4 ms·
why not just use docker.io? what are the differences between zerovm, docker, and warden?
by epynonymous 13y ago
why not just use docker.io? what are the differences between zerovm, docker, and warden?
- wmf 13y agoI found the architecture page helpful in understanding what this thing really is: http://zerovm.org/wiki/Architecture http://zerovm.org/wiki/Architecture
- amalag 13y agoWhat does an instance look like. These are very lightweight instances of what?
- pkconstantine 13y agoIt looks like hardened *nix process. It has no access to anything it's not permitted to access. And it has no notion of network, time or machine it's running on, although it can communicate with other instances (even on remote machines) via ipc. It can be suspended, resumed, relocated and so on without it ever noticing.
- amalag 13y agoThank you. When you instantiate a zerovm instance you give it the associated code as well? And which IPC method can it use? Is zerovm the library you use, is there such a thing as a separate zerovm instance, or is it just the way we are used to talking about virtualization?
- krakensden 13y agoYou give it an x86 (or ARM) binary to execute. NaCL is also working on an LLVM version, that would get compiled to the specific machine at runtime. IPC is super limited: https://github.com/zerovm/zerovm/blob/master/doc/api.txt https://github.com/zerovm/zerovm/blob/master/doc/api.txt You get nothing but /dev/stdin, /dev/stdout, and /dev/stderr by default. You can optionally make other resources (network, files) available, through a similar api.
- pkconstantine 13y agoWhen we instantiate we give zerovm an executable image (a file) and any other files this executable will need (can be arranged in a sort of "VM image" which is a regular tar file). Sessions (instances) can communicate by unix pipes. Yes we have notion of "instance" it is a running zerovm process. Each session runs in a separate process.
- jauer 13y agoI'd compare ZeroVM to Manta ( http://www.joyent.com/products/manta http://www.joyent.com/products/manta ) instead of Docker & Warden. AFAIK the idea as is to have as light of a container as possible so you can afford to throw your app at the data instead of throwing data at the app.
- pkconstantine 13y agoThat's correct. Manta is the closest thing.
- _wmd 13y agoUnlike ZeroVM, Docker is not a security solution, it is only useful for managing administrative domains within a machine. (To preempt a massively pointless, ~20 year old conversation, Google "chroot security" and "jail security" and suchlike to understand why). On the other hand ZeroVM starts with statically verifying any code that executes adheres to a fixed protocol, and that protocol only allows invoking a small set of rigorously defined service stubs. This may sound vaguely similar to how Linux containers and the syscall interface work, but it involves orders of magnitude fewer LOC written from the outset with a robust security design in mind. Compare that to the thousands of LOC daily churn in the Linux kernel, often written by people who are usually too busy fighting with shitty hardware to care about how their driver ioctl might be accidentally exposed to UID 0 running in a container, and even if they notice, might not even care.