<?xml version="1.0" encoding="UTF-8"?><rss xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:atom="http://www.w3.org/2005/Atom" version="2.0" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:googleplay="http://www.google.com/schemas/play-podcasts/1.0"><channel><title><![CDATA[nativly.cloud Blog]]></title><description><![CDATA[Insights from the team at Nativly on building technology for mental health, medical innovation, and meaningful human connection.]]></description><link>https://blog.nativly.cloud</link><image><url>https://substackcdn.com/image/fetch/$s_!lMWX!,w_256,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa978198d-6106-4db6-935f-0a10b1d0ec94_200x200.png</url><title>nativly.cloud Blog</title><link>https://blog.nativly.cloud</link></image><generator>Substack</generator><lastBuildDate>Tue, 14 Apr 2026 06:20:43 GMT</lastBuildDate><atom:link href="https://blog.nativly.cloud/feed" rel="self" type="application/rss+xml"/><copyright><![CDATA[nativly.cloud]]></copyright><language><![CDATA[en]]></language><webMaster><![CDATA[nativly@substack.com]]></webMaster><itunes:owner><itunes:email><![CDATA[nativly@substack.com]]></itunes:email><itunes:name><![CDATA[Cristian Boarna]]></itunes:name></itunes:owner><itunes:author><![CDATA[Cristian Boarna]]></itunes:author><googleplay:owner><![CDATA[nativly@substack.com]]></googleplay:owner><googleplay:email><![CDATA[nativly@substack.com]]></googleplay:email><googleplay:author><![CDATA[Cristian Boarna]]></googleplay:author><itunes:block><![CDATA[Yes]]></itunes:block><item><title><![CDATA[Exotic Containerization in the Wild]]></title><description><![CDATA[Looking beyond the conventional configurations to see what containerization can do when the kernel, runtime and host are pushed to their limits.]]></description><link>https://blog.nativly.cloud/p/exotic-containerization-in-the-wild</link><guid isPermaLink="false">https://blog.nativly.cloud/p/exotic-containerization-in-the-wild</guid><dc:creator><![CDATA[Cristian Boarna]]></dc:creator><pubDate>Sat, 25 Oct 2025 19:36:20 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!aYep!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aYep!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aYep!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aYep!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aYep!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aYep!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aYep!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg" width="1400" height="788" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/ebfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:788,&quot;width&quot;:1400,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:null,&quot;alt&quot;:&quot;What is Docker? | by Techbriel | Jul, 2022 | Medium&quot;,&quot;title&quot;:null,&quot;type&quot;:null,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:null,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="What is Docker? | by Techbriel | Jul, 2022 | Medium" title="What is Docker? | by Techbriel | Jul, 2022 | Medium" srcset="https://substackcdn.com/image/fetch/$s_!aYep!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aYep!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aYep!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aYep!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Febfb2acb-9e5f-4332-9a71-1ef74350211a_1400x788.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>In this post we will cover some deeply technical topics but not in-depth, so we can still see the forest for the trees. Namely, ways in which containers are used to provide services and capabilities at scale for features that hum silently in the background from serverless functions (AWS Lambda, Google/Firebase Cloud Functions, OpenFaaS) and local Kubernetes cluster upgrade testing that can serve millions through per request containers to CI/CD systems(Azure DevOps, Github Actions, BitBucket Pipelines) and self-cannibalizing container image building environments (BuildKit, kaniko, makisu, buildah).</p><p>While we will not cover the conceptual basics of Docker, to better set the stage, let&#8217;s refresh how Docker and other container engines work behind the scenes.</p><h3>Core Architecture and Technical Foundations</h3><h4>The Container Model</h4><p>At its foundation, Docker leverages Linux kernel features to create isolated execution environments. Windows (for Linux containers HyperV/WSL2) and MacOS (Alpine Linux VM on Apple&#8217;s Hypervisor/Virtualization.framework) fundamentally run Docker through a Linux virtual machine where the containers are actually created and run.</p><p>The primary mechanisms include:</p><p><strong>Namespaces</strong> provide process isolation by creating separate views of system resources. Docker uses multiple namespace types: PID namespaces isolate process trees, network namespaces provide independent network stacks, mount namespaces create isolated filesystem views, UTS namespaces separate hostname and domain names, IPC namespaces isolate inter-process communication, and user namespaces map container users to different host users for security.</p><p><strong>Control Groups (cgroups)</strong> manage and limit resource consumption. They restrict CPU usage, memory allocation, disk I/O bandwidth, and network bandwidth for each container. This prevents individual containers from monopolizing host resources and enables predictable performance characteristics.</p><p><strong>Union Filesystems</strong> enable Docker&#8217;s layered image architecture. Technologies like OverlayFS, AUFS, or Btrfs stack multiple filesystem layers, allowing efficient storage and rapid container instantiation. Each layer is read-only except the topmost container layer, which captures runtime changes.</p><p>As Docker did not appear out of the void, it builds on the shoulder of giants, the foundational components are provided by the Linux kernel and it&#8217;s modular scalable design with the above mentioned namespaces, cgroups and union filesystems. From the most run-of-the-mill to the more exotic implementations, they all tweak the dials and knobs provided by the foundational components above.</p><h3>Exotic Usages</h3><h4>1. Triple-Nested Docker (Docker-in-Docker-in-Docker) for CI/CD</h4><p>As this is covering the more advanced patterns we consider </p><ul><li><p>DooD (Docker-outside-of-Docker)</p><ul><li><p>Container mounts the host&#8217;s Docker socket <code>/var/run/docker.sock </code>into a container without running a separate daemon. The container uses the host&#8217;s Docker daemon to create sibling containers rather than nested ones.