This is right, I remember now - docker does mangle your iptables chains. I remember fighting with this a while back.
Terrible practice, in my opinion. Docker shouldn't be touching firewall stuff.
Terrible practice, in my opinion. Docker shouldn't be touching firewall stuff.
It's not as powerful as the later tables in the chain (see https://upload.wikimedia.org/wikipedia/commons/3/37/Netfilte... ) but a lot more robust.
For most container purposes, host networking and the default process namespace is absolutely fine, and reduces a lot of problems with interacting with containerized apps. 95% of the use case of containers is effectively just a chroot wrapper. If you need more features, this should be optional. This would also make rootless federated containerized apps just work. But nobody wants to go back to incremental features if Docker gives them everything at once.