Docker 一直都在使用微型虚拟机(准确地说,是从 2016 年开始)。
Docker has always used microVMs (well since 2016)

原始链接: https://dave.recoil.org/docker-has-always-used-microvms/

Docker 长期以来一直使用轻量级虚拟化技术,在 macOS 和 Windows 上安全运行容器。Docker Toolbox 依赖功能繁重的 VirtualBox 后,Docker 开发了一款 minimalist、可嵌入的虚拟机监控器(VMM),让 Docker Desktop 的使用体验更接近原生应用。其最初实现 hyperkit 后来演变为 Docker VMM,并采用了基于 LinuxKit 的精简内核和根文件系统。 这种 microVM 架构支持跨平台无根运行,宿主机与客户机之间的接口更小、更便于审计,同时具备更强的隔离能力:攻破不受信任的客户机内核不会直接危及宿主机。它还能与 VPN 良好集成,并支持镜像仓库访问控制等网络策略。 同一技术也为 Docker Sandboxes 提供了基础,使编程智能体和其他工作负载能够在严格的隔离、安全和治理机制下运行,例如通过 `sbx run claude` 启动。尽管最初设计为类库式的 unikernel 进程,但由于技术原因,当前实现仍会为每台虚拟机保留一个轻量级宿主机进程。

The Hacker News 上的讨论质疑了“Docker 一直都在使用 microVM”这一说法,并指出这主要适用于 macOS 和 Windows 上的 Docker Desktop,而不是 Linux 上原生运行的 Docker。据报道,自 2016 年起,Docker Desktop 就在轻量级、基于 QEMU 的虚拟机中运行 Linux 容器;较新的版本则使用 Apple 的虚拟化框架。 评论者讨论了这究竟是新技术,还是对旧有虚拟化方案的重新包装。他们指出,与传统容器共享同一个内核相比,虚拟机可以减少内核攻击面并简化隔离机制。不过,Docker Sandboxes 引发了有关数据保留的担忧,而且据称其安全模型也不同于早期 microVM 实现。 其他讨论点还包括:Firecracker 在 Docker-in-Docker 中的实用性、微软的 WSL 和 `wslc`、jail、zone、WPAR 等历史隔离系统,以及“每个工作负载使用一个虚拟机”的系统能否为多租户环境提供比传统容器更强的安全性。
相关文章

原文

There's a lot of buzz about "microVMs", where a workload runs with a stripped down Linux kernel, on a minimalist VMM such as firecracker (announced at re:Invent 2018) on top of a hypervisor like KVM or Xen. MicroVMs are often contrasted to, and considered more secure than, traditional Linux Docker containers. What if I told you that Docker Desktop has always used microVMs?

Always has been meme: wait, Docker uses microVMs? Always has been (since 2016)

Docker Toolbox logo When I joined Docker in 2015 the state of the art was Docker Toolbox. It used VirtualBox, which is a great product with lots of features. VirtualBox has its own GUI and its own update process; way more than we needed for Docker.

We wanted Docker to feel like a native app on Mac and Windows, rather than a bundle of components. Using our Mirage Unikernel libraries we started building a "library VMM": a VMM which could be embedded inside the Docker application, and which would be single purpose, minimal, secure and fast. The first version was called hyperkit and the most recent one is Docker VMM.1

The VM kernel and root filesystem were minimal too, based on the LinuxKit project. The current version is an even more slimmed down and efficient variant but conceptually the same, similar to containerd/nerdbox.

For Docker for Mac (later renamed Docker Desktop) this allowed:

  • Running rootless on all platforms. Without requiring "rootless inside Linux": the whole Linux kernel is untrusted, so even a Linux CVE doesn't matter.
  • Minimal devices. We could carefully limit the host / VM interface, making it easy to understand and audit.
  • VPNs and network policy. It was easy to interoperate with VPNs, and to extend later to impose networking policy such as Registry Access Management.

CACM 2026 - A Decade of Docker Containers

The Docker microVM tech is the foundation of both Docker Desktop and also Docker Sandboxes (why microVMs). Docker Sandboxes enables you to do things like run your favourite coding agent and harness securely, with strict isolation and governance.

To see what Docker microVM's can do, install Docker Sandboxes (sbx) and try `sbx run claude`.

To read more about the history of the tech, check out the article A Decade of Docker Containers (Communications of the ACM).

1 Although we were aiming to make everything a library and link into a static unikernel-like process, for technical reasons it makes sense to still have a single host process per VM. ↩

联系我们 contact @ memedata.com