10 ms·
The 1st thing only happens when users explicitly misconfigure docker, the other one is a real security problem when docker runs in root mode.
by bionade24 4y ago
The 1st thing only happens when users explicitly misconfigure docker, the other one is a real security problem when docker runs in root mode.
- dns_snek 4y agoThere's nothing "explicit" about this sort of misconfiguration, that's exactly why it catches so many people out. It's a bad/insecure default that serves no practical purpose. If Docker bound to 127.0.0.1 by default and required you to explicitly bind to "0.0.0.0" to expose the container to the outside world, the frequency of dangerous misconfigurations would likely be reduced by 95%+. It would still catch people who bind to 0.0.0.0 and expect the traffic to be blocked by UFW, but that's a different issue. `iptables: false` is a very crude solution, they should offer something like `iptables: "manual"` where Docker only touches its own iptables chains and lets you wire them up to your own UFW/iptables chains in a sane way.