Skip to content

Better default security for cagent api|mcp|a2a#1657

Merged
dgageot merged 3 commits intodocker:mainfrom
dgageot:api-security
Feb 9, 2026
Merged

Better default security for cagent api|mcp|a2a#1657
dgageot merged 3 commits intodocker:mainfrom
dgageot:api-security

Conversation

@dgageot
Copy link
Member

@dgageot dgageot commented Feb 9, 2026

Improve security by making sure that cagent api, cagent a2a and cagent mcp are not exposed to 0.0.0.0 by default.
Also removed CORS configuration from cagent api.

This is a breaking change for all three commands and even more for the last two because I changed the --port command line argument to --listen for resemblance with cagent api.

@dgageot dgageot force-pushed the api-security branch 2 times, most recently from 4924dbf to 6e8d936 Compare February 9, 2026 14:55
@dgageot dgageot marked this pull request as ready for review February 9, 2026 14:55
@dgageot dgageot requested a review from a team as a code owner February 9, 2026 14:55
@dgageot dgageot changed the title cagent api security Better default security for cagent api|mcp|a2a Feb 9, 2026
krissetto
krissetto previously approved these changes Feb 9, 2026
Signed-off-by: David Gageot <david.gageot@docker.com>
Signed-off-by: David Gageot <david.gageot@docker.com>
Signed-off-by: David Gageot <david.gageot@docker.com>
@dgageot dgageot merged commit cb2ed7d into docker:main Feb 9, 2026
5 checks passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

3 participants