12 ms·
Bocker: Docker implemented in around 100 lines of Bash (2015)
- sakras 4y agoThis is amazing! Does GitHub allow emoji names? I’d love it to be called 🅱ocker
- nkrisc 4y agoWhy do you need an emoji for the letter ‘B’?
- teaearlgraycold 4y agoThat emoji exists because of the blood type. 🅰🅱🆎🅾 There was a meme a while back where people would use 🅱 all over the place. Not sure why it was funny but it was.
- nkrisc 4y agoThat’s not what I’m asking. I was asking why they need an emoji to write “Bocker”
- teaearlgraycold 4y agoIt's a meme
- ghostly_s 4y agoIf you have to explain it, it's not funny. Particularly when the knowyourmeme page seems to indicate it's most prominently used by racists.
- oaththrowaway 4y agoI see no mention of the word racist on that page. Can you point it out?
- Arnavion 4y agoI don't know if it's its "most prominent" usage, but it gets used to replace the two g's in the N-word.
- oaththrowaway 4y agoCensoring the N word is racist?
- gpvos 4y agoThis is not a meme forum; the occasional meme is fine, but explanations are welcome.
- stjohnswarts 4y agoI think it was popular because of 🅱reaking 🅱ad
- NavinF 4y agohttps://knowyourmeme.com/memes/b-button-emoji-🅱 https://knowyourmeme.com/memes/b-button-emoji-🅱
- cyansmoker 4y agoI was part of this, it was a fun project. I have a final pull request that never made it though, and that's too bad as it addressed some hardcoding issues and added a few helpful commands: https://github.com/p8952/bocker/pull/23 https://github.com/p8952/bocker/pull/23 Revisiting the project, it looks like more people tried submitting PRs for the following couple years. Funny, for a project that was definitely an exercise in "do X in 100 lines of code"
- ohiovr 4y ago8,800 stars!
- throwaway892238 4y agoWhy do people care about github stars?
- ohiovr 4y agoBecause people have hobbies and wish other people are enjoying them. Or it does help people tell if code is helpful if more people are using it. Or its some guy with 8,800 throw away android phones.
- osrec 4y agoThe same reason why people care about likes on Facebook or karma on HN. Internet points mean very little, until you get enough that you start floating to the top of popularity rankings, at which point they suddenly become indirectly monetizable.
- version_five 4y agoStars have some value in they at least let you see that (the potential for funny business aside) many people have looked at the repo and upvoted it for whatever reason. I'm sure there are buggy or otherwise sketchy repos with many stars, and various gems with few stars (I have some :p ), though overall it's a signal Incidentally karma on HN is similar to the extent that it lets you how active a participant someone is, and that they're not a troll or throwaway. Again, it can certainly be gamed, and throwaway accounts often add valuable comments, but its still a signal
- moomin 4y agoI’ve been contacted more than once by recruiters who’ve been attracted by stars of my profile. It’s always a little challenging to explain to them that my profile is just my hobbies.
- tester756 4y ago
- chubot 4y agoIt looks like it relies on BtrFS? Can anyone add support for OverlayFS 2? :) which I think is more deployed these days due to Docker itself I’d be curious to see how it looks
- ajross 4y agoWith overlays, you'd need some kind of registry of all the images in the underlying filesystem. Btrfs subvolumes give that to you for free, essentially. No need for deciding where to put them, just give them a name.
- loxias 4y agoOr you could treat the final image for the container as the read only base for the overlay. That's what I do. I "flatten" the image from buildkit, and untar it to a directory. Then make an overlay mount for the container and chroot inside. :)
- ajross 4y agoRight, but the point is a btrfs snapshot does that for you. No need for a "flattening" step, just make a copy-on-write snapshot of your layer at whatever state it exists in and go. Delete the original later, etc... Doesn't matter.
- loxias 4y agoI, too, wanted something like that and wrote it, in bash. :) Can confirm it's just as easy to do as you'd expect, and works quite well.
- chubot 4y agoLink?
- jamal-kumar 4y agoIt's like 100 lines of bash, I suggest just checking out the source code. Very easy to understand once you know the basics of containerization being basically just cgroups, namespaces, and filesystem level isolation. I link it to people who are trying to learn about what containerization actually does.
- sbarre 4y agoJust a note that this repo's latest update was in 2015
- deleted 4y ago[deleted]
- quocanh 4y agoYou're telling me it's so stable and mature that it hasn't needed an update in 7 years? Incredible.
- andirk 4y agoIt can mean that but the world is a wicked place and that means no security updates either. Maybe none are needed.
- gexla 4y agoRight, because there could be a security vulnerability in any one of those 100 lines of the Bash script. ;)
- interactivecode 4y agoPeople here usually flip out about security when there is a 1 line bash install script. The world is a scary place when you don’t trust anyone
- raydiatian 4y agoThe world is an even scarier place when you trust the wrong person
- lookagain 4y agoEvery piece of software relies to some degree on other software. Similarly, every person relies to some degree on other people. As long as you don't find yourselves in a race to the bottom of the barrel, things should be okay.
- robertlagrant 4y agoWith all those prerequisites it's definitely possible. I can implement Docker witt one prereq in one line of Bash: docker "$@" You're welcome, internet.
- deleted 4y ago[deleted]
- kuschku 4y agoExcept, docker has the same prerequisites. That's kind of the point of this excercise, to show that docker is primarily glue between existing tools, not necessarily new technology.
- vbezhenar 4y agoFor me docker is three things: 1. Dockerfile concept. 2. Container image format (which is know known as OCI container). 3. Docker hub which is a repository of containers including high-quality ones. Every thing is essential and bringed innovation. Launching container is boring and not really interesting indeed.
- mattl 4y agoHow are the first two essential? If they’re useful anyone could improve on them
- vbezhenar 4y agoDockerfile format is essential because it allows for a single code to build container. This code could be used by docker build, docker buildkit, podman, kaniko and other tools. It's not ideal but it's good enough. Container image format is essential because it allows for a shared ecosystem of containers. There are plenty of container registries and you can just pull any image, build your image using those other images, etc. Basically docker introduced some standards and everyone accepted those standards. And that's a good thing. They're far from ideal, but they're kind of shared among implementations and good enough I guess. Now with those standards you can innovate on implementations. Some people replaced docker with podman, having access to the same vast repository of containers. Some people replaced docker build with kaniko, which allows to build containers in a different way using the same source Dockerfile.
- encryptluks2 4y agoJust because you can doesn't mean you should.
- wmf 4y agoYou shouldn't replace Docker with a shell script but you should understand (at some level) how Docker works. Unfortunately this code is pretty dense so it would probably take a while to untangle it.
- LaLaLand122 4y ago> You shouldn't replace Docker with a shell script True. You should replace it with podman!
- CoolCold 4y agoI see such suggestions here and there, but after quick redditing I've got impression podman brings more chores being rootless and daemonless. I couldn't justify usage of it for myself.
- CoolCold 4y agoAnswering for myself: Had short discussion with couple of friends more familiar with podman vs docker, they highlighted the case when you need to give access to docker socket (say for building images) or for other needs to someone who is not in infrastructure admins (devops) team. As we know, having access to docker effectively meant root access on host, so such untrusted parties access implies severe risk of your host belongs to someone else now. For such cases, when you cannot guarantee the one who operates docker is the root on host anyways, podman starts to make sense. Quick demo and intro: https://m.youtube.com/watch?v=OVkj_W6Bynk https://m.youtube.com/watch?v=OVkj_W6Bynk
- n4bz0r 4y agoWoah! Don't know if it can be used as a proper Docker replacement (probably not), but I sure do appreciate the project as an example of how to use all the tools to implement an isolated environment. And the fact that it actually works with Docker containers (well, why wouldn' it, but still) is just a cheery on top!
- rtlfe 4y ago> Don't know if it can be used as a proper Docker replacement The readme says "I can make no guarantees that it won't trash your system", so yeah clearly not intended for real use.
- jen20 4y agoMost software says that in the license too (even commercial software!) so it’s nice to see it front and center for once.
- stjohnswarts 4y agothat's why smart people always check this stuff out on spare machines and VMs. Right? ... right?
