zlacker

[parent] [thread] 1 comments
1. drnick+(OP)[view] [source] 2026-01-12 00:33:04
> but there are still a million other pitfalls to fall in to if you are not a full time system admin.

Pro tip: After you configure a new service, review the output of ss -tulpn. This will tell you what ports are open. You should know exactly what each line represents, especially those that bind on 0.0.0.0 or [::] or other public addresses.

The pitfall that you mentioned (Docker automatically punching a hole in the firewall for the services that it manages when an interface isn't specified) is discoverable this way.

replies(1): >>jsrcou+33
2. jsrcou+33[view] [source] 2026-01-12 00:55:47
>>drnick+(OP)
Thanks, didn't know about this one.
[go to top]