TE
TechEcho
Home24h TopNewestBestAskShowJobs
GitHubTwitter
Home

TechEcho

A tech news platform built with Next.js, providing global tech news and discussions.

GitHubTwitter

Home

HomeNewestBestAskShowJobs

Resources

HackerNews APIOriginal HackerNewsNext.js

© 2025 TechEcho. All rights reserved.

macOS Containers v0.0.1

518 pointsby CiTyBearover 1 year ago

31 comments

highwaylightsover 1 year ago
<a href="https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;homebrew-formula">https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;homebrew-formula</a><p>&quot;macOS <i>native</i> containers&quot;<p>Cool, this sounds interesting.<p>&quot;Disable System Identity Protection.&quot;<p>Eesh.
评论 #37656057 未加载
评论 #37656076 未加载
评论 #37658381 未加载
评论 #37656277 未加载
评论 #37662739 未加载
评论 #37659437 未加载
评论 #37655941 未加载
评论 #37656685 未加载
评论 #37662415 未加载
评论 #37662763 未加载
评论 #37656267 未加载
评论 #37656633 未加载
评论 #37655922 未加载
AceJohnny2over 1 year ago
How does this work?<p>Fundamentally, containers are about namespace&#x2F;isolation of a bunch of OS interfaces, so file system functions, network functions, memory management, process functions, etc, can all pretend like they&#x27;re the only game in town, but crucially without having to virtualize out the kernel.<p>Does XNU have such namespacing functionality across all its interfaces?<p>Furthermore, the existing container ecosystem assumes a Linux syscall interface. [1]. Does macOS provide that? I expect not.<p>The way Docker Desktop (and podman.io) implement &quot;containers on macOS&quot; is a bit of a cop-out: they actually run a <i>Linux virtual machine</i> (using Hypervisor.framework&#x2F;hvf), and have that just provide the container environment.<p>Is that what this project is doing? But then, how could it run a macOS container?<p>[1] based on the foundation that Linux, unlike BSDs, has a stable syscall interface!
评论 #37655950 未加载
评论 #37655896 未加载
评论 #37656565 未加载
评论 #37655912 未加载
评论 #37655964 未加载
评论 #37659336 未加载
评论 #37655892 未加载
评论 #37655902 未加载
dupedover 1 year ago
I can&#x27;t help but feel like this is an X&#x2F;Y problem. Apps on MacOS shouldn&#x27;t need containerization to function.<p>I get the point of isolation for build&#x2F;test situations. But Apple provides a neat virtualization framework, and you get security + isolation + reproducibility + decent performance.<p>It seems like if you feel the need to containerize the userspace on MacOS you&#x27;re using MacOS wrong. It&#x27;s not the same thing as the Linux userspace, and doesn&#x27;t have the same kernel features that would let you do so cleanly or performantly.<p>Orbstack is moving mountains to provide Linux-native perf and support for containers and it still makes me beg the question: why are devs allergic to just using Linux natively? At least I understand why Orbstack is useful, I don&#x27;t know why containerizing MacOS itself is.
评论 #37661330 未加载
donatjover 1 year ago
What&#x27;s the licensing situation on this? Would I be distributing parts of macOS in my containers? I don&#x27;t think Apple is OK with that.<p>Or is this <i>just</i> the fully open source Darwin core? That wouldn&#x27;t likely be super compatible with a ton of production software? I need more explanation of what is actually going on here because it sounds like a good way to get sued.
评论 #37657294 未加载
评论 #37657046 未加载
therealmarvover 1 year ago
Reminds me: Still waiting for native ARM support on GitHub Actions <a href="https:&#x2F;&#x2F;github.com&#x2F;actions&#x2F;runner-images&#x2F;issues&#x2F;5631">https:&#x2F;&#x2F;github.com&#x2F;actions&#x2F;runner-images&#x2F;issues&#x2F;5631</a>
评论 #37695425 未加载
评论 #37661605 未加载
MuffinFlavoredover 1 year ago
