Abstract and keywords
Abstract (English):
This article compares the architectural approaches of Docker and gVisor, assessing the tradeoffs between security, performance, and compatibility. The methodology includes performance testing using standard benchmarks, attack surface analysis, and application compatibility assessment. It reveals gVisor's limited compatibility with applications that make intensive use of specific system calls. The practical significance of this work lies in developing criteria for selecting isolation technologies based on security and performance requirements.

Keywords:
containerization, workload isolation, Docker, gVisor, security, performance, attack surface
References

1. Edrien Mouet Ispol'zovanie Docker. - O'Reilly Media, 2017 g.

2. Terskih M.G. Tehnologii izolyacii prilozheniy i instrumental'nye sredstva dlya upravleniya konteynerami // Teoriya i praktika sovremennoy nauki. - Saratov: Izd-vo OOO "Institut upravleniya i social'no-ekonomicheskogo razvitiya", 2017 g.

3. Nanyan S.M., Nichushkina T.N. Virtual'nye konteynery Docker: naznachenie i osobennosti primeneniya / Inzhenernyy vestnik. - Moskva: Izd-vo MGTU im. N.E. Baumana, 2015 g. // Teoriya i praktika sovremennoy nauki.

4. Seyers E. H., Mill A. Docker na praktike. - Manning Publishing, 2019 g.

Login or Create
* Forgot password?