generated from krisnova/rust-nova
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
Introduce Runtime Core (Spawn, Pods, Containers, Instances, VMs, and Cells) #73
Conversation
This file contains bidirectional Unicode text that may be interpreted or compiled differently than what appears below. To review, open the file in an editor that reveals hidden Unicode characters.
Learn more about bidirectional Unicode characters
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
krisnova
changed the title
Introduce the concept of a Pod
Introduce Runtime.RunP() for Pods (Youki)
Oct 22, 2022
krisnova
changed the title
Introduce Runtime.RunP() for Pods (Youki)
WIP Introduce Runtime.RunP() for Pods (Youki)
Oct 22, 2022
krisnova
changed the title
WIP Introduce Runtime.RunP() for Pods (Youki)
WIP "The Pod PR"
Oct 22, 2022
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
krisnova
changed the title
WIP "The Pod" PR
Introduce Runtime Core (Spawn, Pods, Containers, Instances, VMs, and Cells)
Oct 23, 2022
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
Signed-off-by: Kris Nóva <kris@nivenly.com>
MalteJ
approved these changes
Oct 23, 2022
Sign up for free
to join this conversation on GitHub.
Already have an account?
Sign in to comment
Add this suggestion to a batch that can be applied as a single commit.
This suggestion is invalid because no changes were made to the code.
Suggestions cannot be applied while the pull request is closed.
Suggestions cannot be applied while viewing a subset of changes.
Only one suggestion per line can be applied in a batch.
Add this suggestion to a batch that can be applied as a single commit.
Applying suggestions on deleted lines is not supported.
You must change the existing code in this line in order to create a valid suggestion.
Outdated suggestions cannot be applied.
This suggestion has been applied or marked resolved.
Suggestions cannot be applied from pending reviews.
Suggestions cannot be applied on multi-line comments.
Suggestions cannot be applied while the pull request is queued to merge.
Suggestion cannot be applied right now. Please check back later.
Introduce the concept of Pods, Instances, Cells, Virtual Machines, Executables, and Containers to Aurae.
This calls out the Core service in the Runtime subsystem.
What is an "Aurae Pod"?
In order to play as nicely as possible with Kubernetes and the community we make the assumption that most users of Aurae will try to "run pods".
In order to introduce an added layer of security, and make the secure path the easy path we make Aurae pods behave like normal Kubernetes pods, but create a more secure and elaborate runtime isolation zone.
An Aurae pod is a set of containers (called a Cell in Aurae) running in a unique cgroup. This cell runs inside of a nested Aurae virtual instance that is created using the
Spawn()
RPC.First Aurae spawns a new virtual instance of itself, and inherits properties from the parent. Then a cell of containers is established in the newly created nested Aurae instance.
What about the Kubelet? Will it be a drop in replacement?
In short, no. Aurae will not be a drop-in replacement for the kubelet. However we can build and support adapter patterns, shims, and translation services later if necessary.
The rational to keep the pod nomenclature is as follows:
If we intend to support the Kubernetes control plane (which I believe we should) we will need to play as nice as possible with the API server. While I don't believe Aurae itself should be a drop in replacement for the Kubelet. There is nothing wrong with building a lightweight service in the future to spoof the Kubelet the same way the virtual kubelet has.
Kubelet Documentation To Consider while developing.
In an effort to bring light to the Kubelet documentation here are some notes from my years of hacking on Kube.
Signed-off-by: Kris Nóva kris@nivenly.com