Skip to content

Bind dev and local Postgres, Redis and app ports to loopback only #414

Description

@HMarzban

Summary

The dev and local compose files publish Postgres and Redis on 0.0.0.0. Postgres uses a default password when DB_PASSWORD is unset, and Redis has no auth. On a laptop on shared Wi-Fi, or a dev VM with a public IP, anyone on the network can reach both. Production is not affected: self-host docs use docker-compose.prod.yml.

  • Severity: Low (developer machines only)
  • Area: compose files, Makefile
  • Source: security review of 2026-10-06

Where

  • docker-compose.dev.yml:32 — '${DB_PORT:-5432}:5432'; :29 — POSTGRES_PASSWORD: ${DB_PASSWORD:-CHANGE_ME_STRONG_PASSWORD}
  • docker-compose.dev.yml:53 — '${REDIS_PORT:-6379}:6379'
  • docker-compose.local.yml:27 (Postgres), :24 (default password), :48 (Redis)
  • App ports also bind on all interfaces: docker-compose.dev.yml:82,155,216,287 and docker-compose.backend-local.override.yml:15,21,27 (used by Makefile:95).

Fix plan

  1. Prefix every published port with 127.0.0.1:, for example '127.0.0.1:${DB_PORT:-5432}:5432'.
  2. Apply the same to the app ports (4000, 4001, 4002, 3000) in the dev and local override files.
  3. If a developer needs LAN access (phone testing), document a BIND_HOST variable, for example '${BIND_HOST:-127.0.0.1}:4000:4000'.
  4. Optionally make the dev Postgres refuse to start without DB_PASSWORD (${DB_PASSWORD:?set DB_PASSWORD}).

Acceptance criteria

  • docker compose -f docker-compose.dev.yml up then ss -ltn shows 5432 and 6379 on 127.0.0.1 only.
  • make targets that use these files still work locally.
  • Containers still reach each other by service name.

Generated by Claude Code

Activity

  1. added theissue type on Oct 6, 2026
  2. changed the title [-]Dev and local compose files publish Postgres and Redis on all network interfaces[/-] [+]Bind dev and local Postgres, Redis and app ports to loopback only[/+] on Oct 6, 2026
  3. added
    SecuritySecurity, access control, and data exposure
    and removed
    bugSomething isn't working
    on Oct 6, 2026
  4. HMarzban commented on Oct 6, 2026

    @HMarzban
    CollaboratorAuthor

    Status: fixed in 0a09b5d on claude/youthful-lovelace-3nvsc6. Not merged yet.

    What shipped: every published port in docker-compose.dev.yml, docker-compose.local.yml and docker-compose.backend-local.override.yml now binds to 127.0.0.1. That covers 5432, 6379, 4000, 4001, 4002 and 3000. It also covers the dev admin dashboard on ${ADMIN_PORT:-3100}, which this issue did not list. docker-compose.prod.yml is unchanged.

    Not done: step 3 (BIND_HOST) and step 4 (a required DB_PASSWORD). Both were optional. To test from a phone on the LAN, edit the port line on your machine only.

    Verify: run docker compose -f docker-compose.dev.yml up, then ss -ltn. Every published port must show 127.0.0.1.


    Generated by Claude Code

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    DevOpsSecuritySecurity, access control, and data exposure

    Type

    Projects

    No projects

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions