3 ms·
> As long as debugging isn't fundamentally incompatible with a unikernel approach, it's just a matter of maturity. Well no, it's not "fundamentally" incompatib
by wkz 9y ago
> As long as debugging isn't fundamentally incompatible with a unikernel approach, it's just a matter of maturity.
Well no, it's not "fundamentally" incompatible, it just doesn't seem very practical. And practicality matters IMHO.
Maybe I'm missing something but it seems the debug mode of these systems would be very similar to how you debug a regular kernel. I.e. you have some GDB stub provided by your hypervisor. That might be fine for GDB, but what about all the tools to observe a running system? How would I ftrace, perf, strace, netstat, tcpdump, poke around in /proc and /sys etc?
Sure there is noting stopping you from developing equivalent tools. But it's not very practical. Building a truly isolated container environment for Linux (something like Zones) would also give you isolation and provisioning speed, but you get to keep all your tooling.
- equalunique 9y agoTry it with the LING Erlang-on-Xen unikernel and see for yourself if it's not debugabble. Looks like they've got a solution for dubugging: https://twitter.com/erlang_on_xen/status/641628659657371648 https://twitter.com/erlang_on_xen/status/641628659657371648
- wkz 9y agoAgain, I'm not saying it can't be done. If Erlang+Xen=Debug then that's great. But if we're comparing unikernel-VMs to containers, my guess is that most users are after the "take my $LANG binary and concatenate it with half a Linux kernel"-workflow. And for that general case, most standard tools are off the table.
- weberc2 9y ago> Well no, it's not "fundamentally" incompatible, it just doesn't seem very practical. And practicality matters IMHO. I don't think it's fundamentally impractical either, since a unikernel is simply the parts of the OS that you need compiled into the application binary. Maybe this means it is actually running an SSH server, but I think it will look more like a debug service running in the application (if only because unikernels likely wouldn't have processes or files or other concepts that are designed for a multi-tenant world). > But it's not very practical. I think this is the question--do the gains justify the costs. And considering the gains include a reduced attack surface, simpler orchestration, reduced resource allocation, etc. I think this is the case in the cloud market, which is only growing. > Building a truly isolated container environment for Linux (something like Zones) would also give you isolation and provisioning speed, but you get to keep all your tooling. You don't get to keep all of your tooling with containers anyway--unless you're rolling your own orchestration and container runtime, you're almost certainly using the tools provided by or building off of your container runtime. This is especially true if your service runs on dozens or hundreds of hosts--you're probably not just SSHing onto prod servers to do your debugging with your ordinary tools; you're relying on something that abstracts over those hosts (of course, there are exceptions, but they're just that: exceptions).