4 ms·
What you're describing is exactly the reason people use docker. No need to use ansible, or to manage interfaces if you don't want to, it just work out of the bo
by cdancette 9y ago
What you're describing is exactly the reason people use docker. No need to use ansible, or to manage interfaces if you don't want to, it just work out of the box, and you run just bash commands to configure it.
- inferiorhuman 9y agoI'd argue no. Dockerfiles are riddled with gotchas and limitations. In this case using Anisble initally is more akin to using Packer to build an image. For ongoing maintenance it's because I maintain state in the jails. In terms of managing interfaces, iocage does that for you. The IP address has to be assigned manually, but that would be trivial to automate. A couple of IPFW rules work just fine to NAT the loopback aliases for a dynamic set of jails.
- oblio 9y agoYou sound like that comment on the Dropbox HN annoucement page: https://news.ycombinator.com/item?id=9224 https://news.ycombinator.com/item?id=9224 You've just added at least 2 more concepts to the thing you have to use: iocage and ansible. On top of the jails thing. That's the exact opposite of "easy to adopt". Especially since most people that use something like Docker already don't care or want to learn Docker, they just want the benefits of using containers.
- inferiorhuman 9y agoThat's a bit like saying that Docker is one more thing on top of LXC that you have to learn. jails : iocage :: lxc : docker ansible : iocage :: packer : docker The workflow and terminology is somewhat different but that doesn't make it inherently more difficult to adopt. The "slick" DSL that Dockerfiles provide become quite limiting in short order especially as each line bloats the eventual Docker image quite significantly. Case in point, you can't set file ownership when you copy files into the image so that extra step adds that much more bloat.
- oblio 9y agoYou only learn about docker... Regarding your later edit about bloat, well, it seems most people don't really care about that.
- inferiorhuman 9y agoYou only learn about iocage… (although even with Docker you should have at least a little knowledge of how things work under the hood for when things invariably break).
- oblio 9y agoI was curious about iocage, is it this thing? https://github.com/iocage/iocage https://github.com/iocage/iocage It's FreeBSD only, why are we even having this discussion? :)
- inferiorhuman 9y agoTake a look at the post I originally replied to. It was commenting on docker versus the alternatives.
- imtringued 9y ago> Case in point, you can't set file ownership when you copy files into the image so that extra step adds that much more bloat. I think you could solve that problem easily with multi-stage Dockerfiles. FROM alpine:latest COPY . /app RUN chown/chmod FROM alpine:latest COPY --from=0 /app /app
- inferiorhuman 9y agoThat looks suspiciously like an additional layer beyond the copy step to me (either that or a terrifically non-intuitive syntax).