3 ms·
The real answer is that OP is using docker wrong. If you „publish“ a port, your firewall gets amended. This is clearly stated in the documentation. If you do no
by selfmodruntime 4y ago
The real answer is that OP is using docker wrong. If you „publish“ a port, your firewall gets amended. This is clearly stated in the documentation. If you do not wish for that to happen, and instead want to use a reverse proxy, you „expose“ a port instead and reroute the requests into the docker bridge network.
- LinAGKar 4y agoNo, it isn't. Looking at the documentation (https://docs.docker.com/compose/compose-file/compose-file-v3/#ports https://docs.docker.com/compose/compose-file/compose-file-v3...), it doesn't mention the firewall anywhere.
- selfmodruntime 4y agoIt clearly states “this will publish the mentioned port to the outside world”. How do you expect this to work? Magic?
- allarm 4y agoExcept it is not clear at all and should mention the firewall changes. I expect that publishing means listening on 0.0.0.0, not messing with the firewall.
- selfmodruntime 4y agoSee my comment above. Firewall changes are clearly mentioned under the section "published ports". What you expect does not matter. What you're thinking of is exposing. It's even in the word "publish". The documentation has two sections entirely devoted to the terms. It's in the section "container networking", which is marked as required reading by the docs. It's not dockers fault that you're copy pasting configuration examples from medium blogs. [0]: https://docs.docker.com/config/containers/container-networking/#published-ports https://docs.docker.com/config/containers/container-networki...
- allarm 4y agoYou know, it would be nice for you to actually read the docs before posting insulting comments. > This creates a firewall rule in the container We’re done here.
- LinAGKar 4y agoNo, it doesn't. That's not written anywhere on the page. And even if it were, the obvious interpretation of "outside world" would just be that it's available outside the container. And maybe that it's bound to the external network interfaces, but not that it bypasses the firewall.
- selfmodruntime 4y agoThe documentation clearly states that ports are published. You just didn't follow up on it. Publishing is a docker term different from exposing. There is information on the page about exposing a port without publishing it. Under `long syntax` there is the following information: "published: the publicly exposed port" [0]. How much more clear than "publicly exposed" can you get? What is a published port? Again, look in the documentation, it's clearly states there [1]. You need to learn to read the documentation of potentially dangerous tools fully. If you don't, you're in for a world of hurt. The outside world is clearly just that. [0]: https://docs.docker.com/compose/compose-file/compose-file-v3/#ports https://docs.docker.com/compose/compose-file/compose-file-v3... [1]: https://docs.docker.com/config/containers/container-networking/#published-ports https://docs.docker.com/config/containers/container-networki...