Release of the container management system LXC 5.0

Canonical has released the toolkit for organizing the operation of isolated containers LXC 5.0, providing a runtime suitable for launching containers with a full system environment, akin to virtual machines, as well as for running unprivileged containers of individual applications (OCI). LXC is categorized as a low-level toolkit operating at the level of individual containers. For centralized management of containers deployed in a cluster of several servers, the LXD system based on LXC is being developed. The LXC 5.0 branch is classified as a long-term support release, with updates provided for 5 years. The LXC code is written in C and is distributed under the GPLv2 license.

LXC includes the liblxc library, a set of utilities (lxc-create, lxc-start, lxc-stop, lxc-ls, etc.), templates for building containers, and a set of bindings for various programming languages. Isolation is implemented using the standard mechanisms of the Linux kernel. The namespace mechanism is used for isolating processes, network stacks, ipc, uts, user IDs, and mount points. Resource limits are enforced using cgroups. Kernel features such as Apparmor and SELinux profiles, Seccomp policies, Chroots (pivot_root), and capabilities are utilized to reduce privileges and restrict access.

Key Changes:

  • The transition from autotools to the Meson build system has been made, which is also used for building such projects as X.Org Server, Mesa, Lighttpd, systemd, GStreamer, Wayland, GNOME, and GTK.
  • New options for configuring cgroups have been added — lxc.cgroup.dir.container, lxc.cgroup.dir.monitor, lxc.cgroup.dir.monitor.pivot, and lxc.cgroup.dir.container.inner, which allow for the explicit definition of cgroup paths for the container, monitoring process, and nested cgroup hierarchies.
  • Support for time namespaces has been added to bind a separate state of the system clock to the container, enabling the use of its own time different from the system time. Configuration options lxc.time.offset.boot and lxc.time.offset.monotonic are proposed to set the offset for the container relative to the primary system clocks.
  • Support for VLAN has been implemented for virtual ethernet adapters (Veth). Configuration options for managing VLAN include veth.vlan.id for setting the primary VLAN and veth.vlan.tagged.id for binding additional tagged VLANs.
  • For virtual ethernet adapters, the ability to configure the size of receive and transmit queues has been added with new options veth.n_rxqueues and veth.n_txqueues.

Source: opennet.ru

Buy reliable website hosting with DDoS protection, VPS VDS servers 🔥 Buy reliable website hosting with DDoS protection, VPS VDS servers | ProHoster