Notes / Kubernetes / 07 Kubernetes Security / 7 Linux Kernel Isolation

7 — Linux Kernel Isolation

Containers isolate processes using namespaces and cgroups on a single shared host kernel rather than virtualizing hardware, so a kernel-level exploit inside one container can compromise every other container scheduled on that node.

· §202607201139-61 ·
Chapter Navigation
On This Page

7 — Linux Kernel Isolation

Purpose

[stub: linux-kernel-isolation]

Metadata

AuthorAmit Singh
Scopekubernetes

Local graph

Full graph →