2 ms·
Clear Containers has merged into Kata Containers -- gVisor offers a different set of tradeoffs than Kata (or CC). The big one is resource footprint -- gVisor wi
by jsolson 8y ago
Clear Containers has merged into Kata Containers -- gVisor offers a different set of tradeoffs than Kata (or CC). The big one is resource footprint -- gVisor will typically be lower, often much lower than Kata. On the other hand, for very syscall heavy workloads Kata needn't take exits (while gVisor exits for many syscalls that make it beyond the sandbox), so performance on gVisor will have higher variance with respect to syscall rate. Kata also offers the opportunity for sandboxing things like kernel driver blobs (since you get a whole new Linux ring 0) while gVisor relies on the host kernel for many tasks.
There's a lot of overlap between cgroups, gVisor-style sandboxes, and VM-style sandboxes like Kata. The tradeoffs between them are mostly with respect to compatibility, robustness of the security boundaries, and performance. So, you know, the usual suspects.
We've reached a stage where we probably need better vocabulary for describing these tradeoffs :)
(I work on "near" the gVisor folks at Google, and I'm involved in the Kata community)