11 ms·
Microsoft announces Hyper-V Containers
- O____________O 11y agoLeveraging our deep virtualization experience, Microsoft will now offer containers with a new level of isolation previously reserved only for fully dedicated physical or virtual machines Uh. I don't understand how that sentence has any meaning. Particularly the "a new level of isolation previously reserved only for fully dedicated physical or virtual machines" bit. I mean, isn't that what a container is, a virtual machine? And if so, why is 'container' even involved here? I don't know much about the container scene. I thought they were literally just virtual machines, with presumably some standardized way of spinning them up programmatically. Maybe someone can correct me.
- andrewaylett 11y agoA container isn't just a virtual machine: a VM involves providing an abstracted machine environment in which you run a whole OS, including a fresh kernel. A Container involves starting an extra, isolated user-space with no extra kernel of machine layer.
- BinaryIdiot 11y ago> I don't know much about the container scene. I thought they were literally just virtual machines, with presumably some standardized way of spinning them up programmatically. Maybe someone can correct me. Close but containers share the same kernel. It allows them to do many things more efficiently but it's not a straight up virtual machine.
- ckozlowski 11y agoTo build on this, containerized apps have less overhead than a full on virtual machine, since the binaries aren't replicated every time. Like, de-dupe for your VMs, to use a weak analogy. However, because they all share the same kernel, you're limited to a single flavor of containers per host. So a host can provide for all windows apps, or all linux apps, but not a mix. It makes the most sense when you have a need for many separate instances of similar applications. You can fit many more containers in a given host than their full VM equivalent, but lose the complete abstraction (and therefor, flexibility), that a VM gives you.
- BinaryIdiot 11y ago> So a host can provide for all windows apps, or all linux apps, but not a mix. While this is true I feel like at some point in the future we're going to be able to mix both. I've seen some rough ideas as to how it could happen but they sounded almost impossible to pull off. Still, if we had a way to mix containers it would be absolutely amazing.
- ckozlowski 11y agoIt would be cool, but I can see a point of diminishing returns. If you kept it to say, two OS flavors or so, yeah, not bad. But the moment you go down that path, the abstraction needed to ensure both sets of binaries play correctly with the underlying hardware and still remain isolated and separate starts to eat into the overhead you were trying to save in the first place. It'd be cool to pull off, but I have to imagine that it'd be for niche applications.
- simonjgreen 11y agoFirst half of this video will get you fully up to speed https://www.joyent.com/developers/videos/docker-and-the-future-of-containers-in-production https://www.joyent.com/developers/videos/docker-and-the-futu...
- jacques_chester 11y agoI recently gave a talk about the relationships between VMs and containers: http://original.livestream.com/pivotallabs/video?clipId=pla_985030bf-bbdb-4e9d-a5d7-dbdfb777d2a0 http://original.livestream.com/pivotallabs/video?clipId=pla_...
- tdicola 11y agoLooking forward to hearing more detail about how this works in the near future. I am curious though what are the plans to orchestrate and pull together multiple containers into an application, like Kubernetes, Mesos, CoreOS, etc? Is that coming in the Win 10 timeframe?
- shykes 11y agoYes, via the Docker-native orchestration tools: Swarm [1] and Compose [2]. [1] https://docs.docker.com/swarm/ https://docs.docker.com/swarm/ [2] https://docs.docker.com/compose/ https://docs.docker.com/compose/
- CoreySanders 11y agoRight on, Solomon. Here were some of the details on Azure and Windows Server support for Swarm and Compose (and Machine): http://azure.microsoft.com/blog/2015/02/26/sunny-and-swarmy-in-azure http://azure.microsoft.com/blog/2015/02/26/sunny-and-swarmy-...
- bboreham 11y agoAm I confusing something? That looks like Linux guest support on a Windows Server host, which is rather different to the Windows Container topic of this thread.
- shykes 11y agoI think that the goal was to show that Microsoft already supports the Docker orchestration stack with its current products - and in doing so is laying the groundwork for integrating future Windows containers into that same stack.
- justinsb 11y agoMicrosoft is working on Kubernetes support for Azure (along with the Kismatic people); and so I'd bet Kubernetes on Windows itself can't be far behind this announcement.
- nickstinemates 11y agoReally happy with how this all came together. Congrats Windows team.
