm7lbuv.cloudfront.net:443/<account>/<repo>/blobs/<uuid>/<pkg>.whl.metadata?Expires=...&Signature=...
[044] * egress not allowlisted d3fo0g5hm7lbuv.cloudfront.net
[044] 403 https://d3fo0g5hm7lbuv.cloudfront.net:443/...
Proxy v2.0.20260930064933. The same downloads worked under proxy-egress-observe.
Public reproduction: curl -sI https://packagecloud.io/github/git-lfs/packages/ubuntu/jammy/git-lfs_3.5.1_amd64.deb/download.deb → 302 to d3fo0g5hm7lbuv.cloudfront.net (packagecloud's shared download CDN).
Request: like the ECR starport-layer-bucket derivation in registryRedirectHosts, allow d3fo0g5hm7lbuv.cloudfront.net (exact host) for jobs that have a packagecloud.io credential. It isn't suitable for the static defaults, since the host is multi-tenant. But its content requires a signature that only packagecloud.io issues after authenticating the request (unsigned requests return 403).
If there's a better way to solve this on our side, for example something we could set in dependabot.yml, I'd be glad to hear it. Thanks for taking a look!
Since
proxy-egress-enforcewas enabled,pipupdates using a private packagecloud registry fail withprivate_source_authentication_failure.packagecloud.iois configured underregistries:, so the proxy allows it. But packagecloud302-redirects every file download to a signed CloudFront URL ond3fo0g5hm7lbuv.cloudfront.net, and the proxy blocks that:Proxy
v2.0.20260930064933. The same downloads worked underproxy-egress-observe.Public reproduction:
curl -sI https://packagecloud.io/github/git-lfs/packages/ubuntu/jammy/git-lfs_3.5.1_amd64.deb/download.deb→302tod3fo0g5hm7lbuv.cloudfront.net(packagecloud's shared download CDN).Request: like the ECR
starport-layer-bucketderivation inregistryRedirectHosts, allowd3fo0g5hm7lbuv.cloudfront.net(exact host) for jobs that have apackagecloud.iocredential. It isn't suitable for the static defaults, since the host is multi-tenant. But its content requires a signature that onlypackagecloud.ioissues after authenticating the request (unsigned requests return403).If there's a better way to solve this on our side, for example something we could set in
dependabot.yml, I'd be glad to hear it. Thanks for taking a look!