Kingsfordweg 151, 1043GR Amsterdam, The Netherlands ● 24/7 support — support@novogara.com
Knowledge base

Docker and the firewall trap

Docker is excellent on bare metal. It also silently punches holes through the firewall you carefully configured, and almost nobody notices.

The trap

Publish a port with -p 5432:5432 and Docker writes its own rules straight into the DOCKER chain — which is evaluated before the rules you wrote. Your carefully closed firewall says the database is private. The internet disagrees, and the scanners find it within the hour.

We see this regularly in abuse reports: the customer is certain the port was closed, and the firewall says so too.

How to avoid it

  • Bind to localhost when the service is only for the host: -p 127.0.0.1:5432:5432. That one change fixes most of it.
  • Put containers that only talk to each other on an internal Docker network and publish nothing at all.
  • If you must filter published ports, use the DOCKER-USER chain. It is the one chain Docker leaves alone, and it is evaluated first.
  • Check what is actually reachable from outside, not what you think is: ss -ltnp on the machine, and a port scan from somewhere else.

Other things worth knowing on bare metal

Put /var/lib/docker on a filesystem with room — images and volumes grow faster than anyone expects, and a full disk takes the whole machine down. Prune on a schedule. And watch your logging driver: default JSON logs grow without limit unless you cap them.

Containers are not a security boundary

A container shares the kernel. Root in a container is a short step from root on the machine if something is misconfigured. If you run untrusted workloads, use virtual machines rather than containers — see running virtual machines.


Still stuck? Mail support@novogara.com — an engineer answers, at any hour. Back to the knowledge base