Building Containers from Scratch in Go: A Technical Guide

Added:

Container Basics
Initial Setup
Basic Execution
UTS Namespace
PID Namespace
Fork Exec
Root FS
Full Isolation
Cgroups Recap
Images Tools

Container Basics

0:04
Playing Section
  • 1

    Audience engagement to gauge container knowledge baseline.

  • 2

    Credits Julian Friedman for original talk inspiration.

  • 3

    Sets goal to demystify how container illusion is built.

Basic proficiency in Go programming, including handling system calls (the 'syscall' package) and command-line execution.
Fundamental Linux operating system concepts, particularly processes, the fork/exec model, and the proc filesystem (/proc).
Conceptual understanding of containerization (e.g., using Docker) and how containers differ from traditional Virtual Machines (VMs).
Introductory familiarity with Linux kernel features, specifically the general purpose of namespaces (isolation) and control groups (resource limiting).
Exploring the Open Container Initiative (OCI) runtime specifications and analyzing production-grade runtimes like runc.
Implementing advanced container networking, such as setting up virtual ethernet (veth) pairs, bridge networks, and routing between namespaces.
Applying container security mechanisms, including Linux capabilities, Seccomp filters, and configuring rootless containers using User Namespaces.
Understanding and implementing union filesystems (such as OverlayFS) to manage layered container images and copy-on-write storage.
191.8K views5.2Klikes19:03@ContainerCampOriginal Release: 2016-10-13

Containers achieve their lightweight, isolated execution environment by leveraging Linux namespaces (such as UTS for hostname, PID for process IDs, and mount namespaces for filesystem isolation) combined with control groups (cgroups) for resource limiting, which together create the illusion that a container operates in its own independent environment while actually sharing the host's kernel.