You're right in that it is better to only open ports that you require - will update :)
I'm not quite sure what you mean by "Additionally out of the box fail2ban won't work with docker containers". fail2ban is installed locally on the pi.
I'm not quite sure what you mean by "Additionally out of the box fail2ban won't work with docker containers". fail2ban is installed locally on the pi.
If you had installed for example your web server on a container, the logs will be on the container. Fail2ban on the host won’t be able to parse the ones inside the container (by default, needs more work).