7 ms·
Google Launches Managed Service for Running Docker Apps on Its Platform
- jbeda 12y agoMore info/docs here: https://cloud.google.com/container-engine/ https://cloud.google.com/container-engine/ I'm on the Kubernetes/GKE team and happy to answer any questions you all might have. We also all hang out on IRC at #google-containers on freenode.
- marktangotango 12y ago>>Because this new service is officially in alpha, you’ll need to apply for access and be whitelisted to use the service. It also means the service isn’t feature complete and the whole infrastructure could melt down at any minute. Not sure what the take away here is other than, this may one day be a feature. No information about pricing, support, or sla. My attitude is wait and see. Should it be otherwise? Edit: Can someone tell me why this isn't a valid question? Why the down votes?
- jbeda 12y agoThe TechCrunch article is incorrect. While it is still an early service, there is no whitelist.
- wstrange 12y agoIt's all open source (including kubernetes) - so worst case you move it to the cloud provider of your choice. Other than Docker / k8s being a little immature, I don't see a ton of risk.
- philip1209 12y agoSome google-managed base images would be helpful. The last time I checked, some of the major public docker images were still shellshock-vulnerable. Pre-installed GCE tools would be helpful. Perhaps automated environment variables about region, etc.
- 23david 12y agoWhich images are still shellshock vulnerable? Wasn't aware that was an issue if we stick to the docker-managed images.
- voltagex_ 12y agoWhich? See https://gist.github.com/voltagex/582473e3b86ee5ae4438 https://gist.github.com/voltagex/582473e3b86ee5ae4438 - I ran some tests on the three most popular (?) official base images.
- shykes 12y agoIf you have found an official Docker image that is still shellshock vulnerable, the library maintainers [1] would love to hear from you as they take that stuff quite seriously. As far as I know the entire library is fully patched. [1] https://github.com/docker-library/official-images https://github.com/docker-library/official-images
- tianon 12y agoAs one of the maintainers in question, I'd absolutely mirror this whole statement: if any of the image upstreams have an important update available that isn't applied, we're very interested in rectifying that.
- wstrange 12y agoMy biggest question on Docker / k8s: How does one control where persistent data lives and the required performance characteristics? Example: I need SSD + a certain level of availability? Is there a good strategy for managing this?
- jbeda 12y agoRight now, it isn't plumbed in but it is on the roadmap. Either (a) you have network based block device and the master/manager maps that to a machine dynamically as the container get scheduled or (b) you constrain the containers to machines that have the hardware/data you need. (b) is less than ideal but sometimes necessary. Some discussion: https://github.com/GoogleCloudPlatform/kubernetes/issues/598 https://github.com/GoogleCloudPlatform/kubernetes/issues/598
- superuser2 12y agoThis is THE open question for Docker right now. The first person to actually solve it is going to be in a pretty damn good place. Docker could make most infrastructure-level "cloud" abstraction obsolete and let people run resilient, scalable clusters on hardware pretty easily. There's CoreOS, Kubernetes, and a few others in the app-instance-scheduling space, but right now, if you want persistent data storage of any kind (block, SQL, blob, whatever) then you still need to tie things down to an individual machine or use VM-level cloud technology to acheive some semblance of fault tolerance. The inability to do persistent storage in a reasonable way is, from where I sit, the main thing keeping Docker from eating the world. When you can run Postgres in a stable/supported way in a container on my own hardware that gets scheduled around failure/crowding/etc, you no longer needs AWS, VMWare, etc. That could be huge.
- wastedhours 12y agoThis is also what's holding me back from delving into Docker more. Love the concept, and the workflow, but trying to get my head around how the persistent data storage will work is still troubling me.
- micro_cam 12y agoDo you see this being useful for analytical workloads (ie i need a bunch of cores for a short time to run a parallel job) or more focused on scaling web apps and services?
- jbeda 12y agoIt can be used as both. As we build out better resource isolation and QoS, you'll be able to run mixed workload on the same hardware/VMs and use "every part of the animal".
- lbotos 12y agoI'm kind of confused. I get that they run on the Google VMs (which need a base OS, yes?) so does this manage all of that? Can I: pick my vm size/ pick my docker image/ and go? AKA does this bring me one step closer to docker-oku-aaS?
- jbeda 12y agoEssentially that is the case. If you just want to launch a static set of containers on a specific VM, you can use our Container VM image -- https://cloud.google.com/compute/docs/containers/container_vms https://cloud.google.com/compute/docs/containers/container_v.... Kubernetes (and GKE) is a dynamic system to run across a cluster of machines.
- jff 12y agoIs it possible to run a KVM VM inside one of the containers? I have an application for launching and managing VMs and letting people spin up a Google container to try it out would be neat.
