I have application running inside docker container that is accessed from Internet via port 443 to:
– human users (web/user interface)
– machines (REST API)
Application requires access to the Internet and intranet outside container over all possible ports.
While running there are 2 network interfaces (example IDs):
– docker0
– eth01 (physical network adapter)
Initial setup was default bridge network mode.
Problem with bridged mode was that application could not establish FTP, SFTP, SSH connection to the hosts within intranet if target host is in the same subnet as docker host. I have no any Docker expert neither network admin beside me to explain me all details so AI Claude explained me that it is the problem because packets do not reach further than eth01. It advised me to:
– switch to network host
– to configure docker host redhat OS firwald to map all traffic from eth01 to docker0 and vice versa.
I updated docker compose yml config file (set host mode and remove port mappings as in host mode port mapping is not possible).
I did HARD doceker compose restart
After change application in docker container could only SFTP, FTP, SSH machines in same subnet. All other hosts (in intranet and Internet) become unavailable – it seems as DNS resolution didn't work.
I rollback everything to bridge network mode as exit to Internet and DNS resolution is more important than access to couple hosts in the same subnet.
Can anyone help me to anticipate what are important facts for my docker network configuration so that application in docker container properly establishes connections.
Docker Host is RedHat Linux with SeLinux enabled and firewald enabled
Docker application has liberate access to all ports and IPs internal and external (Internet)
Thank you very much!!
Source: r/docker · by /u/Vivid_Rate_6118