<a href="https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;macos-jail">https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;macos-jail</a> - new code<p><a href="https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;rund">https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;rund</a> - new code<p><a href="https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;moby">https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;moby</a> - fork, 6 commits<p><a href="https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;buildkit">https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;buildkit</a> - fork, 4 commits<p><a href="https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;containerd">https:&#x2F;&#x2F;github.com&#x2F;macOScontainers&#x2F;containerd</a> - fork, 5 commits<p>Would be interesting to see if they can get moby&#x2F;buildkit&#x2F;containerd changes upstreamed
评论 #37660610 未加载
评论 #37686850 未加载
skibzover 1 year ago
System Integrity Protection sounds really important. What does it do normally, and why does this tool require it to be disabled?
评论 #37656046 未加载
评论 #37656031 未加载
miniparkover 1 year ago
Why should anyone trust this website and download the software? There&#x27;s no indication who made it. Could be malware for all I know.
评论 #37655856 未加载
评论 #37656287 未加载
评论 #37655925 未加载
daft_pinkover 1 year ago
I feel cheated by Apple a little bit.<p>I bought an Apple Silicon machine after their presentation claiming that they would have first class docker support, but the reality has been that while the first docker worked well as it was translated, now it wants to default to arm containers and it has become very difficult to use because it doesn&#x27;t want to use Rosetta 2 containers.<p>The whole point of using docker is to use the same containers in production as you use in development, so having docker default to these random arm containers means that my containers aren&#x27;t exactly production, because they are arm based and the servers are not.<p>I understand that docker is the developer of docker software, but I really wish I could just click a button and force intel based containers in docker as the default and have to opt-in to arm.<p>If anyone has an easy solution to this let me know. I don&#x27;t want to spend hours and hours figuring out docker on my mac.
评论 #37666129 未加载
评论 #37675651 未加载
xenaover 1 year ago
This is amazingly cursed and I&#x27;d love to see this become viable
xcdzvynover 1 year ago
TIL SIP blocks chroot. I wonder why?
评论 #37655940 未加载
ravenstineover 1 year ago
This is a cool idea and an impressive project.<p>At the same time, I don&#x27;t truly understand why anyone would need to use it. If your preference is to totally work with macOS, then I&#x27;m sure this would be perfect for that. Otherwise, what&#x27;s the advantage?<p>VMs have really come a long way. Every major OS today has a virtualization framework that makes running another OS extremely performant. Docker on macOS uses a virtual machine, but so what? Performance of individual containers, in my experience, isn&#x27;t really a problem unless you&#x27;re doing something with the GPU, and even then there are ways to deal with that. Even a fully-emulated VM using QEMU (without hypervisor or KVM) won&#x27;t have any noticeable performance penalties in many cases.<p>IMO, there&#x27;s a much greater advantage to sticking with Linux. Even if the host isn&#x27;t Linux, developing and deploying with Linux guests provides a tremendous level of consistency and portability.<p>But maybe I&#x27;ll be proven wrong by this project someday soon!
WesolyKubeczekover 1 year ago
What my dream is that the User Mode Linux is made into a cross-platform userspace binary that translates syscalls transparently between itself and the host. So you might get &quot;drivers&quot; that talk to Windows, Linux, *BSDs, Darwin, it manages memory in an efficient (for the host) way, and enables you to run any kinds of wild experiments with, say, virtualized and passed-through serial devices, USB devices, networking, bind-mounting from the host and image mounts. And yes, containers. All of that without needing host root in most cases.<p>Of course the drawback would be that the host would see just a fat Linux process and its child processes, much like you can see qemu, but it could be an interesting thing nonetheless, if even for shits and giggles of it.
bryanlarsenover 1 year ago
