8 ms·
Mirage – A programming framework for building type-safe, modular systems
- pjmlp 3y agoAlso with a bit living inside Docker. https://mirage.io/blog/2022-04-06.vpnkit https://mirage.io/blog/2022-04-06.vpnkit
- rwmj 3y agoWeren't they at some point acquired by Docker?
- pjmlp 3y agoYes, https://techcrunch.com/2016/01/21/docker-acquires-unikernel-systems-as-it-looks-beyond-containers/ https://techcrunch.com/2016/01/21/docker-acquires-unikernel-...
- hannesm 3y agoSome MirageOS developers were hired/acquired by docker -- though not the (open source) project, beither the code... There's still quite some work on MirageOS itself, including reproducible binary builds, VPN, DNS services, orchestration solutions, ...
- skgough 3y agoThe FAQ mentions that this can run in QEMU. Are there cloud providers that support hosting a custom ISO? I feel like that would be hard to secure.
- PhilipRoman 3y agoLots of them. VPS typically are not secured at the os level, but as separate VMs. For the cloud provider it's just a matter of picking an ISO (plus a few management extensions but those are usually optional)
- iampims 3y agoDigitalocean supports it: https://docs.digitalocean.com/glossary/iso-image/ https://docs.digitalocean.com/glossary/iso-image/
- hannesm 3y agogood news is that MirageOS can as well be executed in a seccomp context with only 5 or 7 system calls allowed -- see the spt target of solo5 https://github.com/solo5/solo5 https://github.com/solo5/solo5 -- also this great talk by mato https://archive.fosdem.org/2019/schedule/event/solo5_unikernels/ https://archive.fosdem.org/2019/schedule/event/solo5_unikern...
- sprobertson 3y agoI'm intrigued but your site gives me little to go on, I feel like I'm missing a big "what this is" page
- ReleaseCandidat 3y agoWell, they say it's a unikernel (construction kit) in the first paragraph. Of course that doesn't help much if you don't know what a unikernel is ;)
- crabmusket 3y agoThis episode of Signals & Threads discusses Mirage, it may be helpful! https://signalsandthreads.com/what-is-an-operating-system/ https://signalsandthreads.com/what-is-an-operating-system/
- kunley 3y agoThis talk is great in its revealing of history, does it in a very meaningful way. I had few romances with OCaml over the last two decades but never had a broad view on the different phases of its evolution. Anil provides a lot of insights about that here
- ekianjo 3y agoIs that similar to Firecracker?
- hexmiles 3y agoIf I understood it correctly, is more like something to run inside firecracker. Is like a toolkit to build a really small os to run a single application, that then you run on top of a hypervisor.
- datadeft 3y agoNot really. Firecracker fits on the host kernel - guest kernel axis while Mirage is a unikernel that is orthogonal to the concept of microvm concept. https://dev.l1x.be/posts/2020/11/22/getting-started-with-firecracker-on-raspberry-pi/#abstract https://dev.l1x.be/posts/2020/11/22/getting-started-with-fir...
- fhuici 3y agoNo, though you could use Firecracker to launch a Mirage (or any other) unikernel. Basically from the bottom up the stack is: 1. Hypervisor (e.g., KVM, Xen, Hyper-V), runs directly on the hardware 2. Virtual Machine Monitor (e.g., QEMU, Firecracker), running on the host's user-space (say Linux) and in charge of starting/stopping/managing VMs and interacting with the hypervisor 3. Virtual machines, eg, a Linux VM running an NGINX web server. (the above is simplified because there are differences between type-1 and type-2 hypervisors, but those diffs would make this message too long) A unikernel is actually a virtual machine, just a very specialized one that doesn't use a general-purpose OS underneath. They tend to use library OSes, so that it's possible to choose libs that are appropriate to each app at build time. And while we're at it :) , a MicroVM is nothing more than a standard VM (e.g., based on Linux) launched/managed via a fast/modern VMM like Firecracker.
- ekianjo 3y agoThanks for the explanation!
- v1ne 3y agoI'm really sold on the idea: Instead of a full-blown OS, you compile your application with a thin layer of support libraries that provide the OS features that your application needs (network, I/O) and that talks to a hypervisor. I mean, if your application runs in a virtualized environment, there's little need to SSH into the system in the first place (except for debugging purposes). Thus, why bother with a full-blown operating system? In the virtualized case, the true OS logic is in the host OS anyway, talking to the hardware. Cutting out all those superfluous layers in the app VM makes it small, start quickly, and gives less attack surface. Sounds like a win-win to me. In contrast, FreeBSD on Firecracker is a full-blown OS, but boots in 25 milliseconds on the Firecracker hypervisor.
- BrittonR 3y agoIsn’t that the aim of webassembly?
- ReleaseCandidat 3y agoNot really, as the filesystem you access from Webassembly needs to be in a sort of sandbox or container too.
- pjmlp 3y agoNot at all, WebAssembly is replacement of PNaCL browser vendors could agree on. Then a bunch of folks, with some VC money, decided to make the second coming of Java and .NET with it.
- Osiris 3y agoIsn’t this the same idea behind unikernels?
- edf13 3y agoThat’s what this is… > MirageOS is a library operating system that constructs unikernels for secure, high-performance network applications across a variety of cloud computing and mobile platforms.
