OS Hypervisor Guest kernel Guest OS Guest kernel Guest OS LXD shared compute node Linux kernel LXD exclusive compute node Linux kernel Host OS Guest OS Host OS Guest OS Guest OS Guest OS Guest OS
kernel Host OS Hypervisor Guest kernel Guest OS Guest kernel Guest OS LXD shared compute node Linux kernel LXD exclusive compute node Linux kernel Host OS Guest OS Host OS Guest OS Guest OS Guest OS Guest OS Juju Ansible Heat, etc.
is optimized for the deployment of applications, as opposed to machines. This is reflected in its API, user interface, design philosophy and documentation. By contrast, the lxc helper scripts focus on containers as lightweight machines ― https://docs.docker.com/engine/faq/
kernel Guest OS Guest kernel Guest OS Container worker node Linux kernel Host OS Guest OS Guest OS Guest OS Guest OS カーネル脆弱性対応アップデートは再起動が必要。 ワークロードの退避が必要なため、台数が増えるにつれて 負担になる。 • ワークロードの退避 /他ホス トへのマイグレーション • 更新カーネルのインストー ル • 再起動 • ワークロードの再移動
kernel Guest OS Guest kernel Guest OS Container worker node Linux kernel Host OS Guest OS Guest OS Guest OS Guest OS Livepatchを使うと再起動することなくカーネルの脆弱性対応パッ チがあてられる。 Livepatch