TE
科技回声
首页24小时热榜最新最佳问答展示工作
GitHubTwitter
首页

科技回声

基于 Next.js 构建的科技新闻平台,提供全球科技新闻和讨论内容。

GitHubTwitter

首页

首页最新最佳问答展示工作

资源链接

HackerNews API原版 HackerNewsNext.js

© 2025 科技回声. 版权所有。

Kata Containers – The speed of containers, the security of VMs

208 点作者 bharatkhatri14超过 7 年前

9 条评论

jeremyjh超过 7 年前
They don&#x27;t seem to have written any code yet. [1] So what we have at this point is a marketing website about their ambition and goals?<p>[1]<a href="https:&#x2F;&#x2F;github.com&#x2F;kata-containers&#x2F;runtimes" rel="nofollow">https:&#x2F;&#x2F;github.com&#x2F;kata-containers&#x2F;runtimes</a>
评论 #15870128 未加载
评论 #15870098 未加载
评论 #15870990 未加载
reacharavindh超过 7 年前
Impressive backing by the big name companies.<p>The idea of treating containers as secure and isolated as VMs is enticing for non-ephemeral services. Are these strictly tuned to exploit intel Hardware features or would they consider supporting the equivalent features in say AMD?<p>On the other hand, isn&#x27;t this the realm of mainline distributions like RHEL, Debian and the like? To support such isolation facilities. I always thought clear Linux was a Intel playground for proof-of-concept which will eventually be up streamed to major Linux distributions.Is it not true?<p>I guess my question is why a separate project like this, instead of RedHat Enterprise Containers or Debian containers?
评论 #15868971 未加载
评论 #15868860 未加载
评论 #15870553 未加载
评论 #15871490 未加载
评论 #15868823 未加载
评论 #15870966 未加载
perlgeek超过 7 年前
One thing that isn&#x27;t mentioned on front page at least is the management aspect.<p>Docker became popular because it was pretty easy to use, and to publish and reuse existing containers. Whatever competes with it only stands a chance if it can either reuse the existing container ecosystem, or offer something roughly as good.
评论 #15870061 未加载
评论 #15869089 未加载
评论 #15869480 未加载
mnd999超过 7 年前
The British Indian Ocean territory really is becoming a tech hub.
评论 #15869528 未加载
评论 #15869158 未加载
评论 #15871115 未加载
e_d_e_v超过 7 年前
How is this better than using rkt with an lkvm stage1[1], which also uses the work done by the Clear Containers team? It looks like Kata packages QEMU as well, which seems a bit overkill.<p>[1]<a href="https:&#x2F;&#x2F;coreos.com&#x2F;rkt&#x2F;docs&#x2F;latest&#x2F;running-kvm-stage1.html" rel="nofollow">https:&#x2F;&#x2F;coreos.com&#x2F;rkt&#x2F;docs&#x2F;latest&#x2F;running-kvm-stage1.html</a>
评论 #15873945 未加载
chungy超过 7 年前
It&#x27;s kind of interesting that it&#x27;s only in the Linux world that containers cannot be thought of as isolated or secure. Seeing it from a jails and zones perspective, rather sad, actually :)
评论 #15869470 未加载
评论 #15869132 未加载
评论 #15869366 未加载
tripue超过 7 年前
Another alternative is using hyper container
评论 #15868596 未加载
acobster超过 7 年前
&gt; <i>It is designed to be architecture agnostic, run on multiple hypervisors and be compatible with the OCI specification for Docker containers</i><p>In what sense is this &quot;OCI compatible&quot;? Do they implement the runtime, image format spec, or both? My understanding of containerization and OCI runtimes is that they&#x27;re fundamentally different from hardware-level virtualization.
评论 #15875844 未加载
jeshwanth超过 7 年前
Whats the difference between unikernels and kata containers?
评论 #15869493 未加载