Docker Socket Proxy

Security-enhanced proxy to restrict Docker socket API access

2.7k stars 204 forks last commit first released Apache-2.0

Actively maintained

Last commit 27 Jul 2026.

Docker Socket Proxy is a security-enhanced proxy for the Docker socket.

  • It sits between clients and the Docker daemon and blocks access to sensitive API endpoints based on per-endpoint allow/deny rules driven by environment variables.
  • The proxy runs as an Alpine-based HAProxy container and uses a small configuration to enforce the ACLs, returning HTTP 403 Forbidden for disallowed requests.

Key Features

  • ACL-driven access control via environment variables that map to Docker API prefixes (eg. /auth, /containers, /images, /volumes, etc.).
  • Default allowances for safe endpoints (eg. EVENTS, PING, VERSION) with fine-grained revocation for security-critical areas.
  • Simple deployment model: run a privileged container that mounts the host Docker socket and exposes a proxy port.
  • Socket-location flexibility via SOCKET_PATH to support non-standard Docker socket paths.
  • Configurable logging through a LOG_LEVEL setting.
  • Clear security guidance: avoid exposing the proxy publicly and rely on Docker network isolation.
  • Image tagging supports versioned releases, latest, and edge builds for development.

Use Cases

  • Expose Docker API to a single service or CI tool with restricted permissions, reducing blast radius if the service is compromised.
  • Place the proxy behind a network firewall or within a private network segment to limit access to the Docker daemon.
  • Point clients to the proxy (via DOCKER_HOST=tcp://host:2375) instead of the raw Docker socket to enforce ACLs without changing client code.

Limitations and Considerations

  • TLS support is not included; the proxy provides a plain HTTP front for the host Docker socket. Plan to terminate TLS at a separate layer or keep the proxy on a secured network.
  • The container must run privileged because it connects to the Docker socket, which carries security implications.
  • Some workflows may require enabling additional API sections; review and adjust environment variables to match your needs.

Conclusion

Docker Socket Proxy offers a straightforward ACL-based barrier between clients and the Docker daemon, enabling safer integrations where Docker access is necessary but tightly controlled. It is quick to deploy in a containerized environment, but requires careful network and permission configurations to maintain security.

Categories:

Tags:

Tech Stack:

Share:

Similar to Docker Socket Proxy

OAuth2 Proxy

Reverse proxy and middleware for OAuth2/OIDC authentication

14.8k
2.2k
Last commit

OAuth2 Proxy is a reverse proxy and middleware that protects web apps with OAuth2/OIDC login and forwards authenticated user identity to upstream services.

MITActively maintained
Alternative to:
Cloudflare Access logo
Cloudflare Access
+14

Pomerium

Identity- and context-aware access proxy for zero trust access

4.9k
343
Last commit

Pomerium is an identity-aware access proxy that provides zero trust, per-request authorization to internal web apps and services without a traditional VPN.

Apache-2.0Actively maintained
Alternative to:
Cloudflare Access logo
Cloudflare Access
+12
Hasura GraphQL Engine logo

Hasura GraphQL Engine

Open-source GraphQL engine providing instant, realtime APIs on your data

32.1k
3k
Last commit

Hasura is an open-source GraphQL engine that instantly exposes realtime, secure GraphQL APIs over databases and other data sources with fine-grained access control.

Apache-2.0Actively maintained
Alternative to:
Hasura logo
Hasura
+16
Kinto logo

Kinto

Minimalist JSON document store with sharing and synchronization

4.4k
433
Last commit

Kinto is a lightweight JSON document store with an HTTP API, built-in permissions, sharing, and client synchronization, designed for offline-first and distributed apps.

Actively maintained
Alternative to:
Firebase logo
Firebase
+3
ShellHub logo

ShellHub

Centralized SSH gateway for remote access and device management

2k
186
Last commit

Centralized SSH gateway to remotely manage Linux servers, containers and IoT devices via web or native SSH; offers key auth, firewall rules, audit logging and session recording.

Apache-2.0Actively maintained
Alternative to:
Teleport logo
Teleport
+14
g3proxy logo

g3proxy

Enterprise-oriented generic forward proxy and TCP/TLS stream proxy

888
82
Last commit

High-performance Rust proxy supporting HTTP/SOCKS5 forwarding, transparent proxying, TLS MITM, ICAP integration, ACLs, auth, and observability features.

Apache-2.0Actively maintained
Alternative to:
Bright Data logo
Bright Data
+10