3 ms·
A more extreme version of this would be to install something like Prox-mox on a machine (doesn't have to be the actual machine you're using, but probably could
by LocalPCGuy 3y ago
A more extreme version of this would be to install something like Prox-mox on a machine (doesn't have to be the actual machine you're using, but probably could be) instead of the standard OS, and then create virtualized containers for each "use case" (and then use good security practices on each containerized OS as well of course).
Setup correctly, if any one container was to get compromised, it shouldn't leak out to anywhere of the other ones. Would be super inconvenient, I'm guessing to actually have a semblance of efficiency there would still likely be a "main" container and you'd SSH into others in order to do tasks associated with that container. Not too much different than the "clean OS" described here, probably the helper scripts could be similarly adapted to utilize the individual containers instead of docker containers.
I personally would be hard pressed to consider something like that, but seems like the logical continuation of this type of machine configuration/setup.
- yjftsjthsd-h 3y agoSo https://www.qubes-os.org/ https://www.qubes-os.org/ ?
- ar_lan 3y agoThey are similar, but Qubes is more targetted at the end user - proxmox is more traditionally used as the hypervisor for distributed applications. You can probably achieve the same goals with either though (barring differences in Xen and KVM).
- _joel 3y agoProxmox isn't a hypervisor (last time I checked!), it's a management plane to different hypervisors.
- LocalPCGuy 3y ago> Proxmox is an open-source, Type 1 hypervisor that comes as a Debian-based Linux distribution. With Proxmox, users can experience a hypervisor that can integrate Linux containers (LXC) and KVM hypervisor, networking functionality, and software-defined storage in a unified platform. I'm not saying you are wrong entirely - it can be used as a management plane for different hypervisors, but it is also a hypervisor in it's own right as I understand it. (grabbed the quote above from ServerWatch). There is a lot of confusion about this topic as some people argue it isn't a type 1 because it goes through KVM, but others rebut that because KVM is in the kernel and has direct hardware access (very gross summary of arguments I barely know enough about to keep up, and sometimes don't).
- ar_lan 3y ago> Proxmox isn't a hypervisor KVM is in the kernel, and I specifically called out KVM. If the point you are trying to make is that KVM is the hypervisor, then Qubes is also not a hypervisor because it uses Xen. But this seems like a very strange distinction to make to me unless you are specifically trying to peer into the inner-workings. At that point you'd probably be saying ESXi is "not a hypervisor" because it has to defer the actual VM deployment to vmkernel. I don't know of an OS without a kernel.
- _joel 3y agoProxmox can use a hypervisor, KVM, or manage containers. It's not a hypervisor. Xen is also hypervisor. Saying proxmox is a hypervisor is like saying virt-manager is a hypervisor.
- ar_lan 3y agoYou're just debating semantics, debatably incorreectly, and for no reason. KVM is not a type-2 hypervisor in this case - Proxmox can be hosted on bare metal and use KVM natively. > Saying proxmox is a hypervisor is like saying virt-manager is a hypervisor. This is... just wrong? Proxmox is much more equivalent to ESXi than to a UI application. -- To grante you the tiniest bit of good faith, I would wager that you and I are two heads of this specific coin. An excerpt from Wikipedia on the matter (https://en.wikipedia.org/wiki/Hypervisor https://en.wikipedia.org/wiki/Hypervisor): > The distinction between these two types is not always clear. For instance, KVM and bhyve are kernel modules[6] that effectively convert the host operating system to a type-1 hypervisor.[7] At the same time, since Linux distributions and FreeBSD are still general-purpose operating systems, with applications competing with each other for VM resources, KVM and bhyve can also be categorized as type-2 hypervisors.[8] You seem very concerned that KVM (and thus Proxmox) cannot be considered a Type 1 Hypervisor. I disagree. But if your assertion is that Proxmox cannot natively deploy VMs... then I have no idea what to tell you. You're blatantly wrong. Just try it.
- _joel 3y agoJust try it? Didn't want to have a pissing contest, but if you will. I've have, since late 2000's and used it to deploy production deployments for eden.sahanafoundation.org in Haiti, Chengdu and other places, using Proxmox and KVM. I've also built public and private clouds using OpenNebula and OpenStack (using KVM/libvirt). I'm also vmware certified (or was, back in late 2000's, when working for a prominent UK ISP). It's a management framework, it doesn't do virtualisation itself, it uses the libvirt framework. I can use the same kvm hypervisor by using qemu-kvm (or virt-manager, which uses the same stuff). Again it's just a management layer.
- m463 3y agoI think the killer app for proxmox would be integrating docker or podman as a first-order feature. Right now you can set up a VM or an LXC container. In comparison to docker/podman, LXC is more like being a sysadmin.
- LocalPCGuy 3y agoYah, as I understand it (not a sysadmin, just hobby stuff), if you want to run something in docker, you'd have to setup the system first and then docker on top of that. I'm not sure you need the docker layer though - it's unnecessary overhead probably. Each VM/container could just have the necessary OS with the packages needed for that particular use case installed directly. Guessing someone who tried to use a system like this would probably have their own custom containers / linux distributions, or at least have custom install scripts that would function much like the docker compose file does in getting everything installed on that container for different use cases.