YARN-7326 leveraged the ANY record type for upstream resolution, but some implementations don't support ANY due to the potential for abuse, namely Cloudflare. Docker Hub leverages Cloudflare for image distribution, so when Registry DNS is used as the sole resolver, docker image downloads are failing.
[root@host ~]# docker run -u root -it centos bash
Unable to find image 'centos:latest' locally
latest: Pulling from library/centos
469cfcc7a4b3: Already exists
docker: error pulling image configuration: Get https:
[root@host~]# nslookup production.cloudflare.docker.com registry.dns.host
production.cloudflare.docker.com hinfo = "ANY obsoleted" "See draft-ietf-dnsop-refuse-any"