I attended the Oracle LOSUG meeting on September 15th to hear a talk from Phil Kirk on Zones and Crossbow.
I also took the opportunity to meet Alasdair Lumsden (who has set up openindiana).
I scribbled down a few notes to help jog my memory.
HISTORY
- Zones were never meant to be like VMs. They were designed as a process container.
- Zones have a shared I/P stack and routing.
- There is (typically) a separate I/P alias per zone.
- IPMP works.
- Config is done from the global zone.
- IPfilter works (v4).
- DHCP, IPsec, raw sockets don’t work.
Some problems with zones:
- Non-global routing is affected by global routing table. (Some examples).
- Using a null route is often used to add a gateway entry but this is where global routing table changes can break zones.
- Default routes are selected round-robin.
- defrouter option in the zone config just does a route add (nothing clever in the kernel).
- inter-zone traffic can be forced to go over the wire. Normally it would go via loopback for efficiency but some sites require audit/logging of traffic.
NOW
- Each zone gets its own I/P stack.
- Config is done in the zone.
- Lots of zones need lots of NICs.
- Can mix shared and exclusive stacks.
CROSSBOW:
- Virtualisation at the data (mac addr) level. vNICs.
- vNIC gives b/w resource management (dladm).
- vlans are supported in Crossbow.
P.S. What happened to my complimentary UKOUG membership?