11 ms·
How is Docker.io different from a normal virtual machine?
- dhaivatpandya 13y agoI recently wrote an article that covers some of this ground: http://www.sitepoint.com/docker-for-rubyists/ http://www.sitepoint.com/docker-for-rubyists/ The basic idea behind Docker is that you don't have to create another operating system in order to just separate your processes from each other. This leads to containers being much more lightweight than virtual machines but also significantly less powerful (i.e. powerful as in ability to do something, not in terms of performance) in some areas.
- jaynate 13y agoAny chance you can elaborate on: "(i.e. powerful as in ability to do something, not in terms of performance)" Do you mean smaller units of functionality which perform at good levels? For example, I wouldn't want to deploy a large, monolithic service this way?
- ihsw 13y agoThe need for containers is more narrow in scope than simply the size of them, but that they allow very simple isolation on a file-system level. It allows a very strict separation of concerns without requiring the sacrifice of resources of spinning up another VM.
- derefr 13y agoOne thing that occurs to me: containers don't get their own network stacks, so you can't use a transport-level protocol (e.g. SCTP) in a Docker "guest" if it isn't programmed into the Docker host kernel. Whereas VMs are routed to at the network level, so they can do whatever they want with the packets they receive.
- dhaivatpandya 13y agoI meant to say that VMs can do a deeper level of process isolation. They also perform complete hardware virtualization, which means you can run a completely different OS inside the VM. However, in terms of performance, VMs are not necessarily faster than containers at all tasks.
- rralian 13y agoHoly cow, the unit test case is fantastic.
- ams6110 13y agoIt is a good example, but I wonder how licensing would treat it. If I'm running hundreds of unit tests, each against a snapshot of my database, and my database is Oracle, they would likely view that as hundreds of instances which would each need a license.
- travem 13y agoThere are Oracle licensing options to do this per CPU rather than per instance. That is what many people do who run Oracle farms on vSphere do to take advantage of the consolidation to reduce overall license costs.
- olefoo 13y agoUnless your application is tied to Oracle specific extensions you should think about using postgreSQL for your dev and testing environments. They both hew pretty closely to the sql standard; and there are versions ( EnterpriseDB ) that have an explicit Oracle compatibility layer that works. And I bet it feels really good to look the Oracle salesperson in the eye and say, "We've been doing most of our dev work on Postgres lately."
- pjmlp 13y agoPart of Team Foundation Server for quite some time now. With Team Foundation Server you can set up a build that ramps up Hyper-V instances with build results. Sure it is all Microsoft stuff, but the concept is nothing new.
- iso-8859-1 13y agobut aren't Hyper-V instances way more heavyweight?
- 13y ago
- csense 13y agoI've been having trouble figuring out the value-add of using Docker over Ubuntu's built-in LXC functionality [1]. [1] https://help.ubuntu.com/12.04/serverguide/lxc.html https://help.ubuntu.com/12.04/serverguide/lxc.html
- shykes 13y agoHere's another Stack Overflow question which addresses that exact question: http://stackoverflow.com/questions/17989306/what-does-docker-add-to-just-plain-lxc http://stackoverflow.com/questions/17989306/what-does-docker...
- deleted 13y ago[deleted]
- jaytaylor 13y agoI also found myself asking this same question, and after careful consideration I ended up choosing LXC over Docker, and here are some reasons why: - LXC works fine on it's own. - Docker has it's own bugs, so you get all of the Docker bugs in addition to potential LXC bugs. - IPTables routing for containers to the outside world isn't that hard to manage. - LXC is simple and straightforward, and by comparison Docker is a convoluted confusing mess of additional layers of complexity. - LXC is already used in many real-world applications for operational software everyday. If you want to know anything else about real-world usage of LXC, please feel free to contact me (jay at jaytaylor com), or check out my relevant project: ShipBuilder [1]. [1] https://github.com/sendhub/shipbuilder https://github.com/sendhub/shipbuilder
- pestaa 13y agoLooks like ShipBuilder has overlap with Docker, if not a direct competitor. A disclaimer wouldn't have hurt in my opinion.
