How Linux Isolates

Under the Hood: How Linux Actually Isolates a Container

Three kernel features turn a process into a container: namespaces decide what it can see, control groups decide how much it can use, and an overlay filesystem gives it a root built from image layers. This section takes each apart with ordinary tools (lsns, unshare, /sys/fs/cgroup, mount), then follows docker run down through containerd 234,762 and runc 13,463 . The listings run in one shell session and inspect two containers, l3-ns and l3-limited.

Subsections