</p></li></ul></li><li><p>Docker-in-Docker (DinD)</p><ul><li><p>Container mounts the host&#8217;s Docker socket into a container running its own Docker daemon. This creates a fully functional Docker environment within the container. However, this technique has significant security implications. The inner Docker daemon requires privileged mode, granting extensive access to host resources. Volume mounts can access the host filesystem. Nested containers may bypass security policies.</p></li></ul></li></ul><p>as known and will not go in depth on them.</p><p>Instead, by building on top of DinD we can have DinDinD (Docker-in-Docker-in-Docker) which, while it may seem an anti-pattern, is used in CI/CD platform to provide isolation of client pipelines as follows:</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Q32N!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Q32N!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png 424w, https://substackcdn.com/image/fetch/$s_!Q32N!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png 848w, https://substackcdn.com/image/fetch/$s_!Q32N!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png 1272w, https://substackcdn.com/image/fetch/$s_!Q32N!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Q32N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png" width="1074" height="648" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:648,&quot;width&quot;:1074,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:99188,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.nativly.cloud/i/177077711?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Q32N!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png 424w, https://substackcdn.com/image/fetch/$s_!Q32N!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png 848w, https://substackcdn.com/image/fetch/$s_!Q32N!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png 1272w, https://substackcdn.com/image/fetch/$s_!Q32N!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F9de642c5-5cd8-4a97-9bea-b33c36637b31_1074x648.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>A host runs Docker, which spawns a CI runner container (first level), which spawns build job containers (second level), which themselves build and test Docker images (third level).</p><p>This extreme nesting creates massive complexity. Each layer adds overhead and potential failure points. Security boundaries become unclear as privileges cascade through layers. However, multi-tenant CI platforms sometimes use this to provide complete isolation between customer builds while allowing those customers to use Docker themselves.</p><p>The above paradigm can be seen in action, for example, on AWS ECS Fargate serverless containers which do not allow privileged mode to avoid &#8220;noisy neighbours&#8221; meddling with other containers running on the respective host. This famously prevent ECS Fargate from being used as build agents for various CI systems that allowed &#8220;on-premise/custom agents&#8221; such as GitLab/Github/TeamCity.</p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.nativly.cloud/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.nativly.cloud/subscribe?"><span>Subscribe now</span></a></p><h4>2. Kubernetes-in-Docker (KIND) Clusters</h4><p>Kubernetes-in-Docker runs entire Kubernetes clusters inside Docker containers. Each Kubernetes node becomes a Docker container, creating a full cluster on a single machine. This pattern serves local development, CI/CD testing of Kubernetes manifests, and training environments.</p><p>KIND creates a control plane container running etcd, API server, scheduler, and controller manager, plus worker node containers running kubelets and container runtimes. The outer Docker manages these node containers while the inner Kubernetes manages application containers inside those nodes. This recursive structure enables testing cluster upgrades, multi-node networking scenarios, and cluster federation patterns without requiring actual infrastructure.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!Layq!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!Layq!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png 424w, https://substackcdn.com/image/fetch/$s_!Layq!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png 848w, https://substackcdn.com/image/fetch/$s_!Layq!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png 1272w, https://substackcdn.com/image/fetch/$s_!Layq!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!Layq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png" width="1342" height="1294" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:1294,&quot;width&quot;:1342,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:170474,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.nativly.cloud/i/177077711?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!Layq!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png 424w, https://substackcdn.com/image/fetch/$s_!Layq!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png 848w, https://substackcdn.com/image/fetch/$s_!Layq!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png 1272w, https://substackcdn.com/image/fetch/$s_!Layq!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F0b760981-4754-4f76-a513-0fa933646a83_1342x1294.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>The exotic aspect is running production-scale distributed systems architectures in a development laptop environment. Teams can test complex failure scenarios like node crashes, network partitions, and rolling updates entirely locally.</p><p>To a less extreme, one can leverage KIND to test out helm deployments of complex applications and provide integration testing for charts that have multiple properties that can be tweaked to ensure all scenarios are valid and functional. Of course, provider specific integrations such as <code>AzureAppConfigurationProvider </code>that links Azure App Config to a Kubernetes native ConfigMap requires more setup on the local cluster level.</p><h4>3. Ephemeral Per-Request Containers</h4><p>Some architectures spawn a fresh container for every HTTP request or function invocation (AWS Lambda, Google/Firebase Cloud Functions, Azure Functions, OpenFaaS). Each request gets complete isolation with the container destroyed after response completion. This provides ultimate security isolation at the cost of startup latency.