Does uwsgi http-socket default binding risk public exposure in host-networked containers?
0 reputation · 12 May 2023, 00:00 UTC
0 reputation · 12 May 2023, 00:00 UTC
In uWSGI 2.0.x, the --http-socket option defaults to binding on 0.0.0.0 when a port is specified without an explicit IP address. This differs from the uwsgi protocol socket, which typically defaults to 127.0.0.1.
When deploying applications within containerized environments, this behavior creates a potential security gap. While a standard Docker bridge network provides isolation, utilizing --network=host or Kubernetes hostNetwork: true bypasses this layer, potentially exposing the HTTP port directly to the external network without an intervening reverse proxy.
Operational requirements, such as health checks from orchestration platforms, often necessitate broad binding, yet there is no native uWSGI mechanism to alert administrators when an HTTP socket is bound to all interfaces in a production context.
--http-socket to specific internal interfaces without manually hardcoding IP addresses for every environment?29275 reputation · 12 May 2023, 11:27 UTC
Yes. In uWSGI 2.0.x, using --http-socket=:PORT binds the HTTP server to 0.0.0.0 by default. When the container runs with --network=host (Docker) or hostNetwork: true (Kubernetes), the host’s network stack is shared, so the port becomes reachable from any external address that can reach the host. If no additional controls (firewall, reverse proxy, or explicit IP binding) are in place, the application can be accessed publicly, creating a security gap.
0.0.0.0 for convenience, mirroring typical development setups.127.0.0.1, which is why many people overlook the HTTP case.0.0.0.0 are exposed to the host’s external interfaces.| Condition | Result |
|---|---|
Container --network=host + --http-socket=:8080 | LISTEN on 0.0.0.0:8080; reachable from host’s public IP |
| Container default bridge network + same socket | LISTEN on 0.0.0.0:8080; reachable only via container’s internal IP |
Explicit IP binding --http-socket=127.0.0.1:8080 | Only reachable from localhost inside container |
uwsgi --http-socket=127.0.0.1:8080
This keeps the server internal to the container, even with host networking.--http-socket option accepts a --http-socket=0.0.0.0:PORT flag that can be combined with --http-socket-allow-from for fine‑grained access control.If you are currently using a reverse proxy or firewall, let us know so the recommendation can be tailored to that setup.
Use comments to ask for clarification. Post a solution as an answer.
No question comments on this page.