Jessie Frazelle 2/12/2019

Secret Design Docs: Multi-Tenant Orchestrator

Read Original

This article presents a detailed design document for a multi-tenant container orchestrator. It outlines requirements for securely running and isolating third-party Docker images using cgroups, network firewalling, and layered security. It discusses host OS selection, focusing on minimal distributions like CoreOS and Container-Optimized OS for a reduced attack surface and verified boot.

Secret Design Docs: Multi-Tenant Orchestrator

Comments

No comments yet

Be the first to share your thoughts!

Browser Extension

Get instant access to AllDevBlogs from your browser

Top of the Week

No top articles yet