{"id":373840,"date":"2021-11-29T16:00:51","date_gmt":"2021-11-29T13:00:51","guid":{"rendered":"https:\/\/en.buradabiliyorum.com\/whats-the-difference-between-exposing-and-publishing-a-docker-port-cloudsavvy-it\/"},"modified":"2021-11-29T16:00:51","modified_gmt":"2021-11-29T13:00:51","slug":"whats-the-difference-between-exposing-and-publishing-a-docker-port-cloudsavvy-it","status":"publish","type":"post","link":"https:\/\/buradabiliyorum.com\/en\/whats-the-difference-between-exposing-and-publishing-a-docker-port-cloudsavvy-it\/","title":{"rendered":"#What\u2019s the Difference Between Exposing and Publishing a Docker Port? \u2013 CloudSavvy IT"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_88 counter-hierarchy ez-toc-counter ez-toc-custom ez-toc-container-direction\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<label for=\"ez-toc-cssicon-toggle-item-6ac5cc7cc03b6\" class=\"ez-toc-cssicon-toggle-label\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #dd3333;color:#dd3333\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #dd3333;color:#dd3333\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/label><input type=\"checkbox\"  id=\"ez-toc-cssicon-toggle-item-6ac5cc7cc03b6\" checked aria-label=\"Toggle\" \/><nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/buradabiliyorum.com\/en\/whats-the-difference-between-exposing-and-publishing-a-docker-port-cloudsavvy-it\/#Exposing_a_Port\" >Exposing a Port<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/buradabiliyorum.com\/en\/whats-the-difference-between-exposing-and-publishing-a-docker-port-cloudsavvy-it\/#Publishing_Ports\" >Publishing Ports<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/buradabiliyorum.com\/en\/whats-the-difference-between-exposing-and-publishing-a-docker-port-cloudsavvy-it\/#Publishing_All_Exposed_Ports\" >Publishing All Exposed Ports<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/buradabiliyorum.com\/en\/whats-the-difference-between-exposing-and-publishing-a-docker-port-cloudsavvy-it\/#When_You_Dont_Need_to_Publish_a_Port\" >When You Don\u2019t Need to Publish a Port<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/buradabiliyorum.com\/en\/whats-the-difference-between-exposing-and-publishing-a-docker-port-cloudsavvy-it\/#Using_Port_Ranges\" >Using Port Ranges<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/buradabiliyorum.com\/en\/whats-the-difference-between-exposing-and-publishing-a-docker-port-cloudsavvy-it\/#Summary\" >Summary<\/a><\/li><\/ul><\/nav><\/div>\n<p><strong>&#8220;#What\u2019s the Difference Between Exposing and Publishing a Docker Port? \u2013 CloudSavvy IT&#8221;<\/strong><\/p>\n<div id=\"article-content-area\">\n<figure style=\"width: 1200px\" class=\"wp-caption aligncenter\"><img loading=\"lazy\" decoding=\"async\" class=\"type:primaryImage size-full wp-image-14349\" srcset=\"https:\/\/www.cloudsavvyit.com\/p\/uploads\/2021\/09\/1b870e67.jpg?width=398&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1 400w, https:\/\/www.cloudsavvyit.com\/p\/uploads\/2021\/09\/1b870e67.jpg?width=1198&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1 1200w\" sizes=\"auto, 400w, 1200w\" src=\"https:\/\/www.cloudsavvyit.com\/p\/uploads\/2021\/09\/1b870e67.jpg?width=1198&amp;trim=1,1&amp;bg-color=000&amp;pad=1,1\" alt=\"Photo of the Docker logo on a building\" width=\"1200\" height=\"675\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><figcaption class=\"wp-caption-text\"><span class=\"type:primaryImage imagecredit\"><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/www.shutterstock.com\/image-photo\/docker-inc-headquarters-campus-facade-silicon-1561719073\">Michael Vi\/Shutterstock.com<\/a><\/span><\/figcaption><\/figure>\n<p>Exposed and Published container ports are two different but related concepts in Docker. Exposed ports are defined in your Dockerfile as simple metadata. You must publish them when your container starts if you want to enable outside access.<\/p>\n<h2 id=\"exposing-a-port\"><span class=\"ez-toc-section\" id=\"Exposing_a_Port\"><\/span>Exposing a Port<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Ports are exposed via <code>EXPOSE<\/code> instructions in an image\u2019s Dockerfile:<\/p>\n<pre>EXPOSE 80<\/pre>\n<p><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/docs.docker.com\/engine\/reference\/builder\/#expose\">Exposing a port<\/a> doesn\u2019t have any im<a href=\"https:\/\/buradabiliyorum.com\/en\/category\/social-mediaa\/\" data-internallinksmanager029f6b8e52c=\"1\" title=\"Social Media\" target=\"_blank\" rel=\"noopener\">media<\/a>te effect though. The statement only communicates that the <a href=\"https:\/\/buradabiliyorum.com\/en\/category\/download-scripts-themes-apps\/\" data-internallinksmanager029f6b8e52c=\"9\" title=\"Download Scripts &amp; Themes &amp; Apps\" target=\"_blank\" rel=\"noopener\">app<\/a>lication inside the container listens on port <code>80<\/code>. It does not open that port to the world or explicitly provide access to any other containers.