Summary
The dev and local compose files publish Postgres and Redis on 0.0.0.0. Postgres uses a default password when DB_PASSWORD is unset, and Redis has no auth. On a laptop on shared Wi-Fi, or a dev VM with a public IP, anyone on the network can reach both. Production is not affected: self-host docs use docker-compose.prod.yml.
- Severity: Low (developer machines only)
- Area: compose files,
Makefile
- Source: security review of 2026-10-06
Where
docker-compose.dev.yml:32 — '${DB_PORT:-5432}:5432'; :29 — POSTGRES_PASSWORD: ${DB_PASSWORD:-CHANGE_ME_STRONG_PASSWORD}
docker-compose.dev.yml:53 — '${REDIS_PORT:-6379}:6379'
docker-compose.local.yml:27 (Postgres), :24 (default password), :48 (Redis)
- App ports also bind on all interfaces:
docker-compose.dev.yml:82,155,216,287 and docker-compose.backend-local.override.yml:15,21,27 (used by Makefile:95).
Fix plan
- Prefix every published port with
127.0.0.1:, for example '127.0.0.1:${DB_PORT:-5432}:5432'.
- Apply the same to the app ports (4000, 4001, 4002, 3000) in the dev and local override files.
- If a developer needs LAN access (phone testing), document a
BIND_HOST variable, for example '${BIND_HOST:-127.0.0.1}:4000:4000'.
- Optionally make the dev Postgres refuse to start without
DB_PASSWORD (${DB_PASSWORD:?set DB_PASSWORD}).
Acceptance criteria
Generated by Claude Code
Summary
The dev and local compose files publish Postgres and Redis on
0.0.0.0. Postgres uses a default password whenDB_PASSWORDis unset, and Redis has no auth. On a laptop on shared Wi-Fi, or a dev VM with a public IP, anyone on the network can reach both. Production is not affected: self-host docs usedocker-compose.prod.yml.MakefileWhere
docker-compose.dev.yml:32—'${DB_PORT:-5432}:5432';:29—POSTGRES_PASSWORD: ${DB_PASSWORD:-CHANGE_ME_STRONG_PASSWORD}docker-compose.dev.yml:53—'${REDIS_PORT:-6379}:6379'docker-compose.local.yml:27(Postgres),:24(default password),:48(Redis)docker-compose.dev.yml:82,155,216,287anddocker-compose.backend-local.override.yml:15,21,27(used byMakefile:95).Fix plan
127.0.0.1:, for example'127.0.0.1:${DB_PORT:-5432}:5432'.BIND_HOSTvariable, for example'${BIND_HOST:-127.0.0.1}:4000:4000'.DB_PASSWORD(${DB_PASSWORD:?set DB_PASSWORD}).Acceptance criteria
docker compose -f docker-compose.dev.yml upthenss -ltnshows 5432 and 6379 on127.0.0.1only.maketargets that use these files still work locally.Generated by Claude Code