Sign inSign up

knrdl/traefik-docker-protector

By knrdl

•Updated over 3 years ago

Image
0

1.8K

knrdl/traefik-docker-protector repository overview

⁠DEPRECATED: Use https://github.com/knrdl/docker-socket-protector⁠ instead

⁠Traefik Docker Protector

Limit traefik's control over the docker daemon

Traefik has a great docker integration⁠! But exposing the docker socket to traefik equals basically giving traefik full root access to the host system. This litte program acts as a filtering proxy so traefik gets readonly access to necessary information from docker. See also https://doc.traefik.io/traefik/providers/docker/#endpoint⁠

.---------.                    .----------------.                          .--------.
|         |                    | Traefik Docker |                          | Docker |
| Traefik |<--Docker Network-->| Protector      |<--/var/run/docker.sock-->| Daemon |
'---------'                    '----------------'                          '--------'

⁠Setup

version: '3.9'

services:

  traefik:
    image: traefik
    command: "--providers.docker.endpoint=http://traefik-docker-protector:2375"
    ports:
      - "80:80"
    networks:
      - docker_socket_net
  
  traefik-docker-protector:
    image: knrdl/traefik-docker-protector
    hostname: traefik-docker-protector
    read_only: true
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock
    networks:
      - docker_socket_net

networks:
  docker_socket_net:
    attachable: false
    internal: true

https://github.com/knrdl/traefik-docker-protector⁠

Tag summary

Content type

Image

Digest

Size

2.1 MB

Last updated

over 4 years ago

docker pull knrdl/traefik-docker-protector