3 ms·
How does this relate to what I've been reading about lately with docker and "containers"?
by breakall 13y ago
How does this relate to what I've been reading about lately with docker and "containers"?
- contingencies 13y agoIn my very limited understanding (could be wrong, but suspect not significantly) docker doesn't really seem to approach this issue... the docker user base seems to almost exclusively use Ubuntu, of ~latest version only.
- shykes 13y agoDocker applies similar concepts (change management at the file and directory level, a chrootable filesystem as the unit of delivery, atomic and revertable deployments), except it applies them 1 level higher in the stack. Instead of rebooting machines into a new filesystem, docker spawns processes directly into them, using the sandboxing capabilities of the linux kernel. So you get a much more powerful and flexible deployment mechanism. But of course, you need a machine to exist in the first place, which docker isn't designed to do. So OSTree is a good companion for Docker, because you need a machine to run docker. A good workflow is probably: pack the bare minimum on a physical machine, using ostree. Then put everything else into docker containers. That's the approach of new "just enough" distros like CoreOS.
- colinwalters 13y agoRight, this is a pretty good summary (that docker is 1 level above). One fundamental difference is that OSTree has a custom serialization format for trees (inspired by git), whereas from what I can tell from the code, docker is just tar (I assume whatever the host /usr/bin/tar serializes to). For example, OSTree explicitly supports extended attributes, so it can support SELinux (and SMACK). Fedora ships a patched tar but...the tar format is a really serious mess. I would further add though that OSTree does, providing the OS is compatible with it, allow booting a separate "deployment" as a container. So for example if you have Debian in /ostree/deploy/debian/90cd266 while you're booted into /ostree/deploy/fedora/562d0a, you can easily just systemd-nspawn /ostree/deploy/debian/90cd266 and boot the same OS as a container. But the emphasis right now of OSTree is indeed on bare metal deployments, and I'd like to push hard to integrate with package systems.
- shykes 13y ago> you can easily just systemd-nspawn /ostree/deploy/debian/90cd266 and boot the same OS as a container Perhaps we should be looking at integrating ostree and docker then? :) > I'd like to push hard to integrate with package systems. How would that integration work exactly?
- colinwalters 13y ago> Perhaps we should be looking at integrating ostree and docker then? :) It might make sense for docker to be able to store containers as OSTree commits in addition to tarfiles. But I haven't used it myself. On the HTTP side, OSTree may be less efficient or more efficient than what docker does on the wire for updates; I don't know. Static deltas will help significantly. > How would that integration work exactly? This section describes it very briefly: https://people.gnome.org/~walters/ostree/doc/adapting-package-manager.html https://people.gnome.org/~walters/ostree/doc/adapting-packag... Basically this is something you can do on a build server or on a client.