Runj — An OCI-compatible toolkit for managing containers based on FreeBSD jail

Samuel Karp, an engineer at Amazon, is developing a new runtime called runj based on FreeBSD jail environments to ensure isolated container execution according to the OCI (Open Container Initiative) specification. The project is positioned as experimental, developed in his spare time, and is currently in the prototype stage. The code is written in Go and is distributed under the BSD license.

Once the development reaches the proper level, the project could potentially grow to the point where runj can replace the default runtime in Docker and Kubernetes systems, using FreeBSD for container execution instead of Linux. Currently, the OCI runtime implements commands for creating, deleting, starting, forcefully stopping, and checking the status of containers. The container's internals are created based on a standard or stripped-down FreeBSD environment.

Since the OCI specification currently lacks support for FreeBSD, the project has developed a number of additional parameters related to jail and FreeBSD configuration, which are planned to be submitted for inclusion in the main OCI specification. The jail is managed using utilities such as jail, jls, jexec, kill, and ps from FreeBSD, without directly calling system calls. Future plans include adding support for resource management through the RCTL kernel interface.

In addition to its own runtime, the project repository is also developing an experimental layer for use alongside the containerd runtime (used in Docker), modified to support FreeBSD. A special utility is proposed for converting the FreeBSD rootfs into an OCI-compatible container image. The created image can later be imported into containerd.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster