官术网_书友最值得收藏!

Clear container

Virtual machines are secure but very expensive and slow to start, whereas containers are fast and provide a more efficient alternative, but are less secure. Intel's Clear containers are a trade-off solution between hypervisor-based VMs and Linux containers that offer agility similar to that of conventional Linux containers, while also offering the hardware-enforced workload isolation of hypervisor-based VMs.

A Clear container is a container wrapped in its own inpidual ultra-fast, trimmed down VM which offers security and efficiency. The Clear container model uses a fast and lightweight QEMU hypervisor that has been optimized to reduce memory footprints and improve startup performance. It has also optimized, in the kernel, the systemd and core user space for minimal memory consumption. These features improve the resource utilization efficiency significantly and offer enhanced security and speed compared to traditional VMs.

Intel Clear containers provide a lightweight mechanism to isolate the guest environment from the host and also provide hardware-based enforcement for workload isolation. Moreover, the OS layer is shared transparently and securely from the host into the address space of each Intel Clear container, providing an optimal combination of high security with low overhead.

With the security and agility enhancements offered by Clear containers, they have seen a high adoption rate. Today, they seamlessly integrate with the Docker project with the added protection of Intel VT. Intel and CoreOS have collaborated closely to incorporate Clear containers into CoreOS's Rocket (Rkt) container runtime.

主站蜘蛛池模板: 柘荣县| 杭州市| 花垣县| 佛学| 日照市| 云浮市| 新余市| 嘉兴市| 合肥市| 泽库县| 江口县| 尤溪县| 蒙阴县| 松原市| 将乐县| 呼和浩特市| 大埔县| 林州市| 城市| 璧山县| 沂南县| 丹江口市| 任丘市| 德保县| 平顺县| 新密市| 阳原县| 新干县| 新泰市| 都江堰市| 都匀市| 呼图壁县| 格尔木市| 武宣县| 台安县| 临西县| 新平| 东辽县| 刚察县| 依兰县| 文水县|