Skip to content

Latest commit

 

History

4 Commits

Folders and files

NameName
Last commit message
Last commit date
 
 
 
 
 
 

Repository files navigation

Container From Scratch (Go)

A minimal container runtime built in Go using core Linux primitives — without Docker.

This project demonstrates how containers work internally using:

  • Linux namespaces (PID, UTS, Mount)
  • chroot for filesystem isolation
  • /proc and tmpfs mounting
  • cgroup v2 for CPU, memory, and process limits

It re-executes itself inside new namespaces, pivots into a minimal root filesystem, applies resource constraints, and runs a command as PID 1 inside the container.

For a detailed explanation of how each part works, read the accompanying blog post. https://dev.to/faizanfirdousi/build-a-container-from-scratch-in-go-modern-namespaces-cgroup-v2-5556


Requirements

  • Linux system
  • Go installed
  • cgroup v2 enabled
  • Root privileges (sudo)

Setup Root Filesystem

docker export $(docker create alpine) -o alpine.tar
mkdir -p ~/alpine-rootfs
tar -xf alpine.tar -C ~/alpine-rootfs

Update the rootfsPath in the code accordingly.


Usage

sudo go run main.go run /bin/sh

Example:

sudo go run main.go run /bin/echo hello

Note

This is a learning project to understand container internals. It is not production-ready.

About

A small container built from scratch in Go using Linux namespaces, chroot, and cgroup v2. It isolates processes and filesystem, sets resource limits (CPU, memory, pids), and runs commands inside a minimal root filesystem, all without Docker.

Resources

Code of conduct

Contributing

Security policy

Stars

11 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages