Linux-VServer 2 for kernel 2.6
Summary
In 2005 Linux-VServer 2.0 was the first stable version to run on kernel 2.6, isolating several Linux environments on one computer from each other. Similar to BSD jails, each environment formed its own context in which processes only saw their part of the file system and no other processes. Unlike User Mode Linux or Xen, the guests did not run their own kernel.
Ideas
- Virtualisation at operating system level shares one kernel between several environments.
- Resource limits prevent one environment from taking over the whole computer.
- Uptime, memory and load were displayed separately for each virtual system.
Insights
- Containers are lighter than virtual machines because they do not bring their own kernel.
- The shared kernel is both an efficiency gain and a shared weak point.
Facts
- VServer 2.0 supported most hardware platforms that Linux ran on.
- The concept resembled FreeBSD’s jails.
References
Critique
- The report omits that VServer required a patched kernel outside the official Linux kernel.
Remarks
- The idea lives on today in the mainline kernel’s namespaces and cgroups, on which LXC, Docker and Podman are built.
Recommendations
- For new container setups, use the mainline mechanisms instead of external kernel patches.
- Separate services with different trust levels using virtual machines, not just containers.
Links to the original source and the Web Archive open in a new tab.