Learning containers from the bottom up
iximiuz.com
Learning containers from the bottom up
1–10 of 23 posts
Re: Learning containers from the bottom up
#2I disagree with this:
> Now, when you have a decent understanding of containers - from both the implementation and usage standpoints - it's time to tell you the truth. Containers aren't Linux processes!
This is a bit of wordplay, I'm assuming, in absence of a word that defines the operating system features that power the concept of containers. To Linux, there is no (to my knowledge) concept of a "container". The container runtime runs your process(es) as the parent and uses the operating systems features to isolate it and restrict it/them. A virtual machine would just be a full emulated version of this, rather than using the operating system to virtualize the network stack. The author is right in that there is no such thing as a container, but only as much as containing is a thing you do, imo. What users think of containers are still just processes though, and I don't think that's an entirely useless abstraction to be cognizant of.
Re: Learning containers from the bottom up
#3This is a great article. I disagree with this: > Now, when you have a decent understanding of containers - from both the implementation and usage standpoints - it's time to tell you the truth. Containers aren't Linux processes! This is a bit of wordplay, I'm assuming, in absence of a word that defines the operating system features that power the concept of containers . To Linux, there is no (to my knowledge) concept…
Fantastic distillation. Thank you!
Re: Learning containers from the bottom up
#4Re: Learning containers from the bottom up
#5This is a great article. I disagree with this: > Now, when you have a decent understanding of containers - from both the implementation and usage standpoints - it's time to tell you the truth. Containers aren't Linux processes! This is a bit of wordplay, I'm assuming, in absence of a word that defines the operating system features that power the concept of containers . To Linux, there is no (to my knowledge) concept…
Re: Learning containers from the bottom up
#6This is a great article. I disagree with this: > Now, when you have a decent understanding of containers - from both the implementation and usage standpoints - it's time to tell you the truth. Containers aren't Linux processes! This is a bit of wordplay, I'm assuming, in absence of a word that defines the operating system features that power the concept of containers . To Linux, there is no (to my knowledge) concept…
Under the hood, that's all containers are!
Re: Learning containers from the bottom up
#7A nice blog series explaining in detail each Linux kernel mechanism making up containers: https://www.schutzwerk.com/en/43/posts/linux_container_intro...
Re: Learning containers from the bottom up
#8This is a great article. I disagree with this: > Now, when you have a decent understanding of containers - from both the implementation and usage standpoints - it's time to tell you the truth. Containers aren't Linux processes! This is a bit of wordplay, I'm assuming, in absence of a word that defines the operating system features that power the concept of containers . To Linux, there is no (to my knowledge) concept…
why not think of them as process (group) spawned with particular parent process setup, in particular the cgroups etc configuration effecting isolation.
Re: Learning containers from the bottom up
#9Fortunately the container architecture is flexible so that you can use as much or as little of it as you like.
I also tend to think that if you want stronger isolation for security purposes then you will want a lightweight VM rather than a container (and if you are worried about side channels, probably hardware partitioning - good luck.)
Re: Learning containers from the bottom up
#10This is a great article. I disagree with this: > Now, when you have a decent understanding of containers - from both the implementation and usage standpoints - it's time to tell you the truth. Containers aren't Linux processes! This is a bit of wordplay, I'm assuming, in absence of a word that defines the operating system features that power the concept of containers . To Linux, there is no (to my knowledge) concept…