Behavior of docker run -P binding to all interfaces without operator warning
When using the docker run -P flag, Docker publishes every port declared in the image’s EXPOSE instructions to a randomly chosen high‑numbered host port. The mapping is always bound to the wildcard address 0.0.0.0 , making the service reachable on all network interfaces unless the host firewall blocks it. The operator receives no automatic notification that a