6 ms·
Show HN: Convert your Containerfile to a bootable OS
- falcor84 2y agoOn a tangential note, does anyone here remember Erlang on Xen [0]? It's a project from a decade ago, allowing you to package your code to run directly on the hypervisor without an OS. I really liked that approach and am wondering why it seems to have hit a dead end. [0] https://github.com/cloudozer/ling https://github.com/cloudozer/ling
- deleted 2y ago[deleted]
- mikef25 2y agohttps://github.com/linka-cloud/d2vm https://github.com/linka-cloud/d2vm does a similar thing an I‘ve used it successfully
- notamy 2y agoSomewhat-related, a project of mine (https://github.com/queer/peckish https://github.com/queer/peckish) allows for converting docker images to ext4 images, among other formats. A way to turn it straight to a bootable image is very cool though, I’ll have to give this a try later!
- nubinetwork 2y agoWhat about the other way around? Writing my own docker(-compose)files by hand kindof stinks.
- MenhirMike 2y agoSo, a bit like docker container commit but actually good?
- ahepp 2y agoYou can use the rootfs generated by a tool such as buildroot or yocto as a container layer.
- koito17 2y agoSomething like this is what I had desired when briefly experimenting with Fedora CoreOS and having to build layered images for ZFS support. I was new to CoreOS and was stuck right after I finished building an OCI image. Eventually I learned that the only way forward was to boot with a base image, then layer what I had built and run `rpm-ostree commit`. I wonder if this project would've served my use case. The OCI images you build when layering FCOS images all build atop the base FCOS image. So I would expect them to be "bootable" in some sense.
- jcastro 2y agouCore does this if you wanna check it out: https://github.com/ublue-os/ucore https://github.com/ublue-os/ucore
- monstajoe 2y agoThat's cool! Can you use it to display react apps on the screen though?
- OJFord 2y agoIf that's what your entrypoint sets up, yeah?
- monstajoe 2y agoI meant physically render the full website on the screen.
- OJFord 2y agoI know. This turns a Linux container into a bootable Linux OS. If your container starts a GUI environment and launches a browser pointed to your React app I see no reason to think that wouldn't work after making it bootable. It sounds like you're expecting it to be some kind of OS of its own though, that it would automatically drop straight in to code you give it somehow. That's not what it is.
- eichin 2y agoIf you're looking to build a bootable kiosk sort of thing, the old-school way was just a service file that ran xinit -- chromium --kiosk http://localhost/whatever http://localhost/whatever. (no idea how to express that in wayland.) It's not locked down as much as you'd hope and there are a lot of details, but starting with that and letting the error messages guide your way is a workable approach...
- allyant 2y agoI wonder as an experiment if you are able to run an instance of the parent OS via mounting /:/ and using an image that matches the parent OS…
- FireInsight 2y agoThe 'bootable container' / 'native container' space is getting really exiting, even (and especially) for desktop usecases. Atomic Fedora has had support for so called Ostree Native Containers for a while now, and that will eventually adapt `bootc` as the base layer for building and booting containers (but as of now it's not totally ready yet). VanillaOS is also working on similar things but I don't think it'll use `bootc`. Some awesome community projects have also been born out of this space: - https://universal-blue.org/ https://universal-blue.org/ provides some neat Fedora images, which have one of the best Nvidia driver experiences on Linux IME, and are over all solid and dependable - https://blue-build.org/ https://blue-build.org/ makes it pretty easy to build images like Universal Blue's for personal use The best part here is really the composability; you can take a solid atomic Linux base, add whatever you like, and ship it over the air to client computers with container registries. All clients see is a diff every day, which they pull and 'apply' to be used after the next boot.
- themgt 2y agoThere's also Elemental which is SUSE-oriented but distro agnostic https://github.com/rancher/elemental-toolkit https://github.com/rancher/elemental-toolkit I've been hoping NixOS moves in this direction over time, the distribution/rollout aspect seems under-baked currently.
- hhh 2y agoWhat's the best way to start with Elemental today? I haven't been able to grasp a start point, unlike RKE/Rancher which is pretty easy to onboard.
- themgt 2y agoIt depends what you're trying to do, but I was essentially following this guide: https://rancher.github.io/elemental-toolkit/docs/examples/embedded_images/ https://rancher.github.io/elemental-toolkit/docs/examples/em... updated to ghcr.io/rancher/elemental-toolkit/elemental-cli:v1.3.0 / registry.suse.com/suse/sle-micro-rancher/5.4 The whole project is in major flux now though, with v1.3 -> v2.1 being pre-release and docs haven't been updated, so I'm waiting for dust to settle before picking it back up. But basically `docker build` -> `elemental build-disk` -> qcow2/iso -> deploy / `elemental upgrade` update via OCI registry, or deploy vanilla image and then just update that via registry.
