Untitled
Virtual Machines
Chapter 14
Learning Objectives
Discuss Type 1 and Type 2 virtualization.
Explain container virtualization and compare it to the hypervisor approach.
Understand the processor issues involved in implementing a virtual machine.
Understand the memory management issues involved in implementing a virtual machine.
Understand the I/O management issues involved in implementing a virtual machine.
Compare and contrast VMware ESXi, Hyper-V, Xen, and Java VM.
Introduction to Virtualization
Abstraction Layer: A software translation layer between software and physical hardware, managing computing resources.
- Converts physical resources into logical, or virtual, resources.
- Users can utilize resources without needing to understand the physical details of the underlying systems.
Virtual Machine Concepts
Fundamental Idea: To abstract the hardware of a single computer into multiple execution environments.
Layered Approach: Creates a virtual system (Virtual Machine or VM) where operating systems or applications can run.
Components:
- Host: The underlying hardware system.
- Virtual Machine Manager (VMM) or Hypervisor: Creates and runs virtual machines, providing an interface identical to the host, with exceptions in paravirtualization.
- Guest: The process utilizing a virtual copy of the host, typically an operating system. Examples include a Windows guest OS running in a VM on a Linux host OS.
System Models
Non-Virtual Machine vs. Virtual Machine: Understanding the difference between traditional and virtual environments.
- Visualization of system architecture with various stacked layers of software and hardware.
Reasons Organizations Use Virtualization
Legacy Hardware: Run applications built for outdated hardware.
Rapid Deployment: Deploy new VMs in minutes.
Versatility: Maximize application variety on a single computer.
Consolidation: Share resources among multiple applications simultaneously.
Aggregating: Easily combine multiple resources into one.
Dynamics: Flexibly allocate hardware resources.
Ease of Management: Simplifies software deployment and testing.
Increased Availability: Automatically restart VMs on a different host in case of physical server failure.
Hypervisors
A virtual machine mimics characteristics of a physical server, configured with processors, RAM, storage, and network connectivity.
Once created, a VM can be powered on just like a physical server.
Operating systems within a VM access resources presented by the hypervisor, functioning as a proxy to manage resource requests.
Hypervisor Functions
Execution Management: Overseeing the runtime of VMs.
Device Emulation and Access Control: Managing virtual hardware devices.
Privileged Operations Execution: Handling operations requiring higher permissions for guest VMs.
VM Lifecycle Management: Administration encompassing the full lifecycle of VMs.
Type 1 Hypervisors
Description & Functionality:
- Installed directly onto a physical server like an operating system.
- Can control physical resources directly and support guest VMs.
- Examples: VMware ESXi (vSphere), Microsoft Hyper-V, Oracle VM Server, KVM.Illustration:
- Depicts hypervisor managing multiple VMs on shared hardware.
Type 2 Hypervisors
Description & Functionality:
- Operates as a software module on top of a host OS, relying on the OS for hardware interactions.
- Examples: VMware Workstation, VMware Fusion (MacOS), Oracle VM VirtualBox.Illustration:
- Shows a type 2 hypervisor utilizing a host operating system.
Differences Between Type 1 and Type 2 Hypervisors
Performance:
- Type 1 hypervisors generally outperform Type 2 by not competing resources with an OS.
- More resources available for VMs on Type 1 due to direct control over the host.
- More VMs can be hosted on a Type 1 hypervisor.Security:
- Type 1 hypervisors offer greater security; their VMs cannot impact each other.Usage Scenarios:
- Type 2 hypervisors allow users to leverage virtualization without needing dedicated servers.
- Malicious activities in Type 2 can affect multiple VMs due to shared resources.
Benefits and Features of Virtualization
Protection: Host systems protected from VMs and vice versa, e.g., viruses less likely to spread.
Resource Management: Flexibility to freeze, suspend, copy, or move VMs, including snapshot capabilities for various states.
Running Multiple OSes: Allows diverse operating systems to run on a single machine.
Cloud Computing: Features support cloud infrastructure actions of creating and managing VMs through APIs.
Paravirtualization
Definition: A software-assisted virtualization technique utilizing specialized APIs for optimizing performance.
Support: Requires specific paravirtualization support within the OS kernel (e.g., Linux, Windows) for efficient operation.
Hardware-Assisted Virtualization
Purpose: Enhanced performance support integrated into AMD and Intel processors.
- Extensions: AMD-V and VT-x, with Intel offering VM Extensions (VMX) instruction set for efficient hypervisor operations.Benefits: Reduces hypervisor code complexity, allowing faster processing by utilizing processor features directly.
Virtual Appliances
Definition: Standalone software packaged as a VM image containing applications and a guest OS.
Portability: Independent of hypervisors and architectures, can operate on both Type 1 and Type 2 hypervisors.
Advantages: Simplifies deployment over traditional app installations; includes Security Virtual Appliances (SVA) for other VMs.
Container Virtualization
Concept: A recent approach where software (virtualization containers) runs atop the host OS kernel, providing isolated execution environments without emulating physical servers.
Efficiency: Containers share a common OS kernel, significantly reducing resource overhead.
Kernel Control Groups (cgroups)
Features:
- Resource Limiting: Set limits on resource usage (e.g., memory).
- Prioritization: Allocate varying CPU or disk IO shares among groups.
- Accounting: Track resource utilization for potential billing.
- Control: Freeze processes and manage their checkpointing.
Tasks Performed by a Container Engine
Responsibilities include maintaining runtime, managing containers, images, and builds; creating processes for containers; managing file system mount points; and requesting kernel resources.
Phases of Linux Containers
Setup: Environment setup for initiating containers.
Configuration: Specific applications or commands configured within containers.
Management: Ongoing management for efficient operations and seamless transitions for startup and shutdown.
Characteristics of Containers
No guest OS is necessary within container environments, simplifying management procedures.
Disadvantages of Using Containers
Portability Limitation: Applications rely on the same OS kernel; hence, predominantly limited to Linux systems.
Security Vulnerability: Lower overhead but greater potential for security issues compared to full VMs.
Container File System
Each container maintains an isolated file system with varying foundational features; containers exist as files and can be adjusted in size easily.
Virus checking conducted at a hardware node level to ensure security.
Microservices
Related to containers, microservices enable smaller deployable units allowing timely updates and precise scalability for development processes.
Docker
Overview: Provides standardized, simplified container management compared to previous systems.
Popularity: Preferred for its efficiency in loading container images quickly.
Principal Components of Docker
Docker Image: Read-only templates for creating containers.
Docker Client: Requests to create new containers using images.
Docker Host: Platform executing the applications in containers.
Docker Engine: Lightweight runtime responsible for managing containers on a host.
Docker Machine: Installs and configures Docker engine on a host.
Docker Registry: Stores Docker images.
Docker Hub: A public repository for Docker images facilitating collaboration.
Processor Issues in Virtualization
Two strategies for processor resource provision:
1. Chip Emulation: Provides access through software; portable but performance-intensive.
2. Time Segmentation: Allocates specific physical processors' time slices to virtual processors of VMs.
Memory Management in Virtual Machines
Focuses on managing physical resources while configuring VMs with less memory than physical hosts.
Hypervisors handle memory requests with:
- Page Sharing: Efficiently using memory by combining identical pages across VMs.
- Ballooning: Allocating and reclaiming memory dynamically.
- Memory Overcommitment: Allowing over-allocation beyond physical memory to improve utilization.
I/O Management in Virtual Machines
The operating system interacts with the device driver similar to physical servers, establishing connections through emulated devices managed by hypervisors.
References
William, S. (2018). Operating Systems: Internals and Design Principles (Ninth Edition).