官术网_书友最值得收藏!

Clear container

Virtual machines are secure but very expensive and slow to start, whereas containers are fast and provide a more efficient alternative, but are less secure. Intel's Clear containers are a trade-off solution between hypervisor-based VMs and Linux containers that offer agility similar to that of conventional Linux containers, while also offering the hardware-enforced workload isolation of hypervisor-based VMs.

A Clear container is a container wrapped in its own inpidual ultra-fast, trimmed down VM which offers security and efficiency. The Clear container model uses a fast and lightweight QEMU hypervisor that has been optimized to reduce memory footprints and improve startup performance. It has also optimized, in the kernel, the systemd and core user space for minimal memory consumption. These features improve the resource utilization efficiency significantly and offer enhanced security and speed compared to traditional VMs.

Intel Clear containers provide a lightweight mechanism to isolate the guest environment from the host and also provide hardware-based enforcement for workload isolation. Moreover, the OS layer is shared transparently and securely from the host into the address space of each Intel Clear container, providing an optimal combination of high security with low overhead.

With the security and agility enhancements offered by Clear containers, they have seen a high adoption rate. Today, they seamlessly integrate with the Docker project with the added protection of Intel VT. Intel and CoreOS have collaborated closely to incorporate Clear containers into CoreOS's Rocket (Rkt) container runtime.

主站蜘蛛池模板: 孝义市| 潼南县| 闸北区| 三门县| 巴林右旗| 大新县| 岗巴县| 民县| 湖州市| 金坛市| 廉江市| 奉新县| 红安县| 龙山县| 平顶山市| 合江县| 宁安市| 息烽县| 定襄县| 鹤山市| 石阡县| 田阳县| 吉木萨尔县| 中阳县| 孝昌县| 五指山市| 分宜县| 诏安县| 平度市| 池州市| 黄陵县| 岑溪市| 利辛县| 天门市| 翁牛特旗| 林西县| 衡山县| 云安县| 日土县| 河曲县| 岳普湖县|