Docker has always used microVMs (well, since 2016)

There's a lot of buzz about "microVMs", where a workload runs with a stripped down Linux kernel, on a minimalist VMM such as firecracker (released in 2018) on top of a hypervisor like KVM or Xen. MicroVMs are often contrasted to, and considered more secure than, traditional Linux Docker containers. What if I told you that Docker Desktop has always used microVMs?

Always has been meme: wait, Docker uses microVMs? Always has been (since 2016)

Back in 2015

Docker Toolbox logo When I joined Docker in 2015 the state of the art was Docker Toolbox. It used VirtualBox, which is a great product with lots of features. VirtualBox has its own GUI and its own update process; way more than we needed for Docker.

A library VMM

We wanted Docker to feel like a native app on Mac and Windows, rather than a bundle of components. Using our Mirage Unikernel libraries we started building a "library VMM": a VMM which could be embedded inside the Docker application, and which would be single purpose, minimal, secure and fast. The first version was called hyperkit and the most recent one is Docker VMM.1

The VM kernel and root filesystem were minimal too, based on the LinuxKit project. The current version is an even more slimmed down variant but conceptually the same, similar to containerd/nerdbox.

Docker for Mac in 2016

For Docker for Mac (later renamed Docker Desktop) this allowed:

And now

The Docker microVM tech is the foundation of Docker Sandboxes today (why microVMs). It continues to get faster, lower overhead and more secure over time.

Further reading

To read more about the history of the tech, see A Decade of Docker Containers (Communications of the ACM).

Footnote

1 Although we were aiming to make everything a library and link into a static unikernel-like process, for technical reasons it makes sense to still have a single host process per VM. ↩