3 ms·
A couple years ago, I wrote a container than periodically polls the Docker Socket to check for currently running containers with exposed ports and a special lab
by styfle 8y ago
A couple years ago, I wrote a container than periodically polls the Docker Socket to check for currently running containers with exposed ports and a special label applied.
It then iterates over those containers and writes a nginx.conf file to a shared volume, then sends a SIGHUP signal to another container running nginx as a reverse proxy to the containers.
The "polling job" container doesn't expose any ports and is not reachable from the outside world and the only input into this program is reading data from the Docker Socket.
Do you think this is still vulnerable to attacks like Traefik is or does this 2-container routing protect against the attacks you're thinking of?
- fpgaminer 8y agoVery nice. Seems airtight to me. As others have suggested, Traefik should really be doing something similar (or Docker should add ACLs to its API).