Trust the active Docker network gateway

This commit is contained in:
2026-08-25 09:08:26 +00:00
parent a84a17df41
commit 1c037aca58
4 changed files with 8 additions and 9 deletions
+5 -4
View File
@@ -79,10 +79,11 @@ docker compose ps
By default, the API is available at `http://localhost:17777/api`. Swagger UI is
available at `http://localhost:17777/api/doc`.
The default bind address is suitable for a reverse proxy on the Docker host.
The backend resolves the Docker host gateway when it starts. Uvicorn trusts
forwarded headers only from this gateway and the loopback interface. This lets
audit and security records contain the client IP address. Keep `BACKEND_BIND`
on `127.0.0.1` and let the reverse proxy provide the public endpoint.
The backend reads its active Docker network gateway when it starts. Uvicorn
trusts forwarded headers only from this gateway and the loopback interface.
This works with multiple Docker Compose networks and lets audit and security
records contain the client IP address. Keep `BACKEND_BIND` on `127.0.0.1` and
let the reverse proxy provide the public endpoint.
## Store persistent data