Containers Seus containers estão seguros? · Marcos Sungaila marcos.sungaila@oracle.com Faça um...

Post on 06-Jul-2020

3 views 0 download

Transcript of Containers Seus containers estão seguros? · Marcos Sungaila marcos.sungaila@oracle.com Faça um...

ContainersSeus containers estão seguros?Marcos Sungaila

.

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. | Confidential – Oracle Internal/Restricted/Highly Restricted

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. | Confidential – Oracle Internal/Restricted/Highly Restricted 2

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. | Confidential – Oracle Internal/Restricted/Highly Restricted

Containers

Host Linux Kernel

namespaces namespaces namespaces

Processo Processo Processo

CPU Memória DiscoRede

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. | Confidential – Oracle Internal/Restricted/Highly Restricted

Containers

Host Linux Kernel

namespaces namespaces namespaces

Processo Processo Processo

CPU Memória DiscoRede

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. | Confidential – Oracle Internal/Restricted/Highly Restricted

Só o controle por software não é suficiente!

Host Linux Kernel

namespaces namespaces namespaces

Processo Processo Processo

CPU Memória DiscoRede

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. | Confidential – Oracle Internal/Restricted/Highly Restricted

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. | Confidential – Oracle Internal/Restricted/Highly Restricted

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. | Confidential – Oracle Internal/Restricted/Highly Restricted

Isolamento manual!

Host físico

VM

Linux Kernel

namespaces namespaces namespaces

Processo Processo Processo

VM

Linux Kernel

namespaces namespaces namespaces

Processo Processo Processo

Rodar containers virtualizados de modo seguro

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. | Confidential – Oracle Internal/Restricted/Highly Restricted

Kata containers

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Baseado na apresentação

Kata Containers - The way to run virtualized containers

de Sebastien Boeuf, realizada no OpenStack Summit 2018 em Vancouver

Como surgiu?

Intel Clear Containers

Maio/2015 Dez/2017

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Kata Containers 101

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Kata Containers 101

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Kata Containers 101

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Integração

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Arquitetura

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Arquitetura simplificada

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - run

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - run

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - run

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - run

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - run

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - run

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - run

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - run

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - run

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - exec

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - exec

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - exec

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Ciclo de vida OCI - exec

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Mais do que apenas OCI

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. | Confidential – Oracle Internal/Restricted/Highly Restricted

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Compatibilidade com OCI

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

VM light – NVDIMM/DAX

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

VM light – KSM

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

VM? Usando templates

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

VM - hotplug

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

VM - hotplug

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Devices - virtio

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Devices – HW passthrough

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Devices – SR-IOV

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Network - MACVTAP

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Network – Traffic Control

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Storage – 9p

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Storage – block

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Host namespaces

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Multi OS

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Resumindo…

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Resumindo…

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Resumindo…

Copyright © 2019, Oracle and/or its affiliates. All rights reserved. |

Teste, use, contribua

Instalando kata containers: https://blogs.oracle.com/linux/kata-containers:-an-important-cloud-native-development-trend-v2

Get started:https://github.com/kata-containers/documentation/blob/ master/Developer-Guide.md

FAQ: https://katacontainers.io/faq/

Marcos Sungailamarcos.sungaila@oracle.comwww.linkedin.com/in/marcossungaila

www.oracle.com.br

Faça um Hands on

Ganhe um Brinde

Faça um Trial

Visite nosso Estande

Ganhe outro Brinde