Containers don't actually run directly on hardware with GCE - there's still a virtualization layer in-between.
I'm 99% sure that Google runs one VM per container because that's the only way to make it safe.
Anything else would be insane.
I'm 99% sure that Google runs one VM per container because that's the only way to make it safe.
Anything else would be insane.
I'm 100% sure you are wrong. You might as well just use VMs.
Containers are not only about safety, you know.
Hypervisors are much, much harder to break out of than a Linux container.