Artifact fetches recognise a second proxy header as a network allowlist block.
What's wrong with this entry?
Artifact fetches now treat a 403 carrying x-deny-reason: host_not_allowed as a network allowlist block, alongside the existing x-proxy-error: blocked-by-allowlist, and other failures append the proxy's deny reason to the error text. The message makes clear the artifact itself is still accessible.
not reachable through this environment's network allowlist; your access to the artifact itself is fine (the boot check passed)
Strings lifted out of the shipped bundle, so the claim above can be checked against them.