3 ms·
> Does this work under Kubernetes? > Yes, but we caution users to evaluate if you really need kubernetes. Chances are you don't and you will experience severe
by dfee 3y ago
> Does this work under Kubernetes?
> Yes, but we caution users to evaluate if you really need kubernetes. Chances are you don't and you will experience severe performance and security problems if you choose to run under k8s. If you still find you must here are instructions for running Nanos under k8s.
https://nanos.org/faq https://nanos.org/faq
Pretty interesting FAQ! I hope to see more HN discussion about this page!
- nextaccountic 3y ago> security problems if you choose to run under k8s I'm here wondering, what security problems could this have? https://docs.ops.city/ops/k8s https://docs.ops.city/ops/k8s doesn't elaborate and just says > Security Warning > Running unikernels under kubernetes diminishes some of their security benefits.
- Twirrim 3y agopure speculation: I imagine it's just "Well, now there will be Linux involved" where previously you'd just be relying on Nanos.
- eyberg 3y agoI can speak to this. Containers, and by extension k8s, break a well known security boundary that has existed for a very long time - whether you are using a real (hardware) server or a virtual machine on the cloud if you pop that instance/server generally speaking you only have access to that server. Yeh, you might find a db config with connection details if you landed on say a web app host but in general you still have to work to start popping the next N servers. That's not the case when you are running in k8s and the last container breakout was just announced ~1 month ago: https://github.com/opencontainers/runc/security/advisories/GHSA-xr7r-f8xq-vfvv https://github.com/opencontainers/runc/security/advisories/G... . At the end of the day it is simply not a security boundary. It can solve other problems but not security ones.
- runlevel1 3y ago> Yes, but we caution users to evaluate if you really need kubernetes. Chances are you don't That's an odd, perhaps presumptuous, claim to make considering this isn't even in the same orchestration/scheduling space as Kubernetes. Especially without mentioning alternatives. From later in the FAQ: > The complexity that comes with kubernetes is that it requires you to re-invent all the layers of a cloud platform that already exists. If you run a vanilla linux instance on AWS you get out of the box: networking, storage, security, routing, etc all for free. They might not like the abstractions, but to say you have to "re-invent" all those layers is reaching.
- ClumsyPilot 3y agoI believe kubernetes is a little misunderstood- kubernetes is not software, and is not an abstraction on top of cloud. It’s an attempt at creating a standard-ish API for cloud. It’s currently being implemented as an abstraction on top of existing systems, because cloud providers have to leverage what they have and because its API still lacks all the functionality. But gradually it became a managed service that can provision databases, etc, and in another 5-10 years most cloud interactions will happen through it