Docker basics in a hundred lines of Bash
Summary
Peter Wilmott recreates images, containers, networks and resource limits with shell commands and Linux kernel mechanisms. Bocker consists of about a hundred lines of Bash. The project requires Linux.
Ideas
- Namespaces isolate processes, mounts, networks and host names.
- Cgroups limit CPU and memory consumption.
- Chroot and overlay file systems form a separate root file tree.
- iptables and virtual Ethernet pairs connect containers to the network.
Insights
- Containers become understandable when their kernel building blocks are visible individually.
- Short teaching code explains concepts but is not a secure production runtime.
- Isolation arises from several mechanisms, each with its own limits.
Facts
- It needs numerous command line tools and root privileges.
Recommendations
- Only run Bocker in an isolated learning environment.
- Check namespaces, capabilities and cgroups separately.
References
Links to the original source and the Web Archive open in a new tab.