It's worth noting that for many of us, Fail2Ban will end up blocking normal Cloudflare traffic and thus Fail2Ban is routinely deactivated. Therefore whitelisting Cloudflare IPs and reactivating Fail2Ban will actually increase protection, not decrease it.
Cloudflare is not typically an outbound...
A late follow up but hopefully useful to someone..
On Plesk 18, Docker instances can't access the main Plesk DB server locally. Therefore you need to set the DB Host as the server's public IP and ensure all firewalls allow traffic through (both on Plesk and on any network firewall)...