Docker publishes port port past the firewall
ufw says this port is closed, but Docker opens it anyway, so it can be reached from the internet.
bind the port to 127.0.0.1 in docker-compose.yml, then
docker compose up -d serviceReferenceThe 22 checks
Security checkdocker-firewall
The ports Docker publishes on all addresses, and the ufw rules for them.
It needs root for part of what it reads. Reading the ufw rules and the Docker socket needs root. Without root, that part is skipped and never counted as passed. Run sudo kiyesi scan to include it.
The report lists it as passed, in these words:
Docker publishes port port past the firewall
ufw says this port is closed, but Docker opens it anyway, so it can be reached from the internet.
bind the port to 127.0.0.1 in docker-compose.yml, then
docker compose up -d service