पाठ 19 / 25

Exposure and Security

Publish deliberately.

Minimal published ports

Every published port is reachable from outside the container network, and Docker's port publishing can bypass some host firewall rules (such as ufw), a frequent surprise. Publish only the entry point (a reverse proxy on 80/443), bind development ports to 127.0.0.1, and keep databases and internal services unpublished. Run containers as non-root users where images allow, and keep images updated.

Exposure review

Check every ports entry.

service   ports                  verdict
proxy     "80:80", "443:443"     needed: public entry point
api       "3000:3000" (override) dev only; remove in production
db        none                   good: reachable only as db:5432
adminer   "8081:8080" (profile)  debug only; bind to 127.0.0.1

Check host firewall interaction

Remember that published Docker ports may bypass ufw rules; test from another machine before trusting a firewall.

त्वरित जाँच: Which service should normally publish ports in production?

  • Internal workers
  • The database
  • Every service
  • The reverse proxy or entry point
Answer

The reverse proxy or entry point — Expose the front door only.