"ufw allow 443 and I'm firewalled"
ufw only controls the INPUT chain. If you run Docker, it punches iptables rules straight into the DOCKER chain and bypasses ufw completely — your "closed" port 5432 is wide open to the internet.
Proof: iptables -L DOCKER -n shows the published ports ufw never saw.
Fix: bind containers to 127.0.0.1:5432 not 0.0.0.0, or use ufw-docker. Don't trust ufw status alone.
Try it tonight.
Root Access Daily
@RootAccessDaily
"ufw allow 443 and I'm firewalled"
Этот пост опубликован в Telegram-канале Root Access Daily. Подписаться можно по ссылке: @RootAccessDaily.