3 ms·
Wait... people run their databases on public IPs?
by foobarbazetc 5y ago
Wait... people run their databases on public IPs?
- edoceo 5y agoYep. It happens. Welcome to earth.
- jbverschoor 5y agoNo, they run databases that listen to localhost, and then use docker to forward that private binding to the public ip
- drdaeman 5y agoNo, they run database that listens to 0.0.0.0/0 and/or ::0/0 on a private isolated network interface (eth0 inside Docker namespace), then let Docker create a NAT to forward packets from a public network interface on the host to this database. The latter is a mistake. It doesn't ever make sense to expose hosted container ports to host, with the exception of public-facing stuff (like a webserver). The whole backoffice should be on a separate network. And this is how Docker works by default, since forever, unless one very explicitly requests that it exposes ("publishes") the ports. Just don't expose stuff. If the host needs to talk to a database or something, it can always talk to it via that `docker0` (or however it's called, I don't really remember the details) interface. (I believe it doesn't always add a route, because on one of my machines I have to manually add a route so Traefik on a host is able to talk to the containers on a isolated virtual network.)
- jbverschoor 5y agoThat depends in if you use docker networks. By default, -p maps a port, afaik to 0.0.0.0:port. So this is more an issue with the default docker settings than anything else. Yes they should’ve configured, checked, etc. But defaults sound be secure by default
- deleted 5y ago[deleted]