THINK FIRST·CODE LATER

← All labs

Linux in practice: build a container by hand

Problem

On a Linux VM (not a production machine), explore what a container really is.

  1. Run docker run -d --name web -m 256m --cpus 0.5 nginx. Find its processes on the host (ps -ef | grep nginx, docker top web). Compare the PIDs seen inside (docker exec web ps or cat /proc/1/status) and outside. Which namespaces does it have (ls -l /proc/<pid>/ns)?
  2. Find its cgroup (cat /proc/<pid>/cgroup) and read cpu.max, memory.max and cpu.stat (nr_throttled, throttled_usec) under /sys/fs/cgroup/.... Generate load (e.g., ab or hey against nginx, or stress inside a container) and watch throttling grow.
  3. Create an isolated shell without Docker: sudo unshare --pid --fork --mount-proc --uts --net bash. Inside, run ps -ef, hostname demo, ip link. What is isolated, what is not (file system, users)?
  4. docker image inspect nginx / docker history nginx: how many layers? Start a second nginx container and use docker system df -v to show that layers are shared.
  5. Write a paragraph: what does a container runtime add on top of namespaces and cgroups (images, networking, seccomp, capabilities, logging)? When would you still choose a VM?

Work it out on paper, in a document or here, then compare with the model answer. Your answer stays in your browser — it is never sent to or stored on the server.