[awf] mcp-gateway-config schema rejects private registry image refs with explicit port
Maintainers usually reply within 1 day
@lpcox is already working on this.
Since Sep 24, 2026.
Assessment
This issue has not been assessed yet.
Description
Problem
The mcp-gateway-config JSON schema's container field regex only allows a single colon (reserved for :tag), so valid Docker image refs like registry.example.com:5000/team/service-image:latest fail schema validation at MCP Gateway (gh-aw-mcpg) startup, causing the entire gateway process to exit before any MCP server starts — even unrelated, correctly-configured servers.
Context
Reported upstream: github/gh-aw#61678. Affects gh-aw-mcpg v0.4.9; gh aw compile does not catch this since the compiler doesn't validate the pattern.
Root Cause
Current pattern ^[a-zA-Z0-9][a-zA-Z0-9./_-]*(:([a-zA-Z0-9._-]+|latest))?$ cannot distinguish a registry_host:port prefix from a trailing :tag, so any second colon fails.
Proposed Solution
Update the schema's container pattern (likely in AWF's enclave/mcp-gateway config schema or wherever this JSON schema is owned/vendored) to allow an optional :<port> immediately after the registry host, before path segments, following Docker's reference grammar, e.g. ^[a-zA-Z0-9][a-zA-Z0-9.-]*(:[0-9]+)?(/[a-zA-Z0-9._-]+)*(:[a-zA-Z0-9._-]+)?$. Add a schema unit test covering host:port/path:tag, host/path:tag, and bare path forms.
Generated by Firewall Issue Dispatcher · copilot · auto · 26 AIC · ⊞ 9.2K · ◷
- Dominant language
- TypeScript
- Stars
- 145
- Forks
- 63
- Avg merge
- 6h 15m
- Merged PRs (30d)
- 248
Getting set up
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from github/gh-aw-firewall
-
automated runner-doctor
Difficulty 2/5 1-3 hours Newbie friendliness 86/100
github/gh-aw-firewall#9081 ·
Maintainers usually reply within 1 day
-
agentic-workflows automated dependencies
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
github/gh-aw-firewall#3837 ·
Maintainers usually reply within 1 day
-
agentic-workflows
Difficulty 4/5 3-5 days Newbie friendliness 35/100
github/gh-aw-firewall#9091 ·
Maintainers usually reply within 1 day
-
code-quality refactoring
Difficulty 3/5 1-2 days Newbie friendliness 68/100
github/gh-aw-firewall#9090 ·
Maintainers usually reply within 1 day
-
agentic-workflows
Difficulty 3/5 1-2 days Newbie friendliness 25/100
github/gh-aw-firewall#9088 ·
Maintainers usually reply within 1 day
All issues in github/gh-aw-firewall
Similar issues
-
bug
Difficulty 1/5 Under an hour Newbie friendliness 88/100
StabilityNexus/Fate-EVM-Frontend#153 ·
Maintainers usually reply within 1 day
-
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
code-yeongyu/oh-my-openagent#9039 ·
Maintainers usually reply within 1 day
-
bug
Difficulty 2/5 1-3 hours Newbie friendliness 84/100
Tencent/teamai-cli#862 ·
Maintainers usually reply within 1 day
-
bug good first issue hacktoberfest redis
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
libredb/libredb-studio#1164 ·
Maintainers usually reply within 1 day
-
flake
Difficulty 2/5 1-3 hours Newbie friendliness 85/100
Maintainers usually reply within 1 day