Namespaces

Linux Namespaces: Isolating What a Process Can See

A namespace gives the processes inside it a private instance of a global resource. Linux has eight kinds: mount, PID, network, UTS (hostname), IPC, user, cgroup and time. Children inherit their parent's namespaces unless they ask for new ones with clone(), unshare() or setns(). lsns lists a process's namespaces:

The namespaces of a running containerShell
docker run -d --name l3-ns alpine:3 sleep 3600 >/dev/null
PID=$(docker inspect -f '{{.State.Pid}}' l3-ns)
sudo lsns -p "$PID"
Output
        NS TYPE   NPROCS    PID USER COMMAND
4026531837 user       60      1 root /sbin/init
4026532233 mnt         1 370227 root sleep 3600
4026532234 uts         1 370227 root sleep 3600
4026532236 ipc         1 370227 root sleep 3600
4026532237 pid         1 370227 root sleep 3600
4026532238 cgroup      1 370227 root sleep 3600
4026532239 net         1 370227 root sleep 3600
4026532362 time        1 370227 root sleep 3600

The sleep is alone in seven new namespaces and shares only the user namespace with /sbin/init, because Docker 514 does not remap user IDs by default (User Namespaces). Each namespace is also a link under /proc/<pid>/ns/, which nsenter uses to join a running container's namespaces from the host.

One process, two views: namespaces give the container private copies of global resources
One process, two views: namespaces give the container private copies of global resources