Problem:Application Update Fails Behind a Proxy Because Docker Cannot Pull the Container Image

Problem

When a UCS system is located behind an Proxy, updating an application, like Keycloak application, may fail because Docker cannot download the required container image from the Univention container registry.

A manual docker pull may fail as well. During an update through the Univention Management Console (UMC), the operation may terminate while downloading the Keycloak Docker image.

The following errors can be found in /var/log/univention/appcenter.log:

3290137 docker                           26-09-09 06:09:28 [    INFO]: ERROR: for keycloak  Get "https://artifacts.software-univention.de/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)
3290137 docker                           26-09-09 06:09:28 [    INFO]: Get "https://artifacts.software-univention.de/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)
3290137 docker                           26-09-09 06:09:28 [   ERROR]: Command docker-compose -p keycloak pull failed with: Pulling keycloak ... 
Pulling keycloak ... error

ERROR: for keycloak  Get "https://artifacts.software-univention.de/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)
Get "https://artifacts.software-univention.de/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers) (1)
3290137 packages                         26-09-09 06:09:28 [   DEBUG]: Releasing LOCK
3290137 actions.upgrade                  26-09-09 06:09:28 [CRITICAL]: Downloading Docker image artifacts.software-univention.de/nubus/images/keycloak:26.7.2-nubus1@sha256:eb72d3a666f9f87328793364d20db823b2590188eeee5ad4d325c4bd8c3eef71 failed: Pulling keycloak ... 
Pulling keycloak ... error

ERROR: for keycloak  Get "https://artifacts.software-univention.de/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)
Get "https://artifacts.software-univention.de/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)


3290137 utils                            26-09-09 06:09:29 [   DEBUG]: send_information: action=upgrade app=keycloak value={'image': 'artifacts.software-univention.de/nubus/images/keycloak:26.7.2-nubus1@sha256:eb72d3a666f9f87328793364d20db823b2590188eeee5ad4d325c4bd8c3eef71', 'out': 'Pulling keycloak ... \r\nPulling keycloak ... error\r\n\nERROR: for keycloak  Get "https://artifacts.software-univention.de/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)\nGet "https://artifacts.software-univention.de/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)\n', 'code': 1} status=435
3290137 utils                            26-09-09 06:09:29 [   DEBUG]: tracking information: {'action': 'upgrade', 'status': 435, 'uuid': '323a1d3b-2916-4d41-8c26-0d66129b402b', 'role': 'domaincontroller_backup', 'app': 'keycloak', 'version': '26.7.2-nubus1', 'value': {'image': 'artifacts.software-univention.de/nubus/images/keycloak:26.7.2-nubus1@sha256:eb72d3a666f9f87328793364d20db823b2590188eeee5ad4d325c4bd8c3eef71', 'out': 'Pulling keycloak ... \r\nPulling keycloak ... error\r\n\nERROR: for keycloak  Get "https://artifacts.software-univention.de/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)\nGet "https://artifacts.software-univention.de/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)\n', 'code': 1}, 'system-uuid': '13498b49-a048-4ec7-8c3b-2eab2a831d8a'}

The relevant error is:

Get "https://artifacts.software-univention.de/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)

Root Cause

The UCS host itself may already be configured to use a proxy. However, the App Center’s Docker containers do not automatically inherit the host’s proxy configuration unless the corresponding UCR variable is enabled.

Check the current value with:

ucr get appcenter/docker/container/proxy/settings

If the command returns no value, the variable is not set.

The UCR variable is:

appcenter/docker/container/proxy/settings

It controls whether containers are started with the proxy settings configured on the host, including:

proxy/http
proxy/https
proxy/no_proxy
/etc/apt/apt.conf.d/80proxy

The variable has the following properties:

appcenter/docker/container/proxy/settings: <empty>

This variable controls whether containers are started with the proxy settings (proxy/http, proxy/https, proxy/no_proxy, /etc/apt/apt.conf.d/80proxy) of the host.

Categories: management-umc
Default: (not set)
Type: bool

If the variable is not enabled, the Docker environment used by the App Center does not receive the required proxy settings. As a result, the connection to artifacts.software-univention.de may time out and the application update fails while pulling the container image.


Solution

Enable the App Center Docker proxy settings by setting the following UCR variable:

ucr set appcenter/docker/container/proxy/settings=1

After enabling the setting, retry the Keycloak application update.

The App Center should now be able to use the configured proxy settings when downloading the required Keycloak container image from:

artifacts.software-univention.de

Additional Information

For additional information about using the App Center through a proxy, see the related Univention Help article: