Ro

Rootless Containers/Pods that run systemd, Docker, and even Kubernetes

Hacker News

Rootless Containers/Pods that run systemd, Docker, and even Kubernetes

Hi HN, this is Cesar and Rodny, developers of an open-source container runtime called Sysbox, and co-founders of a startup called Nestybox (YC S20). We launched on HN almost a year ago and got excellent feedback then (https://news.ycombinator.com/item?id=24084758). Happy to say that over the past year, Sysbox has continued to gain traction, particularly for securing containers in production, CI/CD, and containerized dev environments. We wanted to announce an important new feature: integration between Sysbox and Kubernetes. As a quick refresher, Sysbox is a "runc" that enhances containers in two key ways: 1) Hardens container isolation (Linux user-namespace on all containers, partial procfs & sysfs virtualization, initial mount locking, and more). 2) Enables containers to run not just microservices, but also system software such as systemd, Docker, K8s, K3s, and more. This enables containers to replace slower/less-efficient VMs in many scenarios. Prior to Sysbox this required insecure privileged containers, custom images, and special host mounts, or specialized tools like LXD, KinD and Minikube. With Sysbox, the container runtime sets up the container such that it can run the software securely and seamlessly, increasing security and reducing complexity. Up to recently Sysbox only worked under Docker, but the latest release (v0.4.0) now works under Kubernetes too. This means you can use Kubernetes to orchestrate pods that are rootless (i.e., root in the container maps to an unprivileged user on the host) and can run not just microservices, but full "VM-like" environments. For example, you can create a pod that acts as a well isolated dev environment and inside of it run systemd, your favorite editor, plus Docker. Or create several pods that together form another K8s cluster for testing. Or run the K8s.io KinD inside a pod to create an entire K8s cluster inside one pod. Many interesting and powerful combinations are possible. Sysbox has taken 2-years of very hard work, as it pushes the limits of OS virtualization (uid-shifting, syscall trapping, procfs virtualization, etc.) It was forked from the OCI runc in 2019, so we stand on the shoulders of the developers of that excellent project. Would love to hear your feedback, if you think this new feature is useful, and for which use-cases. Would also encourage you to try it, we think you'll find it useful. Thanks! - Cesar & Rodny Sysbox: https://github.com/nestybox/sysbox Nestybox: https://www.nestybox.com/

Share card

Actual performance

10points
Made the leaderboard

Launch Intel predictions

Analyze your own launch →
Product HuntOn track for Day 1 leaderboard · Strong signals: user, dock, new · Missing: mac, agents, macos
93%93% predicted probability of success on Product Hunt, based on ML models trained on real launch data.
best fitHighest predicted score across all platforms for this description.
Indie HackersFits the IH revenue-focused audience · Strong signals: ios · Missing: supports, reddit linkedin, podcasting
88%88% predicted probability of success on Indie Hackers, based on ML models trained on real launch data.
Hacker NewsStrong engagement from HN community · Strong signals: ide, io · Missing: https docs, excited, just released
74%74% predicted probability of success on Hacker News, based on ML models trained on real launch data.
nativeThis product was originally launched on this platform.
TrustMRRLess likely to generate early MRR · Strong signals: ios, way · Missing: mobile apps, personal, entrepreneurs
44%44% predicted probability of success on TrustMRR, based on ML models trained on real launch data.
AppSumoMay struggle as an AppSumo deal · Strong signals: plus, host, efficient · Missing: platform, intuitive, reviews
35%35% predicted probability of success on AppSumo, based on ML models trained on real launch data.
Acquire.comPre-revenue stage for this audience · Missing: arr, mrr, revenue
16%16% predicted probability of success on Acquire.com, based on ML models trained on real launch data.
BetaListMay not resonate with beta-testers · Missing: web3, chat, crypto
0%0% predicted probability of success on BetaList, based on ML models trained on real launch data.

Correct prediction on native model

Similar products

Ra
Raspberry Pi3 cluster with Docker/Kubernetes50%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Raspberry Pi3 cluster with Docker/Kubernetes

Hacker News86
Do
Docker 2 Kubernetes39%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Docker 2 Kubernetes

Hacker News9
Do
Docker for Mac Kubernetes ingress57%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Docker for Mac Kubernetes ingress

Hacker News1
K8
K8s-TLS-Registry: Private Docker Registry with TLS on Kubernetes46%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

K8s-TLS-Registry: Private Docker Registry with TLS on Kubernetes

Hacker News2
mi
minienv (side project) – run Docker Compose environments in Kubernetes38%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

minienv (side project) – run Docker Compose environments in Kubernetes

Hacker News1
ts
tsdocker – run Docker containers on your Tailnet52%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

tsdocker – run Docker containers on your Tailnet

Hacker News2
#!
#!/usr/bin/env docker run28%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

#!/usr/bin/env docker run

Hacker News496
Do
Docker-boot – Run a system from RAM without LiveCD62%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Docker-boot – Run a system from RAM without LiveCD

Hacker News27
Si
Simple Kubernetes test cluster with Docker registry and ingress36%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

Simple Kubernetes test cluster with Docker registry and ingress

Hacker News1
Ho
How interactive containers work (Docker, Kubernetes, and alike)65%Launch Intel prediction score: how likely this product is to succeed on its source platform, based on its name, tagline, and description.

How interactive containers work (Docker, Kubernetes, and alike)

Hacker News3