</p><p>Optimizations for this pattern include pre-warmed container pools, aggressive layer caching, and checkpoint/restore functionality. Technologies like <a href="https://aws.amazon.com/blogs/aws/firecracker-lightweight-virtualization-for-serverless-computing/">Firecracker</a> combine container and microVM concepts for sub-second isolated environment startup. Container snapshots enable instant restoration to specific states without full initialization.</p><p>Through extreme optimizations and bespoke runtime creation, we can obtain container runtime&#8217;s feasible at scale that serve a wide variety of use cases from updating your cart to gathering data on the latest geomagnetic storm from IoT sensors.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!IY_b!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!IY_b!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png 424w, https://substackcdn.com/image/fetch/$s_!IY_b!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png 848w, https://substackcdn.com/image/fetch/$s_!IY_b!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png 1272w, https://substackcdn.com/image/fetch/$s_!IY_b!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!IY_b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png" width="1456" height="645" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/af77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:645,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:94568,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.nativly.cloud/i/177077711?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!IY_b!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png 424w, https://substackcdn.com/image/fetch/$s_!IY_b!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png 848w, https://substackcdn.com/image/fetch/$s_!IY_b!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png 1272w, https://substackcdn.com/image/fetch/$s_!IY_b!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Faf77a4f0-8154-4cf1-9674-7e764dc64329_1521x674.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><h4>4. Container Network Chaining</h4><p>Advanced networking creates chains where container A&#8217;s network namespace contains container B, which contains container C, creating nested network isolation layers. Each layer can implement different network policies, firewalls, and routing rules.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!vtlT!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!vtlT!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png 424w, https://substackcdn.com/image/fetch/$s_!vtlT!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png 848w, https://substackcdn.com/image/fetch/$s_!vtlT!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png 1272w, https://substackcdn.com/image/fetch/$s_!vtlT!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!vtlT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png" width="537" height="419" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/a5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:419,&quot;width&quot;:537,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:33499,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.nativly.cloud/i/177077711?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!vtlT!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png 424w, https://substackcdn.com/image/fetch/$s_!vtlT!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png 848w, https://substackcdn.com/image/fetch/$s_!vtlT!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png 1272w, https://substackcdn.com/image/fetch/$s_!vtlT!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fa5087f45-4a74-4dcf-81bf-6a6c2aaaf3e5_537x419.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>This pattern enables sophisticated security architectures. An application container sits inside a network policy enforcement container, which sits inside a monitoring container, which sits inside a VPN container. Each layer adds specific network behavior without modifying the application itself.</p><p>The complexity becomes managing IP routing, DNS resolution, and network debugging across multiple namespace layers. Tools must traverse the entire chain to inspect traffic. Performance degradation from repeated packet processing across layers requires careful measurement.</p><p>This onion layered architecture permits the addition of advanced features on the edge of the application for security, monitoring, authentication and caching among other.</p><h4>5. Distributed Filesystem Inside Containers</h4><p>Distributed storage systems like Ceph, GlusterFS, or Minio run entirely in containers, with each container providing storage nodes. The containers themselves use Docker volumes backed by the distributed filesystem they&#8217;re implementing, creating circular dependencies.</p><p>This chicken-and-egg situation requires careful orchestration. Bootstrap containers initialize the distributed storage, then regular application containers consume it, including the storage system&#8217;s own persistent data. Storage cluster membership changes trigger container migrations, which depend on the storage being available during migration.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!oJHW!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!oJHW!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png 424w, https://substackcdn.com/image/fetch/$s_!oJHW!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png 848w, https://substackcdn.com/image/fetch/$s_!oJHW!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png 1272w, https://substackcdn.com/image/fetch/$s_!oJHW!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!oJHW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png" width="1002" height="594" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:594,&quot;width&quot;:1002,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:74863,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.nativly.cloud/i/177077711?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!oJHW!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png 424w, https://substackcdn.com/image/fetch/$s_!oJHW!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png 848w, https://substackcdn.com/image/fetch/$s_!oJHW!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png 1272w, https://substackcdn.com/image/fetch/$s_!oJHW!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F2272fe1e-8d7e-4eb6-ae16-38ca33fad564_1002x594.