Docker is still silently punching holes in your firewall after 5 years
github.com
github.com
https://docs.docker.com/network/iptables/
By default, all external source IPs are allowed to connect to the Docker host. To allow only a specific IP or network to access the containers, insert a negated rule at the top of the DOCKER-USER filter chain.
It should be a big red box with warnings signs all over in the "Getting Started" docs
Admins can be expected to Read-The-Fine-Manual.
For special cases like CI servers where you need to be able to run multiple instances of the same set of containers simultaneously and have them talk to eachother on the same port... better have an external firewall to isolate the machine. Trying to manage the iptables ruleset is a mess (you can't use nftables or iptables-restore), and it's not reliable.
So in case this is new to you, as it was to me up until recently:
> "By default docker is munging the firewall in a way that breaks security - it allows all traffic from all network devices to access the exposed ports on containers."