That page does not address rootless Docker, which can be installed (not just run) without root, so it would not have the ability to clobber firewall rules.