Contents

Infrastructure & Operations › Containers

Container vs Virtual Machine

Sharing the host kernel vs emulating a full machine.

Also known as: containers vs VMs, docker vs vm

Both give you an isolated environment for running software. The difference is what gets isolated.

Virtual machines                    Containers
┌────────┐ ┌────────┐               ┌────────┐ ┌────────┐
│  App   │ │  App   │               │  App   │ │  App   │
│  libs  │ │  libs  │               │  libs  │ │  libs  │
│Guest OS│ │Guest OS│               └────────┘ └────────┘
├────────┴─┴────────┤               ┌───────────────────┐
│    Hypervisor     │               │ Container runtime │
├───────────────────┤               ├───────────────────┤
│  Host OS / HW     │               │ Host OS (1 kernel)│
└───────────────────┘               └───────────────────┘

A virtual machine emulates a whole computer and runs its own operating system, including its own kernel. A container is a process on the host’s kernel, fenced off from the others.

ContainerVM
Starts inTypically seconds or lessTypically tens of seconds to minutes
SizeOften tens to hundreds of MBOften GBs (a full OS)
IsolationProcess-level, shared kernelStronger, separate kernel
Different OS kernelNo (a Linux host runs Linux containers)Yes
Best forPackaging and scaling appsStrong isolation, other operating systems, running the machines containers live on

The classic mistake

Treating a container like a small VM: logging into it with SSH, installing things by hand, and keeping data inside. Containers are meant to be disposable and rebuilt from an image. See ephemeral filesystem.

They’re not rivals

In the cloud, containers usually run on VMs. Security-sensitive platforms may also put each container in a lightweight VM to get both speed and stronger isolation. Choose containers for application packaging, VMs when you need hard isolation or a different operating system.