Skip to content

Docker Network ​

Containers run in isolated environments. This means a container is not automatically connected to the same user-defined network as another container, and it does not automatically know which application containers it should communicate with.

Docker does provide a default bridge network. Containers on that network can communicate using IP addresses, but this is less practical because IP addresses can change. To connect several containers in a clearer and easier-to-manage way, create your own Docker Network.

A Docker Network lets containers communicate using container names. This is important when an app needs to connect to a database, cache, or another service.

How containers communicate ​

Containers on the same Docker user-defined network can connect to each other by name. You do not need to know their IP addresses.

Loading diagram...

localhost inside a container points to the container itself. So, from the app container, access the database in the db container using the hostname db, not localhost.

View Docker Networks ​

sh
docker network ls

Example output:

text
NETWORK ID     NAME      DRIVER    SCOPE
7f3a1b2c4d5e   bridge    bridge    local

This output shows Docker's default bridge network. For a project, it is better to create your own network so its name and members are clear.

Create a network ​

Command format:

sh
docker network create <network-name>

Example:

sh
docker network create app-network

View network details:

sh
docker network inspect app-network

Run containers on the same network ​

Command format:

sh
docker run -d --name <container-name> --network <network-name> <image:tag>

To demonstrate communication between containers, run PostgreSQL as the first service on app-network:

sh
docker run -d --name db \
  --network app-network \
  -e POSTGRES_PASSWORD=secret \
  postgres:16

INFO

The -e option adds an environment variable to the container. POSTGRES_PASSWORD=secret sets PostgreSQL's password. See lesson 8 for a fuller explanation of environment variables.

Now run a temporary container on the same network. We use BusyBox, a small Linux image that contains common basic utilities. It fits this example because it provides nslookup, a command that checks whether the name db can be found on the network.

--rm tells Docker to remove the BusyBox container after the command finishes. This container is only a tool for testing the connection, not an application service.

sh
docker run --rm \
  --network app-network \
  busybox nslookup db

The second container can find db by its container name. In an app that connects to PostgreSQL, use host db and port 5432.

Network and ports ​

Docker Network controls communication between containers. Port mapping with -p controls access from the host, such as access from a laptop browser to a container.

You do not need to publish a database port to the laptop if only an app on the same network uses it. Publish a port only when the host needs access.

After confirming that communication works, remove the practice container and network. These commands do not remove the PostgreSQL image:

sh
docker rm -f db
docker network rm app-network

Docker Compose in the next lesson will create a project network automatically. The concept remains the same: services can reach each other by service name.