ืžืขืœื“ื•ื ื’ ืคื•ืŸ ืงืึทื˜ืึท ืงืึทื ื˜ื™ื™ื ืขืจื– 3.0 ืžื™ื˜ ื•ื•ื™ืจื˜ื•ืึทืœื™ื–ืึทื˜ื™ืึธืŸ-ื‘ืื–ื™ืจื˜ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜

ื ืึธืš ืฆื•ื•ื™ื™ ื™ืึธืจ ืคื•ืŸ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’, ื“ื™ ืžืขืœื“ื•ื ื’ ืคื•ืŸ ื“ื™ Kata Containers 3.0 ืคึผืจื•ื™ืขืงื˜ ืื™ื– ืืจื•ื™ืก, ื“ืขื•ื•ืขืœืึธืคึผื™ื ื’ ืึท ืึธื ืœื™ื™ื’ืŸ ืคึฟืึทืจ ืึธืจื’ืึทื ื™ื™ื–ื™ื ื’ ื“ื™ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื– ื ื™ืฆืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ ืคื•ืœ-ืคืœืขื“ื–ืฉื“ ื•ื•ื™ืจื˜ื•ืึทืœื™ื–ืึทื˜ื™ืึธืŸ ืžืขืงืึทื ื™ื–ืึทืžื–. ื“ื™ ืคึผืจื•ื™ืขืงื˜ ืื™ื– ื’ืขื•ื•ืขืŸ ื‘ืืฉืืคืŸ ื“ื•ืจืš ื™ื ื˜ืขืœ ืื•ืŸ ื”ื™ืคึผืขืจ ื“ื•ืจืš ืงืึทืžื‘ื™ื™ื ื™ื ื’ ืงืœืึธืจ ืงืึทื ื˜ื™ื™ื ืขืจื– ืื•ืŸ ืจื•ื ื•ื• ื˜ืขืงื ืึทืœืึทื“ื–ืฉื™ื–. ื“ื™ ืคึผืจื•ื™ืขืงื˜ ืงืึธื“ ืื™ื– ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ ื’ื™ื™ืŸ ืื•ืŸ ืจื•ืกื˜, ืื•ืŸ ืื™ื– ืคื•ื ืื ื“ืขืจื’ืขื˜ื™ื™ืœื˜ ืื•ื ื˜ืขืจ ื“ื™ Apache 2.0 ื“ืขืจืœื•ื™ื‘ืขื ื™ืฉ. ื“ื™ ืึทื ื˜ื•ื•ื™ืงืœื•ื ื’ ืคื•ืŸ ื“ื™ ืคึผืจื•ื™ืขืงื˜ ืื™ื– ืึธื•ื•ื•ืขืจืกื™ ื“ื•ืจืš ืึท ืึทืจื‘ืขื˜ ื’ืจื•ืคึผืข ื‘ืืฉืืคืŸ ืื•ื ื˜ืขืจ ื“ื™ ืึธื•ืกืคึผื™ืกื™ื– ืคื•ืŸ ื“ื™ ืคืจื™ื™ึท ืึธืจื’ืึทื ื™ื–ืึทืฆื™ืข OpenStack Foundation, ื•ื•ืึธืก ื™ื ืงืœื•ื“ื– ืงืึธืžืคึผืึทื ื™ืขืก ืึทื–ืึท ื•ื•ื™ ืงืึทื ืึธื ื™ืงืึทืœ, ื˜ืฉื™ื™ื ืึท ืžืึธื‘ื™ืœ, Dell / EMC, EasyStack, Google, Huawei, NetApp, Red Hat, SUSE ืื•ืŸ ZTE .

