What a Container Is

Processes, Not Machines: What a Container Actually Is

A container is an ordinary Linux process with a restricted view of the system. There is no small computer inside it and no second kernel. Docker 514 asks the host kernel for a process with private views of process IDs, mounts, network and hostname (namespaces), caps its CPU and memory (cgroups), and gives it a root filesystem unpacked from an image. Start a container that sleeps, then find it from the host:

Finding a container's process on the hostShell
docker run -d --name l3-sleeper alpine:3 sleep 3600
PID=$(docker inspect -f '{{.State.Pid}}' l3-sleeper)
pstree -sp "$PID"
docker exec l3-sleeper ps
docker stats --no-stream --format '{{.Name}}: {{.MemUsage}}' l3-sleeper
Output
0f8f4e74ff94e0e95cf8baeac91e65bf298342a5e4e3309f613081721c678776
systemd(1)---containerd-shim(358329)---sleep(358354)
PID   USER     TIME  COMMAND
    1 root      0:00 sleep 3600
    7 root      0:00 ps
l3-sleeper: 504KiB / 31.28GiB

From the host, the container is sleep, process 358354, a child of a containerd-shim. From inside, the same process believes it is PID 1 and sees nothing else (a PID namespace, PID and Mount Namespaces). It uses 504 KiB of memory, because a container costs what its processes cost, and its limit is the whole machine until you set a cgroup limit (Resource Limits).

An image is the template: read-only filesystem layers plus metadata such as the default command. A container is an instance of an image with a thin writable layer on top. Images are to containers what programs are to processes.