Use case

Docker Hub Pull Limits Seen From a Fresh US Address

Docker Hub counts anonymous image pulls per source address and authenticated pulls per account, and it is honest about telling you when you have used your share. The trouble is that in an office or a CI farm, dozens of machines share one outside address, so the number you see has little to do with your own work. For two dollars, HourlyProxies hands you a US carrier line that nobody else is using. For two hours you can observe the limit, test a mirror, verify a login and check what a new user gets, then walk away without a subscription.

A limit you can finally measure

The per-address allowance is what makes Docker Hub confusing in shared environments. A developer on a corporate network pulls once and gets refused because a build server on the same egress used the allowance an hour ago. Routing one Docker daemon through a dedicated mobile line removes the noise. Every pull from that line is yours, the rate limit headers the registry sends back describe only your activity, and you can finally write accurate documentation for your team about what happens when the window closes.

To be plain: the line does not buy you more pulls. It gives you an address with its own window so that you can see the behavior clearly. Pull throughput for real workloads belongs on an authenticated account or a mirror, which is what Docker recommends anyway.

Testing a registry mirror or pull-through cache

If you run a mirror in front of Docker Hub, the question is whether clients actually use it. Configure a daemon on the line to point at your mirror, pull a public image, and check whether the mirror's logs show the fetch while Docker Hub's headers stay quiet. Then remove the mirror setting and pull again to confirm the fallback path still reaches the registry. Two hours covers both directions with time to spare.

The same session can verify a private registry's TLS and authentication from outside your network, which is where most certificate chain problems first appear.

What an anonymous visitor sees

Beyond pulls, Docker Hub is a website with public repository pages, tag lists, README renders and Docker Official Image descriptions. If you publish an image, a quick look from a US mobile line shows you the page a developer on a phone sees before they decide to trust it. Check the tag you expect to be newest, the description formatting and the pull command snippet.

Setting the daemon up on a mobile line

Docker reads the usual proxy environment variables from the daemon's systemd unit or from the daemon configuration file. Set HTTPS_PROXY to the HTTP endpoint from your dashboard, restart the daemon, and run a single pull to confirm the request leaves through the line. The registry's rate limit headers are visible with a manual token request and a HEAD against a manifest, which is a good way to see the window without burning a pull.

4G is $2 for the first two hours and $2 per extra hour; 5G is $3 and $3. A purchase holds at most four hours and never renews. 4G usually runs 20 to 45 Mbps and 5G 50 Mbps and up, depending on signal at the modem, which is plenty for test pulls. Mirroring an entire image catalog through the line is bulk transfer and falls outside fair use.

  • One address, one pull window, no shared egress noise
  • Mirror and fallback checks in a single session
  • HTTP(S) endpoint for the daemon, SOCKS5 for everything else
  • Nothing renews when the hours run out

Rules we hold ourselves to

Do not use rotation to pretend to be many anonymous pullers. That is a way around the registry's policy, not a test of it, and Docker's terms forbid it. Authenticate for real work, use a mirror for fleets, and use the line to understand and document the behavior.

Setting up a Docker Hub proxy on HourlyProxies

  1. Buy two hours in any of our eight US cities.
  2. Put the HTTP endpoint into the Docker daemon's proxy settings and restart it.
  3. Request an anonymous token and inspect the rate limit headers.
  4. Pull through your mirror, then without it, and compare what the registry reports.
  5. Remove the proxy setting when the meter stops.

Docker Hub proxy questions

Does a mobile line reset the Docker Hub pull limit?

It gives you a separate address with its own window. It does not add pulls to your account or your main network, and we do not sell it for that.

Can I rotate the address during the test?

You can, from the dashboard, the API or a link. For a measurement you want one address, so leave rotation alone.

Which carrier should I pick?

Any of AT&T, T-Mobile or Verizon will do for a registry test. Pick whichever is in stock in the city you choose.

Real US carrier IPs for Docker Hub

Dedicated 4G and 5G lines in eight US metros. Sticky sessions, unlimited rotation, HTTP(S) and SOCKS5. Plans from $2 for 2 hours or $5/day.

View plans See all locations

More HourlyProxies use cases

All HourlyProxies use cases →