4ca9e588b5a8752f0b36f5aec1fc48164265f513
Docker bypasses ufw and exposes 0.0.0.0-bound ports directly via iptables DNAT rules, even when ufw default policy is deny. Bind every service port to 127.0.0.1 so only nginx (and SSH tunnels for wizard) can reach them from outside.
Description
No description provided
Languages
Shell
100%