Trust forwarded IPs from the host proxy

This commit is contained in:
2026-08-25 01:53:11 +00:00
parent 7f85db6689
commit f5aab65ff4
3 changed files with 17 additions and 0 deletions
+4
View File
@@ -72,6 +72,10 @@ docker compose ps
By default, the API is available at `http://localhost:17777/api`. Swagger UI is
available at `http://localhost:17777/api/doc`.
The default bind address is suitable for a reverse proxy on the Docker host.
The backend resolves the Docker host gateway when it starts. Uvicorn trusts
forwarded headers only from this gateway and the loopback interface. This lets
audit and security records contain the client IP address. Keep `BACKEND_BIND`
on `127.0.0.1` and let the reverse proxy provide the public endpoint.
## Store persistent data
+4
View File
@@ -56,6 +56,10 @@ services:
build:
context: .
restart: unless-stopped
environment:
TRUST_HOST_PROXY: "1"
extra_hosts:
- "host.docker.internal:host-gateway"
command: ["drivershub", "--config", "/app/config/config.json", "--banner-service-url", "http://bannergen:8700/banner"]
volumes:
- ./config:/app/config
+9
View File
@@ -2,6 +2,15 @@
# Start a compiled program.
set -eu
if [ "${TRUST_HOST_PROXY:-0}" = "1" ]; then
proxy_ip="$(getent ahostsv4 host.docker.internal | sed -n '1{s/[[:space:]].*//;p;}')"
if [ -z "$proxy_ip" ]; then
echo "Cannot resolve the trusted Docker host gateway." >&2
exit 1
fi
export FORWARDED_ALLOW_IPS="127.0.0.1,$proxy_ip"
fi
if [ "${1:-}" = "drivershub" ]; then
shift
exec /app/drivershub "$@"