-
-
Notifications
You must be signed in to change notification settings - Fork 13
Expand file tree
/
Copy pathreadme-vars.yml
More file actions
483 lines (395 loc) · 22.1 KB
/
Copy pathreadme-vars.yml
File metadata and controls
483 lines (395 loc) · 22.1 KB
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
31
32
33
34
35
36
37
38
39
40
41
42
43
44
45
46
47
48
49
50
51
52
53
54
55
56
57
58
59
60
61
62
63
64
65
66
67
68
69
70
71
72
73
74
75
76
77
78
79
80
81
82
83
84
85
86
87
88
89
90
91
92
93
94
95
96
97
98
99
100
101
102
103
104
105
106
107
108
109
110
111
112
113
114
115
116
117
118
119
120
121
122
123
124
125
126
127
128
129
130
131
132
133
134
135
136
137
138
139
140
141
142
143
144
145
146
147
148
149
150
151
152
153
154
155
156
157
158
159
160
161
162
163
164
165
166
167
168
169
170
171
172
173
174
175
176
177
178
179
180
181
182
183
184
185
186
187
188
189
190
191
192
193
194
195
196
197
198
199
200
201
202
203
204
205
206
207
208
209
210
211
212
213
214
215
216
217
218
219
220
221
222
223
224
225
226
227
228
229
230
231
232
233
234
235
236
237
238
239
240
241
242
243
244
245
246
247
248
249
250
251
252
253
254
255
256
257
258
259
260
261
262
263
264
265
266
267
268
269
270
271
272
273
274
275
276
277
278
279
280
281
282
283
284
285
286
287
288
289
290
291
292
293
294
295
296
297
298
299
300
301
302
303
304
305
306
307
308
309
310
311
312
313
314
315
316
317
318
319
320
321
322
323
324
325
326
327
328
329
330
331
332
333
334
335
336
337
338
339
340
341
342
343
344
345
346
347
348
349
350
351
352
353
354
355
356
357
358
359
360
361
362
363
364
365
366
367
368
369
370
371
372
373
374
375
376
377
378
379
380
381
382
383
384
385
386
387
388
389
390
391
392
393
394
395
396
397
398
399
400
401
402
403
404
405
406
407
408
409
410
411
412
413
414
415
416
417
418
419
420
421
422
423
424
425
426
427
428
429
430
431
432
433
434
435
436
437
438
439
440
441
442
443
444
445
446
447
448
449
450
451
452
453
454
455
456
457
458
459
460
461
462
463
464
465
466
467
468
469
470
471
472
473
474
475
476
477
478
479
480
481
482
483
---
# project information
project_name: socket-proxy
project_logo: "https://raw.githubusercontent.com/linuxserver/docker-templates/master/linuxserver.io/img/docker-logo.png"
project_blurb: The Socket Proxy is a security-enhanced proxy which allows you to apply access rules to the Docker socket, limiting the attack surface for containers such as watchtower or Traefik that need to use it.
project_categories: "Docker"
full_custom_readme: |
{% raw -%}
[](https://linuxserver.io)
[](https://blog.linuxserver.io "all the things you can do with our containers including How-To guides, opinions and much more!")
[](https://discord.gg/YWrKVTn "realtime support / chat with the community and the team.")
[](https://discourse.linuxserver.io "post on our community forum.")
[](https://fleet.linuxserver.io "an online web interface which displays all of our maintained images.")
[](https://github.com/linuxserver "view the source for all of our repositories.")
[](https://opencollective.com/linuxserver "please consider helping us by either donating or contributing to our budget")
The [LinuxServer.io](https://linuxserver.io) team brings you another container release.
Find us at:
* [Blog](https://blog.linuxserver.io) - all the things you can do with our containers including How-To guides, opinions and much more!
* [Discord](https://discord.gg/YWrKVTn) - realtime support / chat with the community and the team.
* [Discourse](https://discourse.linuxserver.io) - post on our community forum.
* [Fleet](https://fleet.linuxserver.io) - an online web interface which displays all of our maintained images.
* [GitHub](https://github.com/linuxserver) - view the source for all of our repositories.
