We need to use go-mmproxy on 0.0.0.0:22 proxying to OpenSSH server on 127.0.0.1:2222 with appropriate loopback rules to support the PROXY protocol so SSH logs the Real IP of connections instead of the proxy's IP. Then we need to enable fail2ban on the containers to block those connections.