The current puppet configuration for releases1002 and release2002 disable docker's built in iptables rules but don't include our profile::docker::builder which provides such rules via ferm. Without proper iptables nat rules, container networking is effectively disabled.
We should either set iptables: true in profile::docker::engine::settings for releases hosts, or include the builder profile.