# Exposure and Security — Docker Compose

Source: https://www.skillbyai.com/en/docker-compose/n-expose

> Publish deliberately.

## Minimal published ports

Every published port is reachable from outside the container network, and Docker's port publishing can bypass some host firewall rules (such as ufw), a frequent surprise. Publish only the entry point (a reverse proxy on 80/443), bind development ports to 127.0.0.1, and keep databases and internal services unpublished. Run containers as non-root users where images allow, and keep images updated.

## Exposure review

Check every ports entry.

```text
service   ports                  verdict
proxy     "80:80", "443:443"     needed: public entry point
api       "3000:3000" (override) dev only; remove in production
db        none                   good: reachable only as db:5432
adminer   "8081:8080" (profile)  debug only; bind to 127.0.0.1
```

## Check host firewall interaction

Remember that published Docker ports may bypass ufw rules; test from another machine before trusting a firewall.

**Quiz:** Which service should normally publish ports in production?

- [ ] Internal workers
- [ ] The database
- [ ] Every service
- [x] The reverse proxy or entry point

*Answer:* The reverse proxy or entry point. Expose the front door only.
