fix(compose): publish db on loopback only — was reachable from any LAN
The unqualified 0.0.0.0 publish put Postgres on every interface, and Docker delivers published ports through PREROUTING DNAT into the FORWARD path — ufw's default deny incoming never sees those packets. Result: the database was reachable from whatever network the laptop joined (home, guest Wi-Fi, hotel), not just from the host. Bind to 127.0.0.1/[::1] instead: with no DNAT matching LAN-destined packets, they fall back to INPUT where the firewall actually applies. Host-side tools keep working over the loopback publish (both families bound because localhost may resolve to ::1 first); app↔db and tests↔db are untouched — they use the db service name on the compose network, which never traverses iptables on this host (br_netfilter not loaded). If LAN access to the DB is ever wanted again, revert to an unqualified publish and rely on DOCKER-USER home-subnet scoping instead of an open binding.
This commit is contained in:
+2
-1
@@ -15,7 +15,8 @@ services:
|
|||||||
# Make other volumes as needed
|
# Make other volumes as needed
|
||||||
- ./uploads:/app/uploads
|
- ./uploads:/app/uploads
|
||||||
ports:
|
ports:
|
||||||
- "${DB_PORT:-5432}:${DB_PORT:-5432}"
|
- "127.0.0.1:${DB_PORT:-5432}:${DB_PORT:-5432}"
|
||||||
|
- "[::1]:${DB_PORT:-5432}:${DB_PORT:-5432}"
|
||||||
healthcheck:
|
healthcheck:
|
||||||
test: ["CMD-SHELL", "pg_isready -U postgres"]
|
test: ["CMD-SHELL", "pg_isready -U postgres"]
|
||||||
interval: 30s
|
interval: 30s
|
||||||
|
|||||||
Reference in New Issue
Block a user