{"id":1095,"date":"2016-03-03T16:13:49","date_gmt":"2016-03-03T13:13:49","guid":{"rendered":"https:\/\/telcocloudbridge.com\/?p=1095"},"modified":"2016-03-03T16:13:49","modified_gmt":"2016-03-03T13:13:49","slug":"beginners-guide-docker-container-nfv","status":"publish","type":"post","link":"https:\/\/telecomlighthouse.com\/?p=1095","title":{"rendered":"A Beginner&#8217;s Guide to Docker Container in NFV"},"content":{"rendered":"<p>The emerging <a href=\"https:\/\/www.docker.com\/why-docker\">Docker<\/a> containers have potential to revolutionalize NFV.<\/p>\n<p>After all, they are lightweight compared to virtual machines; they need less overhead and resources; and, they can provide application isolation running in the same operating system, they live in.<\/p>\n<p>That means,\u00a0 if a Virtual Network function (VNF) in NFV can run in a Docker container with complete isolation, you may not need a virtual machine.<\/p>\n<p>But, is it that easy?<!--more--><\/p>\n<p>And\u00a0 what is the future of virtual machine, then?<\/p>\n<p>Infact, it is too early to say anything about the future of virtual machines as docker containers are still evolving\u00a0 ( and so is NFV <a href=\"https:\/\/telecomlighthouse.com\/wp-content\/uploads\/2016\/03\/clip_image0014.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; margin: 0px; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;\" title=\"clip_image001[4]\" src=\"https:\/\/telecomlighthouse.com\/wp-content\/uploads\/2016\/03\/clip_image0014_thumb.png\" alt=\"clip_image001[4]\" width=\"23\" height=\"23\" border=\"0\" \/><\/a>).<\/p>\n<p>However, if you stay till the end, you will\u00a0 be able to find out, what makes Docker containers so special that everyone is talking about them now.<\/p>\n<p>The <a href=\"https:\/\/telecomlighthouse.com\/blog\/essentials-of-ason-gmpls\/\">primary aim of this guide<\/a> is to walk you step by <a href=\"https:\/\/telecomlighthouse.com\/blog\/what-is-kubernetes-and-its-architecture\/\">step in understanding the architecture of Docker container<\/a>. In the process, you will also understand the basics of the hypervisor and virtual machine.<\/p>\n<p>The concepts are explained, assuming zero prior knowledge about virtual machines and hypervisors.<\/p>\n<h2>What is\u00a0 a container?<\/h2>\n<p>Historically, containers emerged as\u00a0 a way of running applications in a more flexible and agile way. Linux containers enabled running lightweight applications, within Linux OS directly. Without a need for the hypervisor and virtual machines, applications can run in isolation in the same operating system.<\/p>\n<h2>What is \u00a0a Docker container?<\/h2>\n<p>Google has been using Linux containers in\u00a0 its <a href=\"https:\/\/telecomlighthouse.com\/blog\/what-is-software-defined-data-center\/\">data centers<\/a>\u00a0 since 2006. But, they became more popular with the arrival of docker containers in 2013. Which is a more simple and standard way to run containers compared to earlier version of containers.<\/p>\n<p>The Docker container also runs in Linux. But Docker is not the only way run containers. LXC is another way to run containers. Both LXC and Docker have roots in Linux.<\/p>\n<p>One of the reasons, the Docker container is more popular compared to competing containers such as LXC is its ability to load as \u201cimage\u201d on host operating system in a simple and quick manner. Dockers are stored in the cloud as images and called upon for execution by users when needed in a simple way.<\/p>\n<p>Moving forward, I will use the word \u201ccontainer\u201d and \u201cDocker container\u201d interchangeably\u00a0 as the concepts apply to both.<\/p>\n<p>Step by Step guide to understanding\u00a0 Docker containers in NFV<\/p>\n<p>Virtual machines are good, yet they have problems:<\/p>\n<p>You need\u00a0 a dedicated operating system. And, you need a hypervisor to separate the virtual machine to achieve virtualization.<\/p>\n<p>More applications mean more software overhead, more expensive and a need to keep them updated.<\/p>\n<p>Yet, virtual machines are needed for <a href=\"https:\/\/telecomlighthouse.com\/blog\/nfv-network-functions-virtualization-and-its-relation-to-sdn\/\">NFV architecture<\/a>, so let&#8217;s see the NFV architecture.<\/p>\n<h2><\/h2>\n<h2>Step 1: Let&#8217;s start with the\u00a0 Hypervisor in NFV Architecture<\/h2>\n<p>In this diagram, I am showing the NFV architecture, you may have seen many times ( Need a refresher, <a href=\"https:\/\/telecomlighthouse.com\/blog\/a-cheat-sheet-for-understanding-nfv-architecture\/\">visit here<\/a>).