Cloud Computing and VirtualizationUnit 68 min read
Containers, Docker, and Microservices: Isolation, Packaging, and Orchestration
Unit 6 of Cloud Computing and Virtualization explores how containers encapsulate applications with their dependencies, how Docker revolutionizes deployment, and how container orchestration (e.g., Kubernetes) manages distributed systems at scale. This note covers container architecture, Docker commands, container vs. VM
What Are Containers?
Containers are lightweight, standalone, executable software packages that include everything needed to run an application: code, runtime, system tools, libraries, and settings. Unlike virtual machines (VMs), containers share the host OS kernel, making them faster to start and more efficient in resource usage.
How Containers Work
stateDiagram-v2
[*] --> IsolatedUserSpace: Application + Dependencies
IsolatedUserSpace --> SharedKernel: Linux Kernel (host OS)
SharedKernel --> Hardware: CPU, Memory, Storage
Hardware --> [*]- Isolated User Space: Each container runs in its own isolated environment with its own filesystem, libraries, and processes.
- Shared Kernel: Containers share the host OS kernel, reducing overhead compared to VMs.
- Hardware: Containers directly access the host’s CPU, memory, and storage.
Container vs. Virtual Machine (VM)
| Feature | Container | Virtual Machine (VM) |
|---|---|---|
| Isolation | Process-level isolation | Full OS-level isolation |
| Boot Time | Seconds | Minutes |
| Resource Use | Lightweight (MBs) | Heavy (GBs) |
| Performance | Near-native speed | Slightly slower |
| Use Case | Microservices, CI/CD, DevOps | Legacy apps, full OS environments |
Example: Khalti uses containers to deploy its payment microservices. Each service (authentication, transaction processing, fraud detection) runs in its own container, ensuring isolation and scalability.
Docker: The Container Runtime
Docker is the most popular tool for creating, deploying, and managing containers. It uses a client-server architecture with a Docker daemon (dockerd) and a Docker API.
Docker Components
classDiagram
class DockerClient {
+docker build
+docker run
+docker ps
}
class DockerDaemon {
+Manages containers
+Builds images
+Handles networking
}
class DockerImage {
+Layered filesystem
+Immutable
}
class DockerContainer {
+Running instance of an image
+Isolated process
}
DockerClient --> DockerDaemon : Sends commands
DockerDaemon --> DockerImage : Creates from
DockerDaemon --> DockerContainer : RunsKey Docker Concepts
- Images: Read-only templates used to create containers. Built from a
Dockerfile.# Example Dockerfile for a Python app FROM python:3.9-slim WORKDIR /app COPY . . RUN pip install -r requirements.txt CMD ["python", "app.py"] - Containers: Running instances of images. Can be started, stopped, or deleted.
# Run a container from an image docker run -d -p 8080:80 --name my-web-app nginx - Docker Hub: A registry for sharing Docker images (e.g.,
nginx,postgres).
Worked Example: Deploying a Web App with Docker
Scenario: Deploy a simple Flask web app using Docker on a cloud server (e.g., AWS EC2).
Step-by-Step Trace
- Write a
Dockerfile:FROM python:3.9-slim WORKDIR /app COPY requirements.txt . RUN pip install -r requirements.txt COPY . . CMD ["gunicorn", "--bind", "0.0.0.0:8000", "app:app"] - Build the Image:
docker build -t my-flask-app . - Run the Container:
docker run -d -p 8000:8000 --name flask-app my-flask-app - Verify:
Output:docker psCONTAINER ID IMAGE COMMAND CREATED STATUS PORTS NAMES abc123def456 my-flask-app "gunicorn --bind 0.0…" 2 seconds ago Up 1 second 0.0.0.0:8000->8000/tcp flask-app - Access the App:
Open
http://<server-ip>:8000in a browser.
Real-World Tie-In: Pathao uses Docker to containerize its real-time ride-matching service. Each component (user app, driver app, payment gateway) runs in isolated containers, ensuring low latency and scalability during peak hours.