- jaytaylor 13y agoI don't follow. ShipBuilder uses LXC and is a complete open-source self-hosted PaaS; a Heroku-clone. How is it a Docker competitor? I cite it merely as an example of the sorts of cool things which are possible with LXC.
- bobf 13y agoDocker doesn't add a whole lot over what basic Linux containers (lxc and vserver) have offered for years. Having said that, the main benefit to Docker is a change in viewpoint from "virtual machine" to "application". Docker aims to make applications portably deployable to any Docker-machine. Since Docker uses lxc (aka Linux containers), it helps to understand a little how containers are different from other virtualization. Conceptually, they are similar to Linux's chroots or FreeBSD's jails, which offer process isolation. Basically, they work with a lightweight virtual machine instead of a single process. Containers have lower overhead - they are virtualizing on the operating system level. Other virtualization technologies like Xen and KVM work on the CPU level, and provide a fully virtualized hardware setup to the virtual machine[s].
- seiji 13y agoContainers are not virtual. Containers aren't emulating anything or translating anything. They let your partition out system and network resources as you see fit (or to protect users from abusing each other) without running kernels within kernels and other performance killing hokum.
- seldo 13y agoIndeed. One way you can use Docker in production[1] is one container per machine: even when you're not using the containers to split resources, the ability to snapshot and move an application and all of its dependencies in a single, lightweight, easily deployed package is very exciting. And because there's no translation etc. happening, running a single container is pretty much identical, performance-wise, to running it directly on the machine[2]. [1] dotCloud don't actually yet recommend running Docker in production, but if you did... [2] This was part of what Mailgun (part of Rackspace) said in their presentation at the Docker workshop in SF today.
- jaytaylor 13y agoYou can actually do the same thing with LXC containers; it is trivial to rsync a snapshot or compressed archive of a snapshot to another host machine and run it there.
- general_failure 13y agoCompare this with vagrant
- evilduck 13y agoVagrant mostly just generates virtual machines (with the option of running a provisioner), so it would basically be the same comparison. Edit: I suppose you could be using Vagrant to provision VPSs and use your provisioning tool to deploy an app in one fell swoop, but most people don't reprovision a box every time they redeploy their software. Vagrant lets you build a base box, Docker is for deployment on top of that box.
- awongh 13y agoI also thought that another difference was that vagrant can also manage cpu-level (hypervisor?) VMs (as opposed to just linux containers) - one of the main use cases for vagrant would be running it on your local computer- a laptop running osx or windows for example. Correct me if I'm wrong, but you wouldn't be able to run docker on a windows laptop, b/c you're just containerizing the parent os.... I would be curious to see how this could run on osx.
- evilduck 13y agoI've ran Docker on top of Linux, powered by a Vagrant VM just fine. It's exactly what their tutorial walks you through: http://docs.docker.io/en/latest/installation/vagrant/ http://docs.docker.io/en/latest/installation/vagrant/ I don't think OSX or Windows will run linux containers ever though. Maybe something conceptually similar, but I doubt it would be "Docker".
- ams6110 13y agoSince vagrant spins up full VMs, which need to boot, etc. it's slower. Spinning up VMs with vagrant, in my experience, takes tens of seconds to minutes. Launching an docker app in a container takes a few seconds (allegedly... I've never actually tried it myself).
- yalogin 13y agoI thought docker just makes creating, deploying and managing LXC "enabled" applications easier. Do they add anything to the LXC ecosystem other than the online sharing of containers?
- seiji 13y agoDoes github add anything to git other than a multi-tennant gitweb with a prettier interface? git: worth nothing. github: worth a billion dollars.
- goldfeld 13y agoI'm sorry but git is not "worth nothing," it's just that it's a public good and doesn't belong to anyone to sell, hence it has no market value. But consider how much software companies would pay not to have git taken away from them and then consider how much they would pay not to hake github taken away[1]. Which is harder to replace? I'm betting on git. [1]: Imagine a hypothetical scenario where github had mercural as an alternative (for the case git was taken away.)
