Only expose socket proxy on internal networks
This commit is contained in:
parent
66036cd301
commit
cdaa626068
4 changed files with 33 additions and 0 deletions
|
@ -9,6 +9,9 @@ services:
|
||||||
- HEALTHCHECKS_ID={{ vault_db_auto_backup_healthchecks_id }}
|
- HEALTHCHECKS_ID={{ vault_db_auto_backup_healthchecks_id }}
|
||||||
depends_on:
|
depends_on:
|
||||||
- docker_proxy
|
- docker_proxy
|
||||||
|
networks:
|
||||||
|
- default
|
||||||
|
- backup_private
|
||||||
|
|
||||||
docker_proxy:
|
docker_proxy:
|
||||||
image: lscr.io/linuxserver/socket-proxy:latest
|
image: lscr.io/linuxserver/socket-proxy:latest
|
||||||
|
@ -20,5 +23,13 @@ services:
|
||||||
- EXEC=1
|
- EXEC=1
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
|
networks:
|
||||||
|
- backup_private
|
||||||
|
tmpfs:
|
||||||
|
- /run
|
||||||
logging:
|
logging:
|
||||||
driver: none
|
driver: none
|
||||||
|
|
||||||
|
networks:
|
||||||
|
backup_private:
|
||||||
|
internal: true
|
||||||
|
|
|
@ -10,6 +10,9 @@ services:
|
||||||
- DOCKER_HOST=tcp://docker_proxy:2375
|
- DOCKER_HOST=tcp://docker_proxy:2375
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
command: forgejo-runner daemon
|
command: forgejo-runner daemon
|
||||||
|
networks:
|
||||||
|
- default
|
||||||
|
- forgejo_private
|
||||||
depends_on:
|
depends_on:
|
||||||
- docker_proxy
|
- docker_proxy
|
||||||
|
|
||||||
|
@ -31,5 +34,11 @@ services:
|
||||||
- /run
|
- /run
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
|
networks:
|
||||||
|
- forgejo_private
|
||||||
logging:
|
logging:
|
||||||
driver: none
|
driver: none
|
||||||
|
|
||||||
|
networks:
|
||||||
|
forgejo_private:
|
||||||
|
internal: true
|
||||||
|
|
|
@ -9,6 +9,9 @@ services:
|
||||||
- DOCKER_HOST=tcp://docker_proxy:2375
|
- DOCKER_HOST=tcp://docker_proxy:2375
|
||||||
- LOG_LEVEL=debug # Noisy, but required for debugging
|
- LOG_LEVEL=debug # Noisy, but required for debugging
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
networks:
|
||||||
|
- default
|
||||||
|
- renovate_private
|
||||||
depends_on:
|
depends_on:
|
||||||
- redis
|
- redis
|
||||||
- docker_proxy
|
- docker_proxy
|
||||||
|
@ -33,5 +36,13 @@ services:
|
||||||
- IMAGES=1
|
- IMAGES=1
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
|
networks:
|
||||||
|
- renovate_private
|
||||||
|
tmpfs:
|
||||||
|
- /run
|
||||||
logging:
|
logging:
|
||||||
driver: none
|
driver: none
|
||||||
|
|
||||||
|
networks:
|
||||||
|
renovate_private:
|
||||||
|
internal: true
|
||||||
|
|
|
@ -29,6 +29,8 @@ services:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
networks:
|
networks:
|
||||||
- proxy_private
|
- proxy_private
|
||||||
|
tmpfs:
|
||||||
|
- /run
|
||||||
logging:
|
logging:
|
||||||
driver: none
|
driver: none
|
||||||
|
|
||||||
|
|
Loading…
Reference in a new issue