Comment on PSA: Docker nukes your firewall rules, and replaces them with its own.

<- View Parent
adam@doomscroll.n8e.dev ⁨8⁩ ⁨months⁩ ago

But… You literally have ports rules in there. Rules that expose ports.

You don’t get to grumble that docker is doing something when you’re telling it to do it

Dockers manipulation of nftables is pretty well defined in their documentation. If you dig deep everything is tagged and natted through to the docker internal networks.

As to the usage of the docker socket that is widely advised against unless you really know what you’re doing.

source
Sort:hotnewtop