</div>
<div class="slide">
- <h1>User namespaces [3.7]</h1>
+ <h1>More support for containers</h1>
<ul class="incremental">
<li>
- One of the last missing pieces for OpenVZ-like containers
+ Containers are lightweight VMs - run on the same kernel as host,
+ but with limited privileges and resources
</li>
<li>
- Each user namespace has its own <tt>root</tt> user with
- privileges over the users and processes in that namespace - but
- not the whole system
+ Previously done by OpenVZ and Linux-VServer; gradually being
+ reimplemented upstream
+ </li>
+ <li>
+ User namespaces (added in 3.7) support the existence of a
+ <tt>root</tt> user inside the container that is unprivileged
+ outside the container
</li>
<li>
Currently somewhat experimental, and requires filesystem
changes which haven't been done for XFS
</li>
<li>
- Make it work: send patches to upstream XFS developers (this
- one's hard)
+ Make user namespaces work: send patches to upstream XFS
+ developers (this one's hard)
</li>
</ul>
</div>