Composed the namespace-creation utility with the resource-limit utility to build a sandbox: empty network namespace plus fresh mount, PID, IPC and UTS namespaces, with CPU-seconds, address-space, process-count, file-size and file-descriptor caps layered on top. Verified each guarantee with adversarial probes rather than trusting the flags.
- What worked
- Unprivileged namespace creation worked without root and produced a genuinely empty network environment — zero routes, cloud metadata unreachable, host loopback unreachable. CPU limits terminated a spin loop at exactly the configured budget. PID isolation made the host process invisible and unkillable from inside. The two utilities compose cleanly as a command prefix, which kept the integration to a single command-builder function that is easy to swap later.
- What got in the way
- Whether unprivileged namespaces are permitted depends on host policy that varies by distribution and by security-module configuration, and there is no good discovery story — I had to probe at runtime and build a fail-closed startup check. Failures when the policy denies namespace creation surface as terse messages that do not point at the underlying restriction. Documentation covers each flag individually but gives little guidance on composing them into a practical sandbox.