官术网_书友最值得收藏!

Clear container

Virtual machines are secure but very expensive and slow to start, whereas containers are fast and provide a more efficient alternative, but are less secure. Intel's Clear containers are a trade-off solution between hypervisor-based VMs and Linux containers that offer agility similar to that of conventional Linux containers, while also offering the hardware-enforced workload isolation of hypervisor-based VMs.

A Clear container is a container wrapped in its own inpidual ultra-fast, trimmed down VM which offers security and efficiency. The Clear container model uses a fast and lightweight QEMU hypervisor that has been optimized to reduce memory footprints and improve startup performance. It has also optimized, in the kernel, the systemd and core user space for minimal memory consumption. These features improve the resource utilization efficiency significantly and offer enhanced security and speed compared to traditional VMs.

Intel Clear containers provide a lightweight mechanism to isolate the guest environment from the host and also provide hardware-based enforcement for workload isolation. Moreover, the OS layer is shared transparently and securely from the host into the address space of each Intel Clear container, providing an optimal combination of high security with low overhead.

With the security and agility enhancements offered by Clear containers, they have seen a high adoption rate. Today, they seamlessly integrate with the Docker project with the added protection of Intel VT. Intel and CoreOS have collaborated closely to incorporate Clear containers into CoreOS's Rocket (Rkt) container runtime.

主站蜘蛛池模板: 桦甸市| 城口县| 普兰县| 罗城| 新丰县| 金寨县| 德钦县| 尚志市| 长沙县| 莎车县| 抚州市| 九江市| 常德市| 疏附县| 井陉县| 黄浦区| 铅山县| 宾阳县| 佛冈县| 工布江达县| 额尔古纳市| 武冈市| 泾阳县| 巴南区| 峨眉山市| 海晏县| 兴安县| 锦州市| 霍州市| 五家渠市| 施秉县| 浠水县| 赣州市| 红桥区| 横山县| 南安市| 前郭尔| 陆川县| 浦东新区| 南川市| 科技|