Limit traefik's control over the docker daemon
Traefik has a great docker integration! But exposing the docker socket to traefik equals basically giving traefik full root access to the host system. This litte program acts as a filtering proxy so traefik gets readonly access to necessary information from docker. See also https://doc.traefik.io/traefik/providers/docker/#endpoint
.---------. .----------------. .--------.
| | | Traefik Docker | | Docker |
| Traefik |<--Docker Network-->| Protector |<--/var/run/docker.sock-->| Daemon |
'---------' '----------------' '--------'
version: '3.9'
services:
traefik:
image: traefik
command: "--providers.docker.endpoint=http://traefik-docker-protector:2375"
ports:
- "80:80"
networks:
- docker_socket_net
traefik-docker-protector:
image: knrdl/traefik-docker-protector
hostname: traefik-docker-protector
read_only: true
volumes:
- /var/run/docker.sock:/var/run/docker.sock
networks:
- docker_socket_net
networks:
docker_socket_net:
attachable: false
internal: true
Content type
Image
Digest
Size
2.1 MB
Last updated
over 4 years ago
docker pull knrdl/traefik-docker-protector