Containers & Linux Internals

0%
Containersdockernamespacescgroupscontainerdruncociimages

Containers & Linux Internals

7 interactive questions

ContainersQuestion
dockernamespacescgroupscontainerdruncociimages

What makes a container? Namespaces + cgroups?

Click to reveal answer
ContainersAnswer

Namespaces isolate what you see: PID (process tree), NET (network stack), MNT (mount points), UTS (hostname), IPC (shared memory), USER (UID/GID mapping). cgroups (control groups) limit what you use: CPU, memory, I/O, devices. Together = lightweight virtualization.

ContainersQuestion
dockernamespacescgroupscontainerdruncociimages

What happens when you run `docker run`?

Click to reveal answer
ContainersAnswer
  1. Client → daemon (API). 2. Pull image if missing (layers). 3. Create container: allocate namespaces, cgroups, mount image layers (overlayfs), set up network (veth pair, bridge), apply seccomp/apparmor/seccomp profile. 4. runc starts the process as PID 1 in the namespace.
ContainersQuestion
dockernamespacescgroupscontainerdruncociimages

What is the difference between an image and a container?

Click to reveal answer
ContainersAnswer

Image — read-only template (layers + metadata + config). Container — running instance with a writable top layer (copy-on-write). Multiple containers can share the same image.

ContainersQuestion
dockernamespacescgroupscontainerdruncociimages

What is the OCI runtime spec?

Click to reveal answer
ContainersAnswer

Open Container Initiative standard for container runtime (runc, crun, runsc, kata-runtime). Defines: config.json (namespaces, cgroups, mounts, hooks, capabilities), rootfs bundle. runc is the reference implementation.

ContainersQuestion
dockernamespacescgroupscontainerdruncociimages

How does container networking work?

Click to reveal answer
ContainersAnswer

Default: bridge (docker0). Each container gets a veth pair — one end in container (eth0), one in host bridge. NAT for outbound (MASQUERADE). Port mapping: DNAT on host. --network host shares host stack; --network none isolates.

ContainersQuestion
dockernamespacescgroupscontainerdruncociimages

What is a container escape and how to prevent it?

Click to reveal answer
ContainersAnswer

Breaking out of namespace/cgroup isolation to access host. CVEs in kernel, runc, misconfigured privileges (--privileged, --cap-add=ALL, host PID/IPC/NET). Mitigations: drop capabilities, read-only rootfs, seccomp, user namespaces (rootless), gVisor/kata (VM boundary).

ContainersQuestion
dockernamespacescgroupscontainerdruncociimages

What is the difference between `docker` and `containerd`?

Click to reveal answer
ContainersAnswer

Docker — full platform (CLI, daemon, build, compose, registry). containerd — CRI-compliant runtime (pull, push, snapshot, run containers). Docker uses containerd under the hood. Kubernetes uses containerd/CRI-O directly.