Running behind a proxy
Application-level proxy (customer.env)
MDSS services read proxy settings from /etc/mdss/customer.env (see Custom configuration ).
NO_PROXY must list every hostname the MDSS containers reach directly on the Docker network, so that service-to-service traffic is not sent through the proxy. The list below covers both deployment modes: the bundled platform container (md-platform, the default) and the individual-services deployment (COMMON_SERVICES_ENABLED=no). Entries for services that are not running in your deployment are harmless.
What the entries are:
Entry | Deployment | Purpose |
|---|---|---|
| Bundled (default) | The single container that hosts Identity, Licensing, Job Dispatcher, Logging, Scanning, Notification, Discovery, Remediations, Storages and Workflow Manager |
| Individual services ( | The same services, one container each |
| Both | API Gateway, web client and the database migration jobs |
| Both | Infrastructure. Replace with your own hostnames when using external PostgreSQL, RabbitMQ or Redis, if they are reachable without a proxy |
| Both, when the NFS or SMB module is enabled | The NFS and SMB protocol sidecars. All other storage types run in-process and need no extra entry |
| Both, when MetaDefender Core is deployed alongside MDSS | The bundled MetaDefender Core instance |
The configured scan instance address should also be added to the NO_PROXY list if connecting to it does not require a proxy.
Docker daemon proxy (pulling MDSS images)
If a proxy is required to access to docker hub in order to pull MDSS images, then this guide should be followed: https://docs.docker.com/network/proxy/
Create the drop-in config file or edit it if it already exists:
Set the proxy settings:
Apply the changes: