None Network

The None Network and Fully Isolated Containers

--network none gives a container a network namespace containing only the loopback interface. It can talk to itself and to nothing else, and it cannot even look up a name:

A container with no network at allShell
docker run --rm --network none alpine:3 sh -c \
  'ip addr | grep -E "^[0-9]|inet "; wget -T 2 -qO- http://example.com || echo "wget exit $?"'
Output
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1000
    inet 127.0.0.1/8 scope host lo
wget: bad address 'example.com'
wget exit 1

This is Docker 514 's strongest network isolation, suited to jobs that only transform files: converting uploads, parsing untrusted documents, or proving a test suite has no external dependencies. Compromised code there cannot send data out. A job that needs one specific service fits an internal network (Customizing a Bridge Network) better.