Each container runs a userspace OS. It is a shared library which implements most of OS concepts such as Linux process, VFS, and TCP/IP. FTL kernel provides a minimal interface to implement Linux system calls in userspace, just like a hypervisor.
FTL combines the best of microkernels (flexible & secure) and monolithic kernels (performant & simple). Our goal is to make lightweight containers as secure as VMs, and unlock new OS-level abilities in applications, without sacrificing performance:
FTL Linux ┌────────────────────────────────┐ ┌────────────────────────────────┐ │┏━━━━━━━━━━━━━┓ ┏━━━━━━━━━━━━━┓│ │┏━━━━━━━━━━━━━┓ ┏━━━━━━━━━━━━━┓│ │┃ ┃ ┃ ┃│ │┃ ┃ ┃ ┃│ │┃ Linux ┃ ┃ Linux ┃│ │┃ Linux ┃ ┃ Linux ┃│ │┃ Process ┃ ┃ Process ┃│ │┃ Process ┃ ┃ Process ┃│ │┃ ┃ ┃ ┃│ │┃ ┃ ┃ ┃│ │┃╌╌╌╌╌ Linux system calls ╌╌╌╌╌┃│ │┗━━━━━━━━━━━━━┛ ┗━━━━━━━━━━━━━┛│ │┃ ┃│ └────────────────────────────────┘ │┃ Userspace OS ┃│ ╌╌╌╌╌╌╌╌ Linux's interface ╌╌╌╌╌╌╌ │┃ (Process, VFS, TCP, ...) ┃│ ╔════════════════════════════════╗ │┗━━━━━━━━━━━━━━━━━━━━━━━━━━━━━━┛│ ║ ║ └────────────────────────────────┘ ║ Linux Kernel ║ ╌╌╌╌╌╌╌ minimal interface ╌╌╌╌╌╌╌╌ ║ ║ ╔════════════════════════════════╗ ║ process, fork/exec, memory, ║ ║ FTL Kernel ║ ║ signals, TCP/IP, /proc, ║ ║ vCPU, memory, drivers, ... ║ ║ /dev, drivers ... ║ ╚════════════════════════════════╝ ╚════════════════════════════════╝
Userspace OS design also enables you to extend most of Linux kernel features without kernel/eBPF programming. You can add printfs, apply security updates, and add new features quickly and safely. In FTL, OS is just a library. Read more.