- jbeda 12y agoGCE doesn't support nested virtualization. But if you are running Kubernetes on bare metal, there is no reason you couldn't map in /dev/kvm and have k8s run VMs for you. I haven't done it though :)
- jff 12y agoOk, I've done VMs inside docker already which has been fine, was hoping GCE would let me do it on Google's systems.
- abakker 12y agoAs someone who doesn't know, why would you want to run VMs inside of a docker container? Wouldn't this have tremendous overhead relative to just running the hypervisor?
- jff 12y agoIf you use the -privileged flag, docker containers can access /dev/kvm and start low-overhead KVM instances. It's advantageous for me, because I can say "hey check out this software" and they just have to run a single docker command, compared to installing Go, apt-getting a bunch of packages, fetching our repo, compiling, etc.
- jread 12y agoWe use AWS Elastic Beanstalk for Docker deployment. Can you comment on how this is different? I see it supports multiple containers per VM - are there other significant distinguishing factors?
- jbeda 12y agoElastic Beanstalk is a VM centric management framework. Kubernetes and GKE operate at a different level. It is an API for being able to schedule and manage containers instead of VMs. At this point, k8s/GKE doesn't have an idea of an "app" any more than a VM IaaS service has an idea of an app. Moving from a VM centric view to a container centric view improves a lot of things: * Easier to create and manage images * Portability -- images can be moved between providers. Develop on your laptop with docker/k8s and deploy the exact same container image. * More transparency into compute workload. The hosting VM or cloud can see more of what is going on in the container for monitoring and logging, etc. * More efficient/higher density -- you can run more on any piece of (virtual?) hardware * More flexible resource sharing/overcommit -- as you drive density up you can get more nuanced about what workloads take get priority. Some of this stuff is still in its infancy -- complex resource models aren't fully supported in Docker yet -- but it is where things are going, at least based on Google's experience.
- 23david 12y agoGiven that this is the alpha launch of Container Engine, and the Beta launch of Autoscaling and Managed VMs, what is the anticipated timeframe for this to be ready for production workloads? I'm assuming that there'll be a beta of Container Engine in the near future, and then a stable 1.0 launch?
- jbeda 12y agoStable production ready GKE will gate on Kubernetes. Our Kubernetes roadmap is here: https://github.com/GoogleCloudPlatform/kubernetes/blob/master/docs/roadmap.md https://github.com/GoogleCloudPlatform/kubernetes/blob/maste... We are driving aggressively here. I hate to put a date on it but things are converging.
- 23david 12y agoOk that's fair, but just a rough idea would be incredibly helpful. Are we talking sometime within the next 6 months / 12 months / longer? That roadmap document doesn't really explain how the current featureset makes Kubernetes ready for an 'alpha' release on GKE.
- ossreality 12y ago100% yes.
- espeed 12y agoWith the Managed VM and Container Engine releases today, is there now a way for frontend Python GAE apps and backend Java GAE/GCE apps to share the same development server (esp datastore, taskqueue)?
- deleted 12y ago[deleted]
- roberthbailey 12y agoTech Crunch incorrectly mentions that the service requires being added to a whitelist to use. It is available for anyone to try out immediately.
- philip1209 12y agoOh interesting - you appear to be correct. You need to enable it through the APIs page then you have access.
- mh- 12y agoconfirmed I was able to do this (simply enable the API) on an existing project in the API Console
- andrewmunsell 12y agoOddly, I get a "only available for new customers" message, even after I enable the API.
- crb 12y agoThat's because the link from the GKE page is for the free Google Cloud Platform trial ($300 credit), which is only available for new customers.
- andrewmunsell 12y agoAh, that would make sense.
- deleted 12y ago[deleted]
- chx 12y agoCan we ban techcrunch please? http://googlecloudplatform.blogspot.com/2014/11/google-cloud-platform-live-introducing-container-engine-cloud-networking-and-much-more.html http://googlecloudplatform.blogspot.com/2014/11/google-cloud...
- anon1385 12y agopg has mentioned in the past that he would like to ban techcrunch, but couldn't do so because they provide so much coverage of his startups. Submissions from bullshit SV news sites is the price you pay for using a site that primarily exists as a marketing exercise. Note that 'lower quality' sites about other sections of the tech industry have been banned for years (appleinsider, winsupersite etc).
- dang 12y agoWe're unlikely to ban TechCrunch, but are happy to change urls to more substantive articles when you and other users point them out. (We changed the URL from http://techcrunch.com/2014/11/04/google-launches-managed-service-for-running-docker-based-applications-on-its-cloud-platform/?utm_source=twitterfeed&utm_medium=twitter. http://techcrunch.com/2014/11/04/google-launches-managed-ser...)
