Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.

Docker’s “shared memory namespace” is its IPC namespace: it controls which processes can see System V shared-memory segments, semaphores, and message queues. Use Docker’s --ipc setting to keep a container isolated, let selected containers share IPC, or join the host’s IPC namespace. This is separate from the capacity of /dev/shm, which Docker documents as 64 MiB by default.

What a Docker IPC namespace controls

Linux IPC namespaces isolate interprocess communication resources, including System V shared-memory identifiers, semaphores, and message queues. Processes in separate IPC namespaces do not see one another’s IPC resources. See the Linux IPC namespaces documentation.

In Docker, --ipc selects the IPC namespace a container uses. It answers who can see and use these IPC objects; it does not by itself specify how much shared-memory capacity is available.

Docker IPC modes compared

Docker’s CLI reference describes these --ipc choices. The empty/default choice is not a universal fixed mode: Docker says it depends on daemon version and configuration.

What’s actually slowing this PC down?

Pick the symptom - the matching free tool is one click away.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Setting Who shares IPC objects Host IPC exposed? Container-to-container use
private The container uses its own IPC namespace. No. No sharing with other containers through this setting.
shareable The container uses its own private IPC namespace, which other containers can join. No. Use as the namespace for a selected group of containers.
container:<name-or-ID> The container joins the named or identified container’s IPC namespace. No, unless that namespace itself is host IPC. Yes; pair with a shareable donor container.
host The container uses the host system’s IPC namespace. Yes. Not limited to a selected donor-and-peer group.
none The container has a private IPC namespace. No. No; Docker also does not mount /dev/shm in this mode.
Empty or omitted Uses the daemon default, which Docker says can be private or shareable depending on daemon version and configuration. Depends on the daemon’s configured default. Depends on the daemon default.

These mode definitions are in the Docker container run reference. In particular, none is not just another name for ordinary private IPC: its /dev/shm mount behavior differs.

Share IPC between selected containers

For an application split across containers that needs common IPC mechanisms, Docker documents a shareable donor container and peer containers that join it with container:<donor-name-or-ID>. The donor creates the IPC namespace; peers join that namespace rather than each receiving an independent one.

  1. Start the donor with --ipc=shareable, for example: docker run -d --name ipc-donor --ipc=shareable IMAGE.

  2. Start a peer with --ipc=container:ipc-donor, for example: docker run --rm --ipc=container:ipc-donor PEER_IMAGE.

    Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
  3. Configure the application processes to use the appropriate IPC mechanism, then verify their behavior in your deployment. The namespace setting makes IPC resources visible across the joined containers; it does not configure the application’s own IPC protocol.

The exact commands beyond the documented mode pattern are illustrative; replace image names and arguments with those required by your application. Consult Docker’s CLI reference for the option syntax and supported behavior.

What --ipc=host means

--ipc=host joins the host system’s IPC namespace. That is a broader sharing boundary than selecting one donor container and having only designated peers join its namespace: the container uses the host IPC namespace rather than an IPC namespace private to that container group.

Docker also states that IPC sysctls cannot be used with host IPC: “If you use the –ipc=host option these sysctls are not allowed.” This restriction is documented in the Docker container run reference.

Special offer. See more information about Outbyte and uninstall instructions. Please review EULA and Privacy policy.
Best Value
Docker Container Linux Devops Programming Coding T-Shirt
  • Docker, Docker Swarm, Docker Compose, Programmer, Developer, Coding, Programming, Software Engineer, Code, DevOps, Deploy, Deployment, Kubernetes, Salt, Puppet, Chef, Terraform, Container, AWS, Azure, Cloud, Geek, Funny, Computer, Software, Tech, IT
  • Integration, Scrum, Compile, Compilation, Science, Bug, Debug, Python, Linux, Java, Javascript, Scala, Dotnet, Kotlin
  • Lightweight, Classic fit, Double-needle sleeve and bottom hem
Independent reader supportYour contribution helps us test, update, and keep practical guides available for everyone.Support on Ko-Fi

IPC namespace versus /dev/shm size

Namespace selection and shared-memory capacity are distinct settings. The namespace determines which IPC objects processes can see. The size of /dev/shm concerns available shared-memory storage. Docker’s current daemon reference documents a default container shared-memory size of 64 MiB; it does not establish that changing IPC mode increases that capacity. See the Docker daemon reference.

Consequently, an application’s shared-memory error does not, by itself, establish that it needs host IPC. The Docker references cited here describe namespace modes and the documented size default, but do not diagnose a particular application failure. Check whether the application needs to share IPC objects with another container, and separately check its shared-memory capacity requirements and the applicable Docker configuration.

Choosing a mode

  • Choose private when the container should have its own IPC namespace.
  • Choose shareable plus container: when a defined set of containers must use the same IPC namespace.
  • Choose host only when the application specifically needs the host IPC namespace and you accept that wider sharing boundary.
  • Do not treat none as ordinary private IPC: Docker documents that /dev/shm is not mounted in none mode.
  • Check the daemon’s default rather than assuming omitted --ipc always means private or always means shareable.

Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.