https://github.com/Tecnativa/docker-socket-proxy

What?
This is a security-enhanced proxy for the Docker Socket.

Why?
Giving access to your Docker socket could mean giving root access to your host, or even to your whole swarm, but some services require hooking into that socket to react to events, etc. Using this proxy lets you block anything you consider those services should not do.

How?
We use the official Alpine-based HAProxy image with a small configuration file.

It blocks access to the Docker socket API according to the environment variables you set. It returns a HTTP 403 Forbidden status for those dangerous requests that should never happen.

最后修改:2024 年 05 月 11 日
如果觉得我的文章对你有用,请随意赞赏