3 ms·
Be careful with docker and ufw though! Any rules you setup in ufw will be ignored by docker, so exposing a container will always open it up to the public even i
by kalev 5y ago
Be careful with docker and ufw though! Any rules you setup in ufw will be ignored by docker, so exposing a container will always open it up to the public even if you specifically denied access through ufw.
- adamddev1 5y agoVery good point, I didn't know this almost got burned by this while learning Docker. What I did was use shared network (for private db connection etc) in a docker-compose file, and then expose the port I wanted to reverse proxy out on by ports: - 127.0.0.1:3000:3000 This way it only exposes it to the local host on the machine without exposing it on the firewall. Then I reverse proxied out port 3000 with NGINX to the outside world. I'm surprised this isn't talked about more in beginner tutorials etc.
- k8sToGo 5y agoTechnically, Docker is adding iptables rules that are ignored by ufw rather than docker ignoring ufw. To fix, just turn off iptables for the docker daemon and add the rules manually to UFW
- dawnerd 5y agoAnd if you don’t want to do that because there are some downsides, make sure you setup container networking correctly and don’t just expose ports just to expose ports. Learned that one the hard way when someone exposed redis.