[Tracking] Feature/performance parity for process-isolated (shared-kernel) containers vs. Linux containers
まだ誰も着手していません。
評価
- 難易度
- 5/5
- 見積もり時間
- 1週間以上
- 初心者へのやさしさ
- 25/100
- issue の種類
- 機能追加
- 明瞭さ
- 明確に書かれている
- 活発さ
- 活発
- 技術スタック
- docker, linux
調査の方向性
Start by reading the four linked tickets: #649, #650, #651, and #652, since this issue is only a tracking umbrella. Review their owners and implementation scopes rather than looking for an independent change here. The umbrella is done when all four scoped parity tickets are completed or the project chooses another tracking mechanism.
索引モデルが issue の本文から書いたものです。
説明
Is your feature request related to a problem? Please describe.
Process-isolated Windows Server containers lag Linux containers on several related fronts — privilege isolation granularity, PID namespace semantics, image layer/filesystem performance, and host/image version coupling. Each gap has its own owner surface and is filed as its own ticket, but they share a common motivation (closing the parity gap without falling back to Hyper-V isolation, which erases the density/startup-time benefit process isolation exists for), so this issue exists to track them as one effort.
Describe the solution you'd like
Track progress against the four scoped tickets below:
- #649 — Syscall/capability-scoped restriction policy for process-isolated containers (seccomp/capabilities parity)
- #650 — True PID namespace isolation for process-isolated containers (server silos)
- #651 — CimFS-backed overlay mount performance parity with Linux overlayfs for container image layers
- #652 — Decouple container base image version from host OS version for process-isolated containers
Describe alternatives you've considered
N/A — this issue is a tracking umbrella, not an independent ask; alternatives are discussed per-ticket above.
Additional context
#652 is flagged as the hardest of the four, likely requiring changes below the container runtime layer; the other three are scoped to be independently actionable. Happy to close this umbrella once all four are triaged/assigned if the team prefers tracking via a label or milestone instead.
- 主要言語
- PowerShell
- スター
- 551
- フォーク
- 76
- PR マージ指標
- 30日以内にマージされた PR はありません
環境構築
このプロジェクトの環境構築ファイルはまだ確認していません。まず README を読み、一般的な手順ははじめてのコントリビューションガイドを参照してください。
はじめの一歩
- issue を最後まで読み、次にプロジェクトのコントリビューションガイドを読みます。
- 着手することを issue にコメントします — 二人が同じ作業をするのを防げます。
- リポジトリをフォークし、ブランチを切って変更します。
- issue 番号を参照したプルリクエストを送ります。
microsoft/Windows-Containers のほかの issue
-
enhancement triage
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
microsoft/Windows-Containers#630 · コメント 6 件 ·
-
enhancement triage
難易度 5/5 1週間以上 初心者へのやさしさ 30/100
microsoft/Windows-Containers#652 · コメント 1 件 ·
-
enhancement triage
難易度 5/5 1週間以上 初心者へのやさしさ 30/100
microsoft/Windows-Containers#651 · コメント 1 件 ·
-
enhancement triage
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
microsoft/Windows-Containers#650 · コメント 2 件 ·
-
enhancement triage
難易度 5/5 1週間以上 初心者へのやさしさ 25/100
microsoft/Windows-Containers#649 · コメント 1 件 ·
microsoft/Windows-Containers の issue をすべて見る
似ている issue
-
area:ai-suggestions bug P1
難易度 2/5 1〜3時間 初心者へのやさしさ 82/100
uttrflow/uttrflow-swift#3456 ·
メンテナーはふだん 1 日以内に返信
-
easy low
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
open-nudge/opentemplate#185 ·
メンテナーはふだん 1 日以内に返信
-
good-first-issue help-wanted security-slam
難易度 2/5 1〜3時間 初心者へのやさしさ 88/100
-
agent/quality hive/hosted-available-lke648397-260827-5n31 quality testing
難易度 2/5 1〜3時間 初心者へのやさしさ 68/100
cncf/endusers#972 · コメント 1 件 ·
メンテナーはふだん 1 日以内に返信
-
security
難易度 2/5 1〜3時間 初心者へのやさしさ 62/100
IBM/ansible-lifecycle-driver#297 ·