docker compose: restrict internet access

Viewed 249

I want to run with a container that is a copy of a production container, so I want to restrict access to the internet to prevent that call production servers. But I need to access the container from the host machine with internet access

This is what I am trying to do:

version: '2.1'
services:

  proxy:
    image: traefik
    command: --api.insecure=true --providers.docker
    networks:
      - no-internet
      - internet
    ports:
      - "80:80"
      - "8080:8080"
    volumes:
      - /var/run/docker.sock:/var/run/docker.sock


  prod-service:
    image: ....
    depends_on:
      - db
    ports:
     - "8094:8094"
    labels:
      - "traefik.http.routers.blog.rule=Host(`localhost`)"
      - "traefik.port=8094"
    networks:
     - no-internet


  db:
    container_name: db
    image: postgres:11
    hostname: ap-db
    expose:
     - 5433
    ports:
     - 5433:5432
    environment:
     - POSTGRES_USER=postgres
     - POSTGRES_PASSWORD=postgres
    networks:
     - no-internet
     - internet

networks:
  internet:
    driver: bridge
  no-internet:
    internal: true
    driver: bridge

But the trafic configuration is not working for me.

What is the best option to do this? the answers I found do not take into account the access from the host machine, the container without internet is isolated

I appreciate any advice

0 Answers
Related