6 ms·
> By default, when you create or run a container using docker create or docker run, the container doesn’t expose any of it’s ports to the outside world. It doe
by selfmodruntime 4y ago
> By default, when you create or run a container using docker create or docker run, the container doesn’t expose any of it’s ports to the outside world.
It doesn't? You're explicitly telling it to do so and then go on crying about how docker is awful.
- chaps 4y agothat's word for word from: https://docs.docker.com/config/containers/container-networking/ https://docs.docker.com/config/containers/container-networki...
- Godel_unicode 4y agoBy default, as the docs very clearly state, ‘docker run’ doesn’t make network changes. The blog post was written by someone who has a compose file which changes this default behavior, which is extremely unsurprising as that is the entire purpose of compose files. If you change the default behavior, then the default behavior no longer applies and you should read the docs pertaining to how you changed the behavior.
- chaps 4y agoYou're being really generous to the documentation at Docker. It stinks and doesn't make it clear that it punches a hole in your firewall. Neither the compose quickstart [1], nor the compose specification [2] mention anything about iptables nor firewalls. The compose specification adds more details than the quickstart, but... it's obtuse, and overall a 12,000 word document! Surely that incredibly important information that has demonstrably and unexpectedly led to external access should be contained in either of these documents! Surely you can agree that their documentation should contain either the word "iptables" or "firewall"?! [1] https://docs.docker.com/compose/gettingstarted/ https://docs.docker.com/compose/gettingstarted/ [2] https://docs.docker.com/compose/compose-file/ https://docs.docker.com/compose/compose-file/
- selfmodruntime 4y agoThey mention that the port will be published to the internet. Usage of iptables is implementation detailed. They say to make sure to secure it. What else do you want? There is documentation on the behavior in the “docker for Linux” page
- chaps 4y agoI want a damn mention of exactly what is changing on my system!! Why is that hard to understand and why are you trivializing such a big change? This isn't like a config file change that's OS implementation dependent. It's a freaking firewall change that has no obvious mention anywhere in its documentation! That's huge!
- selfmodruntime 4y agoWell, here you go I guess? https://docs.docker.com/network/iptables/ https://docs.docker.com/network/iptables/ I found this right in the docker for linux documentation. Can I ask, how else would you expect traffic to arrive at your container when you publish a port on the internet?
- Godel_unicode 4y agoThey have an absurd amount of detail, you just have to bother to actually read. Linked directly from the overview, after explaining why it’s not on the platform-independent explain, is exactly what you asked for. Tl;dr - If you need to add rules which load before Docker’s rules, add them to the DOCKER-USER chain. https://docs.docker.com/network/iptables/ https://docs.docker.com/network/iptables/
- chaps 4y agoAll I'm saying is they can do a better job presenting the information so these things are more readily findable. People are calling this a footgun for a reason. And no, that link isn't mentioned in the docker overview page[1]. Unless you're talking about another overview, which... come on, lol. Seriously, there's so much room for consolidation and accessibility of their documentation. In terms of relaying information on side effects and how to identify those side effects, this is so much less approachable than pandas and sqlalchemy documentation, and that's saying something. [1] https://docs.docker.com/get-started/overview/ https://docs.docker.com/get-started/overview/