Update Security_Containers/docker-socket-proxy/compose.yaml
This commit is contained in:
@@ -3,14 +3,18 @@ services:
|
|||||||
image: tecnativa/docker-socket-proxy:latest
|
image: tecnativa/docker-socket-proxy:latest
|
||||||
container_name: socket-proxy
|
container_name: socket-proxy
|
||||||
restart: unless-stopped
|
restart: unless-stopped
|
||||||
|
security_opt:
|
||||||
|
- no-new-privileges:true
|
||||||
volumes:
|
volumes:
|
||||||
- /var/run/docker.sock:/var/run/docker.sock:ro
|
- /var/run/docker.sock:/var/run/docker.sock:ro
|
||||||
environment:
|
environment:
|
||||||
CONTAINERS: 1 # Traefik needs this
|
# Timeouts (silences HAProxy warning, sane for event streaming)
|
||||||
SERVICES: 0
|
TIMEOUT_CONNECT: 5
|
||||||
TASKS: 0
|
TIMEOUT_CLIENT: 3600
|
||||||
NETWORKS: 0
|
TIMEOUT_SERVER: 3600
|
||||||
NODES: 0
|
# Traefik only needs CONTAINERS
|
||||||
|
CONTAINERS: 1
|
||||||
|
# Everything else explicitly off
|
||||||
BUILD: 0
|
BUILD: 0
|
||||||
COMMIT: 0
|
COMMIT: 0
|
||||||
CONFIGS: 0
|
CONFIGS: 0
|
||||||
@@ -18,15 +22,22 @@ services:
|
|||||||
EXEC: 0
|
EXEC: 0
|
||||||
IMAGES: 0
|
IMAGES: 0
|
||||||
INFO: 0
|
INFO: 0
|
||||||
|
NETWORKS: 0
|
||||||
|
NODES: 0
|
||||||
PLUGINS: 0
|
PLUGINS: 0
|
||||||
POST: 0
|
POST: 0
|
||||||
SECRETS: 0
|
SECRETS: 0
|
||||||
|
SERVICES: 0
|
||||||
|
SESSION: 0
|
||||||
SWARM: 0
|
SWARM: 0
|
||||||
SYSTEM: 0
|
SYSTEM: 0
|
||||||
|
TASKS: 0
|
||||||
VOLUMES: 0
|
VOLUMES: 0
|
||||||
networks:
|
networks:
|
||||||
- socket_proxy # isolated network, NOT traefik_network
|
- socket_proxy
|
||||||
|
|
||||||
networks:
|
networks:
|
||||||
socket_proxy:
|
socket_proxy:
|
||||||
name: docker_socket_proxy
|
name: docker_socket_proxy
|
||||||
driver: bridge
|
driver: bridge
|
||||||
|
internal: true # no external routing — container-to-container only
|
||||||
Reference in New Issue
Block a user