Running in an existing network namespace
Normally, Docker creates a new network namespace for each container we run. The network namespace of the container corresponds to the sandbox of the container network model we described earlier on. As we attach the container to a network, we define an endpoint that connects the container network namespace to the actual network. This way, we have one container per network namespace.
Docker provides an additional way for us to define the network namespace that a container runs in. When creating a new container, we can specify that it should be attached to (or maybe we should say included in) the network namespace of an existing container. With this technique, we can run multiple containers in a single network namespace:
Figure 10.15 – Multiple containers running in a single network namespace
In the preceding diagram, we can see that in the leftmost network namespace, we have two containers. The two containers...