Cloud ComputingUnit 78 min read
Containers, Orchestration & Microservices in Cloud
Unit 7 of Cloud Computing explores how containers package apps with their dependencies for portability, how orchestration tools like Kubernetes manage clusters at scale, and how microservices architectures leverage these to build resilient cloud-native systems.
TAKEAWAYS:
- Containers encapsulate apps and their dependencies into lightweight, portable units that run consistently across any cloud environment.
- Orchestration platforms like Kubernetes automate deployment, scaling, and management of containerized applications across clusters.
- Microservices break monolithic apps into independent services that communicate via APIs, improving scalability and fault isolation.
- Containerization reduces infrastructure costs by maximizing resource utilization through efficient sharing of OS kernels.
- Orchestration solves challenges like load balancing, self-healing, and rolling updates in distributed containerized environments.
- Real-world examples show how containers enable rapid deployment (e.g., Pathao’s ride-hailing system) and cost efficiency (e.g., Daraz’s dynamic scaling).
What Are Containers?
Containers are lightweight, standalone, executable software packages that include everything needed to run an application: code, runtime, system tools, libraries, and settings. Unlike virtual machines (VMs), containers share the host OS kernel, making them more efficient.
classDiagram
class Container {
+App Code
+Dependencies
+Config Files
+Runtime Environment
}
class HostOS {
+Kernel
+System Libraries
}
class VM {
+Full OS
+Hypervisor
}
Container --> HostOS : "Shares kernel"
VM --> HostOS : "Isolated OS"How Containers Work:
- Isolation: Containers use kernel features like namespaces and cgroups to isolate processes.
- Portability: Containers run consistently across development, testing, and production environments.
- Efficiency: Containers share the host OS, reducing overhead compared to VMs.
Example: Pathao’s Ride-Hailing System Pathao uses containers to deploy microservices for:
- User authentication
- Ride matching
- Payment processing Each service runs in its own container, ensuring scalability during peak hours (e.g., festivals or holidays).
Container vs. Virtual Machines (VMs)
| Feature | Containers | Virtual Machines (VMs) |
|---|---|---|
| Isolation | Process-level (shares OS kernel) | Hardware-level (full OS per VM) |
| Overhead | Low (milliseconds to start) | High (minutes to start) |
| Resource Use | Efficient (shares OS) | Inefficient (dedicated OS per VM) |
| Portability | High (runs anywhere with Docker) | Moderate (depends on hypervisor) |
| Use Case | Microservices, CI/CD, DevOps | Legacy apps, full OS environments |
Containerization Tools
Docker
- Most popular container runtime.
- Uses Dockerfiles to define container images.
- Example Dockerfile for a Python app:
FROM python:3.9-slim WORKDIR /app COPY requirements.txt . RUN pip install -r requirements.txt COPY . . CMD ["python", "app.py"] - How It Works:
FROM: Base image (e.g., Python 3.9).COPY: Adds files from host to container.RUN: Executes commands during build.CMD: Default command to run when container starts.
Podman
- Docker alternative (daemonless, rootless).
- Used in environments where Docker’s daemon is undesirable.
Containerd
- Lightweight container runtime (used by Kubernetes).
Orchestration: Managing Containers at Scale
Orchestration automates the deployment, scaling, and management of containerized applications. The most widely used tool is Kubernetes (K8s).
stateDiagram-v2
[*] --> Deploy: "Pod Creation"
Deploy --> Running: "Container starts"
Running --> Scaling: "Load increases"
Scaling --> Replicas: "Adds more pods"
Replicas --> SelfHealing: "Fails? Restarts"
SelfHealing --> [*]Key Kubernetes Concepts:
Pods
- Smallest deployable unit (one or more containers sharing storage/network).
- Example: A web app pod might run:
- Nginx (web server)
- Redis (cache)
- Sidecar for logging.
Deployments
- Manages pod replicas and updates.
- Ensures desired state (e.g., 3 replicas of a service).
