3 ms·
Thanks! Yes, Sysbox is using OS-virtualization techniques to augment the abstraction of the container, thereby enabling software that interacts deeply with the
by ctalledo 6y ago
Thanks! Yes, Sysbox is using OS-virtualization techniques to augment the abstraction of the container, thereby enabling software that interacts deeply with the kernel (e.g., dockerd, k8s, etc) to run inside the container, and do so with proper isolation (no privileged containers). Now that you mention user-mode linux, it is one of the references we used as we built Sysbox, though they are very different things of course. I think my background as a VMware ESX kernel developer played a strong influence too ...
- swsieber 6y agoSo can you run sysbox in sysbox?
- ctalledo 6y agoUnfortunately not. Sysbox requires "true root" privileges, so it can't run inside a system container deployed by Sysbox itself (since that system container would use the user namespace). You can run Sysbox inside a privileged container however, and in fact the Sysbox test framework relies on this heavily. What use case do you envision for running sysbox in sysbox?
- swsieber 6y agoIt's mostly curiosity. Probably docker in docker in docker.
- ctalledo 6y agoGot it; note that inside a system container you can always run docker-in-docker using privileged containers (https://hub.docker.com/_/docker https://hub.docker.com/_/docker). That is, you don't need sysbox nesting in order to run more levels of docker nesting inside the system container. And those privileged containers would only be privileged within the system container, but not at host level.
- swsieber 6y agoOh, that's cool. TIL. Thanks for taking the time to respond to something pretty far off in the weeds.
- danielheath 6y agoNo OP but one of my first questions about any layer is “how transparent is it”. If it can’t host itself, it’s clearly not 100% transparent. This matters because it adds cognitive overhead - I have to keep track of which features are available at which layer.
- ctalledo 6y agoAgreed; it's certainly something we will keep in mind as we mature Sysbox.