Run the container in a new network namespace, to isolate the host's network from that of the container. Stages, assemblers and the tools they execute are not supposed to assume network access is available and this isolation will make sure of that.
dir_fd
os.scandir()