Linux namespaces are a core building block of containers like Docker and Kubernetes.
In this video, I break down how namespaces isolate processes and why misconfigurations
(such as --pid=host) can allow attackers to escape a container and access the host.
// Chapters
0:00 - Intro
0:27 - Namespace 101
1:24 - Exploring PID namespaces in the terminal
2:00 - Identifying namespaces
3:20 - Parent and Child namespaces
4:29 - Playing around with Parent-Child relationship
6:19 - Creating and entering a namespace
6:59 - Example vulnerable docker configuration
// Links
None for now.
// Tags
#linux #containers #devops #cybersecurity #docker