Docker container can't access host services with firewalld enabled

I have two AlmaLinux servers. I set one up over a year ago. It’s AlmaLinux 9.5. The second server is AlmaLinux 10.2.

Both have Nginx Proxy Manager (NPM) installed in Docker. Both have Apache installed on the host. I have set up both systems to be identical so that NPM is the reverse-proxy for all Docker containers and for the services installed on the host.

On the second server, the problem I have is that NPM is not able to proxy traffic to the host’s services (Apache) unless I disable firewalld. I do not encounter this issue on the first server.

The only difference that I can find between the two servers is that the first server has an interface listed in the firewalld docker zone whereas the second server does not.

First server:

[root@one ~]# firewall-cmd --zone=docker --list-all
docker (active)
  target: ACCEPT
  icmp-block-inversion: no
  interfaces: br-758d135g0e3t docker0
  sources:
  services:
  ports:
  protocols:
  forward: yes
  masquerade: no
  forward-ports:
  source-ports:
  icmp-blocks:
  rich rules:
[root@one ~]# firewall-cmd --zone=public --query-masquerade
no
[root@one ~]# sysctl net.ipv4.ip_forward
net.ipv4.ip_forward = 1
[root@one ~]# firewall-cmd --get-active-zones
docker
  interfaces: br-758d135g0e3t docker0
public
  interfaces: eth0

Second server:

[root@two ~]# firewall-cmd --zone=docker --list-all
docker
  target: ACCEPT
  ingress-priority: 0
  egress-priority: 0
  icmp-block-inversion: no
  interfaces:
  sources:
  services:
  ports:
  protocols:
  forward: yes
  masquerade: no
  forward-ports:
  source-ports:
  icmp-blocks:
  rich rules:
[root@two ~]# firewall-cmd --zone=public --query-masquerade
no
[root@two ~]# sysctl net.ipv4.ip_forward
net.ipv4.ip_forward = 1
[root@two ~]# firewall-cmd --get-active-zones
public (default)
  interfaces: eth0

Is this normal? Is it due to different versions of AlmaLinux?
If this is the root of my problem, how do I fix?

This seems to have fixed the issue:

firewall-cmd --zone=docker --add-interface=br-0f9f3964cf20 --permanent
firewall-cmd --zone=docker --add-interface=docker0 --permanent
firewall-cmd --reload
[root@two ~]# firewall-cmd --get-active-zones
docker
  interfaces: br-0f9f3964cf20 docker0
public (default)
  interfaces: eth0

It is a firewalld thing. You can find a note about this in the docker documentation

https://docs.docker.com/engine/network/packet-filtering-firewalls/#integration-with-firewalld

Quote:

Integration with firewalld

If you are running Docker with the iptables or ip6tables options set to true, and firewalld is enabled on your system, in addition to its usual iptables or nftables rules, Docker creates a firewalld zone called docker, with target ACCEPT.

All bridge network interfaces created by Docker (for example, docker0) are inserted into the docker zone.

Docker also creates a forwarding policy called docker-forwarding that allows forwarding from ANY zone to the docker zone. Integration with firewalld

If you are running Docker with the iptables or ip6tables options set to true, and firewalld is enabled on your system, in addition to its usual iptables or nftables rules, Docker creates a firewalld zone called docker, with target ACCEPT.

All bridge network interfaces created by Docker (for example, docker0) are inserted into the docker zone.

Docker also creates a forwarding policy called docker-forwarding that allows forwarding from ANY zone to the docker zone.

It says the interfaces are automatically added to the docker zone, so if it didn’t happen, I would check the dockerd service logs and any system logs for firewalld. Maybe it also depends on versions.

Thank you for sharing your solution though.