- xlii 3y agoPersonal pet-peeve (from Requirements page): > (…) They should build on any modern UNIX (or macOS) system with OCaml and OPAM installed. (…) I just checked. MacOS Sonoma is STILL UNIX certified, and I get that wording “any modern UNIX” would not be clear this minor error annoys me. s/or MacOS/including MacOS/
- ReleaseCandidat 3y agoMaybe it's not about "Unix", but "modern"? Although, "modern Unix" is an oxymoron. duck and run
- pjmlp 3y agoI not always agree with Rob Pike, but this one is a must. "We really are using a 1970s era operating system well past its sell-by date. We get a lot done, and we have fun, but let's face it, the fundamental design of Unix is older than many of the readers of Slashdot, while lots of different, great ideas about computing and networks have been developed in the last 30 years. Using Unix is the computing equivalent of listening only to music by David Cassidy." -- https://interviews.slashdot.org/story/04/10/18/1153211/rob-pike-responds https://interviews.slashdot.org/story/04/10/18/1153211/rob-p...
- dontlaugh 3y agoIronic, considering how many "different, great ideas about computing" Pike wilfully ignored in the development of Go.
- jezovuk 3y agoIs this (functionally) similar to CloudCaptain, ex-BoxFuse? https://cloudcaptain.sh/ https://cloudcaptain.sh/
- fhuici 3y agoNo, CloudCaptain is based on Linux, and tries to provide a minimal, though Linux-based, image. Unikernels do not use Linux at all: you can always try to minimize Linux but fundamentally it is a monolithic OS and fully specializing with it would require non-negligible engineering. Instead, unikernels are (typically) based on a modular OS that makes it easier to pick and choose modules for each target application, resulting in images that can be an order of magnitude smaller, boot much faster, etc. The difficulty with unikernels in the past has been to (1) making them Linux API compatible, (2) making them accessible/easy to use and (3) integrating them with popular tooling ecosystems (e.g., Docker, Kubernetes, Prometheus, etc.)
- dinosaure 3y agoYou can also have a few examples about unikernels here: https://builds.robur.coop/ https://builds.robur.coop/.
- goy 3y agoAnother one is HalVM [0], for Haskell. Unfortunately it's not maintained anymore. [0] https://github.com/GaloisInc/HaLVM https://github.com/GaloisInc/HaLVM
- fhuici 3y agoThere's also LF/OSS www.unikraft.com, language-agnostic/Linux API compatible, actively maintained.
- baumschubser 3y agohttps://unikraft.org/ https://unikraft.org/ it is
- 9dev 3y agoWhat is the benefit over using containers, as in Docker? Whether you use a container runtime or an actual hypervisor comes down to pretty much the same thing, operationally. Both keep your self-contained services alive and distributed. From the application perspective, a container also contains only those parts of an OS the app actually needs, and defers everything else to the host. The only caveat about MirageOS seems to be that your applications need to be written in OCaml, which is a neat language and all, but certainly not mainstream…
- trenchgun 3y agoDocker Desktop uses Mirage OS behind the hood: https://mirage.io/blog/2022-04-06.vpnkit https://mirage.io/blog/2022-04-06.vpnkit
- gizmo 3y agoIt makes no sense for a microservice that does one simple thing to run on top of 10 million lines of 90s C code. Especially since a lot of that code has to do with hardware quirks that don’t exist in a hypervised environment.
- Veserv 3y agoA hypervised environment also has 10 million lines of 90s C code with a lot of code dealing with hardware quirks, it is called the hypervisor. You are right that it makes no sense to have a hypervisor, OS, and application. The hypervsior and OS are basically doing the same job. But the solution is not bare metal + hypervisor + device drivers + hypervisor services + library OS + application like a unikernel design. It is bare metal + OS + device drivers + OS services + application like a container design.
- fhuici 3y agoAt least for cloud deployments you'll (for almost all cases) already have a hypervisor underneath to provide strong isolation. With that in place, ideally you'd run your application (ultimately the only thing you care about) as close to that hypervisor as possible. Instead, we have hypervisor, and then inside the VM the (say Linux) kernel, user-space, the container runtime, and finally the application. With a unikernel the stack becomes hypervisor and a VM that has a very thin layer and then the application -- as close to the application running on the hypervisor as possible. This results in lots of gains in terms of minimal cold boot times, memory usage, server density (thousands on a single server), etc. In fact, you don't need to see containers and unikernels as an either or choice: in fact, at Unikraft (another unikernel project) for development and local deployment we have support for Docker/Dockerfiles -- and then for deployment we provide a lean unikernel as described above. Hope this clarifies things somewhat.
- mkarliner 3y agoDoes anyone know if there might be Arm support coming? This strikes me a a nice fit for some single board computers.
- mk89 3y agoin the overview page they mention something (deployment to embedded devices) https://mirage.io/docs/overview-of-mirage https://mirage.io/docs/overview-of-mirage EDIT: here as well: https://mirage.io/docs/install https://mirage.io/docs/install maybe you need a Solo5 backend that can run on ARM; and finally: https://github.com/Solo5/solo5/blob/v0.6.3/docs/building.md#supported-targets https://github.com/Solo5/solo5/blob/v0.6.3/docs/building.md#...
- reycharles 3y agoIt is possible to run Mirage in ARM under for example KVM or using the seccomp target. There is as well an experimental bare-metal target for raspberry pi 4 called gilbraltar https://github.com/dinosaure/gilbraltar https://github.com/dinosaure/gilbraltar. A big obstacle there is the device drivers. It is very cool to run bare metal on an rpi4, but it would be cool to be able use the network interface too.
- cmrdporcupine 3y agoThe rough Rust of this is https://github.com/hermit-os/hermit-rs https://github.com/hermit-os/hermit-rs Though last I looked it wasn't nearly as mature as MirageOS.
- Opert34 3y ago[flagged]
- aerzen 3y agoHow is this different than running a docker container based on scratch, containing a single statically linked binary?