3 ms·
That is not an obscure issue. The common manifestation is breaking iptables rule (with expose port) and messing up software firewall has caused a lot of wasted
by NhanH 3y ago
That is not an obscure issue. The common manifestation is breaking iptables rule (with expose port) and messing up software firewall has caused a lot of wasted hours and security issues.
- insanitybit 3y agoAnd yet the example they chose was "It broke wifi on a train's shitty network"
- codetrotter 3y agoDocker uses 172.17.0.0/16 subnet range by default. There is nothing shitty about the network on the train for also using this same IP address range. https://en.wikipedia.org/wiki/Private_network https://en.wikipedia.org/wiki/Private_network 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16 You might be used to seeing addresses from 192.168.0.0/24 and 192.168.1.0/24 in home networks, and addresses from 10.x.y.0/24 in corporate internal networks. But all of 172.16.0.0/12 has exactly the same kind of purpose as do 10.0.0.0/8 and 192.168.0.0/16. The people that set up the network on the train did nothing wrong for using a subnet of 172.16.0.0/12.
- justin_oaks 3y agoDoes anyone configure other IP ranges in Docker? I know there are other reserved IP ranges you might get away with. There's the CGNAT IP range 100.64.0.0/10, and there's the link-local IP range 169.254.0.0/16. These are unused in most situations and may work fine for Docker networks.
- doubled112 3y agoI do. I have a few VLANs and subnets at home. Docker Compose creates a new network for every project, and eventually overlaps with something important. They are fairly large ranges by default, so you end up taking up a lot of address space fast if you're not careful. This is especially wasteful because some of the Docker networks only contain two hosts, but are (from memory) a /24 or maybe even a /20. Easier to handle it manually.