8 parts · 8 chapters
Containers and Virtualisation from Scratch
A container is a normal Linux process with a restricted view and limited resources. This course builds one from system calls, then climbs to the standards (OCI) that Docker and Kubernetes use, and down to the virtual machines and sandboxes used when a shared kernel is not isolation enough.
Eight parts: namespaces; cgroups v2; overlay filesystems and image layers; a container runtime in about a hundred lines of Go; OCI images, registries and runtimes (runc, containerd, CRI-O); seccomp, capabilities and rootless containers; hypervisors and KVM; and Firecracker microVMs and gVisor.
isolationNamespaces hide the rest of the machine.
limitscgroups cap CPU, memory, I/O and process counts.
imagesLayers stacked with overlayfs, addressed by digest.
runtimeclone, mount, pivot_root, exec: written in Go.
hardeningseccomp filters, dropped capabilities, user namespaces.
vmsKVM, Firecracker and gVisor for stronger boundaries.
00
Namespaces
Building isolation by hand
1 ch · ~8 min01cgroups v2
Limiting a process with mkdir and echo
1 ch · ~8 min02Overlay Filesystems
Layers by hand, then in a Dockerfile
1 ch · ~8 min03A Container Runtime in Go
About a hundred lines
1 ch · ~8 min04OCI Images and Runtimes
Specs, digests and runtimes
1 ch · ~8 min05seccomp and Capabilities
Least privilege, enforced
1 ch · ~8 min06Hypervisors and KVM
The kernel as a hypervisor
1 ch · ~8 min07Firecracker and gVisor
Sandboxes compared
1 ch · ~8 minBuilt on Kernel InternalsUses Kernel Internals P7 for namespaces and cgroups and C Systems Programming for the syscalls; Deploy and Platform courses use the result.