Containers From First Principles
Docker taught you the commands. This is what actually happens underneath: namespaces, cgroups, and why a container was never a lightweight virtual machine.
What you'll actually learn
docker run works because of two Linux kernel primitives most container users never see directly: namespaces, which give a process its own private view of the filesystem, network, and process tree, and cgroups, which cap how much CPU and memory it's allowed to touch. This track builds a container from those two primitives up, instead of starting from Docker's CLI — by the time you're done, "container" stops meaning "a lightweight VM" and starts meaning "a normal Linux process wearing a very convincing disguise."
What you'll be able to do
You'll be able to explain — and reproduce — why a container can see its own PID 1 while the host sees a completely different process number, why a memory limit gets enforced even though nothing was "virtualized," and why two containers sharing a kernel is a fundamentally different security boundary than two VMs. That's the difference between using Docker and actually understanding what breaks when a container escapes its isolation.
Syllabus
Frequently asked
Roughly 2 hours across 6 hands-on quests — you can go at your own pace and pick up exactly where you left off.
You should be comfortable with Docker, Kernel Internals first — the skill tree unlocks Containers From First Principles once you've cleared those.
Yes — Containers From First Principles is fully available on the free tier, starting with a free first quest and no payment method required to sign up. Plus and Elite remove pacing limits but don't gate any of the Containers From First Principles curriculum behind a paywall.
Create a free account and begin your first quest — no card required.
Start free