For a Docker-like OCI experience on MacOS without disabling SIP, check out TartVM. Happy user here.
maviliover 1 year ago
When macOS runs on Unix kernel and Linux systems are the best supported for containerisation and I assume are much more lightweight than macOS, I personally don&#x27;t see any reason to run macOS in a container.
评论 #37660433 未加载
keepamovinover 1 year ago
Can anyone speak to how the macOS runners on GitHub actions work? It would seem from this post that containers of any kind for macOS are a brand new thing..
评论 #37656294 未加载
RockRobotRockover 1 year ago
Despite the SIP problem, this is really exciting.
nathantsover 1 year ago
the amount of engineering hours wasted making macos usable for backend dev work and then wasted again from inefficiency due to that failure is staggering.<p>linux is great. macos is great. windows is great too. for their intended purposes.<p>it’s horseless carriages all the way down.
bedersover 1 year ago
MacOS is - by choice - an Apple controlled walled garden.<p>Trying to break out of that is an exercise in futility.<p>Can you come up with situations where I would run a container instead of just running an app or sys service?
prmoustacheover 1 year ago
caveat: this is based on rund. Extract from the readme:<p>rund is an experimental containerd shim for running macOS containers on macOS.<p>rund doesn’t offer the usual level of container isolation that is achievable on other OSes due to limited macOS kernel API.<p>What rund provides:<p><pre><code> Filesystem isolation via chroot(2) Cleanup of container processes using process group OCI Runtime Specification compatibility (to the extent it is possible on macOS) Host-network mode only bind mounts</code></pre>
评论 #37656737 未加载
da39a3eeover 1 year ago
I use MacOS and am very positive about it. I have lots of reasons to run Linux containers. What are some reasons I might want to run a MacOS container?
评论 #37661823 未加载
评论 #37657928 未加载
sourabhvover 1 year ago
This uses macfuse, a closed source software
评论 #37657758 未加载
crabboneover 1 year ago
Unrelated to containers themselves: how do you make a patch when no version was released? I mean, people call this &quot;semantic&quot; versioning, but then spit in the face of those semantics...
评论 #37658421 未加载
评论 #37658384 未加载
评论 #37658346 未加载
ameliusover 1 year ago
Can I run them on a normal PC with Linux?
评论 #37658396 未加载
xystover 1 year ago
7G images, wow
评论 #37660848 未加载
dingiover 1 year ago
Can anybody explain, what&#x27;s the point of Mac containers? Almost nobody uses Mac for container based deployments.
评论 #37661813 未加载
评论 #37656946 未加载
figmertover 1 year ago
It&#x27;s sad to see so many negative comments for this. I get it&#x27;s not an ideal place to start for macOS containers, but it&#x27;s a start. Apple isn&#x27;t doing it, so the community has to. Once you have a start, you can iterate on it. It might not be great now, but hopefully this makes it possible in a year or so. Who knows, maybe this is the kick Apple needs, and maybe they&#x27;ll hire the devs of this project to fully work on this.
评论 #37656864 未加载
_joelover 1 year ago
Sorry, not disabling SIP for something that I can already do without needing to nobble security policies (and have them reset&#x2F;impossible due to MDM). If there was user&#x2F;networking space in Darwin then maybe I&#x27;d be interested but...
评论 #37656789 未加载
评论 #37656892 未加载
tambourine_manover 1 year ago
It’s remarkable that Apple doesn’t have a first party solution to this yet. They used be, or aspire to be, at the forefront of OS research.“The most advanced Unix”.<p>They’re not even trying, now.
评论 #37658301 未加载
评论 #37657546 未加载
baqover 1 year ago
<i>cries in Asahi Linux</i><p>macbook is the best laptop there is but macos...<p>can&#x27;t wait for a stable release of Asahi and permission from corporate to install it even in a VM somehow. probably won&#x27;t happen, but one can dream.
评论 #37657449 未加载
评论 #37656866 未加载
icarover 1 year ago
I hope their software quality is better than what the page looks like in a small form factor.