Enhanced Container Isolation (匷åãããã³ã³ããåé¢) ã¯ã©ã®ããã«åäœããŸããïŒ
Docker 㯠Sysbox ã³ã³ããã©ã³ã¿ã€ã â ã䜿çšã㊠Enhanced Container IsolationïŒåŒ·åãããã³ã³ããéé¢ïŒãå®çŸããŠããŸããSysbox ã¯æšæºã® OCI runc ã©ã³ã¿ã€ã ãåºã«æ¹è¯ããããã©ãŒã¯ã§ãããæšæºçãªã³ã³ããéé¢ãšã¯ãŒã¯ããŒãã®æ§èœãåäžãããããã«èšèšãããŠããŸãã詳ãã㯠ä»çµã¿ã®è©³çŽ° ãã芧ãã ããã
Enhanced Container Isolation ãæå¹åãããŠããå Žåãdocker run
ãŸã㯠docker create
ã³ãã³ãã§äœæãããã³ã³ããã¯ãæšæºã® OCI runc ã©ã³ã¿ã€ã ã§ã¯ãªã Sysbox ã䜿çšããŠèªåçã«èµ·åããŸãããŠãŒã¶ãŒãè¿œå ã®äœæ¥ãè¡ãå¿
èŠã¯ãªããéåžžã©ããã³ã³ããã䜿çšã§ããŸããäŸå€äºé
ã«ã€ããŠã¯ FAQs ãåç
§ããŠãã ããã
ããã«ãåŸæ¥ã¯ã»ãã¥ãªãã£äžã®æžå¿µããã£ã --privileged
ãã©ã°ã䜿çšããã³ã³ããããEnhanced Container Isolation ã䜿çšããããšã§å®å
šã«å®è¡ã§ããããã«ãªããŸãããã®ä»çµã¿ã«ãããDocker Desktop ã®ä»®æ³ãã·ã³ïŒVMïŒãä»ã®ã³ã³ããã䟵害ããããªã¹ã¯ã軜æžããŸãã
Docker Desktop 㧠Enhanced Container Isolation ãæå¹ã«ãªã£ãŠããå ŽåãDocker CLI ã® --runtime
ãã©ã°ã¯ç¡èŠãããŸããDocker ã®ããã©ã«ãã©ã³ã¿ã€ã ã¯åŒãç¶ã runc ã§ããããã¹ãŠã®ãŠãŒã¶ãŒã³ã³ããã¯æé»çã« Sysbox ã䜿çšããŠèµ·åããŸãã
Enhanced Container Isolation ã¯ãDocker Engine ã® userns-remap ã¢ãŒãã Rootless Docker ãšã¯ç°ãªãæ©èœã§ãã
ä»çµã¿ã®è©³çŽ°
Sysbox ã¯ä»¥äžã®ãããªæè¡ãçšããŠã³ã³ããéé¢ã匷åããŸãïŒ
-
ãã¹ãŠã®ã³ã³ããã« Linux ã®ãŠãŒã¶ãŒããŒã ã¹ããŒã¹ãæå¹åïŒã³ã³ããå ã® root ãŠãŒã¶ãŒã Linux VM å ã®éç¹æš©ãŠãŒã¶ãŒã«ãããã³ã°ïŒã
-
ã³ã³ããã«ãã VM ã®éèŠãã£ã¬ã¯ããªã®ããŠã³ããå¶éã
-
ã³ã³ãããš Linux ã«ãŒãã«éã®éèŠãªã·ã¹ãã ã³ãŒã«ãæ€æ»ã
-
ã³ã³ããã®ãŠãŒã¶ãŒããŒã ã¹ããŒã¹ãš Linux VM éã®ãã¡ã€ã«ã·ã¹ãã ã®ãŠãŒã¶ãŒ/ã°ã«ãŒã ID ããããã³ã°ã
-
ã³ã³ããå ã§
/proc
ã/sys
ãã¡ã€ã«ã·ã¹ãã ã®äžéšããšãã¥ã¬ãŒã·ã§ã³ã
ãããã®æè¡ã¯ Linux ã«ãŒãã«ã®æè¿ã®é²åã«ãã£ãŠå¯èœã«ãªããDocker Desktop ã§ããã®å©ç¹ã掻çšããŠããŸããSysbox ã¯ãããã®æè¡ãã³ã³ããã«æå°éã®æ©èœçã»æ§èœç圱é¿ã§é©çšããŸãã
