3 ms·
Nope, nope and nope. This fad is as tone-deaf as Howard Schultz running for POTUS. Unikernels are TERRIBLE for operations. How do you have privilege separation?
by duelingjello 7y ago
Nope, nope and nope. This fad is as tone-deaf as Howard Schultz running for POTUS. Unikernels are TERRIBLE for operations. How do you have privilege separation? Separation of concerns? Processes? Users? Groups? Talk to a database or LDAP? Have a reliable filesystem? Drivers for hardware? Updates? Security audits?
They’re the “emperor’s new clothes” but they throw away ALL the generality, security, lessons and existing infrastructure by reinventing the wheel, badly. They were a fad years ago but failed for these and many reasons.
- eyberg 7y agoMost unikernels dont have the notion of users, groups, or multiple processes on purpose for security and performance reasons. Some unikernels use the best in class file systems available like zfs by default. Containers have all of these. Containers aren't unikernels. Drivers are way less of a concern cause all you need is a clock, a network driver and a disk driver, not 30 different USB drivers, half a dozen networking drivers and more. Half of linux is just drivers cause it's designed to run on real machines whereas unikernels are explicitly designed to run as vms. Happy to engage with real life examples on these concerns but the best way to truly understand since there's all sorts of misunderstanding here is to just simply deploy one.
- sp332 7y agoFor every single ? in your comment, the answer is "it's done at the hypervisor level". A unikernel is basically a single process, so privilege separation, users, groups etc are irrelevant. Drivers are much, much simpler (and I would argue, easier to audit) because they mostly only need to access virtualized, hypervisor-provided HAL APIs. Filesystem, DB, LDAP would be external - possibly provided by another VM on the same physical hardware.