TL;DR: The connection to the registry stalls and the client gives up. If you are behind a corporate proxy, configure it for the daemon (systemd drop-in with HTTP_PROXY/HTTPS_PROXY, then `systemctl daemon-reload && systemctl restart docker`). Otherwise suspect MTU: try `--mtu 1400` on the daemon or network, since VPNs and PPPoE links silently drop large packets.

## The error

```text
Get "https://registry-1.docker.io/v2/": net/http: request canceled while waiting for connection (Client.Timeout exceeded while awaiting headers)
```

## Fix it

1. Check for a proxy requirement:
   `env | grep -i proxy`
   Expected: if the host needs a proxy for the internet, docker does too.
2. Configure the daemon proxy via systemd:
   create /etc/systemd/system/docker.service.d/http-proxy.conf with:
   `[Service]`
   `Environment="HTTP_PROXY=http://proxy:8080" "HTTPS_PROXY=http://proxy:8080" "NO_PROXY=your-internal-hosts"`
3. Reload and restart:
   `sudo systemctl daemon-reload && sudo systemctl restart docker`
   Expected: `docker pull hello-world` succeeds.
4. If no proxy is involved, test MTU:
   `docker network create --opt com.docker.network.driver.mtu=1400 testmtu`
   and pull through a container on that network, or set `"mtu": 1400` in daemon.json.

## When this applies
- Pulls hang for a while then fail with timeout
- Corporate networks, VPNs, PPPoE connections

## When this does NOT apply
- Instant "no such host" (DNS, different fix)
- 401/unauthorized (auth, different fix)

## Versions
All Docker Engine versions.

## Why it happens
The daemon makes outbound HTTPS directly, ignoring the shell's proxy env vars unless configured via systemd. MTU issues cause large TLS packets to be silently dropped, which looks exactly like a hang followed by a client-side timeout.

## Edge cases
- NO_PROXY must include your internal registries and cluster CIDRs, or internal pulls will try to go through the proxy and fail.
- Docker Desktop: set proxies in Settings > Resources > Proxies, not in daemon.json.
- Rate limiting (toomanyrequests) is a different error; timeouts are network-level.
