Authentication

Registry Auth

Authenticate registry/docker pull requests.

In the Depot proxy flow this endpoint is called by nginx auth_request to verify the miner before nginx proxies to Depot's token endpoint; it only needs to return 200 on success (or 401 on failure).

The VM's attested measurement version decides which auth is required:

  • version >= registry_mtls_min_version: mTLS. The nginx frontend forwards the client cert as X-Client-Cert; the leaf is verified against the CA registered for the VM. No legacy fallback — a VM this new must use mTLS.
  • otherwise (older VM, or unknown IP): legacy Bittensor hotkey/signature/nonce.

Setting registry_mtls_min_version to "0.0.0" forces every attested VM onto mTLS — the kill switch that closes the legacy "any registered miner can pull any private chute" hole once the fleet is fully migrated.

The require_registry_proxy_secret dependency, when REGISTRY_PROXY_SECRET is configured, rejects requests that do not carry X-Registry-Proxy-Auth matching the secret, preventing X-Client-Cert / X-Real-IP spoofing on connections that bypass the registry proxy. The mTLS client cert is extracted (typed) by extract_optional_client_cert.

get/registry/auth

Response

Successful Response

{"stackTrail":"paths:/registry/auth:get:responses:200:content:application/json:schema","oasType":"schema","type":"unknown"}

Changes

Changed in 3 of the 11 revisions of this API.143

    • ○

      endpoint added

      endpoint-added

    • ▲

      api path removed without deprecation

      api-path-removed-without-deprecation

    This revision also has 97 changes that name no endpoint, such as unreferenced schemas being removed. See the revision's changelog

    • ●

      deleted the header request parameter Authorization

      request-parameter-removed

    • ●

      deleted the header request parameter X-Chutes-Hotkey

      request-parameter-removed

    • ●

      deleted the header request parameter X-Chutes-Nonce

      request-parameter-removed

    • ●

      deleted the header request parameter X-Chutes-Signature

      request-parameter-removed

    • ○

      the endpoint scheme security APIKeyHeader was removed from the API

      api-security-removed

    • ○

      removed the non-success response with the status

      response-non-success-status-removed