19 ms·
This is a valid concern when running Dockerized containers and it caught me years ago when I was deploying my first containerized servers to the wild. It was a
by netsectoday 4y ago
This is a valid concern when running Dockerized containers and it caught me years ago when I was deploying my first containerized servers to the wild. It was a "holy shit" moment, but anyone who is trusted (getting paid) to secure servers should stumble upon this pretty quickly.
1) Add firewall rules to UFW
2) Test firewall rules
3) Notice you can bypass those rules (they didn't take)
4) iptables -vL
5) Why the fuck is there a DOCKER-USER chain at the top of FORWARD, and it's above all of my UFW entries?
6) Adjust iptables without UFW
7) Realize adjustment didn't work after reboot because Docker dynamically adds the iptables entries on start (above my entries)
8) Add my chain to the bottom of the DOCKER-USER chain, before the RETURN all
9) Verify firewall rules
10) Reboot server
11) Verify firewall rules
This is probably a huge issue today because most people can't do their job correctly. They are pulling that sweet salary, bullshitting their stand-ups, zoning out on video calls, and squirming until they can turn netflix back on while working remotely. You just need to have enough attention span to verify your work and dig in when things are broken.
- hda111 4y agoYou should try podman instead. The rootless version obviously can’t bypass UFW. When I tested podman as root it also didn’t punch holes into UFW. Not sure how it is today however.