Skip to content
Artwork for The Linux Podcast with Fexingo: Open Source Operating Systems, Distros, and Server Stack
The Linux Podcast with Fexingo: Open Source Operating Systems, Distros, and Server Stack · Sunday · 7 min

How Linux Namespaces Isolate Processes Beyond Containers

In episode 170 of The Linux Podcast, Lucas and Luna drill into Linux namespaces — the kernel feature that underpins containers but also powering systemd services, user sessions, and even Flatpak apps. They walk through the seven main namespace types, from mount to user namespaces, and explain how a single process can be isolated without a container runtime. With a concrete example of running a shell in its own namespace, they show how this technology shapes everything from security to systemd sandboxing. Plus, they discuss why namespaces are the quiet workhorse of modern Linux systems and how understanding them helps you reason about containers, systemd, and even your own home lab. The episode also touches on the recent shift toward user namespaces for unprivileged sandboxing and how this changes the threat model. Perfect for anyone who wants to go beyond the basics and truly understand what's happening under the hood. #Linux #Namespaces #Containers #Systemd #Kernel #Technology #OpenSource #OperatingSystems #ServerStack #Distros #Sandboxing #Security #Flatpak #UserNamespaces #MountNamespaces #ProcessIsolation #FexingoBusiness #BusinessPodcast Keep every episode free: buymeacoffee.com/fexingo

0:00-7:05

transcript

No transcript — this publisher did not publish one.

show notes

In episode 170 of The Linux Podcast, Lucas and Luna drill into Linux namespaces — the kernel feature that underpins containers but also powering systemd services, user sessions, and even Flatpak apps. They walk through the seven main namespace types, from mount to user namespaces, and explain how a single process can be isolated without a container runtime. With a concrete example of running a shell in its own namespace, they show how this technology shapes everything from security to systemd sandboxing. Plus, they discuss why namespaces are the quiet workhorse of modern Linux systems and how understanding them helps you reason about containers, systemd, and even your own home lab. The episode also touches on the recent shift toward user namespaces for unprivileged sandboxing and how this changes the threat model. Perfect for anyone who wants to go beyond the basics and truly understand what's happening under the hood.

#Linux #Namespaces #Containers #Systemd #Kernel #Technology #OpenSource #OperatingSystems #ServerStack #Distros #Sandboxing #Security #Flatpak #UserNamespaces #MountNamespaces #ProcessIsolation #FexingoBusiness #BusinessPodcast

Keep every episode free: buymeacoffee.com/fexingo

links1