public inbox for passt-user@passt.top
 help / color / mirror / Atom feed
* Auto forwarding ports, but only to localhost
@ 2025-11-27 12:48 Jan Wrobel
  2025-11-28  1:10 ` David Gibson
  0 siblings, 1 reply; 7+ messages in thread
From: Jan Wrobel @ 2025-11-27 12:48 UTC (permalink / raw)
  To: passt-user

Hi,

For pasta, would you consider an option to enable automatic forwarding
of ports bound in a namespace, but make the forwarded ports available
only via localhost, not all addresses?

I'm working on a sandboxing program which uses pasta. The option -t
"auto" is super convenient, but requires extra care, without proper
firewall setup bound ports become automatically available to outside
world. For a sandboxing program like mine, it is not a safe default to
run with, because the program shouldn't assume the user will have a
firewall configured.

If something like "localhost/auto" was supported, it would match the
convenience of "auto", no manual port mapping config would be needed,
but would be safer for uses cases where exposing ports to outside
world is problematic.

Cheers,
Jan

^ permalink raw reply	[flat|nested] 7+ messages in thread

end of thread, other threads:[~2025-12-01 11:50 UTC | newest]

Thread overview: 7+ messages (download: mbox.gz / follow: Atom feed)
-- links below jump to the message on this page --
2025-11-27 12:48 Auto forwarding ports, but only to localhost Jan Wrobel
2025-11-28  1:10 ` David Gibson
2025-11-28 11:03   ` Jan Wrobel
2025-11-30  7:24     ` David Gibson
2025-11-30 10:42     ` Stefano Brivio
     [not found]       ` <CACm05o-ZJq9AE1bzc7hZ4YGi2Jy346ZxJ4ra9Pwsx3_AkX-SNA@mail.gmail.com>
2025-12-01 10:32         ` Stefano Brivio
2025-12-01 11:49           ` Jan Wrobel

This is a public inbox, see mirroring instructions
for how to clone and mirror all data and code used for this inbox;
as well as URLs for IMAP folder(s).