Docker socket proxy of the base platform: one client, reading only, allowed paths, amd64/arm64
568
The one way to the Docker socket in the base platform: wollomatic/socket-proxy with the platform's rules baked in. It lets one client, cAdvisor, read what it needs to name the containers, and nothing else.
Not a general-purpose socket proxy image. Its rules fit one specific platform. The repository is public only so that the host can pull without credentials. For your own projects, use wollomatic/socket-proxy and set your own rules.
One tag per release, X.Y.Z, the same version as the other base-* images of that release. There is
no latest: deployments reference a version and its digest.
Platforms: linux/amd64, linux/arm64.
wollomatic/socket-proxy 1.13.1, pinned by digestcadvisor, looked up at every request; anyone else gets 403GET and HEAD; another method, every write above all, gets 405version, info, _ping, containers/json,
containers/<id>/json; another path gets 403Mount the socket read-only and run as nobody in the group that owns the socket on the host, here
999 as an example (stat -c %g /var/run/docker.sock).
Port: 2375, meant for an internal Docker network shared with cAdvisor only, never published.
services:
socket-proxy:
image: christianmaier/base-socket-proxy:X.Y.Z
user: "65534:999"
volumes: ["/var/run/docker.sock:/var/run/docker.sock:ro"]
networks: [docker-api]
read_only: true
cap_drop: ["ALL"]
security_opt: ["no-new-privileges:true"]
healthcheck:
test: ["CMD", "/healthcheck"]
networks:
docker-api:
internal: true
nobody in the socket's group, needs no capabilities, read-only root filesystemContent type
Image
Digest
sha256:67908c13c…
Size
5.4 MB
Last updated
1 day ago
docker pull christianmaier/base-socket-proxy:2.9.4