OS//virtualization//container//cgroups
Cgroups (control groups) are a Linux kernel feature that organises processes into groups and limits, prioritises and accounts for the resources each group uses (CPU time, memory, disk and network I/O, number of processes), and they are what keeps one container from starving the others on the same machine. Where namespaces decide what a process can see, cgroups decide how much it can consume. Google engineers started the work in 2006 and it entered the mainline kernel in 2008; the redesigned cgroup v2 is the default in current distributions.
Cgroups (control groups) are a Linux kernel feature that organises processes into groups and limits, prioritises and accounts for the resources each group uses (CPU time, memory, disk and network I/O, number of processes), and they are what keeps one container from starving the others on the same machine. Where namespaces decide what a process can see, cgroups decide how much it can consume. Google engineers started the work in 2006 and it entered the mainline kernel in 2008; the redesigned cgroup v2 is the default in current distributions.
The limits behave differently by resource, and the difference matters in operation:
CPU is shared gracefully. A group given a quota or a weight is slowed down (throttled) when it exceeds it, so a busy container runs slower but keeps running. A latency-sensitive service throttled every scheduling period shows up as unexplained slow requests even though average CPU looks fine.
Memory cannot be throttled the same way. A group that exceeds its hard memory limit has a process killed by the kernel's out-of-memory killer, which is why a container sized too tightly dies abruptly instead of slowing down.
I/O and process counts are capped to stop a runaway job from saturating a disk or forking without end.
Cgroups are the accounting and the brakes of a shared machine. An orchestrator such as Kubernetes turns each container's declared requests and limits into cgroup settings, so the scheduler can pack many workloads on one node and trust that none will take more than its share; they also give the per-container usage figures that monitoring and cost tracking read (FinOps).
They limit consumption only. Cgroups do nothing to stop a process from reading a file or calling the kernel; that is the work of namespaces, permissions and seccomp.
They do not isolate everything shared. Caches and memory bandwidth on the same host remain contended, so a cgroup-limited neighbour can still slow you down (multi-tenancy).