What is sVirt and How Does it Isolate Linux Containers?

What is sVirt and How Does it Isolate Linux Containers?

Background What is sVirt and, why does it matter for your containers? The short answer is, because sVirt is another layer of security and defense in depth is a good approach to security. The longer answer is, sVirt dynamically generates an SELinux label for every single one of your containers, which makes them less likely

Competition Heats Up Between CRI-O and containerd – Actually, That’s Not a Thing…

Competition Heats Up Between CRI-O and containerd – Actually, That’s Not a Thing…

Are you looking at CRI-O vs. contianerd and wondering to yourself, which one should I use? If you are…. DON’T – that’s not actually something you should be thinking about. Here’s why…. When it comes to containers there are a ton of APIs in the ecosystem. Different users, community projects and commercial products have made

Is OpenShift a Fork of Kubernetes? Short Answer – No. Longer Answer – Here’s a Ton of Technical Reasons.

Is OpenShift a Fork of Kubernetes? Short Answer – No. Longer Answer – Here’s a Ton of Technical Reasons.

When I answer technical questions, I try to treat people with respect. I assume that people are smart and know how to make good decisions if they have the right information. I try to give them facts, so that the architect part of their brain has the information it needs to make good decisions and

Containers Don’t Run on Docker

Containers Don’t Run on Docker

Background I’m here to tell you that somebody on the Internet is wrong! Actually, many people. If you have ever consulted Google for the words “Docker Architecture” you may have found a drawing that implies that Docker is some sort of blue box which sits on top of an operating system and runs containers. That

OpenStack Summit 2018: Vancouver: Engineering Container Security: Addressing the Unique Security Challenges of Containers at Scale in a Multi-Cloud World

OpenStack Summit 2018: Vancouver: Engineering Container Security: Addressing the Unique Security Challenges of Containers at Scale in a Multi-Cloud World

This presentation is a 16 slide introduction to what must be thought about when building a production cloud. Proper image management is critical engineering task.

OpenStack Summit 2018: Vancouver: Linux Container Internals

OpenStack Summit 2018: Vancouver: Linux Container Internals

This presentation is a 16 slide introduction to what must be thought about when building a production cloud. Proper image management is critical engineering task.

Red Hat Summit 2018: San Francisco: Hitachi & Red Hat collaborate: Container migration guide

Red Hat Summit 2018: San Francisco: Hitachi & Red Hat collaborate: Container migration guide

This presentation is a 16 slide introduction to what must be thought about when building a production cloud. Proper image management is critical engineering task.

Red Hat Summit 2018: San Francisco: Building Production Ready Containers

Red Hat Summit 2018: San Francisco: Building Production Ready Containers

This presentation is a 16 slide introduction to what must be thought about when building a production cloud. Proper image management is critical engineering task.

Hacker’s Guide to Installing OpenShift Container Platform 3.9

Hacker’s Guide to Installing OpenShift Container Platform 3.9

  Background My problem, like most technologists, is that I only have a slice of my time to dedicate toward acquiring and maintaining knowledge about any given technology, product, project, tool, platform, etc. Split that with the fact that almost every CIO is preaching that we, as technologists, need to be closer to the business,

On Unikernels – Which is Heavier – VMs or OSes?

On Unikernels – Which is Heavier – VMs or OSes?

Many times, new technologies seem deceptively simple – but I have never found them to actually be simpler. I have always loved the deep technical underpinnings of computing and that’s why I often write about how things like Containers, Unikernels, and Serverless work under the covers. Recently, I was at DevConf in Brno, CZ and