• Lucy :3@feddit.org
    link
    fedilink
    arrow-up
    29
    ·
    4 days ago

    Unix sockets all the way. The only open ports for web traffic should be the reverse proxy (so nginx).

    • passepartout@feddit.org
      link
      fedilink
      arrow-up
      16
      ·
      edit-2
      4 days ago

      Or Caddy (simpler than and imho spiritual successor to nginx).

      Or Traefik (has loads of convenient middlewares for reverse proxy stuff).

      Or Apache (if it is somehow better suited to your use case).

    • x00z@lemmy.world
      link
      fedilink
      English
      arrow-up
      3
      ·
      4 days ago

      I use docker ports but only allow the loopback like this: 127.0.0.1:11551:80

      And then serve that app with the reverse proxy.