A network namespace has its own interfaces, addresses, routes, firewall rules and ports, so two containers can both listen on port 3000. Docker 514 adds a virtual Ethernet pair, one end in the container as eth0 and the other on the docker0 bridge (Docker Networking). A UTS namespace holds the hostname; an IPC namespace isolates System V and POSIX shared memory and message queues.
sudo unshare --uts --net sh -c 'hostname l3-box; hostname; ip -brief link'
hostname
docker run --rm --network none alpine:3 ip link
docker run --rm --hostname l3-web alpine:3 hostnameOutput
l3-box
lo DOWN 00:00:00:00:00:00 <LOOPBACK>
PHANG
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 qdisc noqueue state UNKNOWN qlen 1000
link/loopback 00:00:00:00:00:00 brd 00:00:00:00:00:00
l3-webThe host's hostname is still PHANG, and the fresh network namespace holds only lo, down. --network none gives the same empty namespace with lo up. --network container:l3-ns shares another container's network, as a Kubernetes 5,150 pod's containers do (Kubernetes).