- gfodor 12y agoPretty sure we're gonna see a similar offering from AWS in a week.
- jread 12y agoAWS released PaaS docker support 7 months ago: http://aws.amazon.com/blogs/aws/aws-elastic-beanstalk-for-docker/ http://aws.amazon.com/blogs/aws/aws-elastic-beanstalk-for-do...
- ceejayoz 12y agoSomething more is coming soon, though: https://twitter.com/jeffbarr/status/529493907839533056 https://twitter.com/jeffbarr/status/529493907839533056
- deleted 12y ago[deleted]
- deleted 12y ago[deleted]
- lxcp 12y agoHi Joe, I guess you folks are not running containers from customers side-by-side in the same host. So if I scale up my cluster size while I have containers deployed, do you folks rebalance the load on the host machines on the fly (by stopping/relocating some containers) or do you rebalance the new containers?
- jbeda 12y agoCorrect -- we don't do multi-tenant on the same VM. The security just isn't there in our minds. We don't do rebalancing/rescheduling/repacking yet. Those are the types of things that we will be working on moving forward.
- deleted 12y ago[deleted]
- ossreality 12y agoI'm very surprised they're launching this given the immaturity of Kubernetes. Fuck this shithole and their shadow banning. I know I've been banned for like over a year now, but it's fucking stupid. I had one bad comment and I've been locked out of dozens of conversations about topics that I could contribute on, but no, no matter what I do, any account gets shadow banned. Meanwhile, the person I got into an argument with has burned through 3 more throwaways in the meantime.
- TheMagicHorsey 12y agoCan someone explain the difference between Apache Mesos, Apache Spark, and Kubernetes. As someone reading just announcements, and having never experimented with any of these tools, they sound like they promise the same capabilities. Is it just that they are different open source projects aiming for the same goal ... or are their goals different?
- vertex-four 12y agoApache Mesos is based on Twitter's expertise in deploying their cluster, Kubernetes on Google's. They do things in different ways. Spark seems to be in the same area as Hadoop, so not relevant to the conversation.
- 23david 12y agoYep, but there's an important difference I think... Mesos (some customizations, but largely the same as open-source Apache Mesos) IS what Twitter uses to deploy and manage their clusters. Battle-hardened at scale running diverse production workloads. With Kubernetes, we're told that it is built using architectural and philosophical principles proven to work at scale on Google's production systems. But it's a fairly clean-room built-from-scratch implementation and although developing quickly, is still immature and untested.
- hendzen 12y agoNo. Apache Mesos was originally developed at the UC Berkeley AMPLab as a research project. Twitter was a very early adopter, who subsequently hired the Mesos author/creator.
- shepardrtc 12y agoIn simple terms: Apache Mesos is a distributed system that is kind of a "bottom layer" for computations and storage (whether in-memory or on disk). Apache Spark is a distributed application that runs on top of Mesos and does computations that takes advantage of cluster computing. It can do classic MapReduce or other algorithms that you write using its API. Kubernetes is a distributed system that runs Docker in a cluster. Docker is a way to run sandboxed applications. Kubernetes can run on Mesos.
- yim 12y agothis is great news, esp. with the $100K google is giving to qualified startups!
- deweller 12y agoDoes this mean that Google feels confident in running untrusted code inside containers? Or is each container actually running in an isolated VM? It is my understanding that Docker containers are "generally" secure (https://docs.docker.com/articles/security/ https://docs.docker.com/articles/security/). But that statement isn't enough for me to use them to power a multi-user production hosting environment.
- jbeda 12y agoWe aren't doing multi-tenant in a VM. Instead, each user/account/project has their own set of VMs implementing the cluster. My view is that the surface area for cgroups/kernel namespaces is just too large and isn't appropriate for hostile untrusted workloads right now. More nuanced statement on this here: http://googlecloudplatform.blogspot.com/2014/08/containers-vms-kubernetes-and-vmware.html http://googlecloudplatform.blogspot.com/2014/08/containers-v...
- krschultz 12y agoDocker has pulled off some really impressive biz dev. I can't think of too many other things that Azure, Google Cloud, and AWS all support.
- RenegadeofFunk 12y agoStrongly agree with this. I've been interviewing for DevOps jobs and it seems like everyone thinks they need to be using Docker for some reason or another. Studying up on it has improved my interview feedback substantially.
- jchonphoenix 12y agoIf you're interested, I run a team at Docker and would love to chat :P
- omouse 12y agoI hope this have the ripple effect of allowing enterprises to feel comfortable using things like Firebase and Docker. I floated the idea of using Docker but the idea was turned down because we have no idea how it affects performance in a production environment.
- tomcart 12y agoAnyone know if there are plans for auto-resizing of replicas or clusters based on alarms, along the lines of AWS autoscaling?