Docker Resource Isolation

Viewed 530

I'm curious how resource isolation works in Docker, specifically in terms of CPUs. I've seen articles talk about limiting a containers CPU Resource, but limiting sounds different than isolating. Limiting the resource limits how much it can access, but also means the requesting container might not be able to access the CPU instantly. For performance sensitive processes, this seems like a potential deal-breaker. So, I'm just curious how one would isolate resources for containers such that they can instantly access CPU that they are guaranteed.

1 Answers

Docker always runs on linux machine, you can install docker on windows but it will install a linux vm and then install docker on top of that. Docker uses linux technologies named as Namespaces and Cgroups.

Namespaces The kernel provides process isolation by creating separate namespaces for containers. Namespaces enable creating an abstraction of a particular global system resource and make it appear as a separated instance to processes within a namespace

Cgroups The kernel uses cgroups to group processes for the purpose of system resource management. Cgroups allocate CPU time, system memory, network bandwidth, or combinations of these among user-defined groups of tasks

You can read more about it here :- https://access.redhat.com/documentation/en-us/red_hat_enterprise_linux_atomic_host/7/html/overview_of_containers_in_red_hat_systems/introduction_to_linux_containers

Related