CPU Rings & Traps
How CPUs protect themselves — and why virtualizing x86 was a 20-year puzzle.
How CPUs protect themselves — and why virtualizing x86 was a 20-year puzzle.
The software layer that makes virtual machines possible.
The isolation primitive — giving each process its own view of the system.
IPC, User, Cgroup, Time namespaces — and how they combine to create a container.
Resource control at the kernel level — not isolation, but limits and accounting.
CPU throttling, memory limits, I/O control, and fork bomb protection.
How container platforms translate user-facing flags to cgroup files.
Splitting root into pieces and filtering dangerous syscalls.
Mandatory Access Control — the last line of container defense.
What a container image actually is — not a VM disk, but a stack of tarballs with metadata.
How multiple read-only layers merge into a single writable filesystem view.
Dockerfile mechanics, layer caching, multi-stage builds, and BuildKit.
Given a rootfs and a config.json — how a container actually starts.
Why runc isn't enough — image management, supervision, and Kubernetes integration.
When shared kernel isn't secure enough — gVisor, Kata, Firecracker, and Wasm.
From docker run to container process — every layer of the Docker stack.
Solving the persistence problem — bind mounts, named volumes, and tmpfs.
CPU, memory, I/O, and PID limits — and what happens when they're exceeded.
The brain of the cluster — API server, etcd, scheduler, and controllers.
The node agent — from scheduled pod to running containers.
Deployments, StatefulSets, DaemonSets — and how pods land on nodes.
Kubernetes persistent storage — abstracting infrastructure from applications.
Decoupling storage providers from Kubernetes — the plugin architecture.
Open-source virtualization management — KVM VMs and LXC containers on Debian.
Creating, migrating, and connecting VMs in Proxmox.
Storage backends, ZFS, Ceph, clustering, and automatic failover.