Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
ctalledo
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
8 ms
·
31.
▲
by
ctalledo
6y ago
Thanks! Yes, Sysbox is using OS-virtualization techniques to augment the abstraction of the container, thereby enabling software that interacts deeply with the kernel (e.g., dockerd, k8s, etc) to run inside the container, and do so with pro
32.
▲
by
ctalledo
6y ago
Thanks! Performance wise, we've not noticed any reduction in performance compared to a regular container, mainly because Sysbox sits on some control-path operations (e.g., accesses to /proc/sys, mount syscall, etc) but is rea
33.
▲
by
ctalledo
6y ago
We also created a simple tool called kindbox that runs K8s inside system containers deployed with Docker + Sysbox. It's a simple bash script around "docker run --runtime=sysbox" commands. It does some of the same things that
34.
▲
by
ctalledo
6y ago
Yes, it's possible already to run K8s entirely inside a system container deployed with Docker + Sysbox. It's as easy as "docker run --runtime=sysbox-runc -it some-image" and running kubeadm inside to setup K8s. We also h
35.
▲
by
ctalledo
6y ago
I understand gvisor's main goal is to improve container isolation by intercepting and inspecting syscalls before they reach the kernel to reduce the attack surface. Sysbox on the other hand is meant as a way to run system software (in
36.
▲
by
ctalledo
6y ago
I've not used either, but conceptually the main difference is that those approaches use micro-VMs and thus require hardware virtualization (hypervisors). This can be a challenge if you want to run those on cloud VMs, as it would requir
37.
▲
by
ctalledo
6y ago
The main difference is that it's OCI-based, so works with Docker/containerd and hopefully K8s soon (we are working on the latter). Also, correct me if I am wrong, but I don't believe LXD runs K8s inside without privileged con
38.
▲
by
ctalledo
6y ago
IIRC, Linux supports up to 32-levels of nesting, so that's an upper bound. This means that within a system container deployed by Sysbox, you can in theory nest inner containers up to 31 levels (since one of the 32 levels is used by the
39.
▲
by
ctalledo
6y ago
That's always a possibility, and the future will tell, but Docker appears to be more focused on improving application development rather than enabling containers to run system software as we are doing. It's a risk we were willing
40.
▲
by
ctalledo
6y ago
Thanks! Regarding Sysbox EE pricing, it's something that we honestly are still trying to figure out. The reason we ask enterprises to contact us is to understand their use case and needs, so that we can derive a fair price based on thi
41.
▲
Launch HN: Nestybox (YC S20) – Containers beyond microservices
168 points
by
ctalledo
6y ago
|
111 comments