Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Just share an open FD to a socks proxy with the isolated service.


This depends on the service itself supporting inheriting sockets for proxies. Is this a common feature? Some services do support listening socket passing which does solve my problem as I can make it listen on a UNIX socket mounted on the host and accessible to the reverse proxy but many of the lower quality services that I want to give this treatment to don't support that either.


As another commenter says, you can use socat. Specifically, you can run it in double client mode (see http://www.dest-unreach.org/socat/doc/socat-gender.txt) to connect the UNIX socket to the service.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: