15 ms·
Show HN: Slim – Build and run tiny VMs from Dockerfiles
- hardwaresofton 7y agoRecently on HN (I think) and related: - https://micromind.me/en/posts/from-docker-container-to-bootable-linux-disk-image/ https://micromind.me/en/posts/from-docker-container-to-boota... - https://godarch.com/ https://godarch.com/ Really like seeing these new usecases for containers -- would have never thought to mix the two technologies in this way.
- juliangoldsmith 7y agoDarch reminds me a bit of Tiny Core Linux. That uses loopback images for packages, and puts them together with UnionFS, IIRC.
- Koshkin 7y agoWell, containers and VMs are two different things (are they not?).
- derimagia 7y agoThey are different, yes.
- logicallee 7y agoDo some containers run outside a VM? Docker for example "uses operating-system-level virtualization to develop and deliver software in packages called containers."
- viraptor 7y agoMost containers run outside of VMs.
- dspillett 7y agoI'm not sure that is true. I suspect that a great many containers are running in OSs that are in turn running in VMs on hosts in "cloud" structures, perhaps eclipsing the number that are running on an OS on bare metal.
- detaro 7y agoThat's not a virtual machine. I'd personally blame marketing-speak on using "virtualization" at all (unless they refer to their windows/mac offerings, which can run a Linux VM as the docker host, on which the containers are run), but I can see how one could also stretch a definition of virtualization in a way that covers container. Sometimes containers are run in VMs, but they are almost defined as "do not require a full VM running an OS, but instead talk to the host kernel".
- logicallee 7y agoInteresting. So what makes it virtualization? What's "virtual" or "virtualized" about it?
- Bombthecat 7y agoThe kernel
- logicallee 7y agoBut per the other reply, containers are a lot less "contained" than VM's? I.e. if a program wants to list its set of processes, the host could fuck up and show them some from outside its container - whereas for the same thing to happen by a VM, it would have to have code to read that outside stuff, functionality it might not even contain... so vm's seem safer than containers... is that right?
- hardwaresofton 7y agoYep, VMs are safer than containers, because there is a larger barrier between the possibly malicious code running inside the VM than there is in the container context. A container is just another process, bound by limitations via namespaces and cgroups -- running on a shared kernel as a host. But don't take my word for it: > Simply put, containers are just processes, and as such they are governed by the kernel like any other process. Thus any kernel-land vulnerability which yields arbitrary code execution can be exploited to escape a container. To demonstrate this, Capsule8 Labs has created an exploit that removes the process from its confines and gives it root access in the Real World. Let’s take a look at what was involved. (I don't know much about capsule8 as a company is but that article[0] is pretty informative and seems spot on from what I read) If you can infiltrate a process (let's say a web server) running in a container and know a kernel exploit that can be used to get past these limitations (a "container escape"), then you can use them and get root on the main system. If that same process was running in a VM (without a container), you need to: - Infiltrate the process - Kernel exploit to gain root (assuming the program wasn't running under it) in the VM - Escape the VM (i.e. use the kernel or whatever else to actually break past the barriers of the hypervisor which was running the vm -- qemu +/- kvm, hyperv,etc) -- aka a "virtual machine escape"[1] - Gain root on the host system (assuming the process that spawned the hypervisor wasn't running as root) Generally, virtual machine security is pretty good these days, by virtue of being around longer and having more exposure and eyes looking for exploits. [0]: https://capsule8.com/blog/practical-container-escape-exercise/ https://capsule8.com/blog/practical-container-escape-exercis... [1]: https://en.wikipedia.org/wiki/Virtual_machine_escape https://en.wikipedia.org/wiki/Virtual_machine_escape
- vkaku 7y agoYes, but the cool thing is definitely the single system image
- rhizome 7y agoNot a cluster SSI, though (shared environment, process migration between instances, etc.), as far as I could gather? https://en.wikipedia.org/wiki/Single_system_image https://en.wikipedia.org/wiki/Single_system_image
- eeZah7Ux 7y agoThey seem to do very little that SystemD cannot already do with services and overlayFS, with the added benefit of being already available on most systems.
- hn23 7y agoSystemD does not run on Windows which ist still being used in many companies..
- pknopf 7y agoAuthor of Darch here, if anyone has any questions. Here are my personal recipes: https://github.com/pauldotknopf/darch-recipes https://github.com/pauldotknopf/darch-recipes
- mathnmusic 7y agoShameless plug about containers: We recently launched https://cloudcron.polyglot.network https://cloudcron.polyglot.network Tell us a Docker image, a command with arguments to run and a cron schedule - and we will execute the task and send its STDOUT to your preferred endpoint (either an email or webhook). We're in beta and are offering 15$ worth of execution time as free trial and would really appreciate HNers giving it a try. Our blog post has more details: http://polyglot.network/cloudcron http://polyglot.network/cloudcron
- tomglynch 7y agoThis has good potential, what are the limitations on the VM?
- chrisparnin 7y agoSome limitations in terms of the vms and providers: * If the size of the initrd is too large, it cannot properly unpack into vm's RAM --- size of RAM must be increased accordingly. We could also change [boot params](https://www.lightofdawn.org/blog/?viewDetailed=00128 https://www.lightofdawn.org/blog/?viewDetailed=00128), or use shared disks, etc. * For hyperkit, apple's vmnet requires sudo to create a bridge interface on host. We've played with a version that use's vpnkit and port forwarding (like linuxkit/Docker for Mac), but this adds lots of complexity in image, and opted for the simpler approach. * We would like a better template mechanism for reusing base images and extending. Right now, we support using base image reuse, with extensions through docker buildargs---ideally, we would want something like %include support in Dockerfiles. * Finally, we're investigating how to make images work well on multiple providers. For example, ubuntu does not play nice with hyperkit out-of-the-box, but works fine for vbox and kvm.
- sansnomme 7y agoWhat about swarm mode and orchestration? Also I presume like LinuxKit, there will be configs for different clouds e.g. Digital Ocean and AWS run ISOs slightly differently.
- chrisparnin 7y agoYes, one use-case is making it easier to setup/teardown clusters for local testing. Two practical scenarios for us: 1) autograding ansible/configuration scripts, 2) CI for instructions/tutorials that involve clusters/devops: https://builds.sr.ht/~ottomatica/job/69644#task-report https://builds.sr.ht/~ottomatica/job/69644#task-report Cloud-ready images is an important direction, and on the horizon.
- hedora 7y agoI’d love to see an orchestrator that made switching between bare metal, vm and containers a simple configuration option. This is a step in that direction. Cool stuff!
- _frkl 7y agoYes, I want the same thing. I do hope dockerfiles won't be the underlying configuration files to describe the machine setups though...
- pushpop 7y agoProxmox did a pretty good job of that in my opinion. Albeit it was more inspired by vSphere than Docker (it predates Docker).
- pcnix 7y agoThere's this[1], though not exactly what you asked for. [1] - https://github.com/firecracker-microvm/firecracker-containerd https://github.com/firecracker-microvm/firecracker-container...
- shaklee3 7y agoKubevirt will deploy vms on kubernetes. No bare metal option though.
- peterwwillis 7y agoIf this works, this is fantastic. Getting away from the stupidly complex abstractions around Docker is a welcome change, especially if we can still package and deploy immutable images. We already manage containers like tiny VMs, so ditching the abstractions should simplify life a bit.
- tssva 7y agoHave you looked at LXD/LXC? I find it to be a great compromise between the high overhead of VMs and the complex abstractions around Docker.
- peterwwillis 7y agoYes, it's still just more abstractions. If you look at the way people use ECS, allocating specific resource limits to each container, it's basically a micro EC2 node. And for me, the only reason I use containers is to make it easier to package and run applications immutably. If I can do that without "containerisms", all the better. It also seems like VMs would solve a good deal of multi-tenancy issues.
- eeZah7Ux 7y agoSystemD does that.
