3 ms·
> If someone found an exploit in your web app container [...] A good pattern here is to reverse proxy all requests to the application through something like ng
by reportt 5y ago
> If someone found an exploit in your web app container [...]
A good pattern here is to reverse proxy all requests to the application through something like nginx. My applications tend to have a back-end application that is not accessible to the internet, with an nginx instance that proxies all API requests itself. Only port 80 is public facing. If someone can get console access to an nginx container and then use that to springboard to another container and get root access there (again, where the only open ports are ports 80, maybe 8000?) to get envvars, they should get access to it all.
If you are worried about secrets, check out the Docker Compose 3.9 documentation: https://docs.docker.com/compose/compose-file/compose-file-v3/#secrets https://docs.docker.com/compose/compose-file/compose-file-v3...