ืฉื—ืจื•ืจ ืฉืœ Kata Containers 3.0 ืขื ื‘ื™ื“ื•ื“ ืžื‘ื•ืกืก ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื”

ืœืื—ืจ ืฉื ืชื™ื™ื ืฉืœ ืคื™ืชื•ื—, ื™ืฆื ืœืื•ืจ ืคืจื•ื™ืงื˜ Kata Containers 3.0, ื”ืžืคืชื— ืžื—ืกื ื™ืช ืœืืจื’ื•ืŸ ื‘ื™ืฆื•ืข ืงื•ื ื˜ื™ื™ื ืจื™ื ื‘ืืžืฆืขื•ืช ื‘ื™ื“ื•ื“ ื”ืžื‘ื•ืกืก ืขืœ ืžื ื’ื ื•ื ื™ ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื” ืžืœืื™ื. ื”ืคืจื•ื™ืงื˜ ื ื•ืฆืจ ืขืœ ื™ื“ื™ ืื™ื ื˜ืœ ื•ื”ื™ืคืจ ืขืœ ื™ื“ื™ ืฉื™ืœื•ื‘ ืฉืœ Clear Containers ื•ื˜ื›ื ื•ืœื•ื’ื™ื•ืช runV. ืงื•ื“ ื”ืคืจื•ื™ืงื˜ ื›ืชื•ื‘ ื‘-Go and Rust, ื•ืžื•ืคืฅ ืชื—ืช ืจื™ืฉื™ื•ืŸ Apache 2.0. ืคื™ืชื•ื— ื”ืคืจื•ื™ืงื˜ ืžืคื•ืงื— ืขืœ ื™ื“ื™ ืงื‘ื•ืฆืช ืขื‘ื•ื“ื” ืฉื ื•ืฆืจื” ื‘ื—ืกื•ืช ื”ืืจื’ื•ืŸ ื”ืขืฆืžืื™ OpenStack Foundation, ื”ื›ื•ืœืœืช ื—ื‘ืจื•ืช ื›ืžื• Canonical, China Mobile, Dell/EMC, EasyStack, Google, Huawei, NetApp, Red Hat, SUSE ื•-ZTE .

ื‘ืœื™ื‘ื” ืฉืœ Kata ื”ื•ื ื–ืžืŸ ื”ืจื™ืฆื”, ื”ืžืกืคืง ืืช ื”ื™ื›ื•ืœืช ืœื™ืฆื•ืจ ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืงื•ืžืคืงื˜ื™ื•ืช ื”ืคื•ืขืœื•ืช ื‘ืืžืฆืขื•ืช ื”ื™ืคืจื•ื•ื™ื–ืจ ืžืœื, ื‘ืžืงื•ื ืœื”ืฉืชืžืฉ ื‘ืงื•ื ื˜ื™ื™ื ืจื™ื ืžืกื•ืจืชื™ื™ื ื”ืžืฉืชืžืฉื™ื ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ื ืคื•ืฆื” ื•ืžื‘ื•ื“ื“ื™ื ื‘ืืžืฆืขื•ืช ืžืจื—ื‘ื™ ืฉืžื•ืช ื•-cgroups. ื”ืฉื™ืžื•ืฉ ื‘ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืžืืคืฉืจ ืœืš ืœื”ื’ื™ืข ืœืจืžืช ืื‘ื˜ื—ื” ื’ื‘ื•ื”ื” ื™ื•ืชืจ ื”ืžื’ื ื” ืžืคื ื™ ื”ืชืงืคื•ืช ื”ื ื’ืจืžื•ืช ืžื ื™ืฆื•ืœ ืฉืœ ื ืงื•ื“ื•ืช ืชื•ืจืคื” ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก.

Kata Containers ืžืชืžืงื“ืช ื‘ืื™ื ื˜ื’ืจืฆื™ื” ื‘ืชืฉืชื™ื•ืช ืงื™ื™ืžื•ืช ืฉืœ ื‘ื™ื“ื•ื“ ืงื•ื ื˜ื™ื™ื ืจื™ื ืขื ื™ื›ื•ืœืช ืœื”ืฉืชืžืฉ ื‘ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ื“ื•ืžื•ืช ื›ื“ื™ ืœืฉืคืจ ืืช ื”ื”ื’ื ื” ืขืœ ืงื•ื ื˜ื™ื™ื ืจื™ื ืžืกื•ืจืชื™ื™ื. ื”ืคืจื•ื™ืงื˜ ืžืกืคืง ืžื ื’ื ื•ื ื™ื ืœื”ื‘ื˜ื—ืช ืชืื™ืžื•ืช ืฉืœ ืžื›ื•ื ื•ืช ื•ื™ืจื˜ื•ืืœื™ื•ืช ืงืœื•ืช ืžืฉืงืœ ืขื ืชืฉืชื™ื•ืช ืฉื•ื ื•ืช ืฉืœ ื‘ื™ื“ื•ื“ ืงื•ื ื˜ื™ื™ื ืจื™ื, ืคืœื˜ืคื•ืจืžื•ืช ืชื–ืžื•ืจ ื•ืžืคืจื˜ื™ ืงื•ื ื˜ื™ื™ื ืจื™ื ื›ื’ื•ืŸ OCI (Open Container Initiative), CRI (Container Runtime Interface) ื•-CNI (Container Networking Interface). ื›ืœื™ื ื–ืžื™ื ื™ื ืœืฉื™ืœื•ื‘ ืขื Docker, Kubernetes, QEMU ื•-OpenStack.

