Containerization
Containerization packages an application together with its dependencies into an image that runs identically on any machine with a compatible container runtime.
What is containerization?
Containerization packages an application together with its dependencies into an image that runs identically on any machine with a compatible container runtime.
Plain and technical
A container bundles your application with everything it needs to run, so it behaves the same on a laptop as it does in production. It is much lighter than a virtual machine because it shares the host operating system kernel.
A container image is a layered filesystem plus metadata conforming to the OCI specification. At run time the kernel isolates the process using namespaces and cgroups. Containers share the host kernel, which is why they start in milliseconds and why kernel-level isolation is weaker than a virtual machine boundary.
What it looks like in practice
Nearby vocabulary
Kubernetes
Kubernetes is an open-source system that runs containerised applications across a group of machines, keeping the running state matched to a declared one.
Software bill of materials
A software bill of materials is a machine-readable inventory of every component and dependency contained in a piece of software, including versions.
How DevOpsArk handles containerization
Articles on this subject
How to automate Docker builds without hand-writing Dockerfiles
Multi-stage builds, layer caching that actually works, hardening defaults, and how to generate and maintain container definitions across a large service estate.
Container security: the practices that actually reduce risk
Build-time hardening, runtime restriction and supply chain controls for containers, ordered by how much risk each one removes rather than by how often it is mentioned.
More definitions
See these concepts in a running system
A 30-minute walkthrough against your own infrastructure rather than a slide about the theory.