3 ms·
This article seems to miss the point. Not that Unikernels seem useful for running in VMs, not on bare metal. Thus you get the isolation of a true VM with a con
by MCRed 11y ago
This article seems to miss the point. Not that Unikernels seem useful for running in VMs, not on bare metal. Thus you get the isolation of a true VM with a container like performance & resource usage.
- misterbisson 11y agoWhat if you could have isolation that's as good as or better than a VM in a container?
- lmm 11y agoThen I'd be interested. But Solaris is x million lines of C code and the system call attack surface is huge, so I really don't think Joyent can offer that. Fundamentally if the author believes that you need a full traditional unix userland inside the container for debugging then they're never going to be able to offer that level of isolation.
- cyphar 11y agoNot inside the container. Containers are transparent to the host (Zones especially). You have tooling in the kernel, and you take coredumps when a container process dies.
- lmm 11y agoSee that's the model I'd expect to take - but that model makes perfect sense in the unikernel world too. So the author must be claiming that you need the debugging tools inside the container, otherwise the point about not having tcpdump etc. available makes no sense.
- cyphar 11y agoThe problem with applying the same logic to hypervisor'd unikernels is that hypervisors make the guest system opaque. So how could you meaningfully run DTrace on that system?
- marssaxman 11y agoHow would that be possible? If you have a container with an attack surface as small as a VM, haven't you basically just created a VM by another name?