Updated on 2023-02-07 GMT+08:00

What Are Kata Containers?

Kata containers are distinguished from common containers in a few aspects.

Each Kata container or rather pod runs on an independent micro-VM with an independent OS kernel, and is securely isolated from other pods at the virtualization layer. As CCI uses shared multi-tenant clusters, security isolation of containers is of higher requirements than that in the scenarios where users have independent, private Kubernetes clusters. With Kata, containers, kernels, compute resources, storage resources, and networks can be isolated between different tenants, protecting users' resources and data from being preempted or stolen.