Restrict host service access from the docker container

Viewed 92

I have two services running in the docker host. Say service A at port 1080 and service B at port 1090. The docker container is running on the default bridge network.

Given a docker host ip address the container running inside the docker host is able to access both service A and service B.

How can I restrict the container connectivity to only service A in the docker host and cut off all the outgoing connections?

I tried these iptables entries but they dont seem to be doing the trick

iptables -A DOCKER-USER -p tcp --destination-port 1080 -s 172.17.0.2/16 -d HOST_IP -j ACCEPT
iptables -A DOCKER-USER -s 172.17.0.2/16 -j DROP
0 Answers
Related