Get "https://registry-1.docker.io/v2/": net/http: request canceled while waiting for connection
Fixes docker pulls timing out against the registry with 'request canceled while waiting for connection'. Use when pulls hang then fail, pointing at proxy, MTU, or throttling issues. Not for DNS failures or auth errors.
TL;DR: The connection to the registry stalls and the client gives up. If you are behind a corporate proxy, configure it for the daemon (systemd drop-in with HTTPPROXY/HTTPSPROXY, then systemctl daemon-reload && systemctl restart docker). Otherwise suspect MTU: try --mtu 1400 on the daemon or network, since VPNs and PPPoE links silently drop large packets.
The error
Get "https://registry-1.docker.io/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)Fix it
- Check for a proxy requirement:
env | grep -i proxy Expected: if the host needs a proxy for the internet, docker does too.
- Configure the daemon proxy via systemd:
create /etc/systemd/system/docker.service.d/http-proxy.conf with: [Service] Environment="HTTP_PROXY=http://proxy:8080" "HTTPS_PROXY=http://proxy:8080" "NO_PROXY=your-internal-hosts"
- Reload and restart:
sudo systemctl daemon-reload && sudo systemctl restart docker Expected: docker pull hello-world succeeds.
- If no proxy is involved, test MTU:
docker network create --opt com.docker.network.driver.mtu=1400 testmtu and pull through a container on that network, or set "mtu": 1400 in daemon.json.
When this applies
- Pulls hang for a while then fail with timeout
- Corporate networks, VPNs, PPPoE connections
When this does NOT apply
- Instant "no such host" (DNS, different fix)
- 401/unauthorized (auth, different fix)
Versions
All Docker Engine versions.
Why it happens
The daemon makes outbound HTTPS directly, ignoring the shell's proxy env vars unless configured via systemd. MTU issues cause large TLS packets to be silently dropped, which looks exactly like a hang followed by a client-side timeout.
Edge cases
- NO_PROXY must include your internal registries and cluster CIDRs, or internal pulls will try to go through the proxy and fail.
- Docker Desktop: set proxies in Settings > Resources > Proxies, not in daemon.json.
- Rate limiting (toomanyrequests) is a different error; timeouts are network-level.