Problem
The dns service publishes ${APTL_DNS_HOST_PORT:-5353} without a host IP, so Docker binds TCP and UDP port 5353 on every host interface. This was observed live as 0.0.0.0:5353->53/tcp and 0.0.0.0:5353->53/udp.
This is a host-side service surface, not intentional scenario attack surface. Relying only on a host firewall is fragile because Docker manages its own packet-filtering rules for published ports.
Expected behavior
Bind the DNS host publication to loopback by default:
- "127.0.0.1:${APTL_DNS_HOST_PORT:-5353}:53/tcp"
- "127.0.0.1:${APTL_DNS_HOST_PORT:-5353}:53/udp"
If non-loopback DNS access is required, make it an explicit, documented opt-in.
Acceptance criteria
- The default TCP and UDP host publications bind to
127.0.0.1.
- Existing local endpoint discovery and lab workflows continue to work.
- Tests verify the rendered Compose/runtime host bindings for both protocols.
- Any supported non-loopback mode is explicit and documented with its security implications.
Problem
The
dnsservice publishes${APTL_DNS_HOST_PORT:-5353}without a host IP, so Docker binds TCP and UDP port 5353 on every host interface. This was observed live as0.0.0.0:5353->53/tcpand0.0.0.0:5353->53/udp.This is a host-side service surface, not intentional scenario attack surface. Relying only on a host firewall is fragile because Docker manages its own packet-filtering rules for published ports.
Expected behavior
Bind the DNS host publication to loopback by default:
If non-loopback DNS access is required, make it an explicit, documented opt-in.
Acceptance criteria
127.0.0.1.