nsenter - run program in different namespaces
nsenter -t PID [-n] [-m] [-u] [-p] [-i] CMD
Options you will use
-t PID- the process whose namespaces to enter
-n- network namespace
-m- mount namespace (the container's filesystem)
-u- UTS (hostname)
-p- PID namespace
Examples
$ sudo nsenter -t $(docker inspect -f '{{.State.Pid}}' web) -n ss -tlnpthe container's sockets, using the HOST's ss - works on distroless images
Gotchas
- Entering only -n keeps the host filesystem, so host tools work against the container network.
Taught in
Try nsenter in a real terminal Free, in your browser - a real Ubuntu terminal to try it in, with missions that check your work.