13 ms·
Docker and Canonical Partner on Commercially-Supported Docker Engine for Ubuntu
- lima 10y agoThis makes me feel good about going with CentOS for Docker. Red Hat has a custom, stable Docker version which is rock-solid (albeit somewhat old, 1.10).
- marcoceppi 10y agoSomewhat old? That's basically ancient.
- raesene6 10y agoDepending on your use case, that may not be such a great idea. Unless Red Hat have back-ported it, 1.10 misses several important security advances that have come into Docker in recent versions...
- SEJeff 10y agoRedhat also has a lot of security features not in upstream docker due to docker, inc not accepting them: Source: https://github.com/projectatomic/docker/tree/410e23a7eeb52d4e7eadf4ee3fcee18283b8cb00#red-hat-patches https://github.com/projectatomic/docker/tree/410e23a7eeb52d4...
- justincormack 10y agoThat seccomp patch reduces rather than increases security. None of the others, other than back ports, are security features.
- SEJeff 10y agoDisabling the docker hub certainly is.
- justincormack 10y agoIn what way? It changes a default, but it only changes namespaces, not security.
- Thaxll 10y agodocker - rock-solid - v1.10 there is something odd in that sentence.
- alexellisuk 10y agoTechnically runc and the Kernel are setting up/providing your containers. Docker Engine is a platform for managing containers/images.
- user5994461 10y agodocker-engine is the name of the package.
- EtienneK 10y agoCenter for Internet Security Docker Benchmark, rule 1.5: Keep Docker up to date [1] [1] https://benchmarks.cisecurity.org/tools2/docker/CIS_Docker_1.12.0_Benchmark_v1.0.0.pdf https://benchmarks.cisecurity.org/tools2/docker/CIS_Docker_1...
- tcrews 10y ago"Keep a tab on these product updates and upgrade as frequently as when new security vulnerabilities are fixed." https://www.docker.com/docker-cve-database https://www.docker.com/docker-cve-database
- lima 10y agoBackports. I saw Docker break more than once after supposedly stable releases with security fixes.
- deleted 10y ago[deleted]
- therealmarv 10y agoWhen going CS Docker Engine you also have the latest (CS) Engine: https://docs.docker.com/cs-engine/install/ https://docs.docker.com/cs-engine/install/
- fapjacks 10y agoRed Hat has a vested interest in the failure of Docker. So... It's up to you if you want to continue using (or trusting!) any "Docker" software released by Red Hat.
- bigmac 10y agoDo not use Docker distributed by Red Hat, full stop. It has been irresponsibly patched to be insecure. They disable important seccomp filters. Instead, install using instructions here: https://docs.docker.com/engine/installation/linux/centos/#/install-with-yum https://docs.docker.com/engine/installation/linux/centos/#/i...
- darren0 10y agoDid I read that correctly? This will be delivered as a snap package?
- darren0 10y agoAs I read this again I'm quite confused what this announcement means. The mention of snap package makes it seems like "apt-get install docker..." would be a separate binary. A wild guess would be that 99% of Ubuntu users will never buy CS Docker Engine so will that 99% of users be running the debian/ubuntu packaged docker.io binary that exists today?
- simonkamronn 10y agoI think Docker through snap is still free, they'll just sell support.
- nickstinemates 10y agoCorrect. At a not so distant future point, Docker will be delivered as a snap package. Users installing docker via `apt-get` will ultimately be installing the snap. We are working through the final technical details of this portion now. We'll make sure to keep everyone updated as this transition happens, but current best practices should continue to Just Work.
- sandGorgon 10y agoi had a quick question - do you see a convergence of Flatpak and snap at some point ? because it seems that RedHat and Fedora are beginning another divergence on static packaging.
- nickstinemates 10y agoI think it's better for someone from the Canonical/Snap team to comment on that. I'll ask them to comment.
- ronjouch 10y agoCan OP or an admin de-abbreviate "CS" to "Commercially-Supported"?
- nindalf 10y agoFirst time I've ever seen this abbreviation. I only clicked because I wanted to find out what it meant. I probably wouldn't have clicked if I had known it meant "Commercially-Supported".
- LeoPanthera 10y agoOh so it's not Counter Strike running in Docker. That makes much more sense.
- ASalazarMX 10y agoMy first guess was closed source :/
- geerlingguy 10y agoOr Computer Science, Creative Suite... so many things before I would think of 'Commercially-Supported".
- sctb 10y agoSure thing, we've updated the title.
- ronjouch 10y agoThanks!
- ausjke 10y agothought Canonical is doing its own "docker", e.g. SNAP, lxd etc that are not totally identical but very similar to docker, what's going on here.
- goodplay 10y agoSimilar in foundation, different in goals.