- seabrookmx 7y ago> stupidly complex abstractions Not sure what you mean.. could you give some examples? In my experience, people prefer Docker over VM's because they _like_ the abstractions and tooling associated with it. It's a lot friendlier to developers and makes immutable infrastructure a much more realistic goal for ops folks, IMO.
- IloveHN84 7y agoWhy JavaScript instead of something more performant?
- pjc50 7y agoNormally the language for doing this kind of system building would be .. Bourne shell. Or Perl/Python.
- GordonS 7y agoI was actually expecting Bash scripts before I looked at the GitHub repo. TBH, I think the code would be a lot simpler if it was just Bash.
- oblio 7y agoWhat for? It's just glue code, it doesn't actually run the micro-VMs.
- mfatica 7y agoBecause I don't want to have to install the massive nodejs runtime just to glue things together.
- pas 7y agoRun this in a docker env then? docker run -it --entrypoint /bin/sh -v $PWD:/bla -v /run/docker.sock:/run/docker.sock node:12 apk add git docker cdrkit libvirt-daemon qemu-system-x86_64 npm install https://github.com/ottomatica/slim https://github.com/ottomatica/slim cd /bla && /node_modules/.bin/slim
- oblio 7y agoThen you're going to have a hard time in the post Node.js era. You also probably want to avoid looking at what many popular desktop apps use behind the scenes :)
- 7y ago
- Hortinstein 7y agothis is great! This might have saved me some time I was planning on spending to learn packer. I have a docker based project and I wanted to add VM generation to the CI pipeline. Really excited to play with this tonight
- gravypod 7y agoWould be really cool to use this to predictably build images for booting from PXE.
- wmf 7y agoTry LinuxKit.
- AlphaSite 7y agoOn the same vain, there is: https://github.com/vmware/vic https://github.com/vmware/vic a docker engine for esx/vsphere. Note work at VMware but not on this project.
- vkaku 7y agoThis is great! I really wish we'd always create a single system image for both Docker and Physical/VM, preferably with minimal/no-init. This is very useful when trying to create a basic datacenter specific distro/deployment, preferably Pixie bootable as well.
- robbomacrae 7y agoThank you!! I always wanted to have a way of quickly ssh'ing into my docker image with some sort of virtual box implementation so I could poke around. I always felt the debug tools lacking. This is perfect. Can't wait to try it out!
- nine_k 7y agoHere comes! Getting shell in a new copy of container: docker run -it --entrypoint=/bin/sh ${container} Running shell inside a running container: docker exec -it ${container} /bin/sh Running sshd inside a container to let you peek inside is bad taste, and bad security, too.
- saurabhnanda 7y agoCan someone dumb this down for me? What _exactly_ is going on here? > slim will build a micro-vm from a Dockerfile. Slim works by building and extracting a rootfs from a Dockerfile, and then merging that filesystem with a small minimal kernel that runs in RAM. > This results in a real VM that can boot instantly, while using very limited resources. If done properly, slim can allow you to design and build immutable unikernels for running services, or build tiny and embedded development environments.
- dharmab 7y agoDocker images contain a filesystem for an operating system, minus the OS kernel. This project uses Docker to build a tiny OS, extracts all the files out of the Docker image, adds a small OS kernel and re-packages that as a VM image.
- RyanShook 7y agoSo why was Docker needed to create a lightweight VM? I thought Docker was supposed to replace VMs.
- dradtke 7y agoI assume it's mostly to make it easier for people to test this out with existing stuff. Docker containers are the standard for taking a base image and adding stuff on top of it.
- taneq 7y agoIt's a VM for Docker, not a VM using Docker.
- stjohnswarts 7y agoI think it's a VM made using the Docker ecosystem (file system segregation, siloing of other dependencies to the container, etc)
- marcosdumay 7y ago
- nerd7473 7y agoA neat idea
- idlewords 7y agoStuff used to boot off of a floppy disk!
- shereadsthenews 7y agoUsed to have self-replicating persistent malware hidden inside filed that fit on floppy disks.
