पाठ 19 / 25
Exposure and Security
Publish deliberately.
Minimal published ports
Every published port is reachable from outside the container network, and Docker's port publishing can bypass some host firewall rules (such as ufw), a frequent surprise. Publish only the entry point (a reverse proxy on 80/443), bind development ports to 127.0.0.1, and keep databases and internal services unpublished. Run containers as non-root users where images allow, and keep images updated.
Exposure review
Check every ports entry.
service ports verdict
proxy "80:80", "443:443" needed: public entry point
api "3000:3000" (override) dev only; remove in production
db none good: reachable only as db:5432
adminer "8081:8080" (profile) debug only; bind to 127.0.0.1Check host firewall interaction
Remember that published Docker ports may bypass ufw rules; test from another machine before trusting a firewall.
त्वरित जाँच: Which service should normally publish ports in production?
- Internal workers
- The database
- Every service
- The reverse proxy or entry point
Answer
The reverse proxy or entry point — Expose the front door only.