Few Servers

Keyword UFW · from our Short

ufw deny does not close a Docker port

Docker publishes container ports with its own firewall rules, and that traffic is diverted before it reaches the rules UFW writes. So ufw deny 8000 can say the port is closed while the Coolify dashboard still answers from the internet.

The checklist

  1. Test from outside the server: curl -m 5 http://YOUR_IP:8000 from your laptop.
  2. Use your hosting provider's firewall (it filters before traffic reaches the server): open 22, 80 and 443.
  3. Limit 8000, 6001 and 6002 to your own IP, and close them once the dashboard has a domain.
  4. On the server itself, rules for published ports belong in Docker's DOCKER-USER chain, not in UFW's.

The full write-up

The starter kit includes the Docker-aware firewall script and a test that proves the ports are closed from outside. All 84 checks passed on fresh Ubuntu 24.04 and 22.04 on 2 Oct 2026. Pay what you want, USD 9 suggested.