I don't like how Docker messes with your firewall rules and will even force some degree of iptables dependence on you. I have tried using its DOCKER-USER chain but the results were flaky.

Podman, on the other hand, can be run completely daemonless and rootless meaning it will be not only uninterested but also completely unable to mess with your firewall.

This plus a reverse proxy give me so much versatility for a much lower cognitive cost compared to trying to make Docker behave.

Feels like such a basic thing to have your firewall rules managed strictly by you without any interference...

0

If you have a fediverse account, you can quote this note from your own instance. Search https://mastodon.bsd.cafe/users/jutty/statuses/115413233400711850 on your instance and quote it. (Note that quoting is not supported in Mastodon.)