ãããã®æè¡ã¯ãLinux ããŒã ã¹ããŒã¹ãcgroupsãå¶éããã Linux CapabilitiesãSeccompãAppArmor ãªã©ãåŸæ¥ã® Docker ã³ã³ããã»ãã¥ãªãã£ã¡ã«ããºã ãè£å®ãããã®ã§ããããã«ãããDocker Desktop VM å ã®ã³ã³ãããš Linux ã«ãŒãã«ã®éã«åŒ·åãªéé¢å±€ãè¿œå ããŸãã
詳现ã«ã€ããŠã¯ äž»èŠãªç¹åŸŽãšå©ç¹ ãåç §ããŠãã ããã
Enhanced Container Isolation ãšãŠãŒã¶ãŒããŒã ã¹ããŒã¹ãªãããã³ã°ã®éã
Docker Engine ã«ã¯ããã¹ãŠã®ã³ã³ããã§ãŠãŒã¶ãŒããŒã ã¹ããŒã¹ãæå¹åãã userns-remap ã¢ãŒãâ ãšããæ©èœããããŸãããããããã®ã¢ãŒãã«ã¯ããã€ãã®å¶éäºé âããããDocker Desktop ã§ã¯ãµããŒããããŠããŸããã
userns-remap ã¢ãŒãã¯ãEnhanced Container Isolation ãšåæ§ã«ãLinux ã®ãŠãŒã¶ãŒããŒã ã¹ããŒã¹ã掻çšããŠã³ã³ããéé¢ãåäžãããŸããããããEnhanced Container Isolation ã¯ããé«åºŠãªæ©èœãåããŠãããåã³ã³ããããšã«å°çšã®ãŠãŒã¶ãŒããŒã ã¹ããŒã¹ãããã³ã°ãèªåçã«å²ãåœãŠãã»ããçµç¹ã§å³æ Œãªã»ãã¥ãªãã£èŠä»¶ã«å¯Ÿå¿ããããã®ãã®ä»ã®éé¢æ©èœ ãæäŸããŸãã
Enhanced Container Isolation ãš Rootless Docker ã®éã
Rootless Dockerâ ã¯ãDocker Engine ãšã³ã³ããã Linux ãã¹ãäžã§ã«ãŒãæš©éãªãã§å®è¡ããæ©èœã§ããããã«ãããéã«ãŒããŠãŒã¶ãŒã Linux äžã§ Docker ãã€ã³ã¹ããŒã«ããå®è¡ã§ããããã«ãªããŸãã
Rootless Docker 㯠Docker Desktop ã§ã¯ãµããŒããããŠããŸããããã®æ©èœã¯ãLinux äžã§ Docker ããã€ãã£ãã«å®è¡ããå Žåã«æçšã§ãããDocker Desktop ã®å Žåããã®äŸ¡å€ã¯éå®çã§ããããã¯ãDocker Desktop ã Docker Engine ã Linux VM å ã§å®è¡ãããã¹ããŠãŒã¶ãŒãéã«ãŒããšã㊠Docker ãå®è¡ã§ããããã«ããä»®æ³ãã·ã³ã§ãšã³ãžã³ããã¹ãããåé¢ããŠããããã§ãã
Rootless Docker ãšã¯ç°ãªããEnhanced Container Isolation 㯠Docker Engine ã Linux ã®ãŠãŒã¶ãŒããŒã ã¹ããŒã¹å ã§å®è¡ããã®ã§ã¯ãªãããã®ãšã³ãžã³ã«ãã£ãŠçæãããã³ã³ããããŠãŒã¶ãŒããŒã ã¹ããŒã¹å ã§å®è¡ããŸããããã«ãããRootless Docker ã®å¶éâ ãåé¿ããã³ã³ãããš Docker Engine ã®éã«åŒ·åãªå¢çãèšããããšãã§ããŸãã
Enhanced Container Isolation ã¯ãDocker Desktop äžã§èµ·åãããã³ã³ããããDocker Desktop Linux VM ãç°¡åã«äŸµå®³ããŠã»ãã¥ãªãã£èšå®ãå€æŽãããªã¹ã¯ãé²ãããšãç®çãšããŠããŸãã