From 1c037aca5882d1c153a14d8c9dd55f41fa5e263d Mon Sep 17 00:00:00 2001 From: Kosmos Date: Tue, 25 Aug 2026 09:08:26 +0000 Subject: [PATCH] Trust the active Docker network gateway --- Dockerfile | 2 +- README.md | 9 +++++---- compose.yaml | 2 -- docker/entrypoint.sh | 4 ++-- 4 files changed, 8 insertions(+), 9 deletions(-) diff --git a/Dockerfile b/Dockerfile index 9333e43..5b64914 100644 --- a/Dockerfile +++ b/Dockerfile @@ -32,7 +32,7 @@ RUN --mount=type=cache,target=/root/.cache/pip \ FROM debian:trixie-slim AS runtime RUN apt-get update \ - && apt-get install -y --no-install-recommends ca-certificates \ + && apt-get install -y --no-install-recommends ca-certificates iproute2 \ && rm -rf /var/lib/apt/lists/* \ && groupadd --system --gid 10001 drivershub \ && useradd --system --uid 10001 --gid drivershub --home-dir /app drivershub diff --git a/README.md b/README.md index ac901d9..e331b01 100644 --- a/README.md +++ b/README.md @@ -79,10 +79,11 @@ docker compose ps By default, the API is available at `http://localhost:17777/api`. Swagger UI is available at `http://localhost:17777/api/doc`. The default bind address is suitable for a reverse proxy on the Docker host. -The backend resolves the Docker host gateway when it starts. Uvicorn trusts -forwarded headers only from this gateway and the loopback interface. This lets -audit and security records contain the client IP address. Keep `BACKEND_BIND` -on `127.0.0.1` and let the reverse proxy provide the public endpoint. +The backend reads its active Docker network gateway when it starts. Uvicorn +trusts forwarded headers only from this gateway and the loopback interface. +This works with multiple Docker Compose networks and lets audit and security +records contain the client IP address. Keep `BACKEND_BIND` on `127.0.0.1` and +let the reverse proxy provide the public endpoint. ## Store persistent data diff --git a/compose.yaml b/compose.yaml index 392cbfc..15baad2 100644 --- a/compose.yaml +++ b/compose.yaml @@ -58,8 +58,6 @@ services: restart: unless-stopped environment: TRUST_HOST_PROXY: "1" - extra_hosts: - - "host.docker.internal:host-gateway" command: ["drivershub", "--config", "/app/config/config.json", "--banner-service-url", "http://bannergen:8700/banner"] volumes: - ./config:/app/config diff --git a/docker/entrypoint.sh b/docker/entrypoint.sh index 0348e10..2893a28 100755 --- a/docker/entrypoint.sh +++ b/docker/entrypoint.sh @@ -3,9 +3,9 @@ set -eu if [ "${TRUST_HOST_PROXY:-0}" = "1" ]; then - proxy_ip="$(getent ahostsv4 host.docker.internal | sed -n '1{s/[[:space:]].*//;p;}')" + proxy_ip="$(ip -4 route show default | sed -n 's/^default via \([^ ]*\).*/\1/p' | head -n 1)" if [ -z "$proxy_ip" ]; then - echo "Cannot resolve the trusted Docker host gateway." >&2 + echo "Cannot determine the trusted Docker network gateway." >&2 exit 1 fi export FORWARDED_ALLOW_IPS="127.0.0.1,$proxy_ip"