3 ms·
> in a single-process (roughly) operating system. Containers don't (generally) run in their own operating system, just their own userland. It can actually be
by dangerbird2 6y ago
> in a single-process (roughly) operating system.
Containers don't (generally) run in their own operating system, just their own userland. It can actually be a source of security vulnerabilities to assume that containers are completely isolated from each other, such as running a root user container in production, assuming it can't get privileged access to the host. It's less similar to a bare-metal MS DOS application than it is a glorified chroot jail
- avmich 6y ago> Containers don't (generally) run in their own operating system Right, but containerized application can't (ideally) talk to other applications on the same machine, that's how it's similar to a single-process OS with a single app running. Of course there are details like a single application may still contain multiple processes from OS standpoint, but the overall comparison stands. > It's less similar to a bare-metal MS DOS application than it is a glorified chroot jail These two cases are similar enough from containerized application standpoint (only OS services are different than those of MS DOS).