tux7350

joined 2 years ago
[–] tux7350@lemmy.world 5 points 1 week ago

Course, feel free to DM if you have questions.

This is a common setup. Have a firewall block all traffic. Use docker to punch a hole through the firewall and expose only 443 to the reverse proxy. Now any container can be routed through the reverse proxy as long as the container is on the same docker network.

If you define no network, the containers are put into a default bridge network, use docker inspect to see the container ips.

Here is an example of how to define a custom docker network called "proxy_net" and statically set each container ip.

networks:
  proxy_net:
    driver: bridge
    ipam:
      config:
        - subnet: 172.28.0.0/16

services:
  app1:
    image: nginx:latest
    container_name: app1
    networks:
      proxy_net:
        ipv4_address: 172.28.0.10
    ports:
      - "8080:80"

  whoami:
    image: containous/whoami:latest
    container_name: whoami
    networks:
      proxy_net:
        ipv4_address: 172.28.0.11

Notice how "who am I" is not exposed at all. The nginx container can now serve the whoami container with the proper config, pointing at 172.28.0.11.

[–] tux7350@lemmy.world 7 points 1 week ago (2 children)

Well if your reverse proxy is also inside of a container, you dont need to expose the port at all. As long as the containers are in the same docker network then they can communicate.

If your reverse proxy is not inside a docker container, then yes this method would work to prevent clients from connecting to a docker container.

[–] tux7350@lemmy.world 12 points 1 week ago (4 children)

Something like this. This is a compose.yml that only allows ips from the local host 8080 to connect to the container port 80.

services:
  webapp:
    image: nginx:latest
    container_name: local_nginx
    ports:
      - "127.0.0.1:8080:80"
[–] tux7350@lemmy.world 2 points 3 weeks ago (1 children)

You might be thinking of one of the main characters, Edward. Her character has a masculine name but is drawn pretty androgynous, but by all accounts she identifies as a girl. Pretty progressive for the time that it was released. There was also a scene with a posititue in drag.

I think that scene is in the Cowboy Bebop movie. Edward goes trick or treating and knocks on the door of a prostitute in drag. The prostitute then confuses Edward for being a little boy and gets mad saying when they realize Edward is a girl.

[–] tux7350@lemmy.world 16 points 3 weeks ago

Excuse me have you heard about our lord and savior, NixOS?

[–] tux7350@lemmy.world 2 points 1 month ago

Big Bear is such an under rated part of southern California. I loved going there and looking at the giant pinecone. I never realized housing wasn't too bad out that way. How are the taxes?

[–] tux7350@lemmy.world 4 points 1 month ago* (last edited 1 month ago)

Ooo I do love me some Nix modules. Any particular options to look out for in order to configure something like that?

Edit:

It's programs.chromium.extraOpts isnt it? Lol

[–] tux7350@lemmy.world 3 points 1 month ago (1 children)

How do you manage your images in Nix? Ive got a bunch of docker compose files and want to migrate over but havent had the time to sink.

[–] tux7350@lemmy.world 2 points 2 months ago

Kind of a weird thought, but wouldnt a uni benefit from holding so many IP forcing people to use NAT. Then the offer classes and provide degrees in networking to deal with NAT......

excuse me, ill put my tin foil hat down XD

[–] tux7350@lemmy.world 3 points 2 months ago (1 children)

People are going to get cranky when you go around telling people how to speak "more proper and understandable". Who the fuck are you? Lol get outta here with that bull shit

[–] tux7350@lemmy.world 2 points 3 months ago (1 children)

Hmm these are some pretty cool features I'd be interested in. I currently use Voyager for lemmy and quite like the layout. Does Piefed have any good mobile clients? Is there something you'd recommend?

view more: next ›