Features Stacks Solutions Pricing About Contact
Sign in →
Architecture • • 6 min read

Why Rootless Containers Matter for Modern VPS Security

A deep dive into container privilege separation, namespace isolation, and how Rubuz isolates customer workloads.

Traditional server control panels often run background daemons with full root privileges. When an application deployed on the server is compromised, malicious actors frequently escalate privileges to gain full administrative access to your VPS.

In this article, we explain why Rubuz chose a strict rootless container architecture from day one.

The Security Flaw with Traditional Panels

When you install legacy web hosting control panels, their installation scripts typically curl a shell script directly into sudo bash. That daemon then runs with PID 1 or elevated systemd units, listening on public ports and creating arbitrary system users.

If an unauthenticated Remote Code Execution (RCE) bug is discovered in such software, attackers immediately own the whole server, all hosted databases, and your SSH credentials.

What Are Rootless Containers?

Rootless containers allow containers to be created, run, and managed by a non-root user. In a rootless setup:

  • The container engine process runs as an unprivileged UID
  • The root user inside the container (UID 0) is mapped to a harmless unprivileged user on the host using user namespaces (user_namespaces(7))
  • Even if an attacker gains root within the container, they possess zero elevated privileges on the host system
Host System (Kernel)
  └── User Namespace (UID: 10001)
        └── Containerized Runtime (Mapped UID: 0)
              ├── App Process (WordPress / Node.js)
              └── Isolated Virtual Mounts

Zero Performance Overhead

Many developers fear that extra isolation comes with performance degradation. In reality, Linux namespaces and cgroups have zero runtime execution penalty:

  • Raw CPU & Memory Throughput: Processes execute directly on host CPU cores.
  • Direct I/O Performance: File and disk operations utilize native ext4 or Btrfs direct block allocations.
  • Minimal Footprint: The agent consumes less than 40MB of resident RAM.

By combining rootless security with zero-overhead performance, Rubuz offers peace of mind for mission-critical production workloads.

Published on May 22, 2026 • Rubuz Architecture
← Back to all articles

Experience zero-CLI server management

Connect your VPS in one step. Deploy WordPress, Node.js, Ghost, and databases with sub-50ms performance and automatic SSL.