Description
IPv6 is no longer proxied by default as of 20.10.2 (#41805). This is expanded in greater detail in moby/libnetwork#2607, but downgrading to 20.10.1 will restore the previous behavior. This change should be either documented or fixed to not surprise users.
Steps to reproduce the issue:
- Bind NGINX with published ports
--publish 443:443 and get "IPv6 support" (proxy is just accepting any address and proxying to the container. This may be abusing the proxy, but it works.)
- Upgrade to Docker 20.10.2 and now IPv6 is broken and curl returns "Connection refused"
Output of docker version:
Client: Docker Engine - Community
Version: 20.10.2
API version: 1.41
Go version: go1.13.15
Git commit: 2291f61
Built: Mon Dec 28 16:17:43 2020
OS/Arch: linux/amd64
Context: default
Experimental: true
Server: Docker Engine - Community
Engine:
Version: 20.10.1
API version: 1.41 (minimum version 1.12)
Go version: go1.13.15
Git commit: f001486
Built: Tue Dec 15 04:32:52 2020
OS/Arch: linux/amd64
Experimental: false
containerd:
Version: 1.4.3
GitCommit: 269548fa27e0089a8b8278fc4fc781d7f65a939b
runc:
Version: 1.0.0-rc92
GitCommit: ff819c7e9184c13b7c2607fe6c30ae19403a7aff
docker-init:
Version: 0.19.0
GitCommit: de40ad0
Output of docker info:
Client:
Context: default
Debug Mode: false
Plugins:
app: Docker App (Docker Inc., v0.9.1-beta3)
buildx: Build with BuildKit (Docker Inc., v0.5.1-docker)
Server:
Containers: 22
Running: 22
Paused: 0
Stopped: 0
Images: 14
Server Version: 20.10.1
Storage Driver: overlay2
Backing Filesystem: extfs
Supports d_type: true
Native Overlay Diff: true
Logging Driver: json-file
Cgroup Driver: cgroupfs
Cgroup Version: 1
Plugins:
Volume: local
Network: bridge host ipvlan macvlan null overlay
Log: awslogs fluentd gcplogs gelf journald json-file local logentries splunk syslog
Swarm: inactive
Runtimes: io.containerd.runc.v2 io.containerd.runtime.v1.linux runc
Default Runtime: runc
Init Binary: docker-init
containerd version: 269548fa27e0089a8b8278fc4fc781d7f65a939b
runc version: ff819c7e9184c13b7c2607fe6c30ae19403a7aff
init version: de40ad0
Security Options:
apparmor
seccomp
Profile: default
Kernel Version: 5.4.0-1034-aws
Operating System: Ubuntu 20.04.1 LTS
OSType: linux
Architecture: x86_64
CPUs: 2
Total Memory: 3.786GiB
Name: web1.dev.internal.nexleaf.org
ID: 7G37:MVZI:VTVY:Q5UJ:CDA6:UKRI:7PF7:LLM6:YFAR:LTZR:6AQ4:Y7ZF
Docker Root Dir: /var/lib/docker
Debug Mode: false
Registry: https://index.docker.io/v1/
Labels:
Experimental: false
Insecure Registries:
127.0.0.0/8
Live Restore Enabled: false
WARNING: No swap limit support
WARNING: No blkio weight support
WARNING: No blkio weight_device support
Description
IPv6 is no longer proxied by default as of 20.10.2 (#41805). This is expanded in greater detail in moby/libnetwork#2607, but downgrading to 20.10.1 will restore the previous behavior. This change should be either documented or fixed to not surprise users.
Steps to reproduce the issue:
--publish 443:443and get "IPv6 support" (proxy is just accepting any address and proxying to the container. This may be abusing the proxy, but it works.)Output of
docker version:Output of
docker info: