#Cgroups
Cgroups, namespaces, and anti-fascism: building the world we all want to live in.💕💜💗🧊🚫
Genuinely very funny to me that people who were apparently fine with me posting Fuck ICE and Chinga la Migra all day long unfollowed me when I started posting UNIX facts
September 13, 2026 at 6:21 PM
Think about it; answer the question “What exactly is this AI agent allowed to do?”

On Standard Linux, it’s disgustingly messy with lots of overlap.

Do you use UIDs? GIDs? ACLs? CGROUPs? Policies? SELinux? Filesystem modes?
September 24, 2026 at 5:52 PM
Sigil

Sigil is a low-level container runtime written in Rust. It implements process supervision, Linux namespaces, filesystem isolation, and cgroups from scratch to demonstrate how containers actually work under the hood.
April 20, 2026 at 1:02 AM
me when cgroups
deno as pid 1
February 17, 2025 at 10:37 PM
ACAB includes cgroups
Guy who is such an abolitionist that he doesn't containerize his daemons. (Because containers are derivatives of chroot jails.)
July 31, 2026 at 3:51 PM
cgroups: not even once
November 8, 2025 at 10:10 PM
Hot take: Linux cgroups are essentially linters, that prevent devs from doing stupid shit.
September 2, 2025 at 8:31 PM
Podman 6.0 drops CNI, cgroups v1, iptables, slirp4netns, Windows 10, and Intel Mac support while adding new machine and Quadlet features.
linuxiac.com/podman-6-0-l...

#Podman #OpenSource #Containerization
Podman 6.0 Lands with Breaking Changes, AMD GPUs Support
Podman 6.0 drops CNI, cgroups v1, iptables, slirp4netns, Windows 10, and Intel Mac support while adding new machine and Quadlet features.
linuxiac.com
June 24, 2026 at 8:25 PM
if more tech bros studied humanities, well, the chroot/cgroups system would be called foucault and the spyware would be called Bentham
August 1, 2023 at 1:38 AM
it might be bad that we spent 10ish years conflating cgroups and vms
April 30, 2026 at 12:15 AM
Containers Are Just Linux wrapper: Exploring Namespaces and cgroups From Scratch
#golang

blog.iamvedant.in/containers-...
April 19, 2026 at 11:38 AM
But also consider optimizing resource usage with Docker's cgroups and namespace features for AI workloads.
September 23, 2026 at 6:42 AM
www.youtube.com/watch?v=Umib... : un assez bon résumé sur unshare, namespace et cgroups en une dizaine de minutes.
(via @nidouille.bsky.social)
J'ai utilisé Docker 5 ans sans savoir comment ça marche
YouTube video by Passe-Tech 🍉
www.youtube.com
March 3, 2026 at 10:19 AM
I vibe-coded a web-based top for cgroups; it's been pulling its weight.
April 23, 2026 at 11:39 PM
C'est comme un chroot mais avec des cgroups spécifiques et un remapping du FS
January 1, 2025 at 9:57 PM
Très bonne vidéo j'ai enfin pigé ce qu'était les namespace & cgroups (j'avais fais un effort pour comprendre ? non même pas 😛)
March 4, 2026 at 11:45 AM
Well, systemd just uses the kernel's cgroups to limit resource usage for services, so systemd is not strictly necessary for this kind of protection, but the same change that enabled (optional) systemd support in WSL2 - having an actual Linux kernel underneath - made cgroups available as well
January 17, 2026 at 6:39 PM
Funfact an der Stelle: Mit geringem Aufwand kann man unter Linux audit.d dazu bewegen, automatisch Dinge mit cgroups zu tun. Eventbasierend.

Der Trottel vom Marketing deployed was? Ups. Nur 5% RAM frei. OOM Kill. Ist wohl deren Software schuld.
September 2, 2025 at 8:38 PM
On Python, `loky.cpu_count()` will take cgroups settings, common in Docker and Kubernetes, into account when calculating number of available cores.

Are there any other Python APIs that support cgroups options? Standard library doesn't.

(On Rust you can use `num_cpus` crate, on R there's […]
Original post on hachyderm.io
hachyderm.io
May 5, 2026 at 6:54 PM
No, autocorrect, I am not talking about cgroups for once.
February 8, 2024 at 3:30 AM
I'm on that cgroups diet
May 29, 2025 at 3:35 AM
On Linux, the "tuna" utility lets you isolate CPUs so that no processes or IRQs get scheduled on them. taskset still lets you use those CPUs, making this a great combo for running benchmarks with less noise.

There are also isolcpus and cgroups, but those are more involved to set up.
April 12, 2026 at 7:03 PM
if it's prompt injection, then attacks will simply get smarter until it hole-punches through your sandbox. the swiss cheese model is real, but...you get better cheese (hi @jcsalterego.bsky.social) with smaller holes with cgroups or VMs or a separate box you can shoot with a gun.
June 27, 2026 at 7:50 PM
All of this. “Oh, I am famous in an extremely small niche that cares a lot about cgroups and namespaces” is legit hilarious.

But also, try being kind! “Hello, $name! Tell me about what you’re interested in right now! Nice to chat with you!” works whether or not you retain a single word they said. ✨
I love this thread. At times, I have been pony famous. It’s not a permanent status. But it is a very strange state of being.

1) Your parents still don’t know what you do, exactly.
2) It makes very little difference in your day to day work.
3) But you do have to be super careful to not be a jerk.
Okay. Short rambling thread. But about how i have learned to accept that I am "pony famous" and how, and why, you need to not talk down people who love what you do.

This is for minor writers or creators everywhere. Read this. /1
July 4, 2025 at 5:32 PM
Understanding Docker Internals: Building a minimal Container Runtime with Python on Linux using Namespaces, Control Groups and Filesystem Isolation #Docker #Linux muhammadraza.me/2024/buildin...
Understanding Docker Internals: Building a Container Runtime in Python | Muhammad
Breaking down container technology by building a simple container runtime from scratch using Python and Linux primitives like namespaces and cgroups
muhammadraza.me
October 30, 2025 at 8:10 PM