6 ms·
For most public-facing deployed services, I tend to run docker in `--iptables=false` mode with `--net=host` containers. Then you can just use normal iptables IN
by terom 5y ago
For most public-facing deployed services, I tend to run docker in `--iptables=false` mode with `--net=host` containers. Then you can just use normal iptables INPUT rules with your choice of firewall tooling. Works great with IPv6 as well, and fewer moving parts.
For special cases like CI servers where you need to be able to run multiple instances of the same set of containers simultaneously and have them talk to eachother on the same port... better have an external firewall to isolate the machine. Trying to manage the iptables ruleset is a mess (you can't use nftables or iptables-restore), and it's not reliable.