Part 0 · 1 chapters · ~8 min

Namespaces

The eight namespace types (mount, PID, network, UTS, IPC, user, cgroup, time), clone, unshare and setns, PID 1 responsibilities inside a container (signals and reaping zombies), network namespaces with veth pairs and bridges, user namespaces and UID mapping, and nsenter for debugging.

1

Building isolation by hand

code
# Linux only. A shell in new PID, mount, UTS and network namespaces
sudo unshare --pid --fork --mount-proc --uts --net bash
hostname box; ps aux                  # PID 1 is bash; only two processes visible
ip link                               # only lo, and it is down

# connect a network namespace to the host with a veth pair
sudo ip netns add ct1
sudo ip link add veth-host type veth peer name veth-ct
sudo ip link set veth-ct netns ct1
sudo ip addr add 10.10.0.1/24 dev veth-host && sudo ip link set veth-host up
sudo ip netns exec ct1 ip addr add 10.10.0.2/24 dev veth-ct
sudo ip netns exec ct1 ip link set veth-ct up && sudo ip netns exec ct1 ip link set lo up
ping -c1 10.10.0.2                    # host reaches the namespace; Docker adds a bridge (docker0) and NAT

# debug a running container's namespaces from the host
sudo nsenter -t $(docker inspect -f '{{.State.Pid}}' api) -n ss -tlnp

PID 1 duties: inside a PID namespace, the first process must reap orphaned zombies and handle signals; the kernel does not apply default signal actions to PID 1, so a Node process as PID 1 may ignore SIGTERM unless it installs a handler. Use docker run --init (tini) or handle signals explicitly (Deploy course).

ONE PROCESS, NEW NAMESPACES
what changes for the process inside
host viewPID 48213, eth0, /, hostname prod-7clone(CLONE_NEWPID NEWNS container viewPID 1, lo only, its own /, hostname boxsame kernelsame scheduler, same page cache
swipe the figure sideways, or tap expand for full screen
1/4
one syscall
clone (or unshare) with namespace flags starts a process in new namespaces. Nothing else is created: no VM, no daemon required.
flags on clonea process, not a VM