8 parts · 8 chapters

Containers and Virtualisation from Scratch

A container is a normal Linux process with a restricted view and limited resources. This course builds one from system calls, then climbs to the standards (OCI) that Docker and Kubernetes use, and down to the virtual machines and sandboxes used when a shared kernel is not isolation enough.

Eight parts: namespaces; cgroups v2; overlay filesystems and image layers; a container runtime in about a hundred lines of Go; OCI images, registries and runtimes (runc, containerd, CRI-O); seccomp, capabilities and rootless containers; hypervisors and KVM; and Firecracker microVMs and gVisor.

namespaces · cgroups v2 · overlay filesystems · a container runtime in Go · OCI images and runtimes · seccomp and capabilities · hypervisors and KVM · Firecracker and gVisormid → staff · backend, platform and infrastructure engineers
isolationNamespaces hide the rest of the machine.
limitscgroups cap CPU, memory, I/O and process counts.
imagesLayers stacked with overlayfs, addressed by digest.
runtimeclone, mount, pivot_root, exec: written in Go.
hardeningseccomp filters, dropped capabilities, user namespaces.
vmsKVM, Firecracker and gVisor for stronger boundaries.
Built on Kernel InternalsUses Kernel Internals P7 for namespaces and cgroups and C Systems Programming for the syscalls; Deploy and Platform courses use the result.