Information
By default, all network traffic is allowed between containers on the same host. If not
desired, restrict all the inter container communication. Link specific containers together
that require inter communication.By default, unrestricted network traffic is enabled between all containers on the same host.
Thus, each container has the potential of reading all packets across the container network
on the same host. This might lead to unintended and unwanted disclosure of information to
other containers. Hence, restrict the inter container communication.
Solution
Run the docker in daemon mode and pass '--icc=false' as argument.For Example,/usr/bin/dockerd --icc=false
Impact-The inter container communication would be disabled. No containers would be able to talk
to another container on the same host. If any communication between containers on the
same host is desired, then it needs to be explicitly defined using container linking.Default Value-By default, all inter container communication is allowed.