ืฉื—ืจื•ืจ ืฉืœ Kata Containers 3.0 ืขื ื‘ื™ื“ื•ื“ ืžื‘ื•ืกืก ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื”

ืื™ื ื˜ื’ืจืฆื™ื” ืขื ืžืขืจื›ื•ืช ื ื™ื”ื•ืœ ืงื•ื ื˜ื™ื™ื ืจื™ื ืžื•ืฉื’ืช ื‘ืืžืฆืขื•ืช ืฉื›ื‘ื” ื”ืžื“ืžื” ื ื™ื”ื•ืœ ืงื•ื ื˜ื™ื™ื ืจื™ื, ื”ื ื™ื’ืฉืช ืœืกื•ื›ืŸ ื”ืžื ื”ืœ ื‘ืžื›ื•ื ื” ื”ื•ื™ืจื˜ื•ืืœื™ืช ื“ืจืš ืžืžืฉืง gRPC ื•ืคืจื•ืงืกื™ ืžื™ื•ื—ื“. ื‘ืชื•ืš ื”ืกื‘ื™ื‘ื” ื”ื•ื™ืจื˜ื•ืืœื™ืช, ืืฉืจ ืžื•ืฉืงืช ืขืœ ื™ื“ื™ ื”-Hypervisor, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืœื™ื‘ืช ืœื™ื ื•ืงืก ืžื•ืชืืžืช ื‘ืžื™ื•ื—ื“, ื”ืžื›ื™ืœื” ืจืง ืืช ืงื‘ื•ืฆืช ื”ื™ื›ื•ืœื•ืช ื”ืžื™ื ื™ืžืœื™ืช ื”ื ื—ื•ืฆื”.

ื‘ืชื•ืจ ื”ื™ืคืจื•ื•ื™ื–ืจ, ื”ื•ื ืชื•ืžืš ื‘ืฉื™ืžื•ืฉ ื‘-Dragonball Sandbox (ืžื”ื“ื•ืจื” ืฉืœ KVM ื”ืžื•ืชืืžืช ืœืžื›ื•ืœื•ืช) ืขื ืขืจื›ืช ื”ื›ืœื™ื QEMU, ื›ืžื• ื’ื Firecracker ื•-Cloud Hypervisor. ืกื‘ื™ื‘ืช ื”ืžืขืจื›ืช ื›ื•ืœืœืช ื“ืžื•ืŸ ืืชื—ื•ืœ ื•ืกื•ื›ืŸ. ื”ืกื•ื›ืŸ ืžืกืคืง ื‘ื™ืฆื•ืข ืฉืœ ืชืžื•ื ื•ืช ืžื™ื›ืœ ื”ืžื•ื’ื“ืจื•ืช ืขืœ ื™ื“ื™ ืžืฉืชืžืฉ ื‘ืคื•ืจืžื˜ OCI ืขื‘ื•ืจ Docker ื•-CRI ืขื‘ื•ืจ Kubernetes. ื‘ืฉื™ืžื•ืฉ ื‘ืฉื™ืœื•ื‘ ืขื Docker, ื ื•ืฆืจืช ืžื›ื•ื ื” ื•ื™ืจื˜ื•ืืœื™ืช ื ืคืจื“ืช ืขื‘ื•ืจ ื›ืœ ืžื™ื›ืœ, ื›ืœื•ืžืจ. ื”ืกื‘ื™ื‘ื” ื”ืคื•ืขืœืช ืขืœ ื’ื‘ื™ ื”-Hypervisor ืžืฉืžืฉืช ืœื”ืคืขืœื” ืžืงื•ื ื ืช ืฉืœ ืžื›ื•ืœื•ืช.

