---
tags:
- containers
- l1
- flashcard-deck
- docker-networking
---
<!-- wiki:breadcrumb:start -->
[Portal](../../../../library/portal/index.md) | **Level:** [L1: Foundations](../../../../library/portal/levels.md) | **Topics:** [Kubernetes Networking](../../../../library/portal/topics.md) | **Domain:** containers
<!-- wiki:breadcrumb:end -->

id	category	difficulty	tags	question	answer	source_path
docker-networking/01e3029f9fdc	docker-networking	easy	docker-networking, cnm	What are some features of libnetwork?	* Native service discovery\n* ingress-based load balancer\n* network control plane and management plane\n\nName origin: libnetwork is Docker's implementation of the CNM (Container Network Model) specification, written in Go.\n\nUnder the hood: libnetwork provides DNS-based service discovery (containers resolve each other by name), built-in IPAM (IP address management), and pluggable network drivers.	projects/knowledge/interview/docker/113-what-are-some-features-of-libnetwork.txt
docker-networking/39bc82acf780	docker-networking	medium	docker-networking, bridge	How do you create a custom bridge network in Docker?	To create a custom bridge network in Docker, you can use the docker network create command. Here's an example: \n```docker network create my_bridge_network``` \nThis command creates a new bridge network named my_bridge_network. You can then connect containers to this network using the --network option in the docker run command. \n```docker run --network my_bridge_network my_image``` \nCustom bridge networks provide isolation between containers and can be useful for organizing and managing container communication.	projects/knowledge/interview/docker/165-how-do-you-create-a-custom-bridge-network-in-docke.txt
docker-networking/3bc18682bf30	docker-networking	hard	docker-networking, bridge, overlay, host-network	Explain the difference between bridge, host, and overlay network drivers.	**Bridge Network Driver:* • \n • Default network driver in Docker.\n • Creates an internal private network that allows containers to communicate with each other.\n • Containers on a bridge network can expose and publish ports to the host machine.\n**Host Network Driver:* • \n • Containers share the host machine's network namespace.\n • Provides better performance but may lead to port conflicts if multiple containers use the same ports.\n**Overlay Network Driver:* • \n • Used in swarm mode for multi-host communication.\n • Creates an overlay network that spans multiple Docker hosts.\n • Allows	
docker-networking/43c7ff5bf209	docker-networking	easy	docker-networking, networking, fundamentals	You would like to run a web server inside a container but, be able to access it from the localhost. Demonstrate how to do that	`podman run -d --name apache1 -p 8080:8080 registry.redhat.io/rhel8/httpd-24` maps host port 8080 to container port 8080. Then `curl 127.0.0.1:8080` verifies access. Format is `-p HOST_PORT:CONTAINER_PORT`. Use `-p 127.0.0.1:8080:8080` to bind only to localhost for security.	projects/knowledge/interview/docker/018-you-would-like-to-run-a-web-server-inside-a-contai.txt
docker-networking/45dfe4331b4a	docker-networking	medium	docker-networking, cnm	Explain the following blocks in regards to CNM:	* Networks: software implementation of an switch. They used for grouping and isolating a collection of endpoints.\n  * Endpoints: Virtual network interfaces. Used for making connections.\n  * Sandboxes: Isolated network stack (interfaces, routing tables, ports, ...)	projects/knowledge/interview/docker/111-explain-the-following-blocks-in-regards-to-cnm-net.txt
docker-networking/4669d4a48f79	docker-networking	easy	docker-networking, networking, fundamentals	True or False? If you would like to connect a container to multiple networks, you need multiple endpoints	True. An endpoint can connect only to a single network.\n\nUnder the hood: each endpoint is a veth pair — one end in the container's network namespace, the other attached to the Docker bridge. Multiple networks = multiple veth pairs.\n\nExample: docker network connect second_network my_container adds a second endpoint (and a second IP) to an already-running container.	projects/knowledge/interview/docker/112-true-or-false-if-you-would-like-to-connect-a-conta.txt
docker-networking/66f5161a96f1	docker-networking	medium	docker-networking, dns	Explain the concept of Docker network aliases.	Docker network aliases allow a container to have multiple network identities (IP addresses) within the same network. This can be useful in scenarios where a container provides multiple services or when network segregation is needed. \nWhen creating a container, you can specify network aliases using the --network-alias option: \n```docker run --network my_network --network-alias service_alias container_image``` \nThis allows the container to be reachable under both its container name and the specified network alias.	projects/knowledge/interview/docker/163-explain-the-concept-of-docker-network-aliases.txt
docker-networking/742556be6e28	docker-networking	hard	docker-networking, drivers	How do you create a custom Docker network driver?	Creating a custom Docker network driver involves developing a plugin that adheres to the Docker Network Driver API. This allows the driver to interface with Docker and provide customized networking capabilities. \n**Steps for creating a custom Docker network driver:** \n**Develop the Driver:**\n* Implement the required API methods in the language of your choice (e.g., Go).\n* Adhere to the specifications outlined in the Docker Network Driver API. \n**Build the Driver:**	projects/knowledge/interview/docker/192-how-do-you-create-a-custom-docker-network-driver.txt
docker-networking/8b9d93f3a8eb	docker-networking	medium	docker-networking, networking, fundamentals	When running a container, usually a virtual ethernet device is created. To do so, root privileges are required. How is it then managed in rootless containers?	Networking is usually managed by Slirp in rootless containers. Slirp creates a tap device which is also the default route and it creates it in the network namespace of the container. This device's file descriptor passed to the parent who runs it in the default namespace and the default namespace connected to the internet. This enables communication externally and internally.	projects/knowledge/interview/docker/123-when-running-a-container-usually-a-virtual-etherne.txt
docker-networking/9659c48c0e32	docker-networking	medium	docker-networking, networking, fundamentals	What is the purpose of the "--network" option in the "docker run" command?	The --network option in the docker run command is used to specify the network to which the container should be connected. Docker provides various networking options for containers, and using --network allows you to connect containers to the same network, enabling communication between them.\n```docker run --network my_network image_name``` \nThis is especially useful in multi-container applications where different services need to communicate. Docker supports default bridge networks, user-defined bridge networks, host networking, and overlay networks for more complex scenarios.	projects/knowledge/interview/docker/155-what-is-the-purpose-of-the-network-option-in-the-d.txt
