Docker and the firewall trap
Docker is excellent on bare metal. It also silently punches holes through the firewall you carefully configured, and almost nobody notices.
The trap
Publish a port with -p 5432:5432 and Docker writes its own rules
straight into the DOCKER chain — which is evaluated
before the rules you wrote. Your carefully closed firewall says the
database is private. The internet disagrees, and the scanners find it within the
hour.
We see this regularly in abuse reports: the customer is certain the port was closed, and the firewall says so too.
How to avoid it
- Bind to localhost when the service is only for the host:
-p 127.0.0.1:5432:5432. That one change fixes most of it. - Put containers that only talk to each other on an internal Docker network and publish nothing at all.
- If you must filter published ports, use the
DOCKER-USERchain. It is the one chain Docker leaves alone, and it is evaluated first. - Check what is actually reachable from outside, not what you think is:
ss -ltnpon the machine, and a port scan from somewhere else.
Other things worth knowing on bare metal
Put /var/lib/docker on a filesystem with room — images and
volumes grow faster than anyone expects, and a full disk takes the whole machine
down. Prune on a schedule. And watch your logging driver: default JSON logs grow
without limit unless you cap them.
Containers are not a security boundary
A container shares the kernel. Root in a container is a short step from root on the machine if something is misconfigured. If you run untrusted workloads, use virtual machines rather than containers — see running virtual machines.
Still stuck? Mail support@novogara.com — an engineer answers, at any hour. Back to the knowledge base