3 ms·
I wish apple would support a couple extra kernel features (like bind mounts) so we can have native macOS 'containers' instead of this nonsense. Running MySQL by
by bouk 6y ago
I wish apple would support a couple extra kernel features (like bind mounts) so we can have native macOS 'containers' instead of this nonsense. Running MySQL by running qemu inside a Linux VM is just insane. Nix can fill some of the same roles, but it doesn't work on M1 yet
- sneak 6y agoWouldn't that also require full namespace support, not just "a couple extra kernel features"? At that point if you want to bind mount in a container you're talking about macOS binaries running inside the container, which means a full macOS docker architecture port (like they did for Windows, which AFAICT didn't make them much if any money, but I think M$ paid for it anyway).
- bouk 6y agoNamespaces are useful for security maybe, but for macOS the biggest reason to use containers is to have a controlled and reproducible way to run certain pieces of software. With chroot and bind mount you can already achieve that.
- mr_toad 6y ago> native macOS 'containers' instead of this nonsense. Running MySQL by running qemu inside a Linux VM is just insane. A ‘native’ container would be running the MacOS kernel. You could run MacOS software in it, but it would be incompatible with Linux docker images.
- neop1x 6y agoWouldn't some kind of "syscall proxy" or a wrapper possible? There is gVisor [1] which if I understand correctly re-implements Linux kernel in userspace for security, pretty interesting. Such layer would have to re-implement missing pieces in Mach kernel though so maybe it would not be as easy. [1] https://github.com/google/gvisor https://github.com/google/gvisor