logoalt Hacker News

Tell HN: Docker pull fails in Spain due to football Cloudflare block

1103 pointsby littlecranky67yesterday at 12:28 PM401 commentsview on HN

I just spent 1h+ debugging why my locally-hosted gitlab runner would fail to create pipelines. The gitlab job output would just display weird TLS errors when trying to pull a docker images. After debugging gitlab and the runner, I realized after a while I could not even run "docker pull <image>" on my machine as root:

> error pulling image configuration: download failed after attempts=6: tls: failed to verify certificate: x509: certificate is not valid for any names, but wanted to match docker-images-prod.6aa30f8b08e16409b46e0173d6de2f56.r2.cloudflarestorage.com

First blaming tailscale, dns configuration and all other stuff. Until I just copied that above URL into my browser on my laptop, and received a website banner:

> El acceso a la presente dirección IP ha sido bloqueado en cumplimiento de lo dispuesto en la Sentencia de 18 de diciembre de 2024, dictada por el Juzgado de lo Mercantil nº 6 de Barcelona en el marco del procedimiento ordinario (Materia mercantil art. 249.1.4)-1005/2024-H instado por la Liga Nacional de Fútbol Profesional y por Telefónica Audiovisual Digital, S.L.U. https://www.laliga.com/noticias/nota-informativa-en-relacion-con-el-bloqueo-de-ips-durante-las-ultimas-jornadas-de-laliga-ea-sports-vinculadas-a-las-practicas-ilegales-de-cloudflare

For those non-spanish speakers: It means there is football match on, and during that time that specific host is blocked. This is just plain madness. I guess that means my gitlab pipelines will not run when football is on. Thank you, Spain.


Comments

jimaekyesterday at 1:51 PM

Off topic but I wonder when Cloudflare is going to launch their own Docker registry as a product.

show 4 replies
laxmanclotoday at 6:25 PM

Thats crazy

Magnetsyesterday at 4:34 PM

BT used to block the entire streamable.com site during football matches

LtdJorgeyesterday at 5:54 PM

Thankfully, Adamo hasn’t implemented the blockade yet (if ever).

thomasjudgeyesterday at 7:03 PM

Could you bypass this with a VPN?

show 1 reply
ahacheteyesterday at 1:59 PM

Yeah, I know. Welcome to the club :(

https://x.com/ahachete/status/2035783292549755228

lloydatkinsontoday at 8:08 AM

Probably the only even slightly relevant thread I’ll ever find for this so here goes. There is a certain visitor in the “Madrid Autonomous Community” (whatever that is) which frequently requests just my homepage, no other page on my site, over and over again.

It comes in waves, and it’s not enough to affect anything, but it’s very weird because when I did some digging by looking at the ASN there was actually only one active IP address and if I browse to it I get someone’s Synology NAS login page.

Why would someone setup their NAS to randomly keep pinging my homepage?

dmitrygryesterday at 5:22 PM

The last sentence of this submission makes no sense. You are in Spain. Allegedly, the country has a representative government. That means that you should have a way to influence the government to fix this idiocy. If, in fact, you don’t, then it is not a representative government and …ahem… further steps may be warranted to remind the government whom they work for.

maxlintoday at 7:14 AM

sportsball more importanter than your nerd stuff.

regards: spanish authorities (who are watching the sportsball and so are better spaniards than you!)

anthkyesterday at 2:14 PM

Yea, La Liga it's crapping out as always. Docker needs either some I2P gateway, or a Tor service.

show 1 reply
sschuellertoday at 9:36 AM

Just wait until a bank moves their 2FA to CF...

Netblock do not work and will never work.

show 1 reply
Myzel394yesterday at 5:54 PM

Just use a VPN

genericacctyesterday at 9:16 PM

same thing happens in italy

mschuster91yesterday at 6:09 PM

Cloudflare could resolve this without negatively impacting fundamental services... just place all newly registered sites (e.g. <30 days) on a dedicated block of IP addresses. That way, Spain's government-ordered censorship could be limited to (mostly) pirate sites. Or they could invest money in vetting customers properly.

But of course, Cloudflare rather prefers to hold their actual large customers (who don't have much of an alternative to CF) and everyday Spaniard users hostage.

show 1 reply
brepppyesterday at 4:40 PM

Vote early, vote often

richwateryesterday at 2:54 PM

Spain is a failing country. Their economy is in shambles and the government has ceded internet control to a private corporation who runs football games.

show 4 replies
anthkyesterday at 2:18 PM

CF could just sue LaLiga and the judge as interrupting and intercepting telecomms it's a really serious crime in Spain. Call the AEPD too because of consumers' right against both ISP and LaLiga's snooping. Another huge fine.

This is not an issue under the civil code (civilian issues), but something to be dealt under penal (criminal) code.

In Spanish

https://www.fiscal.es/memorias/memoria2020/FISCALIA_SITE/rec...

Oh, and BTW, LaLiga has just partnered with a CF rival.

Now CF can just sue both like hell because of unfair competition:

https://nitter.tiekoetter.com/xataka/status/2042658662850724...

show 2 replies
xkbear89today at 4:56 AM

[flagged]

martmulxtoday at 3:38 AM

[dead]

PocketBotyesterday at 5:56 PM

[dead]

r2vcapyesterday at 8:37 PM

[dead]

lordmomayesterday at 4:48 PM

[dead]

shamclerentoday at 3:28 AM

[dead]

renewiltordyesterday at 4:02 PM

[flagged]

show 3 replies
lofaszvanittyesterday at 4:40 PM

Good. Cloudflare is the next evil entity on the internet.

mathfailureyesterday at 2:04 PM

Cloudflare is cancer. And the tumor is now too big.

show 6 replies