Docker Compose网络通信疑问:容器内部通信是否需开放端口?Nextcloud+MariaDB+SWAG反向代理配置咨询
I'm setting up a Nextcloud Docker environment with MariaDB and SWAG (NGINX HTTPS proxy), and I want the containers to communicate within the Docker network. I know containers can access each other via service names. Currently, the SWAG reverse proxy needs to access the Nextcloud container's port 80. Can I just reference the container as app:80 in the NGINX config, or do I need additional configurations to ensure proper communication?
Here's the Docker Compose file I'll use:
version: "2" volumes: nextcloud: db: services: swag: image: ghcr.io/linuxserver/swag container_name: swag cap_add: - NET_ADMIN environment: - PUID=1000 - PGID=1000 - TZ=Europe/London - URL=secret - SUBDOMAINS=cloud, - VALIDATION=http - EMAIL=secret volumes: - /srv/swagdocker:/config ports: - 443:443 - 80:80 restart: unless-stopped db: image: mariadb restart: always command: --transaction-isolation=READ-COMMITTED --binlog-format=ROW volumes: - db:/var/lib/mysql environment: - MYSQL_ROOT_PASSWORD=secret - MYSQL_PASSWORD=secret - MYSQL_DATABASE=nextcloud - MYSQL_USER=nextcloud app: image: nextcloud restart: always links: - db volumes: - nextcloud:/var/www/html environment: - MYSQL_PASSWORD=secret - MYSQL_DATABASE=nextcloud - MYSQL_USER=nextcloud - MYSQL_HOST=db
Absolutely, using app:80 in your NGINX proxy configuration will work perfectly for SWAG to communicate with your Nextcloud container. Here’s a breakdown of why this works and the key checks/extra configs you should have in place:
Docker Network Auto-Resolution: When using Docker Compose (version 2+), all services defined in the same file are automatically added to a default custom bridge network. In this network, Docker’s built-in DNS resolver lets you use service names (like
app,db) as hostnames, which resolve directly to the container’s internal IP. Sohttp://app:80will correctly route traffic to the Nextcloud container’s exposed port 80.Verify Network Membership: Since all your services are in the same Compose file, they’ll share the default network automatically. If you ever split services into separate files or use custom networks, just make sure
swagandappare attached to the same network (you’d add anetworkssection to each service and define the network at the top of the Compose file).SWAG NGINX Config Setup:
- When you set up SWAG, it should generate a Nextcloud proxy config (usually at
/config/nginx/proxy-confs/nextcloud.subdomain.confif you used thecloudsubdomain). Open this file and confirm theproxy_passline looks like:proxy_pass http://app:80; - Ensure other proxy settings (like
proxy_set_header Host $host;,proxy_set_header X-Real-IP $remote_addr;) are present—these are usually included in the default SWAG configs, but double-check to avoid issues with Nextcloud’s security checks.
- When you set up SWAG, it should generate a Nextcloud proxy config (usually at
Nextcloud Trusted Domains: You need to tell Nextcloud that your domain (e.g.,
cloud.yourdomain.com) is a trusted source. You can do this in two ways:- Add an environment variable to the
appservice in your Compose file:environment: - TRUSTED_DOMAINS=cloud.yourdomain.com localhost 127.0.0.1 - Edit Nextcloud’s
config/config.phpfile (in yournextcloudvolume) and add your domain to thetrusted_domainsarray:'trusted_domains' => [ 0 => 'localhost', 1 => 'cloud.yourdomain.com', ],
Without this, Nextcloud will block requests from SWAG, throwing a "Access through untrusted domain" error.
- Add an environment variable to the
Minor Cleanup Note: In Docker Compose v2+, the
linksdirective is largely unnecessary—services can already communicate via service names without it. You can safely remove thelinks: -dbline from theappservice if you want; theMYSQL_HOST=dbenvironment variable will still work perfectly.
Once these steps are done, your SWAG proxy should successfully route HTTPS traffic to your Nextcloud container over the internal Docker network.
内容的提问来源于stack exchange,提问作者CruZer0

