OK so apparently setting DNS to 0.0.0.0 means setting the upstream DNS so that works to close off DNS.
And then I can use firewall-cmd to configure container networking policies, except for some reason the firewall zone is hardcoded to "trusted" by podman so I have to use that one...???