Sign inSign up

christianmaier/base-socket-proxy

By christianmaier

•Updated 1 day ago

Docker socket proxy of the base platform: one client, reading only, allowed paths, amd64/arm64

Image
Monitoring & observability
0

568

christianmaier/base-socket-proxy repository overview

⁠base-socket-proxy

The one way to the Docker socket in the base platform: wollomatic/socket-proxy⁠ with the platform's rules baked in. It lets one client, cAdvisor, read what it needs to name the containers, and nothing else.

Not a general-purpose socket proxy image. Its rules fit one specific platform. The repository is public only so that the host can pull without credentials. For your own projects, use wollomatic/socket-proxy⁠ and set your own rules.

⁠Tags

One tag per release, X.Y.Z, the same version as the other base-* images of that release. There is no latest: deployments reference a version and its digest.

Platforms: linux/amd64, linux/arm64.

⁠What is inside

  • wollomatic/socket-proxy 1.13.1, pinned by digest
  • Rules:
    • only the client that resolves as cadvisor, looked up at every request; anyone else gets 403
    • only GET and HEAD; another method, every write above all, gets 405
    • only these paths, with or without the API version: version, info, _ping, containers/json, containers/<id>/json; another path gets 403
  • A watchdog that stops the proxy when the socket is gone, so that Docker restarts it

⁠Running

Mount the socket read-only and run as nobody in the group that owns the socket on the host, here 999 as an example (stat -c %g /var/run/docker.sock).

Port: 2375, meant for an internal Docker network shared with cAdvisor only, never published.

services:
  socket-proxy:
    image: christianmaier/base-socket-proxy:X.Y.Z
    user: "65534:999"
    volumes: ["/var/run/docker.sock:/var/run/docker.sock:ro"]
    networks: [docker-api]
    read_only: true
    cap_drop: ["ALL"]
    security_opt: ["no-new-privileges:true"]
    healthcheck:
      test: ["CMD", "/healthcheck"]
networks:
  docker-api:
    internal: true

⁠Security

  • Runs as nobody in the socket's group, needs no capabilities, read-only root filesystem
  • Before every release and weekly: scanned for vulnerabilities with a fix (Trivy), for Dockerfile misconfigurations and for secrets (gitleaks)
  • SBOM (SPDX) and build provenance attached to every release

Tag summary

Content type

Image

Digest

sha256:67908c13c…

Size

5.4 MB

Last updated

1 day ago

docker pull christianmaier/base-socket-proxy:2.9.4