ContainerDays Hamburg • Hamburg
2026

The Reality of Rootless Containers

Wed 2nd September, 10:30 am – 11:05 am

LinuxContainersSecurityGo

Rootless containers are often presented as a simple security win: run without root and you’re safer. But what actually changes under the hood?

In this session, we’ll examine rootless containers from the Linux kernel’s perspective. We’ll explore user namespaces, UID/GID mappings, capability restrictions, cgroups behaviour, and networking differences to understand how the privilege model shifts.

Through practical comparisons between rootful and rootless setups, we’ll see what attack surfaces are reduced, what limitations appear, and where common misconceptions arise.

If you operate containers in production, this talk will give you a clear, realistic understanding of what changes when you go rootless — and what still needs your attention.

Resources