6 ms·
Show HN: Vas-quod – A minimal Linux container runtime written in Rust
- octoberfranklin 6y agoHey cool, I was just about to spend a bunch of time writing pretty much the same thing. What's up with the name? It is cool. But it is weird. In fact it is cool-weird.
- ibraheemdev 6y agoLess then 200 lines of code? That is very minimal :)
- flhoc 6y agolol yeah but i guess it'll grow in size with few more components.
- flhoc 6y agoThere is this roadmap https://github.com/flouthoc/vas-quod#roadmap https://github.com/flouthoc/vas-quod#roadmap
- tym0 6y agoReminded me of Docker in Bash: https://github.com/p8952/bocker https://github.com/p8952/bocker
- RoutinePlayer 6y ago<naming rant> What is wrong with the simpler 'vasquod'??</naming rant> :-)
- Simplicitas 6y agoI second that :-)
- deleted 6y ago[deleted]
- flhoc 6y agoHahahah I'll try to fix the name
- vishvananda 6y agoNice work on this! If you cut out a bunch of the features supported by other containerization systems, the code gets quite short. My first one was in C and only a couple hundred lines. I worked on a full-featured rust container runtime while I was at Oracle. It is compatible with the oci-runtime spec, so can be used as a runtime for docker or kubernetes. The most up to date fork is at https://github.com/drahnr/railcar https://github.com/drahnr/railcar if you want to take a look at it for any ideas.
- flhoc 6y agoSure, I have already heard of railcar before. I'll take a look at this again then i'll try to improvise vas-quod
- flhoc 6y agoJust curious.Why did oracle archive railcar.
- vishvananda 6y agoI was the main developer with a little support from the rest of my team. I moved on a couple of years ago and my team was RIFed a few months later, so likely they don't have anyone left to work on it.
- academi 6y agoAny security concerns?
- flhoc 6y agoits not 100% secure as of now.
- jerry1979 6y agoAlways wish we could run a container system like this without sudo/root access.
- cmonfeat 6y agoPodman allows you to run containers without root privileges, in case you aren't aware. But maybe you mean something else?
- jerry1979 6y agoI wasn't aware of that. Thanks for bringing it to my attention!
- albatruss 6y agoWhich container system can't run this way? I've only used Docker which does run rootless.
- ldng 6y agoPodman has the added value of running daemonless too
- yashmehrotra 6y agoPretty neat, minimal and functional
- a-dub 6y agogiven there's an unshare in linux-util, i think it would be possible to even do this with a shell script. :)
- RenaudWasTaken 6y agoEnroot does exactly that: https://github.com/NVIDIA/enroot https://github.com/NVIDIA/enroot
- flhoc 6y agotrue there is https://github.com/p8952/bocker https://github.com/p8952/bocker.