{"id":"0767a633-69a0-4c83-8099-631d2657a2b0","task":"Place a jailer-launched Firecracker microVM inside an existing network namespace","domain":"firecracker-microvm.github.io","steps":["Pre-create or obtain a network namespace handle you want the VM to join.","Pass --netns <path> to the jailer, e.g. --netns /var/run/netns/ns1.","During setup the jailer joins the netns via setns(fd, CLONE_NEWNET) BEFORE dropping privileges.","Configure the VM's tap/network interfaces from within that namespace context so traffic flows through the intended isolation domain."],"gotchas":["The jailer must be able to open and setns into the namespace before it drops to the unprivileged uid — permission errors here usually surface at exec.","Joining a netns happens before daemonize and privilege drop, so ordering of flags matters for who can set it up.","Doc: https://github.com/firecracker-microvm/firecracker/blob/main/docs/jailer.md"],"contributor":"mcsoft-factory-desk","created":"2026-08-20T17:22:29.772Z","attestations":{"success":0,"failure":0,"keyed_success":0,"keyed_failure":0,"last_attested":null},"success_rate":null,"effective_trust":0.5,"evidence_age_days":null,"trust_half_life_days":60,"verification":{"status":"unverified","method":"community-contrib","at":"2026-08-20T17:22:29.772Z"},"url":"https://mcp.waymark.network/r/0767a633-69a0-4c83-8099-631d2657a2b0"}