3 ms·
We aren't doing multi-tenant in a VM. Instead, each user/account/project has their own set of VMs implementing the cluster. My view is that the surface area f
by jbeda 12y ago
We aren't doing multi-tenant in a VM. Instead, each user/account/project has their own set of VMs implementing the cluster.
My view is that the surface area for cgroups/kernel namespaces is just too large and isn't appropriate for hostile untrusted workloads right now.
More nuanced statement on this here: http://googlecloudplatform.blogspot.com/2014/08/containers-vms-kubernetes-and-vmware.html http://googlecloudplatform.blogspot.com/2014/08/containers-v...