Home / Alt manpages / docker-network(1)

  • docker-network(1)
  • User command
  • linux

Create, inspect and safely remove a Docker network

You will finish with a user-defined Docker bridge network, a container attached to it, and a repeatable way to inspect and remove both. The examples use Docker Community CLI 29.8.1 from package docker-ce-cli version 5:29.8.1-1~ubuntu.24.04~noble.

Allow about fifteen minutes. You need a running Docker Engine and permission to talk to its daemon. On many installations that means using sudo or belonging to the Docker group. The commands below create and remove local Docker objects, so use the exact names shown and do not substitute a production network.

Checkpoint

This guide is complete when the network list shows no guide-net entry and the temporary container has been removed.

1. Confirm the CLI and daemon

Check the installed client first. This is an ordinary read-only command:

$ docker --version
Docker version 29.8.1, build 4a63305

Now ask the daemon for its version:

$ docker info --format '{{.ServerVersion}}'
29.8.1

If this fails with a permission or connection error, fix that prerequisite before creating anything. Adding sudo to every later command is one option, but keep it consistent: objects created through the same daemon are then easy to find and remove.

2. Check the existing network names

List the networks the Engine knows about:

$ docker network ls
NETWORK ID     NAME      DRIVER    SCOPE
...            bridge    bridge    local
...            host      host      local
...            none      null      local

The identifiers and spacing vary. The useful columns are NAME, DRIVER and SCOPE. A network name must be unique, so choose a name that is not already present. You can narrow the check without parsing a long table:

$ docker network ls --filter name=guide-net

An empty result is the safe checkpoint for the next step. The name filter matches a substring, so inspect any result rather than assuming an empty-looking search means an exact match.

3. Create a user-defined bridge network

Create a local bridge network using the CLI's documented default driver explicitly:

$ docker network create --driver bridge --label purpose=network-guide guide-net
...network-id...

The command prints the new network ID. If you omit --driver, the installed command also defaults to bridge, but spelling it out makes a copied command easier to audit. A user-defined bridge is a network on this Docker Engine. It is not automatically a multi-host network.

Do not add --internal casually. That option restricts external access to the network and changes how containers reach outside it. Likewise, choose --subnet, --gateway and --ip-range only when you have checked for overlap with the host and other networks. Docker allocates a non-overlapping subnet when you do not provide one.

Verify the object by name:

$ docker network ls --filter name=guide-net
NETWORK ID     NAME        DRIVER    SCOPE
...            guide-net   bridge    local

4. Inspect the network configuration

docker network inspect returns JSON by default. Ask for the important fields in a compact, script-friendly form:

$ docker network inspect --format '{{.Name}} driver={{.Driver}} scope={{.Scope}} internal={{.Internal}}' guide-net
guide-net driver=bridge scope=local internal=false

For the complete configuration, omit --format:

$ docker network inspect guide-net

Read the IPAM section before assigning a fixed address. It contains the Engine-selected subnet and gateway. The Containers object is empty at this point, which confirms that no container is attached yet.

5. Attach a temporary container

Start a small container directly on the network. This changes daemon state and downloads the image if it is not already cached:

$ docker run --detach --name guide-box --network guide-net busybox sleep 300
...container-id...

Use docker ps to check that it is running, then inspect the network again:

$ docker ps --filter name=guide-box
$ docker network inspect --format '{{range .Containers}}{{.Name}} {{.IPv4Address}}{{"\n"}}{{end}}' guide-net
guide-box 172.XX.0.2/16

The address is allocated from the subnet shown by your inspection, so the exact value is host-specific. The container's name and address appearing in the network output are the useful verification. Containers on the same network can communicate using another container's name or IP address.

6. Test connecting and disconnecting

A running container can join an additional network with docker network connect. To keep this test reversible, create the second network first:

$ docker network create --driver bridge guide-extra
...network-id...
$ docker network connect guide-extra guide-box
$ docker network inspect --format '{{range .Containers}}{{.Name}}{{"\n"}}{{end}}' guide-extra
guide-box

Disconnect it without stopping the container:

$ docker network disconnect guide-extra guide-box
$ docker network inspect --format '{{range .Containers}}{{.Name}}{{"\n"}}{{end}}' guide-extra

The final command should print no container name. If a container will not disconnect cleanly, docker network disconnect --force exists, but use it only when ordinary disconnection fails and you understand the service impact. The network itself remains until you remove it.

7. Clean up deliberately

Warning

Removing a network disconnects its attached containers and destroys the network's configuration. It is not an undoable edit. First stop and remove the temporary container:

$ docker rm --force guide-box
guide-box

Now remove only the two networks created in this guide:

$ docker network rm guide-extra guide-net
guide-extra
guide-net

Docker attempts each network in turn and reports success or failure for each one. Do not use docker network rm against an unfamiliar ID, and do not copy the broad cleanup pattern from a different machine without checking the result first.

docker network prune is a separate, destructive operation: it removes all unused networks. It may accept a filter and, with --force, skips the confirmation prompt. That is useful for controlled maintenance, not for cleaning up one test network.

Done means

  • docker network inspect guide-net showed a local bridge network and its IPAM details.
  • guide-box appeared in the network's Containers data with an allocated address.
  • The temporary container was removed before its networks.
  • docker network ls --filter name=guide-net and the equivalent check for guide-extra return no test network.