官术网_书友最值得收藏!

Namespaces and cgroups

Users logged into a Linux system have a transparent view of various system entities such as global resources, processes, kernel, and users. For instance, a valid user can access PIDs of all running processes on the system (irrespective of the user to which they belong). Users can observe the presence of other users on the system, and they can run commands to view the state of global system global resources such as memory, filesystem mounts, and devices. Such operations are not deemed as intrusions or considered security breaches, as it is always guaranteed that one user/process can never intrude into other user/process.

However, such transparency is unwarranted on a few server platforms. For instance, consider cloud service providers offering PaaS (platform as a service). They offer an environment to host and deploy custom client applications. They manage runtime, storage, operating system, middleware, and networking services, leaving customers to manage their applications and data. PaaS services are used by various e-commerce, financial, online gaming, and other related enterprises.

For efficient and effective isolation and resource management for clients, PaaS service providers use various tools. They virtualize the system environment for each client to achieve security, reliability, and robustness. The Linux kernel provides low-level mechanisms in the form of cgroups and namespaces for building various lightweight tools that can virtualize the system environment. Docker is one such framework that builds on cgroups and namespaces.

Namespaces fundamentally are mechanisms to abstract, isolate, and limit the visibility that a group of processes has over various system entities such as process trees, network interfaces, user IDs, and filesystem mounts. Namespaces are categorized into several groups, which we will now see.

主站蜘蛛池模板: 茶陵县| 阳泉市| 嘉兴市| 岫岩| 舟山市| 宁都县| 筠连县| 高陵县| 称多县| 临猗县| 多伦县| 阿拉善右旗| 潮州市| 吉水县| 尚志市| 河西区| 象山县| 南和县| 巫山县| 普定县| 陆河县| 砀山县| 镇沅| 高台县| 韶山市| 无锡市| 彭阳县| 湖北省| 安义县| 甘德县| 修水县| 丹阳市| 区。| 弋阳县| 永平县| 南投县| 金湖县| 皮山县| 北票市| 洛阳市| 延安市|