Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Yeah, google does it too. I could not use certain Hetzner IPs to download container image on my kubernetes nodes at all. Even the official registry.k8s.io registry is hosted on Google Cloud Services and basic stuff like the pause image cant be pulled.


Google's IP to location mapping is so bad it has to be intentional. I was in Japan and using my home network as a VPN quite a bit, after a while Google decided my home comcast IP had to be located in Japan. Even though others in the household were still there, they started getting default-Japanese pages on google/maps/youtube/... It didn't fix itself back until a couple weeks after I got home, even filled out https://support.google.com/websearch/contact/ip


They finger print your browser. You need to vpn to your home and serve from your US browser not tunnel traffic back to your Japan machine.


I'd be more willing to bet that it's because my GPS location is in Japan, which is the strongest signal of my physical location. Nevertheless, my home IP is used by multiple people, they probably know who they are and that they're not in Japan. My own signals are a mix of VPN'd/non-VPN'd apps on my phone and laptop (not strict about the VPN, some Japan sites require a Japanese IP), and I do often NoMachine back to my home machine and access google services just like I do at home.


I can confirm this. All Google container registries, including the official k8s repos are unaccessible via some hetzner ipv4 domains.

There is a GitHub issue that also covers the problem and it states you should report thos IPS to their support. I did but support says they can't do anything until the ip region list is updated.

IPv6 as a workaround is also difficult because some of the image I need are on GitHub and they are still not ipv6 accessible


I noticed some IPv6 addresses were getting blocked too.

We reported a lot IPs to Hetzner, but since we use autoscaling new blocked ones just kept on appearing.


For a while, Google was blocking IPv6 from Linode, to similar effect.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: