You need to enable JavaScript to run this app.
优惠活动
大模型
产品
解决方案
定价
更多

如何向私有容器网络暴露带认证的Docker TCP API供容器调用?

Great question—mounting the Docker socket directly is quick but comes with big security red flags, so switching to a TLS-authenticated TCP endpoint restricted to your private network is a smart move. Let's walk through exactly how to set this up, step by step.

Step 1: Configure Docker Daemon for TLS-Authenticated TCP (Private IP Only)

First, we need to enable TLS authentication (unauthenticated TCP is extremely risky) and configure Docker to listen only on your private network IP.

Generate TLS Certificates

We'll use OpenSSL to create a CA, server, and client certificate set for secure communication:

# Create a dedicated directory for certs
mkdir -p /etc/docker/certs && cd /etc/docker/certs

# Generate CA key and certificate (set a strong passphrase when prompted)
openssl genrsa -aes256 -out ca-key.pem 4096
openssl req -new -x509 -days 365 -key ca-key.pem -sha256 -out ca.pem

# Generate server key and signing request
openssl genrsa -out server-key.pem 4096
# Replace "your-internal-private-ip" with your Docker host's private IP (or internal domain)
openssl req -subj "/CN=your-internal-private-ip" -sha256 -new -key server-key.pem -out server.csr

# Sign the server certificate with your CA
openssl x509 -req -days 365 -sha256 -in server.csr -CA ca.pem -CAkey ca-key.pem -CAcreateserial -out server-cert.pem

# Generate client key and signing request
openssl genrsa -out key.pem 4096
openssl req -subj "/CN=client" -new -key key.pem -out client.csr

# Sign client certificate for authentication
echo extendedKeyUsage = clientAuth > extfile.cnf
openssl x509 -req -days 365 -sha256 -in client.csr -CA ca.pem -CAkey ca-key.pem -CAcreateserial -out cert.pem -extfile extfile.cnf

# Lock down permissions (critical for security)
chmod 0400 ca-key.pem server-key.pem key.pem
chmod 0444 ca.pem server-cert.pem cert.pem

Update Docker Daemon Configuration

Edit /etc/docker/daemon.json to set up the private TCP listener and TLS settings:

{
  "hosts": ["unix:///var/run/docker.sock", "tcp://your-internal-private-ip:2376"],
  "tls": true,
  "tlscacert": "/etc/docker/certs/ca.pem",
  "tlscert": "/etc/docker/certs/server-cert.pem",
  "tlskey": "/etc/docker/certs/server-key.pem",
  "tlsverify": true
}
  • Replace your-internal-private-ip with your Docker host's private IP (e.g., 192.168.1.50 or your private container network's gateway IP)
  • The unix:// socket remains for local host use, while the tcp:// endpoint is restricted to your private IP

Important Note: If you use systemd to manage Docker, remove any -H flags from the ExecStart line in /lib/systemd/system/docker.service (or a custom override file). The hosts field in daemon.json takes precedence, and conflicting settings will break Docker. Run systemctl daemon-reload after making changes.

Restart Docker and Verify

systemctl restart docker
# Check that Docker is listening on your private IP:2376
ss -tulpn | grep docker

You should see a line like LISTEN 0 4096 your-internal-private-ip:2376 0.0.0.0:* users:(("dockerd",pid=XXXX,fd=X))

Step 2: Lock Access to Your Private Network Only

Even with TLS, we need to ensure external traffic can't reach the TCP socket. Use firewall rules to restrict access to your private subnet:

For iptables:

# Allow traffic from your private subnet (replace 192.168.1.0/24 with your actual range)
iptables -A INPUT -p tcp -s 192.168.1.0/24 --dport 2376 -j ACCEPT
# Block all other traffic to port 2376
iptables -A INPUT -p tcp --dport 2376 -j DROP

For UFW (Ubuntu/Debian):

ufw allow from 192.168.1.0/24 to any port 2376
ufw deny 2376
Step 3: Make Docker API Available to Private Containers

Now let your target containers access the authenticated API. Here are two reliable methods:

Option 1: Attach Containers to a Custom Private Network

Create a dedicated private network (recommended for isolation) and attach your containers to it:

# Create a custom private network (adjust subnet as needed)
docker network create --driver bridge --subnet 192.168.200.0/24 private-docker-net

Run your container with mounted TLS certs and environment variables pointing to the private API:

docker run -d \
  --name docker-controller \
  --network private-docker-net \
  # Mount certs as read-only to prevent modification
  -v /etc/docker/certs:/certs:ro \
  -e DOCKER_TLS_VERIFY=1 \
  -e DOCKER_CERT_PATH=/certs \
  -e DOCKER_HOST=tcp://your-internal-private-ip:2376 \
  your-container-image

The container will use the TLS certs to authenticate, and since it's on the same private network, it can reach the Docker host's private IP.

Option 2: Use host.docker.internal (Docker Desktop/Modern Docker)

If you're running Docker Desktop or have enabled the internal DNS entry, you can use host.docker.internal instead of the raw private IP:

docker run -d \
  --name docker-controller \
  -v /etc/docker/certs:/certs:ro \
  -e DOCKER_TLS_VERIFY=1 \
  -e DOCKER_CERT_PATH=/certs \
  -e DOCKER_HOST=tcp://host.docker.internal:2376 \
  your-container-image

This resolves to the Docker host's IP automatically from within containers.

Key Security Reminders
  • Never expose an unauthenticated TCP socket (tcp://0.0.0.0:2375)—this is a critical security vulnerability
  • Rotate your TLS certificates every 6-12 months
  • Only grant access to trusted containers/IPs via firewall rules
  • Keep certs mounted as read-only in containers to prevent tampering

内容的提问来源于stack exchange,提问作者xenoterracide

相关产品推荐
方舟 Agent Plan

超全模态模型 × Harness 升级,最新支持 Deepseek-V4.1-Flash、GLM-5.3 系列、Doubao-Seedream-5.0-pro、Kimi-K3 (部分), 限时 9.9 元起

最近更新时间:2026.05.19 07:24:57