<\/p>\n<p><a href=\"https:\/\/telecomlighthouse.com\/wp-content\/uploads\/2016\/03\/NFVI-Virtualization-Layer-Hypervisor.png\" rel=\"attachment wp-att-1110\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter wp-image-1110\" src=\"https:\/\/telecomlighthouse.com\/wp-content\/uploads\/2016\/03\/NFVI-Virtualization-Layer-Hypervisor.png\" alt=\"NFVI-Virtualization Layer-Hypervisor\" width=\"595\" height=\"517\" srcset=\"https:\/\/telecomlighthouse.com\/wp-content\/uploads\/2016\/03\/NFVI-Virtualization-Layer-Hypervisor.png 894w, https:\/\/telecomlighthouse.com\/wp-content\/uploads\/2016\/03\/NFVI-Virtualization-Layer-Hypervisor-345x300.png 345w, https:\/\/telecomlighthouse.com\/wp-content\/uploads\/2016\/03\/NFVI-Virtualization-Layer-Hypervisor-768x667.png 768w\" sizes=\"auto, (max-width: 595px) 100vw, 595px\" \/><\/a><\/p>\n<p>For the purpose of this discussion, I will zoom only on the NFVI ( NFV Infrastructure) that has three distinct components:<\/p>\n<p>The Hypervisor domain, the Compute domain, and the Network Infrastructure domain.<\/p>\n<p>The virtualization layer\u00a0 is actually the hypervisor, which is responsible for abstracting the hardware resources of a compute domain (physical\/x86 servers). For example, you may have a single physical server ( physical memory and physical compute) but the hypervisor\u00a0 can partition it into multiple virtual\u00a0 memories and <a href=\"https:\/\/telecomlighthouse.com\/blog\/the-misunderstood-facts-about-compute-domain-in-nfv\/\">virtual computes<\/a> in a way that each entity is independent.<\/p>\n<p>Together, the virtualization layer ( which we called hypervisor) with the virtual resources is called \u201cHypervisor domain\u201d.<\/p>\n<h2><\/h2>\n<h2>Step 2: Lets zoom in Virtual Machines<\/h2>\n<p>To understand virtual machines, I will now\u00a0 expand the hypervisor domain to show what is inside this domain.<\/p>\n<p>Have a look at Fig 2 below:<\/p>\n<p>I am showing on the left the same Hypervisor domain as in Fig1 above. But in the figure to the right, I have expanded the Hypervisor domain to show the virtual machines. That is, the virtual resources of the hypervisor domain are now shown as virtual machines.<\/p>\n<p><a href=\"https:\/\/telecomlighthouse.com\/wp-content\/uploads\/2016\/03\/clip_image0034.png\"><img loading=\"lazy\" decoding=\"async\" style=\"background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;\" title=\"clip_image003[4]\" src=\"https:\/\/telecomlighthouse.com\/wp-content\/uploads\/2016\/03\/clip_image0034_thumb.png\" alt=\"clip_image003[4]\" width=\"789\" height=\"341\" border=\"0\" \/><\/a><\/p>\n<p>For simplicity, I have removed the virtual network\/network blocks on the left, as they are not important for this discussion.<\/p>\n<p>The virtualization layer has become the resource\/network manager. The virtual compute\/memory has become virtual machine (VM)<\/p>\n<p>So what is a virtual machine?<\/p>\n<p>A virtual machine\u00a0 provides an environment in which a VNF ( Virtual Network Function) runs.<\/p>\n<p>If you look at the diagram, each Virtual Machine is linked to a VNF .<\/p>\n<p>Let&#8217;s take an example to clarify. There is a VNF1 called Virtual CPE and another VNF2 called Virtual Firewall. From the example above, each then runs into its own virtual machine. They can then be chained and connected internally through a hypervisor domain.<\/p>\n<p>Also, note that virtual machines are logically separate from one another. This makes it possible to run independent operating systems on each virtual machine. For example, Guest Operating System OS1 can be Linux and Guest OS2 can be Solaris (as an example).<\/p>\n<p>And in addition to the Guest operating systems\/OS, did you notice that\u00a0 there is also a need for Host Operating System\/OS, which is an environment in which the hypervisor runs.Keep this important point in mind, as I discuss containers in the next paragraph.<\/p>\n<p>Let&#8217;s take the journey forward and now remove the Virtual Machines.<\/p>\n<h2><\/h2>\n<h2>Step 3. Remove virtual machines and introduce containers!<\/h2>\n<p>Now instead of virtual machine, I introduce a totally new component Container<\/p>\n<p><a href=\"https:\/\/telecomlighthouse.com\/wp-content\/uploads\/2016\/03\/clip_image0044.png\"><img loading=\"lazy\" decoding=\"async\" class=\"alignnone\" style=\"background-image: none; padding-left: 0px; padding-right: 0px; display: inline; padding-top: 0px; border: 0px;\" title=\"clip_image004[4]\" src=\"https:\/\/telecomlighthouse.com\/wp-content\/uploads\/2016\/03\/clip_image0044_thumb.png\" alt=\"Docker container in NFV\" width=\"731\" height=\"340\" border=\"0\" \/><\/a><\/p>\n<p>VNF1 now runs in container 1 and VNF2 runs in container 2 providing the same functionality as virtual machines.