3 ms·
By default, as the docs very clearly state, ‘docker run’ doesn’t make network changes. The blog post was written by someone who has a compose file which change
by Godel_unicode 4y ago
By default, as the docs very clearly state, ‘docker run’ doesn’t make network changes.
The blog post was written by someone who has a compose file which changes this default behavior, which is extremely unsurprising as that is the entire purpose of compose files. If you change the default behavior, then the default behavior no longer applies and you should read the docs pertaining to how you changed the behavior.
- chaps 4y agoYou're being really generous to the documentation at Docker. It stinks and doesn't make it clear that it punches a hole in your firewall. Neither the compose quickstart [1], nor the compose specification [2] mention anything about iptables nor firewalls. The compose specification adds more details than the quickstart, but... it's obtuse, and overall a 12,000 word document! Surely that incredibly important information that has demonstrably and unexpectedly led to external access should be contained in either of these documents! Surely you can agree that their documentation should contain either the word "iptables" or "firewall"?! [1] https://docs.docker.com/compose/gettingstarted/ https://docs.docker.com/compose/gettingstarted/ [2] https://docs.docker.com/compose/compose-file/ https://docs.docker.com/compose/compose-file/
- selfmodruntime 4y agoThey mention that the port will be published to the internet. Usage of iptables is implementation detailed. They say to make sure to secure it. What else do you want? There is documentation on the behavior in the “docker for Linux” page
- chaps 4y agoI want a damn mention of exactly what is changing on my system!! Why is that hard to understand and why are you trivializing such a big change? This isn't like a config file change that's OS implementation dependent. It's a freaking firewall change that has no obvious mention anywhere in its documentation! That's huge!
- selfmodruntime 4y agoWell, here you go I guess? https://docs.docker.com/network/iptables/ https://docs.docker.com/network/iptables/ I found this right in the docker for linux documentation. Can I ask, how else would you expect traffic to arrive at your container when you publish a port on the internet?
- Godel_unicode 4y agoThey have an absurd amount of detail, you just have to bother to actually read. Linked directly from the overview, after explaining why it’s not on the platform-independent explain, is exactly what you asked for. Tl;dr - If you need to add rules which load before Docker’s rules, add them to the DOCKER-USER chain. https://docs.docker.com/network/iptables/ https://docs.docker.com/network/iptables/
- chaps 4y agoAll I'm saying is they can do a better job presenting the information so these things are more readily findable. People are calling this a footgun for a reason. And no, that link isn't mentioned in the docker overview page[1]. Unless you're talking about another overview, which... come on, lol. Seriously, there's so much room for consolidation and accessibility of their documentation. In terms of relaying information on side effects and how to identify those side effects, this is so much less approachable than pandas and sqlalchemy documentation, and that's saying something. [1] https://docs.docker.com/get-started/overview/ https://docs.docker.com/get-started/overview/
- Godel_unicode 4y agoPeople who read the docs aren’t calling these things footguns though. If you look through the comments section here it’s full of people saying the same thing I’m saying. Just take the L and do the reading.
- chaps 4y agoThe fact that you can't admit that the documentation has wiggle room for improvement here is telling. But by all means keep thinking this was a competition deserving of Ls and continue to miss the simple point. Peace and good luck, friend.
- Godel_unicode 4y agoI just wish you’d read the docs before deciding they’re bad. But feel free to creatively misinterpret responses as you see fit. Doc updates aren’t free, let’s not waste effort fixing a problem that doesn’t exist when there are much better uses for that effort. Moving the words around isn’t going to effect their ability to be understood by those who refuse to actually put eyes on them.