<\/p>\n<p>As an image author, listing ports used by your workload with <code>EXPOSE<\/code> helps users configure appropriate port forwarding rules when they start a container. This is particularly important when non-standard ports are used: while a web server can be expected to listen on port 80, users won\u2019t be able to guess the port used by a custom socket server.<\/p>\n<p>Exposed ports are visible when you list your containers with <code>docker ps<\/code>. They\u2019ll show up in the <code>PORTS<\/code> column, even though they won\u2019t actually be accessible outside the container. This gives you a simple way of checking which ports the software inside a container is listening on.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-14883\" src=\"https:\/\/www.cloudsavvyit.com\/p\/uploads\/2021\/11\/f19f7ce6.png?trim=1,1&amp;bg-color=000&amp;pad=1,1\" alt=\"\" width=\"1175\" height=\"119\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><\/p>\n<p>You can inspect ports exposed by an image without starting a container by using <code>docker inspect<\/code>. Substitute your image\u2019s tag or ID instead of <code>demo-image<\/code>:<\/p>\n<pre>docker inspect --format=\"{{json .Config.ExposedPorts}}\" demo-image<\/pre>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-14884\" src=\"https:\/\/www.cloudsavvyit.com\/p\/uploads\/2021\/11\/7efe9e9a.png?trim=1,1&amp;bg-color=000&amp;pad=1,1\" alt=\"\" width=\"1216\" height=\"60\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><\/p>\n<h2 id=\"publishing-ports\"><span class=\"ez-toc-section\" id=\"Publishing_Ports\"><\/span>Publishing Ports<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p><a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/docs.docker.com\/config\/containers\/container-networking\/#published-ports\">Publishing a port<\/a> makes it accessible from outside the container. It lets you take a port you\u2019ve discovered by an <code>EXPOSE<\/code> instruction, then bind a host port to it.<\/p>\n<p>Ports are exposed with the <code>-p<\/code> flag for the <code>docker run<\/code> command:<\/p>\n<pre>docker run -d -p 8080:80 httpd:latest<\/pre>\n<p>This command binds port <code>8080<\/code> on your Docker host to <code>80<\/code> inside your new container. Now you can visit <code>http:\/\/localhost:8080<\/code> to access the container\u2019s port. If you run <code>docker ps<\/code>, you\u2019ll see the <code>PORTS<\/code> column now shows this mapping. The exposed container port <code>80<\/code> has been published to the host.<\/p>\n<p><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-full wp-image-14885\" src=\"https:\/\/www.cloudsavvyit.com\/p\/uploads\/2021\/11\/449a53d8.png?trim=1,1&amp;bg-color=000&amp;pad=1,1\" alt=\"\" width=\"1315\" height=\"89\" onload=\"pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\" onerror=\"this.onerror=null;pagespeed.lazyLoadImages.loadIfVisibleAndMaybeBeacon(this);\"\/><\/p>\n<p>The <code>-p<\/code> flag can be used without specifying a port to bind to:<\/p>\n<pre>docker run -d -p 80 httpd:latest<\/pre>\n<p>This variant will bind port 80 in the container to a random port on the host. You can check the port that\u2019s been assigned by running <code>docker ps<\/code>.<\/p>\n<p><code>-p<\/code> also supports publishing a port to specific network interfaces:<\/p>\n<pre>docker run -d -p 127.0.0.1:8080:80 httpd:latest<\/pre>\n<p>Here the container port 80 will only be accessible via port 8080 on the host\u2019s local loopback address. This protects your container from network calls made by your other devices.<\/p>\n<h2 id=\"publishing-all-exposed-ports\"><span class=\"ez-toc-section\" id=\"Publishing_All_Exposed_Ports\"><\/span>Publishing All Exposed Ports<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>You can start a container with the <code>--publish-all<\/code> flag to have Docker automatically publish all the exposed ports listed in the image\u2019s Dockerfile:<\/p>\n<pre>docker run -d --publish-all httpd:latest<\/pre>\n<p>This will assign random free ports on your host to each exposed port in the container. Use the <code>docker ps<\/code> command to see the port assignations that have been made. This simplifies starting a new container from an image that requires several non-standard ports to be opened.<\/p>\n<p>You can combine <code>--publish-all<\/code> with explicit <code>-p<\/code> mappings. In this case, a mapping created by a <code>-p<\/code> flag will override the random port assigned by <code>--publish-all<\/code>.<\/p>\n<h2 id=\"when-you-dont-need-to-publish-a-port\"><span class=\"ez-toc-section\" id=\"When_You_Dont_Need_to_Publish_a_Port\"><\/span>When You Don\u2019t Need to Publish a Port<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>You only need to publish container ports with <code>-p<\/code> if you want to access them from your Docker host or another device on your physical network. Docker networks are the preferred alternative approach for inter-container traffic.<\/p>\n<p>Containers that share a network can always communicate with each other, even if their ports have not been explicitly published.