docker-networking/a111eba5dda1	docker-networking	medium	docker-networking, networking, fundamentals	What container network standards or architectures are you familiar with?	CNM (Container Network Model):\n  * Requires distrubited key value store (like etcd for example) for storing the network configuration\n  * Used by Docker\nCNI (Container Network Interface):\n  * Network configuration should be in JSON format	projects/knowledge/interview/docker/109-what-container-network-standards-or-architectures-.txt
docker-networking/b6cc1ea42d0c	docker-networking	hard	docker-networking, dns	How does Docker Swarm handle service discovery?	Docker Swarm handles service discovery through its built-in DNS-based service discovery mechanism. Each service in a Docker Swarm has a DNS entry that allows other services to discover and communicate with it. \n**Key aspects of Docker Swarm service discovery:**\n* Service Names: Each service is given a unique name within the swarm.\n* DNS Resolution: Services can be accessed by other services using their DNS name (e.g., my_service) or by the full DNS name (e.g., my_service.my_network).\n* Load Balancing: Swarm provides built-in load balancing for services, distributing incoming requests among available replicas. \nThis DNS-based service discovery simplifies communication between services within the swarm.	projects/knowledge/interview/docker/187-how-does-docker-swarm-handle-service-discovery.txt
docker-networking/be2bbac21aa0	docker-networking	easy	docker-networking, port-mapping	How do you expose a port from a Docker container to the host?	By using the -p or -P flag with docker run. For example, -p 8080:80 maps port 8080 on the host to port 80 in the container. The container's service listening on 80 will then be accessible via host:8080.\n\nGotcha: -p 8080:80 binds to 0.0.0.0 (all interfaces) by default. Use -p 127.0.0.1:8080:80 to restrict to localhost only — important for security.\n\nRemember: -p = publish specific ports. -P = publish all EXPOSE'd ports to random host ports. Lowercase -p is almost always what you want.	projects/knowledge/interview/docker/209-expose-port.txt
docker-networking/c2e9821de9ed	docker-networking	hard	docker-networking, networking, fundamentals	What is Docker networking, and how does it facilitate communication between containers?	Docker networking enables communication between containers running on the same host or across multiple hosts. Docker provides various networking options to facilitate this communication: \n**Bridge Networks:** The default network type in Docker. Containers on the same bridge network can communicate with each other. This is suitable for most applications. \n**Host Networking:** Containers share the host network namespace, meaning they have the same network stack as the host machine.	projects/knowledge/interview/docker/158-what-is-docker-networking-and-how-does-it-facilita.txt
docker-networking/c6031bb85fc2	docker-networking	hard	docker-networking, port-mapping	How can you expose ports from a Docker container?	To expose ports from a Docker container, you use the -p or --publish option with the docker run command: \n```docker run -p host_port:container_port image_name``` \n`host_port` is the port on the host machine. \n`container_port` is the port inside the container. \nThis command maps the specified container port to the specified host port, allowing external access to the containerized application. You can also specify the host IP address if needed: \n```docker run -p host_ip:host_port:container_port image_name``` \nExposed ports are crucial for allowing external services or other containers to communicate with the running container.	projects/knowledge/interview/docker/160-how-can-you-expose-ports-from-a-docker-container.txt
docker-networking/ca3c23902a84	docker-networking	medium	docker-networking, compose	What is Docker Compose networking, and how is it configured?	Docker Compose networking is a feature that enables the definition and management of networks for multi-container applications. It allows you to specify custom networks for containers, control communication between services, and define network-related configurations. \nNetworks in Docker Compose are defined in the docker-compose.yml file under the networks section. Here's an example:\n```yaml\nversion: '3'\nservices:\n app1:\n image: image1\n networks:\n - custom_network\n app2:\n image: image2\n networks:\n - custom_network\nnetworks:\n custom_network:\n```\nThis configuration creates a custom network named custom_network, and both app1 and app2 services are connected to this network.	projects/knowledge/interview/docker/164-what-is-docker-compose-networking-and-how-is-it-co.txt
docker-networking/d676169aeb6d	docker-networking	medium	docker-networking, inspection	How do you inspect the network settings of a running container?	To inspect the network settings of a running container, you can use the docker inspect command with the container ID or name: \n```docker inspect container_id``` \nThis command provides detailed information about the container, including its network settings, IP address, gateway, and more. You can also filter the output to display specific information, such as: \n```docker inspect --format '{{ .NetworkSettings.IPAddress }}' container_id```	projects/knowledge/interview/docker/162-how-do-you-inspect-the-network-settings-of-a-runni.txt
docker-networking/e28de89ce42d	docker-networking	easy	docker-networking, networking, fundamentals	What network specification Docker is using and how its implementation is called?	Docker is using the CNM (Container Network Model) design specification. \nThe implementation of CNM specification by Docker is called "libnetwork". It's written in Go.\n\nX vs Y: CNM (Docker) vs CNI (Container Network Interface, Kubernetes). CNM uses a key-value store; CNI uses JSON config files. Kubernetes chose CNI — that's why Docker and Kubernetes networking work differently.\n\nName origin: CNM = Container Network Model. CNI = Container Network Interface. Both are specifications, not implementations.	projects/knowledge/interview/docker/110-what-network-specification-docker-is-using-and-how.txt
docker-networking/f727172a83f5	docker-networking	medium	docker-networking, port-mapping	What is the purpose of the "-p" option in the "docker run" command?	The -p (or --publish) option in the docker run command is used to map ports between the host machine and the container. It facilitates the exposure and access of services running inside the container to the external network. \n```docker run -p host_port:container_port image_name``` \n`host_port` is the port on the host machine. \n`container_port` is the port inside the container. \nThis option allows external applications to connect to the containerized service using the specified host port.	projects/knowledge/interview/docker/161-what-is-the-purpose-of-the-p-option-in-the-docker-.txt
docker-networking/z7a8b9c0d1e2	docker-networking	medium	docker-networking, isolation	How does a container's network namespace provide isolation?	The container gets its own network stack: interfaces, routing table, firewall rules, and listening sockets. The process thinks it owns eth0 without accessing the host's network stack. Communication with the host uses virtual bridges or veth pairs.	zines/how.containers.work.cleaned.notes

