Jessie Frazelle 2/12/2019

Secret Design Docs: Multi-Tenant Orchestrator

Read Original

This article presents a detailed design document for a multi-tenant container orchestrator. It outlines requirements for securely running and isolating third-party Docker images using cgroups, network firewalling, and layered security. It discusses host OS selection, focusing on minimal distributions like CoreOS and Container-Optimized OS for a reduced attack surface and verified boot.

Secret Design Docs: Multi-Tenant Orchestrator

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser