Namespaces are what separate a container from the host. Sharing any of the host's namespaces back (--pid=host, --net=host, --ipc=host, userns=host, or the Kubernetes hostPID/hostNetwork/hostIPC) removes one wall. Host PID is the strongest: it exposes every host process for nsenter or injection. Check what is shared:
ls -l /proc/1/ns/ # compare namespace inode numbers with the host's
cat /proc/1/comm # if this is the host's init, PID namespace is shared
Subtopics#
- Host PID namespace: see host processes and nsenter into them.
- Host network namespace: the host's interfaces and loopback services.
- Host IPC namespace: host shared memory and IPC objects.
- Host user namespace: container root is real host root.