Skip to content
BotServBotServ
DockerNetworkingBridgeOverlayHostContainer

Docker Networking

Understand Docker networks. Bridge, Host, Overlay and custom networks for AI services.

S

schutzgeist

3 min read
Docker Networking

Docker Networking

What this article covers

  • The network types Docker offers.
  • How containers communicate with each other.
  • Creating custom networks.
  • Differences between Bridge, Host, and Overlay.
  • Tips for local AI stacks.

Introduction: Docker Networking

Docker isolates containers by default. Multi-container applications like Ollama, Open WebUI, and databases need a shared network to function. Docker provides several network drivers that enable container communication, publish ports, and allow external access. Understanding Docker networks helps you avoid common connectivity issues and build more reliable setups.

This article explains the main Docker network types and how to use them in local AI projects.

Key terms

  • Bridge: Docker’s default network.
  • Host: Container shares the host’s network stack.
  • Overlay: Network for Docker Swarm and clusters.
  • None: No network connectivity.
  • DNS: Name resolution within container networks.
  • Alias: Additional name for a container in a network.
  • Port mapping: Forwarding from host port to container port.

Standard network types

Bridge

Any container that doesn’t specify a network uses the default bridge. Containers can reach each other by IP address, but not by name. Custom bridge networks add DNS name resolution.

Host

The container uses the host’s network stack directly. No isolation, but maximum performance. Not available on Windows or macOS.

None

No network connectivity. Only for specialized use cases.

Overlay

For Docker Swarm and clusters. Enables communication between containers on different hosts.

Custom bridge networks

docker network create ki-net

Attach containers to the network:

docker run -d --name ollama --network ki-net ollama/ollama
docker run -d --name open-webui --network ki-net -e OLLAMA_BASE_URL=http://ollama:11434 ghcr.io/open-webui/open-webui:main

The open-webui container can now reach Ollama using the name ollama.

In Docker Compose

services:
  ollama:
    image: ollama/ollama
    networks:
      - ki-net

  open-webui:
    image: ghcr.io/open-webui/open-webui:main
    networks:
      - ki-net
    environment:
      - OLLAMA_BASE_URL=http://ollama:11434

networks:
  ki-net:

Publishing ports

docker run -d -p 127.0.0.1:8080:8080 open-webui

Only the host port 8080 is accessible. The container remains hidden behind the bind address.

DNS in networks

Custom bridges include built-in DNS. Containers can reach each other by name. This is especially useful in Compose stacks.

Host networking

docker run -d --network host ollama/ollama

No port mapping needed. The container listens directly on host interfaces. Less secure, but sometimes necessary.

Isolating networks

Containers that shouldn’t communicate can be placed in separate networks:

networks:
  front:
  back:

Only the desired services get access to both networks.

Troubleshooting connectivity

docker network ls
docker network inspect ki-net
docker exec -it open-webui ping ollama

If ping fails, check whether both containers are on the same network.

Common pitfalls

  • Default bridge without DNS: Container names cannot be resolved.
  • Wrong port: Confusing host port and container port.
  • Wrong bind IP: Using 0.0.0.0 instead of 127.0.0.1.
  • Container on wrong network: Reachable by IP but not by name.
  • Firewall blocking: Host firewall prevents external access.
  • Host network on macOS/Windows: Not available.

Further reading and resources

FAQ: Docker Networking

How do I reach a container by name? Use DNS name resolution on the same custom bridge network.

What’s the difference between Bridge and Host? Bridge isolates; Host shares the network stack.

Do I need Overlay? Only for Docker Swarm or clusters spanning multiple hosts.

How do I publish ports securely? Bind only to 127.0.0.1.

Why can’t Container A reach Container B? They may be on different networks.

Sources and further reading

Summary: Docker Networking

Docker networks are essential for multi-container setups. Custom bridge networks provide DNS name resolution and logical service isolation. Port mappings should bind only to 127.0.0.1. Host networking is a special case. Using docker network create, docker network inspect, and simple connectivity tests helps you diagnose network issues quickly. For AI stacks with Ollama, Open WebUI, and databases, clean networks form the foundation of stable operation.

Back to Blog
Share:

Related Posts