- counttheforks 4y agoI typically run stuff inside of docker
- yjftsjthsd-h 4y agoAnd now I'm curious whether this would work inside a container or not. I know dind is a thing, but I don't recall whether it needs special hacks that bocker lacks.
- chupasaurus 4y agoIt requires nearly full root access for the inner container runtime, thus it can trash your system.
- ajross 4y agoReally this is more interesting as a great tutorial on the way Linux container tools work (and especially their fundamental simplicity -- the docs make them seem scary when they really aren't) more than it is as a docker replacement (docker is obviously much larger than this one script, but not really "large" as a software stack). But reading this makes clear that, yes, containers are just filesystem trees, network namespaces are just like internal networks maintained by straightforward commands underneath an "ip netns" command, etc... Great stuff.
- awinter-py 4y agofollow up blogpost 'reimplementing 100 lines of bash in 1 million lines of go as resume building exercise'
- deleted 4y ago[deleted]
- DrewADesign 4y agoThen a level 79 Unix beard reimplements it in 40 inscrutable lines of Perl in the shape of an ascii whale... But can't figure out how it works an hour later.
- awinter-py 4y ago=for comment keep the ascii whale swimming do not modify this code =cut
- dang 4y agoRelated: Bocker – Docker implemented in around 100 lines of Bash (2015) - https://news.ycombinator.com/item?id=22244706 https://news.ycombinator.com/item?id=22244706 - Feb 2020 (196 comments) Docker implemented in around 100 lines of bash - https://news.ycombinator.com/item?id=16453610 https://news.ycombinator.com/item?id=16453610 - Feb 2018 (9 comments) Show HN: Bocker – Docker implemented in 100 lines of bash - https://news.ycombinator.com/item?id=9925896 https://news.ycombinator.com/item?id=9925896 - July 2015 (87 comments)
- smoldesu 4y agoLiz Rice's presentation on re-creating Docker in Go is also quite eye-opening: https://www.youtube.com/watch?v=Utf-A4rODH8 https://www.youtube.com/watch?v=Utf-A4rODH8
- version_five 4y agoYes agreed, as someone who had basically no understanding of what docker does, this was very helpful (I'm pretty sure I saw it because docker used it as an introduction to itself on their site)
- mavu 4y agoLove this. There is no other single project as overhyped and over used as Docker. This is a great way of making fun of it.
- nine_k 4y agoIf docker is overused, what would you suggest instead?
- codegeek 4y agoFor many cases, you don't need it. For example, deploying a Go binary. Some people have the habit of dockerizing everything at any cost and complexity.
- eru 4y agoYou can still stick a single binary in a container. (Putting a whole Linux in the container as well, that's probably overkill. And alas, it's also what docker does by default.)
- nine_k 4y agoThere are ready-made no-distro base images where you can stick a single binary and reap the benefits of isolation.
- tchaffee 4y agoSimple doesn't mean overhyped or over used. Both 'ls' and 'cd' are simple to implement. The script is more of a tutorial than it is making fun of anything. You'd need to give better reasons for why Docker is overhyped than "look at this simple script which does some Docker-like stuff".
- amelius 4y agoDoes it also handle the GPU correctly?
- arjvik 4y agoDoes Docker? (not counting the Nvidia docker runtime)
- amelius 4y agoIirc, docker has a "--gpus" flag.
- chupasaurus 4y agoThe flag is there for compatibility with any underlying runtime that provides access to GPU.
- llanowarelves 4y agoYet more proof that this exact UX/DX from the interface is a major part of the value add. (Edit: and docker-compose) One day the FreeBSD devs will understand. The closest is Focker: https://github.com/sadaszewski/focker https://github.com/sadaszewski/focker
- HL33tibCe7 4y agoLaughing my head off at that “important legal notice”
- jaytaylo 4y agohttps://raw.githubusercontent.com/sadaszewski/focker/master/LICENSE https://raw.githubusercontent.com/sadaszewski/focker/master/...
- mumblemumble 4y agoOnly a few lines later we have the first paragraph of the GNU GPL, which includes the sentence "Everyone is permitted to copy and distribute verbatim copies of this license document, but changing it is not allowed." IANAL, but I would guess that that implies that the author is in violation of the GPL for adding that restriction?
