There's a lot of buzz about "microVMs", where a workload runs with a stripped down Linux kernel, on a minimalist VMM such as firecracker (released in 2018) on top of a hypervisor like KVM or Xen. MicroVMs are often contrasted to, and considered more secure than, traditional Linux Docker containers. What if I told you that Docker Desktop has always used microVMs?
A library VMM
We wanted Docker to feel like a native app on Mac and Windows, rather than a bundle of components. Using our Mirage Unikernel libraries we started building a "library VMM": a VMM which could be embedded inside the Docker application, and which would be single purpose, minimal, secure and fast. The first version was called hyperkit and the most recent one is Docker VMM.1
The VM kernel and root filesystem were minimal too, based on the LinuxKit project. The current version is an even more slimmed down variant but conceptually the same, similar to containerd/nerdbox.
Docker for Mac in 2016
For Docker for Mac (later renamed Docker Desktop) this allowed:
- Running rootless on all platforms. Without requiring "rootless inside Linux": the whole Linux kernel is untrusted, so even a Linux CVE doesn't matter.
- Minimal devices. We could carefully limit the host / VM interface, making it easy to understand and audit.
- VPNs and network policy. It was easy to interoperate with VPNs, and to impose networking policy such as Registry Access Management.
And now
The Docker microVM tech is the foundation of Docker Sandboxes today (why microVMs). It continues to get faster, lower overhead and more secure over time.
Further reading
To read more about the history of the tech, see A Decade of Docker Containers (Communications of the ACM).
1 Although we were aiming to make everything a library and link into a static unikernel-like process, for technical reasons it makes sense to still have a single host process per VM. ↩