Container Escape — How Containers Break Out to the Host

A container feels like a tiny machine, but it is not one. It is just ordinary processes running on the host's own kernel, fenced off by a handful of kernel features. An escape is the moment those fences fail — and a process that thought it was alone in a box finds itself standing on the host's root filesystem.

Related Articles