Add disclaimer about Docker firewall handling
Transcript of my support ticket:
A few hours ago, I read about the fact that Docker, in most cases, exposes ports passed through the host externally without any warning or information about doing it.
A few sources:
https://www.jeffgeerling.com/blog/2020/be-careful-docker-might-be-exposing-ports-world
https://blog.newsblur.com/2021/06/28/story-of-a-hacking/
https://github.com/moby/moby/issues/22054
https://github.com/moby/moby/issues/4737
Since you have guides regarding Docker in your documentation, would it be possible to add a big and noticeable disclaimer to each page discussing Docker to inform the Webdock users about this?
It shouldn't be necessary to explain how to fix it (but will be well received if done, however the workaround differs between environments sadly), just to inform this security issue exists.
Log in to comment and vote
Comments4
May 5, 2023
We added a disclaimer here: https://webdock.io/en/docs/how-guides/docker-guides/how-to-install-and-run-docker-containers-on-webdock-ubuntu-server
Let us know if you feel other places should receive this disclaimer
Epsilon PS _ Paul Schiffer
May 5, 2023
Arni from Webdock: I would add it to these two articles as well:
https://webdock.io/en/docs/how-guides/docker-guides/how-to-create-and-manage-docker-networks-and-docker-volumes
https://webdock.io/en/docs/how-guides/docker-guides/how-to-install-and-run-docker-containers-using-docker-compose
Epsilon PS _ Paul Schiffer
May 5, 2023
Arni from Webdock: Also, when you add Docker dashboard functionality in the future, the disclaimer should show up there as well or be remediated by the dashboard automatically, steering the user away from public any access.
Arni Johannesson
May 5, 2023
Epsilon PS _ Paul Schiffer: Agreed :) We will add the notice in those two locations as well. As always: Thanks for the feedback Paul!