3 ms·
Linux namespaces isolate certain functionality for a group of processes. See more here: http://man7.org/linux/man-pages/man7/namespaces.7.html http://man7.org/l
by cesnja 11y ago
Linux namespaces isolate certain functionality for a group of processes. See more here: http://man7.org/linux/man-pages/man7/namespaces.7.html http://man7.org/linux/man-pages/man7/namespaces.7.html
And yes, a blank new network namespace won't even have the loopback interface available. There is a program named unshare, which executes a program in another namespace.
- digi_owl 11y agoReally wish there was a basic set of commands for manipulating namespaces. It seems we are reliant on support being baked into larger tools like systemd at present, and said tools may not allow the user/admin to manipulate namespaces directly.
- krakensden 11y ago"ip" will let you futz around with network namespaces in an ad hoc way. There's a good LWN intro to it somewhere.
- tobbyb 11y agoThe unshare tool [1] can be used along with ip-tools to create a namespace with networking support. Add a chroot or pivot root to it and you have a Linux container. It's quite easy to do. We have a guide on using namespaces directly and the various projects using it including Firejail here [2] Linux namespaces were created to support containers. This is how userland container projects like LXC, Docker and Nspawn work, only they don't use the unshare tool but the underlying system calls clonens, setns and unshare [3]. [1] http://man7.org/linux/man-pages/man2/unshare.2.html http://man7.org/linux/man-pages/man2/unshare.2.html [2] https://www.flockport.com/alternatives-to-docker-and-lxc/ https://www.flockport.com/alternatives-to-docker-and-lxc/ [3] https://lwn.net/Articles/531114/ https://lwn.net/Articles/531114/