Topic summary

Linux namespaces

Linux namespaces

Namespaces are a feature of the Linux kernel that partition kernel resources such that one set of processes sees one set of resources, while another set of processes sees a different set of resources. The feature works by assigning the same namespace type to a set of resources and processes, but allowing those namespaces to refer to distinctly isolated environments. This provides the illusion that a process or a process group is the sole user of the system's hardware and software resources. Examples of such resources include process IDs, hostnames, user IDs, file names, network interfaces, and inter-process communication (IPC) mechanisms.

Linux namespaces, alongside cgroups (control groups), are the foundational technologies underpinning modern OS-level virtualization and Linux containerization platforms such as Docker, Kubernetes, LXC, and Podman. While cgroups dictate how much of a system's resources a process can use (such as CPU, memory, and disk I/O limits), namespaces dictate what a process is allowed to see and interact with.

The term "namespace" is often used to denote a specific type of namespace (e.g., process ID namespace) as well as a particular space of names. A Linux system begins with a single initial namespace of each type, which is shared by all processes. Processes can subsequently create additional namespaces or join existing ones, allowing complex, nested isolation boundaries.