ArchitectureNetworking model
Why 127.0.0.1
Ports published on 127.0.0.1 work on each system, expose nothing by accident and never conflict.
The published port is on 127.0.0.1. Only the host itself can connect to it.
1 / 3
Three reasons
| Reason | Detail |
|---|---|
| It works on Docker Desktop | On macOS and Windows, containers run in a VM. The host, where ferryd runs, cannot reach their IP addresses. Published ports work on Docker Desktop and on Linux. |
| Nothing is open by accident | An app is never on the public interfaces of the machine. A private service gets a published port too, for the health checks. Only the host can reach it. |
| No port conflict | The old and the new instances of a blue-green deploy listen on the same container port. Random host ports let any number of instances do that. |
The cost
A host port can change. When Docker restarts a crashed container, the new port can be different.
The engine follows this change in two ways:
- The route watcher checks the instances each second.
- The reconciler does a full pass each 10 seconds.
Thus the routes always have the current ports.