5 ms·
It does not bypasses them, it uses the firewall to add forwarding rules to the container. If you read https://www.baeldung.com/linux/docker-container-published-
by masom 3y ago
It does not bypasses them, it uses the firewall to add forwarding rules to the container. If you read https://www.baeldung.com/linux/docker-container-published-port-ignoring-ufw-rules https://www.baeldung.com/linux/docker-container-published-po... there's a bunch of ways to prevent this from happening.
By enabling port forwarding and exposing, you're essentially asking docker to configure the host for it. It's likely a surprising behaviour, but seems like ufw has a bug if you have multiple chains and groups instead of just the default one.
- 3abiton 3y agoFor the average users, it goes over the head
- deleted 3y ago[deleted]
- yjftsjthsd-h 3y ago> It does not bypasses them, it uses the firewall to add forwarding rules to the container. ... yes, it adds a forwarding rule. Which skips over the rest of my firewall rules. One might even say that it bypasses them. > By enabling port forwarding and exposing, you're essentially asking docker to configure the host for it. No, I'm asking docker to listen on that port and pass it through to the container. If I tell nginx to listen on port 80, would you expect it to take that as a "do anything you can to make sure you get port 80, including rewriting the firewall tables to ignore the rule that blocks port 80"?
- tinco 3y agoGP is being annoying and I agree with you for the most part and I feel Docker should have tried to play nicer with the firewall. That said it is a mistake to consider Docker in the same class as nginx. Docker is a system for telling the Linux kernel how to set up the environments of processes. Doing whatever it can at the absolute lowest level of abstraction the kernel offers is kind of its entire gig.
- yjftsjthsd-h 3y agoThat's a fair argument - I disagree, but it's a valid perspective and probably the root of the difference in views. I personally expect docker to be a piece that fits into the system to run containers. If docker expects to effectively be the system at least for things in its domain, then that would explain why it does things that I consider out of its scope. (There's an echo here of the argument about systemd; if you expect systemd to be everything between the kernel and userspace, then of course it includes ex. its own ntpd and cron replacement, whereas if you expect it to be a service manager then every extra function looks like an overreach)
- masom 3y agoThe reason docker is integrating this way is to easily group the rules it introduced. > I feel Docker should have tried to play nicer with the firewall. The problem is on the UFW side not setting up properly when other chains are present. UFW is just a front-end for iptables, and docker integrates with iptables. Can the situation be made better? Likely on the UFW side. https://docs.docker.com/network/packet-filtering-firewalls/#add-iptables-policies-before-dockers-rules https://docs.docker.com/network/packet-filtering-firewalls/#... The docker behaviour is documented... UFW seems buggy in that it only operates on set of prefixed groups instead of looking at all the groups in iptables. Now, looking at the UFW code: https://git.launchpad.net/ufw/tree/src/backend_iptables.py?h=ubuntu/master https://git.launchpad.net/ufw/tree/src/backend_iptables.py?h... it seems to setup it's own chains and ignores everything else. It even filters out all other chains unless they're part of UFW.
- tinco 3y agoYeah I agree, I guess it should have been up to whoever packages Docker for Ubuntu to make sure it plays nice with the standard Ubuntu tooling. Given how Docker forward Ubuntu itself is, it probably should have made UFW aware of Docker. Btw, ouch at that 1400 line python file..
- skibbityboop 3y ago> yes, it adds a forwarding rule. Which skips over the rest of my firewall rules. ... which you explicitly asked it to do by using the -p option.
- yjftsjthsd-h 3y agoNot explicitly, no. The flag is `--publish`, not `--publish-regardless-of-firewall-rules`. It looks for all the world like the usual server --listen or --port options unless you happen to know about this little "feature".
- Dylan16807 3y ago-p explicitly asks for forwarding, it doesn't ask for it to be applied before firewall rules.
- masom 3y agoThe issue is UFW ignoring other firewall rules, Docker just adds itself to iptables, but UFW actively ignores other chains. The bug is on UFW being insecure by design.
- boolemancer 3y agoI wouldn't expect Docker to be listening on anything. Docker isn't proxying any traffic into the container, it's just configuring how ports are forwarded from the host to the container.
- deleted 3y ago[deleted]
- zokier 3y agoits... complicated. depending on things docker might or might not be proxying the traffic. see for example https://github.com/moby/moby/issues/14856 https://github.com/moby/moby/issues/14856 for discussion
- boolemancer 3y agoFair enough, I wasn't familiar with that feature. Seems like introducing unnecessary overhead to me, but I'm also sure there's a reason it exists, so...
- nullindividual 3y agoNo 3rd party application should be able to manipulate firewall rules. Hiding configuration details leads to mistakes.
- paulddraper 3y agoIt's a 2nd party application
- edvinbesic 3y agoUpvoted because you are correct. Calling it a bypass almost implies something more nefarious vs saying docker automatically adds its own forwarding rules.
- southerntofu 3y agoIt's not intended to be nefarious, but it can have bad consequences. I know the docker devs had good intentions to help people expose services, when they introduced this. However, they also "helped" people unwillingly expose services, oops. Just because it was meant to be useful and harmless doesn't mean they didn't actually bypass the firewall rules by adding their own rules.