ืื™ืŸ ื“ื™ ื”ืึทืจืฅ ืคื•ืŸ ืงืึทื˜ืึท ืื™ื– ื“ื™ ืจื•ื ื˜ื™ืžืข, ื•ื•ืึธืก ื’ื™ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ืฉืึทืคึฟืŸ ืกืึธืœื™ื“ ื•ื•ื™ืจื˜ื•ืึทืœ ืžืืฉื™ื ืขืŸ ื•ื•ืึธืก ืœื•ื™ืคืŸ ืžื™ื˜ ืึท ืคื•ืœ ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ, ืึทื ืฉื˜ืึธื˜ ืคื•ืŸ ื ื™ืฆืŸ ื˜ืจืื“ื™ืฆื™ืื ืขืœืŸ ืงืึทื ื˜ื™ื™ื ืขืจื– ื•ื•ืึธืก ื ื•ืฆืŸ ืึท ืคึผืจืึธืกื˜ ืœื™ื ื•ืงืก ืงืขืจืŸ ืื•ืŸ ื–ืขื ืขืŸ ืืคื’ืขื–ื•ื ื“ืขืจื˜ ืžื™ื˜ ื ืึทืžืขืกืคึผืึทืกืขืก ืื•ืŸ ืงื’ืจื•ืคึผืก. ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ื•ื•ื™ืจื˜ื•ืึทืœ ืžืืฉื™ื ืขืŸ ืึทืœืึทื•ื– ืื™ืจ ืฆื• ื“ืขืจื’ืจื™ื™ื›ืŸ ืึท ื”ืขื›ืขืจ ืžื“ืจื’ื” ืคื•ืŸ ื–ื™ื›ืขืจื”ื™ื™ื˜ ื•ื•ืึธืก ืคึผืจืึทื˜ืขืงืฅ ืงืขื’ืŸ ืื ืคืืœืŸ ื’ืขืคึฟื™ืจื˜ ื“ื•ืจืš ืขืงืกืคึผืœื•ื™ื˜ื™ื™ืฉืึทืŸ ืคื•ืŸ ื•ื•ืึทืœื ืขืจืึทื‘ื™ืœื™ื˜ื™ื– ืื™ืŸ ื“ื™ ืœื™ื ื•ืงืก ืงืขืจืŸ.

Kata Containers ืื™ื– ืคืึธื•ืงื™ืกื˜ ืื•ื™ืฃ ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ ืื™ืŸ ื™ื’ื–ื™ืกื˜ื™ื ื’ ืงืึทื ื˜ื™ื™ื ืขืจ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ ืžื™ื˜ ื“ื™ ืคื™ื™ื™ืงื™ื™ื˜ ืฆื• ื ื•ืฆืŸ ืขื ืœืขืš ื•ื•ื™ืจื˜ื•ืึทืœ ืžืืฉื™ื ืขืŸ ืฆื• ืคืึทืจื‘ืขืกืขืจืŸ ื“ื™ ืฉื•ืฅ ืคื•ืŸ ื˜ืจืื“ื™ืฆื™ืื ืขืœืŸ ืงืึทื ื˜ื™ื™ื ืขืจื–. ื“ื™ ืคึผืจื•ื™ืขืงื˜ ื’ื™ื˜ ืžืขืงืึทื ื™ื–ืึทืžื– ืฆื• ืขื ืฉื•ืจ ืงืึทืžืคึผืึทื˜ืึทื‘ื™ืœืึทื˜ื™ ืคื•ืŸ ืœื™ื™ื˜ื•ื•ื™ื™ื˜ ื•ื•ื™ืจื˜ื•ืึทืœ ืžืืฉื™ื ืขืŸ ืžื™ื˜ ืคืึทืจืฉื™ื“ืŸ ืงืึทื ื˜ื™ื™ื ืขืจ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜ ื™ื ืคืจืึทืกื˜ืจืึทืงื˜ืฉืขืจ, ืงืึทื ื˜ื™ื™ื ืขืจ ืึธืจืงืขืกื˜ืจืึทื˜ื™ืึธืŸ ืคึผืœืึทื˜ืคืึธืจืžืก ืื•ืŸ ืกืคึผืขืกืึทืคืึทืงื™ื™ืฉืึทื ื– ืึทื–ืึท ื•ื•ื™ OCI (Open Container Initiative), CRI (Container Runtime Interface) ืื•ืŸ CNI (Container Networking Interface). ืžื›ืฉื™ืจื™ื ื–ืขื ืขืŸ ื‘ืืจืขื›ื˜ื™ื’ื˜ ืคึฟืึทืจ ื™ื ืึทื’ืจื™ื™ืฉืึทืŸ ืžื™ื˜ Docker, Kubernetes, QEMU ืื•ืŸ OpenStack.

