7 ms·
Docker doesn't add a whole lot over what basic Linux containers (lxc and vserver) have offered for years. Having said that, the main benefit to Docker is a chan
by bobf 13y ago
Docker doesn't add a whole lot over what basic Linux containers (lxc and vserver) have offered for years. Having said that, the main benefit to Docker is a change in viewpoint from "virtual machine" to "application". Docker aims to make applications portably deployable to any Docker-machine. Since Docker uses lxc (aka Linux containers), it helps to understand a little how containers are different from other virtualization.
Conceptually, they are similar to Linux's chroots or FreeBSD's jails, which offer process isolation. Basically, they work with a lightweight virtual machine instead of a single process. Containers have lower overhead - they are virtualizing on the operating system level. Other virtualization technologies like Xen and KVM work on the CPU level, and provide a fully virtualized hardware setup to the virtual machine[s].
- seiji 13y agoContainers are not virtual. Containers aren't emulating anything or translating anything. They let your partition out system and network resources as you see fit (or to protect users from abusing each other) without running kernels within kernels and other performance killing hokum.
- seldo 13y agoIndeed. One way you can use Docker in production[1] is one container per machine: even when you're not using the containers to split resources, the ability to snapshot and move an application and all of its dependencies in a single, lightweight, easily deployed package is very exciting. And because there's no translation etc. happening, running a single container is pretty much identical, performance-wise, to running it directly on the machine[2]. [1] dotCloud don't actually yet recommend running Docker in production, but if you did... [2] This was part of what Mailgun (part of Rackspace) said in their presentation at the Docker workshop in SF today.
- jaytaylor 13y agoYou can actually do the same thing with LXC containers; it is trivial to rsync a snapshot or compressed archive of a snapshot to another host machine and run it there.
- pestaa 13y agoWhy the downvote? Simple tools always work well. If you want process isolation on Linux, LXC + rsync might as well be the simplest route.
- jaytaylor 13y agoAnything not pro-docker usually gets downvoted by shykes and his ring of cronies.
- aegiso 13y agoThere's definitely hype behind Docker, but this is a ridiculous accusation.
- jaytaylor 13y agoPeople do crazy things for money.
- pekk 13y agoYou have rationalized away the people who disagree with you by making them into a conspiracy. I don't know about said ring of cronies, but I guarantee that many downvoters are not associated.
- jaytaylor 13y agoMy claim seems validated. Just look at both of my comments in this thread; they've both been downvoted deep into the negatives.
- kbutler 13y agoMy downvotes because the comments were disparaging and lacked proof. My only Docker affiliation is reading a bit about it lately. I had to search the page to see who shykes is.
- mritun 13y agoDocker is based on LXC containers. It bundles it's own management layer that replaces the "rsync" solution you propose.
- darklajid 13y agoRegarding your first footnote: Is there an explanation why 'in production' is actively discouraged? Is that a limitation of the underlying lxc stuff? I ask, because the interesting parts of docker _for me_ seem to be focused on the setup, deployment - and not the runtime. So if I create a working image and want to use that in production, wouldn't docker become passive as soon as I run that thing? What's the danger here?
- pekk 13y agoI expect the danger is that someone will lose money and blame the developers for as-yet unforeseen issues which can only be smoked out after a few years of heavy use. But a specific danger would be interesting to hear.
- shykes 13y agoDocker maintainer here. That's basically it. There's no specific danger that we're worried about - just engineering best practices. As long as we're not comfortable operating Docker at large scale ourselves (we run quite a lot of containers in production at dotCloud), we won't recommend that others do it.
- contingencies 13y agoContainers are not virtual. They belong to a category of virtualization known as 'container-based virtualization' which implements virtualized perspectives of the system within the host kernel, effectively dividing the system in to multiple systems (from the perspective of the affected processes). That is unquestionably virtualization. I believe a statement closer to what you were looking to express was containers are not running under a hypervisor. LXC still creates a performance impact, depending upon which options are selected, with particular note for the various memory accounting options. However, that impact is far lower than a hypervisor. In addition, startup times are vastly reduced since the kernel bootstrap and hardware detection concerns are rendered unnecessary.
- lrem 13y agoI don't know about LXC, but back in the day, the impact of linux-vserver was within bounds of measurement error. Since then I have been using it reflexively on any server I touch, even if it ends with only one container.
