Each container has its own network namespace, solocalhostThe app refers to the same container, not the database or host. Docker Network provides the container connection path, service name DNS, outgoing access, and selective port distribution on the host. Many 502 and connection refused errors come from mistaking the internal port, host port, and service name.
Quick answer:In Compose, share the associated services on a user-defined network and connect to the service name and port.portsPost; the database and cache usually stay internal. After recreate, do not rely on fixed IP and check DNS, listener, network membership and firewall step by step.
What does Network Namespace mean?
Containers usually have separate interface, route, and port space.127.0.0.1Listening is only accessible within the same namespace; to receive from another container, you have to listen to the appropriate interface. This is not a complete security isolation, and the rules of host, capability, and driver are still important.
Default and User-defined Bridge
On a Docker host, a bridge builds a virtual network between containers and hosts. A user-defined bridge is better for the project because it makes separation and service discovery more manageable. Connecting all services to a large network makes lateral movement easier. Separate the frontend, backend, and data network based on actual need; a proxy should not necessarily have access to the database.
What network does Compose build?
If you don't define a network, Compose usually creates a default network for the project, and its real name is associated with the project prefix. Services find each other with the service name. With recreate, the IP can be changed but the name remains. Short-lived connections must be resolved again; keeping an old IP in Nginx or pool without reconnect can cause failure after deployment.
Internal port, Expose and Publish
The internal port is the same listener program in the container.exposeThe contract specifies the network access and does not necessarily open the host port.portsmapping makes the host container and may make the service accessible from the outside.8080:80So the reference to the port 8080 host goes to the port 80 container.service:80The hit, not the host port.
Release on all interfaces or Loopback.
If the host address is not specified, the port may be published on public interfaces.127.0.0.1However, check the firewall, IPv6 and environmental routes separately. Don't assume that because the cloud security group is closed, the host configuration is also secure.
Service Discovery and DNS
Docker DNS resolves the service name on a shared network. The container name or alias may work, but the stable service name is better. Check the DNS failure from within the consumer container; resolve on the host does not have the same result./etc/hostsManually or IP-hard-coded, lifecycle recreate and scale breaks.
A sample of the composite separation
services:
proxy:
image: nginx:stable
ports: ["80:80", "443:443"]
networks: [frontend]
app:
image: registry.example/app@sha256:...
networks: [frontend, backend]
db:
image: postgres:18
networks: [backend]
networks:
frontend:
backend:
internal: true
This is just a concept pattern. secret, volume, health, TLS and image version should be defined separately. The internal network has its own output/input limitations and you should check the actual dependencies of the app.
What's the difference between Host Network?
In the case of a Linux host, the container network namespace does not have a separate, standalone IP and directly consumes the host port; thus port mapping is meaningless or ignored. This will reduce network isolation and increase conflict port. Do not migrate to host mode just to solve DNS or limited performance; measure the need, limitations of the platform and the security model.
Overlay Network for multiple hosts
The network overlay is distributed among Docker daemons and is usually associated with Swarm. It requires control/data plane ports and a special firewall. The overlay is not a high availability magic password; state, load balancing, certificate and failure node are designed separately.
Internet and NAT.
In a typical bridge, container output traffic often leaves the host with NAT. The destination service may see the IP host, not the IP container. The external allowlist, output proxy, and DNS must be aligned with this path. If the container does not have internet, check the route, DNS, firewall host, and internal network; turning off the firewall is not a secure public response.
The real IP of the user behind Reverse Proxy
The app usually sees the connection from the proxy and the user's IP is transmitted with forwarded header. Only default proxies should have the right to assign the actual IP; the client can send the desired header.The Nginx Reverse Proxy GuideHost setting explains the scheme and the confidence limit.
Do not ignore IPv6.
AAAA DNS, IPv6 firewall, and port publishing can create a different path from IPv4. IPv4 internal testing may be successful and IPv6 user may fail. Check both family from the outside.
Connection refused, timeout or DNS error?
- DNS error:Check the name, network membership and resolver.
- Connection refused:See listener, in-house port and startup.
- Timeout:Route, firewall, saturation or packet loss are possible.
- 502 proxy:Compare upstream, health, DNS cache and logs on both sides.
This is the primary diagnostic category; keep the exact message and timestamp.
MTU and some of the requests are working.
In VPN routes, the cloud overlay or tunnel may not be compatible with the outer network path. Small connections succeed but large responses, TLS handshake or upload. Measure the MTU before changing, packet loss, fragmentation, and actual path; the amount copied from another provider may create a new problem. It will.
External network and multi-project connectivity
Sometimes a shared proxy must connect to separate Compose stacks. An external network can provide this connection, but its lifecycle is outside the project anddownThe same owner stack is not removed. Document the name, owner, subnet and authorized services. Connecting all projects to the proxy network makes unwanted mutual access; keep alias and network membership to a minimum.
Subnet coverage.
If the Docker subnet is also covered by a VPN, office network, or VPC, the wrong route and timeout will only occur for certain purposes. See the host and container route table before changing. The move of an existing network subnet usually requires recreate and downtime schedule; record IPAM from the outset with the organization's networks and reserved ranges.
From which point will the test be conducted?
Successful requesting from the host itself does not prove the container path is safe. Repeat the same request from the consumer container, from the shared network, and then from outside the proxy, and record the destination name, port, and DNS response at each step. For minimal images, it is not necessary to permanently install the troubleshooting tool within the image production; a temporary, limited container can be connected to the same network. Removal is done after checking to prevent attack levels or hidden changes in the program artifact.
The process of finding fault is safe.
- Draw the expected flow from client to service.
- Compose config and inspect connected networks.
- Resolve the service name from the consumer container.
- Verify the listener and the destination's internal port.
- Measure the low-risk TCP/HTTP connection within the same network.
- Compare the proxy log, app and firewall at the same time.
- After the correction, re-audit the port exposure.
Common Mistakes
- Use localhost for other containers
- Connection to host port from internal network without need
- Proving the IP container.
- Putting proxy and database on an open network.
- Publishing cache and DB across all interfaces
- Trust the Forwarded Header from every angle.
- Switch to host network to hide the wrong configuration
When does network design need to be revised?
If you have multiple domains, proxies, workers and services, or an error occurs only after recreate, the topology and DNS should be documented.The application is Dockerized.It can design frontend/backend, exposure, health and TLS path networks to fit production.
Common Questions
Do containers need to connect to the publish port?
If they are shared on the network, they are usually connected by the service name and the internal port.
Why did the IP container change after the deployment?
Recreate creates a new sample; base the service name on the discovery.
Is the internal network completely secure?
The useful layer of constraint is, but program permissions, host and secret are still required.
Is Host Network faster?
It may remove the NAT, but the tradeoff has security and port; just select with the actual benchmark.