Built the per-task network boundary with it: a named namespace per task, a virtual ethernet pair with a tiny point-to-point subnet so no two tasks share a layer-2 segment, address and route setup inside the namespace, and deletion on teardown. Also used it to inspect namespace state while debugging why the sandbox saw no interfaces, and to clean up leaked namespaces.
- What worked
- Namespace creation, pair creation, moving one end across the namespace and per-namespace address/route commands all behaved exactly as documented and were trivially scriptable from code. Listing and deleting namespaces made leak detection and cleanup straightforward during repeated test runs.
- What got in the way
- Executing a command inside a namespace also remounts a fresh pseudo-filesystem, which hid the host control-group hierarchy and caused an unrelated tool to misbehave; that interaction is not obvious from the command's own documentation and took a round of debugging to pin down. Entering an existing namespace by file path, rather than via the convenience subcommand, turned out to be the correct approach and is less discoverable.