hn.today

Docker has always used microVMs (well since 2016)

dave.recoil.org48 points39 comments
Screenshot of Docker has always used microVMs (well since 2016)

The piece argues that Docker Desktop has effectively used microVMs since 2016, predating recent attention around minimalist VMMs like Firecracker. It recounts how Docker Toolbox relied on VirtualBox in 2015, then shifted to an embedded "library VMM" approach to make Docker feel like a native Mac/Windows app. That work produced hyperkit and later Docker VMM, paired with a minimal kernel and root filesystem built from LinuxKit; the resulting runtime is a slim, single-purpose VM environment that functions like a microVM and resembles efforts such as containerd/nerdbox.

The account highlights concrete benefits achieved by this design: consistent rootless operation across platforms without depending on in-guest rootless Linux, a tightly constrained host-VM interface that eases auditing, and straightforward interoperability with VPNs plus enforceable network policies like registry access management. The same microVM foundation now powers both Docker Desktop and Docker Sandboxes, enabling strongly isolated, governed workflows for tasks such as running coding agents (example: sbx run claude). A technical caveat notes that, despite intentions to fully link the VMM as a library, each microVM still runs as a single host process.

Read on dave.recoil.org39 comments on Hacker News

Summary generated by AI from the linked article. hn.today is not affiliated with Hacker News or Y Combinator.

More in Web

The daily digest

Today's best Hacker News stories, summarized and screenshotted, one email a day.