Skip to content
This repository has been archived by the owner on Jun 20, 2024. It is now read-only.

Bind router HTTP listener to localhost when fastdp enabled #1637

Merged
merged 2 commits into from
Nov 5, 2015

Conversation

awh
Copy link
Contributor

@awh awh commented Nov 4, 2015

Prevent containers from accessing the weave router control port when fast datapath is in use.

Fixes #1632.

Prevent containers from accessing the weave router control port when
fast datapath is in use.
@awh awh added this to the 1.2.1 milestone Nov 4, 2015
@rade
Copy link
Member

rade commented Nov 4, 2015

hmm. so there is still (and always has been) a problem when running w/o fastdp, and -icc=true.

We should mention somewhere in our docs (the security section, perhaps?), that setting -icc=false is needed to prevent application containers from interfering with the weave network. Or we could fix #1546, but that's too much of a change for point release.

@awh
Copy link
Contributor Author

awh commented Nov 5, 2015

We should mention somewhere in our docs (the security section, perhaps?)

I'll add a doc update commit to this PR.

bboreham added a commit that referenced this pull request Nov 5, 2015
Bind router HTTP listener to localhost when fastdp enabled
LGTM.  Fixes #1632
@bboreham bboreham merged commit 6c0bdec into master Nov 5, 2015
@bboreham
Copy link
Contributor

bboreham commented Nov 5, 2015

Note this PR was merged into master then cherry-picked onto 1.2 as 4dd63d8 and 3abb657

@awh awh deleted the issues/1632-http-localhost-bind branch November 9, 2015 16:38
Sign up for free to subscribe to this conversation on GitHub. Already have an account? Sign in.
Labels
None yet
Projects
None yet
Development

Successfully merging this pull request may close these issues.

3 participants