/knowledge/notes/vms-vs-containers
Concept note · ML
VMs vs Containers
Systems
- Studied
- Cluster and Cloud ComputingCOMP90024
- When
- 2023 S1
- Applied in
- Social Sense
- Read / Refreshed
- ~4 min read2026-10-15
Virtual machines run a full OS on emulated hardware. Containers share the host kernel and isolate processes with namespaces and cgroups. The tradeoff: VMs are heavier but more isolated; containers are lighter but less secure.
01
The idea
A hypervisor (Type 1 on bare metal, Type 2 on a host OS) emulates hardware for each VM. Each VM runs its own kernel, init system, and userland. Boot time is seconds to minutes. Disk images are gigabytes. A container shares the host kernel and runs a single process tree. Docker builds images with layers (base OS + app dependencies). Boot time is milliseconds. Images are tens to hundreds of megabytes.
VMs provide stronger isolation: a compromised guest cannot access the host kernel directly. Containers rely on kernel features (cgroups, namespaces) that have had privilege-escalation bugs. Use VMs for untrusted workloads; use containers for density and speed.
02
The maths
03
Try it
04
Where I used it
05
Easy to get wrong
06
Sources
Covered in COMP90024 (2023). Hands-on practice with Docker and Ansible deployments on Melbourne Research Cloud VMs.