Linux containers in 500 lines of code

A deep dive into building Linux containers from scratch in just 500 lines of code. The author explores kernel features like namespaces and capabilities, highlighting security pitfalls such as user namespace privilege escalation. Includes code examples, discussions of distribution patches (Ubuntu, Debian, Arch), and practical demonstrations of container isolation.

If a (real) root user has had the SYS_CAP_ADMIN capability removed, but then creates a user namespace, this capability is restored for the (fake) root user.

More from this day

2026-10-05