Skip to content

packagecloud.io: allow CloudFront download redirect for jobs with a packagecloud registry #285

Description

@miguelafmonteiro

Since proxy-egress-enforce was enabled, pip updates using a private packagecloud registry fail with private_source_authentication_failure.

packagecloud.io is configured under registries:, so the proxy allows it. But packagecloud 302-redirects every file download to a signed CloudFront URL on d3fo0g5hm7lbuv.cloudfront.net, and the proxy blocks that:

[042] 302 https://packagecloud.io:443/<org>/<repo>/pypi/packages/<pkg>.whl.metadata
[044] GET https://d3fo0g5hm7lbuv.cloudfront.net:443/<account>/<repo>/blobs/<uuid>/<pkg>.whl.metadata?Expires=...&Signature=...
[044] * egress not allowlisted d3fo0g5hm7lbuv.cloudfront.net
[044] 403 https://d3fo0g5hm7lbuv.cloudfront.net:443/...

Proxy v2.0.20260930064933. The same downloads worked under proxy-egress-observe.

Public reproduction: curl -sI https://packagecloud.io/github/git-lfs/packages/ubuntu/jammy/git-lfs_3.5.1_amd64.deb/download.deb → 302 to d3fo0g5hm7lbuv.cloudfront.net (packagecloud's shared download CDN).

Request: like the ECR starport-layer-bucket derivation in registryRedirectHosts, allow d3fo0g5hm7lbuv.cloudfront.net (exact host) for jobs that have a packagecloud.io credential. It isn't suitable for the static defaults, since the host is multi-tenant. But its content requires a signature that only packagecloud.io issues after authenticating the request (unsigned requests return 403).

If there's a better way to solve this on our side, for example something we could set in dependabot.yml, I'd be glad to hear it. Thanks for taking a look!

No activity

Activity on this issue will appear here.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Labels

No labels
No labels

Type

No type

Projects

No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions