7 ms·
Proxmox Docker Containers Monster – 13000 containers on a single host
- samspenc 3y ago"Your scientists were so preoccupied with whether they could, they didn’t stop to think if they should." Dr Ian Malcom, Jurassic Park Not knocking this achievement though, it's awesome they were able to pack that many containers in one host.
- oriettaxx 3y agoI strongly suggest any sys admin to look at the relatively new Proxmox Backup Server https://www.proxmox.com/en/proxmox-backup-server https://www.proxmox.com/en/proxmox-backup-server which makes full incremental backups so light thanks to a well enginered deduplication
- dizhn 3y agoIt really pairs well with proxmox. I've tried many methods but for proxmox vm and cts nothing was better than their own backup server.
- Havoc 3y agoAlso, this can be deployed to hyper-v. So you can backup your proxmox server to your desktop machine easily. Most people's desktops are well spec'd so that's functionally free
- the_third_wave 3y agoIt works well and saves a fair bit of space due to deduplication (which is filesystem-independent as it implements its own deduplication layer). It can get quite slow when backing up containers, e.g. a container with a 200GB root filesystem takes a bit more than 2 hours (PBS running in container on the same Proxmox host, backup from SAS array to single SATA drive). Backup of a group of 4 filesystems totalling 2.25TB containing mostly larger files (Peertube video storage, Nextcloud data directories and image archives) on the same installation takes about 4 hours so the time needed varies significantly with the characteristics of the data to be backup up.
- CoolCold 3y agoit's could happen that only Sysadmins among this site visitors crowd are FreeBSD guys, everyone else are Developers or DevOps/SREs in the worst case :) And on FreeBSD there are Jails and BHyve, so not a Proxmox audience as well, IMHO.
- HTTP418 3y agoWhy run docker in lxc when you can run lxc directly?
- m463 3y agoI would LOVE it if proxmox supported docker (or podman) out-of-the-box. (I mean with docker/podman showing up in the gui, just like LXC containers and vms) LXC is just a container, docker is much more than just that. It is a recipe (dockerfiles), it is sort of a social project sharing setup, it is like a version control system (the layered filesystem that only updates changes), it is a disposable dev container, it is a deployable runtime container, etc
- lhoff 3y agoThis is one of the reasons is switched to TrueNas Scale for my HomeServer. Before that I always had a VM that was the Docker Host and another one with OpenMediaVault as Backup Server. Both these VMs are replaced by TrueNas. Less complexity and less maintenance overhead.
- duffyjp 3y agoHave you by chance tried GPU passthrough on TrueNAS Scale? I'm planning a Homelab do-over this summer and one requirement is to have a Windows VM with a dedicated GPU I can use as a Steam host via Parsec. I haven't used TrueNAS since it was FreeNAS and BSD based.
- Helmut10001 3y agoI run nested Docker in unprivileged LXC on Proxmox on ZFS since 2019 without problems. Gitlab, Nextcloud, mailcow-dockerized etc., for 10 people, - altogether 10 LXC with about 25 Docker services, 1-2% CPU utilization on average, thanks to sharing all resources of the host. I've written a blog post about it [1]. [1]: https://du.nkel.dev/blog/2021-03-25_proxmox_docker/ https://du.nkel.dev/blog/2021-03-25_proxmox_docker/
- szszrk 3y agoLXC doesn't have the images and tools ecosystem around. Also, LXC and Proxmox have a mutual vibe that is amazing to work with (if you care to take a closer look). LXC is a first class citizen in Proxmox, with clear documentation, config files, CLI tools and web UI. It can be backed-up just like a VM (Proxmox Backup Server FTW!), can be set up mostly like a VM, it boots instantly and so on. It's such a joy to work with, unless you want access to actual hardware (which includes things like mounting or hosting NFS/Samba), but even then it's easy to find help on docs and forums (the latter are surprisingly up to date). But LXC does not have that "ephemeral" nature like Docker. Container "templates" are clean but full operating systems, full hard drives are connected and host all data, both user files/images and OS. Just like a VM, I guess. Now, you can actually run Docker inside LXC easily and have best of both worlds: docker with docker-compose and alike to quickly prototype and homelab AND super light and quick to boot machines which will host that Docker for you. It's actually a very clean and pleasant approach, I highly recommend this as tool for testing and homelabing.
- yootyootr 3y agoas a technology risk and compliance manager who is embroiled in a big disaster recovery/business continuity/ISO 22301 project at the moment, reading this headline made parts of me turn to dust and drop off.
- speedgoose 3y agoWhy ?
- ahachete 3y agoIt's not the same, but reminded me of this post [1] I wrote some time ago, about a 63-nodes EKS cluster running on VMs with Firecracker on a single instance. [1]: https://www.ongres.com/blog/63-node-eks-cluster-running-on-a-single-instance-with-firecracker/ https://www.ongres.com/blog/63-node-eks-cluster-running-on-a...
- trollied 3y agoThis is all well & good, but I'm not sure what useful images you could actually run with 10 megabytes of memory each. The nginx containers provisioned would not have been able to do much, if anything.
- blueflow 3y agoIf you keep in mind that containers are only namespaces for the filesystem and network resources, this is not too different from running 13000 processes on the host without containers. Comparable to building something with make -j64.
- xhrpost 3y agoI guess I still don't fully understood containers / Docker. If they are only namespaces, what does it mean to run an Ubuntu image on my Mac?
- detaro 3y agoOn Mac there is simply the additional step of Docker Desktop running a Linux VM for you, so that it has something to run the containers in. (EDIT: On Windows that's also an option, or you set it to run against Windows' native container support - which then can only run windows-based images. But really, usually people mean "on Linux" when they discuss how Docker works)
- xhrpost 3y agoHmm, what kind of VM? By default, my M1 Mac will only run arm64 software under Docker. If an arm64 build is not available for something (ie x64 only), I can change the architecture setting, and only then will Docker attempt to run the process using Qemo. If Docker on Mac is already a VM, why does it need Qemo? Why does the Docker VM not emulate across architectures?
- KronisLV 3y agoOh hey, you don't see a lot of Docker Swarm nowadays, though in my experience it's still a wonderful solution for getting started with container orchestration, that will take a lot of the smaller/medium scale projects pretty far, before you need to look at something else (e.g. Nomad or Kubernetes). There's a lot of benefit in being able to hit the ground running even when you're self-hosting your clusters and administering them yourself. It comes available with an install of Docker, is easy to setup and operate, has great optional UI solutions like Portainer (analogue to Rancher for Kubernetes), has one of the lower resource usages for the orchestrator itself, as well as supports the Docker Compose specification, which in my opinion is far more usable than the Kubernetes manifests (though less powerful than Helm charts) and far more common than Nomad's HCL. For my Master's Degree, I explored a comparison where I ran the same workloads across a Docker Swarm cluster and a K3s cluster (a great Kubernetes distro that's low on resource usage as well) and even then Swarm used less memory (~2x less than Kubernetes for the leader node both under load and when idle) and used a bit less CPU (~30% less for the leader nodes under load) as well. That said, K3s still performed admirably, at least in comparison to RKE which wouldn't even run in a stable fashion on the limited hardware that I had at the time. Maybe one of these days I should run Proxmox in my homelab as well, instead of just something like Debian or Ubuntu directly on the hardware. Also, while Podman is great, Docker still seems like a dependable option just because of how common it is and given how it's gotten more stable over time (despite the arguable architecture disadvantages). I think the only actual issues I've had since when using Docker Swarm have been using a network that ran out of addresses to assign to the containers (probably some default), some Oracle Linux bug where kswapd would top out the CPU when the swap got full, as well as some Debian bug years ago on an old version of Docker that caused networking to fail and the cluster needed to be re-created to fix it.
- ndsipa_pomu 3y agoWe've been using docker swarm for running some basic services as kubernetes seems way over-engineered for simple stuff. Our basic requirements is that a service will be auto-restarted as soon as possible if/when something breaks. However, though swarm is easy to use and configure, I've found that having a small swarm (e.g. three nodes) means that you end up having each node be a manager as the swarm fails if half the manager nodes aren't up. I've also found that "docker compose config" doesn't work in a compatible manner and have to use "docker-compose config" instead.
- whalesalad 3y agoI am so glad the latest Proxmox VE release contains a dark mode.
- oriettaxx 3y agodark mode? what is it?
