bk99.de entertain the web since 1997

Docker basics in a hundred lines of Bash

Summary

Peter Wilmott recreates images, containers, networks and resource limits with shell commands and Linux kernel mechanisms. Bocker consists of about a hundred lines of Bash. The project requires Linux.

Ideas

  • Namespaces isolate processes, mounts, networks and host names.
  • Cgroups limit CPU and memory consumption.
  • Chroot and overlay file systems form a separate root file tree.
  • iptables and virtual Ethernet pairs connect containers to the network.

Insights

  • Containers become understandable when their kernel building blocks are visible individually.
  • Short teaching code explains concepts but is not a secure production runtime.
  • Isolation arises from several mechanisms, each with its own limits.

Facts

  • It needs numerous command line tools and root privileges.

Recommendations

  • Only run Bocker in an isolated learning environment.
  • Check namespaces, capabilities and cgroups separately.

References

Read the original article

Search the Web Archive