diff --git a/m/hut/gitlab-runner.nix b/m/hut/gitlab-runner.nix index a68d8d1..2fe7c1c 100644 --- a/m/hut/gitlab-runner.nix +++ b/m/hut/gitlab-runner.nix @@ -99,10 +99,9 @@ # DOCKER* chains are useless, override at FORWARD and nixos-fw networking.firewall.extraCommands = '' - # Allow docker to use our proxy - iptables -I FORWARD 1 -p tcp -i docker0 -d hut --dport 23080 -j nixos-fw-accept - # Block anything else coming from docker - iptables -I FORWARD 2 -p all -i docker0 -j nixos-fw-log-refuse + # Don't forward any traffic from docker + iptables -I FORWARD 1 -p all -i docker0 -j nixos-fw-log-refuse + # Allow incoming traffic from docker to 23080 iptables -A nixos-fw -p tcp -i docker0 -d hut --dport 23080 -j ACCEPT '';