On a Linux VM (not a production machine), explore what a container really is.
- Run
docker run -d --name web -m 256m --cpus 0.5 nginx. Find its processes on the host (ps -ef | grep nginx,docker top web). Compare the PIDs seen inside (docker exec web psorcat /proc/1/status) and outside. Which namespaces does it have (ls -l /proc/<pid>/ns)? - Find its cgroup (
cat /proc/<pid>/cgroup) and readcpu.max,memory.maxandcpu.stat(nr_throttled, throttled_usec) under/sys/fs/cgroup/.... Generate load (e.g.,aborheyagainst nginx, orstressinside a container) and watch throttling grow. - Create an isolated shell without Docker:
sudo unshare --pid --fork --mount-proc --uts --net bash. Inside, runps -ef,hostname demo,ip link. What is isolated, what is not (file system, users)? docker image inspect nginx/docker history nginx: how many layers? Start a second nginx container and usedocker system df -vto show that layers are shared.- Write a paragraph: what does a container runtime add on top of namespaces and cgroups (images, networking, seccomp, capabilities, logging)? When would you still choose a VM?