<!-- wiki:related:start -->
---

## Wiki Navigation

### Related Content

- [API Gateways & Ingress](../../../../library/topics/api-gateways/index.md) (Topic Pack, L2) — Kubernetes Networking
- [Case Study: CNI Broken After Restart](../../../../library/case-studies/kubernetes_ops/cni-broken-after-restart/README.md) (Case Study, L2) — Kubernetes Networking
- [Case Study: Canary Deploy Routing to Wrong Backend — Ingress Misconfigured](../../../../library/case-studies/cross-domain/canary-deploy-wrong-backend-ingress/README.md) (Case Study, L2) — Kubernetes Networking
- [Case Study: CoreDNS Timeout Pod DNS](../../../../library/case-studies/kubernetes_ops/coredns-timeout-pod-dns/README.md) (Case Study, L2) — Kubernetes Networking
- [Case Study: Grafana Dashboard Empty — Prometheus Blocked by NetworkPolicy](../../../../library/case-studies/cross-domain/grafana-empty-prometheus-networkpolicy/README.md) (Case Study, L2) — Kubernetes Networking
- [Case Study: Service Mesh 503s — Envoy Misconfigured, RBAC Policy](../../../../library/case-studies/cross-domain/service-mesh-503-envoy-rbac/README.md) (Case Study, L2) — Kubernetes Networking
- [Case Study: Service No Endpoints](../../../../library/case-studies/kubernetes_ops/service-no-endpoints/README.md) (Case Study, L1) — Kubernetes Networking
- [Cilium & eBPF Networking](../../../../library/topics/cilium/index.md) (Topic Pack, L2) — Kubernetes Networking
- [Deep Dive: Kubernetes Networking](../../../../library/deep-dives/kubernetes.networking.md) (deep_dive, L2) — Kubernetes Networking
- [Interview: Ingress 404](../../../../library/interview-scenarios/10-ingress-404.md) (Scenario, L2) — Kubernetes Networking

<!-- wiki:related:end -->
