How does Podman work with the different firewall providers? I can't access a web server migrated from Docker. #29817
|
I'll provide any and all necessary info, so please let me know if I'm missing anything. I found the following issues which may be related (?):
Here's the Compose.yml file for the container: services:
pihole:
container_name: pihole
image: docker.io/pihole/pihole:latest
ports:
# Serve DNS on all 3 interfaces
- "192.168.68.100:53:53/tcp"
- "192.168.68.100:53:53/udp"
- "127.0.0.1:53:53/tcp"
- "127.0.0.1:53:53/udp"
- "[200:f86e:ed65:d1e9:47e0:d308:f265:869b]:53:53/tcp"
- "[200:f86e:ed65:d1e9:47e0:d308:f265:869b]:53:53/udp"
# Serve webpage over local network and yggdrasil
- "192.168.68.100:80:80/tcp"
- "192.168.68.100:443:443/tcp"
- "[200:f86e:eb65:d1e9:47e0:d308:f265:869b]:80:80/tcp"
- "[200:f86e:eb65:d1e9:47e0:d308:f265:869b]:443:443/tcp"
environment:
TZ: 'America/Argentina/Mendoza' # Timezone
# DNS addresses:
FTLCONF_dns_upstreams: |-
1.1.1.1
1.0.0.1
volumes:
- './etc-pihole:/etc/pihole' # Pi-hole's databases and common configuration file
- './etc-dnsmasq.d:/etc/dnsmasq.d' # Make DNS settings persistent
restart: unless-stopped
networks:
- pihole
networks:
pihole:
name: piholeThe web page (only thing I've thoroughly tested) is not accessible at all, not even from the host machine, and I'm stumped. I've checked:
Everything 'just works' if I just use Docker, which I'm trying to move away from. My working theory is that there's some issue with the way Podman handles firewalls and the way I set up the service here, but as I said before, I'm stumped. Thanks for taking the time to read this over, I really appreciate it. |
Replies: 2 comments 5 replies
|
Okay, I'm making some edits because looking back, I wrote this in a frustrated stupor. I believe I may have some new information (edit: Done, I can also append the output of nft list ruleset, but it was a little too extensive.) |
|
Your own nmap output is the most useful thing in the report, and it says the container is not listening on that address at all. On rootful podman, a published port is a real listening socket that podman opens and holds on the host while the container runs. If the container were up and publishing Two things in the compose file explain it. The two yggdrasil addresses are not the same address. The DNS ports use and the container stays in And One more thing for when it does start: the About UFW in general, since that was the theory: the friction with podman is the opposite of what you are seeing. netavark installs its own firewall rules (iptables or nftables, depending on how your podman was built and on |
Those scans pin it down, and they also show I had the UFW part of my first reply backwards. It is UFW, just not on the path you allowed.
With the container stopped, a SYN to port 80 reaches the host itself, UFW's
80/tcpallow lets it into INPUT, nothing listens there, and the kernel answers with a RST:closed. With the container running, podman rewrites that SYN to the container's address before routing, so it no longer goes to INPUT at all. It goes through FORWARD, and UFW's default for forwarded traffic isdeny (routed)(DEFAULT_FORWARD_POLICY="DROP"in/etc/default/ufw), which drops it silently:filtered. Yourufw allowrules only apply to INPUT, so they never see it. From the server i…