3 ms·
I'd love something sorta like this but for Docker containers running APIs or web services. Like: containerA: all outbound traffic allowed containerB: no outbo
by meonkeys 2y ago
I'd love something sorta like this but for Docker containers running APIs or web services. Like:
containerA: all outbound traffic allowed
containerB: no outbound traffic allowed, except to reply to a client
containerC: may only reach out to updates.example.com
Is this just per-container iptables? I could wedge iptables into existing images but it seems like a lot of work.
Or maybe something with iptables on the host?
- rnmmrnm 2y agojust my two cents that netfilter (for which iptables is a frontend) is a kernel subsystem and therefore global to all containers on host.