From 4a2ae8d6ee927005c6b6c8cf5a63a1dde26e8f5f Mon Sep 17 00:00:00 2001 From: Tien Thanh Pham Date: Fri, 18 Sep 2026 09:44:27 +0800 Subject: [PATCH 1/2] [MOL-22452][TP] fix asgard-0002, bind Playwright server to loopback and remove host networking --- Dockerfile | 2 +- docker-compose.yml | 3 ++- 2 files changed, 3 insertions(+), 2 deletions(-) diff --git a/Dockerfile b/Dockerfile index db9128135d..1a90e0eaaf 100644 --- a/Dockerfile +++ b/Dockerfile @@ -3,4 +3,4 @@ FROM mcr.microsoft.com/playwright:v1.58.2-noble # Set working directory inside the container WORKDIR /home/pwuser -CMD ["npx", "-y", "playwright@1.58.2", "run-server", "--port", "3010", "--host", "0.0.0.0"] +CMD ["npx", "-y", "playwright@1.58.2", "run-server", "--port", "3010", "--host", "127.0.0.1"] diff --git a/docker-compose.yml b/docker-compose.yml index f72cf6aa31..d87bd2eb33 100644 --- a/docker-compose.yml +++ b/docker-compose.yml @@ -1,6 +1,7 @@ services: playwright-tests: build: . - network_mode: "host" + ports: + - "127.0.0.1:3010:3010" extra_hosts: - "host.docker.internal:host-gateway" From 1b9de1a701acd0fc2e68d5f6339c24472ad2e87d Mon Sep 17 00:00:00 2001 From: Tien Thanh Pham Date: Fri, 18 Sep 2026 10:43:07 +0800 Subject: [PATCH 2/2] [MOL-22452][TP] fix: revert Playwright bind to 0.0.0.0 inside container 0.0.0.0 is required inside the container for Docker bridge traffic to reach the server. Security is enforced by the host-side port mapping (127.0.0.1:3010:3010) which restricts access to loopback. --- Dockerfile | 2 +- 1 file changed, 1 insertion(+), 1 deletion(-) diff --git a/Dockerfile b/Dockerfile index 1a90e0eaaf..db9128135d 100644 --- a/Dockerfile +++ b/Dockerfile @@ -3,4 +3,4 @@ FROM mcr.microsoft.com/playwright:v1.58.2-noble # Set working directory inside the container WORKDIR /home/pwuser -CMD ["npx", "-y", "playwright@1.58.2", "run-server", "--port", "3010", "--host", "127.0.0.1"] +CMD ["npx", "-y", "playwright@1.58.2", "run-server", "--port", "3010", "--host", "0.0.0.0"]