3 ms·
This has been a major pain point for me. Despite my `firewalld` configuration only allowing specific traffic, all my containers were exposed. My current policy
by l3s2d 6y ago
This has been a major pain point for me. Despite my `firewalld` configuration only allowing specific traffic, all my containers were exposed.
My current policy is to set `"iptables": false` in Docker's `daemon.json` on any public machine. I don't understand why this isn't the default.
- Nullabillity 6y ago> My current policy is to set `"iptables": false` in Docker's `daemon.json` on any public machine. I don't understand why this isn't the default. If you don't muck with iptables then you need a (slow) userspace proxy to expose your pods. That also means losing things like the source IP address for any incoming connections.
- l3s2d 6y agoInteresting, I haven't noticed any slowdown, but I am running fairly low traffic services. I do see that RemoteAddr is from a private IP range. Luckily I'm not using this information anywhere, but good to know.