- sudioStudio64 11y agoREALLY looking forward to this. We've needed container style deployments on Windows forever. This is actually going to make my life better...at least this part, anyway.
- alttab 11y agoImagine what switching to linux could do for you.
- emodendroket 11y agohttp://blogs.msdn.com/b/oldnewthing/archive/2006/03/22/558007.aspx http://blogs.msdn.com/b/oldnewthing/archive/2006/03/22/55800... > In particular, if the solution begins with "First, install..." you've pretty much lost out of the gate. Solving a five-minute problem by taking a half hour to download and install a program is a net loss. In a corporate environment, adding a program to a deployment is extraordinarily expensive. You have to work with your company's legal team to make sure the licensing terms for the new program are acceptable and do not create undue risk from a legal standpoint. What is your plan of action if the new program stops working, and your company starts losing tens of thousands of dollars a day? You have to do interoperability testing to make sure the new program doesn't conflict with the other programs in the deployment. (In the non-corporate case, you still run the risk that the new program will conflict with one of your existing programs.) > Second, many of these "solutions" require that you abandon your partial solution so far and rewrite it in the new model. If you've invested years in tweaking a batch file and you just need one more thing to get that new feature working, and somebody says, "Oh, what you need to do is throw away you batch file and start over in this new language," you're unlikely to take up that suggestion.
- hueving 11y agoThe fud from Microsoft is interesting. They imply that by using open source, you can't get support for when you're company is losing money. Additionally, they imply that by using Microsoft, they will actually do something useful in this contrived situation losing thousands per day. Here's a hint, whichever solution is more complex is going to bite much harder from a downtime perspective, regardless of the underlying technology. I would much rather depend on a few line script that uses sendmail rather than a 5,000 mail client half implemented in a batch script.
- justinsb 11y agoAnyone found the link to the Github PR? Or is this just PR? ;-)
- CoreySanders 11y agoHey Justin, is this what you are looking for: https://github.com/Microsoft/docker https://github.com/Microsoft/docker. This is where the Windows team is doing the work to add Windows Server support to the Docker engine. We are working with Docker Inc. to plan the PR up, once it is ready for primetime. Note, I am an engineer in the Azure team...
- justinsb 11y agoThanks for the link - I checked out the master branch and it didn't have any real diffs on it. Which branch should I be looking at?
- taylorbrown 11y agoHi Justin, We are doing most of our working in a branch right now (https://github.com/microsoft/docker/tree/jjh-argon https://github.com/microsoft/docker/tree/jjh-argon), as we stabilize the Windows Server Container and Hyper-V Container foundation the work we are doing to develop new drivers into the docker engine will stabilize and we’ll be pushing it upstream. -Taylor, PM on Windows @taylorb_msft
- swernli 11y agohttps://github.com/docker/docker/issues/10662 https://github.com/docker/docker/issues/10662
- ckozlowski 11y agoI always thought a hypervisor on top of Windows didn't make much sense. But this, this makes a lot of sense. Looking forward to it.
- kirinan 11y agoThis will be what takes containers into the mainstream businesses. Companies may adopt docker or other instead of this, but Microsoft creating their own version of it means its a viable technology. Im more interested in the new frameworks and technologies that get adopted because of this than the fact that its in use. Traditional Java web projects that are hosted on Tomcat/JBoss don't run well inside containers but there are technologies like Node.js that lend themselves to containerization. Open source .NET is now a viable option for linux deployments, and Microsoft's new containers. It will be an interesting couple of years as this shakes out.
- lgas 11y agoCan you elaborate on, or point me to some reading on the issues with containerizing tomcat and/or jboss? This is not something I've encountered before and may become an issue for me soon. Thanks.
- tokenizerrr 11y agoIn my experience the Tomcat/JBoss tend to be a relatively large overhead, but since they can run multiple "war" files under the same overhead this is not as much a problem when running a single container for multiple applications. But when you containerize them you'd like to run one instance per application which will multiply the already significant overhead. Not sure if this is what the GP was referring to, but just my 2 cents.
- jsprogrammer 11y agoMicrosoft creating their own version means the technology is viable? I think people have been using 'the technology' for years, without any input from Microsoft. It doesn't need to be anointed by Microsoft to be 'viable'.
