4 ms·
I was bitten by this as well, luckily I was setting up ufw after docker (and was really surprised that dockerized services showed up in port scan). To be fair,
by fest 5y ago
I was bitten by this as well, luckily I was setting up ufw after docker (and was really surprised that dockerized services showed up in port scan).
To be fair, it did not look to me that docker intentionally punched holes in firewall- it purposefully places it's rules in separate table/queue, which due to way iptables work, hampers the firewall rules.
However, once it became apparent to docker developers, it should have been made a priority to be fixed, as it is counterintuitive default.