Any people knowledgeable with know if exposed rootfull container ports being automatically exposed on the host machine regardless of firewall config is expected behavior?

(Yes, I know I should be using rootless containers)

