services: # Docker Socket Proxy - Security Enchanced Proxy for Docker Socket socket-proxy: container_name: socket-proxy image: lscr.io/linuxserver/socket-proxy:latest restart: unless-stopped ports: - "2375:2375" # Do not expose this to the internet with port forwarding environment: ## Variables match the URL prefix (i.e. AUTH blocks access to /auth/* parts of the API, etc.). # 0 to revoke access. # 1 to grant access. ## Granted by Default - EVENTS=1 - PING=1 - VERSION=1 ## Revoked by Default # Security critical - AUTH=0 - SECRETS=0 - POST=1 # Portainer and Watchtower # Not always needed - BUILD=0 - COMMIT=0 - CONFIGS=0 - CONTAINERS=1 # Traefik, Portainer, etc. - DISTRIBUTION=0 - EXEC=0 - IMAGES=1 # Portainer - INFO=1 # Portainer - NETWORKS=1 # Portainer - NODES=0 - PLUGINS=0 - SERVICES=1 # Portainer - SESSION=0 - SWARM=0 - SYSTEM=0 - TASKS=1 # Portainer - VOLUMES=1 # Portainer volumes: - "/var/run/docker.sock:/var/run/docker.sock:ro" networks: back_network_diun: back_network_socket_proxy: ipv4_address: 192.168.91.254 # Static IP labels: - "diun.enable=true" read_only: true tmpfs: - /run security_opt: - no-new-privileges:true