3 ms·
Lol, that’s the same footgun I discovered myself when was checking open ports. Who that wise guy in Docket team who decided to pass default firewall rules and o
by glintik 4y ago
Lol, that’s the same footgun I discovered myself when was checking open ports. Who that wise guy in Docket team who decided to pass default firewall rules and open containers ports to public?
- berkle4455 4y agoHow would docker know which interface is publicly accessible? Binding to localhost isn’t useful for actual deployments. Why not utilize the ingress/egress firewall rules offered by nearly all cloud/vps providers instead of relying on iptables of an instance?
- mhitza 4y ago> Why not utilize the ingress/egress firewall rules offered by nearly all cloud/vps providers instead of relying on iptables of an instance? Because its advantageous to use all the facilities your OS provides. The fact that docker bypasses the highlevel firewall on the system and pokes holes through via iptables is very unfortunate, and something I myself have learned as recently as 2019. Related to your question about docker knowing which interface to bind to, it generally sets up it's own docker network interface. With a highlevel firewall it's trivial to attach that interface to any firewall zone created (eg public zone with only specific ports exposed).
- MrPowerGamerBR 4y agoYou can tame Docker with iptables by using the DOCKER-USER chain There are a bunch of tutorials about how to tame Docker, but this one is the solution that I use and it was the simplest that I've found https://unrouted.io/2017/08/15/docker-firewall/ https://unrouted.io/2017/08/15/docker-firewall/ This way, even if you mistakenly expose your container ports to 0.0.0.0, you won't be able to access them until exposing them with iptables
- nickstinemates 4y ago> Who that wise guy in Docket team who decided to pass default firewall rules and open containers ports to public? This is pure ignorance and slandering the Docker team for it seems weird.
- yjftsjthsd-h 4y agoWhat's ignorant about it? Or wrong, for that matter, since it can't be "slander" if it's true. Docker does bypass default firewall rules and expose container ports to the public. If I run anything else on a server (apache2, say), and tell it to bind to 0.0.0.0:80, it doesn't matter, because the firewall will block it. If I tell a docker container to bind to 0.0.0.0:80, it magically skips over any other protections and immediately exposes itself to the world.
- nickstinemates 4y agoHow is it that you can spawn many containers and have them all bind to `0.0.0.0:80` in your example? Try doing the same with Apache2. Multiple instances listening on Port 80. This is the difference, and the source of ignorance.
- yjftsjthsd-h 4y agoYou... can't? I mean, you can bind it inside the container, of course, but you can't bind it on the host ("publish"), which seems like the analogous thing to running on the host. Also, AIUI podman manages to not ignore the firewall, so it's not like it's some inherent issue.
- nickstinemates 4y agoYou can. Because each container has its own ip address. Publish IS EXACTLY the creation of the iptables entry to route traffic over the docker0 bridge.
- convolvatron 4y agothats a really weird take. the whole point of developing and using infrastructure projects like docker is to package up best practices and let other people leverage them without becoming experts themselves. maybe its fair to say that we shouldn't attempt to find an individual to blame. but that doesn't mean docker as an organization didnt screw up here