Most developers know UFW blocks unwanted traffic. What they don't know is that Docker bypasses UFW entirely by rewriting iptables directly.

This in your docker-compose.yml:

ports:

"5432:5432"

Exposes Postgres to the public internet. UFW never sees it. Your firewall rules don't matter.