Most developers know UFW blocks unwanted traffic. What they don't know is that Docker bypasses UFW entirely by rewriting iptables directly.
This in your docker-compose.yml:
ports:
"5432:5432"
Exposes Postgres to the public internet. UFW never sees it. Your firewall rules don't matter.