- yjftsjthsd-h 7y agoAnd now we have compromised NPM packages and Dockerhub accounts. What's your point?
- shereadsthenews 7y agoMy point is people used to be able to program computers and now it's all embedded browsers all the way down which is why the recommended way to install ubuntu from macos involves downloading and running (as root!) a 330MB electron app.
- yjftsjthsd-h 7y agoPretty sure you still can, if you throw out all the drivers and libraries we've invented since then. Like, we waste lots of space, but a lot of it really is going to useful features.
- quickthrower2 7y agoAnd it took ages. What’s your point?
- ph0rque 7y agoDoes this allow for a docker image to be run inside a browser tab?
- pas 7y agoNaturally. With this and a bit of hacking: https://bellard.org/jslinux/ https://bellard.org/jslinux/
- ph0rque 7y agoForgive my lack of technical depth, but is it actually running client-side, in the memory allocated to my newly-opened browser tab, or on bellard.org's server and syncing the input/output to my browser?
- wazoox 7y agoIt's a real VM running in your browser, in Javascript.
- cbluth 7y agoTechnical depth? Did you click the link? > Run Linux or other Operating Systems in your browser! It runs in your browser. If you clicked the link you would also see demo links that run in your browser.
- pas 7y agoNo need to be abrasive, many companies offer things "in your browser" yet they merely send you the frontend and instruct your browser to connect to their backend. Such as gaming SaaS thingies.
- lioeters 7y agoThe virtual machine (emulated CPU, devices) and the OS are running fully client-side: https://bellard.org/jslinux/tech.html https://bellard.org/jslinux/tech.html
- smattiso 7y agoWhat would it take to get this running on iOS and Android?
- seabrookmx 7y agoYou'd never be able to run this on iOS. It's far too locked down. You might be able to add QEMU support to this, and then run it on an Android device if you have root. But it would perform terribly because mobile chips generally don't have virtualization extensions and ARM as a virtualization host is a pretty immature platform. TL;DR - far too much to be practical.
- buildbuildbuild 7y agoI’m curious how this approach compares with Kata Containers. Very cool.
- lwb 7y agoWait a minute. I thought Docker was useful because you didn't want to run a whole VM. But this project turns a Dockerfile into a VM specification? Have we come full circle?
- gjmacd 7y agoI was also thinking the same thing. I also think that the prior person wanting to SSH into their docker instance hasn't quite grasped that you can already do that. I'm not sure what the value of this is.
- pknopf 7y agoThe "building" feature of Docker is very much applicable to VMs/bare metal. There spirit of this feature is just "building a root fs". There is no concept of "containers" or "vms".
- turtlebits 7y agoWell, containers generally run headless applications/servers. I can see this for VM sandboxed GUI apps.
- zarmin 7y agoYou should check out that Docker project where you take most of the files from a Docker VM and spin up a Docker container. It's called Docker.
- root_axis 7y agoDocker can replace a VM for many use-cases, but there are times when a VM is still preferable. If you find yourself in such a situation, this tool allows you to leverage declerative Dockerfiles to build your VM. Pretty handy.
- freedomben 7y agoYep, I could see this being a nice option if you're running something very security sensitive and want some extra defense by isolating the kernel.
- deleted 7y ago
- pard68 7y agoCan slim be used to create an iso? So: Dockerfile > slim > iso
- PhilippGille 7y agoFrom the GitHub README: > `$ slim build images/alpine3.8-simple` > This will add a bootable iso in the slim registry.
