Navigation Menu

So, What Does a Container Engine Really Do Anyway?

By on Jul 13, 2018 in Article

It only takes a couple of quick google searches to realize that people have no idea what a container engine is. That’s understandable because It was a completely new concept back in 2013. Plenty of good people have tried and failed – see WTF is a Container (not deep enough) or What is Docker and why is it so darn popular? (technical drawing completely...

Read More

What is CRICTL and Why Should You Care?

By on Jul 13, 2018 in Article

Container Engines are like wheel bearings, you should be able to replace them when they stop working. Also, you shouldn’t have to care about what brand they are. That’s what the Kubernetes Container Runtime Interface (CRI) aims to solve. CRI defines the API used to talk to container engines and all the major container engines support CRI either natively...

Read More

What is sVirt and How Does it Isolate Linux Containers?

By on Jul 10, 2018 in Article

Background What is sVirt and, why does it matter for your containers? The short answer is, because sVirt is another layer of security and defense in depth is a good approach to security. The longer answer is, sVirt dynamically generates an SELinux label for every single one of your containers, which makes them less likely to be able to break into each other, break...

Read More

Is OpenShift a Fork of Kubernetes? Short Answer – No. Longer Answer – Here’s a Ton of Technical Reasons.

By on Jun 7, 2018 in Article

When I answer technical questions, I try to treat people with respect. I assume that people are smart and know how to make good decisions if they have the right information. I try to give them facts, so that the architect part of their brain has the information it needs to make good decisions and go forth in the world to help others. Well, if you’re asking...

Read More

Containers Don’t Run on Docker

By on Jun 6, 2018 in Article

Background I’m here to tell you that somebody on the Internet is wrong! Actually, many people. If you have ever consulted Google for the words “Docker Architecture” you may have found a drawing that implies that Docker is some sort of blue box which sits on top of an operating system and runs containers. That makes sense right? Wrong! Containers don’t run on Docker...

Read More