← All projectsProblem statement Solution Architecture Key features Challenges Lessons learned
2026
Docker Clone
A minimal container runtime built from scratch in Go, using raw Linux syscalls instead of Docker itself.
Docker feels like magic until you ask what actually isolates a container from its host. I wanted to understand the Linux primitives underneath it rather than just consuming the CLI.
A minimal container runtime written in Go that reimplements Docker's core isolation model directly on top of Linux kernel features (namespaces, cgroups, and networking), with no external containerization libraries.
The runtime re-executes itself: the parent process forks a child with PID, UTS, and mount clone flags, the child joins a cgroup with resource limits, sets an isolated hostname, chroots into a minimal Alpine root filesystem with a fresh /proc, and then execs the requested command. Network isolation and internet access are configured separately from the host side via veth pairs and iptables NAT after the container starts.
- Process isolation via PID namespaces, so the container sees itself as PID 1
- Hostname isolation through UTS namespaces
- Filesystem isolation via chroot and mount namespaces with a fresh /proc
- Resource limits enforced with cgroups v2 (memory and process count caps)
- Optional network isolation with internet access via veth pairs and NAT
Getting namespace, cgroup, and chroot setup to happen in the right order without leaking host state, and working around pivot_root limitations under WSL2 by using chroot instead, while documenting the tradeoff.
Docker is mostly a thin, well-designed layer over primitives the kernel already provides. Building the isolation by hand made concepts like namespaces and cgroups concrete instead of abstract buzzwords.