ืžืขืœื“ื•ื ื’ ืคื•ืŸ ืงืึทื˜ืึท ืงืึทื ื˜ื™ื™ื ืขืจื– 3.0 ืžื™ื˜ ื•ื•ื™ืจื˜ื•ืึทืœื™ื–ืึทื˜ื™ืึธืŸ-ื‘ืื–ื™ืจื˜ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜

ื™ื ื˜ืขื’ืจืึทื˜ื™ืึธืŸ ืžื™ื˜ ืงืึทื ื˜ื™ื™ื ืขืจ ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’ ืกื™ืกื˜ืขืžืขืŸ ืื™ื– ืึทื˜ืฉื™ื•ื•ื“ ืžื™ื˜ ืึท ืฉื™ื›ื˜ืข ื•ื•ืึธืก ืกื™ืžื™ืึทืœื™ื™ืฅ ืงืึทื ื˜ื™ื™ื ืขืจ ืคืึทืจื•ื•ืึทืœื˜ื•ื ื’, ื•ื•ืึธืก ืึทืงืกืขืก ื“ื™ ืึธื ืคื™ืจื•ื ื’ ืึทื’ืขื ื˜ ืื™ืŸ ื“ื™ ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ ื“ื•ืจืš ื“ื™ gRPC ืฆื•ื‘ื™ื ื“ ืื•ืŸ ืึท ืกืคึผืขืฆื™ืขืœ ืคึผืจืึทืงืกื™. ื™ืŸ ื“ื™ ื•ื•ื™ืจื˜ื•ืึทืœ ืกื•ื•ื™ื•ื•ืข, ื•ื•ืึธืก ืื™ื– ืœืึธื ื˜ืฉื˜ ื“ื•ืจืš ื“ื™ ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ, ืึท ืกืคึผืขืฆื™ืขืœ ืึธืคึผื˜ื™ืžื™ื–ืขื“ ืœื™ื ื•ืงืก ืงืขืจืŸ ืื™ื– ื’ืขื ื™ืฆื˜, ืžื™ื˜ ื‘ืœื•ื™ื– ื“ื™ ืžื™ื ื™ืžื•ื ื’ืึทื ื’ ืคื•ืŸ ื ื™ื™ื˜ื™ืง ืงื™ื™ืคึผืึทื‘ื™ืœืึทื˜ื™ื–.

ื•ื•ื™ ืึท ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ, ืขืก ืฉื˜ื™ืฆื˜ ื“ื™ ื ื•ืฆืŸ ืคื•ืŸ ื“ืจืึทื’ืึธื ื‘ืึทืœืœ ืกืึทื ื“ื‘ืึธืงืก (ืึทืŸ ืึทื“ื™ืฉืึทืŸ ืคื•ืŸ KVM ืึธืคึผื˜ื™ืžื™ื–ืขื“ ืคึฟืึทืจ ืงืึทื ื˜ื™ื™ื ืขืจื–) โ€‹โ€‹ืžื™ื˜ ื“ื™ QEMU ื˜ืึธืึธืœืงื™ื˜, ื•ื•ื™ ื’ืขื–ื•ื ื˜ ื•ื•ื™ Firecracker ืื•ืŸ Cloud Hypervisor. ื“ื™ ืกื™ืกื˜ืขื ืกื•ื•ื™ื•ื•ืข ื›ื•ืœืœ ืึทืŸ ื™ื ื™ื˜ื™ืึทืœื™ื–ืึทื˜ื™ืึธืŸ ื“ืขืžืึธืŸ ืื•ืŸ ืึทืŸ ืึทื’ืขื ื˜. ื“ืขืจ ืึทื’ืขื ื˜ ื’ื™ื˜ ื“ื•ืจื›ืคื™ืจื•ื ื’ ืคื•ืŸ ื‘ืึทื ื™ืฆืขืจ-ื“ื™ืคื™ื™ื ื“ ืงืึทื ื˜ื™ื™ื ืขืจ ื‘ื™ืœื“ืขืจ ืื™ืŸ OCI ืคึฟืึธืจืžืึทื˜ ืคึฟืึทืจ Docker ืื•ืŸ CRI ืคึฟืึทืจ Kubernetes. ื•ื•ืขืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืื™ืŸ ืงืึทื ื“ื–ืฉืึทื ื’ืงืฉืึทืŸ ืžื™ื˜ ื“ืึธืงืขืจ, ืึท ื‘ืึทื–ื•ื ื“ืขืจ ื•ื•ื™ืจื˜ื•ืึทืœ ืžืึทืฉื™ืŸ ืื™ื– ื‘ืืฉืืคืŸ ืคึฟืึทืจ ื™ืขื“ืขืจ ืงืึทื ื˜ื™ื™ื ืขืจ, ื“"ื”. ื“ื™ ืกื•ื•ื™ื•ื•ืข ืคืœื™ืกื ื“ื™ืง ืื•ื™ืฃ ืฉืคึผื™ืฅ ืคื•ืŸ ื“ื™ ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ ืื™ื– ื’ืขื ื™ืฆื˜ ืคึฟืึทืจ ื ืขืกื˜ืขื“ ืงืึทื˜ืขืจ ืคื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื–.