* [Open Collective](https://opencollective.com/linuxserver) - please consider helping us by either donating or contributing to our budget
# [linuxserver/socket-proxy](https://github.com/linuxserver/docker-socket-proxy)
[](https://scarf.sh/gateway/linuxserver-ci/docker/linuxserver%2Fsocket-proxy)
[](https://github.com/linuxserver/docker-socket-proxy)
[](https://github.com/linuxserver/docker-socket-proxy/releases)
[](https://github.com/linuxserver/docker-socket-proxy/packages)
[](https://gitlab.com/linuxserver.io/docker-socket-proxy/container_registry)
[](https://quay.io/repository/linuxserver.io/socket-proxy)
[](https://hub.docker.com/r/linuxserver/socket-proxy)
[](https://hub.docker.com/r/linuxserver/socket-proxy)
[](https://ci.linuxserver.io/job/Docker-Pipeline-Builders/job/docker-socket-proxy/job/main/)
The Socket Proxy is a security-enhanced proxy which allows you to apply access rules to the Docker socket, limiting the attack surface for containers such as watchtower or Traefik that need to use it.

## Supported Architectures
We utilise the docker manifest for multi-platform awareness. More information is available from docker [here](https://distribution.github.io/distribution/spec/manifest-v2-2/#manifest-list) and our announcement [here](https://blog.linuxserver.io/2019/02/21/the-lsio-pipeline-project/).
Simply pulling `lscr.io/linuxserver/socket-proxy:latest` should retrieve the correct image for your arch, but you can also pull specific arch images via tags.
The architectures supported by this image are:
| Architecture | Available | Tag |
| :----: | :----: | ---- |
| x86-64 | ✅ | amd64-\<version tag\> |
| riscv64 | ✅ | riscv64-\<version tag\> |
| arm64 | ✅ | arm64v8-\<version tag\> |
| armhf | ❌ | |
## Application Setup
This container is conceptually based on [https://github.com/Tecnativa/docker-socket-proxy](https://github.com/Tecnativa/docker-socket-proxy) and as such does not follow our usual container conventions. It *does not* support mods or custom scripts/services. It is designed to act as a drop-in replacement for the Tecnativa container.
The container should be run on the same docker network as the service(s) using it. Most containers that would normally connect to a mounted docker.sock can have their endpoint overridden using the `DOCKER_HOST` environment variable if they do not offer the option in their configuration; it should typically be pointed to `tcp://socket-proxy:2375`.
* Never expose this container's port to a public network. It should be treated the same way you would treat the docker socket or TCP endpoint.
* Revoke access to any API section that you consider your service should not need.
* To see the versions of the API your Docker daemon and client support, use `docker version` and check the `API version`.
* [Read the docs](https://docs.docker.com/engine/api/) for the API version you are using for an explanation of all the available endpoints.
### Podman / libpod API
Podman exposes two API groups on the same socket: the Docker-compatible API (controlled by the existing env vars above) and the libpod-native API prefixed with `/libpod/`. The `LIBPOD_*` environment variables control access to the libpod endpoints independently of their Docker-compat equivalents.
For example, to use [prometheus-podman-exporter](https://github.com/containers/prometheus-podman-exporter), enable:
```yaml
- LIBPOD_CONTAINERS=1
- LIBPOD_INFO=1
- LIBPOD_NETWORKS=1
- LIBPOD_PODS=1
- LIBPOD_VOLUMES=1
- LIBPOD_IMAGES=1
- LIBPOD_EVENTS=1
```
Point the exporter at `tcp://socket-proxy:2375` using `CONTAINER_HOST`. `LIBPOD_PING` and `LIBPOD_VERSION` are enabled by default (like their Docker-compat counterparts `PING` and `VERSION`).
### Rootless Podman as a non-root user
Under rootless Podman the container process runs as `root` *inside its user namespace* by default. You can go a step further and drop root inside the container as well, running the proxy as an unprivileged user such as `nobody` (UID/GID `65534`). Two things need to be handled for this to work:
* **Socket ownership.** The rootless Podman socket (`$XDG_RUNTIME_DIR/podman/podman.sock`) is owned by your host user. That user maps to `root` inside the container's namespace, so a non-root user in the container cannot read it. Use `--userns=keep-id:uid=65534,gid=65534` to map your host user onto UID/GID `65534` inside the container, so `nobody` owns the socket and can proxy it.
