AI & Agent Dev Bug Sandbox logo
AI & Agent Dev Bug Sandbox
Back to Radar

Docker Desktop MacOS Ignores Host_binding_ipv4, Exposing Supabase Local Dev Ports To LAN

The documented Docker network host binding to 127.0.0.1 does not restrict access on macOS because Docker Desktop runs Docker inside a Linux VM, causing local Supabase services to remain reachable from other devices on the same LAN.

highConfidence 88%Docker Desktop

Origin Analysis

Docker Desktop on macOS runs the Docker daemon inside a Linux VM. The Docker network option com.docker.network.bridge.host_binding_ipv4=127.0.0.1 only affects binding inside that VM, while Docker Desktop's userland proxy forwards published ports to all host interfaces, ignoring the bridge IP binding on the macOS host.
1. On macOS, install Docker Desktop. 2. Run: docker network create -o 'com.docker.network.bridge.host_binding_ipv4=127.0.0.1' local-network 3. Start Supabase: npx supabase start --network-id local-network 4. Find the Mac's LAN IP using ifconfig. 5. From another device on the same network, open http://<LAN-IP>:54323 in a browser. 6. Supabase Studio loads despite the documentation stating only localhost access is allowed.

Fixing Code Block

Edge Case Audit

The script replaces the entire active pf ruleset, which may disrupt existing firewall or VPN policies. Always back up current rules (the script does this to /tmp/pf-backup-*). The rules are not persistent across macOS reboots and must be reapplied manually or via launchd. If you need to use other services on the listed ports from external interfaces, adjust or remove those ports. Rollback: restore the backup with sudo pfctl -f /tmp/pf-backup-<timestamp>.rules or disable pf with sudo pfctl -d.

Ecosystem Topology