Secret Design Docs: Multi-Tenant Orchestrator
Read OriginalThis article presents a detailed design document for a multi-tenant container orchestrator. It outlines requirements for securely running and isolating third-party Docker images using cgroups, network firewalling, and layered security. It discusses host OS selection, focusing on minimal distributions like CoreOS and Container-Optimized OS for a reduced attack surface and verified boot.
Comments
No comments yet
Be the first to share your thoughts!
Browser Extension
Get instant access to AllDevBlogs from your browser