Topic 05: Virtual Networking, veth Pairs & Network Namespaces

Target Duration: 2–4 minutes (~300–450 spoken words)
Focus: Pointwise verbal delivery covering anonymous network namespace linking, veth pair plumbing, dynamic subnet allocation, and resolving the kernel IPv6 DAD race condition.


🎙️ Pointwise Spoken Speech (Word-for-Word Delivery)


📋 Step-by-Step Summary (What, How & Why)

Step What Was Done How It Works Why This Mechanism / Order
1. Netns Linking Symlinked netns descriptor Linked /proc/<pid>/ns/net into /var/run/netns/<name>. Makes anonymous kernel netns manageable by host iproute2 tools.
2. veth Plumbing Created virtual link pair Kept host end outside; injected peer end into container netns. Acts as virtual patch cable connecting isolated container to host stack.
3. Subnet Slicing Assigned dedicated /24 subnets Host gets .1; container gets .2 on isolated subnet. Guarantees clean, conflict-free IP addressing per container.
4. DAD Race Fix Polled tentative flag on up Brought up lo & veth; polled until DAD cleared before routing. Prevents kernel RTNETLINK errors caused by assigning routes during DAD.
5. Default Route Set host as container gateway Added container default route via host endpoint IP (.1). Routes all outgoing container traffic across the veth link to the host.

❓ Anticipated Interview Questions & Crisp Answers

Q1: Why use a veth pair instead of macvlan or ipvlan?

Answer: macvlan and ipvlan bind virtual interfaces directly to the host's physical network adapter, bypassing the host's Netfilter and routing stack. A veth pair terminates in the host network namespace, allowing the host kernel to act as a full router and firewall where we can inspect, filter, NAT, and peer traffic between containers using standard routing and iptables rules.

Q2: What happens to the container's virtual interface when the container dies?

Answer: Network namespaces in Linux are destroyed by the kernel when all referencing processes terminate. When the container namespace is destroyed, the kernel automatically removes all interfaces inside it and tears down the paired host-side veth endpoint cleanly.

Q3: Why is manual /var/run/netns symlinking needed when using unshare --net?

Answer: unshare creates a network namespace attached only to the process's file descriptors. iproute2 management commands (ip netns) require a filesystem mount point or symlink in /var/run/netns to locate and reference the namespace descriptor.