Behavior of docker run -P binding to all interfaces without operator warning
0 reputation · 26 Apr 2022, 12:26 UTC
When using the docker run -P flag, Docker publishes every port declared in the image’s EXPOSE instructions to a randomly chosen high‑numbered host port. The mapping is always bound to the wildcard address 0.0.0.0, making the service reachable on all network interfaces unless the host firewall blocks it. The operator receives no automatic notification that a port has been exposed in this way, and the decision to restrict access relies entirely on external firewall rules.
Given that the -P flag is intended for quick testing or development, there is currently no built‑in mechanism to limit the binding to a specific interface or to warn the user when a wildcard binding occurs. This leaves an unresolved design decision about whether Docker should provide additional safeguards against accidental public exposure while preserving the convenience of automatic port publishing.
-P bindings to a particular host interface or address?
Could Docker emit a warning when -P results in a 0.0.0.0 binding?
Is there a recommended practice to mitigate the risk of unintended exposure without abandoning the -P flag?