7 ms·
The "market" did not want Docker. Docker as a product failed. There are many reasons why FreeBSD jails count not get out for FreeBSD land, one, very important
by StreamBright 5y ago
The "market" did not want Docker. Docker as a product failed.
There are many reasons why FreeBSD jails count not get out for FreeBSD land, one, very important thing is the Linux community's NIH attitude.
- shatteredgate 5y agoI don't think you can explain that as NIH. From what I have seen, Linux namespaces are a much more powerful primitive than BSD jails.
- kazen44 5y agonamespaces in what sense? network namespaces? because freebsd has VNET for a while now. which seems to do the same thing.
- shatteredgate 5y agoAnd all the other ones: https://man7.org/linux/man-pages/man7/namespaces.7.html https://man7.org/linux/man-pages/man7/namespaces.7.html BSD jails are similar but not quite the same thing.
- ori_b 5y agoI don't get it. How are people using this flexibility to get things done in practice, and what uses aren't allowed by the jail model?
- shatteredgate 5y agoYou can just compare the APIs, namespaces are like the individual components of a jail. You can use them to build something like a jail, or something different that has a different security model. This was discussed a lot in an old HN thread: https://news.ycombinator.com/item?id=13982620 https://news.ycombinator.com/item?id=13982620
- ori_b 5y agoYes, I am aware that it's got more moving parts. What are you using this flexibility for?
- shatteredgate 5y agoI'm using them for several things but the most straightforward one is probably that namespacing can be gradually added to services, you most likely see benefits from this already if you use systemd. That's one way that namespaces can be used in a different way from the docker model.
- ori_b 5y agoWhat are you adding gradually, specifically? Like, a concrete example that names a namespace you may want to use. I'm trying to figure out what problems a half sandbox solves, and a vague "I just want to enable some capabilities" doesn't help here.
- shatteredgate 5y agoA lot of the various security options in systemd: https://www.freedesktop.org/software/systemd/man/systemd.exec.html https://www.freedesktop.org/software/systemd/man/systemd.exe... The sandboxing and mount-related ones are implemented with namespaces, and the idea with them is to not make any of them mandatory so they can be slowly added to system services. That way you can get some of the benefits without needing to build a full rootfs/container for the service. I am not sure how any of those would be done with jails because jails require you to create a chroot and network interface, whereas in Linux the mount and network namespaces are just optional namespaces and you can still use the other namespaces without using them.
- shatteredgate 5y agoSide note: I suppose you could chroot to /.
- 5y ago
- ajross 5y ago> How are people using this flexibility to get things done in practice Um... to loop back to the upthread point: Docker. People are using Docker, and docker is using this stuff.
- ori_b 5y agoAnd how is it mixing and matching these APIs? Given that there's an OCI-compatible runner for jails (runj, compatible with runc -- which is what docker uses to start containers), it seems to me that Docker isn't in actually using the flexibility afforded by the APIs here, but is just using a relatively fixed set of options. If I'm wrong: what is it using, and what problems is this flexibility solving?
- shatteredgate 5y agoI haven't tested runj but just from looking at it, it seems it is not fully compatible with everything that runc does because the OCI itself specifies a lot of Linux-specific functionality.
- trasz 5y agoCan you provide some examples?
- ajross 5y agorunC is literally the abstraction layer docker wrote internally on top of linux containers! It exists as a separate layer now because they spun it out precisely to freeze the API and enable other efforts like runj. And runj, IIRC (though I'm not an expert in the space) wasn't a trivial 1:1 thing and required changes to the underlying jails layer to enable it.
- StreamBright 5y agoWell, looking at the following things sort of gives it away: - brtfs vs zfs - cgroups vs jails - SystemTap vs dtrace - Systemd vs smf I get it, many of these were due to licensing issues. So they said[1]. Anyways, there are still some things to implement for linux. pf is my favourite (software) firewall. It would be great to see it ported to Linux. 1. https://opensource.stackexchange.com/questions/2094/are-cddl-and-gpl-really-incompatible/2106 https://opensource.stackexchange.com/questions/2094/are-cddl...
- shatteredgate 5y agoIn my experience, both Linux developers and BSD developers don't seem to care too much about porting things to the other's operating system. If you want to do things the Linux way you can use Linux, and if you want to do things the BSD way you can use BSD. That's seen as easier than trying to glue two incompatible things together.
- int_19h 5y agoBSD developers can't port things from Linux in a straightforward manner due to license issues. But that doesn't apply the other way around.
- shatteredgate 5y agoI don't see why. BSD and GPL are equally compatible, it doesn't matter which way you go. I can see why they wouldn't want a GPL component to be mandatory but it can be made an optional component for Linux compatibility which seems to be the way BSD would want it anyway.
- ajross 5y agoWon't, not can't. *BSDs shipped GPL components for decades before they decided to go for purity. It's a policy decision, not a incapability or mandate.
- deleted 5y ago[deleted]
- redis_mlc 5y ago
- ajross 5y ago> The "market" did not want Docker. Docker as a product failed. Docker as a paid product failed. Docker as a company is failing. "Docker" in the sense I meant (of the software people use to launch containers), is pervasive and dominant. It won. And jails, in comparison, "lost", because jails didn't really do what Docker wanted. And what the market wanted was Docker.