What a container actually is
Namespaces and cgroups — the two kernel features containers are built from. · 9 min
A container is not a lightweight virtual machine — there's no separate kernel, no hypervisor layer; a container is a regular Linux process (or group of processes) running on the same kernel as the host, made to look isolated through two specific kernel features. Namespaces isolate what a process can see: a PID namespace makes a containerized process think it's PID 1 in its own private process tree, unaware of other processes on the host; a network namespace gives it its own network interfaces and routing table; a mount namespace gives it its own view of the filesystem. cgroups (control groups) limit and account for what a process can use — CPU, memory, disk I/O — enforced by the kernel regardless of what the process inside believes about its own resources.
This is why containers start in milliseconds and share the host kernel's resources efficiently (no second OS to boot, no hypervisor overhead), but also why container isolation is fundamentally weaker than a real virtual machine's: a kernel vulnerability, or a container run with excessive privileges, can potentially let a process escape its namespace/cgroup confinement and affect the host directly — exactly the reasoning behind avoiding `--privileged` and host-filesystem/Docker-socket mounts for anything running untrusted code, discussed in this course's own lab-architecture design decisions.
An image is a read-only template — a filesystem snapshot plus metadata about what to run — that a container is instantiated from at runtime; multiple containers can run from the same image simultaneously, each getting its own writable layer on top. A registry (Docker Hub being the most common public one) stores and distributes images, pulled down with `docker pull` before a container can be created from them.
- • Namespaces — isolate what a process can SEE (its own PIDs, network, filesystem view)
- • cgroups — limit and account for what a process can USE (CPU, memory, I/O)
- • Image — a read-only template a container is instantiated from
- • Container — a running instance of an image, with its own writable layer on top
Takeaway: A container is a regular Linux process made to look isolated via namespaces and limited via cgroups — not a separate virtual machine with its own kernel, which is exactly why container isolation, while genuinely useful, is not equivalent to full VM-level isolation.