HNHacker News
TopNewBestAskShowJobs

ctalledo

84 karma · joined July 10, 2019

submissionscomments
ctalledo··on Launch HN: Nestybox (YC S20) – Containers beyond microservices
Yes, it's possible already to run K8s entirely inside a system container deployed with Docker + Sysbox. It's as easy as "docker run --runtime=sysbox-runc -it some-image" and running kubeadm inside to setup K8s. We also have images that come preloaded with K8s to make it easier.

Here is a demo video: https://asciinema.org/a/V1UFSxz6JHb3rdHpGrnjefFIt?speed=1.75

Having said this, K8s is very complex and while its most common functionality works inside the container, we've not yet tested it all.

Here is a doc that describes this in more detail, including what is supported and not supported at this time: https://github.com/nestybox/sysbox/blob/master/docs/user-gui...

ctalledo··on Launch HN: Nestybox (YC S20) – Containers beyond microservices
I understand gvisor's main goal is to improve container isolation by intercepting and inspecting syscalls before they reach the kernel to reduce the attack surface. Sysbox on the other hand is meant as a way to run system software (in addition to apps/microservices) easily inside a Docker container, so its focus is on enabling this functionality. Having said this, Sysbox always enables the Linux user-namespace in containers, and thus also improves container isolation.
ctalledo··on Launch HN: Nestybox (YC S20) – Containers beyond microservices
I've not used either, but conceptually the main difference is that those approaches use micro-VMs and thus require hardware virtualization (hypervisors). This can be a challenge if you want to run those on cloud VMs, as it would require nested virtualization. Sysbox on the other hand is a pure OS-virtualization container runtime, so it does not require hardware virtualization.

Also, I think the goal is different: I understand Firecracker is meant as a way of strengthening the isolation of containers by wrapping them in micro-VMs. Sysbox is meant as way of enabling containers to run system workloads without complex images, entrypoints, volume mounts, etc., and with proper isolation via the Linux user-namespace.

ctalledo··on Launch HN: Nestybox (YC S20) – Containers beyond microservices
The main difference is that it's OCI-based, so works with Docker/containerd and hopefully K8s soon (we are working on the latter). Also, correct me if I am wrong, but I don't believe LXD runs K8s inside without privileged containers. Having said this, I know LXD and Sysbox use many of the same OS-virtualization techniques to do what they do. And in fact we owe much of the work we've done to the ground-work done by the good folks at Canonical/LXD.
ctalledo··on Launch HN: Nestybox (YC S20) – Containers beyond microservices
IIRC, Linux supports up to 32-levels of nesting, so that's an upper bound. This means that within a system container deployed by Sysbox, you can in theory nest inner containers up to 31 levels (since one of the 32 levels is used by the system container). In fact you can do docker-in-docker using privileged containers inside the system container. Having said this, while I've tried docker-in-docker inside the system container and it works fine, I've not gone to deeper nesting levels yet. And this is complex stuff, so I won't say that it definitely works until we try it.
ctalledo··on Launch HN: Nestybox (YC S20) – Containers beyond microservices
That's always a possibility, and the future will tell, but Docker appears to be more focused on improving application development rather than enabling containers to run system software as we are doing. It's a risk we were willing to take.
ctalledo··on Launch HN: Nestybox (YC S20) – Containers beyond microservices
Thanks! Regarding Sysbox EE pricing, it's something that we honestly are still trying to figure out. The reason we ask enterprises to contact us is to understand their use case and needs, so that we can derive a fair price based on this. It's early days for Nestybox, and pricing is a work in progress at this time.
← PreviousPage 2 of 2