Module 03 of 11

Underlying Technologies

Lessons

About This Module

Docker doesn't invent isolation from scratch. It packages features the Linux kernel already has. This module gives you the basic idea of those features so containers stop feeling like magic. You don't need deep expertise, because Docker manages all of this for you.

It covers three building blocks. Namespaces give a process its own isolated view of resources such as process IDs, network interfaces, and mount points, which is what makes a container look like its own machine. cgroups limit and account for how much CPU, memory, and I/O a container can use. Union filesystems layer read-only image layers with a thin writable layer on top, which is the basis of image layer caching.

Watch the lessons in order (the last one is an optional deep dive), then continue on to Installation & Setup.

Lessons

5 videos
01

Linux Namespaces and Their Part in Containers

A quick introduction to Linux namespaces and how they relate to what we think of as containers: giving a process its own isolated view of the system.

02

Linux cgroups Explained: Limiting Resources

How the cgroup kernel feature limits the resources a process or set of processes can use. This is what stops one container from starving the rest of the host.

03

Understanding OverlayFS

A deep dive into OverlayFS, the filesystem Docker uses to stack image layers and add a writable layer on top for a running container.

04

Container Security Fundamentals: Cgroups, Namespaces & Capabilities

How cgroups, namespaces, and Linux capabilities combine to create isolation in Docker, a good recap that puts the pieces together.

05

Containers Unplugged: Linux Namespaces (Optional Deep Dive)

Michael Kerrisk's conference talk on how each namespace type wraps a global system resource. Optional: a basic idea of namespaces is enough for day-to-day Docker.