File tree Expand file tree Collapse file tree 4 files changed +4
-0
lines changed
Expand file tree Collapse file tree 4 files changed +4
-0
lines changed Original file line number Diff line number Diff line change @@ -10,6 +10,7 @@ ENV ALLOW_RESTARTS=0 \
1010 DISTRIBUTION=0 \
1111 EVENTS=1 \
1212 EXEC=0 \
13+ GRPC=0 \
1314 IMAGES=0 \
1415 INFO=0 \
1516 LOG_LEVEL=info \
Original file line number Diff line number Diff line change @@ -127,6 +127,7 @@ extremely critical but can expose some information that your service does not ne
127127- ` CONTAINERS `
128128- ` DISTRIBUTION `
129129- ` EXEC `
130+ - ` GRPC `
130131- ` IMAGES `
131132- ` INFO `
132133- ` NETWORKS `
Original file line number Diff line number Diff line change @@ -51,6 +51,7 @@ frontend dockerfrontend
5151 http-request allow if { path,url_dec -m reg -i ^(/v[\ d\ .]+)?/distribution } { env(DISTRIBUTION) -m bool }
5252 http-request allow if { path,url_dec -m reg -i ^(/v[\ d\ .]+)?/events } { env(EVENTS) -m bool }
5353 http-request allow if { path,url_dec -m reg -i ^(/v[\ d\ .]+)?/exec } { env(EXEC) -m bool }
54+ http-request allow if { path,url_dec -m reg -i ^(/v[\ d\ .]+)?/grpc } { env(GRPC) -m bool }
5455 http-request allow if { path,url_dec -m reg -i ^(/v[\ d\ .]+)?/images } { env(IMAGES) -m bool }
5556 http-request allow if { path,url_dec -m reg -i ^(/v[\ d\ .]+)?/info } { env(INFO) -m bool }
5657 http-request allow if { path,url_dec -m reg -i ^(/v[\ d\ .]+)?/networks } { env(NETWORKS) -m bool }
Original file line number Diff line number Diff line change @@ -34,6 +34,7 @@ def test_default_permissions(proxy_factory):
3434 ("info" ,),
3535 ("system" , "info" ),
3636 ("build" , "." ),
37+ ("buildx build" , "." ),
3738 ("swarm" , "init" ),
3839 )
3940 _check_permissions (allowed_calls , forbidden_calls )
You can’t perform that action at this time.
0 commit comments