Containers unplugged: understanding user namespaces - Michael Kerrisk
User namespaces are at the heart of many interesting technologies that allow isolation and sandboxing of applications, for example running containers without root privileges and sandboxes for web browser plug-ins. In this presentation, we'll look in detail at user namespaces, building up a basic understanding of what a user namespace is and going on to questions such as: what does being “superuser inside a user namespace” allow you do (and what does it not allow); what is the relationship between user namespaces and other namespace types (PID, UTS, network, etc.); and what are the security implications of user namespaces? We'll also explore some simple shell commands that can be used for creating and experimenting with user namespaces in order to better understand how they work. Along the way, there will hopefully be time for a few live demos. You will likely find it helpful to attend my other presentation, "Linux namespaces", beforehand, but this is not essential. Save the date for NDC TechTown 2020 (31st of August - 3rd of September) Check out more of our talks at: https://ndctechtown.com/ https://www.ndcconferences.com/

Containers unplugged: Linux namespaces - Michael Kerrisk

Understanding and Working with the Cgroups Interface - Michael Anderson, The PTR Group, LLC

Understanding user namespaces - Michael Kerrisk

Keynote: After the AI Hype – What’s Real, and What’s Next - Richard Campbell - 2026

Michael Kerrisk :: Understanding Linux user namespaces

Linux user namespaces: a blessing and a curse - Ignat Korchagin - NDC TechTown 2024

Cgroups, namespaces, and beyond: what are containers made from?

Build your own Container Runtime

Network Namespaces Basics Explained in 15 Minutes

Containers From Scratch • Liz Rice • GOTO 2018

Diving deeper into control groups (cgroups) v2 - Michael Kerrisk - NDC TechTown 2021

What’s Under the Hood of Docker? Process Separation in the Linux kernel by Janos Pasztor
![Life of a Packet [I] - Michael Rubin, Google](https://i.ytimg.com/vi/0Omvgd7Hg1I/hqdefault.jpg?sqp=-oaymwEjCNACELwBSFryq4qpAxUIARUAAAAAGAElAADIQj0AgKJDeAE=&rs=AOn4CLDrL7ag0cePoj42-Q3JCy4xf56bJQ)
Life of a Packet [I] - Michael Rubin, Google

What Have Namespaces Done for You Lately?

An introduction to control groups (cgroups) version 2 - Michael Kerrisk - NDC TechTown 2021

Tutorial: Using Linux Primitives to Build Your Own Containers - Stéphane Graber & Christian Brauner

Using seccomp to limit the Linux kernel attack service - Michael Kerrisk - NDC Security 2023

The Tragedy of systemd

Linux Namespaces | TatOG Explains

