Release of Container Management System Incus 0.3

The third release of the Incus project has been introduced, in which the Linux Containers community develops a fork of the container management system LXD, created by the original development team that once built LXD. The Incus code is written in Go and is distributed under the Apache 2.0 license.

Recall that the Linux Containers community oversaw the development of LXD until Canonical decided to develop LXD separately as a corporate project. The goal of the fork is to provide a managed alternative to the LXD project, controlled by Canonical, by an independent community. The Incus project also aims to address some conceptual errors made in LXD's development, which could previously not be corrected without breaking backward compatibility.

Incus provides tools for centralized management of containers and virtual machines deployed on both a single host and a cluster of multiple hosts. serversThe project is implemented as a background process that accepts network requests through a REST API and supports various storage backends (directory trees, ZFS, Btrfs, LVM), stateful snapshots, live migration of running containers from one machine to another, and tools for storing container images. LXC is used as the runtime for launching containers, including the liblxc library, a set of utilities (lxc-create, lxc-start, lxc-stop, lxc-ls, etc.), templates for building containers, and a set of bindings for various programming languages. Isolation is achieved using standard Linux kernel mechanisms (namespaces, cgroups, AppArmor, SELinux, Seccomp).

The most notable changes are:

  • Support for managing user authorization based on the Relationship-Based Access Control model, implemented through a background OpenFGA process responsible for making decisions regarding user permissions. In combination with the OpenID Connect provider, OpenFGA support allows for the formation of an open stack for identification and authorization, enabling Incus to serve as a complete alternative to Canonical RBAC configurations for LXD. Parameters for configuring access to OpenFGA include openfga.api.token, openfga.api.url, openfga.store.id, and openfga.store.model_id.
  • The lxd-to-incus utility has been improved, automating the migration from LXD to Incus. The new version adds support for distributions with the OpenRC init system, implements the ability to transfer Ceph storage and OVN networks, ensures migration logging, and creates backups.
  • In virtual machines Support for hot-plugging and hot-removing file paths or individual partitions passed from the host environment has been added. Previously, such passthrough using the virtio-fs driver or 9p FS required stopping the virtual machine. To bypass this limitation, QEMU's hot-plug capability for PCI devices and mounting paths within the guest system through incus-agent has been utilized.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster