Description
TCP and UDP port numbers range from 0 to 65535, with 0 reserved. Use an appropriate value from 1 to 65535 for a fixed service port. An out-of-range EXPOSE value can cause a build error.
EXPOSE declares port metadata. It does not make the application listen on that port or publish it on the host.
Potential impact
- An invalid declaration can fail the build or mislead tools about the service port.
- A mismatch with the actual listener can lead to an incorrect port mapping and an unreachable service.
Remediation
- Set EXPOSE to the service’s actual port from 1 to 65535 and the required TCP or UDP protocol.
- Check application listeners, runtime port publication and firewall policy separately. A valid port number alone does not enforce access controls.
Examples
The existing NGINX examples compare port declarations only. Use a supported image for actual deployment. Port 80 in the after-example matches the example image’s default HTTP listener.
Before
dockerfile
FROM nginx:1.27-alpine
EXPOSE 65536
CMD ["nginx", "-g", "daemon off;"]
After
dockerfile
FROM nginx:1.27-alpine
EXPOSE 80
CMD ["nginx", "-g", "daemon off;"]
Explanation:
- Before: 65536 is outside the valid port-number range.
- After: Port 80 matches NGINX’s default HTTP listener. Host port publication must be configured separately.