11 ms·
Interview with Eric Brewer
- deleted 11y ago[deleted]
- deleted 11y ago[deleted]
- zallarak 11y ago"Heroku took off for doing things with Salesforce" - This is not my impression at all.
- MCRed 11y agoI'd like a real explanation for why containers are better than unikernels. Yes, unikernals are still early, and containers are convenient, because you have all of linux there... but it seems that running several linuxes on a linux machine is a bit much. One operating system plus XEN plus several applications in unikernels seems more efficient, and more exciting. But it's the less common choice. I am guessing convenience is more important than the better solution that would ultimately be more just as convenient and more efficient if it gets enough eyeballs?
- ticviking 11y agoI strongly suspect that as time goes on we'll see that containers and uni-kernels converge.
- DannoHung 11y agoI'm completely unfamiliar with unikernels, but I just skimmed a brief description. My first question is: Do they still incur the overhead of running against a Hypervisor like common virtual machines? Also, possibly a clairification: Unless I'm misunderstanding what you mean by "running several linuxes on a linux machine", I believe you may be mistaken about the way containers work. Only one Linux is really running. And that is the Linux that the kernel comes from. The other stuff doesn't run unless you tell it to (so, no init, no daemons you don't specify, etcetera). Yeah the image size can be a little fat if you don't trim them down, but you can have a container nearly as small as your code is, if you statically compile. On the order of just a few bytes of overhead.
- mirceal 11y agounikernel basically means that you pack your application and only the lower level bits and pieces that you need to get it working. you no longer have an OS in the traditional sense.
- jacquesm 11y agoI'd like a real explanation for why containers and unikernels are better than regular run-of-the-mill applications running on dedicated servers. It's almost as if the wild west of the web isn't quite enough and we now need to add another explosion of layers-of-abstraction but this time on the server in order to pretend we have infinite hardware which then becomes it's own reason for existence rather than to simply run efficient software configured properly on properly utilized hardware. As if regular virtualization alone doesn't give enough headaches in trying to figure out why some subsystem does not perform. At this rate we'll end up shipping containers as 'apps' to the clients machines with a suitable emulator at some point. All this luxury comes at (considerable) cost and not everybody seems to be doing the math before deployment which more often than not leads to terrible efficiency. But we're technology fans, so 'oohh! shiny!'.
- DannoHung 11y agoSorry, but what costs do containers incur? From my understanding, the resource overhead should be exceedingly minimal (disk space would ostensibly be the largest drawback, if you don't spend time cutting out the fat. Personally, I see this as a tooling issue since fat containers are completely orthogonal to how a container really executes). I understand some of the situation with IO isn't perfect yet, but I haven't heard anyone suggest that it cannot be corrected.
- jacquesm 11y agoAn OS has some pretty extensive insight into the processes that it executes, a container is an OS with a single application, so containers (assuming they take basic precautions for isolation) are not going to be able to schedule with anywhere near the efficiency that multiple processes on a single OS will. I can see some (mostly potential at this point) security advantages but that's about it (and maybe those advantages will be enough to justify the performance overhead but containers are mostly treated as a silver bullet by the adherents and I'd like to see a bit more balance).
- DannoHung 11y ago
- mixmastamyk 11y ago> but it seems that running several linuxes on a linux machine is a bit much Perhaps because that's not what happens, the host runs one copy of linux, which namespaces the containers.
- sp332 11y agoIf you have a statically-linked binary you can just run it in a container. You don't need a whole OS userland in there.
- zobzu 11y ago[...] since the whole userland that you need is included in the binary (worth noting) you just dont get the debugging stuff (which is okay as long as you can choose)
- mirceal 11y agowould argue that it's not just the userland. you only have the functionality you need and your bits. for example an http server would have the http stack + your app. there is no userland, there are no drivers, just your app as the only thing that is running on the machine. your app basically merges with the "kernel"
- zobzu 11y agothe kernel has the drivers you need. the http stack needs libc or equivalent. basically its the same except statically linked, and without debug/troubleshooting tools. yes, really! it does reduce the attack surface/amount of things.
- mark_l_watson 11y agoGreat Interview! I worked as a contractor at Google in 2013 and loved their infrastructure. It was amazing to fire off a Borg job that used hundreds to thousands of servers, and the web based tools for tracking the job, fantastic logging to drill into problems, etc. And, Borg was two generations ago! Even though I am very happy doing what I am now, sometimes I literally wake up in the morning thinking about Google's infrastructure. I now use lesser but public services like AppEngine, Heroku, nitrous.io (like Google's web based IDE Cider, a bit) but it is not the same. BTW, not to be negative, but while Google is a great home for someone like Eric Brewer, it is a shame that many hundreds of future students at UC Berkeley will not have him as a professeur.
- philip1209 11y agoHow hard was it to learn these tools as a contractor? I hear that Google is more aggressively making their tools open-source to help the portability of their engineers' skills. Specifically, friends have told me that onboarding at Google is difficult because every tool is a proprietary one built on top of more proprietary systems. In addition, people who leave Google have trouble interviewing because they rely heavily on tools that are unavailable outside of Google. By beginning to contribute more to open-source, I think that it has the potential to make interviewing at and joining Google a smoother experience.