ืฉื—ืจื•ืจ ืฉืœ Kata Containers 3.0 ืขื ื‘ื™ื“ื•ื“ ืžื‘ื•ืกืก ื•ื™ืจื˜ื•ืืœื™ื–ืฆื™ื”

ื›ื“ื™ ืœืฆืžืฆื ืืช ืฆืจื™ื›ืช ื”ื–ื™ื›ืจื•ืŸ, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ืžื ื’ื ื•ืŸ DAX (ื’ื™ืฉื” ื™ืฉื™ืจื” ืœืžืขืจื›ืช ื”ืงื‘ืฆื™ื, ืขืงื™ืคืช ืžื˜ืžื•ืŸ ื”ืขืžื•ื“ื™ื ืœืœื ืฉื™ืžื•ืฉ ื‘ืจืžืช ื”ืชืงืŸ ื”ื—ืกื™ืžื”), ื•ืœื‘ื™ื˜ื•ืœ ืฉื›ืคื•ืœ ืฉืœ ืื–ื•ืจื™ ื–ื™ื›ืจื•ืŸ ื–ื”ื™ื, ื ืขืฉื” ืฉื™ืžื•ืฉ ื‘ื˜ื›ื ื•ืœื•ื’ื™ื™ืช KSM (Kernel Samepage Merging) ื”ืžืืคืฉืจืช ืœืš ื›ื“ื™ ืœืืจื’ืŸ ืืช ื”ืฉื™ืชื•ืฃ ืฉืœ ืžืฉืื‘ื™ ืžืขืจื›ืช ืžืืจื— ื•ืœื”ืชื—ื‘ืจ ืœืžืขืจื›ื•ืช ืื•ืจื—ื•ืช ืฉื•ื ื•ืช, ืฉืชืคื• ืชื‘ื ื™ืช ืกื‘ื™ื‘ืช ืžืขืจื›ืช ืžืฉื•ืชืคืช.

ื‘ื’ืจืกื” ื”ื—ื“ืฉื”:

  • ืžื•ืฆืข ื–ืžืŸ ืจื™ืฆื” ื—ืœื•ืคื™ (Runtime-rs), ื”ื™ื•ืฆืจ ืžื™ืœื•ื™ ืฉืœ ืžื™ื›ืœื™ื, ื”ื›ืชื•ื‘ื™ื ื‘ืฉืคืช Rust (ื–ืžืŸ ื”ืจื™ืฆื” ืฉืกื•ืคืง ืงื•ื“ื ืœื›ืŸ ื ื›ืชื‘ ื‘ืฉืคืช Go). ื–ืžืŸ ืจื™ืฆื” ืชื•ืื ืœ-OCI, CRI-O ื•-Containerd, ื•ืžืืคืฉืจ ืœื”ืฉืชืžืฉ ื‘ื• ืขื Docker ื•-Kubernetes.
  • ื”ื•ืฆืข hypervisor ื—ื“ืฉ ืฉืœ Dragonball ื”ืžื‘ื•ืกืก ืขืœ KVM ื•-rust-vmm.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืœื”ืขื‘ืจืช ื’ื™ืฉื” ืœ-GPU ื‘ืืžืฆืขื•ืช VFIO.
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ cgroup v2.
  • ืชืžื™ื›ื” ื‘ืฉื™ื ื•ื™ ื”ื’ื“ืจื•ืช ืžื‘ืœื™ ืœืฉื ื•ืช ืืช ืงื•ื‘ืฅ ื”ืชืฆื•ืจื” ื”ืจืืฉื™ ื™ื•ืฉืžื” ืขืœ ื™ื“ื™ ื”ื—ืœืคืช ื‘ืœื•ืงื™ื ื‘ืงื‘ืฆื™ื ื ืคืจื“ื™ื ื”ืžืžื•ืงืžื™ื ื‘ืกืคืจื™ื™ืช "config.d/".
  • ืจื›ื™ื‘ื™ ื—ืœื•ื“ื” ื›ื•ืœืœื™ื ืกืคืจื™ื™ื” ื—ื“ืฉื” ืœืขื‘ื•ื“ื” ืžืื•ื‘ื˜ื—ืช ืขื ื ืชื™ื‘ื™ ืงื‘ืฆื™ื.
  • ืจื›ื™ื‘ virtiofsd (ื›ืชื•ื‘ ื‘-C) ื”ื•ื—ืœืฃ ื‘-virtiofsd-rs (ื›ืชื•ื‘ ื‘-Rust).
  • ื ื•ืกืคื” ืชืžื™ื›ื” ืขื‘ื•ืจ ืจื›ื™ื‘ื™ QEMU ืฉืœ ืืจื’ื– ื—ื•ืœ.
  • QEMU ืžืฉืชืžืฉ ื‘ืžืžืฉืง ื”-API ืฉืœ io_uring ืขื‘ื•ืจ I/O ืืกื™ื ื›ืจื•ื ื™.
  • ื”ื•ื˜ืžืขื” ืชืžื™ื›ื” ื‘ื”ืจื—ื‘ื•ืช Intel TDX (ื”ืจื—ื‘ื•ืช ื“ื•ืžื™ื™ืŸ ืžื”ื™ืžื ื•ืช) ืขื‘ื•ืจ QEMU ื•-Cloud-hypervisor.
  • ืจื›ื™ื‘ื™ื ืžืขื•ื“ื›ื ื™ื: QEMU 6.2.0, Cloud-hypervisor 26.0, Firecracker 1.1.0, ืœื™ื‘ืช ืœื™ื ื•ืงืก 5.19.2.

ืžืงื•ืจ: OpenNet.ru

ื”ื•ืกืคืช ืชื’ื•ื‘ื”