Skip to content

Glossary

OverlayFS

OverlayFS is the Linux union filesystem that stacks read-only lower layers under a writable upper layer, used by Docker and containerd for container images.

OverlayFS is a union filesystem in the Linux kernel. It presents a single merged view built from one or more read-only lowerdir layers and a writable upperdir, with a workdir used internally. Reads fall through to the lower layers; any write copies the file up into the upper layer first. Deleting a lower-layer file creates a whiteout in the upper layer, a character device with device number 0/0, and a directory replaced wholesale is marked opaque with an extended attribute.

Container engines use it heavily. With Docker's overlay2 driver, each layer lives under /var/lib/docker/overlay2/<id>/, where diff/ holds that layer's contents and merged/ is the mount point of a running container.

mount -t overlay | head
ls /var/lib/docker/overlay2/<id>/diff

For investigators this is convenient: the container's upperdir contains exactly what changed since the image was started, such as dropped tools, modified configuration and whiteouts for deleted files, which makes it a precise diff of attacker activity inside the container. The upper layer is removed with the container, so collect it before anyone runs docker rm. See container forensics with Docker and containerd.