Starling’s proxy_bind_addr hardcodes Ipv4Addr::UNSPECIFIED (0.0.0.0) for Mode::Docker. This prevents the proxy from accepting connections directly over IPv6, affecting deployments in dual-stack Kubernetes clusters.
Proposed change:
Expose a Docker startup option to configure the proxy’s listening address, including IPv6, and support accepting both IPv4 and IPv6 connections. Preserve existing IPv4 deployments and document the default behavior.
Simply replacing 0.0.0.0 with :: needs additional consideration:
- Dual-stack behavior: Explicitly handle the socket’s IPv6-only setting so IPv4 connectivity does not depend on host defaults.
- Client address handling: Normalize IPv4-mapped IPv6 addresses before trusted-proxy/CIDR checks, loopback checks, and access logging. For example,
::ffff:127.0.0.1 should retain the same loopback behavior as 127.0.0.1.
- Compatibility: Keep an IPv4-only configuration available for environments where IPv6 is disabled.
- Healthchecks: Ensure the built-in healthcheck can reach the proxy with the configured listener.
Validate IPv4-only, IPv6-only, and dual-stack configurations, including trusted-proxy handling and healthchecks. Keep embedded mode’s loopback-only binding unchanged.
Starling’s
proxy_bind_addrhardcodesIpv4Addr::UNSPECIFIED(0.0.0.0) forMode::Docker. This prevents the proxy from accepting connections directly over IPv6, affecting deployments in dual-stack Kubernetes clusters.Proposed change:
Expose a Docker startup option to configure the proxy’s listening address, including IPv6, and support accepting both IPv4 and IPv6 connections. Preserve existing IPv4 deployments and document the default behavior.
Simply replacing
0.0.0.0with::needs additional consideration:::ffff:127.0.0.1should retain the same loopback behavior as127.0.0.1.Validate IPv4-only, IPv6-only, and dual-stack configurations, including trusted-proxy handling and healthchecks. Keep embedded mode’s loopback-only binding unchanged.