Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

My point is that this is a well-known issue with absolutely catastrophic results when you get it wrong. It would cost the docker app almost nothing to do a quick check on docker run to see if you're on a machine with iptables & ufw enabled, and then violently complain or fail in a very obvious ways like:

*** WARNING YOUR FIREWALL ISN'T WORKING!! RUN AGAIN WITH --my_firewall_is_broken_and_I_accept_the_risks OPTION TO CONTINUE!!! SEE THIS FOR MORE INFO: <hyperlink to docs> ***



Docker could also enumerate the IP addresses on the host, and alert if there are any that aren't in RFC1918 space.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: