
Linux Server User Namespaces for Container Security
User namespaces are a powerful Linux kernel feature that lets containers run as ‘root’ inside their namespace while actually running as an unprivileged user on the host. In this episode, Lucas and Luna walk through a real-world scenario: an attacker who compromises a containerized web app and tries to escape to the host. With user namespace mapping, the attacker’s root privileges inside the container are worthless outside it. They explain how UID 0 inside maps to UID 100000 outside, why this breaks privilege escalation, and how to configure user namespaces with Podman and runc. They also discuss the trade-offs: not all system calls are sandboxed, and filesystem permissions get tricky. Practical takeaways include how to verify mappings, how to avoid common misconfigurations, and why user namespaces are not a silver bullet but a critical layer in defense-in-depth. A must-listen for any engineer hardening container hosts.
#LinuxServer #Sysadmin #ContainerSecurity #UserNamespaces #Podman #Docker #KernelSecurity #PrivilegeEscalation #DefenseInDepth #UIDMapping #RootlessContainers #ContainerEscape #SecurityHardening #FexingoBusiness #BusinessPodcast #Technology #LinuxAdmin #ServerEngineering
Keep every episode free: buymeacoffee.com/fexingo
Information
- Show
- FrequencyUpdated Daily
- PublishedJuly 29, 2026 at 11:08 PM UTC
- Length9 min
- Season3
- Episode138
- RatingClean