Docker Compose中Dante SOCKS v5无认证转发AMQP消息的技术问题
Hey there! Let's tackle your questions and fix this issue step by step.
1. Is using Dante as an unauthenticated SOCKS5 proxy for AMQP traffic via Docker Compose feasible?
Absolutely! SOCKS5 proxies handle TCP traffic forwarding regardless of the upper-layer protocol, and AMQP runs over TCP. As long as your proxy and client configurations are set correctly, this setup will work perfectly for routing your producer's AMQP messages to RabbitMQ.
2. How to fix the authentication issue and get the setup working?
Your current problem stems from the default configuration of the wernight/dante image, which enables PAM system authentication by default. Here's what's happening:
- The producer container runs as
root(its default user), and Java's SOCKS client tries to use this OS user for proxy authentication. - The Dante container doesn't recognize the
rootuser from your producer container, so authentication fails. - Even though you set
-Djava.net.socks.username/password, these parameters are for SOCKS5's built-in username/password auth, which doesn't align with Dante's default PAM system auth.
To set up an unauthenticated SOCKS5 proxy, follow these steps:
Step 1: Create a custom Dante configuration
Make a sockd.conf file with the following content to disable authentication:
logoutput: stderr internal: 0.0.0.0 port = 1080 external: eth0 # Disable authentication for clients and proxy connections clientmethod: none socksmethod: none user.privileged: root user.unprivileged: nobody # Allow all client connections client pass { from: 0.0.0.0/0 to: 0.0.0.0/0 log: error connect disconnect } # Allow all proxy traffic forwarding socks pass { from: 0.0.0.0/0 to: 0.0.0.0/0 log: error connect disconnect }
Step 2: Update your Docker Compose file
Mount the custom config to the Dante service, and adjust the producer's Java options to remove unnecessary auth parameters:
services: dante: image: wernight/dante volumes: - ./sockd.conf:/etc/sockd.conf # Mount your custom config networks: - proxy-network rabbitmq: image: rabbitmq:3-management networks: - proxy-network # Add your RabbitMQ environment vars/ports here producer: build: ./your-producer-directory environment: # Only set proxy host/port - no auth params needed JAVA_OPTS: "-DsocksProxyHost=dante -DsocksProxyPort=1080" networks: - proxy-network # Add your producer's build/run config here networks: proxy-network: driver: bridge
Step 3: Verify the setup
- Start your stack with
docker-compose up -d- Check Dante logs:
docker-compose logs danteshould show no authentication errors, just connection/disconnect logs. - Check producer logs: You should see successful proxy connections and AMQP message delivery to RabbitMQ.
- Check Dante logs:
- You can test the proxy directly from the producer container with:
This should return the RabbitMQ management UI HTML if you have it enabled, confirming the proxy is routing traffic correctly.docker-compose exec producer curl --socks5 dante:1080 http://rabbitmq:15672
内容的提问来源于stack exchange,提问作者Daniel Figueroa

