[Tracking] Feature/performance parity for process-isolated (shared-kernel) containers vs. Linux containers
Nobody has claimed this yet.
Assessment
- Difficulty
- 5/5
- Estimated time
- Over a week
- Newbie friendliness
- 25/100
- Issue type
- Feature
- Clarity
- Clearly specified
- Activity status
- Active
- Tech stack
- docker, linux
- Domain
- infrastructure
Research direction
Start by reading the four linked tickets: #649, #650, #651, and #652, since this issue is only a tracking umbrella. Review their owners and implementation scopes rather than looking for an independent change here. The umbrella is done when all four scoped parity tickets are completed or the project chooses another tracking mechanism.
Written by the indexing model from the issue text.
Description
Is your feature request related to a problem? Please describe.
Process-isolated Windows Server containers lag Linux containers on several related fronts — privilege isolation granularity, PID namespace semantics, image layer/filesystem performance, and host/image version coupling. Each gap has its own owner surface and is filed as its own ticket, but they share a common motivation (closing the parity gap without falling back to Hyper-V isolation, which erases the density/startup-time benefit process isolation exists for), so this issue exists to track them as one effort.
Describe the solution you'd like
Track progress against the four scoped tickets below:
- #649 — Syscall/capability-scoped restriction policy for process-isolated containers (seccomp/capabilities parity)
- #650 — True PID namespace isolation for process-isolated containers (server silos)
- #651 — CimFS-backed overlay mount performance parity with Linux overlayfs for container image layers
- #652 — Decouple container base image version from host OS version for process-isolated containers
Describe alternatives you've considered
N/A — this issue is a tracking umbrella, not an independent ask; alternatives are discussed per-ticket above.
Additional context
#652 is flagged as the hardest of the four, likely requiring changes below the container runtime layer; the other three are scoped to be independently actionable. Happy to close this umbrella once all four are triaged/assigned if the team prefers tracking via a label or milestone instead.
- Dominant language
- PowerShell
- Stars
- 551
- Forks
- 76
- PR merge metrics
- No merged PRs in 30d
Contributor guide
No contributing guide indexed for this repository
First steps
- Read the whole issue, then the project's contributing guide.
- Comment on the issue to say you are picking it up — it saves two people doing the same work.
- Fork the repository and make your change on a branch.
- Open a pull request that references the issue number.
More from microsoft/Windows-Containers
-
enhancement triage
Difficulty 2/5 1-3 hours Newbie friendliness 68/100
microsoft/Windows-Containers#630 · 5 comments ·
-
enhancement triage
Difficulty 5/5 Over a week Newbie friendliness 30/100
microsoft/Windows-Containers#652 · 1 comment ·
-
enhancement triage
Difficulty 5/5 Over a week Newbie friendliness 30/100
microsoft/Windows-Containers#651 · 1 comment ·
-
enhancement triage
Difficulty 5/5 Over a week Newbie friendliness 25/100
microsoft/Windows-Containers#650 · 1 comment ·
-
enhancement triage
Difficulty 5/5 Over a week Newbie friendliness 25/100
microsoft/Windows-Containers#649 · 1 comment ·
All issues in microsoft/Windows-Containers
Similar issues
-
A cancelled tests run makes the coverage comment workflow fail and reports it as a red check on main Openarea: ci bug perceived difficulty: 3
Difficulty 2/5 1-3 hours Newbie friendliness 78/100
Nitjsefnie-Harness-Commons/daedalus#921 · 1 comment ·
-
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
crossplane/crossplane#7859 ·
-
Product: Terraform (AVM) Topic: Networking (HS) :globe_with_meridians:
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
Azure/Azure-Landing-Zones#4282 · 1 comment ·
-
Difficulty 1/5 Under an hour Newbie friendliness 88/100
-
bug carvel-triage
Difficulty 2/5 1-3 hours Newbie friendliness 88/100
carvel-dev/kapp-controller#1861 ·