Skip to content

Bind the APTL DNS host port to loopback by default #1004

Description

@Brad-Edwards

Problem

The dns service publishes ${APTL_DNS_HOST_PORT:-5353} without a host IP, so Docker binds TCP and UDP port 5353 on every host interface. This was observed live as 0.0.0.0:5353->53/tcp and 0.0.0.0:5353->53/udp.

This is a host-side service surface, not intentional scenario attack surface. Relying only on a host firewall is fragile because Docker manages its own packet-filtering rules for published ports.

Expected behavior

Bind the DNS host publication to loopback by default:

- "127.0.0.1:${APTL_DNS_HOST_PORT:-5353}:53/tcp"
- "127.0.0.1:${APTL_DNS_HOST_PORT:-5353}:53/udp"

If non-loopback DNS access is required, make it an explicit, documented opt-in.

Acceptance criteria

  • The default TCP and UDP host publications bind to 127.0.0.1.
  • Existing local endpoint discovery and lab workflows continue to work.
  • Tests verify the rendered Compose/runtime host bindings for both protocols.
  • Any supported non-loopback mode is explicit and documented with its security implications.

Activity

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    blockedBlocked on an external/upstream dependency

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions