
Stefan Schimanski
@the_sttts
Control Planes @ Upbound, Ex-Redhat, Kubernetes, logician, restless, hungry & foolish, þetta reddast, github.com/sttts @sttts.social – Opinions are my own
ID: 6650392
https://github.com/sttts 07-06-2007 20:51:32
6,6K Tweet
3,3K Followers
709 Following

Stefan Schimanski Stefan Schimanski so the idea of vNode is not to run a separate kubelet (although you could), instead it wraps and starts the pods of the vCluster in a separate linux user namespace, similar to how the pod sandbox does that with the network namespace

Stefan Schimanski Yes exactly, we have a runtime that starts the actual pods inside another container (the vNode) that uses linux user namespaces, seccomp filters and sysfs/procfs to pretend to be a real node to the inner pod(s)








