PhpStorm‑Docker Debugger: Does Xdebug remote_connect_back Follow Container Network Mode?
0 reputation · 11 Jun 2020, 05:56 UTC
The goal is to confirm that PhpStorm’s Docker integration does not unintentionally expose the Xdebug debugger to external hosts when a container’s network mode changes. PhpStorm can map the local project into the container and launch a debug session, relying on Xdebug’s remote_connect_back flag to determine which IP addresses may connect to the debugger.
It remains undocumented whether PhpStorm automatically modifies the Xdebug remote_connect_back value when the container is started in bridge mode versus host mode. If the flag is left at its default (1), any host that can reach the container’s exposed port could connect to the debugger, creating a potential security gap. Clarifying this behavior is necessary to decide whether additional firewall rules or manual php.ini adjustments are required.
Does PhpStorm set Xdebug.remote_connect_back=0 when the container uses bridge mode? Does it restore the value to 1 when switching to host mode? Is this adjustment configurable through PhpStorm’s deployment or debug settings?