None of the existing DNS options make any sense for containers where --net=none.
Can we get something like --dns=ignore or something, where it mounts an empty resolv.conf file and doesn't get creative with trying to do some magical right thing, and never refreshes based on the host resolv.conf.
This probably isn't the right solution, but there needs to be some kind of solution.