Trust the active Docker network gateway

This commit is contained in:
2026-08-25 09:08:26 +00:00
parent a84a17df41
commit 1c037aca58
4 changed files with 8 additions and 9 deletions
+1 -1
View File
@@ -32,7 +32,7 @@ RUN --mount=type=cache,target=/root/.cache/pip \
FROM debian:trixie-slim AS runtime FROM debian:trixie-slim AS runtime
RUN apt-get update \ RUN apt-get update \
&& apt-get install -y --no-install-recommends ca-certificates \ && apt-get install -y --no-install-recommends ca-certificates iproute2 \
&& rm -rf /var/lib/apt/lists/* \ && rm -rf /var/lib/apt/lists/* \
&& groupadd --system --gid 10001 drivershub \ && groupadd --system --gid 10001 drivershub \
&& useradd --system --uid 10001 --gid drivershub --home-dir /app drivershub && useradd --system --uid 10001 --gid drivershub --home-dir /app drivershub
+5 -4
View File
@@ -79,10 +79,11 @@ docker compose ps
By default, the API is available at `http://localhost:17777/api`. Swagger UI is By default, the API is available at `http://localhost:17777/api`. Swagger UI is
available at `http://localhost:17777/api/doc`. available at `http://localhost:17777/api/doc`.
The default bind address is suitable for a reverse proxy on the Docker host. The default bind address is suitable for a reverse proxy on the Docker host.
The backend resolves the Docker host gateway when it starts. Uvicorn trusts The backend reads its active Docker network gateway when it starts. Uvicorn
forwarded headers only from this gateway and the loopback interface. This lets trusts forwarded headers only from this gateway and the loopback interface.
audit and security records contain the client IP address. Keep `BACKEND_BIND` This works with multiple Docker Compose networks and lets audit and security
on `127.0.0.1` and let the reverse proxy provide the public endpoint. records contain the client IP address. Keep `BACKEND_BIND` on `127.0.0.1` and
let the reverse proxy provide the public endpoint.
## Store persistent data ## Store persistent data
-2
View File
@@ -58,8 +58,6 @@ services:
restart: unless-stopped restart: unless-stopped
environment: environment:
TRUST_HOST_PROXY: "1" TRUST_HOST_PROXY: "1"
extra_hosts:
- "host.docker.internal:host-gateway"
command: ["drivershub", "--config", "/app/config/config.json", "--banner-service-url", "http://bannergen:8700/banner"] command: ["drivershub", "--config", "/app/config/config.json", "--banner-service-url", "http://bannergen:8700/banner"]
volumes: volumes:
- ./config:/app/config - ./config:/app/config
+2 -2
View File
@@ -3,9 +3,9 @@
set -eu set -eu
if [ "${TRUST_HOST_PROXY:-0}" = "1" ]; then if [ "${TRUST_HOST_PROXY:-0}" = "1" ]; then
proxy_ip="$(getent ahostsv4 host.docker.internal | sed -n '1{s/[[:space:]].*//;p;}')" proxy_ip="$(ip -4 route show default | sed -n 's/^default via \([^ ]*\).*/\1/p' | head -n 1)"
if [ -z "$proxy_ip" ]; then if [ -z "$proxy_ip" ]; then
echo "Cannot resolve the trusted Docker host gateway." >&2 echo "Cannot determine the trusted Docker network gateway." >&2
exit 1 exit 1
fi fi
export FORWARDED_ALLOW_IPS="127.0.0.1,$proxy_ip" export FORWARDED_ALLOW_IPS="127.0.0.1,$proxy_ip"