* **A writable `/run`.** The entrypoint renders the HAProxy config into `/run/haproxy` at startup, so `/run` must be writable by the non-root user. Mount it as a tmpfs with `mode=1777` (this also satisfies read-only operation).
Example `podman run`:
```bash
podman run -d \
--name=socket-proxy \
--user 65534:65534 \
--userns=keep-id:uid=65534,gid=65534 \
-e CONTAINERS=1 `#optional` \
-e LIBPOD_CONTAINERS=1 `#optional` \
-e POST=0 `#optional` \
-v $XDG_RUNTIME_DIR/podman/podman.sock:/var/run/docker.sock:ro \
-p 2375:2375 \
--read-only \
--tmpfs /run:rw,mode=1777 \
--restart unless-stopped \
lscr.io/linuxserver/socket-proxy:latest
```
Or as a rootless [Quadlet](https://docs.podman.io/en/latest/markdown/podman-systemd.unit.5.html) unit (`~/.config/containers/systemd/socket-proxy.container`), started with `systemctl --user daemon-reload && systemctl --user start socket-proxy`:
```ini
[Container]
ContainerName=socket-proxy
Image=lscr.io/linuxserver/socket-proxy:latest
User=65534:65534
UserNS=keep-id:uid=65534,gid=65534
Environment=CONTAINERS=1
Environment=LIBPOD_CONTAINERS=1
Environment=POST=0
Volume=%t/podman/podman.sock:/var/run/docker.sock:ro
PublishPort=2375:2375
ReadOnly=true
Tmpfs=/run:rw,mode=1777
[Install]
WantedBy=default.target
```
(`%t` expands to `$XDG_RUNTIME_DIR`.) Enable the socket first with `systemctl --user enable --now podman.socket`.
> [!NOTE]
> On SELinux-enforcing hosts (e.g. Fedora/RHEL), add `--security-opt label=disable` to the `podman run` (or `SecurityLabelDisable=true` to the Quadlet) so the container can access the mounted socket.
## Read-Only Operation
This image can be run with a read-only container filesystem. For details please [read the docs](https://docs.linuxserver.io/misc/read-only/).
## Usage
To help you get started creating a container from this image you can either use docker compose or the docker cli.
>[!NOTE]
>Unless a parameter is flaged as 'optional', it is *mandatory* and a value must be provided.
### docker compose (recommended, [click here for more info](https://docs.linuxserver.io/general/docker-compose))
```yaml
---
services:
socket-proxy:
image: lscr.io/linuxserver/socket-proxy:latest
container_name: socket-proxy
environment:
- ALLOW_ARCHIVE=0 #optional
- ALLOW_CHANGES=0 #optional
- ALLOW_EXPORT=0 #optional
- ALLOW_LOGS=0 #optional
- ALLOW_PAUSE=0 #optional
- ALLOW_RESTARTS=0 #optional
- ALLOW_STOP=0 #optional
- ALLOW_START=0 #optional
- ALLOW_TOP=0 #optional
- ALLOW_UNPAUSE=0 #optional
- AUTH=0 #optional
- BUILD=0 #optional
- COMMIT=0 #optional
- CONFIGS=0 #optional
- CONTAINERS=0 #optional
- DISABLE_IPV6=0 #optional
- DISTRIBUTION=0 #optional
- EVENTS=1 #optional
- EXEC=0 #optional
- IMAGES=0 #optional
- INFO=0 #optional
- LOG_LEVEL=info #optional
- NETWORKS=0 #optional
- NODES=0 #optional
- PING=1 #optional
- PLUGINS=0 #optional
- POST=0 #optional
- SECRETS=0 #optional
