Hacker Newsnew | past | comments | ask | show | jobs | submitlogin

Iptables magic is essential to how a lot of container networking stuff is implemented, though.


This is (imho) a huge flaw in the concept of a "container". I don't think most people comprehend how much crap is going on in the background.

For most container purposes, host networking and the default process namespace is absolutely fine, and reduces a lot of problems with interacting with containerized apps. 95% of the use case of containers is effectively just a chroot wrapper. If you need more features, this should be optional. This would also make rootless federated containerized apps just work. But nobody wants to go back to incremental features if Docker gives them everything at once.


If you think that’s bad, wait til you see what the iptables-save output is like on an istio-proxy sidecar ;)


Kubernetes as well. We ran into instances where iptables contention was so bad during outage recovery that things just stalled. iptables-save looked like a bomb went off.




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: