Answer the question
In order to leave comments, you need to log in
Why can I see processes from a docker container on the host machine?
There are several containers. They have processes running. Am I supposed to see these processes on the target host system? I see them, I can complete them, and then the work of the container is completed. Aren't containers isolated?
Answer the question
In order to leave comments, you need to log in
Because docker containers are not virtual machines. Docker isolates processes in containers so that they (the processes) cannot see the processes of the host system and other containers. He does this with "Kernel namespaces" & "cgroups" .
If you read in English - here is the basic description
https://docs.docker.com/engine/security/security/#...
Didn't find what you were looking for?
Ask your questionAsk a Question
731 491 924 answers to any question