Replies: 1 comment
|
You're reading it correctly: the comparison figure predates gVisor's Docker support. What that tutorial requires, and what it means for security:
The trade-offs versus Sysbox are compatibility, performance and operations rather than "one works, one doesn't". gVisor re-implements syscalls in user space, so some workloads behave differently or run slower (heavy I/O especially), but it's a managed checkbox on GKE (Standard and Autopilot). Sysbox runs containers on the host kernel with user-namespace isolation, so software inside behaves more like a VM, and it does support GKE. Its install guide lists GKE with Ubuntu-Containerd or Ubuntu-Docker node images, so it needs a Standard cluster with an Ubuntu node pool; Autopilot does not let you pick node images. |
Uh oh!
There was an error while loading. Please reload this page.
I use GKE myself and would like to ask you (the community) for advice regarding running Docker safely within a Kubernetes container.
The README of this project states in the picture https://github.com/nestybox/sysbox/raw/master/docs/figures/sysbox-comparison.png that Docker is not available as a workload inside of a gvisor container.
According to this tutorial: https://gvisor.dev/docs/tutorials/docker-in-gke-sandbox/ this should work however.
Is the picture outdated or am I misunderstanding the security implications when using Docker inside of a gvisor Kubernetes Pod (rootful Docker inside of the gvisor pod, basically the gvisor pod is run with
rootuser, so Docker and further things can be used)I would like to double check, as I am looking for a secure option that allows installation of packages via
aptinside of a container, using Docker and other similar things inside of that Kubernetes podBig thanks in advance for any help here! :)
All reactions