I'm not sure about ufw/firewalld. Maybe docs aren't clear there either
I configured iptables and had no trouble blocking WAN access to docker...
In addition to that there's the default host in daemon.json plus specifying bindings to local host directly in compose / manually.