- yalogin 13y agoWhoa. I am not questioning the business model of something I am obviously not familiar with. It was more of a technical clarification/question since the topic is purely technical.
- evilduck 13y agoI'm merely an observer since Docker interests me, but I from what I gather the magic of Docker is LXC and AuFS combined.
- theatraine 13y agoI wonder how Microsoft's Drawbridge OS (http://research.microsoft.com/en-us/projects/drawbridge/ http://research.microsoft.com/en-us/projects/drawbridge/) will compare to LXC, and the Docker APIs? Currently Drawbridge looks like it's lacking adoption, and doesn't seem to be widely available. Regardless, the container model looks like it solves a lot of PaaS security issues without the overhead of VMs (Iaas).
- rdl 13y agoI really don't like giving up the isolation of modern hypervisors, particularly those with Intel virtualization extensions. Docker (and LXC) seems like a huge step backwards for security. I'm sure there are use cases, but I'd never multi-tenant with it.
- shykes 13y ago> I really don't like giving up the isolation of modern hypervisors You don't have to! Think of docker as a unit of software delivery, rather than resource allocation. It's very common to use Docker to either a) deploy only trusted containers on the same machine, or b) deploy only 1 container per machine. There are also cases where linux cgroups and namespaces are an appropriate security mechanism (usually combined with other best practices, like apparmor/grsec/selinux, network lockdown, active monitoring, running things as non-root etc.) but it's not mandatory. Here's our latest overview of container security: http://blog.docker.io/2013/08/containers-docker-how-secure-are-they/ http://blog.docker.io/2013/08/containers-docker-how-secure-a...
- mtam 13y agoHow about OS patching? If I am running hundreds of different containers and I need to patch the OS (let's say upgrade the kernel or a driver), will I affect hundreds of applications at once? If so this will be a problem for several shops. How about built-in failover? On a virtualized environment you can run a cluster and the VM will move to another host in case of failure. Does docker support that? Is that what the docker-cluster project (https://github.com/globocom/docker-cluster https://github.com/globocom/docker-cluster) is about?
- lotyrin 13y agoOS updates (updates to files inside containers) would be on a per-container basis. Kernel upgrades would affect all of the containers running under that kernel (machine or VM) at the same time. Though, if you wanted to be super cautious, you could upgrade kernel on an empty container host (quite easy if virtualized) and migrate containers to it and test them on an individual basis.
- est 13y agoI always wanted to ask a question about docker, if the local devel machine is ubuntu 12.04, I can not deploy my docker image build to a 10.04 ubuntu server, right? (Unless you run a 12.04 virtual machine or something.)
- shykes 13y agoYes you can. Docker doesn't care about the underlying distro, as long as it can run on it. You can build a container on a Red Hat host machine, and transfer it to an Ubuntu host machine - it will run just fine on both.
- wmf 13y agoBut Docker can't run on 10.04, right?
- jessaustin 13y agoIt depends on the kernel version rather than the distro version. So if the 3.8 kernel is compatible with the 10.04 distro, you'd be fine. Sorry I don't actually know if that kernel is compatible with such an old distro. I sort of doubt many people would have been interested enough to do the backport...
- shykes 13y agoI haven't tested docker on Ubuntu 10.04. But you can probably expect the following: 1) You will need to boot a 3.8+ kernel, which is definitely possible but probably not available as a 10.04 package (unless someone has backported it). 2) Docker has a few userland dependencies as well. Most of them are extremely stable (tar, iptables, ip). But the lxc userland scripts have changed a lot in the last couple years. Docker is known to work with version 0.8, and that version might not be available in Ubuntu 10.04. In short, I expect that docker will not work out of the box on a vanilla 10.04 system, but it can be made to work with a fairly small amount of customization. If you're interested in trying it out, feel free to join the #docker IRC channel on Freenode. We'll help you out!
