Publish docker-mode containers on loopback only; warn for compose - #2
Merged
Merged
Conversation
docker run -p host:container publishes on every interface, so a managed app was reachable directly, around the gateway's auth (Docker's iptables rules also bypass host firewalls such as ufw). DockerProcess now publishes on bind_host (default 127.0.0.1). For compose stacks, whose port mapping is the user's, a WARNING is logged when the service is published on a non-loopback address. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
- LOOPBACK is the single publish interface and the address the proxy and health probes connect to (the configurable bind host could not work). - compose: every binding reported by 'docker compose port' is checked (mixed v4/v6), warned once, with an ephemeral-port loopback suggestion. - docker_attached: warns when the container's port is published on a non-loopback HostIp. - README: network exposure section. Co-Authored-By: Claude Opus 5 <noreply@anthropic.com>
This file contains hidden or bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.This suggestion is invalid because no changes were made to the code.Suggestions cannot be applied while the pull request is closed.Suggestions cannot be applied while viewing a subset of changes.Only one suggestion per line can be applied in a batch.Add this suggestion to a batch that can be applied as a single commit.Applying suggestions on deleted lines is not supported.You must change the existing code in this line in order to create a valid suggestion.Outdated suggestions cannot be applied.This suggestion has been applied or marked resolved.Suggestions cannot be applied from pending reviews.Suggestions cannot be applied on multi-line comments.Suggestions cannot be applied while the pull request is queued to merge.Suggestion cannot be applied right now. Please check back later.
docker/imagemodes randocker run -p <host>:<container>, which publishes on every interface. The gateway only needs to reach the container locally, and an all-interfaces publish lets clients reach the app directly, around enlace_auth (Docker's own iptables rules also bypass host firewalls such as ufw)._docker.LOOPBACKis the single interface containers are published on and the address the proxy and health probes connect to; thedocker runpublish spec becomes127.0.0.1:<host>:<container>.composeanddocker_attachedmodes: the port mapping belongs to the user, so enlace cannot change it; it now logs a WARNING (once) when the routed port is published on any non-loopback address (all bindings checked, v4 and v6), with the loopback mapping to use._docker.compose_published_addresses()/parse_published_addresses()/container_published_host_ips()/is_loopback_host()added;compose_published_port()keeps its signature.Independent refute-review done; fixed from it: the configurable bind host (probes/proxy could not follow it) replaced by one constant; mixed-binding compose output; warn-once; docker_attached exposure warning; docs. Not covered: other services in a compose file (the warning says so),
extra_run_args(not reachable from TOML).Behaviour change: a docker-mode app's port is no longer reachable from other machines. Nothing in the fleet runs a docker-mode app today (no fleet dependents). The one existing assertion on the
-pvalue (test_start_passes_env_and_port_mapping) is updated to the loopback form, which is the point of the change.Tests: 61 passed, 2 skipped locally (incl. doctests).
🤖 Generated with Claude Code