3 ms·
Yes but this breaks the very container routing that we need Docker for. An "all or nothing" approach is not ideal.
by hackyhacky 3y ago
Yes but this breaks the very container routing that we need Docker for. An "all or nothing" approach is not ideal.
- drdaeman 3y agoI'm not sure how much this routing is really needed. I use nftables instead of iptables, so I told Docker to not touch anything. I'm gradually getting rid of Docker (NixOS containers powered by systemd-nspawn are more convenient for me at the moment), so I don't have any fancy networking for it - but I still run it. I have a bunch of static nftables rules for the bridge (`iifname "docker0" ct state established,related counter accept` etc.) so the containers can access what they need. And then Docker uses docker-proxy for the exposed ports (paired with appropriate firewall rules when it's not on `lo`, where I have an umbrella `iif "lo" accept`) and it seem to works just fine.