ืžืขืœื“ื•ื ื’ ืคื•ืŸ ืงืึทื˜ืึท ืงืึทื ื˜ื™ื™ื ืขืจื– 3.0 ืžื™ื˜ ื•ื•ื™ืจื˜ื•ืึทืœื™ื–ืึทื˜ื™ืึธืŸ-ื‘ืื–ื™ืจื˜ ืืคื’ืขื–ื•ื ื“ืขืจื˜ืงื™ื™ื˜

ืฆื• ืจืขื“ื•ืฆื™ืจืŸ ื–ื™ืงืึธืจืŸ ืงืึทื ืกืึทืžืฉืึทืŸ, ื“ื™ DAX ืžืขืงืึทื ื™ื–ืึทื ืื™ื– ื’ืขื ื™ืฆื˜ (ื“ื™ืจืขืงื˜ ืึทืงืกืขืก ืฆื• ื“ื™ ื˜ืขืงืข ืกื™ืกื˜ืขื, ื‘ื™ื™ืคึผืึทืกื™ื ื’ ื“ื™ ื‘ืœืึทื˜ ืงืึทืฉ ืึธืŸ ื ื™ืฆืŸ ื“ื™ ื‘ืœืึธืง ืžื™ื˜ืœ ืžื“ืจื’ื”), ืื•ืŸ ืฆื• ื“ืขื“ื•ืคึผืœื™ืงืึทื˜ ื™ื™ื“ืขื ื™ืงืึทืœ ื–ื›ึผืจื•ืŸ ื’ืขื‘ื™ื˜ืŸ, KSM (Kernel Samepage Merging) ื˜ืขื›ื ืึธืœืึธื’ื™ืข ืื™ื– ื’ืขื ื™ืฆื˜, ื•ื•ืึธืก ืึทืœืึทื•ื– ืื™ืจ ืฆื• ืึธืจื’ืึทื ื™ื–ื™ืจืŸ ื“ื™ ื™ื™ึทื ื˜ื™ื™ืœื•ื ื’ ืคื•ืŸ ื‘ืึทืœืขื‘ืึธืก ืกื™ืกื˜ืขื ืจืขืกื•ืจืกืŸ ืื•ืŸ ืคืึทืจื‘ื™ื ื“ืŸ ืฆื• ืคืึทืจืฉื™ื“ืขื ืข ื’ืึทืกื˜ ืกื™ืกื˜ืขืžืขืŸ ื˜ื™ื™ืœืŸ ืึท ืคึผืจืึธืกื˜ ืกื™ืกื˜ืขื ืกื•ื•ื™ื•ื•ืข ื˜ืขืžืคึผืœืึทื˜ืข.

ืื™ืŸ ื“ื™ ื ื™ื™ึทืข ื•ื•ืขืจืกื™ืข:

