Table of Contents
What is the isolation of docker containers?
Home Operation and Maintenance Docker What is the isolation of docker containers by?

What is the isolation of docker containers by?

Aug 15, 2022 pm 04:42 PM
docker

Docker containers achieve isolation through the Linux kernel technology Namespace; the "Linux Namespaces" mechanism provides a resource isolation solution. The resources under each namespace are transparent and invisible to the resources under other namespaces. Therefore, at the operating system level, there will be multiple processes with the same pid.

What is the isolation of docker containers by?

The operating environment of this tutorial: linux7.3 system, docker version 19.03, Dell G3 computer.

What is the isolation of docker containers?

Docker mainly relies on the Linux kernel technology Namespace to achieve isolation. The Linux Namespaces mechanism provides a resource isolation solution.

PID, IPC, Network and other system resources are no longer global, but belong to a specific Namespace. Resources under each namespace are transparent and invisible to resources under other namespaces. Therefore, at the operating system level, there will be multiple processes with the same pid. There can be two processes with process numbers 0, 1, and 2 in the system at the same time. Since they belong to different namespaces, there is no conflict between them. At the user level, only resources belonging to the user's own namespace can be seen. For example, using the ps command can only list processes under the user's own namespace. This way each namespace looks like a separate Linux system.

What is the isolation of docker containers by?

The example is as follows: Process isolation

Start a container

docker run -it -p 8080:8080 --name pai-sn pai-sn:snapshot /bin/bash
Copy after login

-it Interactive startup, -p port mapping, –name The container name is followed by the image name, open the shell, and enter the container after startup

View process

ps -ef
Copy after login

What is the isolation of docker containers by?

Use the top command to view process resources

What is the isolation of docker containers by?

View the process currently executing the container on the host machine ps -ef|grep pai-sn

What is the isolation of docker containers by?

From this, we can know that the docker run command starts only one process, and its pid is 4677. As for the container program itself, it is isolated, and only its own internal processes can be seen inside the container. Docker is implemented with the help of the Namespace technology of the Linux kernel.

File isolation

Execute the ls command in the root directory inside the container

What is the isolation of docker containers by?

Inside the container These folders have been included

The host executes docker info to see what file system our Docker uses

What is the isolation of docker containers by?

The Docker version is 20.10 .6. The storage driver is overlay2. Different storage drivers behave differently in Docker, but the principles are similar.

The Docker file system is mounted through mount. Execute docker ps command instance id

What is the isolation of docker containers by?

Execute docker inspect container_id | grep Mounts -A 20 to find Mount the directory on the host machine, check the directory list

What is the isolation of docker containers by?

and find that this is consistent with the directory of our container, we create a new directory in this directory, and then look See if a new directory will appear inside the container. In fact, file isolation and resource isolation are all done by mounting in the new namespace.

Recommended learning: "docker video tutorial"

The above is the detailed content of What is the isolation of docker containers by?. For more information, please follow other related articles on the PHP Chinese website!

Statement of this Website
The content of this article is voluntarily contributed by netizens, and the copyright belongs to the original author. This site does not assume corresponding legal responsibility. If you find any content suspected of plagiarism or infringement, please contact admin@php.cn

Hot AI Tools

Undresser.AI Undress

Undresser.AI Undress

AI-powered app for creating realistic nude photos

AI Clothes Remover

AI Clothes Remover

Online AI tool for removing clothes from photos.

Undress AI Tool

Undress AI Tool

Undress images for free

Clothoff.io

Clothoff.io

AI clothes remover

Video Face Swap

Video Face Swap

Swap faces in any video effortlessly with our completely free AI face swap tool!

Hot Tools

Notepad++7.3.1

Notepad++7.3.1

Easy-to-use and free code editor

SublimeText3 Chinese version

SublimeText3 Chinese version

Chinese version, very easy to use

Zend Studio 13.0.1

Zend Studio 13.0.1

Powerful PHP integrated development environment

Dreamweaver CS6

Dreamweaver CS6

Visual web development tools

SublimeText3 Mac version

SublimeText3 Mac version

God-level code editing software (SublimeText3)

How to update the image of docker How to update the image of docker Apr 15, 2025 pm 12:03 PM

The steps to update a Docker image are as follows: Pull the latest image tag New image Delete the old image for a specific tag (optional) Restart the container (if needed)

How to exit the container by docker How to exit the container by docker Apr 15, 2025 pm 12:15 PM

Four ways to exit Docker container: Use Ctrl D in the container terminal Enter exit command in the container terminal Use docker stop <container_name> Command Use docker kill <container_name> command in the host terminal (force exit)

How to copy files in docker to outside How to copy files in docker to outside Apr 15, 2025 pm 12:12 PM

Methods for copying files to external hosts in Docker: Use the docker cp command: Execute docker cp [Options] <Container Path> <Host Path>. Using data volumes: Create a directory on the host, and use the -v parameter to mount the directory into the container when creating the container to achieve bidirectional file synchronization.

How to restart docker How to restart docker Apr 15, 2025 pm 12:06 PM

How to restart the Docker container: get the container ID (docker ps); stop the container (docker stop <container_id>); start the container (docker start <container_id>); verify that the restart is successful (docker ps). Other methods: Docker Compose (docker-compose restart) or Docker API (see Docker documentation).

How to use docker desktop How to use docker desktop Apr 15, 2025 am 11:45 AM

How to use Docker Desktop? Docker Desktop is a tool for running Docker containers on local machines. The steps to use include: 1. Install Docker Desktop; 2. Start Docker Desktop; 3. Create Docker image (using Dockerfile); 4. Build Docker image (using docker build); 5. Run Docker container (using docker run).

How to view the docker process How to view the docker process Apr 15, 2025 am 11:48 AM

Docker process viewing method: 1. Docker CLI command: docker ps; 2. Systemd CLI command: systemctl status docker; 3. Docker Compose CLI command: docker-compose ps; 4. Process Explorer (Windows); 5. /proc directory (Linux).

How to check the name of the docker container How to check the name of the docker container Apr 15, 2025 pm 12:21 PM

You can query the Docker container name by following the steps: List all containers (docker ps). Filter the container list (using the grep command). Gets the container name (located in the "NAMES" column).

How to start mysql by docker How to start mysql by docker Apr 15, 2025 pm 12:09 PM

The process of starting MySQL in Docker consists of the following steps: Pull the MySQL image to create and start the container, set the root user password, and map the port verification connection Create the database and the user grants all permissions to the database

See all articles