Token导航 LogoToken导航TokenDH.com
研究检索external-serviceclawhub未标认证来源可访问clear审计提醒

localhost-bridge本地主机桥

Agent Skill

localhost-bridge 用于查找、检索和筛选相关信息,适合在 OpenClaw 中需要根据关键词、任务场景或来源线索快速定位候选结果时使用。可结合来源仓库、安装命令和原始 README 继续核验具体用法。安装前建议确认权限范围、维护状态,以及是否会触发联网、命令执行或文件读写。

总安装

16,043

周安装

649

GitHub Stars

公开资料未说明

下载量

5,036
OpenClaw

安装说明

本站只整理中文说明和来源信息,不托管安装包,也不代用户安装。

GitHub

来源数

2

许可证

MIT-0

最后核验

2026-05-01

来源状态

来源可访问

安装方式

通过对话安装

复制提示词发给支持本地命令或 Skills 的 AI 助手,先确认命令和权限,再让它执行。

请帮我安装这个 Agent Skill:localhost-bridge(本地主机桥)
来源仓库:https://github.com/superworldsavior/localhost-bridge
安装命令:
openclaw skills install localhost-bridge
安装前请先检查当前环境是否支持对应 CLI,并向我确认将要执行的命令、安装目录、联网范围和文件读写权限;确认后再执行。

命令行安装

复制命令到本机终端执行。该命令会通过 OpenClaw 从第三方来源获取 Skill;本站只展示命令,不托管安装包,也不自动执行。

ClawHubOpenClaw
openclaw skills install localhost-bridge

简介

通过 socat 桥接 Docker 容器以托管本地主机服务,解决容器网络访问问题。

  • 适合查找、检索和筛选相关信息,尤其在容器化部署环境中。
  • 可用于定位候选结果或协助网络配置排查。
  • 使用前请确认是否会触发命令执行及网络连接操作。
  • localhost-bridge 属于研究检索类 Skill,可作为该场景下的辅助能力补充。

SKILL.md

name
localhost-bridge
description
Bridge Docker containers to host localhost services via socat. Solves the #1 networking issue in containerized AI agent deployments: containers can't reach services bound to 127.0.0.1.
homepage
https://casys.ai/blog/the-localhost-trap
source
https://github.com/Casys-AI/casys-pml-cloud
author
Erwan Lee Pesle (superWorldSavior)
always
false
privileged
false
requires

localhost-bridge — Connect containers to host localhost services

⚠️ Security & Privileges

This skill requires host-level privileges. It must be reviewed and executed manually by an administrator — never autonomously by an agent.

What it does on the host:

  • Creates a systemd service (persistent across reboots) that forwards traffic from a Docker bridge IP to localhost
  • Adds a UFW firewall rule scoped to a specific Docker bridge interface
  • Requires sudo, Docker daemon access, and socat from your distro's official package repository

Before running any command:

  1. Review the generated /etc/systemd/system/socat-<SOURCE_NETWORK>-<TARGET_SERVICE>-<PORT>.service file — confirm ExecStart binds only to the intended Docker bridge IP (172.x.x.1), never 0.0.0.0
  2. Review the UFW rule — confirm it targets the correct br-<ID> interface and port
  3. After setup, verify the port is NOT reachable from the public network: curl --connect-timeout 2 http://<PUBLIC_IP>:<PORT>/ must fail
  4. Test from inside a container before deploying widely

Do not grant an automated agent permissions to run these commands without human approval.


The Problem

A service on the host listens on 127.0.0.1 (AI gateway, MCP server, Ollama, database...). A Docker container needs to reach it. localhost inside the container points to the container itself, not the host. Requests either timeout silently (firewall drops packets) or get connection refused.

The Solution

socat listens on the Docker bridge gateway IP and forwards to host loopback. Combined with a scoped firewall rule, this gives containers access without exposing the service externally.

Setup (run manually as admin)

1. Find the Docker bridge gateway IP

# For a specific container
docker inspect <container_name> --format '{{json .NetworkSettings.Networks}}' \
  | python3 -c "
import json,sys
d = json.load(sys.stdin)
for net, info in d.items():
    print(f'{net}: gateway={info[\"Gateway\"]}')"

2. Create a systemd service

Replace <GATEWAY_IP>, <PORT>, <SOURCE_NETWORK>, and <TARGET_SERVICE> with your values.

Naming convention: socat-<source_network>-<target_service>-<port> — source network is the Docker network (consumer), target service is the host service. Self-documenting.

