Linux containers in 500 lines of code
Summary
Liz Rice builds a small container in Go and makes namespaces, cgroups, the root file system and process start directly visible in the code. The example comprises about 500 lines of Go. It uses Linux-specific system calls.
Ideas
- clone starts a process in new Linux namespaces.
- UTS and PID namespaces separate host names and process IDs.
- A separate root file system limits the visible file hierarchy.
- Cgroups restrict resources outside the isolated process tree.
Insights
- Containers arise from several kernel mechanisms, not from a single container function.
- Isolation and resource limits solve different problems.
- Short teaching code shows trust boundaries more clearly than large production tools.
Facts
- A container shares the kernel with its host.
Recommendations
- Only run the teaching container on an expendable test system.
- Check namespaces, capabilities and cgroups as separate layers of protection.
References
Links to the original source and the Web Archive open in a new tab.