4 ms·
I had no idea what a control group is, so here is a short summary for others in my position: - cgroups (abbreviated from control groups) is a Linux kernel feat
by maggit 12y ago
I had no idea what a control group is, so here is a short summary for others in my position:
- cgroups (abbreviated from control groups) is a Linux kernel feature to limit, account, and isolate resource usage (CPU, memory, disk I/O, etc.) of process groups.
- Various projects are using cgroups as their basis, including Docker
http://en.wikipedia.org/wiki/Cgroups http://en.wikipedia.org/wiki/Cgroups
- avz 12y agoAlso: https://www.kernel.org/doc/Documentation/cgroups/cgroups.txt https://www.kernel.org/doc/Documentation/cgroups/cgroups.txt
- jpgvm 12y agoThis is probably the best resource for namespaces if you are also interested in those: http://lwn.net/Articles/531114/ http://lwn.net/Articles/531114/
- jpgvm 12y agoTechnically isolation is actually implemented in what we call Linux namespaces (which are analogous to Solaris Zones/BSD jails etc) and are not part of the cgroups infrastructure per se. The definition above comes from wikipedia and is incorrect in my opinion. Cgroups only really encompasses accounting, limits and some other cool functionality (like freezer, which allows you to atomically pause groups of processes). Namespaces on the other hand implement namespacing of all the crucial resources like UIDs, PIDs, devices (including network adapters), routing tables etc and form the basis of the "security" part of a container. It just so happens that people tend to think of them as one thing as their only interaction with them so far has been LXC/Docker/Heroku/Borg when in reality they are much richer systems that can be used to do all sorts of cool things.
- menage 12y agoBeing able to ensure that your important job gets a certain fraction of the CPU, memory or I/O resources regardless of what other jobs on the same machine are doing is very much an instance of 'resource isolation' - in terms of usage, rather than access/naming which is the kind of isolation that namespaces provide. CGroups can theoretically provide resource access isolation too, e.g. the device security cgroup subsystem, but it's not really the ideal model for it. FWIW, Borg (at least as of a few years ago - it's possible that it's changed now) hardly uses any resource access isolation - apart from a bit of bind-mount trickery to provide filesystem isolation, it's primarily concerned with resource usage isolation, and jobs are very aware that they're running on the same kernel with potentially many other jobs.