- mark_l_watson 11y agoGood question. I found onboarding at Google really fun and interesting. I took several great classes, the best being the end-to-end class that in 8 hours let you write code that used most of Google's infrastructure - that class was so awesome that I would have payed Google for that day at work :-) Also, they had code labs that are self paced modules for learning specific tech. I didn't spend much time at work doing code labs, but I could access them at home with my corporate laptop and I went through about a dozen of them at home. One other nice thing is even mentioning that you couldn't figure out something from the documentation or code labs would cause someone to jump in to help you. Also, I don't think that people leaving Google have problems getting other jobs :-) The retention rate at Google is surprising low, given the pleasant atmosphere there. People leave to go elsewhere, start their own companies, etc. I was 63 when I worked there, and although it was probably not the most awesome place I worked, it was really great. Apply for a job if you are interested, or go the easier route and get a contractor position.
- jedberg 11y agoA funny and somewhat off topic story -- back in 2003, before the Google IPO, Google was doing a recruiting event at Berkeley. They brought a few of their folks with them: their founder Larry, one of their female engineers, Marissa, and some others. They did a little talk, and during the Q&A, professor Brewer told Larry that there was an opening in the PhD program and he was welcome to it. Larry politely declined. Afterwards I asked Larry, "so, do you think you'll ever finish your PhD, either here or at Stanford?". He said, "If this Google thing doesn't work out I might, but I have a feeling it will work out ok." It amuses me that Professor Brewer is now working for Larry. :)
- bostonpete 11y agoIn 2003, Google had over a billion dollars in revenue. I suspect that answer was tongue in cheek.
- voronoff 11y agoI suspect the question was as well.
- dba7dba 11y agoIt amuses me that Professor Brewer is now working for Larry. Pretty sure Prof Brewer isn't exactly tiptoeing around Larry. He can work ANYWHERE.
- nickpsecurity 11y agoOne thing that bothers me about the article is that it shows a recurring problem: IT not knowing what it knows. The NoSQL movement didn't notice that NonStop Architecture scaled linearly to thousands of cores with strong-consistency, five 9's, and SQL support. In the mid-80's. Instead of making a low-cost knockoff, like cluster movement did for NUMA's, they ditched consistency altogether and launched NoSQL movement. Now, I see man who invented CAP theorem discuss it while referencing all kinds of NoSQL options to show us the tradeoffs. Yet, there's Google services in production and tech such as FoundationDB doing strong consistency with distributed, high throughput and availability. http://www.theregister.co.uk/2012/11/22/foundationdb_fear_of_cap_theorem/ http://www.theregister.co.uk/2012/11/22/foundationdb_fear_of... So, why aren't such techs mentioned in these discussions? I liked his explanation of the partitioning problem. Yet, he and NoSQL advocates seem unaware that numerous companies surmounted much of the problem with good design. We might turn CAP theorem into barely an issue if we can get the industry to put the amount of innovation into non-traditional, strong-consistency architectures as they did into weak-consistency architectures. There is hope: Google went from a famous, NoSQL player to inventing an amazing, strong-consistency RDBMS (F1). Let's hope more follow. https://static.googleusercontent.com/media/research.google.com/en/us/pubs/archive/41344.pdf https://static.googleusercontent.com/media/research.google.c...
- zobzu 11y agothats a pretty good comment actually. there's quite a bit of similarity. we generally tend to jump into these as "omg awesome new tech" with a very narrow view. But it also helps boosting more though-out techs (even thus it feels less efficient to go through that route first, its perhaps the only route that works with human: try, fail, try again, etc.)
- nickpsecurity 11y agoYeah we do. My only guess is it's two things: (a) our industry is horrendous at communicating previous generation's wisdom in a usable way; (b) a social phenomenon. Quick example of the first are industry pro's locking up their good advice in obscure, expensive books and cutting edge research silo'd into ACM, IEEE, etc. The other is a social thing that leads to the "network" effect. People flock to something for whatever reason. This builds a community (or network) that entices others to join. That also tend to forget about other things and reinvent the wheel. Example: much of current work in Web applications aims to solve problems already solved in client-server apps with better efficiency, security, reliability, and portability. Even Facebook went back to that model for mobile IIRC. Good luck convincing most Web technologists to switch to client-server, though. Whoever solves both these problems will create ripple effects that grow innovation at a heightened, maybe exponentially better, pace. The reason will be a combination of avoiding wasted effort plus visibility into best efforts. I got ideas on Problem 1 but the best minds need to get on Problem 2: it's a gold mine if it's solved.
- kayman 11y agoI love the idea of using containers. Due to linux popularity and google's backing, containers will be next. But FREEBSD had jails since back in the day. What's the benefit of containers over bsd jails?
- otterley 11y agoLinux has copy-on-write block devices that make it possible to efficiently layer container filesystems. FreeBSD has no such thing as far as I know; the best you can do involves hard links (correct me if I'm wrong).
