I avoid most docker problems by running unprivileged containers via rootless podman, on a rocky-linux based host with selinux enabled.
At this point docker should be considered legacy technology, podman is the way to go.
At this point docker should be considered legacy technology, podman is the way to go.
But regardless of software used, it would have led to the same conclusion, a vulnerable service running on the open internet.
Edit: just confirmed this to be sure.
$ podman run --rm -p 8000:80 docker.io/library/nginx:mainline
$ podman ps
CONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES
595f71b33900 docker.io/library/nginx:mainline nginx -g daemon o... 40 seconds ago Up 41 seconds 0.0.0.0:8000->80/tcp youthful_bouman
$ ss -tulpn | rg 8000
tcp LISTEN 0 4096 *:8000 *:* users:(("rootlessport",pid=727942,fd=10))