Instant clone technology is the mechanism that VMware uses to supply a base Linux OS to each of the containers...
By submitting your personal information, you agree that TechTarget and its partners may contact you regarding relevant content, products and special offers.
running within the virtual container host environment created by VMware vSphere Integrated Containers (VIC).
How does VMware instant clone technology affect vSphere Integrated Containers?
In conventional container environments, each container instance runs on top of a common operating system (OS) -- typically a version of Linux -- and shares the OS kernel. VIC more closely resembles a virtualized environment where each container is basically run within its own virtual machine instance. As with traditional virtualization, this approach promises greater hardware isolation and security, which is preferred for important enterprise application deployments.
But spinning up lots of OSes poses a technical challenge for virtualized environments like VIC. Common VMs each use a unique OS. When a server runs multiple VMs, the multiple OSes can add up to significant duplication in OS components, which consume computer resources, ultimately limiting the number of VMs that the physical server can support -- thereby limiting scalability.
VMware gets around OS duplication and inflated container resource use by using a custom Linux OS based on Project Photon stored as a base image in the virtual container host (VCH). When a new container is started in the VCH, a thin copy of the Photon OS kernel is copied to the new container instance. In addition to using only a small amount of resources -- only a small fraction of the resources needed for a full OS -- the kernel copy can be modified, or forked, for the specific container application while still sharing common OS components within the VCH. These containers cannot communicate with each other directly, preventing malware, crashes and other issues from disrupting a large number of containers simultaneously. Even Docker components are relegated to the VCH rather than individual containers, further reducing the size of each container. VMware calls this approach "just enough VM" to run a container.
What sets vSphere Integrated Containers apart from other containers?
An exploration of VMware's container storage strategy
Docker trumps the container technology competition in cloud
Dig Deeper on VMware new releases and updates
Related Q&A from Stephen J. Bigelow
One size does not fit all when administrators develop a protection policy for specific applications. Learn about the configuration options in System ...continue reading
Set up and operate a VM network using proven strategies to ensure security and performance. With a little planning, virtualization admins can avoid ...continue reading
Virtual switch security is achieved through a number of features. Virtualization admins can create and enforce policies, lock down MAC addresses and ...continue reading
Have a question for an expert?
Please add a title for your question
Get answers from a TechTarget expert on whatever's puzzling you.