- dastx 7y agoWhy does everything in node have to have all the dependencies in the world? ``` @sindresorhus/is JSONStream ansi-regex ansi-styles archive-type argparse asn1 async balanced-match base64-js bcrypt-pbkdf bl bluebird brace-expansion buffer buffer-alloc buffer-alloc-unsafe buffer-crc32 buffer-fill buffer-from cacheable-request camelcase caw chalk chownr cliui clone-response color-convert color-name commander concat-map concat-stream config-chain content-disposition core-util-is cross-spawn debug decamelize decode-uri-component decompress decompress-response decompress-tar decompress-tarbz2 decompress-targz decompress-unzip docker-modem dockerode download duplexer3 emoji-regex end-of-stream escape-string-regexp esprima execa ext-list ext-name fd-slicer file-type filename-reserved-regex filenamify find-up from2 fs-constants fs-extra fs-minipass fs.realpath get-caller-file get-proxy get-stream glob got graceful-fs graceful-readlink has-flag has-symbol-support-x has-to-string-tag-x hasbin http-cache-semantics ieee754 inflight inherits ini into-stream invert-kv ip is-fullwidth-code-point is-natural-number is-object is-plain-obj is-port-available is-retry-allowed is-stream isarray isexe isurl js-yaml json-buffer jsonfile jsonparse keyv lcid locate-path lodash lowercase-keys make-dir map-age-cleaner md5-file mem mime-db mimic-fn mimic-response minimatch minimist minipass minizlib mkdirp ms mustache nice-try node-virtualbox normalize-url npm-conf npm-run-path object-assign once os-locale p-cancelable p-defer p-event p-finally p-is-promise p-limit p-locate p-timeout p-try path-exists path-is-absolute path-key pend pify pinkie pinkie-promise prepend-http process-nextick-args progress proto-list pump query-string readable-stream require-directory require-main-filename responselike safe-buffer safer-buffer scp2 seek-bzip semver set-blocking shebang-command shebang-regex signal-exit simple-git sort-keys sort-keys-length split-ca sprintf-js ssh2 ssh2-streams streamsearch strict-uri-encode string-width string_decoder strip-ansi strip-dirs strip-eof strip-outer sudo-prompt supports-color tar tar-fs tar-stream through timed-out to-buffer trim-repeated tunnel-agent tweetnacl typedarray unbzip2-stream universalify url-parse-lax url-to-options util-deprecate uuid which which-module wrap-ansi wrappy xtend y18n yallist yargs yargs-parser yauzl ```
- montecarl 7y agoThis is what you get when you combine a really easy to use package management ecosystem and the standard library is really bad. You don't see this in Python for example, because its not so easy (its getting better though) to create packages and because its standard library is massive.
- sealthedeal 7y agoWhat would an ideal re-world scenario look like for using these micro vms?
- pcnix 7y agoDocker containers don't have a robust security boundary, due to the kernel sharing that they do. These micro VMs combine the low resource cost of a container with the solid security boundary of a VM, which is very useful in a multi tenant architecture. AWS Fargate and AWS Lambda run entirely on micro VMs.
- JustSomeNobody 7y agoAre we just going in circles now? Why not just start with a tiny vm and call it a day?
- yjftsjthsd-h 7y agoTooling matters. Building and managing VMs has, historically, been more work.
- eeZah7Ux 7y agoDebootstrap has been doing the work with pretty much one command for 10+ years.
- 40four 7y agoThis sounds interesting, I want to look into it further. However, my immediate thought is what about the naming conflict with the very popular PHP framework? http://www.slimframework.com/ http://www.slimframework.com/
- ajsharp 7y agoThis is cool. For dev, the docker runtime consumes an enormous amount of host system resources. Even with a 16gb RAM host machine, docker is really resource heavy for a development environment. If this can cut down on host system resource usage, that's a major win.
- kristianp 7y agoAre you on a non linux host? I assume docker is a lot less heavy on resources on linux than on mac&win.
- freedomben 7y agothey have to be. Docker is extremely light weight on a linux host.
- GordonS 7y agoI assume they are running it on Windows - I've been running Docker Desktop on Windows for years, and it's backed by a Hyper-V Linux VM, which does seem to use a lot more CPU than running Docker on Linux.
- dlespiau 7y agoYet another different take: footloose – Containers that look like Virtual Machines! https://github.com/weaveworks/footloose https://github.com/weaveworks/footloose (Disclamer: I'm the author of footloose)