6 ms·
On AWS Linux is the dom0 OS on Xen (I don't know of any other CPs who are different, unless you get a dedicated host), so the same is true of unikernels right n
by hacknat 11y ago
On AWS Linux is the dom0 OS on Xen (I don't know of any other CPs who are different, unless you get a dedicated host), so the same is true of unikernels right now as well, not of docker though, as they have a containers product now. So...
- geofft 11y agoI'd hope that AWS' container product runs at least each customer's containers in a separate VM per customer, if not one VM per app. It is too easy for a malicious customer to break out of a Docker container (far easier than breaking out of Xen, and they take those security vulnerabilities seriously). The advantage here would be that Amazon could change their container product to allow only one layer of isolation (user code in a unikernel, inside Amazon-run Xen) instead of two (user code in Docker, inside Amazon-run Linux per customer, inside Amazon-run Xen).
- kylequest 11y agoYep, they do run each customer's containers in separate VMs. It's actually bring own VM kind of design :-) You configure your own EC2 instances, install ECS agents...
- hacknat 11y agoI think this is a bit of an overstatement, breaking out of a docker container is not "easy", especially if you add other security products on top. Then there is the extensibility of the OS to be used to make things even more secure. If you look at security through the narrow lens of "being able to break out of your environment" then yes, Hypervisors are more secure, but you have to look at more than just that. The OS allows you to make more than just the host secure, it allows you to make the network secure, ensure that all customers get encrypted disks, etc... Full disclosure, I work for a company doing this right now (Catalyze Inc.)
- geofft 11y agoYeah, I don't mean to say breaking out of Docker confinement is easy by any objective measure, just that it is much less hard than breaking out of Xen confinement, and even that seems to be a fair bit of concern for AWS already.
- monocasa 11y agoBut on Xen, it's not like to dom0 is required to be called in the dataplane. It's mainly there for config and emulation of devices that don't have SR-IOV.
- SEJeff 11y agoFrom https://cloud.google.com/compute/docs/faq#whatis https://cloud.google.com/compute/docs/faq#whatis ... """ Google Compute Engine includes Linux and Windows based virtual machines running on KVM, local and durable storage options, and a simple REST based API for configuration and control. """ No Xen there
- cthalupa 11y agoThe dom0 is not the hypervisor. Guests are not running on top of a dom0 in Xen - the dom0 is a management domain that is a VM running on top of the hypervisor just like any other, just with some additional privileges and management functionality.