▲ | fulafel 12 days ago | ||||||||||||||||||||||
From docker-compose
This will cause Docker to expose this to the internet and even helpfully configure an allow rule to the host firewall, at least on Linux. | |||||||||||||||||||||||
▲ | rubslopes 12 days ago | parent [-] | ||||||||||||||||||||||
Good catch. OP, exposing your application without authentication is a serious security risk! Quick anecdote: Last week, I ran a Redis container on a VPS with an exposed port and no password (rookie mistake). Within 24 hours, the logs revealed someone attempting to make my Redis instance a slave to theirs! The IP traced back to Tencent, the Chinese tech giant... Really weird. Fortunately, there was nothing valuable stored in it. | |||||||||||||||||||||||
|