Docker Datacenter – develop and manage apps at any scale
docker.com
docker.com
See this for some known exploits:
Suggestion:
Please include a license if one was not (did not notice).
Publish an HTML version.
Before that happened, I felt the exact same way. I still do. Docker, HashiCorp, CoreOS, Google and Amazon are all fighting for control, some building on the work of others, some developing their own solutions, some targeting different markets, some targeting the same market. It's incredibly messy, confusing and yet also somehow supposed to make my life easier.
i.e. You can pay money to have someone run it for you (GKE), or you can roll your own.
CoreOS maintains and builds kube-aws[1].
[1] https://coreos.com/kubernetes/docs/latest/kubernetes-on-aws....
I know that you're referring to development but just wanted to point out to anyone that might think you're referring to their cloud service that you're not.
It is built on top of docker and Kubernetes (CoreOS/fleet in v1), and lets you deploy docker containers natively and/or automatically builds those for you using Heroku buildpacks or Dockerfiles when doing git push deployments. You can also drop down to the Kubernetes level if you need to for things that don't really fit the 12-factor app model without breaking Deis.
That being said, I'm totally biased as I wrote an Heroku-like UI for it (http://deisdash.com/about) and using it for our infrastructure at work. Other similar alternatives are http://pivotal.io/platform, https://flynn.io/, https://www.openshift.com/, https://github.com/dokku/dokku (for single server), etc.
Docker's security concerns are mostly about multitenant systems where you're hosting other people's containers. If all your own apps are your own, then Docker is certainly a step up, securitywise, from running an app as a process running as its own Unix user. You just shouldn't assume that a container is perfectly isolated.
If you're using a system that has rolling, verified, graceful restarts built in (e.g., Marathon, and I believe Kubernetes does, too), you'll easily avoid any downtime, which is harder to accomplish with classical VMs.
With a classical system (VM or otherwise) you'll still have to restart your apps whenever some library (glibc, ImageMagick or whatever) is patched. Docker doesn't change that. It does potentially minimize the surface area.
The playbook tasks would look like:
* Start a new container from the image you want to update
* Using the Docker connector, run your various roles
* Commit the container to a new image
Then you'd push to your registry and redeploy your containers from the updated image.
I suppose there should be something similar for Puppet...
https://github.com/convox/rack
Convox is another open source PaaS, but we're building it entirely on top of AWS services like CloudFormation, ECS, ASG, etc.
This means it's only suitable for teams that have 100% bought into AWS. If that's you, we make all the hard parts of operating a distributed deployment system Amazon's problem.
There's another project in this same space, Empire: https://github.com/remind101/empire
If 100% AWS is not you, Docker Datacenter / Swarm, CoreOS, Deis, CloudFoundry, etc. are doing incredible work.
It's amazing how these sophisticated tools are available to all of us.
Flynn and Deis etc all seem to be writing their own schedulers and routing layer, where Convox and Empire just reuse AWS components. This to me is a huge plus, since those problems are already solved and rock solid.
But as a developer, I just want to push a docker image some where and scale it up later.
Note that the price you mention is yearly. A node is anything you can install Docker Engine on. Typically it's a physical or virtual server. All nodes are combined into a swarm, which you can manage from the control plane.
I know they call it "CaaS", but I guess they are comparing it to using other PaaS's that can be installed on-premise, such as Cloud Foundry. Personally I find the term confusing, as I'm not sure who the consumer of the service is meant to be (developers creating containers? ops who get a platform for running them?)