Containerd – An open and reliable container runtime, by Docker
github.com
github.com
Layering matters, and Docker seems to be offering a solution that is Docker compatible but more usable by layered systems.
Devil's in the details, of course, but this seems like what our customers want - docker but not Docker.
Disclosure: Kubernetes dev
I don't think that this is the exact bug for our issue but it's closely related:
https://github.com/docker/docker/issues/10355
I really want to give rkt a shot but our tooling investment in Docker is huge. I want to wait and see what the runtime ecosystem looks like in another 6 months before considering a switch.
- https://github.com/kelseyhightower/cri-o-tutorial
- Mesos already has something called UCR that allows one to run docker images minus the dependency on the docker runtime. (http://mesos.apache.org/documentation/latest/mesos-container...)
Disclaimer: I work at Mesosphere on Mesos.
I'm not a huge fan of Docker's runtime because it tends to be rather sluggish. I haven't used it in quite a while, though.
Edit: Relevant details https://news.ycombinator.com/item?id=13110897
Note these were not issues with using docker poorly, or out of mainline use cases. They are all issues with dockers core networking or runtime stack that are acknowledged bugs.
#28889 is resolved in 1.12.4
#26492 was found to be not a Docker issue, but if you are still having an issue here, please open a new one, thanks!
However, our integration suite repeatedly caught deadlocks and some panics in 1.12.* so we have yet to upgraded to that. I'll ask our infrastructure teams to do a custom CoreOS with 1.12.4 and run it through the paces; though, I know we've had issues with Kube in the CoreOS alpha channel so it may be a no go.
Thanks for the reply!
The rest of the lockup issues have been related to kernel bugs which would also be observed with other tools. One major issue we've had (which is really multiple kernel issues with multiple causes) is netlink (a kernel interface) not responding and the container's mutex is held forever while we wait on netlink. The locking up part should be resolved in 1.12.4 for this as well, where it uses a timeout on the netlink socket... still going to have errors from this since if netlink isn't responding there's something else weird happening, but at least the container mutex can be released you can interact with the daemon.
In 1.14 we should have a lock-free container object so that any new issues that come up in this regard are isolated to a particular thread. This makes detecting that there is an issue harder, but something we could potentially track and even report on.
note that the daemon isn't really locking up fully, just that any command that tries to lock the container's mutex will get stuck, which includes listing it in `docker ps`, start/stop/restart/etc on that particular container.
Avoiding thing Docker daemon, for example, was a big motivation with rkt.
But of course it's gotten even more important as Docker has ballooned in complexity.
People still want to use runc because it's a great piece of battle tested kit but don't want the kitchen sink and projects like CRI-O and Garden-Runc/Guardian are pushing the much simpler, smaller surface area angle.
Overall I appreciate all of the discussion on architecture of these systems and nailing this stuff down into the right format. My end goal is to ensure people get a strong reliable system, the exact technologies and projects used to get there is less important.
[1] https://coreos.com/blog/rkt-and-kubernetes.html [2] https://www.youtube.com/watch?v=x84Nes2P3Z4&t=124s
(Perspective: Docker in production. Would rather bite my arm off than do it again. rkt looks like a sane Docker, but I haven't used it in anger.)
Previous discussions:
https://news.ycombinator.com/item?id=11492736
> Docker today announced that it is spinning out containerd, a core component of Docker Engine, its industry-leading container platform, and donating it to a new community project.
Press release linked to from: https://blog.docker.com/2016/12/containerd-core-runtime-comp...
* scope table: https://github.com/docker/containerd#scope
* roadmap: https://github.com/docker/containerd/blob/master/ROADMAP.md
* new API: https://github.com/docker/containerd/tree/master/api
Disclosure: Red Hat Evangelist.
I know this is for rkt but it gives a good comparison of container runtimes. https://coreos.com/rkt/docs/latest/rkt-vs-other-projects.htm...