- kirinan 11y agoFor the tech enthusiast and the visionaries, you are correct; It is a very viable technology. However the majority of people that deploy software are rather conservative and unless they see a market leader such as Microsoft with a solution they don't deem the technology safe to use. This is well documented in a lot of literature like Crossing the Chasm but can be observed frequently if you work at a larger non-tech oriented company. Whether or not this notion is actually correct is debatable but it doesn't change the validity of it.
- justinsb 11y agoI'd be interested to hear more details of what this actually is. At the OpenStack summit a few years ago we were discussing how everything done in containers via cgroups today could also be done via KVM, for greater security. This sounds like it could be a step in that direction (?)
- deleted 11y ago[deleted]
- bydo 11y agoPardon the skepticism, but do "Hyper-V Containers" with "enhanced isolation powered by Hyper-V virtualization" sound suspiciously like, err, Hyper-V virtual machines? And "Server Nano" has a description rather reminiscent of 2008's "Server Core". Is this just about management tools? Because that's cool, too, but why the spin?
- kolencherry 11y agoFrom the TechNet Announcement: "we removed the GUI stack, 32 bit support (WOW64), MSI and a number of default Server Core components. There is no local logon or Remote Desktop support. All management is performed remotely via WMI and PowerShell. We are also adding Windows Server Roles and Features using Features on Demand and DISM. We are improving remote manageability via PowerShell with Desired State Configuration as well as remote file transfer, remote script authoring and remote debugging. We are working on a set of new Web-based management tools to replace local inbox management tools." http://blogs.technet.com/b/windowsserver/archive/2015/04/08/microsoft-announces-nano-server-for-modern-apps-and-cloud.aspx http://blogs.technet.com/b/windowsserver/archive/2015/04/08/...
- lawl 11y agoThanks for the clarification. I at first assumed they'd bring OS level virtualization, apparently I'm not the only one. But it's basically just minimal images of windows in regular VMs then... A step in the right direction but still disappointing imo. Linux and BSD are still miles ahead.
- waitwaitwhay 11y agoThat referrs to Nano, not Hyper V virtualization?
- throwaway1979 11y agoSo this is like boot2docker ... on Windows? You have a VM and you have containers inside it. This is not the same as containers on baremetal. But that is fine .. my confusion is the OS inside the VM. Is that Linux or Windows? Normally, I can run Ubuntu and Centos-based containers on my box. Can I run these as Hyper V containers? What about dot net? Can that be containerized.
- arthurfm 11y agoThere's a short video on Microsoft's Channel 9 website showing Nano Server in action [1]. [1] http://channel9.msdn.com/Blogs/Regular-IT-Guy/Quick-Nano-Server-Scale-Demo http://channel9.msdn.com/Blogs/Regular-IT-Guy/Quick-Nano-Ser...
- simonjgreen 11y agoTop it off with SSH access to PowerShell and we're all set? (Something something something dark side)
- UK-AL 11y agohttp://ss64.com/ps/enter-pssession.html http://ss64.com/ps/enter-pssession.html
- antod 11y agoYes please. And native rsync interoperability too? I've love to banish cygwin from my Windows servers. Although I'm finding the remote powershell execution from a Linux machine use case is now handled quite well by tools like Salt (via ZeroMQ to the minion) and Ansible (via WinRM). Native SSH would still be good though for tunnelling etc.
- robert_nsu 11y ago> And native rsync interoperability too? I've love to banish cygwin from my Windows servers. Hear, Hear! You and me both. I've never liked Cygwin and do my best to avoid when possible.
- brianpgordon 11y agoThis is too perfect. http://i.imgur.com/WOQGknl.png http://i.imgur.com/WOQGknl.png
- Scuds 11y agoIt'd be nice if Visual Studio tooling could let you hit F5 and your app could Compile, Deploy to an On-Desktop Container after running a dockerfile, Start Debugging from a 'remote' debugger.
- CoreySanders 11y agoGood feedback!! Something for us to look at...
- ossreality 11y agoI know for a fact people are already working on this...
- skeletonjelly 11y agoWould certainly reduce the difference between dev and live testing environments!
