docker in gVisor: I am one with the force, the force is with me
Startup is currently blocked by oom_score_adj, but there are many additional blockers.
Running Docker in a gVisor shielded container would be such a nice feature :slightly_smiling_face: - The dream of actual lightweight "VMs" in which you could land a user without having sleepless nights would come true.
+1
+1
This is now blocked on some kind of cgroups support inside the sandbox Related: #906 #1906
+1
This is now blocked on some kind of cgroups support inside the sandbox Related: #906 #1906
A lot more it's blocked on: no support for bind mounts, no support for CLONE_NEWNS, etc. etc. I will try to fix all of that. On the other hand running it in a real docker daemon is probably too much of a task, because it will always fail at the various "security" measures that docker tries to set up and which are not needed.
A friendly reminder that this issue had no activity for 120 days.
@avagin has made good amounts of progress on this.
A friendly reminder that this issue had no activity for 120 days.
This issue has been closed due to lack of activity.
https://gvisor.dev/docs/tutorials/docker-in-gvisor/
This is awesome. I figured this was coming when I saw the veth device support being added!
@hbhasker Hi Bhasker. Good to see you here:). Right now, we support only the host network mode. The bridge mode is coming soon. veth and bridges are still in development.
I lurk and follow random PRs:) Good to see you too! Looking forward to the rest landing!