Description
A port mapping such as 7000:8000 can make the service accessible on all host network interfaces by default.
For development or internal-only services, binding to a required interface such as 127.0.0.1 can reduce exposure. Otherwise, an unintended external access path may remain.
Potential impact
- An internal service may become accessible from an external network.
- Port scans and unauthorized connection attempts may reach the service more easily.
- Controlling network exposure separately for each service becomes harder.
Remediation
- Specify a host IP in
portsto bind only to the required interface. - Limit services that do not need external access to a local interface such as
127.0.0.1. - Separate public and internal services in Compose so their exposure policies are clear.
Examples
The actual service must listen on container port 8000. If clients on other hosts need access, use an approved interface and firewall rules instead of loopback.
Before
yaml
services:
webapp:
image: sample/webapp:latest
ports:
- "7000:8000"
After
yaml
services:
webapp:
image: sample/webapp:latest
ports:
- "127.0.0.1:7000:8000"
Explanation:
- Before: Binding may use all host interfaces, exposing the service more broadly than intended.
- After: Binding to the host loopback address restricts remote access through this published port. Manage application authentication and access between containers separately.