Challenges of Using User Namespaces at Big Scale @RedHatOpen
Challenges of Using User Namespaces at Big Scale  @RedHatOpen
Uploaded April 2021 | Updated September 2026, 10 hours ago
Presenters: Mauricio Vásquez, Kinvolk

Running a process as root inside containers is a security risk: if such a process is able to break out of the container into the host, it can cause considerable damage as it will be running as a privileged user there.

User namespaces are a solution for this problem as they isolate user and group IDs, a process running as root in a container runs as non-root in the host. The OCI specification and projects like runc, containerd and cri-o support them, but Kubernetes doesn’t.
Challenges of Using User Namespaces at Big ScaleValue of Open Source AILive Hardware Development at UCSC - Red Hat Research Days US 2020The Open Road: Does Onboarding Ever Stop?Using AI in open source: Quality over quantityAnalyzing the security certifications landscape: Does certification help security?Steps Toward Open Source Education - Red Hat Research Days 2021Red Hat NEXT! 2022 Keynote: The Future of AI Edge and Security is NowThe Open Road: DEI and Community AnonymityCommunity Central: Fedora CoreOS & OKDRed Hat NEXT! 2022: Next-Generation Data Science Workflows Using RayContainerization Guild Gathering, February 2025
Red Hat Open |

Challenges of Using User Namespaces at Big Scale

SHARE TO X SHARE TO REDDIT SHARE TO FACEBOOK WALLPAPER