- SERVICES=0 #optional
- SESSION=0 #optional
- SWARM=0 #optional
- SYSTEM=0 #optional
- TASKS=0 #optional
- TZ=Etc/UTC #optional
- VERSION=1 #optional
- VOLUMES=0 #optional
- LIBPOD_CONTAINERS=0 #optional
- LIBPOD_EVENTS=0 #optional
- LIBPOD_EXEC=0 #optional
- LIBPOD_GENERATE=0 #optional
- LIBPOD_IMAGES=0 #optional
- LIBPOD_INFO=0 #optional
- LIBPOD_MANIFESTS=0 #optional
- LIBPOD_NETWORKS=0 #optional
- LIBPOD_PING=1 #optional
- LIBPOD_PLAY=0 #optional
- LIBPOD_PODS=0 #optional
- LIBPOD_SECRETS=0 #optional
- LIBPOD_SYSTEM=0 #optional
- LIBPOD_VERSION=1 #optional
- LIBPOD_VOLUMES=0 #optional
volumes:
- /var/run/docker.sock:/var/run/docker.sock:ro
restart: unless-stopped
read_only: true
tmpfs:
- /run
```
### docker cli ([click here for more info](https://docs.docker.com/engine/reference/commandline/cli/))
```bash
docker run -d \
--name=socket-proxy \
-e ALLOW_ARCHIVE=0 `#optional` \
-e ALLOW_CHANGES=0 `#optional` \
-e ALLOW_EXPORT=0 `#optional` \
-e ALLOW_LOGS=0 `#optional` \
-e ALLOW_PAUSE=0 `#optional` \
-e ALLOW_RESTARTS=0 `#optional` \
-e ALLOW_STOP=0 `#optional` \
-e ALLOW_START=0 `#optional` \
-e ALLOW_TOP=0 `#optional` \
-e ALLOW_UNPAUSE=0 `#optional` \
-e AUTH=0 `#optional` \
-e BUILD=0 `#optional` \
-e COMMIT=0 `#optional` \
-e CONFIGS=0 `#optional` \
-e CONTAINERS=0 `#optional` \
-e DISTRIBUTION=0 `#optional` \
-e DISABLE_IPV6=0 `#optional` \
-e EVENTS=1 `#optional` \
-e EXEC=0 `#optional` \
-e IMAGES=0 `#optional` \
-e INFO=0 `#optional` \
-e LOG_LEVEL=info `#optional` \
-e NETWORKS=0 `#optional` \
-e NODES=0 `#optional` \
-e PING=1 `#optional` \
-e PLUGINS=0 `#optional` \
-e POST=0 `#optional` \
-e SECRETS=0 `#optional` \
-e SERVICES=0 `#optional` \
-e SESSION=0 `#optional` \
-e SWARM=0 `#optional` \
-e SYSTEM=0 `#optional` \
-e TASKS=0 `#optional` \
-e TZ=Etc/UTC `#optional` \
-e VERSION=1 `#optional` \
-e VOLUMES=0 `#optional` \
-e LIBPOD_CONTAINERS=0 `#optional` \
-e LIBPOD_EVENTS=0 `#optional` \
-e LIBPOD_EXEC=0 `#optional` \
-e LIBPOD_GENERATE=0 `#optional` \
-e LIBPOD_IMAGES=0 `#optional` \
-e LIBPOD_INFO=0 `#optional` \
-e LIBPOD_MANIFESTS=0 `#optional` \
-e LIBPOD_NETWORKS=0 `#optional` \
-e LIBPOD_PING=1 `#optional` \
-e LIBPOD_PLAY=0 `#optional` \
-e LIBPOD_PODS=0 `#optional` \
-e LIBPOD_SECRETS=0 `#optional` \
-e LIBPOD_SYSTEM=0 `#optional` \
-e LIBPOD_VERSION=1 `#optional` \
-e LIBPOD_VOLUMES=0 `#optional` \
-v /var/run/docker.sock:/var/run/docker.sock:ro \
--restart unless-stopped \
--read-only \
--tmpfs /run \
lscr.io/linuxserver/socket-proxy:latest
```
## Parameters
Containers are configured using parameters passed at runtime (such as those above). These parameters are separated by a colon and indicate `<external>:<internal>` respectively. For example, `-p 8080:80` would expose port `80` from inside the container to be accessible from the host's IP on port `8080` outside the container.
