Y
HN Search
Hacker News Search
new
|
comments
|
top
|
jobs
sys_call
searching PlanetScale…
1.
▲
2.
▲
3.
▲
4.
▲
5.
▲
6.
▲
2 ms
·
1.
▲
Ambient Music via Conway's Game of Life
(moishelettvin.com)
2 points
by
sys_call
3mo ago
|
0 comments
2.
▲
NUMA: Cores, memory, and the distance between them
(edera.dev)
140 points
by
sys_call
3mo ago
|
33 comments
3.
▲
Rendering OCI Images in Rust: Introducing Ocirender
(edera.dev)
5 points
by
sys_call
6mo ago
|
0 comments
4.
▲
by
sys_call
2y ago
We run unmodified containers in a VM guest environment, so you get the developer ergonomics of containers with the security and hardware controls of a VMM.
5.
▲
by
sys_call
2y ago
Yes, precisely. This also provides container operators with the benefits of a hypervisor, like memory ballooning, and dynamically allocating CPU and memory to workloads, improving resource utilization and the current node overprovisioning p
6.
▲
by
sys_call
2y ago
A zone is jargon for a virtual machine guest environment (an homage to Solaris Zones). Styrolite and Edera runs containers inside virtual machine guests for improved isolation and resource management.
7.
▲
by
sys_call
2y ago
gVisor runs a userspace kernel that proxies syscalls to a shared host kernel. Running an "application kernel" in userspace impacts performance because it goes through two schedulers. Virtual machine isolation is more restrictive b
8.
▲
by
sys_call
2y ago
gVisor emulates a kernel in userspace, providing some isolation but still relying on a shared host kernel. The recent Nvidia GPU container toolkit vulnerability was able to privilege escalate and container escape to the host because of a sh
9.
▲
by
sys_call
2y ago
Non-root containers still operate under a shared kernel. Non-root containers that run under a vulnerable kernel can lead to privilege escalation and container escapes. Styrolite is a container runtime engine that runs containers in a virtua
10.
▲
by
sys_call
6y ago
Also https://ebpf.io/