@ptesarik also I've heard that in this setup docker container ports might be exposed to the internet despite whatever firewalld config because the two interact a bit weird
better double check, or — I'd recommend this — switch to rootless docker/podman which doesn't touch iptables at all
better double check, or — I'd recommend this — switch to rootless docker/podman which doesn't touch iptables at all