<\/p>\n<pre>docker network create demo-network&#13;\ndocker run -d --network demo-network --name web web:latest&#13;\ndocker run -d --network demo-network --name database database:latest<\/pre>\n<p>In this example, the <code>web<\/code> container could connect to a MySQL server running on port 3306 in the <code>database<\/code> container using the <code>database:3306<\/code> address. Docker automatically sets up routing tables for the container names in the network.<\/p>\n<h2 id=\"using-port-ranges\"><span class=\"ez-toc-section\" id=\"Using_Port_Ranges\"><\/span>Using Port Ranges<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Docker can expose and publish entire port ranges when you need to have multiple ports available:<\/p>\n<pre>EXPOSE 8000-8100&#13;\n&#13;\ndocker run --publish-all&#13;\ndocker run -p 6000-6100:8000-8100<\/pre>\n<p>In the first case, <code>--publish-all<\/code> will assign 100 random ports on your host and map them into the container\u2019s range. The second form explicitly binds a host range to a container range as normal. Performance can be impacted if you use a very large number of ports as an <code>iptables<\/code> rule will be created for each one.<\/p>\n<h2 id=\"summary\"><span class=\"ez-toc-section\" id=\"Summary\"><\/span>Summary<span class=\"ez-toc-section-end\"><\/span><\/h2>\n<p>Exposed ports are pieces of metadata that define the ports listened to by software inside a container image. The presence of exposed ports doesn\u2019t render them accessible unless you manually publish them. In this sense, the verb \u201cexpose\u201d is a misnomer, as many people assume it\u2019s an active action when in fact it\u2019s an informational statement. <code>EXPOSE<\/code> <a rel=\"nofollow noopener\" target=\"_blank\" href=\"https:\/\/docs.docker.com\/engine\/reference\/builder\/#expose\">should be treated as documentation<\/a> whereas the <code>-p<\/code> flag creates a functioning port mapping.<\/p>\n<p>Docker does provide some extra behavior based on <code>EXPOSE<\/code> instructions. You can view a container\u2019s exposed ports with <code>docker ps<\/code> irrespective of whether they\u2019ve been published. There\u2019s also the <code>--publish-all<\/code> flag that publishes an image\u2019s exposed ports to random host ports.<\/p>\n<p>You only need to publish ports when you want to access a container from outside a Docker network. Communication between containers in the same network is always uninhibited, whether or not the ports involved have been exposed or published.\n<\/p><\/div>\n<blockquote><p><strong><span style=\"color: #ff6600;\">If you liked the article, do not forget to share it with your friends. Follow us on\u00a0<span style=\"color: #ff0000;\"><a style=\"color: #ff0000;\" href=\"https:\/\/news.google.com\/publications\/CAAqBwgKMLG0nwswvr63Aw\" target=\"_blank\" rel=\"nofollow noopener noreferrer\">Google News<\/a><\/span>\u00a0too, click on the star and choose us from your favorites.<\/span><\/strong><\/p><\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\">For forums sites go to <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/forum.buradabiliyorum.com\/\" target=\"_blank\" rel=\"noopener\">Forum.BuradaBiliyorum.Com<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<blockquote>\n<p style=\"text-align: center;\"><strong>If you want to read more like this article, you can visit our <span style=\"color: #ff9900;\"><a style=\"color: #ff9900;\" href=\"https:\/\/en.buradabiliyorum.com\/technology\/\" target=\"_blank\" rel=\"noopener\">Technology category.<\/a><\/span><\/strong><\/p>\n<\/blockquote>\n<p><span style=\"color: black;\"><a style=\"color: #ff9900;\" href=\"https:\/\/www.cloudsavvyit.com\/14880\/whats-the-difference-between-exposing-and-publishing-a-docker-port\/\" target=\"_blank\" rel=\"noopener\">Source<\/a><\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>&#8220;#What\u2019s the Difference Between Exposing and Publishing a Docker Port? \u2013 CloudSavvy IT&#8221; Michael Vi\/Shutterstock.com Exposed and Published container ports are two different but related concepts in Docker. Exposed ports are defined in your Dockerfile as simple metadata. You must publish them when your container starts if you want to enable outside access. Exposing a&#8230;<\/p>\n","protected":false},"author":1,"featured_media":373841,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"fifu_image_url":"https:\/\/www.cloudsavvyit.com\/p\/uploads\/2021\/09\/1b870e67.jpg","fifu_image_alt":"","footnotes":""},"categories":[18],"tags":[],"class_list":["post-373840","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-technology"],"_links":{"self":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/373840","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/comments?post=373840"}],"version-history":[{"count":0,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/posts\/373840\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media\/373841"}],"wp:attachment":[{"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/media?parent=373840"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/categories?post=373840"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/buradabiliyorum.com\/en\/wp-json\/wp\/v2\/tags?post=373840"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}