Host Network
A Docker network mode where the container shares the host's network namespace directly, using the host's IP address and ports without any NAT. Provides the best network performance but eliminates all network isolation between the container and host.
Host Network — Maximum Performance, Minimum Isolation
What Is Host Network in Simple Terms?
Normally Docker gives each container its own private network — its own IP address, its own network interfaces, its own routing table. Host network mode skips all of that. The container shares the host's network directly — it uses the same IP addresses, the same ports, the same network interfaces as if it were a process running directly on the host.
Bridge network mode: Container: eth0 = 172.17.0.2 (private) Host: eth0 = 10.0.1.50 (real IP) NAT: container traffic -> host eth0 -> internet Port mapping needed: -p 8080:80 Host network mode: Container: eth0 = 10.0.1.50 (same as host) Host: eth0 = 10.0.1.50 No NAT, no isolation No port mapping needed — container binds to host ports directlyUsing Host Network
# Run with host networkingdocker run -d --network host nginx# nginx listens on port 80 of the HOST directly# No -p needed and -p flags are IGNORED in host mode # Verify nginx is on the host networkss -tulpn | grep :80# tcp LISTEN nginx *:80 <- listening on host interface # Same effect as running nginx directly on the hostWhen to Use Host Network
GOOD use cases: Monitoring agents that need to see host network traffic (Prometheus node_exporter, network scanners) Performance-critical services where NAT overhead matters (high-frequency trading, low-latency networking) Network tools that manage host interfaces (CNI plugins, network debugging tools) BAD use cases: Most application services (port conflicts) Services that should be isolated from the host Production web servers (use bridge + port publishing instead) Multi-tenant environments where isolation is requiredPlatform Limitation
# Host network is Linux-only# Docker Desktop on macOS/Windows runs inside a VM# --network host means host of the VM, NOT your Mac # On macOS:docker run --network host nginx# nginx is on the VM's host network (10.0.2.x)# NOT on your Mac's network interface# Port mapping still required to access from Mac browser # On Linux:docker run --network host nginx# nginx is on the actual host network# Access directly at host-ip:80SecurityHost network mode eliminates all network isolation. A container running in host mode can bind to any port on the host, can reach any service on the host's network, and can potentially interfere with other services. Only use it when the performance benefit or the network access requirement genuinely cannot be achieved any other way.
Frequently Asked Questions
What exactly changes when a container uses --network host instead of the default bridge network?
The container skips Docker's virtual bridge, NAT, and iptables port-mapping rules entirely and binds directly to the host's network stack — so a process listening on port 8080 inside the container is reachable on the host's port 8080 with no `-p` mapping needed. This removes the NAT translation overhead bridge networking incurs, which matters for high-throughput or low-latency workloads like packet processing or software load balancers.
Why is host networking generally discouraged for typical application containers?
It eliminates network isolation: the container sees every network interface the host has, can bind to any host port (creating collisions between containers), and a compromised process gets direct access to the host's network namespace rather than being contained. It also doesn't work at all on Docker Desktop for Mac/Windows since containers run inside a Linux VM. Reserve it for cases where the NAT overhead is genuinely the bottleneck, not as a default.