So what do you do, exactly?
So what do you do, exactly?
What do you mean by "zone" exactly?
i asked specifically because the word "zones" reminded me of solaris zones :)
> Styrolite and Edera runs containers inside virtual machine guests for improved isolation and resource management.
do your have your own vmm or is it firecracker with make up and a wig?
How does your approach compare to Google's gVisor?
Styrolite runs containers in a fully isolated virtual machine guest with its own, non-shared kernel, isolated from the host kernel. Styrolite doesn't run a userspace kernel that traps syscalls; it runs a type 1 hypervisor for better performance and security. You can read more in our whitepaper: http://arxiv.org/abs/2501.04580
I skimmed the paper and it suggests your hypervisor can work without CPU-based virtualisation support - that's pretty neat.
Many cloud environments do not have support for nested virtualisation extensions available (and also it tends to suck, so you shouldn't use it for production even if it is available). So there aren't many good options for running containers from different security domains on the same cloud instance. gVisor has been my go-to for that up until now. I will be sure to give this a shot!
This is what the entire public cloud is built on. You don't really read articles that often where someone is talking about breaking vm isolation on AWS and spying on the other tenants on the server.
Well... The entire public cloud except Azure. They've been caught multiple times for vulnerabilities stemming from the lack of hardware backed isolation between tenants.
[1] https://unit42.paloaltonetworks.com/azure-container-instance...
[2] https://www.wiz.io/blog/chaosdb-explained-azures-cosmos-db-v...
It hasn't always been the case for manged services, but I don't think that's true for AWS either.
Between first and second hand experience I can confidently say that, at a bare minimum, the majority of managed services at AWS, GCP, and even OCI use VM's to isolate tenant workloads. Not sure about OCI, but at least in GCP and AWS, security teams that review your service will assume that customers will break out of containers no matter how the container capabilities/permissions/configs are locked down.
What API? The kernel syscall API?
If we assume for a moment, that there are no bugs in the Linux namespace implementation, would containers be as safe as virtual machines?
They can do very little anyway, that way.
Styrolite is a container runtime engine that runs containers in a virtual machine guest environment with no shared kernel state. It uses a type 1 hypervisor to fully isolate a running container from the node and other containers. It's similar to Firecracker or Kata containers, but doesn't require bare metal instances (runs on standard EC2, etc) and utilizes paravirtualization.