OS2ATC 2025 - 安全容器统一架构.pdf
1、安全容器统一架构1分享人:谈鉴锋2025.03背景:容器运行时VMrunvSandboxgVisorgVisor,Nabla,QuarkContainerMicroVM KATA,Firecracker,Cloud HypervisorLinux Containersruncrunc,crun,youki2背景:安全容器源于安全Wang,Xu,and Samuel Ortiz.Kata Containers:Hypervisor-Based Container Runtime.KubeCon North America,2017,HyperHQ&Intel.Chen,Dawn,and Zhen
2、gyu He.Container Isolation at Scale(Introducing gVisor).KubeCon Europe,May 2018,Google.Barr,Jeff.Firecracker Lightweight Virtualization for Serverless Computing.AWS re 2018,26 Nov.2018.Wang,Xu.Kata and gVisor:A Quantitative Comparison.hyper.sh,1013 Dec.2018.3AppsAppsAppsHost Linux KernelDaemonsetsSe
3、cure Container Runtime(Kata&gVisor&Firecracker)System servicesAppsL0:Final bastion,e.g.,Live-patch&eBPF-based LSML1:Jailer Barrier,e.g.,cgroup/chroot/namespace/capabilityL2:Sandbox,e.g.,Lock-in-Pop or VirtualizationGuest KernelL3:Customized kernel,e.g.,mem-safe,KSPCIPU/IPU/DPUDevice passthroughSecur
4、echannelL-1:IaaS security背景:安全容器不止于安全4性能隔离故障隔离定制内核“software interrupts a conglomerate of mostly unrelated jobs,which run in the context of a randomly chosen victimw/o the ability to put any control on them.”-Thomas Gleixner(Linux developer)安全容器是云原生基础设施必要组件!5蚂蚁的云原生节点架构节点组件L2:Virtualization&Sandbox,e.





点击查看更多