
How Linux Namespaces Isolate Processes Beyond Containers
In episode 170 of The Linux Podcast, Lucas and Luna drill into Linux namespaces — the kernel feature that underpins containers but also powering systemd services, user sessions, and even Flatpak apps. They walk through the seven main namespace types, from mount to user namespaces, and explain how a single process can be isolated without a container runtime. With a concrete example of running a shell in its own namespace, they show how this technology shapes everything from security to systemd sandboxing. Plus, they discuss why namespaces are the quiet workhorse of modern Linux systems and how understanding them helps you reason about containers, systemd, and even your own home lab. The episode also touches on the recent shift toward user namespaces for unprivileged sandboxing and how this changes the threat model. Perfect for anyone who wants to go beyond the basics and truly understand what's happening under the hood.
#Linux #Namespaces #Containers #Systemd #Kernel #Technology #OpenSource #OperatingSystems #ServerStack #Distros #Sandboxing #Security #Flatpak #UserNamespaces #MountNamespaces #ProcessIsolation #FexingoBusiness #BusinessPodcast
Keep every episode free: buymeacoffee.com/fexingo
Information
- Show
- FrequencyUpdated Daily
- PublishedAugust 30, 2026 at 11:03 PM UTC
- Length7 min
- Season4
- Episode170
- RatingClean