There's a lot of buzz about "microVMs", where a workload runs with a stripped down Linux kernel, on a minimalist VMM such as firecracker (released in 2018) on top of a hypervisor like KVM or Xen. MicroVMs are often contrasted to, and considered more secure than, traditional Linux Docker containers. What if I told you that Docker Desktop has always used microVMs?
When I joined Docker in 2015 the state of the art was
Docker Toolbox.
It used
VirtualBox, which is a great product with lots of features. VirtualBox has its own GUI and its
own update process; way more than we needed for Docker.
We wanted Docker to feel like a native app on Mac and Windows, rather than a bundle of components. Using our Mirage Unikernel libraries we started building a "library VMM": a VMM which could be embedded inside the Docker application, and which would be single purpose, minimal, secure and fast. The first version was called hyperkit and the most recent one is Docker VMM.1
The VM kernel and root filesystem were minimal too, based on the LinuxKit project. The current version is an even more slimmed down variant but conceptually the same, similar to containerd/nerdbox.
For Docker for Mac (later renamed Docker Desktop) this allowed:
The Docker microVM tech is the foundation of Docker Sandboxes today (why microVMs). It continues to get faster, lower overhead and more secure over time.
To read more about the history of the tech, see A Decade of Docker Containers (Communications of the ACM).
1 Although we were aiming to make everything a library and link into a static unikernel-like process, for technical reasons it makes sense to still have a single host process per VM. ↩