Untitled

Virtual Machines

Chapter 14

Learning Objectives
  • Discuss Type 1 and Type 2 virtualization.

  • Explain container virtualization and compare it to the hypervisor approach.

  • Understand the processor issues involved in implementing a virtual machine.

  • Understand the memory management issues involved in implementing a virtual machine.

  • Understand the I/O management issues involved in implementing a virtual machine.

  • Compare and contrast VMware ESXi, Hyper-V, Xen, and Java VM.

Introduction to Virtualization
  • Abstraction Layer: A software translation layer between software and physical hardware, managing computing resources.
      - Converts physical resources into logical, or virtual, resources.
      - Users can utilize resources without needing to understand the physical details of the underlying systems.

Virtual Machine Concepts
  • Fundamental Idea: To abstract the hardware of a single computer into multiple execution environments.

  • Layered Approach: Creates a virtual system (Virtual Machine or VM) where operating systems or applications can run.

  • Components:
      - Host: The underlying hardware system.
      - Virtual Machine Manager (VMM) or Hypervisor: Creates and runs virtual machines, providing an interface identical to the host, with exceptions in paravirtualization.
      - Guest: The process utilizing a virtual copy of the host, typically an operating system. Examples include a Windows guest OS running in a VM on a Linux host OS.

System Models
  • Non-Virtual Machine vs. Virtual Machine: Understanding the difference between traditional and virtual environments.
      - Visualization of system architecture with various stacked layers of software and hardware.

Reasons Organizations Use Virtualization
  • Legacy Hardware: Run applications built for outdated hardware.

  • Rapid Deployment: Deploy new VMs in minutes.

  • Versatility: Maximize application variety on a single computer.

  • Consolidation: Share resources among multiple applications simultaneously.

  • Aggregating: Easily combine multiple resources into one.

  • Dynamics: Flexibly allocate hardware resources.

  • Ease of Management: Simplifies software deployment and testing.

  • Increased Availability: Automatically restart VMs on a different host in case of physical server failure.

Hypervisors
  • A virtual machine mimics characteristics of a physical server, configured with processors, RAM, storage, and network connectivity.

  • Once created, a VM can be powered on just like a physical server.

  • Operating systems within a VM access resources presented by the hypervisor, functioning as a proxy to manage resource requests.

Hypervisor Functions
  • Execution Management: Overseeing the runtime of VMs.

  • Device Emulation and Access Control: Managing virtual hardware devices.

  • Privileged Operations Execution: Handling operations requiring higher permissions for guest VMs.

  • VM Lifecycle Management: Administration encompassing the full lifecycle of VMs.

Type 1 Hypervisors
  • Description & Functionality:
      - Installed directly onto a physical server like an operating system.
      - Can control physical resources directly and support guest VMs.
      - Examples: VMware ESXi (vSphere), Microsoft Hyper-V, Oracle VM Server, KVM.

  • Illustration:
      - Depicts hypervisor managing multiple VMs on shared hardware.

Type 2 Hypervisors
  • Description & Functionality:
      - Operates as a software module on top of a host OS, relying on the OS for hardware interactions.
      - Examples: VMware Workstation, VMware Fusion (MacOS), Oracle VM VirtualBox.

  • Illustration:
      - Shows a type 2 hypervisor utilizing a host operating system.

Differences Between Type 1 and Type 2 Hypervisors
  • Performance:
      - Type 1 hypervisors generally outperform Type 2 by not competing resources with an OS.
      - More resources available for VMs on Type 1 due to direct control over the host.
      - More VMs can be hosted on a Type 1 hypervisor.

  • Security:
      - Type 1 hypervisors offer greater security; their VMs cannot impact each other.

  • Usage Scenarios:
      - Type 2 hypervisors allow users to leverage virtualization without needing dedicated servers.
      - Malicious activities in Type 2 can affect multiple VMs due to shared resources.

Benefits and Features of Virtualization
  • Protection: Host systems protected from VMs and vice versa, e.g., viruses less likely to spread.

  • Resource Management: Flexibility to freeze, suspend, copy, or move VMs, including snapshot capabilities for various states.

