3 ms·
Swarm mode is great, but I haven't found a good resource yet on how it alters firewall rules. I've been trying to deploy it to a DO droplet using Ansible and wh
by gnur 10y ago
Swarm mode is great, but I haven't found a good resource yet on how it alters firewall rules. I've been trying to deploy it to a DO droplet using Ansible and whenever I start throwing in ufw rules it overrules those. Ports that should be closed are suddenly open.
And when I use iptables I cannot even start a new swarm when I block some traffic on an Ethernet device that shouldn't even be used by docker..
Anyone have more experience with this?
I'm almost tempted to go to AWS so I don't have to deal with the firewall on the machine itself.
- oron 10y agoWhat I use is tinc to create a kind of a private subnet between all my docker hosts and then only listen with internal dockers on internal ips, ufw rules don't apply to docker networks, docker messes with the iptables directly.
- zenlikethat 10y agoI think the main firewall modification to keep in mind with Docker (swarm mode or not) is that if you publish a port with `--publish`, Docker will pretty much always punch a hole through your existing firewall rules for this port. If you don't want this, simply don't use `--publish` (or the equivalent through the Docker API). Container-to-container communication should be done using containers on the same `docker network` (generally, 'overlay' driver) and should not require exposing ports to the host directly.