- jbverschoor 2y agoNice! Same-same-but-different shameless plug: https://github.com/jrz/container-shell https://github.com/jrz/container-shell boot a shell into your container and mount the working/project dir
- FireInsight 2y agoThat seems more like Distrobox to me(?) https://distrobox.it/ https://distrobox.it/
- jbverschoor 2y agoInteresting. Similar way of thinking. Key differences: I like the chrootyness instead of having the complete filesystem available (similar to what orbstack does). I'll have a look this weekend.
- anthk 2y agoGuix did that too, right?
- satertek 2y agoKeeping an eye on this. I've been wanting something like this to manage an air-gapped system. I don't want to worry about keeping on offline apt repository (or what have you) synced, I just want to boot a full new image and mount my home folder.
- brirec 2y agoI haven’t set it up myself yet, but at least in theory all you need to do is build and push (and sign) images to a self-hosted container registry, and then have your air-gapped systems update from that machine. I have used GitHub Actions and GitHub Container Registry the way Bluefin uses it to build and push images there. You might be able to even just mirror them from there if you want to punch a hole in your air gap.
- cogman10 2y agoReally interesting. I'm guessing this would be used when you want a container experience with VM level security. Would hopefully make it easier to create bespoke VM images to do fun stuff.
- tamimio 2y agoLooks interesting, any Proxmox support or tests were done? I would love to see how this compares to a docker in LXC and having one for each container.
- mathfailure 2y agoI don't understand how it works. Did I guess it right that it basically processes Containerfile and instead of producing a .tar artifact (which is what container images usually are) it produces .qcow2/.ami/.raw/.iso/.vmdk file which in case of .qcow2/.raw/.vmdk can be used by a virtualization software to start up a VM with a disk mounted from that file? Will the changes made inside a session with such a VM persist? or will they get lost (which is the default behavior with containers)? Container's filesystem may be as narrow as a single binary file, surely a VM with such a filesystem won't be able to boot - where will it take the OS (with the kernel, drivers and other stuff) from?
- remram 2y agoI think you are supposed to use their base images.
- vmfunction 2y agoso it is only bootc-enabled container https://centos.github.io/centos-bootc/ https://centos.github.io/centos-bootc/ So only CentOS? Would it be possible to run that with firecracker? If that is the case, then wouldn't it be better to just run a Docker/container file in a firecracker vm. It will be more isolation, and easier scripting and networking?
- brirec 2y agoI’m not sure how exactly you turn a Dockerfile into a Firecracker VM, but I suppose this is an alternative method to that. Surely you can even boot a bootc-enabled container image like this on a Firecracker MicroVM.
- rhatdan 2y agoregistry.redhat.io/rhel9/rhel-bootc registry.redhat.io/rhel9/rhel-bootc quay.io/centos-bootc/centos-bootc Are currently available, but since this is an open source project, we look forward to other distros creating bootc images.
- mikepurvis 2y agoI build Ubuntu OVAs offline using debootstrap->systemd-nspawn. All you really need to do is install the kernel and initramfs packages, then mount the fs to install grub to it.
- cbxyp 2y agoAnd we've come full circle almost.
- dmvdoug 2y ago“We shall not cease from exploration/And the end of all our exploring/Will be to arrive where we started/And know the place for the first time.”
- theanonymousone 2y agoIs it something similar to d2vm(https://github.com/linka-cloud/d2vm https://github.com/linka-cloud/d2vm)? It would be nice to have my "own" Linux distro.
- buildbot 2y agoExcellent, now I can write docker files to run containers as VMs on FreeBSD!
- symlinkk 2y agoWhat is a practical example of how this is useful?
- fathyb 2y agoMakes it easy to migrate from containers to VMs using the same tooling.
- sunshine-o 2y agoI understand this is similar to alpine-make-vm-image [0] or nixos-generators [1] By the way, is there a way to create minimal NixOS VMs without systemd? - [0] https://github.com/alpinelinux/alpine-make-vm-image https://github.com/alpinelinux/alpine-make-vm-image - [1] https://github.com/nix-community/nixos-generators https://github.com/nix-community/nixos-generators
- turboponyy 2y ago> By the way, is there a way to create minimal NixOS VMs without systemd? No, systemd is a hard dependency for NixOS.