3 ms·
I’m all for more people using immutable machine images for their base system images, and think more environments should be built this way. However, I’m not sur
by tjfontaine 8y ago
I’m all for more people using immutable machine images for their base system images, and think more environments should be built this way.
However, I’m not sure what the difference is here from say https://github.com/linuxkit/linuxkit https://github.com/linuxkit/linuxkit which also has an example for how to use LinuxKit to build Kubernetes environments https://github.com/linuxkit/kubernetes https://github.com/linuxkit/kubernetes
- andrewrynhard 8y agoIt is indeed very similar. Talos does a few things differently. The biggest being that it does not allow any host-level access and exposes a gRPC API for things like querying the processes, or restarting a node.
- tjfontaine 8y agoSo essentially you just need to put your gRPC agent in a linuxkit image with access to the containerd socket? That’s how the docker in docker/kubernetes examples already work for LinuxKit. I am not sure what exactly you mean by “does not allow host level access”, the benefit of linuxkit is you can configure the software that needs to run in the root namespace, or not, aside from every process generally having a mount namespace. The real benefit (imo) of LinuxKit is the familiar declarative manifest model for image definition, and container configuration. As a by product, it’s really straight forward to have reproducible builds.
- andrewrynhard 8y agoLinuxKit is really neat. Don't get me wrong. I think each have their benefits. LinuxKit is great if you need that flexibility. With Talos we would rather focus on building a Kubernetes-centric distro.
- coredog64 8y agoSo it’s like osquery over gRPC?