安装CSF防火墙后Docker容器本地连接异常求助
问题场景与现象
- 服务器运行WHM,已安装Docker并部署listmonk,容器状态正常:
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES 0eb46a14e3c2 listmonk/listmonk:latest "./listmonk" 20 hours ago Up 9 minutes 0.0.0.0:9000->9000/tcp, :::9000->9000/tcp listmonk_app 43b308157ebe postgres:13-alpine "docker-entrypoint.s…" 20 hours ago Up 9 minutes (healthy) 0.0.0.0:9432->5432/tcp, :::9432->5432/tcp listmonk_db
- 原本通过Cloudflare Tunnel实现
https://listmonk.ygprodeck.com访问http://localhost:9000正常,安装ConfigServer Security and Firewall(CSF)后,因未将9000端口加入TCP_IN/TCP_OUT(需求为不暴露端口),导致Cloudflare Tunnel连接容器超时。 - 服务器本地执行
curl -v http://127.0.0.1:9000报错:
* Rebuilt URL to: http://127.0.0.1:9000/ * Trying 127.0.0.1... * TCP_NODELAY set * Connected to 127.0.0.1 (127.0.0.1) port 9000 (#0) > GET / HTTP/1.1 > Host: 127.0.0.1:9000 > User-Agent: curl/7.61.1 > Accept: */* > * Recv failure: Connection reset by peer * Closing connection 0 curl: (56) Recv failure: Connection reset by peer
已尝试的无效方案
- 禁用CSF可解决问题,但会暴露端口,不符合需求;
- 尝试Apache反向代理,出现相同连接重置问题;
- 将
docker0加入ETH_DEVICE_SKIP,但会把9000端口暴露给公网,不可行。
配置文件信息
采用listmonk官方生产环境安装方式,相关配置如下:
docker-compose.yml
version: "3.7" x-app-defaults: &app-defaults restart: unless-stopped image: listmonk/listmonk:latest ports: - "9000:9000" networks: - listmonk environment: - TZ=Etc/UTC x-db-defaults: &db-defaults image: postgres:13-alpine ports: networks: - listmonk environment: - POSTGRES_PASSWORD=<REMOVED> - POSTGRES_USER=<REMOVED> - POSTGRES_DB=<REMOVED> restart: unless-stopped healthcheck: test: ["CMD-SHELL", "pg_isready -U listmonk"] interval: 10s timeout: 5s retries: 6 services: db: <<: *db-defaults container_name: listmonk_db volumes: - type: volume source: listmonk-data target: /var/lib/postgresql/data app: <<: *app-defaults container_name: listmonk_app depends_on: - db volumes: - ./config.toml:/listmonk/config.toml demo-db: container_name: listmonk_demo_db <<: *db-defaults demo-app: <<: *app-defaults container_name: listmonk_demo_app command: [sh, -c, "yes | ./listmonk --install --config config-demo.toml && ./listmonk --config config-demo.toml"] depends_on: - demo-db networks: listmonk: volumes: listmonk-data:
config.toml
[app] # Interface and port where the app will run its webserver. The default value # of localhost will only listen to connections from the current machine. To # listen on all interfaces use '0.0.0.0'. To listen on the default web address # port, use port 80 (this will require running with elevated permissions). address = "0.0.0.0:9000" # BasicAuth authentication for the admin dashboard. This will eventually # be replaced with a better multi-user, role-based authentication system. # IMPORTANT: Leave both values empty to disable authentication on admin # only where an external authentication is already setup. admin_username = "<REMOVED>" admin_password = "<REMOVED>" # Database. [db] host = "listmonk_db" port = 5432 user = "<REMOVED>" password = "<REMOVED>" # Ensure that this database has been created in Postgres. database = "listmonk" ssl_mode = "disable" max_open = 25 max_idle = 25 max_lifetime = "300s" # Optional space separated Postgres DSN params. eg: "application_name=listmonk gssencmode=disable" params = ""
内容的提问来源于stack exchange,提问作者GenesisBits
相关产品推荐
相关产品推荐

