Newbies are better served starting with the simple stuff and then moving to the complex if needed
Newbies are better served starting with the simple stuff and then moving to the complex if needed
But yeah, I'd personally recommend Docker for self-hosting. Kubernetes or Proxmox always end up being too much to handle for personal use - or even small to medium sized companies.
I've been running a 2-node Proxmox cluster for about 3 years with close to no maintenance. What's too much about it?
It gives me easy VM and LXC management and very easy declarative networking and firewalling. That alone makes it worth it for me.
Yes they are complicated. Yes, they are still worth learning. And once you learn them they make a lot of sense to use when given the option.
But even in those 3 areas I haven't exhausted all the knowledge and features available.
So I'm just skeptical when someone is using k8s and hasn't mastered the fundamentals. How do they know whether they should be using a high level k8 feature or a low level os feature? Happened with docker a lot to me when I didn't know better, I was learning how to set memory limits on containers and reset policies instead of learning to do it on the OS level.
Except docker, on its own without something else in the stack, isn't Virtualization.
You are incorrect, this is true:
"OS-level virtualization is an operating system (OS) virtualization paradigm in which the kernel allows the existence of multiple isolated user space instances, including containers (LXC, Solaris Containers, AIX WPARs, HP-UX SRP Containers, Docker, Podman)..."[0].
>you share your host kernel
Kernel != OS
>There are parts of the kernel that aren't namespaced as well. The kernel keyring is probably the big one.
Immaterial.
"OS Virtualization" != "OS" "Virtualization"
https://papers.freebsd.org/2000/phk-jails/
https://youtu.be/hgN8pCMLI2U?si=CH-Fpyj16bEWDZzc
2nd containers go farther and virtualize network, and other resources.
I call it as it is.
>but absolutely no one considers chroot virtualization in any meaningful sense.
Absolutely everyone who's knowledgable in virtualization considers chroot to be a type of OS-level virtualization.
>Nothing is being virtualized, containers are just regular processes on the host system.
Wrong, "...OS-level virtualization is an operating system (OS) virtualization paradigm in which the kernel allows the existence of multiple isolated user space instances..."
"OS Virtualization" == "OS " + "Virtualization"
It’s _very_ different technology than virtualization.
You don’t need docker to make a container on Linux (or Solaris for that matter).
You are incorrect, this is OS-level virtualization:
"OS-level virtualization is an operating system (OS) virtualization paradigm in which the kernel allows the existence of multiple isolated user space instances, including containers (LXC, Solaris Containers, AIX WPARs, HP-UX SRP Containers, Docker, Podman)..."[0].
>it’s namespaces. Docker makes use of Linux kernel features; started out with cgroups and now uses libcontainer. Each container is running in its own isolated(ish) namespace on the same host kernel.
Yes, OS-level virtualization.
>It’s _very_ different technology than virtualization.
Incorrect, this is a virtualization technology.
>You don’t need docker to make a container on Linux (or Solaris for that matter).
No one claimed otherwise.
Of course I haven't mastered he fundamentals of K8s yet, I am just beginning to learn it.
Like you, I have been using docker for years, and to be honest it served me very well - and would probably continue to do so. But as a geek, I have a natural curiosity, sometimes just the curiosity of whether or not something can be done, and how it works, is enough justifications to do it.
As you probably read, this is in my home services. Which is where I am free to do exactly these experiments before I know the inns and outs of it.
Some of what I wrote in the blog post, I have already ditched. I am no longer hardcoding the ipv6 addresses from the pools, for example, but I still need to change my pool ip addresses if my ISP changes the range. I am not sure if my way is the correct one. I could do it manually, but what's the fun in that ?
There will be more blog posts as I learn, you be sure (there already is). I have more coming up, but one of my current projects will take a bit of time, as I have decided that writing a Unifi Operator for managing firewall rules is a better way to do it :)
Now, for home use? Whoever does that, write K8s Operators?
If you're on hacker news then you should understand that the goal isn't necessarily the result, it's the learning experience.
Anyway I agree that there no point in using k8s for home stuff. Single instance of anything should be sufficient for any needs like that.
On the other hand maybe someone just like to tinker with technology.
The goal wasn't necessarily the result.
I like to tinker.
And well...my K8s cluster is only one node so far, so there's limits to what I can play with.
And please: No comments that K8s is overkill. I know, and I don't care :) There's things to learn from it, and that's good enough reason for me.