- totony 4y agoThe license doesn't apply to the copyright owner afaik
- mumblemumble 4y agoI believe the GPL itself is also copyrighted, and its use is covered by terms.
- renonce 4y agoAdding such a restrction does not have to change GPL itself, it’s just another sentence applied as part of the license by the author.
- wanderlust123 4y agoAny good guides that go i to detail about building docker from scratch? How would one even begin to do something like this?
- charles_f 4y agoLook at the code in bocker and understand what it's doing. That's a good guide
- elwebmaster 4y agoWhat an utter bloat and waste of resources has Docker become. Bocker looks refreshing, most of the goodies that made docker popular and no more.
- systemvoltage 4y agoWhat drives me insane about Docker is the user interface it exposes. There are atleast 3 or 4 ways to do something. API is terrible (ports - 127.0.0.1:5000:5000 is confusing as fuck design). Volumes is a total mess, networking is worse and as a veteran user of docker for over 4 years on a daily basis, I still get confused about everything Docker is and is not. It is one tool that makes me feel like a moron. I know it is an amazing tool so not to bash too much. There is a reason why I use it all the time. But goddamn it: https://stackoverflow.com/questions/24319662/from-inside-of-a-docker-container-how-do-i-connect-to-the-localhost-of-the-mach https://stackoverflow.com/questions/24319662/from-inside-of-... and goddamn it: https://stackoverflow.com/questions/22049212/docker-copying-files-from-docker-container-to-host https://stackoverflow.com/questions/22049212/docker-copying-... Docker needs a new command "sudo docker someone --invent new:docker-replacement:latest".
- nine_k 4y agoWhile some parts of Docker are far from elegance, I find the isolation of containers from the host by default a beneficial feature, and part of the very point of containers. The syntax of port mapping is unfortunate and unergonomic, but I suppose it just follows the syntax of port forwarding in OpenSSH :-/ For a number of improvements / different trade-offs, see Podman. But does it have a neat client for macOS, which many developers unfortunately run? (I don't.)
- systemvoltage 4y agoI think Docker is great, just needs a new interface.
- nine_k 4y ago
- knutwannheden 4y agoI would have opted for Shocker ;-)
- idle76 4y agoBacker?
- bgribble 4y agoMy team is being hit with really extreme pricing changes for Docker Desktop. I have never been clear on why we even wanted DD (I guess right now it’s the easiest path to getting x86 containers running on M1 Macs?). Alternatives like Podman or even a more extreme solution like this one are becoming more and more attractive.
- 411111111111111 4y agoCheck out rancher desktop, it's free and also available on apple silicone https://rancherdesktop.io/ https://rancherdesktop.io/
- kervantas 4y agoI actually replaced Docker Desktop on my M1 Mac, because even after quitting the app (properly), the qemu VM kept runing, and running my battery. I like that I have more control over the processes with podman. `podman machine stop` and the vm is gone.
- seanhunter 4y agoOn an M1 Mac I believe that rancher desktop (mentioned in a sibling thread) is the way to go if you are going the kubernetes route. Because I only have a really simple usecase and want something just like docker I've been using lima[1] which you can just install with homebrew and set up an alias and then pretend you're using docker. I have had some problems where in long-running processes with a lot of network usage in the container after a while I get some network timeouts. I'm not sure whether that's a problem with lima or qemu or what else might actually be causing it. But basically as a dev experience it works fine even on a pretty underpowered laptop (which is what I'm using it on in this case). [1] https://medium.com/nttlabs/containerd-and-lima-39e0b64d2a59 https://medium.com/nttlabs/containerd-and-lima-39e0b64d2a59
- pnt12 4y agoThe basic license is 5 dollars a month. I think that's a low price, if you consider the time cost of exploring alternatives. Additionally, it's a shame that the docker company struggles to profit from their revolutionary technology: operations, devops and infra looks completely different than 10 years ago and they played a big role in it.
- meken 4y agoAnyone know if there’s a blog post which adds more discussion and context for understanding the bash script and how all the commands fit together?
- ekiauhce 4y agoI'm excited to see _Cocker_ implementation in 50 lines of C code :)