MettEagle: Costs and Benefits of Implementing Containers on Microkernels
Till Miemietz, Viktor Reusch, Matthias Hille, Lars Wrenger, Jana Eisoldt, Jan Klötzke, Max Kurze, Adam Lackorzynski, Michael Roitzsch, Hermann Härtig
Abstract
Today, many applications are hosted by cloud providers. In order to isolate the workloads of different clients, cloud enterprises mostly rely on containers rather than standard processes, since the latter are able to exercise a lot of ambient authority. Containers counter this deficiency by sandboxing processes. To this end, they use dedicated security mechanisms such as seccomp-bpf. However, these mechanisms add complexity to the kernel and increase its attack surface, thus prompting new security challenges.
Processes in microkernel-based systems do not have ambient authority. Thus, they do not require additional security mechanisms to build sandboxes. In this paper, we try to answer the question whether a microkernel-based OS architecture enables a leaner and more secure container infrastructure. Based on a CVE analysis, we show that the conceptual simplicity of containers on microkernels results in a better security posture than that typically found on monolithic systems.
We furthermore demonstrate the practical feasibility of implementing containers on state-of-the-art microkernels by building MettEagle, a prototype container service running on L4Re. We found that applications running in containers on L4Re expose performance characteristics comparable to that of containers on Linux for both synthetic and real-world benchmarks. In some cases, the container implementation of L4Re even outperforms Linux, accelerating container startup latency and improving network performance.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext 651a5c69-5de9-4fac-9d92-c26ab453e818Cited by top-tier papers1
Ask how each one uses itBuilds on8
- Catalyzer: Sub-millisecond Startup for Serverless Computing with Initialization-less BootingDong Du, Tianyi Yu, Yubin Xia, Binyu Zang et al.ASPLOS 2020 · 280 citations
- RunD: A Lightweight Secure Container Runtime for High-density Deployment and High-concurrency Startup in Serverless ComputingZijun Li, Jiagan Cheng, Quan Chen, Eryu Guan et al.USENIX ATC 2022 · 106 citations
- BlackBox: A Container Security Monitor for Protecting Containers on Untrusted Operating SystemsAlexander Van't Hof, Jason NiehOSDI 2022 · 44 citations
- LLFree: Scalable and Optionally-Persistent Page-Frame AllocationLars Wrenger, Florian Rommel, Alexander Halbuer, Christian Dietrich et al.USENIX ATC 2023 · 17 citations
- Groundhog: Efficient Request Isolation in FaaSMohamed Alzayat, Jonathan Mace, Peter Druschel, Deepak GargEuroSys 2023 · 16 citations
Related papers
- A Hardware-Software Co-Design for Efficient Secure ContainersJiacheng Shi, Yang Yu, Jinyu Gu, Yubin XiaEuroSys 2025
- SKernel: An Elastic and Efficient Secure Container System at Scale with a Split-Kernel ArchitectureXiaohu Chai, Keyang Hu, Jianfeng Tan, Tiwei Bie et al.EuroSys 2026 · 1 citation
- CofferOS: Hardening OS-level Virtualization with RustMinkyu Jung, Chanshin Kwak, Junho Ahn, Sunho Park et al.EuroSys 2026
- Security Namespace: Making Linux Security Frameworks Available to ContainersYuqiong Sun, David Safford, Mimi Zohar, Dimitrios Pendarakis et al.USENIX Security 2018 · 79 citations
- RContainer: A Secure Container Architecture through Extending ARM CCA Hardware PrimitivesQihang Zhou, Wenzhuo Cao, Xiaoqi Jia, Peng Liu et al.NDSS 2025
