I just read about people running Docker on a RP and thought, wouldn't Firecracker be better suited for this?
I just read about people running Docker on a RP and thought, wouldn't Firecracker be better suited for this?
The performance overhead is probably not the biggest reason why you'd stick with Docker, though. The real kicker is that most existing services already run Docker containers and there are loads of resources out there to get you started. Firecracker is relatively new and unsupported. There's no technical reason why Firecracker is a better use case for an RPi, but I think people running RPi servers are on average less experienced and will likely benefit from the Docker knowledge base out there compared to, say, people renting a VPS somewhere, or people building full server machines.
- 40ms for nsjail run an isolated command and exit [1]
- 150[2]-250ms to boot a firecracker microvm
- ~450ms for docker startup [3]
There are probably very good reasons for the difference (e.g. docker has layered filesystems to set up), but the default experience makes a difference.
[0] https://news.ycombinator.com/item?id=24853660
[1] `nsjail --user 9999 --group 9999 -macvlan_iface wlp2s0 --chroot / -Mo --macvlan_vs_ip 192.168.0.44 --macvlan_vs_nm 255.255.255.0 --macvlan_vs_gw 192.168.0.1 -- /bin/true`
[2] https://blog.acolyer.org/2020/03/02/firecracker/
[3] `docker run -d ubuntu:18.04 true`
However, in this context (being on a rpi) it probably wouldn't be the case.
Now, as for the firecracker discussion: Firecracker trades a faster boot time for a slower runtime as evidenced by this issue here:
https://github.com/nanovms/nanos/issues/483#issuecomment-650...
There are plans to fix this but afaict this is the case today.
As an aside, there's also krustlet--an experimental project that uses Kubernetes to schedule WASM programs (instead of containers) which are less versatile but which are much lighter-weight and more secure than containers. I'm really excited for WASM orchestrators like this.
EDIT: Wow, I really didn't expect this to be controversial. I'm really curious about what people are objecting to with this?
Depends what do you want to manage in your infra. I also like to manage most of my infra so I usually use VMs, packaging (Packer) and custom deployment tools (Ansible) but for development workflows, tests, environment replication sometimes I use Docker. These are not interchangeable entirely.
One thing I will say about docker is the packaging is very convenient. I have one container for node-red, one for InfluxDb and one for Grafana. I didn't have to deal with anything, just fire them up right out of docker hub and point at each other. Obviously a bit more scrutiny would be recommended for anything important but the overall experience was quite simple.
Another possible use case for Firecracker would be ones where folks are wiring up software-defined radios to RPi. (E.g. ADSB reflectors for FlightRadar24 and the like) Firecracker might be a more robust mechanism to ensure that the stream processing from the radio has sufficient capacity and priority vs whatever other cruft is happening on the box.