Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
rmolina
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
5 ms
·
1.
▲
by
rmolina
4y ago
Appreciate your comment lmarcos! Yes, the above instruction runs on macos too as long as you have docker-desktop installed.
2.
▲
by
rmolina
4y ago
You are probably referring to Sysbox ( https://github.com/nestybox/sysbox ), which I believe will meet your requirements (systemd, inner containers, security, etc). Btw, Sysbox is already supported in Docker-Desktop (bus
3.
▲
by
rmolina
6y ago
Thanks a lot Peter!
4.
▲
by
rmolina
6y ago
Right, that will work. I fully agree that Sysbox use-cases extend beyond docker-in-docker and k8s-in-docker. These, docker and k8s, were just the first two system 'apps' that we decided to support, but Sysbox can grow to support
5.
▲
by
rmolina
6y ago
We are actively working on this one as @ctalledo mentioned. Please ping us offline if want more details.
6.
▲
by
rmolina
6y ago
Thanks!
7.
▲
by
rmolina
6y ago
Please see our response to a similar question below. Hope that helps. Thanks. "The main difference is that Sysbox is OCI-based, so it works with Docker/containerd and hopefully K8s soon (we are working on the latter). Also, correc
8.
▲
by
rmolina
6y ago
Thank you. Please reach out to us through email/slack. Would love to hear more.
9.
▲
by
rmolina
6y ago
Didn't know that. But it makes sense given that podman already supports it. Btw, i did a quick search but couldn't find anything on this (docker's systemd support in rhel). If you happen to know where to find these patches, p
10.
▲
by
rmolina
6y ago
Thanks @sanketdasgupta for reporting the issue and @asadlionpk for the explanation. Nestybox's github account is an organization now.
11.
▲
by
rmolina
6y ago
Thanks @geofft, you made a lot of great points. I don't think rootless approach is fully aligned with what we're doing right now. True, we both rely on user-namespaces, and we both emphasize the security angle, but our goal is to
12.
▲
by
rmolina
6y ago
Interesting. Thanks @jdoss!
13.
▲
by
rmolina
6y ago
We haven't had enough cycles to look at Podman in details (yet), but my understanding is that Podman and Docker serve similar purposes: they are high-level runtimes. (i'm obviating important nuances though and i'm not podman
14.
▲
by
rmolina
6y ago
As @wh33zle mentioned, CI/CD is an obvious use-case. Development environments is another one (pls see the other question i just answered on this topic). But i also see 'production' scenarios. Think about having a reverse-prox
15.
▲
by
rmolina
6y ago
Absolutely, that's one of Sysbox's main use-cases, we usually refer to it as 'docker sandboxes'. As you mentioned, the idea is to have your entire dev environment within your fully-customized container, which would allow
16.
▲
by
rmolina
6y ago
I see. Will look into that right away. Thanks!
17.
▲
by
rmolina
6y ago
Thanks for the kind words!
18.
▲
by
rmolina
6y ago
Thanks! We are out of the critical path, meaning we only emulate interactions with procfs / sysfs, and we only intercept mount syscalls at the moment, so we don't see any tangible performance hit. Having said that, we haven't
19.
▲
by
rmolina
6y ago
Yes. Having said that, we have certain limitations at the moment (e.g. we don't run all cni's), but we are not relying on priv containers as i believe is the case for existing K8s-in-docker solutions (pls correct me if i'm wr
20.
▲
by
rmolina
6y ago
Sorry, not sure i got that. Can you please elaborate?
21.
▲
by
rmolina
6y ago
Got it, thanks for the explanation. I clearly see the use-case, just need to review cgroup specs (specifically cpuset) to fully understand if what you mention is already supported (which i believe it is).
22.
▲
by
rmolina
6y ago
Thanks! Both of your suggestions sound very interesting. I personally like the idea of creating large network topologies with a very few outer containers: the real mesh would be at L2/L3 levels. You would launch your large topo with ju
23.
▲
by
rmolina
6y ago
Right, systemd uses pid 1, but it does so within the pid-namespace of the container, so each container has its own systemd. Hope it makes sense. Thanks!