Skip to content

Publish docker-mode containers on loopback only; warn for compose - #2

Merged
thorwhalen merged 2 commits into
mainfrom
bind-published-ports-to-loopback
Sep 22, 2026
Merged

thorwhalen merged 2 commits into
mainfrom
bind-published-ports-to-loopback

Conversation

@thorwhalen

@thorwhalen thorwhalen commented Sep 22, 2026 •

Copy link
Copy Markdown
Member

docker/image modes ran docker run -p <host>:<container>, which publishes on every interface. The gateway only needs to reach the container locally, and an all-interfaces publish lets clients reach the app directly, around enlace_auth (Docker's own iptables rules also bypass host firewalls such as ufw).

  • _docker.LOOPBACK is the single interface containers are published on and the address the proxy and health probes connect to; the docker run publish spec becomes 127.0.0.1:<host>:<container>.
  • compose and docker_attached modes: the port mapping belongs to the user, so enlace cannot change it; it now logs a WARNING (once) when the routed port is published on any non-loopback address (all bindings checked, v4 and v6), with the loopback mapping to use.
  • _docker.compose_published_addresses() / parse_published_addresses() / container_published_host_ips() / is_loopback_host() added; compose_published_port() keeps its signature.
  • README: "Network exposure" section.

Independent refute-review done; fixed from it: the configurable bind host (probes/proxy could not follow it) replaced by one constant; mixed-binding compose output; warn-once; docker_attached exposure warning; docs. Not covered: other services in a compose file (the warning says so), extra_run_args (not reachable from TOML).

Behaviour change: a docker-mode app's port is no longer reachable from other machines. Nothing in the fleet runs a docker-mode app today (no fleet dependents). The one existing assertion on the -p value (test_start_passes_env_and_port_mapping) is updated to the loopback form, which is the point of the change.

Tests: 61 passed, 2 skipped locally (incl. doctests).

🤖 Generated with Claude Code

thorwhalen and others added 2 commits September 22, 2026 15:19
docker run -p host:container publishes on every interface, so a managed
app was reachable directly, around the gateway's auth (Docker's iptables
rules also bypass host firewalls such as ufw). DockerProcess now publishes
on bind_host (default 127.0.0.1). For compose stacks, whose port mapping
is the user's, a WARNING is logged when the service is published on a
non-loopback address.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- LOOPBACK is the single publish interface and the address the proxy and
  health probes connect to (the configurable bind host could not work).
- compose: every binding reported by 'docker compose port' is checked
  (mixed v4/v6), warned once, with an ephemeral-port loopback suggestion.
- docker_attached: warns when the container's port is published on a
  non-loopback HostIp.
- README: network exposure section.

Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
@thorwhalen
thorwhalen merged commit 650870a into main Sep 22, 2026
12 checks passed
@thorwhalen
thorwhalen deleted the bind-published-ports-to-loopback branch September 22, 2026 15:25
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant