mirror of
https://github.com/novatiq/packages.git
synced 2026-07-30 07:13:07 +01:00
docker-ce: add device option to expand interface blocking
If docker-ce handles the firewall and fw3 is not envolved because the rules get not proceed, then not only docker0 should be handled but also other interfaces and therefore other docker networks. This commit extends the handling and introduces a new uci option `device` in the docker config firewall section. This can be used to specify which device is allowed to access the container. Up to now only docker0 is covert. Signed-off-by: Florian Eckert <fe@dev.tdt.de>
This commit is contained in:
@@ -16,4 +16,5 @@ config globals 'globals'
|
||||
# Docker ignores fw3 rules and by default all external source IPs are allowed
|
||||
# to connect to the Docker host. See https://docs.docker.com/network/iptables/
|
||||
config firewall 'firewall'
|
||||
option device 'docker0'
|
||||
list blocked_interfaces 'wan'
|
||||
|
||||
Reference in New Issue
Block a user