An introduction to the Moby Project and LinuxKit. The demo essentially walked through the LinuxKit examples available on Github at https://github.com/linuxkit/linuxkit paying specific attention to the linuxkit.yml nginx example in the home directory, and the redis-os example in the examples directory.
6. A commercial product,
built on
a development platform,
built on
infrastructure,
built on
standards.
Docker is building a stack to program the Internet
9. Docker is a platform made of components
Raft Store
Node
Identity
Secrets
Routing
Mesh
Overlay
Networking
Swarm Orchestration
Engine
Application Services
19. Introducing LinuxKit
A secure, lean, portable Linux subsystem for the container movement
OrchestrationOrchestration
Container Runtime
Linux Subsystem
Infrastructure Management
Application Services
20. Only works with
containers
- Smaller attack
surface
- Immutable
infrastructure
- Sandboxed system
services
- Specialized patches
and configuration
Incubator for
security innovations
- Wireguard,
Landlock, KSPP
- MirageOS type
safe system
daemons
Community-first
security process
- Linux is too big
for any one
company to
secure it
- Participate in
existing Linux
security efforts
1. LinuxKit: a SECURE Linux subsystem
21. - Minimal size, minimal boot time
- All system services are containers
- Everything can be removed or
replaced
2. LinuxKit: a LEAN Linux subsystem
22. - Desktop, server, IoT, mainframe
- Intel & ARM
- Bare metal & virtualized
3. LinuxKit: a PORTABLE Linux subsystem
35. It’s time to take our ecosystem to the next level…
By collaborating on components AND COMMON ASSEMBLIES.
36.
37. – Library of 80+ components
– Package your own
components as containers
– Reference assemblies
deployed on millions of
nodes
– Create your own assemblies
or start from an existing one
A framework to assemble
specialized container
systems without
reinventing the wheel.
38. Docker uses Moby for its
open-source
– Thousands of contributors,
hundreds of patches/week
– Component development
– Specialized assembly
development
– Integration tests
– Architecture design
– Integration with other projects
– Experimentation and bleeding
edge features
39. Docker uses Moby for its
open-source...
and so can you!
– Community-run
– Open governance inspired by
the Fedora project
– Plays well with existing
projects - no donation
necessary!
40. What it means for you
Moby helps you
innovate without tying
you to Docker
System BuildersDocker Users
Docker will better
leverage the ecosystem
to innovate faster for you