Create and Safely Remove Linux Network Namespaces with ip netns

ip netns carves out a separate network stack on one Linux box, with its own interfaces, routes and firewall rules. You will create a named namespace, bring up its loopback interface, run a command inside it, inspect its processes and identity, and remove it cleanly. The examples use iproute2 6.1.0, installed here as Ubuntu package 6.1.0-1ubuntu6.4. Allow about fifteen minutes. You need a shell and root access, or the capabilities your system grants for network namespace management.

A network namespace has its own network devices, routes and firewall state. A named namespace is represented by a handle below /run/netns/. The handle keeps the namespace alive while it exists, even when no process is currently using it.

1. Check the installed command

Start with read-only checks. These do not need elevated privileges:

$ command -v ip
/usr/sbin/ip
$ ip -V
ip utility, iproute2-6.1.0, libbpf 1.3.0
$ ip netns help

The subcommands used here are list, add, exec, identify, pids and del. The exact help text can vary between iproute2 releases, so the installed manpage and command are the useful references on the host where you are working.

Checkpoint: Choose a name that is local to this test, such as demo-netns. Do not reuse a namespace that belongs to a container runtime, VPN service or another administrator.

2. Inspect existing names before changing state

List the named namespaces currently visible to this mount namespace:

$ ip netns list
demo-netns (id: 0)

Your output may be empty, and the names will be host-specific. If the name you chose already appears, stop and select another name. Removing an existing name can disrupt services and can move or strand devices.

3. Create the namespace

This changes system state and normally requires root privileges. Create the namespace with a name that is not already in use:

# ip netns add demo-netns
# ip netns list
demo-netns

The command creates a new network namespace and assigns the name. It does not configure an address, add a usable external interface or start a process. The new namespace initially has its own loopback device, but loopback is down until you raise it.

If the add command reports that the name is unavailable, do not delete the existing name just to make the example fit. Inspect it with ip netns pids demo-netns and identify its owner first.

4. Bring up loopback inside the namespace

Run ip link in the new namespace. The exec subcommand changes the network context for the child command, not for your parent shell:

# ip netns exec demo-netns ip link set lo up
# ip netns exec demo-netns ip link show lo
1: lo: <LOOPBACK,UP,LOWER_UP> mtu 65536 ...

The abbreviated output is intentional: interface indexes, queue details and other fields depend on the kernel. The useful check is that the command succeeds and the loopback interface is shown as UP.

Use the same pattern for a harmless identity check:

# ip netns exec demo-netns ip route show
# ip netns exec demo-netns ip addr show lo

An empty route listing is normal for a namespace that has no configured network device. Creating the namespace alone does not provide connectivity.

5. Run a program with namespace-specific configuration

Place configuration files for a namespace under /etc/netns/NAME/. For example, a resolver file for demo-netns would be /etc/netns/demo-netns/resolv.conf. The directory is optional and should be created only when a command needs namespace-specific configuration.

ip netns exec creates a mount namespace for the child and bind-mounts matching files from that directory over their conventional paths in /etc. This lets a program that only reads /etc/resolv.conf see the namespace-specific file without changing the file seen by unrelated processes.

# ip netns exec demo-netns sh -c 'printf "namespace: "; ip netns identify $$; printf "resolver: "; readlink -f /etc/resolv.conf'
namespace: demo-netns
resolver: /etc/resolv.conf

The second line is not proof that a particular resolver file exists. Check the contents and permissions separately if DNS matters. Treat resolver configuration as security-sensitive: a namespace can be directed to a resolver that observes or alters queries.

6. Find processes before removal

A process can keep the namespace alive after its name is removed. Ask which processes have the named namespace as their primary network namespace:

# ip netns pids demo-netns
12345
# ip netns identify 12345
demo-netns

Both commands inspect the running system. The PID list can be empty, because ip netns add does not start a process. The optional PID to identify defaults to the current process when omitted, so ip netns identify reports the namespace name for your current network context when a matching name exists.

7. Remove the test namespace carefully

Deletion is disruptive and can affect devices moved into the namespace. First stop processes that you own and understand. Do not blindly pipe the result of ip netns pids to kill on a production host: the list can contain service processes, and a race can make a PID refer to a different process.

For this isolated example, confirm that the list is empty, then remove the name:

# ip netns pids demo-netns
# ip netns del demo-netns
# ip netns list

No output from the last command means there are no remaining named namespaces visible here. If a process is still using the namespace, ip netns del removes the name but the namespace can persist until its other users exit. The deletion can also fail when the mount point is in use from another mount namespace.

If you moved a physical device into the namespace and then delete its name while a process is running there, the device may not return to the default namespace until that process exits or is killed. To recover, identify the remaining users with ip netns pids, stop the owning service or process through its normal supervisor, then check the default namespace with ip link. Avoid forcing a kill unless you have confirmed the process and accepted the service interruption.

8. Understand IDs when integrating with netlink tools

Named namespaces and namespace IDs are different things. ip netns set NAME auto assigns an ID for a peer namespace in the current network namespace. You can also supply a positive integer:

# ip netns set demo-netns auto
# ip netns list-id

An ID is valid only from the network namespace where it was assigned. Once assigned, the manual page says it cannot be changed. Use this feature when a tool needs stable peer identifiers, not as a replacement for the human-readable name. If you do not need peer IDs, leave them to the kernel's normal automatic handling.

Done means