Ports, Networks & Volumes
Docker & Kubernetes for Interviews: lesson 3 of 12
Private names, one published port, and data that outlives the container.
Lesson 3 of 12 · 6 min
Ports, Networks & Volumes
Step 1 of 12
Two containers on a user-defined network called app-net.
The Idea
Containers on a user-defined bridge network reach each other by name; on the default bridge, only by IP. Nothing outside the host reaches a container until you publish a port: -p 8080:80 maps host port 8080 to container port 80. Files written inside a container vanish when it is removed; a volume outlives it.
Real-World Example
An API and Postgres share a network called app-net. The API connects to db:5432, and only the API publishes a port. Postgres keeps its data in a named volume, so replacing the container for an upgrade keeps every row.
The Tradeoff
Publishing binds every host address by default, so -p 8080:80 exposes the port beyond the host; 127.0.0.1:8080:80 keeps it local. Bind mounts suit live code in development but depend on the host's directory layout; volumes are managed by Docker.
Hands-On
# illustrative — a private network, a named volume, one published port
docker network create app-net
docker volume create pgdata
docker run -d --name db --network app-net -e POSTGRES_PASSWORD=dev \
-v pgdata:/var/lib/postgresql/data postgres:17
docker run -d --name api --network app-net -p 127.0.0.1:8080:8000 my-api
Your turn
Put the steps in the right order.
- Start db on it, with a named volume for its data
- Create a user-defined network
- api connects to db:5432 by name
- Start api on the same network, publishing one port
Mini quiz
1 / 3
Two containers sit on Docker's default bridge network. Can api reach db by the name db?
Sources
- Networking overview — Docker Docs
- Port publishing and mapping — Docker Docs
- Volumes — Docker Docs