CentOS 7下如何阻止MongoDB Docker容器的外部访问?
Hey there, let's break down why your MongoDB container is still reachable from the public internet even after blocking port 27017 with firewall-cmd, and walk through the fixes step by step.
1. Fix the Docker Compose Port Binding (Most Critical Step)
The likely culprit here is that your Docker Compose config is binding the container's 27017 port to all network interfaces (0.0.0.0) on your server, which bypasses your firewall rules for external access.
Open your docker-compose.yml file and modify the ports section to explicitly bind only to the server's loopback interface (127.0.0.1):
services: mongodb: image: mongo # Other configs like volumes, environment vars go here ports: - "127.0.0.1:27017:27017" # Bind only to local loopback
This tells Docker to expose the MongoDB port only to processes running on the server itself, not to any external IPs.
After making this change, restart your container to apply the new config:
docker-compose down && docker-compose up -d
2. Verify the Port Listening Status
To confirm the change worked, check which interface the port is listening on using either netstat or ss:
ss -tulpn | grep 27017
You should see output that shows 127.0.0.1:27017 instead of 0.0.0.0:27017. If it still shows 0.0.0.0, double-check your docker-compose.yml for typos and restart the container again.
3. Handle Docker's Automatic IPTables Rules
Docker automatically creates its own iptables rules to manage container networking, which can sometimes override or bypass firewall-cmd settings. If you still see external access after fixing the port binding, you have two options here:
Option A: Disable Docker's IPTables Integration
Edit or create the Docker daemon config file /etc/docker/daemon.json and add:
{ "iptables": false }
Then restart the Docker daemon to apply this change:
systemctl restart docker
This stops Docker from modifying your iptables rules, so your firewall-cmd configurations will take full effect. Just remember to restart your MongoDB container after this.
Option B: Add a Firewall Rule to Block External Access
If you prefer to keep Docker's iptables integration, use a firewall-cmd rich rule to explicitly reject external traffic to 27017:
firewall-cmd --add-rich-rule='rule family="ipv4" source address="0.0.0.0/0" port port="27017" protocol="tcp" reject' --permanent firewall-cmd --reload
This ensures any external attempts to reach port 27017 get rejected, even if Docker's rules try to allow it.
4. Double-Check MongoDB's Bind IP (Extra Security Layer)
MongoDB itself defaults to listening on all interfaces. To add another layer of protection, you can configure MongoDB to only bind to the loopback interface directly. Update your docker-compose.yml with a command override:
services: mongodb: image: mongo command: mongod --bind_ip 127.0.0.1 ports: - "127.0.0.1:27017:27017" # Rest of your config...
This ensures MongoDB won't accept connections from any interface other than the server's own loopback, even if there's a misconfiguration in Docker's port binding.
After implementing these steps, test from an external machine to confirm the MongoDB container is no longer accessible over the public internet.
内容的提问来源于stack exchange,提问作者Ehsan Sarshar

