7 ms·
I feel nowadays containers generally refer to the concept, and cgroups and namespaces are the implementation details of a specific container runtime. These are
by matharmin 7y ago
I feel nowadays containers generally refer to the concept, and cgroups and namespaces are the implementation details of a specific container runtime. These are very important implementation details for security and performance, but it doesn't fundamentally impact how you structure your containerized application.
You can take the same container image, and run using Docker, Firecracker, gVisor, or many other container runtimes. Some of them are exactly "like a VM, but lighter".
- cmckn 7y agoAgreed. The post feels a bit pedantic; I don't know any dev doing "cool things" with the underlying namespaces/cgroups. They're just using Docker. De-mystifying containers has value, but so does the abstraction.
- mav3rick 7y agoThe abstraction muddles the performance, security etc. impact of these two models. Not knowing them is going to be bad in the long run. Not everyone is a web dev.
- mav3rick 7y agoAnd I'm a dev "doing cool things" with namespaces / cgroups.
- moomin 7y agoPlenty of them using those features, if they’re using Kubernetes, Docker Swarm or especially Istio. They might not know they are, but that’s besides the point.
- jdmichal 7y ago> They might not know they are, but that’s besides the point. I actually thought that was exactly the point here...
- bregma 7y agoYour personal ignorance makes a poor argument. Not only do I know several devs doing cool things with namespaces and cgroup, but I myself have done cool things with namespaces and cgroups. I played with Docker briefly, but it has no real practical application in my line of work.
- mav3rick 7y agoPlease don't propagate this. Running in a hypervisor with a possible different kernel vs running on the same kernel in the same ring as the host are two very different things. Implications of these are very different.
- imtringued 7y agoFrom the perspective of the developer there is no difference. They just configure kubernetes or docker to use a different Container runtime and keep using the same compose files, etc.
- simonh 7y agoI think the point the OPs was making is that yes, as you say, developers can use containers without knowing these differences, but that there are actually real and important differences and maybe it would be better if more devs were aware of them.
- mav3rick 7y agoYes exactly.
- pydry 7y agoI've had bugs when doing webdev stuff in docker that didn't crop up under one kernel that cropped up when using another. It's rare but it happens.