Update Security_Containers/docker-socket-proxy/compose.yaml

This commit is contained in:
2026-05-14 02:59:59 +00:00
parent 1b4b2313a5
commit 6ab08bdcb0
@@ -3,14 +3,18 @@ services:
image: tecnativa/docker-socket-proxy:latest image: tecnativa/docker-socket-proxy:latest
container_name: socket-proxy container_name: socket-proxy
restart: unless-stopped restart: unless-stopped
security_opt:
- no-new-privileges:true
volumes: volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro - /var/run/docker.sock:/var/run/docker.sock:ro
environment: environment:
CONTAINERS: 1 # Traefik needs this # Timeouts (silences HAProxy warning, sane for event streaming)
SERVICES: 0 TIMEOUT_CONNECT: 5
TASKS: 0 TIMEOUT_CLIENT: 3600
NETWORKS: 0 TIMEOUT_SERVER: 3600
NODES: 0 # Traefik only needs CONTAINERS
CONTAINERS: 1
# Everything else explicitly off
BUILD: 0 BUILD: 0
COMMIT: 0 COMMIT: 0
CONFIGS: 0 CONFIGS: 0
@@ -18,15 +22,22 @@ services:
EXEC: 0 EXEC: 0
IMAGES: 0 IMAGES: 0
INFO: 0 INFO: 0
NETWORKS: 0
NODES: 0
PLUGINS: 0 PLUGINS: 0
POST: 0 POST: 0
SECRETS: 0 SECRETS: 0
SERVICES: 0
SESSION: 0
SWARM: 0 SWARM: 0
SYSTEM: 0 SYSTEM: 0
TASKS: 0
VOLUMES: 0 VOLUMES: 0
networks: networks:
- socket_proxy # isolated network, NOT traefik_network - socket_proxy
networks: networks:
socket_proxy: socket_proxy:
name: docker_socket_proxy name: docker_socket_proxy
driver: bridge driver: bridge
internal: true # no external routing — container-to-container only