@bitaffair/mdnx
v0.2.1
Published
Expose Docker services as secure .local domains in development
Maintainers
Readme
mdnx
Expose Docker services as secure .local domains in development
- Traefik as reverse proxy
- Custom mDNS responder
- Easy to configure with docker labels
Currently on macOS only
How it works
mdnx runs a background daemon (installed as a macOS LaunchAgent) that combines three pieces:
- Traefik as a reverse proxy in front of your Docker containers.
- A custom mDNS responder that resolves
*.localqueries on your local network to your machine's IP. - A self-signed CA and TLS certificates so HTTPS on those
.localdomains works without browser warnings.
Any container with the right labels, on the mdnx Docker network, automatically gets picked up and made reachable at https://<yourhost>.local.
Requirements
- macOS
- Docker (Docker Desktop or compatible)
Install
# Install globally
npm i -g @bitaffair/mdnx
# Create the external Docker network mdnx services attach to
docker network create mdnx
# Init mdnx: starts the daemon, generates a local CA and
# imports it into the macOS System keychain (asks for your sudo password)
mdnx initExample docker-compose.yml
networks:
mdnx:
external: true
services:
foo:
image: traefik/whoami
networks:
- mdnx
labels:
- traefik.enable=true
- mdnx.enable=true
- traefik.http.routers.foo.rule=Host(`foo.bar.local`)# Start the mdnx daemon + Traefik
mdnx start
# Start your environment
docker compose up -dYour service is now reachable at https://foo.bar.local with a trusted certificate — no /etc/hosts editing, no browser warnings.
Commands
| Command | Description |
| ---------------- | --------------------------------------------------------------------------------------------------------- |
| mdnx init | Starts the daemon, generates the local CA and imports it into the macOS System keychain (sudo required) |
| mdnx start | Installs/loads the daemon (LaunchAgent) and starts Traefik |
| mdnx stop | Stops Traefik and unloads the daemon |
| mdnx restart | Restarts daemon and Traefik |
| mdnx status | Shows daemon status (installed/loaded/running/pid) and, if running, the detected local IP and domains |
| mdnx uninstall | Removes the daemon LaunchAgent completely |
| mdnx version | Prints the installed mdnx version |
Uninstalling
mdnx stop
mdnx uninstallThis removes the background daemon. If you also want to remove the trusted CA certificate, open Keychain Access, go to the System keychain, find the mdnx CA and delete it.
Troubleshooting
*.localdomain doesn't resolve — make suremdnx statusshows the daemon as running, and that mDNS/Bonjour isn't blocked by your firewall.- Browser shows a certificate warning — re-run
mdnx initto (re-)import the CA into the System keychain, and make sure you trust it (see Keychain Access). - Service doesn't show up — check that the container has both
traefik.enable=trueandmdnx.enable=truelabels, is attached to the externalmdnxnetwork, and defines atraefik.http.routers.<name>.rulewith aHost(...)rule.
