fix: scope headless-shell to a dedicated network, off the Traefik proxy network
Prod override put headless-shell on the externally-managed `proxy` network so manga-api (confined there for Traefik routing) could still resolve it. That reopened CDP (port 9222, raw remote code execution) to every other container on that shared network, not just manga-api. Give both services a project-private `browser` network (defined in the base compose file, not `internal: true` since headless Chrome needs outbound access to kagane.to). manga-api joins both `proxy` and `browser` in the prod override; headless-shell never touches `proxy`.
This commit is contained in:
+11
-1
@@ -45,6 +45,8 @@ services:
|
||||
# the public internet does not.
|
||||
ports:
|
||||
- "127.0.0.1:8080:8080"
|
||||
networks:
|
||||
- browser
|
||||
|
||||
headless-shell:
|
||||
image: chromedp/headless-shell:stable
|
||||
@@ -55,12 +57,20 @@ services:
|
||||
# container's lifetime.
|
||||
init: true
|
||||
# Deliberately no `ports:` — an exposed CDP endpoint is remote code
|
||||
# execution. Only the backend on the internal network may reach it.
|
||||
# execution. Only manga-api, via the `browser` network below, may reach it.
|
||||
command:
|
||||
- --remote-debugging-address=0.0.0.0
|
||||
- --remote-debugging-port=9222
|
||||
- --disable-gpu
|
||||
- --no-sandbox
|
||||
networks:
|
||||
- browser
|
||||
|
||||
volumes:
|
||||
bookmarks-data:
|
||||
|
||||
networks:
|
||||
# Not `internal: true`: headless Chrome still needs outbound access to reach
|
||||
# kagane.to. Isolation here comes from membership (only manga-api and
|
||||
# headless-shell join it), not from cutting egress.
|
||||
browser:
|
||||
|
||||
Reference in New Issue
Block a user