Trust the active Docker network gateway
This commit is contained in:
+1
-1
@@ -32,7 +32,7 @@ RUN --mount=type=cache,target=/root/.cache/pip \
|
||||
FROM debian:trixie-slim AS runtime
|
||||
|
||||
RUN apt-get update \
|
||||
&& apt-get install -y --no-install-recommends ca-certificates \
|
||||
&& apt-get install -y --no-install-recommends ca-certificates iproute2 \
|
||||
&& rm -rf /var/lib/apt/lists/* \
|
||||
&& groupadd --system --gid 10001 drivershub \
|
||||
&& useradd --system --uid 10001 --gid drivershub --home-dir /app drivershub
|
||||
|
||||
@@ -79,10 +79,11 @@ docker compose ps
|
||||
By default, the API is available at `http://localhost:17777/api`. Swagger UI is
|
||||
available at `http://localhost:17777/api/doc`.
|
||||
The default bind address is suitable for a reverse proxy on the Docker host.
|
||||
The backend resolves the Docker host gateway when it starts. Uvicorn trusts
|
||||
forwarded headers only from this gateway and the loopback interface. This lets
|
||||
audit and security records contain the client IP address. Keep `BACKEND_BIND`
|
||||
on `127.0.0.1` and let the reverse proxy provide the public endpoint.
|
||||
The backend reads its active Docker network gateway when it starts. Uvicorn
|
||||
trusts forwarded headers only from this gateway and the loopback interface.
|
||||
This works with multiple Docker Compose networks and lets audit and security
|
||||
records contain the client IP address. Keep `BACKEND_BIND` on `127.0.0.1` and
|
||||
let the reverse proxy provide the public endpoint.
|
||||
|
||||
## Store persistent data
|
||||
|
||||
|
||||
@@ -58,8 +58,6 @@ services:
|
||||
restart: unless-stopped
|
||||
environment:
|
||||
TRUST_HOST_PROXY: "1"
|
||||
extra_hosts:
|
||||
- "host.docker.internal:host-gateway"
|
||||
command: ["drivershub", "--config", "/app/config/config.json", "--banner-service-url", "http://bannergen:8700/banner"]
|
||||
volumes:
|
||||
- ./config:/app/config
|
||||
|
||||
@@ -3,9 +3,9 @@
|
||||
set -eu
|
||||
|
||||
if [ "${TRUST_HOST_PROXY:-0}" = "1" ]; then
|
||||
proxy_ip="$(getent ahostsv4 host.docker.internal | sed -n '1{s/[[:space:]].*//;p;}')"
|
||||
proxy_ip="$(ip -4 route show default | sed -n 's/^default via \([^ ]*\).*/\1/p' | head -n 1)"
|
||||
if [ -z "$proxy_ip" ]; then
|
||||
echo "Cannot resolve the trusted Docker host gateway." >&2
|
||||
echo "Cannot determine the trusted Docker network gateway." >&2
|
||||
exit 1
|
||||
fi
|
||||
export FORWARDED_ALLOW_IPS="127.0.0.1,$proxy_ip"
|
||||
|
||||
Reference in New Issue
Block a user