Peering into the PID namespace isolation of your containers
Container Basics On Linux (Namespaces/Cgroups)
Peering into the PID namespace isolation of your containers
🧩 The Challenge
Trying to figure out why your containerized app can suddenly see every process running on the host is enough to drive you nuts. I’ve wasted a whole afternoon once because a developer forgot that PID namespaces weren’t enabled by default in their custom runtime config.
💡 The Fix
Use the unshare command to verify your isolation boundaries before you launch a fragile production service. It lets you simulate exactly what a container sees without actually building a whole image.
unshare --fork --pid --mount-proc ps aux
⚙️ Why It Works
By creating a new PID namespace and re-mounting the proc filesystem, you effectively trick the shell into thinking it is process ID 1. Anything outside that namespace becomes invisible to the tools you run inside it.
🚀 Pro-Tip: Run that command without the –fork flag first and watch your shell freak out when it tries to talk to the original init process.
Linux Tips & Tricks | © ngelinux.com | 10/3/2026
