AiVibe

Cloud & AI Infrastructure

Software Container

A software container packages an application with its dependencies into an isolated unit that shares the host operating system kernel, so it starts quickly and runs consistently across development, test and production.

A software container is a lightweight, isolated runtime environment that packages an application together with its libraries and configuration so that it runs the same way on any compatible host. Unlike a virtual machine, a container shares the host operating system kernel. On Linux, isolation comes from kernel features such as namespaces and control groups (cgroups), which limit what a process can see and how much CPU and memory it can use.

Containers became mainstream with Docker, and their image and runtime formats are now standardised by the Open Container Initiative (OCI). They are the usual unit of deployment for microservices, CI/CD pipelines and Kubernetes clusters, because they start quickly, use fewer resources than VMs and remove differences between development, test and production. Edge gateways increasingly run analytics and protocol services as containers.

Because containers share a kernel, isolation is weaker than with VMs, so hosts must be patched and containers should run without unnecessary privileges or root access. Images should come from trusted sources and be scanned for known vulnerabilities. Containers are designed to be disposable, so persistent data belongs in external volumes or managed storage, and logs should be shipped off the container.

Key points

Where AiVibe comes in

AiVibe Software Services delivers cloud solutions on AWS, Microsoft Azure, Google Cloud or on-premise, together with cloud security, legacy modernisation, data analytics and AI and machine learning services.

Explore AiVibe’s work in Cloud & AI Infrastructure →

Related terms

Ask AiMuruga can explain Software Container for your plant, product or security programme, and draw how it fits.