fix(compose): publish db on loopback only — was reachable from any LAN

The unqualified 0.0.0.0 publish put Postgres on every interface, and
Docker delivers published ports through PREROUTING DNAT into the
FORWARD path — ufw's default deny incoming never sees those packets.
Result: the database was reachable from whatever network the laptop
joined (home, guest Wi-Fi, hotel), not just from the host.

Bind to 127.0.0.1/[::1] instead: with no DNAT matching LAN-destined
packets, they fall back to INPUT where the firewall actually applies.
Host-side tools keep working over the loopback publish (both families
bound because localhost may resolve to ::1 first); app↔db and tests↔db
are untouched — they use the db service name on the compose network,
which never traverses iptables on this host (br_netfilter not loaded).

If LAN access to the DB is ever wanted again, revert to an unqualified
publish and rely on DOCKER-USER home-subnet scoping instead of an
open binding.
This commit is contained in:
John O'Keefe
2026-10-03 21:35:15 -04:00
parent 72839921f2
commit b03ed9a2f2
+2 -1
View File
@@ -15,7 +15,8 @@ services:
# Make other volumes as needed # Make other volumes as needed
- ./uploads:/app/uploads - ./uploads:/app/uploads
ports: ports:
- "${DB_PORT:-5432}:${DB_PORT:-5432}" - "127.0.0.1:${DB_PORT:-5432}:${DB_PORT:-5432}"
- "[::1]:${DB_PORT:-5432}:${DB_PORT:-5432}"
healthcheck: healthcheck:
test: ["CMD-SHELL", "pg_isready -U postgres"] test: ["CMD-SHELL", "pg_isready -U postgres"]
interval: 30s interval: 30s