9 ms·
Linux Container Internals
- tyingq 9y agoA great resource to understand how Linux containers work is "Linux containers in 500 lines of code": https://blog.lizzie.io/linux-containers-in-500-loc.html https://blog.lizzie.io/linux-containers-in-500-loc.html Or, if you just want to skip to the code: https://blog.lizzie.io/linux-containers-in-500-loc/contained.c https://blog.lizzie.io/linux-containers-in-500-loc/contained...
- liaoyw 9y agobocker(https://github.com/p8952/bocker https://github.com/p8952/bocker) is also very good for understanding containers
- kragniz 9y agoWriting the basics of a container runtime is easier than it sounds. Last summer I was curious how they work and wrote something simple in python that can run docker images: https://github.com/kragniz/omochabako/blob/master/omochabako https://github.com/kragniz/omochabako/blob/master/omochabako https://asciinema.org/a/77296?speed=2&autoplay=true https://asciinema.org/a/77296?speed=2&autoplay=true I learned a lot doing this, and I'd recommend it to anyone who's interested about containers.
- pooktrain 9y agoThanks for sharing! When you set out to do this, had you studied docker's source code at all? Or did you just have a basic understanding of containers? Other than the link from OP, are there any resources you'd recommend to get one to the point where you have enough understanding of the concepts without having to "cheat" and look at the docker implementation? I want to do this too, but it's not as much fun if you need to go to the source due to not understanding the fundamentals.
- kragniz 9y agoI started with a basic understanding about the parts involved, but not so much how they fit together. Most of the necessary information came from the lwn series of articles posted in another comment: https://lwn.net/Articles/531114/ https://lwn.net/Articles/531114/ The actual namespace stuff was easy, the harder part was pivoting the root fs and figuring out all the things to mount. At some point I looked at the source for systemd-nspawn, but I forget exactly what for.
- bogomipz 9y agoThanks for the links. What was your starting point the Docker/Golang source?
- jbb67 9y agoWhich language is the sample code written in? Looks.... awful.
- mhh__ 9y agoRust?
- deleted 9y ago[deleted]
- simcop2387 9y agoLooking at the blog's source, yes rust (and the code looks like rust also). https://github.com/rabbitstack/rabbitstack.github.io/blob/master/operating%20systems/linux-containers-internals-part-i/index.html#L177 https://github.com/rabbitstack/rabbitstack.github.io/blob/ma...
- archrabbit 9y agoit's Rust. Btw, did you see erlang or clojure? ;p
- striking 9y agoWhat's the point of writing your program in Rust if it's almost entirely wrapped in `unsafe{}`? You'd be better off just writing a C program. It could even be clearer to a wider audience what exactly you're doing.
- archrabbit 9y agoI probably could wrap in the `unsafe` block just the invocations to the system calls. I'm learning Rust and I wanted to give the post some freshness. There are already a plethora of examples in C.
- tiles 9y agoThat's a bizarre argument; the post is about writing an abstraction over another interface, and it's clearly meant to be extended. The abstraction can be written in a safer language than C. Seems like there's an obvious upside.
- corbet 9y agoIf you want more information on how Linux namespaces work, there's an extensive series of articles on LWN at https://lwn.net/Articles/531114/ https://lwn.net/Articles/531114/
- deleted 9y ago[deleted]
- dankohn1 9y agoFor a very high level overview, I really like this essay: You Could Have Invented Container Runtimes: An Explanatory Fantasy https://medium.com/@gtrevorjay/you-could-have-invented-container-runtimes-an-explanatory-fantasy-764c5b389bd3#.npqdu2abx https://medium.com/@gtrevorjay/you-could-have-invented-conta...