Featured Developer Sponsor • Zero-Token Protection
OCI Runtime Spec
Linux Kernel Namespaces
OverlayFS Union Mount
Linux Namespaces, OCI Container Runtime & OverlayFS Architecture Studio
Architect bare-metal Linux containers from first principles: explore kernel isolation across 7 namespaces (PID, NET, MNT, IPC, UTS, USER, CGROUP), simulate OverlayFS Copy-on-Write layer merges and whiteout deletions, verify pivot_root vs chroot jailbreak security, and synthesize production OCI config.json and C/Rust runtime blueprints.
7 of 7 Active
Isolated Namespaces
PID 1 (Host: 10,482)
Process Virtualization
UID 0 -> 100,000
Rootless User Mapping
3 Lower + 1 Upper
OverlayFS Layers
pivot_root (Secure)
Root Isolation Type
CAP_SYS_ADMIN Dropped
Capability Profile
1. Linux Kernel Namespaces Virtualization Matrix
Toggle active kernel namespaces to observe process tree, network stack, and user ID isolation
CLONE_NEWPID
PID Virtualization
PID Virtualization
CLONE_NEWNET
Network Stack
Network Stack
CLONE_NEWNS
Mount Table
Mount Table
CLONE_NEWIPC
IPC Message Queues
IPC Message Queues
CLONE_NEWUTS
Hostname (my-container)
Hostname (my-container)
CLONE_NEWUSER
UID/GID Mapping
UID/GID Mapping
CLONE_NEWCGROUP
Cgroup Hierarchy
Cgroup Hierarchy
Container has full namespace isolation. Process runs as PID 1 inside container (mapped to host PID 10482). Network isolated via veth0 pair. User UID 0 maps to host UID 100000 (Rootless mode). Old root detached via pivot_root.
2. OverlayFS Union Mount & Copy-Up Simulator
Simulate file modifications, additions, and whiteout deletions across stacked image layers
3. Production OCI Runtime Blueprints & Specifications
Sponsored Utility
While You're Here
Sponsored Recommendations
Advertisement