Networking — the basics
Be able to explain IP, DNS, TLS and latency — and why a lab container with no network is safe.
Prerequisites
- DAPIs and HTTPrequired
Intuition
What happens during an API call:
- DNS:
api.example.com→93.184.216.34. One lookup, often cached. - TCP: a three-way handshake with the server (1 round trip).
- TLS: the certificate is verified and keys are exchanged (1–2 round trips). Now the traffic is encrypted.
- HTTP: the request goes out, the response comes back.
Latency = the sum of the round trips plus the server's own time. A round trip Stockholm–Frankfurt is ~25 ms; Stockholm–California ~150 ms. A new connection costs 3–4 round trips — which is why you reuse connections (a long-lived httpx.AsyncClient, keep-alive). It is often the single biggest latency win in a client.
Bandwidth ≠ latency. More bandwidth helps with big files; latency is set by distance and the speed of light.
Formal
Network isolation as a security measure. AI-grafen's lab containers run with --network none. What that means in practice:
| With no network the code cannot | Consequence |
|---|---|
| resolve DNS | no contact with named services |
| open TCP/UDP connections | no exfiltration of data |
| reach metadata services (169.254.169.254) | no cloud keys can be stolen |
| reach other containers | no lateral movement |
| fetch packages | nothing can be installed at run time |
It is the single strongest measure against malicious code in a sandbox, because almost all damage requires either that something leaves the machine or that something extra is fetched in.
The other layers in the platform (ADR-003): a read-only root filesystem, tmpfs for what must be writable, uid 65534, cap-drop ALL, no-new-privileges, CPU, memory and pid ceilings, and a timeout. Network isolation is the one that tools/isolation_check.py verifies on every CI run — precisely because it is so central.
Code
import socket, time, httpx
print(socket.gethostbyname("example.com")) # a DNS lookup
# Reuse the connection: measure the difference
with httpx.Client() as c:
for i in range(3):
t = time.perf_counter(); c.get("https://example.com"); print(i, round((time.perf_counter()-t)*1000))
# 0 210 ← DNS + TCP + TLS
# 1 35 ← the connection is reused
# 2 34
# Verify the isolation in a sandbox
docker run --rm --network none python:3.12-slim \
python -c "import socket; socket.create_connection(('1.1.1.1', 443), timeout=3)"
# OSError: [Errno 101] Network is unreachable ← exactly what should happen
Mastery means
- Explains IP, DNS, TLS and latency
- Justifies why a lab container with no network is safe
Sign in to do the exercises and build your mastery up.
Sources
- Wikipedia — Transport Layer Security (CC BY-SA 4.0) — CC BY-SA 4.0
- Docker — network drivers (Apache-2.0) — Apache-2.0