Part 0 · 1 chapters · ~8 min
Namespaces
The eight namespace types (mount, PID, network, UTS, IPC, user, cgroup, time), clone, unshare and setns, PID 1 responsibilities inside a container (signals and reaping zombies), network namespaces with veth pairs and bridges, user namespaces and UID mapping, and nsenter for debugging.
1
Building isolation by hand
code
# Linux only. A shell in new PID, mount, UTS and network namespaces
sudo unshare --pid --fork --mount-proc --uts --net bash
hostname box; ps aux # PID 1 is bash; only two processes visible
ip link # only lo, and it is down
# connect a network namespace to the host with a veth pair
sudo ip netns add ct1
sudo ip link add veth-host type veth peer name veth-ct
sudo ip link set veth-ct netns ct1
sudo ip addr add 10.10.0.1/24 dev veth-host && sudo ip link set veth-host up
sudo ip netns exec ct1 ip addr add 10.10.0.2/24 dev veth-ct
sudo ip netns exec ct1 ip link set veth-ct up && sudo ip netns exec ct1 ip link set lo up
ping -c1 10.10.0.2 # host reaches the namespace; Docker adds a bridge (docker0) and NAT
# debug a running container's namespaces from the host
sudo nsenter -t $(docker inspect -f '{{.State.Pid}}' api) -n ss -tlnpPID 1 duties: inside a PID namespace, the first process must reap orphaned zombies and handle signals; the kernel does not apply default signal actions to PID 1, so a Node process as PID 1 may ignore SIGTERM unless it installs a handler. Use docker run --init (tini) or handle signals explicitly (Deploy course).
ONE PROCESS, NEW NAMESPACES
what changes for the process inside
swipe the figure sideways, or tap expand for full screen
1/4
one syscall
clone (or unshare) with namespace flags starts a process in new namespaces. Nothing else is created: no VM, no daemon required.
flags on clonea process, not a VM