5 ms·
Does Kubernetes use chroot jails like Borg, or has it advanced to LXC containers? Nowadays LXC isolation seems strictly preferable.
by dcsommer 11y ago
Does Kubernetes use chroot jails like Borg, or has it advanced to LXC containers? Nowadays LXC isolation seems strictly preferable.
- jhspaybar 11y agoLXC uses chroot + other things. chroot is essentially the foundation of any containerization tool.
- zobzu 11y agoNot really- chroot provides no isolation, namespaces do. choot is the visible portion (changes root.. ie changes /mnt/blah/bleh to /) but not "the foundation" Things can in fact work isolated without chroot, too. Its just convenient.
- exacube 11y agoNote that chroot will provide containerization, but without isolation (processes can always fork out of their chroot jails). You still need things like pid namespaces etc.
- jbeda 11y agoKubernetes uses Docker (or now rkt) to do the actual containing. The focus is on scheduling and managing lots of containers. You may run O(10) containers on a single machine. When you run O(10k)+ containers in a cluster you need new tools to manage things.
- wffurr 11y agoBorg also uses cgroups, just like LXC. From the paper: "We use a Linux chroot jail as the primary security isolation mechanism between multiple tasks on the same machine… all Borg tasks run inside a Linux cgroup-based resource container."
- samkone 11y agoRemember that Borg is an old thing. At the time they probably started out with chroot jails, because cgroups weren't ready yet. But Kubernetes, Mesos use docker and cgroups(Mesos).
- KaiserPro 11y agoCgroups have been around for a long time. Wikipedia says 8 years. I think was in RHEL 6.2 possibly even 6.0
- powera 11y agocgroups were largely written by members of the Borg team.
- deleted 11y ago[deleted]