- galbar 3y ago>docker swarm init And just like that you have a cluster to run containers on. I really like the simplicity of Docker Swarm. I've been using it for at least five years and it's just worked. During the COVID lockdown I got tired of having to open a UI (at the time I was using CapRover[0]) to edit any of the services I run so I decided to make my own PaaS with a nice CLI. Connecting to the docker socket is easy and the API is simple enough. It's been working no problem for the last two years. The only complaint I have is that I can't see the user's IP for HTTP requests[1] but there is some hope in the form of Proxy Protocol[2]. I have no idea how complex the code for Docker Swarm ingress is, but I may spend a weekend in the near future scouting the code to get an idea. The current possible solution is to put a load balancer in front of the cluster that either sets the X-Forwarded-For header (or any of the equivalent ones) or speaks Proxy Protocol but I will avoid that solution for now. I recommend Docker Swarm as a solution for anyone starting that doesn't want to spend hours and hours configuring a production environment. Even if it is just one node, you get services, replication, healthchecks, restart policies, secrets... And it all starts with that simple command, no further config needed. [0]: https://caprover.com/ https://caprover.com/ [1]: https://github.com/moby/moby/issues/25526 https://github.com/moby/moby/issues/25526 [2]: https://github.com/moby/moby/issues/39465 https://github.com/moby/moby/issues/39465
- MuffinFlavored 3y agoWhy Swarm over Compose? Why Swarm over k3s?
- galbar 3y agocompose has no proper concept of service and its replicas. Deploying an update to a service in Compose can be problematic. Swarm also enables multi-node deployments, which you can't do with Compose. k3s, as simple as it is compared to full k8s, still carries some of the complexity of k8s. Swarm just feels simpler and easier to manage.
- remram 3y agoAs opposed to "minikube start"? Or "k3s server"?
- nnntriplesec 3y ago13000x 10MB memory, to be precise
- galkk 3y agoTl;dr - there is nothing really special in Proxmox that lets run and manage 13000 containers. Author created 10 vms on Proxmox host and ran docker on them. You don’t really need Proxmox for what described. When I first saw Proxmox I also wanted to see if I could use it to manage docker containers, but it doesn’t support it directly. For working with containers you need other tools, eg Kubernetes.
- razerbeans 3y agoTrying to figure out what's unique here, but it seems like Proxmox is being used to create VMs that then run docker. Then docker on these VMs is used to spin up a bunch of containers. So really, it's just Proxmox -> VM -> Docker -> Containers. So it's dedicated docker VMs to coordinate containers... I was expecting Proxmox's LXC capabilities to be used to scale up to 13000, but this is just VMs + docker allowing that. Seems like the same thing could be done with any LVM hypervisor and VMs? Can someone correct me if I'm missing something?
- unethical_ban 3y agoNo, sounds like you got it.
- ornornor 3y agoAFAIK it’s the only way to run docker containers on proxmox. You can run lxc containers directly but docker requires an intermediate vm… which is one more reason to avoid docker altogether :)
- salmon 3y agoYou can install Docker directly on Proxmox. I did a little comparison of the 3 methods [1]. [1] https://danthesalmon.com/running-docker-on-proxmox/ https://danthesalmon.com/running-docker-on-proxmox/
- pxc 3y agoIf you wanna watch a beefy Windows machine fall apart, run this under WSL. Even relatively modest Docker workloads completely destroy vmmem.exe (or vmmemWSL.exe, depending on your WSL version).
- gamedna 3y agoWhile there is merit to this post my main criticism running 13000 containers with zero load - essentially all the nginx processes are doing nothing - zero I/O, etc. after launch. Its a bit more interesting to see N# of containers running something synthetic that mimics a workload. That said, containers are very lean (or can be with the right setup) given there is no kernel, drivers, etc to load.
- unethical_ban 3y agoActually, I'm confused. They talk about running it in LXC containers, but where exactly he installs Portainer is still a mystery to me. Furthermore, the screenshots show a lot of VM icons, not CT icons. So where is this person using LXC? edit: Wait, did they install docker/portainer on Proxmox bare metal? They say to access Portainer through the Proxmox host IP, but any CT or VM created on Proxmox would probably have its own IP on a Proxmox bridge. So the IP should be the IP of the VM/CT hosting the docker install, not the Proxmox host.