| Parameter | Function |
| :----: | --- |
| `-e ALLOW_ARCHIVE=0` | `(/libpod)?/(containers∣pods)/{id}/archive` |
| `-e AUTH=0` | `/auth` |
| `-e BUILD=0` | `/build` |
| `-e COMMIT=0` | `/commit` |
| `-e CONFIGS=0` | `/configs` |
| `-e CONTAINERS=0` | `/containers` |
| `-e DISTRIBUTION=0` | `/distribution` |
| `-e DISABLE_IPV6=0` | Set to `1` to prevent binding to the IPv6 interface for legacy systems that cannot support IPv6. |
| `-e EVENTS=1` | `/events` |
| `-e EXEC=0` | `/exec` & `/containers/{id}/exec` |
| `-e IMAGES=0` | `/images` |
| `-e INFO=0` | `/info` |
| `-e LOG_LEVEL=info` | Possible values are: `debug`, `info`, `notice`, `warning`, `err`, `crit`, `alert` and `emerg`. Defaults to `info`. |
| `-e NETWORKS=0` | `/networks` |
| `-e NODES=0` | `/nodes` |
| `-e PING=1` | `/_ping` |
| `-e PLUGINS=0` | `/plugins` |
| `-e POST=0` | When set to `0`, only `GET` and `HEAD` operations are allowed, making API access read-only. |
| `-e SECRETS=0` | `/secrets` |
| `-e SERVICES=0` | `/services` |
| `-e SESSION=0` | `/session` |
| `-e SWARM=0` | `/swarm` |
| `-e SYSTEM=0` | `/system` |
| `-e TASKS=0` | `/tasks` |
| `-e TZ=Etc/UTC` | `Set container timezone` |
| `-e VERSION=1` | `/version` |
| `-e VOLUMES=0` | `/volumes` |
| **Podman libpod API** | |
| `-e LIBPOD_CONTAINERS=0` | `/libpod/containers` |
| `-e LIBPOD_EVENTS=0` | `/libpod/events` |
| `-e LIBPOD_EXEC=0` | `/libpod/exec` |
| `-e LIBPOD_GENERATE=0` | `/libpod/generate` (systemd/kube YAML generation) |
| `-e LIBPOD_IMAGES=0` | `/libpod/images` |
| `-e LIBPOD_INFO=0` | `/libpod/info` |
| `-e LIBPOD_MANIFESTS=0` | `/libpod/manifests` |
| `-e LIBPOD_NETWORKS=0` | `/libpod/networks` |
| `-e LIBPOD_PING=1` | `/libpod/_ping` |
| `-e LIBPOD_PLAY=0` | `/libpod/play` (kube play) |
| `-e LIBPOD_PODS=0` | `/libpod/pods` (Podman-specific pod management) |
| `-e LIBPOD_SECRETS=0` | `/libpod/secrets` |
| `-e LIBPOD_SYSTEM=0` | `/libpod/system` |
| `-e LIBPOD_VERSION=1` | `/libpod/version` |
| `-e LIBPOD_VOLUMES=0` | `/libpod/volumes` |
| **These are `GET`-only options (they are not affected by the `POST` option)** | |
| `-e ALLOW_CHANGES=0` | `(/libpod)?/(containers∣pods)/{id}/changes` |
| `-e ALLOW_EXPORT=0` | `(/libpod)?/(containers∣pods)/{id}/export` |
| `-e ALLOW_LOGS=0` | `(/libpod)?/(containers∣pods)/{id}/logs` |
| `-e ALLOW_TOP=0` | `(/libpod)?/(containers∣pods)/{id}/top` |
| **These options work even when `POST=0`** | |
| `-e ALLOW_PAUSE=0` | `(/libpod)?/(containers∣pods)/{id}/pause` |
| `-e ALLOW_RESTARTS=0` | `(/libpod)?/(containers∣pods)/{id}/stop`, `(/libpod)?/(containers∣pods)/{id}/restart`, and `(/libpod)?/(containers∣pods)/{id}/kill` |
| `-e ALLOW_START=0` | `(/libpod)?/(containers∣pods)/{id}/start` |
| `-e ALLOW_STOP=0` | `(/libpod)?/(containers∣pods)/{id}/stop` |
| `-e ALLOW_UNPAUSE=0` | `(/libpod)?/(containers∣pods)/{id}/unpause` |
| `-v /var/run/docker.sock:ro` | Mount the host docker socket into the container. |
| `--read-only` | Make the container filesystem read-only. |
| `--tmpfs /run` | Mount /run to tmpfs (RAM) to make it writeable. |
## Support Info
* Shell access whilst the container is running:
```bash
docker exec -it socket-proxy /bin/sh
```
* To monitor the logs of the container in realtime:
```bash
docker logs -f socket-proxy
```
* Container version number:
```bash
docker inspect -f '{{ index .Config.Labels "build_version" }}' socket-proxy
```
* Image version number:
```bash
docker inspect -f '{{ index .Config.Labels "build_version" }}' lscr.io/linuxserver/socket-proxy:latest
```
## Updating Info
Most of our images are static, versioned, and require an image update and container recreation to update the app inside. With some exceptions (noted in the relevant readme.md), we do not recommend or support updating apps inside the container. Please consult the [Application Setup](#application-setup) section above to see if it is recommended for the image.
