OS//virtualization//container//namespaces
Namespaces are a Linux kernel feature that gives a group of processes its own private view of a global system resource, so that inside the namespace the processes see only their own processes, network, filesystem or hostname, and they are the mechanism that makes a container look like a separate machine to the software inside it. They control what a process can **see**; how much it can use is the job of cgroups.
Namespaces are a Linux kernel feature that gives a group of processes its own private view of a global system resource, so that inside the namespace the processes see only their own processes, network, filesystem or hostname, and they are the mechanism that makes a container look like a separate machine to the software inside it. They control what a process can see; how much it can use is the job of cgroups.
Each kind of namespace isolates one resource:
A PID namespace gives the processes their own numbering, with their main program as process 1, and hides every process outside. A container listing its processes sees a handful, not the host's hundreds.
A network namespace gives its own network interfaces, IP addresses, routing table and ports, so two containers can both listen on port 80 (Docker network builds on this).
A mount namespace gives its own tree of mounted filesystems, so the container sees its image as the root directory and not the host's disk.
Others isolate the hostname (UTS), inter-process communication (IPC), user and group IDs (user namespace, which lets root inside a container map to an unprivileged user outside) and the time.
A namespace is a view, and the wall behind it is the kernel everyone shares.
The processes still run on the same kernel as everything else and make system calls into it, so a namespace is an illusion of separateness maintained by that kernel. A kernel bug, a namespace left shared by mistake (running a container with the host's network or PID namespace) or excessive privileges dissolve the illusion, which is why namespaces are combined with cgroups, seccomp and dropped privileges (sandbox).
The idea is old (mount namespaces date from 2002) and the set grew over the following decade; containers are essentially an assembly of these kernel features with a packaging format on top (virtualization).