OS//virtualization

Virtualization is the technique of presenting software with a simulated or partitioned version of a machine, so that several isolated environments run on one physical computer as if each had its own, and it is what lets a cloud provider sell slices of a server and lets a developer ship software with everything it needs. It extends the job an OS already does for processes (giving each program its own view of memory and devices) to whole operating systems or whole application environments.


Virtualization is the technique of presenting software with a simulated or partitioned version of a machine, so that several isolated environments run on one physical computer as if each had its own, and it is what lets a cloud provider sell slices of a server and lets a developer ship software with everything it needs. It extends the job an OS already does for processes (giving each program its own view of memory and devices) to whole operating systems or whole application environments.

There are two families, and the difference between them is the first thing to know:

Hardware virtualization runs complete operating systems side by side. A hypervisor sits on the hardware (or on a host OS) and gives each guest a virtual CPU, memory, disk and network card; each guest boots its own kernel. That is a virtual machine: strong isolation, any OS, a few seconds to boot and a full OS's worth of memory per copy.

OS-level virtualization keeps one kernel and partitions what processes can see and use. Kernel features restrict each group of processes to its own view of files, processes and network (namespaces), its own share of CPU and memory (cgroups) and a reduced set of system calls (seccomp). That is a container: starts in milliseconds, costs almost nothing extra, and isolates less, because every container trusts the same kernel.

The choice is how much of the machine to duplicate.

A VM duplicates the operating system and buys a wall that holds even against a hostile guest; a container shares the kernel and buys speed and density. Production systems often stack both: containers for packaging and scheduling, running inside VMs for the wall between customers (multi-tenancy).

The overhead is now small either way. CPUs have had hardware support for virtualization since the mid-2000s, so a VM runs compute close to native speed; the costs that remain are in input and output, in memory, and in the time to start.

Isolation is never total. A hypervisor or kernel flaw can let a guest reach its host or neighbours (sandbox escape), and shared hardware leaks through timing (side channel), so the strength of the wall is matched to how much the tenants distrust each other (sandbox).