5 ms·
I wouldn’t consider the distinction “fuzzy”. Assuming we’re talking Linux (I don’t know about the Mac and Windows world) containers are implemented using namesp
by openasocket 3y ago
I wouldn’t consider the distinction “fuzzy”. Assuming we’re talking Linux (I don’t know about the Mac and Windows world) containers are implemented using namespaces and cgroups, and always have been. Whether you are talking docker, containerd, some more minimalistic thing built on runc, it’s all Linux namespaces and cgroups. And those things were explicitly not designed to act as security boundaries when running untrusted code.
- deleted 3y ago[deleted]
- zokier 3y agoKata containers would like a word
- yjftsjthsd-h 3y agoNow in fairness, that is very specifically using a VM to add an even stronger boundry; it's not really the same thing.
- Kluggy 3y agoDoes anyone actually use Kata containers? I've tried recently to run them on a current Ubuntu platform and couldn't get it working at all after a few days of work.
- dharmab 3y agoYes, I worked for a very large tech company that used Kata.
- k1r1ka 3y agoIf it's Ubuntu, possible you had docker inside snap unintentionally and issues because of that? I had a bit trouble getting it integrated with certain versions of Podman, but that aside setting up kata was pretty straightforward. I have so far only used it for hosting some gameservers which I don't trust, i.e some simple containers, but I really want to try it in a new k3s cluster once I get it setup and move some services there. I like the idea of putting internet facing ones into it as an additional layer of separation and could imagine it being useful in production.
- pjmlp 3y agoAzure does, https://thenewstack.io/microsoft-adopts-openinfra-kata-containers-security-on-azure/ https://thenewstack.io/microsoft-adopts-openinfra-kata-conta... https://learn.microsoft.com/en-us/azure/confidential-computing/confidential-containers https://learn.microsoft.com/en-us/azure/confidential-computi...