Below are the instructions for updating containers:
### Via Docker Compose
* Update images:
* All images:
```bash
docker compose pull
```
* Single image:
```bash
docker compose pull socket-proxy
```
* Update containers:
* All containers:
```bash
docker compose up -d
```
* Single container:
```bash
docker compose up -d socket-proxy
```
* You can also remove the old dangling images:
```bash
docker image prune
```
### Via Docker Run
* Update the image:
```bash
docker pull lscr.io/linuxserver/socket-proxy:latest
```
* Stop the running container:
```bash
docker stop socket-proxy
```
* Delete the container:
```bash
docker rm socket-proxy
```
* You can also remove the old dangling images:
```bash
docker image prune
```
### Image Update Notifications - Diun (Docker Image Update Notifier)
>[!TIP]
>We recommend [Diun](https://crazymax.dev/diun/) for update notifications. Other tools that automatically update containers unattended are not recommended or supported.
## Building locally
If you want to make local modifications to these images for development purposes or just to customize the logic:
```bash
git clone https://github.com/linuxserver/docker-socket-proxy.git
cd docker-socket-proxy
docker build \
--no-cache \
--pull \
-t lscr.io/linuxserver/socket-proxy:latest .
```
The ARM variants can be built on x86_64 hardware and vice versa using `lscr.io/linuxserver/docker-qemu-static`
```bash
docker run --rm --privileged lscr.io/linuxserver/docker-qemu-static --reset
```
Once registered you can define the dockerfile to use with `-f Dockerfile.aarch64`.
## Versions
* **18.08.26:** - Add `ALLOW_ARCHIVE`, `ALLOW_CHANGES`, `ALLOW_EXPORT`, `ALLOW_LOGS`, `ALLOW_TOP` options.
* **15.06.26:** - Rebase to Alpine 3.24.
* **13.06.26:** - Add libpod API support for Podman via `LIBPOD_*` environment variables.
* **24.02.26:** - Add `ALLOW_PAUSE` and `ALLOW_UNPAUSE`.
* **26.12.25:** - Rebase to Alpine 3.23.
* **19.08.25:** - Add tzdata for localised logging timestamps.
* **03.06.25:** - Rebase to Alpine 3.22. Add RISCV support.
* **08.04.25:** - Add `LOG_LEVEL` back.
* **06.04.25:** - Switch back to haproxy for better handling of `docker exec` connection hijacking.
* **02.01.25:** - Support custom read timeout values.
* **05.12.24:** - Rebase to Alpine 3.21.
* **26.08.24:** - Change `ALLOW_START`, `ALLOW_STOP`, and `ALLOW_RESTARTS` to work even with `POST=0`.
* **24.05.24:** - Rebase to Alpine 3.20.
* **15.04.24:** - Allow disabling IPv6 support for legacy devices.
* **08.04.24:** - Use nginx due to haproxy's wonky websockets handling.
* **07.04.24:** - Initial Release.
{%- endraw %}