5 ms·
Are linux containers really not securable? That's how Google runs all their stuff in production. http://research.google.com/pubs/pub43438.html http://research.
by acconsta 11y ago
Are linux containers really not securable? That's how Google runs all their stuff in production.
http://research.google.com/pubs/pub43438.html http://research.google.com/pubs/pub43438.html
- geofft 11y agoGoogle generally doesn't have to worry about mutually-untrusted containers. The meaning of "Linux containers are not secure" is that untrusted code should not be given root privileges within a container. Google is generally not doing that. They have e.g. trusted Gmail code running on the same machine as trusted YouTube code, handling untrusted emails and untrusted videos. But the Gmail team is not worried about the YouTube team hacking them, or vice versa. The security mechanisms just need to keep honest people honest. And when they do have untrusted, third-party code to run, for Google Cloud Platform, they use VMs or actual sandboxes: see section 6.1 of the paper you linked.
- acconsta 11y agoNo, but the Gmail team might be worried about some Russian guy finding a buffer overflow in YouTube's application. Then what? They can escalate privileges and read your email?
- KirinDave 11y agoGoogle's deployment of Docker is less susceptible to this. They do additional partitioning of applications.
- acconsta 11y agoYeah... so it seems like Linux containers can be sufficiently hardened?
- the_mitsuhiko 11y agoNot really. You physically seperate gmail and youtube.
- acconsta 11y agoSource? How do you get 80% CPU utilization if you have to physically separate all your job types? http://csl.stanford.edu/~christos/publications/2015.heracles.isca.pdf http://csl.stanford.edu/~christos/publications/2015.heracles...
- geofft 11y agoGoogle has way more applications than just Gmail and YouTube. Basically, if someone breaks into Gmail, you're already in deep trouble. You're not significantly better off because they didn't break into Hangouts. Same in the other direction. So you can run those on the same hardware. If you think YouTube is less sensitive than Gmail (I don't know if Google actually does), you can separate those, sure. But there are enough applications that are no worse to break into than YouTube, like Photos. You can run those on the same hardware. At Google's scale it's not too hard to say, this is the stuff we're ridiculously paranoid about and this is everything else, and get 80% CPU utilization on both infrastructures.
- KirinDave 11y agoGoogle can afford to keep separate server flights for each app. They have a lot of money and a lot of dedicated computer power for actual revenue generators.