World Congress 2025 Aug 20, 2025 Session details

Docker network without Docker

Oliver Seitz

Mastering Linux kernel primitives gives you total control over container networks. Strip away the Docker daemon to manually route traffic, boost performance, and remap ports without restarts.

Pause
Mute Enter Fullscreen
#1 about 3 min

Fundamentals of container network isolation and system components

How Linux namespaces and control groups restrict process access before introducing network communication pathways.

#2 about 5 min

Connecting namespaces with local virtual ethernet pairs

Constructing direct network pathways between isolated Linux namespaces using virtual ethernet interfaces.

#3 about 5 min

Connecting multiple container namespaces using virtual network bridges

Implementing network bridges to efficiently switch traffic between multiple container virtual interfaces without direct point-to-point links.

#4 about 4 min

Managing container packet flow with Linux kernel iptables

How network address translation and routing rules determine packet destinations and control layer access.

#5 about 2 min

Bypassing the Docker userland proxy for kernel networking

Disabling the default userspace proxy process allows local network traffic to route purely through kernel level packet chains.

#6 about 3 min

Inspecting default bridge architectures and custom Docker networks

Demonstrating how tooling sets up distinct isolated bridge networks to prevent default container cross-communication.

#7 about 5 min

Dissecting iptables rules preventing internal inter-bridge communication

Analyzing the specific packet filtering policies implemented to drop traffic attempting to cross isolated bridge networks.

#8 about 6 min

Manual port forwarding configuration using network address translation

Configuring kernel destination NAT rules to manually forward host ports into a running container without external tooling.

Matching moments

1:02 min

Abstracting container communication utilizing robust overlay networks

Marc Nimmerrichter · World Congress 2022

1:59 min

Orchestrating with Kubernetes against Docker and accessing slides

Philipp Krenn · World Congress 2022

3:32 min

High-level infrastructure topologies and isolation boundaries

Ryan Niño Dizon · LIVE

3:17 min

Injecting network messages directly from compromised container environments

Reinhard Reinhard · World Congress 2024

3:12 min

Configuring Docker images, networking protocols, and persistent storage volumes

Francesco Ciulla Francesco Ciulla · World Congress 2024

2:20 min

Isolating pod communication with strict network policies

Rico Komenda Rico Komenda · World Congress 2025

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 23, 2026 · 11:00–11:30

Stage 1

Docker does that? Five Docker capabilities you did not know about

Ajeet Raina, Kristiyan Velkov

Ajeet Raina
Kristiyan Velkov
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 3

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 4

Your registry can't stop a valid login. What happens then?

Khushboo Verma

Systems Engineer at Cloudflare

Khushboo Verma
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 8

Docker's Agentic Platform: Sandboxes, MCP, and the Infrastructure of Autonomous Development

Oleg Šelajev

AI and Developer Relations at Docker

Oleg Šelajev
Open session

World Congress 2026 North America

September 25, 2026 · 15:30–16:00

Mainstage

One Boundary for the Agentic Era

Mark Lechner

Chief Information Security Officer of Docker

Mark Lechner
Open session

World Congress 2026 North America

September 25, 2026 · 12:30–14:30

Stage 13

Docker sandboxes: protect your secrets, tokens, and personal data from AI agent mistakes

Kristiyan Velkov

Developer Relations Engineer at Zerops.io

Kristiyan Velkov