30 pointsby avsm14 hours ago13 comments
  • unsnap_biceps6 hours ago
    Article title is a bit click-baity. The article is only talking about Docker Desktop on Mac or Windows. Docker Linux have not been using microVMs for a decade.
    • throwaway274485 hours ago
      It's still not a bad idea to reduce attack surface. A VM is much easier to harden than a kernel.
      • otterley38 minutes ago
        Of course it’s not a bad idea. It’s just a bad article.
      • c0balt3 hours ago
        In those two cases they also use VMs because they don't really have another cheap option.

        Neither XNU/Darwin nor Windows have had an oob option for running Linux images. WSL is rather new in comparison.

  • jeswin24 minutes ago
    Dynamic memory hot-plugging is still not as efficient. So if you don't want strict isolation between containers or individual sandboxes around each one of them, avoid VMs to achieve the highest density per box.
  • yjftsjthsd-h6 hours ago
    > What if I told you that Docker Desktop has always used microVMs?

    Then I would say your title is wildly misleading.

  • segmondy3 hours ago
    I was just exploring the new docker sandbox and saw that they could retain all your data in/out of the sandbox for 30 days. I wash my hand of docker, use with care. Data is gold and lots of companies are now going to be giving their "free" products as a sort of trojan horse to steal your data.
  • otterley38 minutes ago
    Docker *Desktop*, not Docker Engine. Most uses of Docker, at least until Kubernetes shifted to containerd, were the latter. The reality is that most running production containers today share a kernel.
  • Betelbuddy5 hours ago
    Its bending history to call what before were Linux Vms inside Mac or Windows to have containers to that is a real MicroVM.

    And the current Sandboxes dont offer the same security model - See Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994

    https://docs.docker.com/security/security-announcements/

  • cr125rider7 hours ago
    Is all of docker one “micro” VM though? Or does each container get a clean, fresh one?
    • firesteelrain7 hours ago
      It’s all one lightweight VM. Containers share the VM’s kernel.
      • binsquare6 hours ago
        The shared kernel/lack of isolation between the cotnainer workloads is the model that this article isn't really touching but is really important.

        Because the current needs are extremely lightweight and isolated environments i.e. vm per workload rather than shared.

        And there's been a lot of wonderful innovations happen there

      • jbverschooran hour ago
        So no micro VMs at all
  • davoneus4 hours ago
    I wonder if this is due to Microsoft pushing forward with wslc in the past week or so.

    I tried pure wslc for a project or two this past week. It got me 90% of the way but not all the way. Still pretty impressive, even if it is another example of extend and extinguish.

  • sudb6 hours ago
    One reason I think a distinction is made is that native Docker-in-Docker can be a real pain, but Docker in a Firecracker microVM "just works".
  • kj4ips5 hours ago
    I often wonder what would have happened if rkt had been more successful.
  • screm4 hours ago
    And yet it's never picked by coding agents for sandboxes -> https://armature.tech/leaderboards#app/sandboxes
  • garypdx6 hours ago
    Yawn. IBM/AIX's WPARs & LPARs, Sun/Solaris' dynamic system domains & zones, BSD jails. How many times are we going to pat ourselves on the back for reinventing the wheel?
    • bradknowles5 hours ago
      Lots. Remember the first VM OS? Running on IBM mainframes? Do you remember what the name of it was? Or when that came out?

      Do you remember VMS on DEC hardware? And again, which decade did that come out?

      Yeah, this wheel is going to continue to be re-invented for as long as computers exist.

      • mech4225 hours ago
        Damm...thats going waayy back - but I want to say VS/VME (VM/VME) in the early 70s and vms in the mid 70s ?
    • yjftsjthsd-h3 hours ago
      Most of those are shared kernel, though, which is very much what you want to avoid if security is a primary goal.
  • rvz6 hours ago
    ...*on macOS only and runs qemu as the emulator.

    We know. But of course the hype of "microVMs" is just a rebranding of existing technologies with some modifications, macOS needed extra virtualization technologies just for containers for years:

       Docker Desktop macOS (until 2025): QEMU + Virtualization.framework + Linux kernel (without extra drivers) = "microVM".
    
    Now they use the native Apple virtualization libraries instead of QEMU for both containers and microVMs. [0] Linux never needed to use KVM for containers, but requires it for microVMs:

       Linux: KVM + Linux kernel (without extra drivers) = Firecracker "microVM".
    
    In reality, it is different depending on the OS that you are using.

    [0] https://www.docker.com/blog/docker-desktop-for-mac-qemu-virt...