Secret Design Docs: Multi-Tenant Orchestrator
Read OriginalThis article presents a detailed design document for a multi-tenant container orchestrator. It outlines requirements for securely running and isolating third-party Docker images using cgroups, network firewalling, and layered security. It discusses host OS selection, focusing on minimal distributions like CoreOS and Container-Optimized OS for a reduced attack surface and verified boot.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser
Top of the Week
No top articles yet