官术网_书友最值得收藏!

Clear container

Virtual machines are secure but very expensive and slow to start, whereas containers are fast and provide a more efficient alternative, but are less secure. Intel's Clear containers are a trade-off solution between hypervisor-based VMs and Linux containers that offer agility similar to that of conventional Linux containers, while also offering the hardware-enforced workload isolation of hypervisor-based VMs.

A Clear container is a container wrapped in its own inpidual ultra-fast, trimmed down VM which offers security and efficiency. The Clear container model uses a fast and lightweight QEMU hypervisor that has been optimized to reduce memory footprints and improve startup performance. It has also optimized, in the kernel, the systemd and core user space for minimal memory consumption. These features improve the resource utilization efficiency significantly and offer enhanced security and speed compared to traditional VMs.

Intel Clear containers provide a lightweight mechanism to isolate the guest environment from the host and also provide hardware-based enforcement for workload isolation. Moreover, the OS layer is shared transparently and securely from the host into the address space of each Intel Clear container, providing an optimal combination of high security with low overhead.

With the security and agility enhancements offered by Clear containers, they have seen a high adoption rate. Today, they seamlessly integrate with the Docker project with the added protection of Intel VT. Intel and CoreOS have collaborated closely to incorporate Clear containers into CoreOS's Rocket (Rkt) container runtime.

主站蜘蛛池模板: 祁门县| 宁明县| 寻乌县| 临猗县| 高青县| 阜阳市| 敖汉旗| 忻州市| 宝兴县| 晴隆县| 天峨县| 汶上县| 桃江县| 湛江市| 江陵县| 武城县| 若羌县| 理塘县| 昂仁县| 凤凰县| 北票市| 察雅县| 浙江省| 桃园市| 丰都县| 临城县| 炎陵县| 金华市| 海安县| 额敏县| 辉南县| 临沭县| 九龙坡区| 邯郸县| 海盐县| 道孚县| 郸城县| 稻城县| 开阳县| 长武县| 西乡县|