Get the App
SLTechnology News&Howtos  ›  Servers  › 

The method of Network isolation for docker Container

Shulou Source: shulou.com Published: 2022-06-03 05:49:14 10月03日 Update

What I want to share with you today is the method of network isolation for docker containers. Docker can create an isolated network environment for containers. In an isolated network environment, containers have a completely independent network stack and are isolated from host hosts. Containers can also share the network namespaces of hosts or other containers, which can basically meet the needs of developers in various scenarios.

The network of docker container usually includes host mode, container mode, none mode, bridge mode and so on.

In host network mode

Docker uses Linux's Namespaces technology to isolate resources, such as PID Namespace isolation process, Mount Namespace isolation file system, Network Namespace isolation network and so on. A Network Namespace provides an independent network environment, including network cards, routing, Iptable rules, etc. are isolated from other Network Namespace.

When we execute any similar ifconfig command in the container to view the network environment, all we see is the information on the host. For external access to applications in the container, you can directly use 10.10.101.105 NAT 80 without any conversion, just like running directly in the host. However, other aspects of the container, such as file systems, process lists, and so on, are isolated from the host.

In container network mode

Instead of creating its own Nic and configuring its own IP, the newly created container shares IP, port range, and so on with a specified container. Similarly, apart from the network, the two containers are isolated, such as file systems, process lists, and so on. The processes of the two containers can communicate through the lo network card device.

Container cloud products are implemented by deploying container services on cluster servers through docker technology, with tens of thousands of Linux images, powerful, easy to use, easy to use as cluster services and free to build VPCs.

Tags: Container network isolation mode host environment process host file system network card service two technology aspect or cluster independent method powerful Apple Docker Huawei Linux macOS MariaDB Microsoft MySQL NVidia OPPO Reno Redmi Linux Microsoft Shulou Technology MySQL