Stop your containers from fighting over PID 1

Container Basics On Linux (Namespaces/Cgroups)

Stop your containers from fighting over PID 1

🧩 The Challenge

Ever notice how a containerized app refuses to die when you send a SIGTERM, leaving you to wait for a timeout before the orchestrator force-kills it? It’s almost always because your entrypoint script isn’t a proper init process, so it can’t reap the zombie processes piling up inside the namespace.

💡 The Fix

You need to make sure your primary process actually handles signals correctly or use a tiny init shim to sit in front of your app and do the heavy lifting for you. It keeps the process tree clean and saves you from the headache of orphaned zombies eating up your PID limits.

docker run --init -d my-flaky-app:latest

⚙️ Why It Works

Setting that flag tells the container engine to inject a small binary that acts as the real init process, which correctly handles signal forwarding and reaps all those dead subprocesses you didn’t even know were hanging around. Without it, your app is basically flying blind and can’t clean up after itself when the house is on fire.

🚀 Pro-Tip: If you’re building images, check out ‘tini’ as a cleaner, lighter way to get the same init behavior baked into your Dockerfile.

Linux Tips & Tricks | © ngelinux.com | 10/9/2026

0 0 votes
Article Rating
Subscribe
Notify of
guest

0 Comments
Newest
Oldest Most Voted