Skip to content

Use a private subnet for the tutorial network - #12

Merged
jason-fox merged 1 commit into
FIWARE:NGSI-LDfrom
kzangeli:fix/private-subnet
Sep 21, 2026
Merged

jason-fox merged 1 commit into
FIWARE:NGSI-LDfrom
kzangeli:fix/private-subnet

Conversation

@kzangeli

Copy link
Copy Markdown

SUBNET in .env is 182.18.1.0/24, which is public address space allocated to APNIC — not a private range. Every other NGSI-LD tutorial hardcodes 172.18.1.0/24 in docker-compose/common.yml; this is the only one that parameterises the subnet.

Why it's hard to spot

The stack appears to start perfectly:

  • ./services coraine exits 0
  • its own output says "is now running and exposed on localhost:1026"
  • the container reports healthy, with an empty log and correct arguments
  • docker ps shows 0.0.0.0:1026->1026/tcp

and then nothing answers:

$ curl localhost:1026/ngsi-ld/v1/entities
   ... exit 28 (timeout) — not "connection refused"

$ docker inspect ... → container IP 182.18.1.8
$ curl 182.18.1.8:1026/...
   ... timeout

A bound port that accepts and never replies, because as far as the host's routing is concerned 182.18.1.8 is a machine on the internet.

It also occupies 256 public addresses on whatever machine runs the tutorial.

The change

One line: SUBNET=172.18.1.0/24, matching every other tutorial. With it, the tutorial runs.

Found while running all sixteen NGSI-LD tutorials against a different NGSI-LD broker; this was the only one that could not be started at all.

SUBNET was 182.18.1.0/24, which is public address space allocated to APNIC -
not a private range. Every other NGSI-LD tutorial hardcodes 172.18.1.0/24 in
docker-compose/common.yml; this is the only one that parameterises the subnet.

The effect is that the stack appears to start correctly and is then unreachable
from the host: docker publishes the port, the container reports healthy, and a
request to localhost:1026 TIMES OUT rather than being refused, because the
container's address (182.18.1.8) is a real internet host as far as the kernel's
routing is concerned. It also occupies 256 public addresses on the machine
running it.

With 172.18.1.0/24 the tutorial runs.
@jason-fox
jason-fox merged commit d38ff76 into FIWARE:NGSI-LD Sep 21, 2026
1 check passed
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants