Actually you have to manually remove port 3000 from container forwarding (which will also override whatever fierwall you have)
If you don't, it's going to be accessible via :3000 AND whatever domain you choose over https:// (provided it can use let's encrypt cert). So it's a bit of a gotcha.