Trust forwarded IPs from the host proxy

This commit is contained in:
2026-08-25 01:53:11 +00:00
parent 7f85db6689
commit f5aab65ff4
3 changed files with 17 additions and 0 deletions
+4
View File
@@ -72,6 +72,10 @@ docker compose ps
By default, the API is available at `http://localhost:17777/api`. Swagger UI is By default, the API is available at `http://localhost:17777/api`. Swagger UI is
available at `http://localhost:17777/api/doc`. available at `http://localhost:17777/api/doc`.
The default bind address is suitable for a reverse proxy on the Docker host. The default bind address is suitable for a reverse proxy on the Docker host.
The backend resolves the Docker host gateway when it starts. Uvicorn trusts
forwarded headers only from this gateway and the loopback interface. This lets
audit and security records contain the client IP address. Keep `BACKEND_BIND`
on `127.0.0.1` and let the reverse proxy provide the public endpoint.
## Store persistent data ## Store persistent data
+4
View File
@@ -56,6 +56,10 @@ services:
build: build:
context: . context: .
restart: unless-stopped restart: unless-stopped
environment:
TRUST_HOST_PROXY: "1"
extra_hosts:
- "host.docker.internal:host-gateway"
command: ["drivershub", "--config", "/app/config/config.json", "--banner-service-url", "http://bannergen:8700/banner"] command: ["drivershub", "--config", "/app/config/config.json", "--banner-service-url", "http://bannergen:8700/banner"]
volumes: volumes:
- ./config:/app/config - ./config:/app/config
+9
View File
@@ -2,6 +2,15 @@
# Start a compiled program. # Start a compiled program.
set -eu set -eu
if [ "${TRUST_HOST_PROXY:-0}" = "1" ]; then
proxy_ip="$(getent ahostsv4 host.docker.internal | sed -n '1{s/[[:space:]].*//;p;}')"
if [ -z "$proxy_ip" ]; then
echo "Cannot resolve the trusted Docker host gateway." >&2
exit 1
fi
export FORWARDED_ALLOW_IPS="127.0.0.1,$proxy_ip"
fi
if [ "${1:-}" = "drivershub" ]; then if [ "${1:-}" = "drivershub" ]; then
shift shift
exec /app/drivershub "$@" exec /app/drivershub "$@"