ZZomato·Tech KnowledgeL2Machine Coding

Docker Internal Implementation

Problem Explain how Docker works internally — what mechanisms give a container its isolation?

Be ready to discuss

  • Namespaces: PID, network, mount, UTS, IPC, and user namespaces each give the container its own view of one kernel resource — its own process tree, network stack, filesystem mounts, hostname, and UID mapping.
  • cgroups: control groups enforce and account resource limits per container — CPU shares/quota, memory ceilings and the OOM killer, block I/O and PID limits.
  • Union filesystem: images are stacked read-only layers (overlay2), one per Dockerfile instruction, with copy-on-write and a thin writable layer added at container start — which is why layer ordering drives cache hits and image size.
  • The key distinction: containers share the host kernel and are process isolation, not virtualization — no guest OS or hypervisor, hence fast start and low overhead, but a weaker security boundary than a VM.
  • Runtime architecture: the Docker daemon delegates to containerd and runc (OCI runtime), so "Docker" is a toolchain over standard kernel features rather than a single monolith.
  • Networking and storage: bridge/host/none network drivers, veth pairs and NAT for port publishing, and volumes/bind mounts for state that must outlive the container.
  • Security hardening layers: capabilities dropping, seccomp and AppArmor/SELinux profiles, and why running as root inside a container still matters.
asked …
LeaderboardSalaryAccount