Learning path

Full curriculum

Full curriculum

Unit content

Virtualization and containers

Operating systems already isolate processes, but software deployment often needs stronger or more reproducible boundaries. Virtualization and containers provide different ways to create those environments.

Virtual machines

A virtual machine emulates or virtualizes enough hardware to run its own guest operating system.

hardware
  ↓
hypervisor
  ↓
guest OS
  ↓
applications

The guest kernel is separate from the host kernel.

Containers

A container usually runs ordinary host processes with operating-system isolation around resources such as process identifiers, filesystems and resource limits.

host kernel
  ↓
isolated processes

Containers therefore do not normally contain a separate kernel of their own.

Isolation and resource control

Operating-system mechanisms can give a group of processes a restricted view of resources and limit how much CPU or memory they consume.

Isolation is not absolute security by definition; the strength of the boundary depends on the implementation and configuration.

Images and reproducibility

Container systems commonly create filesystem environments from versioned images. Reusing the same image helps reproduce the software and dependencies surrounding an application.

Virtual machines isolate by virtualizing a whole machine environment; containers isolate processes while sharing the host kernel. The appropriate choice depends on the boundary and compatibility required.