- deleted 11y ago[deleted]
- bch 11y agohttps://en.wikipedia.org/wiki/UnionFS https://en.wikipedia.org/wiki/UnionFS Edit: addendum Additionally, a hardlink solution (as you point out) really doesn't sound too outrageous to me. A trivial tool to write to manage immutable things like binaries. Or is there some trouble I'm failing to see (possible)?
- otterley 11y agoAccording to the mount_unionfs(8) man page: > THIS FILE SYSTEM TYPE IS NOT YET FULLY SUPPORTED (READ: IT DOESN'T WORK) AND USING IT MAY, IN FACT, DESTROY DATA ON YOUR SYSTEM.
- bch 11y agoYou're right. My personal reference for unionfs is NetBSD, which doesn't include such a warning [0]; apparently freebsd's implementation needs some love. [0] http://netbsd.gw.com/cgi-bin/man-cgi?mount_union++NetBSD-current http://netbsd.gw.com/cgi-bin/man-cgi?mount_union++NetBSD-cur...
- tachion 11y agoYou are incorrect, FreeBSD has ZFS file system as a first class citizen and that allows all these things (and much more). Check out tools like iocage[1] that are using it in very user friendly manner. [1] https://github.com/iocage/iocage https://github.com/iocage/iocage
- andyidsinga 11y agoimo, if containers are the future ( very plausible ), then, things like Aws lambda are just as plausible if only just a bit further out. I think this is the case due to granularity of workloads and what apears to be a continuum in the workload container from metal > vm > containers > lambdas (as first class workloads). fun stuff
- TheIronYuppie 11y agoDisclaimer: I work at Google on Kubernetes True, lambda is DEFINITELY an advance, but it's more like the salmon at a buffet that includes steak and chicken. Some applications will need just the ability to run code (lambda), some will need defined environments (containers) and some will need total isolation (VMs/bare metal). You'll see a mix of all of these in every mature environment - some things do not fit. For example, it's super unlikely that you'd be able to run a trading app on Lamdba (needs 10GB/sec of direct network access & memory); similarly it'd be totally unnecessary to run a thumbnail processor on bare metal (though you could, of course).
- andyidsinga 11y agogood points but I'm not sure anything about the fundamental lambda architecture prevents it from being applied to high bandwidth or low latency uses. especially if lambda functions are orchest rated to run in the metal ...think: kernel module implements lambda, then add orchestration glue up in user land
- la6470 11y agoWith all these container talks people forget Solaris zones which were pretty advanced sort of containers in Solaris. However Sun was honest about not mentioning zones as the solution for everything. The most important problem with containerization is that due to dependence of multiple containers on the same kernel of the host or VM OS , any kind of upgrade specially the security patching is virtually impossible to do without taking full downtime.
- voidr 11y agoI have been using Amazon Web Services and other cloud platforms for over a year now, and I never really felt that VMs were the bottleneck in any way. Can someone explain to me the advantage of containers here? I know that containers are faster because they don't virtualize the hardware, however it comes at the cost of security.
- TheIronYuppie 11y agoDisclaimer: I work at Google on Kubernetes & containers. I tried to address it here: https://news.ycombinator.com/item?id=9570639 https://news.ycombinator.com/item?id=9570639 But in summary, the basic thing that containerized software offers is inherent portability and simple composition. VMs aren't going anywhere; running a container on top of them just makes everything more powerful.
- jesstaa 11y agoContainers, like virtual machines before them, aren't the future of computing. They're how we manage legacy apps. The future of computing is not this horrible kludge.
- vidarh 11y agoNo matter what, we will want more isolation, not less. But I sort-of agree in that we're just starting to make the transition from whole-os VMs to app containers, with a rare few going further. But cgroup/jails type isolation is lightweight enough that we can easily apply it at a much finer-grained level.
- TheIronYuppie 11y agoDisclaimer: I work at Google on Kubernetes The problem containers are trying to solve is not isolation of environments (though, that's a tremendously good outcome). The problem is how do you develop microservices that are self-contained, easily composable and inherently portable. It doesn't matter if you're running on Java 1.1 on AIX 3.0 or Node on Ubuntu 26, if I have a ball of computing providing a service in Dubai, and want to move it to Ireland to take advantage of computing space that just opened up, containers make that trivial (and about a million other scenarios).
- digitalzombie 11y agoI saw a kubernete talk at a local meetup. Google have 40 programmers dedicated to that project. It's still very beta btw all programmed in Go. There's also mesos and I think you can use both in tandem since they're targeting a different thing. Anyway if anybody is doing or thinking about containers check Kubernete and Mesos out. Also of course docker and rocket. Kubernete officially support docker and will be supporting rocket. There are also article about how rump kernel are better than containers. Just fyi.
- dunkelheit 11y agoCan someone explain or provide an educated guess about what is the google's strategy with kubernetes here? Surely containers are hot now and it is nice to have a stake in the game but borg has been one of their key competitive advantages. What is the profit in making an open-source alternative?
- inquisitiveio 11y agoI have been wondering the same thing. I suppose it's partly because it was only going to be a competitive advantage as long as as containers where not commoditized which seems to be the direction its now heading.