Container ports and management interfaces
A container being reachable from its host does not mean it should be reachable from the Internet. Published container ports and host firewall settings must be reviewed together. Docker can manage firewall rules itself, which changes how some traffic is processed.
Review the exposure
- List published ports and the interfaces they bind to; identify which endpoints should be public, private or host-only.
- Keep administrative APIs, databases and dashboards behind the agreed restricted access path.
- Review runtime privileges, mounted host directories and access to the container-management socket.
- Test allowed and blocked connections from appropriate external and internal locations after changes.
Do not assume a host firewall rule alone blocks every published container port. Send the deployment topology and redacted configuration if you need a review. Avoid exposing a container-management API without a designed authentication and network-control arrangement.
Further reading: Docker: packet filtering and firewalls