The Man Who Would Build a Computer the Size of the Entire Internet
wired.com
wired.com
> So what does Docker actually do?
Thanks for asking!
From the project homepage: Docker is an open-source project to easily create lightweight, portable, self-sufficient containers from any application. The same container that a developer builds and tests on a laptop can run at scale, in production, on VMs, bare metal, OpenStack clusters, public clouds and more.
There's a nice high-level overview on http://www.docker.io/learn_more/ , and a really cool interactive tutorial on http://www.docker.io/gettingstarted/
I also encourage you to join the IRC channel (#docker on freenode). It's extremely active and the people there are super nice. They will get you up to speed in no time!
> Why is the press talking about Docker when the kernel developers did all the real work?
Press coverage is not a zero-sum game. Does it hurt Linux and its developers when Docker gets attention? Or does it further establish Linux as the ubiquitous software infrastructure that it is?
There's no question that Docker wouldn't be possible (or would be much less useful anyway) without the work of countless kernel hackers who implemented and hardened namespacing and control groups. We also owe a lot to Junjiro Okajima, the author of AUFS. I don't believe we're doing any of these people a disservice by building cool stuff on top of their code, open-sourcing all of it, and getting a lot more people excited about the combined result.
> How do I buy an article like this on Wired?
That's not how press works. Based on my experience, here's how to get quality press coverage.
First build something people want. As more people use it and express their excitement, journalists will take notice. They will then contact you for details and if they like what they hear they will write a story.
> I was going to try Docker, but it's so hyped now that it doesn't seem legit anymore
Really? This reaction makes me so, so sad.
Speaking on behalf of everyone who has contributed to Docker in one way or the other. ALL WE ASK is that you evaluate the project based on its merits, instead of how fashionable it is.
Tell me you hit a bug. Tell me it doesn't solve a real problem for you. Tell me the documentation isn't clear, or the code is not clean. But for the love of god, don't tell me your criticism of a project is that it's too popular, and therefore no longer a trendy thing to use. Please tell me that is not what the hacker community has come to.
Really? "Build a Computer the Size of the Entire Internet" based off LXC containers they're creating an abstraction over?
It's like saying virtualenv can "Build a Computer the Size of the Entire Internet" because you can relocate an entire python program easily.
I love how rabid they are, but self-promotional attention is getting out of hand.
[SELF-CHECK: If you find this article annoying to read, is it because you're jealous of their attention? Are there things you've done that have mattered (or could have mattered) if only other people paid attention? How are you going to get attention next time? Yeah, getting attention this way can seem slimy, icky, unseemly, and feel like outright lies, but they'll be the millionaires and you won't. Gotta get slimy sometime.]
I like Docker, because it automates much of the LXC bits, and adds cool filesystem features. So, do not take my comments the wrong way, but I think articles like this do a disservice since they over hype!
[1] http://www.wired.com/wiredenterprise/2013/08/coreos-the-new-...
http://www.wired.com/wiredenterprise/2013/09/nginx/
So the internet endgame seems to be One Huge Reinvented Internet in a huge computer running Nginx. It could be worse.
Here is the home page of LXC: http://lxc.sourceforge.net/
Here is the home page of Docker: https://www.docker.io/
Reading both should answer this question.
I also would not categorize Docker as a 'little wrapper' around LXC. Sure, Docker uses LXC as a default container provider but it could have just as well have been raw cgroups/network namespaces, libvirt, openvz, or any other abstraction that suits the core abstractions of Docker.
Nobody's paying for advertisement of scp scripts.
In several of my personal project, I have noticed that once you have a following, you try to keep the standards up and only release quality, things start to take longer, and longer, because you do not want to let anyone down. I have felt real pressure to perform, and my projects are not anywhere near their level!
The amount of work ahead of us is minuscule in comparison to the amount of work we'll have ahead of us in a year, and so on. However, scaling appropriately to become an organization that can handle those demands is really, really hard.
Try the tutorial, if it still doesn't make much sense to you, then it's probably not something you need to worry about.
The main thing Docker does is run arbitrary commands with (or like) LXC, which is basically a way of running a program inside a chroot environment, plus providing a more low-level separation for various parts of the kernel. The end result is your host is kept insulated from the program being run. Here's a great HOWTO on setting up LXC: http://lxc.teegra.net/ And here's a great StackOverflow answer on what Docker/LXC does: http://stackoverflow.com/questions/16047306/how-is-docker-io...
This page from Docker's blog discusses not only the security aspects of a container, but a comparison to traditional virtual machines: http://blog.docker.io/2013/08/containers-docker-how-secure-a...
And the best technical summary from Docker's documentation on what a container is:
"Once you start a process in Docker from an Image, Docker fetches the image and its Parent Image, and repeats the process until it reaches the Base Image. Then the Union File System adds a read-write layer on top. That read-write layer, plus the information about its Parent Image and some additional information like its unique id, networking configuration, and resource limits is called a container."
On top of that it adds a Registry, an Index, and a Remote API. So really, it has remote deployment features, it builds chroot environments, and it combines them and runs applications in a container. Oh, and here is the FAQ: http://docs.docker.io/en/latest/faq/ Summary of their points de-marketingized:
Portable deployment across machines
You can copy a big image of your chroot environment, application, etc to a remote machine and run it. Docker makes the configuration configurable. Application-centric
They added features to make it easier to deploy a program and run it how you want it to run. Automatic build
Instead of using a shell script to build your container's chroot environment, you use a Dockerfile, which is like a less useful shell script. Versioning
Docker assigns a SHA hash to each image you deploy so you can roll back and do other things on the hash instead of the file name. It also transfers deltas of changes, apparently. Component re-use
Due to using a unionfs, you can mount multiple images on top of one another, so you can have smaller separate images and pick the ones you want to use for your app. Sharing
You can upload your images to a public repository or download them for your own use. Tool ecosystem
Docker has an API. (Actually three APIs)[1] http://en.wikipedia.org/wiki/Deus_Ex_characters#Artificial_i...