← All projects
2026

Docker Clone

A minimal container runtime built from scratch in Go, using raw Linux syscalls instead of Docker itself.

GoLinux Namespacescgroups v2iptables
Problem statement
Docker feels like magic until you ask what actually isolates a container from its host. I wanted to understand the Linux primitives underneath it rather than just consuming the CLI.
Solution
A minimal container runtime written in Go that reimplements Docker's core isolation model directly on top of Linux kernel features (namespaces, cgroups, and networking), with no external containerization libraries.
Architecture
The runtime re-executes itself: the parent process forks a child with PID, UTS, and mount clone flags, the child joins a cgroup with resource limits, sets an isolated hostname, chroots into a minimal Alpine root filesystem with a fresh /proc, and then execs the requested command. Network isolation and internet access are configured separately from the host side via veth pairs and iptables NAT after the container starts.
Key features
  • Process isolation via PID namespaces, so the container sees itself as PID 1
  • Hostname isolation through UTS namespaces
  • Filesystem isolation via chroot and mount namespaces with a fresh /proc
  • Resource limits enforced with cgroups v2 (memory and process count caps)
  • Optional network isolation with internet access via veth pairs and NAT
Challenges
Getting namespace, cgroup, and chroot setup to happen in the right order without leaking host state, and working around pivot_root limitations under WSL2 by using chroot instead, while documenting the tradeoff.
Lessons learned
Docker is mostly a thin, well-designed layer over primitives the kernel already provides. Building the isolation by hand made concepts like namespaces and cgroups concrete instead of abstract buzzwords.
Next project

Healthcare Management Dashboard

View project →