4 ms·
The main difference is that it's OCI-based, so works with Docker/containerd and hopefully K8s soon (we are working on the latter). Also, correct me if I am wron
by ctalledo 6y ago
The main difference is that it's OCI-based, so works with Docker/containerd and hopefully K8s soon (we are working on the latter). Also, correct me if I am wrong, but I don't believe LXD runs K8s inside without privileged containers. Having said this, I know LXD and Sysbox use many of the same OS-virtualization techniques to do what they do. And in fact we owe much of the work we've done to the ground-work done by the good folks at Canonical/LXD.
- tarasglek 6y agoHere is how to think about NUMA. In a modern AMD epyc box, you have 2 CPUs. Each cpu has 350GB/s of memory bandwidth and has PCI devices connected to it. Memory speed between CPU sockets is some fraction, 70GB/s? if you run computation on cpu0 and talk to nic on cpu1, you burn a lot more cpu cycles, than if you move your computation to cpu1. So in theory, if you partition the box using containers such that everything on cpu0 runs in container0 and has own nics, and same thing on cpu1. You end up with 2 'virtual' boxes that might actually perform better within your container than outside of it. Note on modern CPUs, each cpu is further broken down into numa nodes(numactl -H and numa stuff n lscpu)...perf degradation isn't as great going between chiplets, but it's measurable(2x reduction in ram bandwidth?).
- rmolina 6y agoGot it, thanks for the explanation. I clearly see the use-case, just need to review cgroup specs (specifically cpuset) to fully understand if what you mention is already supported (which i believe it is).