Make listening address configurable - #19
itsthisjustin merged 2 commits into
Conversation
crosspoint-sync listens on all interfaces without a way to change this, add a LISTEN_ADDRESS env var to configure the listening socket.
The listening address was changed to default to localhost which won't do for docker, this changes the listen address back to the old value in the docker-compose files.
|
Navigate logical layers of code changes, visualize relationships, and explore their blast radius. No actionable comments were generated in the recent review. 🎉 ℹ️ Recent review info⚙️ Run configuration
📒 Files selected for processing (3)
Included review availability: This review used your included allowance. Your plan provides up to 1 included review per hour; 0 remain after this review. 📜 Recent review details🔇 Additional comments (3)
📝 WalkthroughWalkthroughThe Compose files set ChangesListen address configuration
Priority: ⬇️ Low Estimated code review effort: 2 (Simple) | ~10 minutes Change: Feature Suggested reviewers: Merge Risk: ⚪ Minimal · up to The Compose configurations preserve the intended external listener address, while standalone runs default to localhost. No verified issue currently warrants delaying the change. Security Architecture ReviewSecurity architecture risk: 🔵 Low · up to The default listener becomes more restrictive, while Compose deliberately preserves external access. Existing application authorization remains in place. The deployed image version and host networking behavior are not established, limiting assurance about rollout behavior. Retained concerns Security review detailsSecurity Blast Radius
Security Findings and Attack Paths
Trust Boundaries and Controls
Hardening Proposals
🚥 Pre-merge checks | ✅ 4✅ Passed checks (4 passed)
Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out. Comment |
This adds a environment variable
LISTEN_ADDRESSthat allows to configure the listening address. For security purposes it defaults to localhost.It also updates the compose files to set the old, implicit, address of
::, since the new default does not work with docker.