mirror of
https://github.com/novatiq/packages.git
synced 2026-07-29 23:03:06 +01:00
docker-ce: Added blocked_interfaces config option
* blocked_interfaces blocks all packets to docker0 from the given interface. This is needed because all the iptables commands dockerd adds operate before any of the fw3 generated rules. Signed-off-by: Gerard Ryan <G.M0N3Y.2503@gmail.com>
This commit is contained in:
@@ -1,11 +1,18 @@
|
||||
# The following settings require a restart to take full effect, A reload will
|
||||
# only have partial or no effect:
|
||||
# option bip
|
||||
# list blocked_interfaces
|
||||
|
||||
config globals 'globals'
|
||||
# option alt_config_file "/etc/docker/daemon.json"
|
||||
option data_root "/opt/docker/"
|
||||
option log_level "warn"
|
||||
list hosts "unix:///var/run/docker.sock"
|
||||
# If the bip option is changed, dockerd must be restarted.
|
||||
# A service reload is not enough.
|
||||
option bip "172.18.0.1/24"
|
||||
# list registry_mirrors "https://<my-docker-mirror-host>"
|
||||
# list registry_mirrors "https://hub.docker.com"
|
||||
|
||||
# Docker ignores fw3 rules and by default all external source IPs are allowed
|
||||
# to connect to the Docker host. See https://docs.docker.com/network/iptables/
|
||||
config firewall 'firewall'
|
||||
list blocked_interfaces 'wan'
|
||||
|
||||
Reference in New Issue
Block a user