Open ContainerÏîÄ¿ÆìϵÄÇáÁ¿¼¶Í¨ÓÃÔËÐÐʱÈÝÆ÷runC×î½ü¹«²¼ÁË1.0·¢²¼ºòÑ¡°æ¡£runCÊÇÒ»ÖÖ°´ÕÕOCP¹æ·¶Éú³ÉºÍÔËÐÐÈÝÆ÷µÄCLI¹¤¾ß£¬´úÂëÒÑ·¢²¼ÖÁGitHub¡£
ÈÝÆ÷¼¼ÊõÖð½¥Êܵ½Óû§ºÍÉçÇøµÄ»¶Ó£¬Linux»ù½ð»áÔçÔÚ2015Äê6Ô¾ͳÉÁ¢ÁËOCI£¨Open Container Initiative£©×éÖ¯£¬Ö¼ÔÚÎ§ÈÆÈÝÆ÷¸ñʽºÍÔËÐÐÊ±ÖÆ¶¨¿ª·ÅµÄ±ê×¼¡£¸Ã×éÖ¯Òѵõ½°üÀ¨Amazon¡¢»ªÎª¡¢Google¡¢MicrosoftµÈÔÆ¹©Ó¦É̵ÄÖ§³Ö¡£Ô´×ÔDockerµÄrunCÊÇͨ¹ý¿ª·ÅÈÝÆ÷¸ñʽ±ê×¼£¨OCF, Open Container Format£©Öƶ¨µÄÒ»ÖÖ¾ßÌåʵÏÖ¡£
runCµÄ¿ÉǶÈëÌØÐÔʹµÃÈÝÆ÷¿ÉÒÔ×÷ΪrunCµÄ×Ó½ø³ÌÆô¶¯£¬²¢ÄÜÔÚÎÞÐèÔËÐÐDocker´úÀí³ÌÐòµÄÇé¿öϽ«ÆäǶÌ×ÖÁ¸÷ÖÖÆäËûϵͳÖС£runCÒÔlibcontainerΪ»ù´¡¿ª·¢¶øÀ´£¬ÕâÖÖÈÝÆ÷¼¼ÊõĿǰÕýÇý¶¯×ÅÈ«ÇòÊý°ÙÍòDockerÒýÇæ£¬Óû§¿ÉÒÔÖ±½Óͨ¹ýrunCÔËÐÐDockerÓ³Ïñ¡£
¹¦ÄܺÍÖ÷Òª¸Ä½ø
runCµÄÄ¿±êÊÇÈÃÓû§ËæÊ±ËæµØÊ¹Óñê×¼»¯µÄÈÝÆ÷£¬ÆäÖаüº¬´óÁ¿¹ãÊÜ»¶ÓµÄ¹¦ÄܺÍÌØÐÔ£¬ÀýÈ磺
ÍêÕûÖ§³ÖLinuxÃüÃû¿Õ¼ä£¬°üÀ¨Óû§ÃüÃû¿Õ¼ä¡£
ÔÉúÖ§³ÖLinuxµÄËùÓа²È«¹¦ÄÜ£¬°üÀ¨Selinux¡¢Apparmor¡¢seccomp¡¢control groups¡¢capability drop¡¢pivot_root¡¢uid/gid droppingµÈ¡£
ÔÉúÖ§³ÖÊµÊ±Ç¨ÒÆºÍWindows 10ÈÝÆ÷¡£
¼Æ»®ÎªArm¡¢Power¡¢SparcµÈ¼Ü¹¹ÌṩÔÉúÖ§³Ö£¬²¢Ö±½ÓµÃµ½Arm¡¢Intel¡¢Qualcomm¡¢IBM£¬ÒÔ¼°Õû¸öÓ²¼þÖÆÔìÉÌÉú̬ϵͳµÄ²ÎÓëºÍÖ§³Ö¡£
¼Æ»®ÎªÇ°ÑØÓ²¼þ¹¦ÄÜÌṩÔÉúÖ§³Ö£¬ÀýÈçDPDK¡¢sr-iov¡¢tpm¡¢secure enclaveµÈ¡£
¿ÉÒÆÖ²µÄÐÔÄÜÅäÖÃÎļþ£¬ÒÔ¼°³ÉΪÕýʽ±ê×¼µÄÅäÖøñʽ¡£
´Ë´Î¹«²¼µÄ1.0·¢²¼ºòÑ¡°æÊÇOCIÔËÐÐʱ¹æ·¶ºÍrunC 1.0µÄÊ׸öºòÑ¡°æ±¾£¬¸Ã°æ±¾Õë¶Ô´´½¨ºÍÆô¶¯µÈÃüÁî½øÐÐÁ˽ϴóµ÷Õû¡£
ÈÝÆ÷µÄ´´½¨ºÍÆô¶¯¹ý³ÌÏÖÒѲð·ÖΪÁ½¸ö²½Ö裬ͨ¹ýÕâÑùµÄÉè¼Æ£¬Éϲãϵͳ¿ÉÒÔÔÚÓû§¶¨ÒåµÄ¹ý³ÌÆô¶¯Ç°ÐÞ¸ÄÈÝÆ÷ÄÚÈÝ¡£Èç¹ûÒÀȻϣÍûÏñ֮ǰµÄ°æ±¾ÄÇÑùʹÓÃrunC£¬Ôò¿ÉÒÔʹÓÃrunc runÃüÁî¡£Ôڸð汾ÖУ¬»¹¿ÉÒÔʹÓÃrunc stateÃüÁî»ñÈ¡ÈÝÆ÷µÄ״̬ÐÅÏ¢¡£ÁíÍâ¿ÉÒÔͨ¹ýÐÂÔöµÄpsÃüÁî²é¿´ÈÝÆ÷ÄڵĽø³Ì£º
³ý´ËÖ®Í⣬±¾´Î·¢²¼µÄ1.0ºòÑ¡°æ»¹ÔÚÏÂÁм¸¸ö·½ÃæÓÐËù¸Ä½ø£º
Ϊ¸ü¶à¼Ü¹¹ÌṩÁËseccompÖ§³Ö
¸üÎȶ¨µÄ״̬Êä³ö
Ôö¼ÓÁËÓÃÓÚ¶¯Ì¬¸üÐÂÈÝÆ÷×ÊÔ´µÄupdateÃüÁî
´óÁ¿ÆäËû¸Ä½øºÍ man Ò³Ãæ
Ŀǰ¿ÉÒÔ½«1.3°æÒÔÉϵÄDockerÓ³ÏñÓërunCÅäºÏʹÓᣴËÍârunC»¹¿ÉÅäºÏsystemdʹÓá£
Èí¼þÏêÇ飺https://www.opencontainers.org/
ÏÂÔØµØÖ·£ºhttps://github.com/opencontainers/runc
À´×Ô:¿ªÔ´ÖйúÉçÇø