<\/p>\n<p>What we have achieved is the same functionality as a virtual machine but within the same OS, which is Linux here.<\/p>\n<p>Did you notice that there is no need for Guest OS now?<\/p>\n<p>Simple architecture;\u00a0 isn&#8217;t it?<\/p>\n<h2><\/h2>\n<h2>What have we achieved with containers?<\/h2>\n<p>1. There is no need for Guest Operating System (OS) in the container environment as you can see that the Host OS is Linux. Therefore, they are lighter weight and need less overhead compared to virtual machines<\/p>\n<p>2. Architecture is simplified by removing the hypervisor as now the containers can retain sufficient isolation at the OS level inside the same Host OS.<\/p>\n<p>3. Virtual Machine provides hardware level virtualization\u00a0 meaning classic virtual machines take a host and partition it via hypervisor software. This essentially means that VMs are isolated from the OS of the host machine. You can run a windows Host over a Linux operating system.On the other hand, containers provide OS level virtualization. That is in the same OS, applications can keep themselves isolated. This is far less overhead compared to VM as the whole OS is not duplicated.<\/p>\n<p>That\u2019s it about the Containers.<\/p>\n<h2><\/h2>\n<h2>Future of containers for NFV<\/h2>\n<p>Let&#8217;s face it, the current NFV architecture and standards are based on the Virtual machines.<\/p>\n<p>Containers are still new to NFV. There are still a lot of development going on especially from a security point of view. As you can see that the Host OS is exposed to all containers so there could be potential multi-tenancy security issues.<\/p>\n<p>However, they do promise a good future considering the ease and simplicity of running the VNFs in such environments. Also, they can open a door to running microservices instead of running a complete VNF over a virtual machine.<\/p>\n<p>For <a href=\"https:\/\/telecomlighthouse.com\/blog\/virtual-cpe-deployment-sprint-marathon\/\">example in the case of virtual CPE<\/a>, a lot of its components can be decomposed into small containers and chained together. By decomposing the functions, this will provide an opportunity for small software vendors to develop small functions of a VNF easily with less overhead.<\/p>\n<p>Did this guide help you in understanding the containers in a simple way ?<\/p>\n<p>Share your views in the following comments section.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The emerging Docker containers have potential to revolutionalize NFV. After all, they are lightweight compared to virtual machines; they need less overhead and resources; and, they can provide application isolation running in the same operating system, they live in. That means,\u00a0 if a Virtual Network function (VNF) in NFV can run in a Docker container [&hellip;]<\/p>\n","protected":false},"author":2,"featured_media":1831,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[9],"tags":[],"class_list":["post-1095","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-nfv"],"_links":{"self":[{"href":"https:\/\/telecomlighthouse.com\/index.php?rest_route=\/wp\/v2\/posts\/1095","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/telecomlighthouse.com\/index.php?rest_route=\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/telecomlighthouse.com\/index.php?rest_route=\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/telecomlighthouse.com\/index.php?rest_route=\/wp\/v2\/users\/2"}],"replies":[{"embeddable":true,"href":"https:\/\/telecomlighthouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcomments&post=1095"}],"version-history":[{"count":0,"href":"https:\/\/telecomlighthouse.com\/index.php?rest_route=\/wp\/v2\/posts\/1095\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/telecomlighthouse.com\/index.php?rest_route=\/wp\/v2\/media\/1831"}],"wp:attachment":[{"href":"https:\/\/telecomlighthouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fmedia&parent=1095"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/telecomlighthouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Fcategories&post=1095"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/telecomlighthouse.com\/index.php?rest_route=%2Fwp%2Fv2%2Ftags&post=1095"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}