Corporate networks
On this page
The most common “works at home, breaks at work” failure: behind a TLS-inspecting
proxy, docker pull fails with an x509 / certificate error because the engine
does not trust the corporate root CA. Skrog fixes that, opt-in.
skrog config set network.import-host-cas on # trust the host's roots
skrog config set network.proxy http://proxy.corp:8080
skrog config set network.no-proxy internal.corp,10.0.0.0/8
skrog restart # applies the above
skrog doctor flags the classic mistake — a proxy set without CA import — before
you hit the x509 error.
What each does
network.import-host-cas— reads your Windows host’s trusted root CA store (both LocalMachine and CurrentUserRoot; no elevation — it’s a readable store) and installs those roots into the engine’s trust store on every start. This is what lets the engine pull through a proxy that re-signs TLS with a corporate root. Nothing silent: it is off by default, opt-in, and logged.network.proxy/network.no-proxy— setHTTP_PROXY/HTTPS_PROXY/NO_PROXYfor dockerd, so its registry pulls go through your proxy.localhostand127.0.0.1are always bypassed.- Registry mirrors / insecure registries are the engine
daemon.jsonkeys fromskrog config set engine.*:engine.registry-mirrors,engine.insecure-registries.
Notes
These are re-read at every engine start, so
skrog restartapplies a change and a rootfs re-import (reinstall) keeps one. They configure dockerd itself, which is why they need the engine to come back rather than taking effect mid-flight.They used to be captured once when the supervisor started, which meant
skrog restartre-applied whatever was set at logon and silently ignored anything you had changed since. Fixed in #202.The proxy affects the engine’s pulls. Containers and builds that need a proxy still take it the usual way (build args / a container’s own env).
Trusting the host CA store is a real trust decision — it means the engine accepts the same roots your machine does. That is exactly what a corporate TLS-inspecting proxy needs, and why it is opt-in.
See also
- vpn.md — the other half of “works at home, breaks at work”: a VPN
that clamps the MTU or hijacks DNS.
skrog doctorrecognizes the common clients and prints the fix.