- anoopelias 13y agoOne of the issues I found with contributing to open source is the time it takes to get a build environment up and running. Since different people face different kind of issues and projects usually lack an exhaustive documentation, I've always felt adding a light weight image of the build environment could help. I hope in future Docker or similar projects pave the way for it.
- bpierre 13y agoNot sure if you are talking about production or only development environments, but Vagrant seems to provide a good solution for that: http://www.vagrantup.com/ http://www.vagrantup.com/
- leefrank 13y agoup to I looked at the draft for $5082, I did not believe ...that...my friend was like actualey earning money in their spare time on their laptop.. there moms best frend has been doing this for less than eight months and as of now cleared the loans on their villa and purchased a new GMC. look at more info big57.CoM
- ailox 13y agoI Would love to migrate 50+ KVM VMs to LXC-Containers, but there seem to be some problems left with security[1][2]. I cant wait to get my hands on Docker, but I lack the SELinux knowledge to secure everything the 'proper' way. Is LXC (and therefore Docker) really ready for Production yet? Edit: Formatting. --- [1] http://mattoncloud.org/2012/07/16/are-lxc-containers-enough/ http://mattoncloud.org/2012/07/16/are-lxc-containers-enough/ [2] https://blog.flameeyes.eu/2010/06/lxc-and-why-it-s-not-prime-time-yet https://blog.flameeyes.eu/2010/06/lxc-and-why-it-s-not-prime...
- jaytaylor 13y agoIt depends on how you are using containers. If you control what code is run in them and who has access to the containers and their hosts, then production use should be fine as far as security goes. However, if you're trying to run something which lets untrusted people login to the containers or run arbitrary untrusted code in the containers, then I certainly wouldn't recommend doing that with containers in a production environment. One project you might like to keep an eye on is CoreOS [1]. As I understand it, their goal is to create an OS which will come configured to safely run containers. Once it is ready I would expect it will be suitable for use in a production environment. [1] http://coreos.com/ http://coreos.com/
- losethos 13y agoAre you a Jew? You have moved against God's temple. Yer fucked. God says... Virtual-Notary.Org hereby notes that on Date: Friday September 13, 2013 09:10.34 EDT (UTC-0400) a random drawing in the range [1, 100000], inclusive, based on a hardware source of true randomness, yielded the following decision. Random Value: 63372 inhabitants of Jerusalem, saying, Thus saith the LORD; Behold, I frame evil against you, and devise a device against you: return ye now every one from his evil way, and make your ways and your doings good. 18:12 And they said, There is no hope: but we will walk after our own devices, and we will every one do the imagination of his evil heart. 18:13 Therefore thus saith the LORD; Ask ye now among the heathen, who hath heard such things: the virgin of Israel hath done a very horrible thing. 18:14 Will a man leave the snow of Lebanon which cometh from the rock of the field? or shall the cold flowing waters that come from another place be forsaken? 18:15 Because my people hath forgotten me, they have burned incense to vanity, and they have caused them to stumble in their ways from the ancient paths, to walk in paths, in a way not cast up; 18:16 To make their land desolate, and a perpetual hissing; every one that passeth thereby shall be astonished, and wag his head. 18:17 I will scatter them as with an east wind before the enemy; I will shew them the back, and not the face, in the day of their calamity.
- portmanteaufu 13y agoHa! Crazy to see a question I asked 5 months ago pop up on Hacker News. The docker.io team has said that they don't consider it to be production ready [0]. Has anyone experienced any major problems? Anyone using it in production? [0] http://blog.docker.io/2013/08/getting-to-docker-1-0/ http://blog.docker.io/2013/08/getting-to-docker-1-0/
- jaytaylor 13y agoI found myself asking the same question. See my related comment: https://news.ycombinator.com/item?id=6378823 https://news.ycombinator.com/item?id=6378823
- somberinad 13y agoHow is this different from HPUX or Solaris Package managers? Asking to learn.