Docker has always used microVMs (well since 2016)
Thread
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
Docker has always used microVMs (well since 2016)
Loading the complete thread in the background. This saved snapshot is available now. Refresh
Unofficial Hacker News client; not affiliated with Y Combinator.
cr125rider · · focus · HN ↗
firesteelrain · · focus · HN ↗
binsquare · · focus · HN ↗
Because the current needs are extremely lightweight and isolated environments i.e. vm per workload rather than shared.
And there's been a lot of wonderful innovations happen there
jbverschoor · · focus · HN ↗
sureglymop · · focus · HN ↗
sudb · · focus · HN ↗
yjftsjthsd-h · · focus · HN ↗
Then I would say your title is wildly misleading.
unsnap_biceps · · focus · HN ↗
throwaway27448 · · focus · HN ↗
c0balt · · focus · HN ↗
Neither XNU/Darwin nor Windows have had an oob option for running Linux images. WSL is rather new in comparison.
pjmlp · · focus · HN ↗
c0balt · · focus · HN ↗
Developers, ime, also don't really want to start building their own container images for auxiliary services like, e.g., PostgreSQL, MongoDB or MySQL. Having virtualized Linux support means you can take the existing ecosystem and make it accessible to the other two.
otterley · · focus · HN ↗
avsm · · focus · HN ↗
You sure could. Kata containers have been around for a long time; I remember putting them into production back in 2017 or so (and dealing with filesystem forwarding issues). <a href="https://lwn.net/Articles/755230/" rel="nofollow">https://lwn.net/Articles/755230/
unsnap_biceps · · focus · HN ↗
rvz · · focus · HN ↗
We know. But of course the hype of "microVMs" is just a rebranding of an existing technologies with some modifications.
Linux: KVM + Linux kernel (without extra drivers) = Firecracker "microVM".
This is what Docker uses for macOS:
macOS: QEMU + Virtualization.framework + Linux kernel (without extra drivers) = "microVM".
In reality, it is different depending on the OS that you are using.
garypdx · · focus · HN ↗
bradknowles · · focus · HN ↗
Do you remember VMS on DEC hardware? And again, which decade did that come out?
Yeah, this wheel is going to continue to be re-invented for as long as computers exist.
mech422 · · focus · HN ↗
yjftsjthsd-h · · focus · HN ↗
happymellon · · focus · HN ↗
yjftsjthsd-h · · focus · HN ↗
happymellon · · focus · HN ↗
kj4ips · · focus · HN ↗
Betelbuddy · · focus · HN ↗
And the current Sandboxes dont offer the same security model - See Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994
<a href="https://docs.docker.com/security/security-announcements/" rel="nofollow">https://docs.docker.com/security/security-announcements/
user_account · · focus · HN ↗
> and considered more secure than, traditional Linux Docker containers.
davoneus · · focus · HN ↗
I tried pure wslc for a project or two this past week. It got me 90% of the way but not all the way. Still pretty impressive, even if it is another example of extend and extinguish.
screm · · focus · HN ↗
segmondy · · focus · HN ↗
throooooo · · focus · HN ↗
otterley · · focus · HN ↗
jeswin · · focus · HN ↗
LeBit · · focus · HN ↗
qalmakka · · focus · HN ↗
I'd say that I don't think it's that relevant? Hopefully everyone was aware that you required a VM to run Linux software on Windows and Mac, and then who would really care about what VM docker used to run development containers? The more expendable the better. Hopefully nobody is using a Windows PC with docker desktop in a production scenario - but given how utterly incompetent some people I met was, I'd not be too surprised from that
happosai · · focus · HN ↗
jbverschoor · · focus · HN ↗
LeBit · · focus · HN ↗
GuestFAUniverse · · focus · HN ↗
Pretty strange article considering all the Docker shortcomings.
avsm · · focus · HN ↗
I do think this was well ahead of its time. Under the hood, we designed a Linux distro called LinuxKit (<a href="https://github.com/linuxkit/linuxkit" rel="nofollow">https://github.com/linuxkit/linuxkit) which ran every process in its own mount namespace (including the init process), and had a deterministic build with hashes. As far as I can tell, it's still pretty hard to get this experience even with Nix in 2026.
The boot time was also quick enough to be entirely in parallel and so not be noticeable (the 'bounce time' of the application on Mac was one bounce!)
spwa4 · · focus · HN ↗
But decent VM automation on VirtualBox (for the first ~5 years had MUCH better API/RPC and frankly still does than anything else) got you all that 10+ years ago.