RYZHOV / Linux
A working reference for Linux

Containers & virtual machines

Choose isolation, run rootless workloads, and build disposable test environments.

Containers share a kernel; virtual machines provide a guest kernel. Choose the boundary needed for the test and check host architecture, mounts, networking, and privileges explicitly. Rootless operation reduces some risks but still needs a considered configuration.

Where to start

Start with Podman or Docker's operating model. Use QEMU and libvirt when you need a guest machine. Read systemd-nspawn for system containers and the OCI runtime specification when investigating the lower-level contract.

6 resources

Choose isolation, run rootless workloads, and build disposable test environments.

  • Podman documentation

    Look up rootless containers, pod operations, networking, and command behavior for the Podman release on your host.

    ReferencePodman Projectdocs.podman.io
    Upstream latest · compare installed version · Project documentation · Selection reviewed
  • Docker Engine documentation

    Understand the engine, storage, networking, and security model before running a service or building a test environment.

    HandbookDockerdocs.docker.com
    Docker Engine · maintained documentation · Project documentation · Selection reviewed
  • QEMU system emulation

    Choose a machine model, accelerator, block device, and network backend for an isolated guest; check stable-release support.

    ReferenceQEMU Projectwww.qemu.org
    Development branch · master · Project documentation · Selection reviewed
  • libvirt domain XML reference

    Inspect the declared CPU, disks, interfaces, and devices when a managed virtual machine differs from expectations.

    Referencelibvirt Projectlibvirt.org
    Current upstream domain format · Project documentation · Selection reviewed
  • systemd-nspawn system containers

    Check machine-container options, boot behavior, and filesystem boundaries for a disposable Linux userspace.

    Referencesystemd / Debianmanpages.debian.org
    systemd 252 · Debian 12 · Distribution reference · Selection reviewed
  • OCI runtime specification

    Trace container lifecycle and configuration requirements when debugging behavior beneath a high-level container CLI.

    SpecificationOpen Container Initiativegithub.com
    Development branch · main · Project documentation · Selection reviewed

How this library is selected

References are selected for a concrete operational task, with preference for project and distribution documentation. Annotations describe when to use a source; version labels make its scope explicit.

Selection reviewed means the destination, subject, and version scope were checked. It is not a claim that every upstream command has been tested. Original guides identify their own test environment. Platform filters also include references that apply across distributions.