Container Isolation via Virtualization - Don't Forget to Shrink the Guest
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Explore container isolation through virtualization in this conference talk that emphasizes the importance of shrinking guest kernels. Learn about lightweight virtualization techniques for improving container runtime isolation, such as Kata containers. Discover how new VM monitors like AWS Firecracker and tools like Weaveworks Ignite have advanced lightweight virtualization. Examine the often-overlooked aspect of guest kernel optimization and its impact on performance and security. Understand the case for guest kernel specialization through kernel configuration and the challenges of applying these techniques in sandboxed container environments. Gain insights into the balance between isolation, performance, and security in modern containerized systems.
Syllabus
Container Isolation via Virtualization: Don't Forget to Shr... Dan Williams & Hsuan-Chi (Austin) Kuo
Taught by
CNCF [Cloud Native Computing Foundation]