A minimal container runtime built in Go using core Linux primitives — without Docker.
This project demonstrates how containers work internally using:
- Linux namespaces (PID, UTS, Mount)
chrootfor filesystem isolation/procandtmpfsmounting- cgroup v2 for CPU, memory, and process limits
It re-executes itself inside new namespaces, pivots into a minimal root filesystem, applies resource constraints, and runs a command as PID 1 inside the container.
For a detailed explanation of how each part works, read the accompanying blog post. https://dev.to/faizanfirdousi/build-a-container-from-scratch-in-go-modern-namespaces-cgroup-v2-5556
- Linux system
- Go installed
- cgroup v2 enabled
- Root privileges (
sudo)
docker export $(docker create alpine) -o alpine.tar
mkdir -p ~/alpine-rootfs
tar -xf alpine.tar -C ~/alpine-rootfsUpdate the rootfsPath in the code accordingly.
sudo go run main.go run /bin/shExample:
sudo go run main.go run /bin/echo helloThis is a learning project to understand container internals. It is not production-ready.