Namespaces
▶
Light-weight virtualization
▶
Only one kernel running, no additional layers
▶
Change how processes see the system
▶
Identifiers like PIDs, paths, etc. can have different
meanings in each namespace
▶
PID 42 can be a different process in each namespace
▶
Directory
/
can be a different directory in each namespace
▶
. . .
▶
Can be used to build application containers
without possibility to escape
▶
Usable without root access
Philipp Wendler 11 / 21