Services
- Exposes pods internally or externally (ClusterIP, NodePort, LoadBalancer).
Ingress
- Manages external HTTP/HTTPS access (e.g., routing traffic to different services).
ConfigMaps & Secrets
- Stores configuration data separately from app code.
Example: Daraz’s Dynamic Scaling Daraz uses Kubernetes to:
- Scale containers during sales events (e.g., Dashain, Tihar).
- Auto-recover failed containers (self-healing).
- Route traffic efficiently using Ingress controllers.
Microservices Architecture
Microservices break applications into small, independent services that communicate via APIs. Containers and orchestration enable microservices by:
- Isolation: Each service runs in its own container.
- Scalability: Scale only the services under load.
- Fault Tolerance: Failures in one service don’t crash the entire app.
classDiagram
class UserService {
+Authenticate
+ManageProfiles
}
class OrderService {
+CreateOrder
+ProcessPayment
}
class PaymentService {
+ChargeCard
+Refund
}
class InventoryService {
+CheckStock
+UpdateStock
}
UserService --> OrderService : "Places order"
OrderService --> PaymentService : "Processes payment"
OrderService --> InventoryService : "Updates stock"Advantages of Microservices:
- Scalability: Scale individual services (e.g., payment service during Diwali sales).
- Resilience: One service failure doesn’t affect others.
- Flexibility: Use different tech stacks per service (e.g., Node.js for APIs, Go for microservices).
Disadvantages:
- Complexity: Requires service discovery, monitoring, and inter-service communication.
- Data Consistency: Managing transactions across services is harder.
Container Security
Containers introduce new security challenges:
Image Vulnerabilities
- Use tools like Trivy or Clair to scan images for vulnerabilities.
- Example: A vulnerable Python library in a container could expose the app to exploits.
Runtime Protection
- Use seccomp, AppArmor, or SELinux to restrict container actions.
- Example: Prevent a container from accessing
/etc/shadow.
Network Security
- Isolate containers using network policies (e.g., allow only specific pods to communicate).
- Example: Restrict database access to only the
OrderServicepod.
Secrets Management
- Never hardcode secrets in containers. Use Kubernetes Secrets or Vault.
- Example: Store database passwords in Secrets, not in the container image.
Real-World Applications
Pathao (Ride-Hailing)
- Idea Used: Microservices + Kubernetes orchestration.
- How: Containers run independently for:
- Driver matching
- Payment processing
- Ride tracking
- Benefit: Scales dynamically during peak demand (e.g., 2077 BS festivals).
Khalti (Digital Payments)
- Idea Used: Containerized APIs for fraud detection.
- How: Each payment validation service runs in a container, ensuring:
- Low latency for transactions.
- Easy updates without downtime.
NTC (Telecom Billing)
- Idea Used: Containers for real-time billing systems.
- How: Billing microservices run in Kubernetes, handling:
- Prepaid/postpaid calculations.
- Data usage tracking.
- Benefit: Auto-scaling during network congestion.
Exam Tip
Define Key Terms Clearly
- Differentiate between containers, VMs, and serverless.
- Explain orchestration as "automating container lifecycle management."
Compare Tables
- Be ready to compare IaaS vs. PaaS vs. SaaS (from Unit 2) with container use cases.
- Example: "Containers are used in PaaS to provide isolated runtime environments."
Worked Examples
- Practice explaining how a company like Daraz uses Kubernetes to:
- Scale containers during sales.
- Manage traffic with Ingress.
- Use real metrics (e.g., "reduced deployment time by 60%").
- Practice explaining how a company like Daraz uses Kubernetes to:
Diagrams
- Draw a Kubernetes pod lifecycle or a microservices communication flow in exams.
- Label components like
Deployment,Service, andIngress.
Security Focus
- Mention at least one security tool (e.g., Trivy) or best practice (e.g., Secrets management) in answers.
Based on the TU BIM syllabus for Cloud Computing (IT277), unit 7.
Discussion
Loading…