Container Orchestration: Managing Clusters
Containers are ephemeral and often need to be scaled, updated, or restarted. Container orchestration tools like Kubernetes (K8s) automate these tasks.
Why Orchestration?
- Scaling: Automatically add/remove containers based on load.
- Self-Healing: Restart failed containers or replace them.
- Load Balancing: Distribute traffic across containers.
- Rolling Updates: Update containers without downtime.
Kubernetes Basics
classDiagram
class Kubernetes {
+Manages containers at scale
}
class MasterNode {
+API Server
+Scheduler
+Controller Manager
+etcd (Key-value store)
}
class WorkerNode {
+Kubelet
+Container Runtime (Docker)
+Kube-Proxy
}
Kubernetes --> MasterNode : Controls
MasterNode --> WorkerNode : Deploys workloads
WorkerNode --> ContainerRuntime : Runs containersExample: Ncell uses Kubernetes to orchestrate its customer service microservices. During network outages, Kubernetes automatically scales up support containers to handle increased call volumes.
## In the Real World
Khalti (Nepal):
- Idea Used: Microservices in containers.
- How: Each service (e.g., payment processing, user authentication) runs in a separate Docker container. Containers are orchestrated using Kubernetes to handle thousands of transactions per second during festival seasons like Dashain and Tihar.
Pathao (Nepal/Global):
- Idea Used: Real-time container scaling.
- How: Pathao’s backend services (ride matching, payment processing, driver tracking) run in Docker containers. Kubernetes auto-scales these containers during rush hours (e.g., 6–9 PM in Kathmandu) to maintain sub-second response times.
Google Cloud Run:
- Idea Used: Serverless containers.
- How: Google Cloud Run automatically scales Docker containers based on HTTP requests. For example, a startup’s API hosted on Cloud Run can handle 10 requests per second or 10,000 without manual intervention.
Advantages and Disadvantages of Containers
Advantages
- Portability: Run anywhere (on-premises, cloud, or hybrid).
- Efficiency: Faster startup and lower resource usage than VMs.
- Consistency: Identical environments from development to production.
- Isolation: Secure separation of applications.
Disadvantages
- Security Risks: Shared kernel can expose vulnerabilities (e.g., container breakout attacks).
- Complexity: Orchestration tools (e.g., Kubernetes) have a steep learning curve.
- Storage Overhead: Each container requires its own filesystem layers.
## Exam Tip
This unit is heavily tested in TU/PU exams with:
- Definitions: Expect questions on containers vs. VMs, Docker architecture, and orchestration.
- Example Question: "Differentiate between containers and virtual machines with respect to isolation and performance."
- Docker Commands: Know how to build, run, and inspect containers.
- Example Question: "Write the commands to create a Docker image from a
Dockerfileand run it in detached mode."
- Example Question: "Write the commands to create a Docker image from a
- Real-World Scenarios: Apply concepts to case studies (e.g., Khalti’s microservices, Pathao’s scaling).
- Example Question: "How would you deploy a scalable web app using Docker and Kubernetes? Explain with a step-by-step trace."
- Diagrams: Draw container architectures, Docker workflows, or Kubernetes clusters.
- Example Question: "Draw and explain the components of a Docker container’s runtime environment."
Focus Areas:
- Memorize the Dockerfile directives (
FROM,COPY,RUN,CMD). - Understand Kubernetes objects (Pods, Deployments, Services).
- Compare containers vs. VMs in a table (as shown above).
- Practice troubleshooting (e.g., "Why is my container not starting?").
Summary Checklist:
- Understand container isolation and shared kernel.
- Know Docker’s components and commands.
- Compare containers vs. VMs.
- Explain container orchestration with Kubernetes.
- Relate concepts to real-world apps (Khalti, Pathao, Google Cloud Run).
Based on the PU BE Computer (PU) syllabus for Cloud Computing and Virtualization (CMP424), unit 6.
Discussion
Loading…