Linux Container Basics: Namespaces and cgroups Explained
Containers are not magic. They are two kernel features, namespaces and cgroups, wrapped by a runtime. Understanding them makes container debugging far easier. Containers feel like magic until you learn that they are built from two kernel features that have existed for years: namespaces and cgroups. Docker, Podman, containerd, and every other container runtime wrap these primitives into a convenient interface. Understanding the underlying mechanisms has made my debugging of containerized systems far more effective, because when something goes wrong, the runtime abstractions often obscure the cause. Here is what namespaces and cgroups actually do. Namespaces: What a Process Sees A namespace limits what a process can see. Without namespaces, every process sees the same mount table, network interfaces, process list, and hostname. With namespaces, a process gets its own isolated view of each. This isolation is what makes a container feel like a separate machine. The main namespace types are: mnt : isolates the mount table, so the container has its own filesystem view pid : isolates process IDs, so the container only sees its own processes net : isolates network interfaces, routing, and firewall rules ipc : isolates interprocess communication primitives…