Linux Namespaces - from one process to connected network namespaces
This Learning is about Linux namespaces: what they are, how a process gets its own, and how separated network namespaces are connected again with virtual cables and switches. In the first four levels you work as root on one Linux machine with the standard tools, unshare and ip netns; only the last two connection labs install anything, Open vSwitch. The fifth level completes the set with the IPC, user, cgroup and time namespaces, works as an ordinary user, and shows what is still missing before isolation becomes a sandbox.
The levels
Each level ends with a small check. There is no time limit: when you can do what the check asks, go on to the next level.
| Level | You practice | You have passed the level when |
|---|---|---|
| 1 · Understand | What a namespace is, the kinds there are, the three system calls | You can say what each namespace isolates and list the namespaces of a running process under /proc/<PID>/ns |
| 2 · Isolate | Giving a process its own MNT, UTS or PID namespace | You can start a shell in a new UTS namespace, change the host name there, and show that the host kept its own |
| 3 · Network | Creating, entering, watching and removing NET namespaces | You can create a network namespace, run a command inside it, and remove it again |
| 4 · Connect | veth pairs, a Linux bridge, an Open vSwitch switch | Two namespaces answer each other's ping, once over a veth pair and once through a switch |
| 5 · Without root | The IPC, user, cgroup and time namespaces, UID maps, and what a sandbox needs beyond namespaces | You can become root inside a user namespace, say why that root cannot touch the host's files, and name two things that still get into a bwrap sandbox |
Level 1 is the Introduction. Level 2 is articles 2 to 4, level 3 is article 5, level 4 is the five connection labs, articles 6 to 10, and level 5 is articles 11 to 15.
The articles
Read them in this order. Articles 1 to 10 also exist in Slovak, the language they were written in; the (SK) link is at the top of each. In the Slovak versions of articles 2 and 4 the practical part is still marked TODO; it is written in the English versions only.
| # | Article | What it is |
|---|---|---|
| 1 | Introduction | Level 1: the concepts, the API, the default namespaces and the namespaces-info.sh script |
| 2 | MNT namespace | Level 2: mount points seen by a process, private mounts, propagation |
| 3 | UTS namespace | Level 2: host name and domain name, with the full walk-through |
| 4 | PID namespace | Level 2: process IDs, PID 1 of a namespace, the view from outside |
| 5 | NET namespace | Level 3: the network stack, and the life of a network namespace |
| 6 | Connecting a network namespace to the host system - with a veth pair | Level 4: one namespace and the host, joined by a veth pair |
| 7 | Connecting two network namespaces (ns1, ns2) - with a veth pair | Level 4: two namespaces joined directly by a veth pair |
| 8 | Connecting two network namespaces (ns1, ns2) - with two veth pairs and a standard Linux bridge | Level 4: two namespaces on a standard Linux bridge |
| 9 | Connecting two network namespaces (ns1, ns2) - with two veth pairs and a distributed OVS switch (openvswitch) | Level 4: two namespaces on an Open vSwitch switch, with veth pairs |
| 10 | Connecting two network namespaces (ns1, ns2) - with two ports on a distributed OVS switch (openvswitch) | Level 4: two namespaces on Open vSwitch internal ports |
| 11 | IPC namespace | Level 5: System V IPC objects and POSIX message queues of a process's own |
| 12 | USER namespace | Level 5: UID and GID maps, root without privilege, and the namespace every unprivileged one builds on |
| 13 | CGROUP namespace | Level 5: a private view of the cgroup hierarchy, and how it differs from a limit |
| 14 | TIME namespace | Level 5: a process with its own monotonic and boot-time clocks |
| 15 | From namespaces to a sandbox | Level 5: capabilities, seccomp and Landlock, pasta, bwrap, and what still leaks in |
What you will be able to do
- Name the Linux namespaces and say what each one isolates.
- Find out which namespaces a process lives in.
- Start a process in a new namespace and run commands inside an existing one.
- Build a small virtual network between namespaces and test it.
- Do all of that as an ordinary user, through a user namespace.
- Say what a sandbox or a container adds on top of namespaces.
Set up once
One Linux machine, physical or virtual, where you are root. Use one you can afford to break: the labs create network devices and change addresses. The connection labs with Open vSwitch need the openvswitch package. Level 5 needs no root; articles 12 and 15 use podman, and article 15 also bwrap (bubblewrap) and pasta (passt).
Inspiration and current practice
Articles 1 to 10 do everything as root, the way it was done in 2016. Today the starting point is the user namespace, which needs no root and which the other namespaces build on. Each of those articles therefore ends with a section Current practice, which says what has changed and shows the unprivileged way where there is one, and articles 12 and 15 cover the user namespace and what a sandbox needs on top of it.
Those sections and the new articles build on one talk:
- Michal Vyskočil: Moderní izolace procesů v Linuxu: namespaces, seccomp a další (LinuxDays 2026, slides in Czech)
It puts namespaces beside the other pieces of process isolation in Linux, capabilities, seccomp and Landlock, walks through unshare, user namespaces, pasta and bubblewrap at the keyboard, and shows why namespaces alone are not a sandbox: environment variables, open file descriptors and the network all pass through unless something stops them.
Final check
Create two network namespaces, connect them, and make one ping the other. Then explain, for each command you typed, which namespace it ran in. A container runtime does the same steps for you.