4 ms·
"VM" means it has its own kernel? Why have 2 kernels on the same machine? All processes in a proper OS are already isolated and there is no need for VM.
by codedokode 2y ago
"VM" means it has its own kernel? Why have 2 kernels on the same machine?
All processes in a proper OS are already isolated and there is no need for VM.
- Cthulhu_ 2y agoIsolated, but are they isolated enough? The article states that containers offer weaker isolation than VMs. (it doesn't quantify it though and I don't know this kind of thing offhand)
- codedokode 2y agoProcesses run in a userspace and cannot do anything without OS approval.
- akdev1l 2y agoThe kernel can be attacked and exploited. Container escape exploits are more common than VM escape exploits.
- kevincox 2y agoThe Linux kernel has far too large of an attack surface to be trusted as a hard security boundary. It is good enough to prevent mostly trusted software from accidentally interfering with each other but I would not trust it to protect me from an untrusted workload. For example GCP and AWS both have container running services. They both use hardware VMs to isolate different tenants. You will never share a kernel with another customer (I don't even think you will share one with yourself by default).
- codedokode 2y agoMaybe you need a better kernel then? For example, a microkernel.
- fhuici 2y agoI agree with the other comments. On the cloud, the VM is still the golden standard for strong (hardware-level isolation): if you deploy a container in the cloud, you can almost be sure there's a VM underneath. Given this, what we tried to do in that paper, in the LF Unikraft project (www.unikraft), and on kraft.cloud, is ensure that each VM only has the thinnest possible layer between the application and the hypervisor underneath -- strong isolation and hopefully max efficiency. We do use Dockerfiles to have users specify the app/filesystem, but then we transparently convert them to unikernels (specialized VMs) at deploy time.
- brap 2y agoEverything you said is correct, in theory. In practice, however...
- macspoofing 2y agoWho is complaining? And if containers do not offer enough of an isolation, why would you think VMs do? There are use cases where you have to have host-level isolation - for example, if you want to build a HIPAA-compliant cloud service, your customer data has to be isolated at the host level and VMs are not enough.
- nderjung 2y agoCorrect -- and you can run multiple kernels on the machine with virtualization extensions. Even Docker Desktop does this. You'd do this for _real_ isolation purposes.
- hi-v-rocknroll 2y agoIt depends on the type of v12n. Paravirtualization and similar, the answer is sort-of while hard emulation is definitely yes. There are efficiencies in memory usage because the often will share the same kernel code and userland code, which are memory pages that can be deduplicated at the hypervisor level. Read more about type-1 v12n. > All processes in a proper OS are already isolated and there is no need for VM. No. This is not how things work in reality. (Ideally, yes because hypervisors are OS "duct tape" but there is no such readily-available OS with strict resource limits and hard enforced VFS and network isolation.) Isolation, sharing, and hard limits on RAM, CPU, networking, and storage (bandwidth, block devices, and IOPS) is beyond the capabilities of every major OS. This is why VMware and similar type-1 hypervisors exist.