World Congress 2024 • Aug 20, 2024 • Session details

Docker exec without Docker

Oliver Seitz

Ever wondered what happens if you strip away the Docker CLI? Learn to replicate docker exec using raw Linux primitives to master resource isolation and tighten security.

Pause
Mute Enter Fullscreen
#1 about 4 min

Demystifying the mechanics behind container execution routines

Exploring the underlying execution paths and hidden processes activated when launching standard container commands.

#2 about 2 min

Essential Linux kernel features for running containers

How operating system features like control groups and namespaces form the foundational building blocks of containerization.

#3 about 3 min

Limiting container resources using control groups

Configuring processing time, memory thresholds, process creation counts, and io constraints to prevent system resource exhaustion.

#4 about 4 min

Controlling process execution limits directly via shell

Manually assigning running processes to a modified cgroup filesystem configuration to observe utilization throttling.

#5 about 6 min

Isolating container environments with Linux namespaces

Utilizing network interfaces, mount points, process trees, and user identity mapping to sandbox application boundaries.

#6 about 4 min

Creating isolated network interfaces via the unshare command

Spawning partitioned local network spaces to selectively restrict the inter-process communication pathways.

#7 about 4 min

Joining an active process environment using nsenter

Using process identifiers to dynamically attach standard host shells into previously localized target namespaces.

#8 about 4 min

Simulating the docker exec command with native tools

Entering a running web server container strictly by targeting its root process identifiers through nsenter execution.

#9 about 2 min

Learning strategies for deep technical tool understanding

Why investigating low-level implementations and limiting operational scope yields better security insights over superficial usage.

Matching moments

2:51 min

Fundamentals of container network isolation and system components

Oliver Seitz Oliver Seitz · World Congress 2025

3:43 min

Isolating workloads using kernel namespaces and control groups

Marc Nimmerrichter · World Congress 2022

6:01 min

Handling container constraints and fileless malware

Dimitrij Klesev +1 · LIVE

1:59 min

Orchestrating with Kubernetes against Docker and accessing slides

Philipp Krenn · World Congress 2022

11:34 min

Answering audience questions on container functionality and local workflows

Rob Richardson · World Congress 2021

2:55 min

Enterprise container migration and historical technology evolution

Federico Fregosi · World Congress 2022

Upcoming sessions on this topic

Open session

World Congress 2026 North America

September 23, 2026 · 11:00–11:30

Stage 1

Docker does that? Five Docker capabilities you did not know about

Ajeet Raina, Kristiyan Velkov

Ajeet Raina
Kristiyan Velkov
Open session

World Congress 2026 North America

September 25, 2026 · 12:30–14:30

Stage 11

Docker sandboxes: protect your secrets, tokens, and personal data from AI agent mistakes

Kristiyan Velkov

Front-End Advocate | Speaker | AI & DevOps | Docker Captain | Cursor Ambassador | DevReal | Tech Blogger | Book Author

Kristiyan Velkov
Open session

World Congress 2026 North America

September 23, 2026 · 15:45–17:45

Stage 8

Docker's Agentic Platform: Sandboxes, MCP, and the Infrastructure of Autonomous Development

Oleg Å elajev

AI and Developer relations at Docker

Oleg Å elajev
Open session

World Congress 2026 North America

September 24, 2026 · 11:40–12:10

Stage 3

Stop Running Mystery Meat in Production

Jeroen van Erp

Technical Advocate @ SUSE

Jeroen van Erp
Open session

World Congress 2026 North America

September 25, 2026 · 09:40–10:10

Stage 4

Your registry can't stop a valid login. What happens then?

Khushboo Verma

Systems Engineer at Cloudflare

Khushboo Verma
Open session

World Congress 2026 North America

September 25, 2026 · 10:20–10:50

Stage 4

rm -rf: Horror Stories From Unsandboxed AI Agents (and How Docker Fixes This)

Rishab Kumar

Staff Developer Evangelist @ Twilio

Rishab Kumar