-
Notifications
You must be signed in to change notification settings - Fork 0
Expand file tree
/
Copy pathdocker-compose.proxy.yml
More file actions
47 lines (43 loc) · 1.22 KB
/
Copy pathdocker-compose.proxy.yml
File metadata and controls
47 lines (43 loc) · 1.22 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
# Docker Compose with Docker Socket Proxy
# Uses tecnativa/docker-socket-proxy to limit Docker API access for increased security
services:
docker-socket-proxy:
image: tecnativa/docker-socket-proxy:latest
restart: unless-stopped
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
environment:
# Only allow container operations transctrl needs
CONTAINERS: 1
POST: 1
DELETE: 1
# Deny everything else
NETWORKS: 0
SERVICES: 0
TASKS: 0
VOLUMES: 0
INFO: 0
transctrl:
image: ghcr.io/redsudo/transctrl:latest
restart: unless-stopped
depends_on:
- docker-socket-proxy
environment:
DOCKER_HOST: tcp://docker-socket-proxy:2375
ALLOWED_MOUNT_BASE: /mnt
LOG_LEVEL: INFO
volumes:
- transctrl-socket:/var/run/transctrl
- /mnt:/mnt:ro
# Note: No docker.sock mount - all access goes through the proxy
# Example core service that communicates with transctrl
# core:
# image: your-core-service
# depends_on:
# - transctrl
# volumes:
# - transctrl-socket:/var/run/transctrl:ro
# environment:
# TRANSCTRL_SOCKET: /var/run/transctrl/transctrl.sock
volumes:
transctrl-socket: