In a Container, Nobody Hears Your Screams - Next Generation Process Isolation
CNCF [Cloud Native Computing Foundation] via YouTube
Overview
Syllabus
Intro
Sandboxing Tech
Glossary • untrusted workload: cannot be certified as safe to run
Containers and VMs
What's wrong with containers?
Assumption Maketh the Ass
Rootlessness
Rootless State of Union
History of Virtualisation
Virtual Machine Monitor
KVM vs Xen vs QEMU
Spectrum of Isolation
gVisor vs Firecracker vs Kata
gVisor Sentry
Firecracker Device Model
Kata Containers
Honourable mention: rust-vmm
Docker & Kubernetes RuntimeClass
What are the risks of next gen proc iso?
What should I use?
Conclusion
Taught by
CNCF [Cloud Native Computing Foundation]