Traditional server control panels often run background daemons with full root privileges. When an application deployed on the server is compromised, malicious actors frequently escalate privileges to gain full administrative access to your VPS.
In this article, we explain why Rubuz chose a strict rootless container architecture from day one.
The Security Flaw with Traditional Panels
When you install legacy web hosting control panels, their installation scripts typically curl a shell script directly into sudo bash. That daemon then runs with PID 1 or elevated systemd units, listening on public ports and creating arbitrary system users.
If an unauthenticated Remote Code Execution (RCE) bug is discovered in such software, attackers immediately own the whole server, all hosted databases, and your SSH credentials.
What Are Rootless Containers?
Rootless containers allow containers to be created, run, and managed by a non-root user. In a rootless setup:
- The container engine process runs as an unprivileged UID
- The root user inside the container (
UID 0) is mapped to a harmless unprivileged user on the host using user namespaces (user_namespaces(7)) - Even if an attacker gains root within the container, they possess zero elevated privileges on the host system
Host System (Kernel)
└── User Namespace (UID: 10001)
└── Containerized Runtime (Mapped UID: 0)
├── App Process (WordPress / Node.js)
└── Isolated Virtual Mounts
Zero Performance Overhead
Many developers fear that extra isolation comes with performance degradation. In reality, Linux namespaces and cgroups have zero runtime execution penalty:
- Raw CPU & Memory Throughput: Processes execute directly on host CPU cores.
- Direct I/O Performance: File and disk operations utilize native ext4 or Btrfs direct block allocations.
- Minimal Footprint: The agent consumes less than 40MB of resident RAM.
By combining rootless security with zero-overhead performance, Rubuz offers peace of mind for mission-critical production workloads.