Why does the Docker one click image expose the docker ports via UFW

Docker Ubuntu 18.04

In the default configuration of the one-click 18.04 docker image the ports 2375 & 2376 are exposed via UFW.

Is there any reason for this? By default, docker isn't listening on those ports. And even if it were it seems highly questionable opening up it's API to the world by default.

  • I was just about to ask the same thing. But when I run an nmap scan it returns 'filtered' instead of open for some reason.

Is the API protected via TLS authentication by default? Otherwise that's trouble waiting to happen.