  • ืึทืŸ ืึธืœื˜ืขืจื ืึทื˜ื™ื•ื• ืจื•ื ื˜ื™ืžืข (ืจื•ื ื˜ื™ืžืข-ืจืก) ืื™ื– ืคืืจื’ืขืœื™ื™ื’ื˜, ื•ื•ืึธืก ืคืืจืžืขืŸ ื“ื™ ืคื™ืœื•ื ื’ ืคื•ืŸ ืงืึทื ื˜ื™ื™ื ืขืจื–, ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ ื“ื™ ืจื•ืกื˜ ืฉืคึผืจืึทืš (ื“ื™ ื‘ื™ื– ืึทื”ืขืจ ืกืึทืคึผืœื™ื™ื“ ืจื•ื ื˜ื™ืžืข ืื™ื– ื’ืขื•ื•ืขืŸ ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ ื“ื™ ื’ื™ื™ืŸ ืฉืคึผืจืึทืš). ืจื•ื ื˜ื™ืžืข ืื™ื– ืงืึทืžืคึผืึทื˜ืึทื‘ืึทืœ ืžื™ื˜ OCI, CRI-O ืื•ืŸ Containerd, ืึทืœืึทื•ื™ื ื’ ืขืก ืฆื• ื–ื™ื™ืŸ ื’ืขื•ื•ื™ื™ื ื˜ ืžื™ื˜ Docker ืื•ืŸ Kubernetes.
  • ื ื ื™ื™ึทืข ื“ืจืึทื’ืึธื ื‘ืึทืœืœ ื›ื™ื™ืคึผืขืจื•ื•ื™ื™ื–ืขืจ ื‘ืื–ื™ืจื˜ ืื•ื™ืฃ KVM ืื•ืŸ ื–ืฉืึทื•ื•ืขืจ-ื•ื•ืžื ืื™ื– ืคืืจื’ืขืœื™ื™ื’ื˜.
  • ืฆื•ื’ืขืœื™ื™ื’ื˜ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ืคืึธืจื•ื•ืขืจื“ื™ื ื’ ืึทืงืกืขืก ืฆื• ื“ื™ ื’ืคึผื• ื ื™ืฆืŸ VFIO.
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ cgroup v2.
  • ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื˜ืฉืึทื ื’ื™ื ื’ ืกืขื˜ื˜ื™ื ื’ืก ืึธืŸ ื˜ืฉืึทื ื’ื™ื ื’ ื“ื™ ื”ื•ื™ืคึผื˜ ืงืึทื ืคื™ื’ื™ืขืจื™ื™ืฉืึทืŸ ื˜ืขืงืข ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“ ื“ื•ืจืš ืจื™ืคึผืœื™ื™ืกื™ื ื’ ื‘ืœืึทืงืก ืื™ืŸ ื‘ืึทื–ื•ื ื“ืขืจ ื˜ืขืงืขืก ืื™ืŸ ื“ื™ "config.d/" ื•ื•ืขื’ื•ื•ื™ื™ึทื–ืขืจ.
  • ื–ืฉืึทื•ื•ืขืจ ืงืึทืžืคึผืึธื•ื ืึทื ืฅ ืึทืจื™ื™ึทื ื ืขืžืขืŸ ืึท ื ื™ื™ึทืข ื‘ื™ื‘ืœื™ืึธื˜ืขืง ืคึฟืึทืจ ืกื™ืงื™ื•ืจืœื™ ืืจื‘ืขื˜ืŸ ืžื™ื˜ ื˜ืขืงืข ืคึผืึทื˜ืก.
  • ื“ื™ ื•ื•ื™ืจื˜ื™ืึธืคืกื“ ืงืึธืžืคึผืึธื ืขื ื˜ (ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ C) ืื™ื– ืจื™ืคึผืœื™ื™ืกื˜ ืžื™ื˜ virtiofsd-rs (ื’ืขืฉืจื™ื‘ืŸ ืื™ืŸ ืจื•ืกื˜).
  • ืฆื•ื’ืขื’ืขื‘ืŸ ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื–ืึทืžื“ื‘ืึธืงืกื™ื ื’ QEMU ืงืึทืžืคึผืึธื•ื ืึทื ืฅ.
  • QEMU ื ื™ืฆื˜ ื“ื™ io_uring API ืคึฟืึทืจ ื™ื™ืกื™ื ื’ืงืจืึทื ืึทืก I/O.
  • ืฉื˜ื™ืฆืŸ ืคึฟืึทืจ ื™ื ื˜ืขืœ TDX (ื˜ืจืึทืกื˜ืขื“ ื“ืึธืžืึทื™ืŸ ืขืงืกื˜ืขื ืกื™ืึธื ืก) ื™ืงืกื˜ืขื ืฉืึทื ื– ืื™ื– ื™ืžืคึผืœืึทืžืขื ืึทื“ ืคึฟืึทืจ QEMU ืื•ืŸ Cloud-Hypervisor.
  • ื“ืขืจื”ื™ื™ึทื ื˜ื™ืงื˜ ืงืึทืžืคึผืึธื•ื ืึทื ืฅ: QEMU 6.2.0, Cloud-Hypervisor 26.0, Firecracker 1.1.0, Linux Kernel 5.19.2.

ืžืงื•ืจ: opennet.ru

ืœื™ื™ื’ืŸ ืึท ื‘ืึทืžืขืจืงื•ื ื’