Containers & Linux Internals
Containers & Linux Internals
7 interactive questions
What makes a container? Namespaces + cgroups?
Namespaces isolate what you see: PID (process tree), NET (network stack), MNT (mount points), UTS (hostname), IPC (shared memory), USER (UID/GID mapping). cgroups (control groups) limit what you use: CPU, memory, I/O, devices. Together = lightweight virtualization.
What happens when you run `docker run`?
- Client → daemon (API). 2. Pull image if missing (layers). 3. Create container: allocate namespaces, cgroups, mount image layers (overlayfs), set up network (veth pair, bridge), apply seccomp/apparmor/seccomp profile. 4.
runcstarts the process as PID 1 in the namespace.
What is the difference between an image and a container?
Image — read-only template (layers + metadata + config). Container — running instance with a writable top layer (copy-on-write). Multiple containers can share the same image.
What is the OCI runtime spec?
Open Container Initiative standard for container runtime (runc, crun, runsc, kata-runtime). Defines: config.json (namespaces, cgroups, mounts, hooks, capabilities), rootfs bundle. runc is the reference implementation.
How does container networking work?
Default: bridge (docker0). Each container gets a veth pair — one end in container (eth0), one in host bridge. NAT for outbound (MASQUERADE). Port mapping: DNAT on host. --network host shares host stack; --network none isolates.
What is a container escape and how to prevent it?
Breaking out of namespace/cgroup isolation to access host. CVEs in kernel, runc, misconfigured privileges (--privileged, --cap-add=ALL, host PID/IPC/NET). Mitigations: drop capabilities, read-only rootfs, seccomp, user namespaces (rootless), gVisor/kata (VM boundary).
What is the difference between `docker` and `containerd`?
Docker — full platform (CLI, daemon, build, compose, registry). containerd — CRI-compliant runtime (pull, push, snapshot, run containers). Docker uses containerd under the hood. Kubernetes uses containerd/CRI-O directly.