- marcoceppi 10y agoThere's more than one type of container. Docker, and docker flavors (runc, rkt, etc). LXD is a machine container, it's the same technology that Docker was first built off of, but it's a hypervisor for really dense machines that are as light as process containers. Snaps is a package format that gives you a cross (linux) platform distribution, atomic updates, security, and isolation. It's not really like docker as it's not a density story, there's no unique TCP/IP stack, etc.
- nepotism2016 10y agolike xen? I sat on a 10 minute presentation during openstack meetup, Ubuntu dude presented LXD...then I asked myself...xen does all this...then again choice is always welcomed
- marcoceppi 10y agoSure, Xen is a hypervisor - just like KVM and a whole host of others, but Xen is /very/ heavy from a resource utilization. Xen doesn't produce lightweight VMs, they're traditional virtulation. You can produce 13 times more density with no performance trade off. No virtio, no paravirtualization, using native kernel primitives to get you machines that feel like "docker" containers, but are actual full machines.
- markshuttle 10y agoThe VM experience ("guests") without the VM overhead. A virtual machine like Xen or KVM or ESX lets you run a guest kernel of a different OS, like WIndows. LXD avoids the overhead of hardware virtualisation and the guest OS, which means it only supports Linux guests, but they run at native speeds.
- taeric 10y agoI really want to like docker for end user applications. However, until the problem of sanely sharing users into the container is solved, it is something that merely works well right up to the point you try to do something useful. I suppose this can be sidestepped by allowing root in all of your containers for the applications. I am curious if that actually provides security benefits, though.
- saganus 10y agoWhat do you mean by sanely sharing users in the container?
- taeric 10y agoAn example is easiest. I have my machine setup to provide who I am to machines I ssh to. Now, launch a container that you want to pull data from a machine that you have ssh access to. First, you'll find that the user used to setup the container was not you. So you can't even just map in your .ssh dir. So you'll try modifying the image to work with specified user at start up. Only, again, it wasn't setup that way. You will start modifying the entire image to work, but will hit tons of assumptions on user name. (You may get lucky here. I didn't.) So then you think to just run as root so that the user in the container will have permission to your .ssh files. At first you forget to specify user name on ssh commands, since the command thinks you are root now. easy enough, at least. Only, you forgot you have proxy commands in your config and other scripts that you now have to edit because they rely on your user name. So you can fix that. Now you can finally do what would have been trivial for an app installed on your machine.
- Diederich 10y agoThis is well stated. I have been making end-user apps for myself and for folks at work that require such identity, in one case, ~/.ssh, and in another, ~/.gnupg. My solution isn't particularly novel or clever, but it works well. The docker image of the command-line app is the same for all users, and so lacks their identity built in. The hack is to drive invocation of the docker image with a shell script that makes a temporary directory, copies in the necessary identity files from ~, and does a docker run that maps those identify files into the docker image. After the docker image exits, the bash invocation script cleans up. It's a hack, but it works surprisingly well. In my tests, it adds about 100ms of invocation latency for a python program. That is, running the docker image containing a python program that copies some files in as described is about 100ms slower than just running the same python program directly. It would be nice to have a more elegant solution to this, but it's not too bad.
- therealmarv 10y agoDon't be confused. CS Docker Engine is not the public available Docker Engine: https://docs.docker.com/cs-engine/install/ https://docs.docker.com/cs-engine/install/
- hackcrafter 10y agoCan anyone enumerate the differences between this and the public Docker Engine? Does it just have a different release process/QA process to allow for more stable use in deploy environments bundled with a support contract?
- hackcrafter 10y agoI'm worried about Docker living up to its valuation, and I haven't seen the business model that will meet the expectation of their valuation long-term yet. They have built a great open source product, but now that there has been a collective shift to understanding the benefits of containers, the docker runtime + container format will/should be commoditized by infrastructure companies (Google, RedHat, MS etc). So where is the value-add of Docker the company going to come from? edit: s/evaluation/valuation
- itomato 10y ago_E_valuation?
- bogomipz 10y agoDoes anyone know if this means anything significant in regards to LXD?
- markshuttle 10y agoDocker and LXD don't compete. Docker is great for running clustered processes - cloud-native apps - where Docker gives you hyperelasticity. CS Docker Engine provides more coordination facilities for those cloud-native apps. LXD is more like KVM in that gives you "guests" that feel like a full OS. You can run existing apps in there in exactly the same way you would run them in a VM. So these are two counterparts in the container continuum, and it's useful to understand them both so you use the right thing at the right time.
- bogomipz 10y agoI'm well aware of LXC, I do understand them both. And LCX is not more like KVM. KVM is full virtualization, it emulates hardware, and nothing like LXC. LXC is based on cgroups and kernel namespaces - the exact same things that enable Docker-based containers. LXD and Docker engine are competing "container"-based virtualization engines. LXC can can be run as app-based containers just like Docker. This is what lxc-execute does. You don't have to run init as pid 1 in LXC. By the way "Cloud-native" is little more than a marketing term.