42 ms·
Alternative idea: throw away docker and katacontainers and move to freebsd, where jails were introduced on 14 Mar 2000 (no, seriously, superior technology exist
by justanother- 8y ago
Alternative idea: throw away docker and katacontainers and move to freebsd, where jails were introduced on 14 Mar 2000 (no, seriously, superior technology exists for 19 years - stable, time proven, working).
Some more info: https://www.freebsd.org/doc/handbook/jails.html https://www.freebsd.org/doc/handbook/jails.html
And for quick start: https://github.com/iocage/iocage https://github.com/iocage/iocage
- jeswin 8y agoThere have been vulnerabilities in jails previously. Also, Linux gets far more attention from exploit researchers because of wider adoption - so the number of incidents isn't a good metric. Kata has hardware isolation, so will be safer. If I have misunderstood jails and it's immune to kernel exploits please do correct me.
- justanother- 8y agoSorry, I am not going into endless debates. It is waste of my time. Check documentation, read about it and technology is here for 19 years. I dont care what anyone useses. I have just stated what the most reliable technology for compartmentization is. Docker and kata are in IT time since yesterday and there are lots of dragons still hiding. Same goes for integration with ZFS (part of freebsd since 6 April 2007).
- peterwwillis 8y agoThe major use case for Docker is really as a massively simplified package manager and an entrypoint for distributed applictions. Other features, like quicker runtime than VMs and system isolation, are just icing on the cake. It took a massive marketing campaign to get people to use Docker and realize it made their life easier, so something like iocage would need the same push. (Also, nobody wants to start adopting additional OSes unless absolutely necessary)
- halbritt 8y agoImmutability is pretty cool. Also the sibling to that where you're running the same immutable artifact in all of your environments. Any kind of isolation is just icing on the cake.
- v_lisivka 8y agoLinux VServer project started in 2003: http://linux-vserver.org/ChangeLog-1.2 http://linux-vserver.org/ChangeLog-1.2 . We used it in production more than 10 years ago at multi-terabyte site (Bazaarvoice).
- ajross 8y agoJails are virtually identical technology to Linux containers from a security point of view. They've had holes before and they likely will again, and a breakout like this (seems like the root cause here is a writable file descriptor to the host binary) can absolutely compromise the host system. The upthread recommendation was using hardware VM technology, which is a fundamentally different isolation model from what software can provide and (at least in theory) makes that kind of exploit impossible. And while there are tradeoffs with everything, for you to throw that argument out due to personal platform loyalty is really, really bad advice.
- justanother- 8y agoSure, but there were 19 years of time proofing them. Each product has vulnerabilities which get weeded out when time passes. And for kata and docker, in context of what they are used for, they are bleeding edge. (from a technical perspective, you would be running jails for years too - so much about platform loyality)
- geofft 8y agoVulnerabilities don't get weeded out by time like radioisotopes decaying. Vulnerabilities get weeded out by attention, and attention happens when people use a system in production to protect a high-value target. Jails haven't been used to protect as many high-value targets as Linux containers have. This is not a comment on the technical quality of jails. It may well be a comment on the world's anti-FreeBSD prejudice. But either way it's still true, and that means the 19 years of existence didn't magically harden the product.
- SteveNuts 8y ago> Jails haven't been used to protect as many high-value targets as Linux containers have This is not true in my experience at all. It may be true that it hasn't been in use at startups until Docker came out, but a few large, established companies I've worked at absolutely used Jails or Zones to protect their most valuable IP. And have been for a long time.
- deleted 8y ago[deleted]
- barbecue_sauce 8y agoIs there a centralized jail image repository with images of jails running popular open source software applications that I can search from the command line and spin up locally or in a cluster with a few commands? Can I easily replicate and distribute an image of a jail? Because that is what Docker offers.
- nisa 8y ago...or Solaris Zones / illumos Zones (2005) - you can even run Docker on them.
- howiroll 8y ago19 years without vulnerability because no one uses it seriously. Seriously. Deal with it.
- justanother- 8y agoTaken from some other thread: "Most "unix" admins only know linux and will advocate for it vigorously because it is so much better than.. "what do you use again? Fedora? Ah, FreeBSD, something with F, I knew it!""
- duncaen 8y agoMaybe they just want exploit mitigation techniques like ASLR.