Remix.run Logo
▲ Docker has always used microVMs (well since 2016)(dave.recoil.org)
19 points by avsm 9 hours ago | 13 comments
▲Betelbuddy 4 minutes ago | parent | next [-]

Its bending history to call what before were Linux Vms inside Mac or Windows to have containers to that is a real MicroVM.

And the current Sandboxes dont offer the same security model - See Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994

https://docs.docker.com/security/security-announcements/

▲unsnap_biceps 2 hours ago | parent | prev | next [-]

Article title is a bit click-baity. The article is only talking about Docker Desktop on Mac or Windows. Docker Linux have not been using microVMs for a decade.

▲throwaway27448 9 minutes ago | parent [-]

It's still not a bad idea to reduce attack surface. A VM is much easier to harden than a kernel.

▲yjftsjthsd-h 2 hours ago | parent | prev | next [-]

> What if I told you that Docker Desktop has always used microVMs?

Then I would say your title is wildly misleading.

▲cr125rider 2 hours ago | parent | prev | next [-]

Is all of docker one “micro” VM though? Or does each container get a clean, fresh one?

▲firesteelrain 2 hours ago | parent [-]

It’s all one lightweight VM. Containers share the VM’s kernel.

▲binsquare an hour ago | parent [-]

The shared kernel/lack of isolation between the cotnainer workloads is the model that this article isn't really touching but is really important.

Because the current needs are extremely lightweight and isolated environments i.e. vm per workload rather than shared.

And there's been a lot of wonderful innovations happen there

▲sudb 2 hours ago | parent | prev | next [-]

One reason I think a distinction is made is that native Docker-in-Docker can be a real pain, but Docker in a Firecracker microVM "just works".

▲kj4ips 39 minutes ago | parent | prev | next [-]

I often wonder what would have happened if rkt had been more successful.

▲garypdx an hour ago | parent | prev | next [-]

Yawn. IBM/AIX's WPARs & LPARs, Sun/Solaris' dynamic system domains & zones, BSD jails. How many times are we going to pat ourselves on the back for reinventing the wheel?

▲bradknowles 28 minutes ago | parent [-]

Lots. Remember the first VM OS? Running on IBM mainframes? Do you remember what the name of it was? Or when that came out?

Do you remember VMS on DEC hardware? And again, which decade did that come out?

Yeah, this wheel is going to continue to be re-invented for as long as computers exist.

▲mech422 14 minutes ago | parent [-]

Damm...thats going waayy back - but I want to say VS/VME (VM/VME) in the early 70s and vms in the mid 70s ?

▲rvz an hour ago | parent | prev [-]

...*on macOS only and runs qemu as the emulator.

We know. But of course the hype of "microVMs" is just a rebranding of existing technologies with some modifications, macOS needed extra virtualization technologies just for containers for years:

   Docker Desktop macOS (until 2025): QEMU + Virtualization.framework + Linux kernel (without extra drivers) = "microVM".
Now they use the native Apple virtualization libraries instead of QEMU for both containers and microVMs. [0] Linux never needed to use KVM for containers, but requires it for microVMs:

   Linux: KVM + Linux kernel (without extra drivers) = Firecracker "microVM".
In reality, it is different depending on the OS that you are using.

[0] https://www.docker.com/blog/docker-desktop-for-mac-qemu-virt...