6 ms·
How Container Filesystem Works: Building a Docker-Like Container from Scratch
- zoobab 1y agoWe had chroot since 1979, nobody managed to build a docker like wrapper for chroot which do not require netns?
- ronsor 1y agoChroot has significantly less isolation than Linux namespaces as used by Docker.
- miladyincontrol 1y agoThis, better yet just use systemd-nspawn. Benefits of proper containers, configuration similar to any ol systemd service, super easy to use, simple to automate builds with mkosi. The one thing people really seem to miss on them is like, contrary to popular belief you dont need a whole OS container there, minimal distroless containers work just fine with systemd-nspawn similar to as they would on docker.
- interroboink 1y agoFreeBSD has had jails since version 4 (~year 2000), fwiw. Much of the technology was there, but Docker was able to achieve a critical mass, with streamlined workflows. Perhaps as much a social phenomenon as a technical one?
- Yeroc 1y agoI think the real genius of Docker was the image packaging. The pieces were there but delivery and scripting it all wasn't easy.
- disagr 1y agoBSD jails were no harder to automate than Docker; setup many ci/cd pipelines into jails in the 00s for a variety of applications. They're way closer to the usual "Unix" tool feel too. Docker feels 100% like an attempt to get rich by engineering a monolith rather than be a few helper C tools. Docker was so annoying to learn. Fortunately with the end of ZIRP and SaaS deflation (in real user terms, not fake investment to project we still live in the 2010s heyday), software engineers are focused on engineering more than hype generation. Am excited about energy based models, capture of electromagnetic geometry of the machine as it runs programs. 60s style lexical state management systems dragged forward in time because of social momentum have little to do with engineering. Are hardly high tech in 2025.
- mikepurvis 1y agoIndeed. Even to this day, debootstrap feels a bit arcane and unapproachable, particularly relative to `docker pull ubuntu`.
- tkcranny 1y agoYeah it really was a social phenomena. Ten years ago conferences were swarmed with docker employees, swag, plenty of talks and excitement. The effort to introduce the concepts to the mainstream can’t be understated. It seems mundane now but it took a lot of grassroots effort and marketing to hit that critical mass.
- magicalhippo 1y agoI used FreeBSD on my firewall in the early 2000s, and on my NAS from around 2007 till last year. The big pain with jails for me was the tooling. There was a number of non-trivial steps needed to get a jail that could host a networked service, with a lot that could go wrong along the way. Sure a proper sysadmin would learn and internalize these steps, but as someone who just used it now and again it was a pain. Way down the line things like iocage came along, but it was fragile and not reliable when I tried it, leading to jails in weird states and such. So I gave up and moved to Linux so I could use Docker. Super easy to spin up a new service, and fairly self-documenting as you just configure everything in a script or compose file so much less to remember. Initially in a VM on Bhyve, now on bare metal. It feels a bit sad though, as jails had some nice capabilities due to the extra isolation.
- oftenwrong 1y agoDon't discount the technical innovation required to integrate existing technologies in a novel and useful way. Docker was an "off the shelf" experience unlike any other solution at the time. You could `docker run ...` and have the entire container environment delivered incrementally on demand with almost no setup required. It did have a social factor in that it was easy for people to publish their own images and share them. Docker Hub was provided as a completely free distribution service. The way they made distribution effortless was no doubt a major factor in why it took off. https://www.youtube.com/watch?v=wW9CAH9nSLs https://www.youtube.com/watch?v=wW9CAH9nSLs
- jayd16 1y agoThere was clear incremental progress. Some of it can be seen in how mobile app isolation shook out as well.
- vbezhenar 1y agoDocker is a genius idea which looks obvious in retrospect, but someone need to invent it. Docker is more than just chroot. You also need: overlay file system; OCI registry and community behind it, to create thousands of useful images. And, of course, the whole idea of creating images layer by layer and using immutable images to spawn mutable containers. I don't actually think that you need network or process isolation. In terms of isolation, chroot is enough for most practical needs. Network and process isolations are nice to have, but they are not essential.
- akdev1l 1y agonetwork isolation is very important too, that’s what lets people run 4 containers all listening on port 80 process isolation is less prominent
- mikepurvis 1y agoProcess isolation is more about load management/balancing, which is more of a production concern than a development one.
- vbezhenar 1y agoYou can bind your application to 127.0.0.2 for one container and to 127.0.0.3 for another container. Both can listen on port 80 and both can communicate with each other. And you can run another container, binding to 1.2.3.4:80 and using it as reverse-router. You can use iptables/nftables to prevent undesired connections and manually (or with some scripting) crafted /etc/hosts for named hosts to point to those loopback addresses. Or just DNS server. It's all doable. The only thing that you need is the ability to configure a target application to choose address to bind to. But any sane application have that configuration knob. Of course things are much easier with network namespaces, but you can go pretty far with host network (and I'd say it might be easier to understand and manage).
- cbluth 1y agoYou can see why people like the docker experience, you can manage to do all that in a single interface, instead of one off scripts touching a ton of little things
- spullara 1y agoSolaris Zones (follow on to Solaris Containers) was pretty amazing. https://en.wikipedia.org/wiki/Solaris_Containers https://en.wikipedia.org/wiki/Solaris_Containers
- aussieguy1234 1y agoBocker, docker in 100 lines of bash https://github.com/p8952/bocker https://github.com/p8952/bocker
- philipallstar 1y agoSome of Docker in 100 lines of bash - Linux only :-)
- aussieguy1234 1y agoLayered file systems (multiple filesystems mounted on the same mount point) used to be used for making CD's and DVD's "writeable".
- nightfly 1y ago"re"-writable
- gethly 1y agoWhenever topic of Docker inner-workings comes up, I am always reminded by this video https://www.youtube.com/watch?v=HPuvDm8IC-4 https://www.youtube.com/watch?v=HPuvDm8IC-4