Suggest an editImprove this articleRefine the answer for “How does Docker provide process isolation?”. Your changes go to moderation before they’re published.Approval requiredContentWhat you’re changing🇺🇸EN🇺🇦UAPreviewTitle (EN)Short answer (EN)**Docker** provides isolation at the Linux kernel level using two key mechanisms: **namespaces** and **cgroups**. **Key point:** Docker provides isolation of processes, network, users, and the file system through namespaces, resource limits through cgroups, and security through seccomp and AppArmor/SELinux.Shown above the full answer for quick recall.Answer (EN)ImageDocker provides isolation at the Linux kernel level using two key mechanisms: **namespaces** and **cgroups**. ### **1. Namespaces - isolate the "visibility" of the world for a process** Namespaces give each container its own namespace. This means a process inside a container **cannot see** the resources of other processes or of the system as a whole. The following types of namespaces are used: | Namespace | What it isolates | |---|---| | **PID** | The process table - the container sees only its own processes | | **NET** | Network interfaces, routes, iptables | | **IPC** | Message queues, shared memory | | **UTS** | Hostname, domain name | | **MNT** | Mount points and the file system | | **USER** | Users and UIDs | **Effect:** each container has its own mini-world. ### **2. Cgroups - limit resources** Control Groups manage **how many resources a container can consume**, so that it does not "eat" everything. Cgroups let you set limits on: - CPU - RAM - I/O - Network (indirectly, via tc) - number of processes, and so on **Effect:** even if the application in a container falls into an infinite loop, it will not bring down the entire server. ### **3. Rootfs + OverlayFS - file system isolation** Docker uses **copy-on-write (CoW)** and overlay FS layers so that each container has a *logically separate* root file system, even when the layers are physically shared. ### **4. Seccomp, AppArmor, SELinux - security** Docker can additionally restrict system calls and privileges: - **Seccomp** - blocks dangerous syscalls - **AppArmor/SELinux** - restrict access to system resources ### **Summary for middle level:** Docker provides isolation of **processes, network, users, and the file system through namespaces**, **resource limits through cgroups**, and **security through seccomp and AppArmor/SELinux**. Thanks to this, a container works *as a separate environment* while staying lightweight, because the OS kernel is shared. If you want, I can just as briefly break down **"how a pid namespace differs from chroot"** or **"why a container is not the same as VM-level security"**.For the reviewerNote to the moderator (optional)Visible only to the moderator. Helps review go faster.