fix(S2-a): keep plaintext MQTT inside compose network
This commit is contained in:
@@ -12,7 +12,7 @@ exposes three listeners, each with a different trust model:
|
||||
|
||||
| Port | Protocol | Auth | Who it's for |
|
||||
|------|----------|------|---------------|
|
||||
| `1883` | MQTT (plaintext) | username/password | internal services (e.g. the Laravel subscriber, Python publisher) |
|
||||
| `1883` | MQTT (plaintext, Compose network only) | username/password | internal backend service; not host-published |
|
||||
| `8883` | MQTT over TLS | **client certificate** | field devices |
|
||||
| `443` (`/mqtt` → loopback `9001`) | MQTT over WSS/TLS | username/password | scoped app clients |
|
||||
| `8884` | MQTT over TLS | username/password (server cert only) | scoped app clients and administrators on networks that expose the raw port |
|
||||
|
||||
@@ -11,7 +11,6 @@ services:
|
||||
mosquitto:
|
||||
image: eclipse-mosquitto:2
|
||||
ports:
|
||||
- "1883:1883"
|
||||
- "8883:8883"
|
||||
- "8884:8884"
|
||||
- "127.0.0.1:9001:9001"
|
||||
|
||||
Reference in New Issue
Block a user