Examples: socat-bridge-gateway-18789, socat-windmill_default-gateway-18789, socat-bridge-ollama-11434

Review the ExecStart line before enabling — confirm it binds to the Docker bridge IP only.

sudo tee /etc/systemd/system/socat-<SOURCE_NETWORK>-<TARGET_SERVICE>-<PORT>.service > /dev/null << 'EOF'
[Unit]
Description=Socat bridge: <SOURCE_NETWORK> -> <TARGET_SERVICE>:<PORT>
After=network.target docker.service

[Service]
Type=simple
ExecStart=/usr/bin/socat TCP-LISTEN:<PORT>,bind=<GATEWAY_IP>,fork,reuseaddr TCP:127.0.0.1:<PORT>
Restart=always
RestartSec=5

[Install]
WantedBy=multi-user.target
EOF

# Review the file before enabling:
cat /etc/systemd/system/socat-<SOURCE_NETWORK>-<TARGET_SERVICE>-<PORT>.service

sudo systemctl daemon-reload
sudo systemctl enable --now socat-<SOURCE_NETWORK>-<TARGET_SERVICE>-<PORT>

3. Add firewall rule (MANDATORY)

Without this, socat listens but packets from the container are silently dropped — causing 30-second timeouts with no error.

Review the bridge ID before applying — a wrong ID can expose services.

# Find the Linux bridge interface for the Docker network
BRIDGE_ID=$(docker network inspect <network_name> --format '{{.Id}}' | cut -c1-12)

# Verify this is the right bridge
ip link show br-${BRIDGE_ID}

# Allow traffic only on that bridge interface
sudo ufw allow in on br-${BRIDGE_ID} to any port <PORT> proto tcp comment "<SOURCE_NETWORK>-<TARGET_SERVICE>-<PORT>"

4. Verify security

# MUST succeed (from inside a container)
docker exec <container_name> curl -s --connect-timeout 5 http://<GATEWAY_IP>:<PORT>/

# MUST fail (from the public network)
curl --connect-timeout 2 http://<PUBLIC_IP>:<PORT>/

Multi-Network Workers

A container can be on multiple Docker networks. Each has its own bridge IP. You need a socat instance + firewall rule for each network the container uses. In practice, one network is usually enough.

Check all networks: docker inspect <container> --format '{{json .NetworkSettings.Networks}}'

Common Use Cases

Host serviceContainer clientDefault port
AI gateway (OpenClaw, LiteLLM)Workflow orchestrator (Windmill, n8n)18789
MCP serverDockerized agentvaries
OllamaRAG pipeline, agent11434
PostgreSQLAPI server5432
RedisAny containerized app6379

Troubleshooting

SymptomCauseFix
30s timeout, no errorFirewall dropping packetsAdd UFW rule on the bridge interface
Connection refusedsocat not runningsystemctl status socat-<SOURCE_NETWORK>-<TARGET_SERVICE>-<PORT>
Works then stops after Docker restartBridge IP changedCheck new gateway IP, update socat bind
socat won't start after rebootDocker not readyEnsure After=docker.service in unit file

Alternatives

Depending on your security posture, consider:

  • Docker host networking (network_mode: host) — simpler but removes all container network isolation
  • Running socat inside a minimal privileged container — avoids host-level systemd changes
  • Configuring the host service to bind to the Docker bridge IP directly — no socat needed, but the service must support custom bind addresses
  • host.docker.internal (Docker Desktop) — works on Mac/Windows, not reliably on Linux

Prerequisites

Install socat from your distro's official package repository:

sudo apt-get install -y socat  # Debian/Ubuntu
sudo dnf install -y socat      # Fedora/RHEL

References

适合场景

01

OpenClaw 用户查找和安装 Skill 时

02

用户想查找某类 Agent Skill 时

03

需要根据任务场景推荐可安装能力包时

04

需要对比不同来源的安装命令和来源信息时

能力概览

能力 1

按任务关键词查找相关 Skills

能力 2

展示可复制的安装命令

能力 3

保留来源站点、仓库和原始说明,方便继续核验

能力 4

补充不同宿主或平台的使用分布数据

能力 5

展示第三方安全扫描或审计结果

安装后应在对应宿主中按原始 README 的触发条件使用;具体调用方式请以来源页面和 README 为准。

平台分布

OpenClaw

83.45%
按下载量换算4,203

安全审计

VirusTotal

可疑

ClawScan

可疑

Static analysis

未展示

权限和风险

external-service

该 Skill 可能调用第三方服务、云服务或外部模型 API,使用前需要确认账号、额度、数据发送范围和服务条款。

安装前确认

本站仅展示第三方公开信息,不托管安装包,不提供自动安装或运行环境。安装前应自行审查源码、依赖和命令行为。来源安全扫描存在 warning/failed 结果,不能写成本站确认安全。当前只有一个来源,正式发布前建议补源仓库或其他目录站核验。

来源信息

继续浏览同类 Skills