- chatmasta 11y agoTHE STORY OF THE CONTAINER GOLDRUSH As seen by a verbose, presumptuous 22 year old. OPEN SOURCE MOVEMENT lays foundation for containerization: - linux kernel gains mainstream adoption, becomes standardized across distributions - kernel matures to support containerization (i.e., namespacing critical OS operations) - lxc project takes advantage of kernel support, builds tooling around namespace containerization DOCKER (THEN DOTCLOUD) is first company to capitalize on power of containerization: - dotcloud demonstrates clear use case for containers, encouraging developer adoption - dotcloud releases internal infrastructure code ("moves up the value chain") for PaaS - dotcloud develops project into docker, builds existing momentum into early adoption of docker. AT THIS POINT other companies begin to emerge around Docker, e.g. CoreOS. Key facts: - Docker is an abstraction around LXC, effectively a set of convenient scripts for controlling LXC - Docker is building a platform via a package management system preloaded with their repos - Platform is a threat to new entrants, e.g. CoreOS, because they risk becoming tenants CoreOS realized the risk of the Docker platform, and also that Docker is unnecessary for many of its value-adds. Everything Docker can accomplish, raw linux containers can also accomplish. The problem is that scripting LXC is less convenient than using Docker, but Docker depends on LXC, therefore LXC featureset will always be ahead of Docker. In the developer community, there is a growing acceptance of the fact that Docker is an abstraction over LXC. CoreOS is trying to standardize the abstraction as an implementation of the "app container spec" [0]. This spec puts Docker, Rocket, and lxc-tools on level playing ground. Despite this apparent acceptance, the market continues to build tooling and platforms around Docker, instead of raw LXC containers. This announcement from Microsoft is just the latest example. If a new product wants to support containers, it needs to support Docker. Docker is benefitting from network effects even though its product is not defensible from a technical standpoint. Docker is signing deals with competing enterprises like Microsoft, Google, and Amazon, because those companies are its customers. The risk for Docker is that these big companies eventually cut Docker out of the equation. They may eventually choose to replace Docker with their own "app container runtime," with features only supported on their own platform. Docker was one of the first companies to capitalize on advantages of containers, probably because they have a seriously talented group of engineers writing their code. But the market has now woken up to these advantages, and Docker is being chased by massive companies with massive resources. I hope they can fend them off and keep the upper hand in the relationship, but unfortunately I think it far more likely that Docker will eventually be cut out of the equation or acquired by one of them. This will result in a fragmentation of container technology as each company rushes to develop their own app runtime engine. Ultimately developers will suffer as platforms divide and silo, increasing developer friction and reducing cloud market competition as users consolidate around the single platform with the most momentum. Eventually, I suspect one company will control 80% of cloud computing. [0] https://github.com/appc/spec/blob/master/SPEC.md https://github.com/appc/spec/blob/master/SPEC.md
- sgwealti 11y agoWhat filesystem backend does docker use on Windows? Doesn't it require a copy on write filesystem to be efficient?
- johngossman 11y agoWe're building a new one as part of the Windows Server Container implementation. Also doing copy-on-write registry and tightening up Job Objects: https://msdn.microsoft.com/en-us/library/windows/desktop/ms684161%28v=vs.85%29.aspx https://msdn.microsoft.com/en-us/library/windows/desktop/ms6... With any OS, containers are actually made up of several low-level components put together behind a management experience (which will include Docker).
- trentnelson 11y agoDang, COW registry is pretty neat.
- frik 11y agoIf only WindowsNext Shell/Explorer would contain a sandbox feature like Docker or Sandboxie: http://en.wikipedia.org/wiki/Sandboxie http://en.wikipedia.org/wiki/Sandboxie Many Windows application could run in its own sandbox.
- m_mueller 11y agoWill this technology allow running a POSIX kernel alongside like in a VM? Or will these Containers be limited to Windows server software?
- jacques_chester 11y agoContainerisation is a new term for OS-level virtualisation. So in a current meaning of virtualisation, no. It will not let you put a Linux container on a Windows kernel. You could run a VM on Hyper-V VMs, and presumably it will respond to the Docker API, but that just means it's a VM.
- m_mueller 11y agoI figured as much, I just wasn't sure. I figured it's possible that at some point the container host could load another kernel in case a container needs it. I'm thinking this is where VMware and Citrix should be going in the future.
- kern_dude 11y agoI have a question: if I run a bunch of usermode processes on a hyper-v container and they make system calls to interact with the kernel, will the kernel they will be interacting with be running within the container? I.e. does each Hyper-V container run a distinct Windows kernel for each contained workload? Or is there just one single and common kernel on the host and mechanisms like EPT and other virtualization hardware extensions are used to isolate user mode only?