2 ms·
Re: 1 - that might be true, but you still probably wouldn't want to co-tenant a sandbox'd process with a total stranger. The overhead of a total Linux kernel is
by madmax96 8y ago
Re: 1 - that might be true, but you still probably wouldn't want to co-tenant a sandbox'd process with a total stranger. The overhead of a total Linux kernel is still larger than a unikernel-native application, so if you're a cloud provider, encouraging and using unikernel technology makes a lot of sense.
Re: 2 - this is managed by the hypervisor. SEL4 can be run as a hypervisor and has been formally verified to be correct [1]. Trusting a proven system like SEL4 is a far-cry from trusting Linux's isolation primitives because we can make hard-guarantees about the behavior.
Unikernels have the advantage that they are basically backwards-compatible (you can run any VM on the infrastructure you develop, even if that infrastructure is tuned for unikernel-native applications). With Unikernels, you can achieve VMs that are lighter than containers [2] thereby increasing your customer-per-server ratio.
[1] https://sel4.systems/Info/FAQ/proof.pml https://sel4.systems/Info/FAQ/proof.pml
[2] http://cnp.neclab.eu/projects/lightvm/lightvm.pdf http://cnp.neclab.eu/projects/lightvm/lightvm.pdf