The Runtime Theory
Operating SystemsIn production

Container Isolation in Linux

Recording in progress
#containers#namespaces#cgroups#linux

A container is not a VM. It is a regular process that cannot see the rest of the machine: its own process tree, network stack, mount table, and user IDs, plus a cgroup throttling its CPU and memory. This video goes through each namespace and controller, then traces what docker run does — a series of clone() and unshare() calls.

Topics covered:

  • Why containers share the host kernel
  • Namespaces: PID, mount, network, UTS, IPC, and user
  • Why PID 1 inside a container isn't the real PID 1
  • cgroups: CPU shares, memory limits, and the OOM killer
  • clone() flags and unshare(): the syscalls that build a container
  • The filesystem illusion: overlayfs and how image layers stack
  • The security model: seccomp, capabilities, and why root in a container is not root
  • Where isolation ends: syscalls and the shared kernel

Related articles

More in Operating Systems

19:20
operating systems

Virtual Memory in One Diagram

Page tables, TLB, demand paging, and copy-on-write — how your 16GB laptop 'has' 128GB of addressable memory.

Watch
In production
operating systems

Signals and Interrupts

Hardware interrupts and Unix signals — the two asynchronous mechanisms that interrupt your program, and what the kernel does between the wire and your handler.

Details
In production
operating systems

Locks and Synchronization Primitives

Mutexes, spinlocks, semaphores, and condition variables — how they map to hardware atomics and futexes, and when each one is the right tool.

Details
In production
operating systems

Memory-Mapped Files

How mmap() maps a file into your address space — demand paging from disk, the page cache, and why mapped I/O beats read() and write().

Details
In production
operating systems

File Systems Explained

How a file system stores your data — inodes, directory entries, extents, and journaling — and what actually happens on read and write.

Details
In production
operating systems

Thread Pools Explained

How thread pools work under the hood — worker threads, work queues, and why reusing threads beats spawning them for every request.

Details
In production
operating systems

Syscalls Under the Hood

What actually happens when your program calls read(), open(), or fork() — the trap, the kernel mode switch, and the return path.

Details
In production
operating systems

Virtual Memory Explained

Address translation, page tables, and the TLB — the full path from a virtual address to the physical RAM cell, including why the translation is cached.

Details
In production
operating systems

Process Scheduling, Visualized

How the Linux scheduler picks the next runnable process — time slices, priorities, CFS virtual runtime, and why your busy server still feels responsive.

Details

Depth, delivered weekly

One technical dispatch a week — articles and episode notes before they go public.

One technical dispatch per week. No noise.