--- # TCP proxy on ana-docker: exposes ana-ml2's Docker API (10.250.50.54:2375) as # 10.250.50.70:2354 so Homepage on esh-docker-vm can discover ana-ml2's # containers. # # WHY: ana-ml2 is up and its docker API is reachable from within Anaheim, but # NOT cross-site from ESH (a return-route gap on ana-ml2 itself; there is no SSH # path to ana-ml2 from the ops seats to fix its routing). ana-docker sits on the # same Anaheim subnet, reaches ana-ml2:2375 directly, and IS reachable from ESH, # so it relays. Plaintext, trusted mesh-internal only — same posture as the # fleet's other plaintext :2375 docker hosts (docker.yaml). # # UNDO: once ana-ml2 has a working return route to ESH, point Homepage's # ana-ml2-docker entry back at 10.250.50.54:2375 directly and `docker compose # down` this stack. services: ana-ml2-docker-proxy: image: alpine/socat@sha256:ef6c281978dcd6927d9b3829484e4c4fdfc5d98de5acbd6312c04565d2d58cbf container_name: ana-ml2-docker-proxy restart: unless-stopped # host networking so socat binds ana-docker's :2354 and reaches ana-ml2 over # the host's Anaheim-subnet route; no bridge/port-map hop needed. network_mode: host command: TCP-LISTEN:2354,fork,reuseaddr TCP:10.250.50.54:2375