- FreeBSD-user 13y agoTo be honest I've never worked out why Docker gets so much press. If you use the Ezjail utility to configure and manage FreeBSD jails you have been able to do most of the things Docker does for years (stacked fs using unionfs, templates/flavours, snapshots, export/import etc) and this seems like a much simpler and more stable solution. The networking stuff is also easy using pf.
- danieldk 13y agoThere's also Solaris Containers, which leverages ZFS snapshots, etc.: http://en.wikipedia.org/wiki/Solaris_Containers http://en.wikipedia.org/wiki/Solaris_Containers Of course, Solaris is even more despised by some people since they changed hands. I think Docker appeals more to people, because: - It's on Linux, which is more popular than FreeBSD or Solaris. - It's very easy to set up and configure. - Integration with Puppet et al. - The have great marketing :).
- justincormack 13y agoBecause almost no one around here uses FreeBSD it seems.
- jmspring 13y agoSome of us do, when appropriate. Docker took a technology known to many that setup/admin/manage machines, added some fluff, made things simpler, and marketed the idea. In a crowd that might spend more time thinking about nodejs and callbacks vs promises or how easily one can tip a rails app up on heroku, existing systems tools for things like jails/virtualization may either be over looked or not a concern. For every docker, there are people (of which I may be one) that think , "big deal, it is just x". Meanwhile that thing is getting traction and popularity. It might not last, but it is around and making noise now.
- mtam 13y agoYes, Docker builds on top Linux containers but they seem to be releasing some neat features that make containers easier to use, manage, and reuse. For example: The docker-cluster project, https://github.com/globocom/docker-cluster https://github.com/globocom/docker-cluster seems very interesting as it might allow you to abstract the host with a cluster/logical group. Having this abstraction is key if you are running docker on a non-virtualized (bare metal) host because it provides some level of fault-tolerance against hardware failures. Can you do that with Linux Containers? Edit: I just realized that docker clusters is not being developed by the docker team
- shykes 13y agoIf you're interested in cool projects built on top of Docker, take a look at http://github.com/dockerforge http://github.com/dockerforge, it has a nice list.
- passfree 13y agoYou can also have a look at VxDocker https://github.com/websecurify/node-vxdocker https://github.com/websecurify/node-vxdocker
- rdtsc 13y agoExactly a point that is important to make is that LXC VMs are bound to same kernel and architecture as host machine. But then the "fix" is to have a farm of host machines of all supported configuration of kernel and architecture (mostly just Linux distributions). Migration and load balancing will be more rigid as can't move any machine to any host. Some hosts What is not doable it seems is say supporting windows guests, older Linux kernels etc. That argues for a hybrid approach with a controller API on top that uses KVMs or Xen hypervisors alongside LXC
- derefr 13y agoWhy are you building your applications to need specific kernels/distributions? That sort of goes against the spirit of 12-factor apps -- if a particular kernel/OS is part of the app, put it in the app. (Thus, use a full VM.) Docker is for when that isn't the case.
- rdtsc 13y agoWell because for one it was tested and developed on one distribution. Because one might have chosen to use system level packaging instead of copying code to /var/local or /opt. So it is taking advantage of transactional updates to the system, transitive dependencies, pre-post install scripts. The downside it being tied to a packaging system. Also certifications. Government agencies for example will accept only certain OS-es have been certified. Sometimes it is simply because there are features on some distribution or kernels that aren't in others.
- derefr 13y agoBasically, what you're saying is, Docker sucks at being a foreign porting target for things developed for some other system. Well, everything sucks at being a foreign porting target. Don't do that. Test and develop your app using Docker. Install your app into the container using Docker. These are the things Docker is for--it's a development aid, not some performance-boosting alternative to virtualization. You have to integrate it into your app's workflow; you can't just tack it on as some final "and then we also generate a Docker container version of our app" step at the end, or you lose every advantage Docker gives you. Docker is made to, basically, develop apps the same way you develop them when using a PaaS like Heroku (or, more specifically, a PaaS like Dotcloud): have a frozen base+runtime image; compose a "slug" consisting of exactly the stuff in your build/ directory and layer it on top; and tell the target host to launch it. To upgrade, create a new slug, and rolling-restart your old instances into new instances.