A container's isolation is only as strong as the code that serves its syscalls. With runc, that code is the host kernel, shared by every container on the node: namespaces, cgroups and seccomp are checks inside it; one bug in a syscall path the container can reach is code execution in the host kernel. A sandboxed …
Read MoreA container is an ordinary Linux process, wrapped in constraints the kernel already has. The kernel has no container object. A container is a process tree plus: namespaces: its own view of PIDs, the network, the mounts, the hostname; a cgroup: limits on memory, CPU and the number of processes; a changed root: the …
Read More