  • Running Multiple OSes: Allows diverse operating systems to run on a single machine.

  • Cloud Computing: Features support cloud infrastructure actions of creating and managing VMs through APIs.

Paravirtualization
  • Definition: A software-assisted virtualization technique utilizing specialized APIs for optimizing performance.

  • Support: Requires specific paravirtualization support within the OS kernel (e.g., Linux, Windows) for efficient operation.

Hardware-Assisted Virtualization
  • Purpose: Enhanced performance support integrated into AMD and Intel processors.
      - Extensions: AMD-V and VT-x, with Intel offering VM Extensions (VMX) instruction set for efficient hypervisor operations.

  • Benefits: Reduces hypervisor code complexity, allowing faster processing by utilizing processor features directly.

Virtual Appliances
  • Definition: Standalone software packaged as a VM image containing applications and a guest OS.

  • Portability: Independent of hypervisors and architectures, can operate on both Type 1 and Type 2 hypervisors.

  • Advantages: Simplifies deployment over traditional app installations; includes Security Virtual Appliances (SVA) for other VMs.

Container Virtualization
  • Concept: A recent approach where software (virtualization containers) runs atop the host OS kernel, providing isolated execution environments without emulating physical servers.

  • Efficiency: Containers share a common OS kernel, significantly reducing resource overhead.

Kernel Control Groups (cgroups)
  • Features:
      - Resource Limiting: Set limits on resource usage (e.g., memory).
      - Prioritization: Allocate varying CPU or disk IO shares among groups.
      - Accounting: Track resource utilization for potential billing.
      - Control: Freeze processes and manage their checkpointing.

Tasks Performed by a Container Engine
  • Responsibilities include maintaining runtime, managing containers, images, and builds; creating processes for containers; managing file system mount points; and requesting kernel resources.

Phases of Linux Containers
  • Setup: Environment setup for initiating containers.

  • Configuration: Specific applications or commands configured within containers.

  • Management: Ongoing management for efficient operations and seamless transitions for startup and shutdown.

Characteristics of Containers
  • No guest OS is necessary within container environments, simplifying management procedures.

Disadvantages of Using Containers
  • Portability Limitation: Applications rely on the same OS kernel; hence, predominantly limited to Linux systems.

  • Security Vulnerability: Lower overhead but greater potential for security issues compared to full VMs.

Container File System
  • Each container maintains an isolated file system with varying foundational features; containers exist as files and can be adjusted in size easily.

  • Virus checking conducted at a hardware node level to ensure security.

Microservices
  • Related to containers, microservices enable smaller deployable units allowing timely updates and precise scalability for development processes.

Docker
  • Overview: Provides standardized, simplified container management compared to previous systems.

  • Popularity: Preferred for its efficiency in loading container images quickly.

Principal Components of Docker
  • Docker Image: Read-only templates for creating containers.

  • Docker Client: Requests to create new containers using images.

  • Docker Host: Platform executing the applications in containers.

  • Docker Engine: Lightweight runtime responsible for managing containers on a host.

  • Docker Machine: Installs and configures Docker engine on a host.

  • Docker Registry: Stores Docker images.

  • Docker Hub: A public repository for Docker images facilitating collaboration.

Processor Issues in Virtualization
  • Two strategies for processor resource provision:
      1. Chip Emulation: Provides access through software; portable but performance-intensive.
      2. Time Segmentation: Allocates specific physical processors' time slices to virtual processors of VMs.

Memory Management in Virtual Machines
  • Focuses on managing physical resources while configuring VMs with less memory than physical hosts.

  • Hypervisors handle memory requests with:
      - Page Sharing: Efficiently using memory by combining identical pages across VMs.
      - Ballooning: Allocating and reclaiming memory dynamically.
      - Memory Overcommitment: Allowing over-allocation beyond physical memory to improve utilization.

I/O Management in Virtual Machines
  • The operating system interacts with the device driver similar to physical servers, establishing connections through emulated devices managed by hypervisors.

References
  • William, S. (2018). Operating Systems: Internals and Design Principles (Ninth Edition).