A namespace gives the processes inside it a private instance of a global resource. Linux has eight kinds: mount, PID, network, UTS (hostname), IPC, user, cgroup and time. Children inherit their parent's namespaces unless they ask for new ones with clone(), unshare() or setns(). lsns lists a process's namespaces:
docker run -d --name l3-ns alpine:3 sleep 3600 >/dev/null
PID=$(docker inspect -f '{{.State.Pid}}' l3-ns)
sudo lsns -p "$PID"Output
NS TYPE NPROCS PID USER COMMAND 4026531837 user 60 1 root /sbin/init 4026532233 mnt 1 370227 root sleep 3600 4026532234 uts 1 370227 root sleep 3600 4026532236 ipc 1 370227 root sleep 3600 4026532237 pid 1 370227 root sleep 3600 4026532238 cgroup 1 370227 root sleep 3600 4026532239 net 1 370227 root sleep 3600 4026532362 time 1 370227 root sleep 3600
The sleep is alone in seven new namespaces and shares only the user namespace with /sbin/init, because Docker 514 does not remap user IDs by default (User Namespaces). Each namespace is also a link under /proc/<pid>/ns/, which nsenter uses to join a running container's namespaces from the host.
