Your Hidden Container Engine - Systemd

ops-tactics.jpg

You have systemd.

  • It's your init system.
  • You have timers in it.
  • Systemd manages your network configuration.

What do you install when you need OS containers?

The answer can be: " nothing".

You sit on a container engine in systemd.

Its features are:

  • Command or OS containers.
  • Namespaces.
  • IPC isolation.
  • Own hostname.
  • Own networking.

systemd-nspawn is a light-weight, easy-to-configure container engine.
Ready to use. You just don't know about it.

systemd-nspawn

systemd-nspawn is part of the systemd ecosystem.

On Debian, the tools are provided by systemd-container.

One of the useful tools inside it is machinectl.

Install it:

sudo apt install systemd-container

On Debian, to run Debian containers, install debootstrap:

sudo apt install debootstrap

Create a configuration directory for the future containers:

sudo mkdir -p /etc/systemd/nspawn

Architecture

Stop for a moment.
Let's see what architecture will be created here.

On the host:

  • Debian Trixie.
  • Bridge interface ( bridge0).
  • Btrfs.

On the containers:

  • Fixed IP address.
  • Hostname.
  • Snapshots.
  • Deployment from templates.

Bootstrap A Container

You want to create a Debian 13 container.

Issue the following commands:

sudo btrfs subvolume create /var/lib/machines/debian-container
sudo debootstrap --include=systemd,dbus trixie /var/lib/machines/debian-container
  1. The first command creates a subvolume for the container.
  2. The second bootstraps the machine.

Network Configuration

Remember: a bridge interface is configured on the host.

The container requires a fixed IP address.

The address below is only an example. Replace it with an address from your network.

Create the /etc/systemd/nspawn/debian-container.nspawn file.

Add this content to it:

[ Exec]
 Boot=yes
 Hostname=debian-container

[ Network]
 Bridge=bridge0

For the container's networking edit the
/var/lib/machines/debian-container/etc/systemd/network/20-host0.network
file:

[ Match]
 Name=host0

[ Network]
 Address=192.168.1.40/24
 Gateway=192.168.1.1
 DNS=1.1.1.1
 DNS=8.8.8.8

Edit the IP addresses matching to your system.

The systemd-networkd must be enabled in the container to apply this configuration:

sudo systemctl enable --now systemd-networkd

The host systemd manages the container.
The container's own systemd manages the services inside it.

Container Lifecycle Management

Start:

sudo machinectl start debian-container

Enter:

sudo machinectl shell debian-container

Check the container status:

sudo machinectl status debian-container

List running containers:

sudo machinectl list

List available container images:

sudo machinectl list-images

Reboot:

sudo machinectl reboot debian-container

Stop:

sudo machinectl stop debian-container

Remove the container image:

sudo machinectl remove debian-container

Templates

For fast deployment, some architects prefer to use machine templates.
It's a read-only machine that you clone with machinectl.

If you use Btrfs you have the advantages of

  • copy-on-write
  • cloning
  • snapshots.

With Btrfs, the filesystem becomes part of the container architecture.

With ordinary ext4 directories you can imitate some of these actions.
You lose the native filesystem-level advantages of Btrfs snapshots and CoW cloning.

Bootstrap a machine that you will use as a template:

sudo btrfs subvolume create /var/lib/machines/debian-13-template
sudo debootstrap --include=systemd,dbus trixie /var/lib/machines/debian-13-template
  1. Set up the networking for the container.
  2. Start it.
  3. Make your changes, install your software.
  4. Clean up history and cache.
  5. Stop the container.

Make it read-only:

sudo machinectl read-only debian-13-template yes

Now you can clone it for new containers:

sudo machinectl clone debian-13-template newcontainer

Final Whisper

systemd-nspawn doesn't compete with other similar technologies.
It sits there.
Silently.

It has its place in the architecture.

For example:

            [host]
              |
  |-----------|-------------|
  |           |             |
[KVM]      [nspawn]      [podman]
  |           |             |
[VMs]     [OS containers] [apps]

Always remember:

A container is not a virtual machine. The kernel is still shared with the host.

[ Fear the Silence. Fear the Switch. ]