Skip to content

fix: publish the db and app ports on loopback only

isidro requested to merge fix/bind-loopback-ports into main

Summary

  • db: 5433:5432 → 127.0.0.1:5433:5432. Postgres with the default credentials was reachable from the home Wi-Fi and the tailnet (checked with nc -z from the MacBook).
  • app: drop the 8788:8788 publish. The native launchd portal already holds 127.0.0.1:8788 and reaches the container on 127.0.0.1:8792, so the wildcard publish only served LAN/tailnet clients, bypassing Cloudflare Access.

Part of the Mac mini security review (Mac-mini-Ops, docs/seguridad-2026-09.md).

Test plan

  • CI green
  • After merge: docker compose up -d db app, then lsof -nP -iTCP:5433 -sTCP:LISTEN shows only 127.0.0.1
  • https://studio.doctrinestrike.com still redirects to Access; portal on 127.0.0.1:8788 answers; 127.0.0.1:8792 answers

🤖 Generated with Claude Code

https://claude.ai/code/session_01G4n469m8dAMJZ37Z5dxYoE

Merge request reports