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Some architectures take this further by running database clusters where each database node is containerized, storing its data on a distributed filesystem provided by other containerized storage nodes, with the entire system using container orchestration that itself uses the database for state management.</p><h4>6. Container-per-File Isolation</h4><p>Extreme security architectures spawn a container for processing each individual file. Document conversion services might create a container for each PDF rendering, Word document processing, or image transcoding task. The container reads one input file, processes it, writes one output file, and terminates.</p><p>This pattern prevents malicious documents from compromising the system. Even if a specially crafted file exploits the processing software, the compromise is contained within a disposable container with no access to other files or system resources. The overhead is enormous but provides ultimate isolation for processing untrusted content.</p><div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!FWwU!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!FWwU!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png 424w, https://substackcdn.com/image/fetch/$s_!FWwU!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png 848w, https://substackcdn.com/image/fetch/$s_!FWwU!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png 1272w, https://substackcdn.com/image/fetch/$s_!FWwU!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!FWwU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png" width="711" height="780" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:780,&quot;width&quot;:711,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:69192,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/png&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:true,&quot;topImage&quot;:false,&quot;internalRedirect&quot;:&quot;https://blog.nativly.cloud/i/177077711?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!FWwU!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png 424w, https://substackcdn.com/image/fetch/$s_!FWwU!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png 848w, https://substackcdn.com/image/fetch/$s_!FWwU!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png 1272w, https://substackcdn.com/image/fetch/$s_!FWwU!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2F8d1f9118-01d7-4ad8-8a2d-f17af120f75e_711x780.png 1456w" sizes="100vw" loading="lazy"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p>Implementations optimize with container pools, volume mounting strategies, and parallel processing. A service might maintain 100 idle containers ready to process files instantly, with containers recycled after handling a configured number of files to prevent resource leaks.</p><p>This paradigm is useful when dealing with sensitive PII information, such as Stripe when dealing with uploaded documents leverages a similar architecture to ensure your passport or financial documents are processed in a secure enclave.</p><h3>Conclusion</h3><p>These exotic container patterns reveal a fundamental truth about modern infrastructure: the line between clever engineering and controlled chaos is being blurred ever so slightly more with each new implementation. What began as a simple abstraction layer&#8212;isolating processes from one another&#8212;has evolved into recursive, self-referential architectures that push the boundaries of what&#8217;s architecturally sensible.</p><p>The patterns we&#8217;ve explored aren&#8217;t merely technical curiosities. They represent real-world solutions to genuine problems: multi-tenant isolation, zero-trust security, ephemeral compute at planetary scale, and the democratization of complex distributed systems. A developer testing Kubernetes deployments on their laptop using KIND would have needed a datacenter rack a decade ago. A serverless function serving millions of requests through per-invocation containers achieves security isolation that was once thought impossible at scale.</p><p>Yet each pattern carries a warning. Triple-nested Docker environments create debugging nightmares. Per-request containers burn CPU cycles on initialization overhead. Sidecar proliferation can make the cure costlier than the disease. The distributed filesystem bootstrapping dance could be prone to race condition making the AWS DynamoDB DNS updating race condition that took down a good chunk of the internet child&#8217;s play. These aren&#8217;t anti-patterns to avoid&#8212;they&#8217;re calculated trade-offs where security, isolation, and flexibility are purchased with complexity, resources, and operational burden.</p><p>The future promises even more exotic arrangements. WebAssembly runtimes in containers, confidential computing enclaves nested within isolation layers, and quantum-container hybrids (should they ever exist) will continue blurring the boundaries. The containers we consider extreme today will become tomorrow&#8217;s baseline.</p><p>The true mastery lies not in implementing these patterns because you can, but in knowing when you must. Understanding these exotic architectures equips you to make informed decisions when standard approaches fail, when security requirements escalate, or when scale demands innovation. </p><p>Docker didn&#8217;t emerge from the void&#8212;it built on giants. These exotic patterns aren&#8217;t departures from that foundation; they&#8217;re proof that when you provide powerful primitives, engineers will compose them in ways you never imagined. The namespaces, cgroups, and union filesystems that enable a simple web server also enable recursive complexity that would seem absurd if it weren&#8217;t solving real problems at scale.</p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.nativly.cloud/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading nativly.cloud Blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div>]]></content:encoded></item><item><title><![CDATA[VDS 2025: First Day Impressions]]></title><description><![CDATA[On my way to VDS 2025 (Valencia Digital Summit), I caught myself wondering: how do you navigate a conference this big?]]></description><link>https://blog.nativly.cloud/p/vds-2025-first-day-impressions</link><guid isPermaLink="false">https://blog.nativly.cloud/p/vds-2025-first-day-impressions</guid><dc:creator><![CDATA[Alexandra Boarna]]></dc:creator><pubDate>Thu, 23 Oct 2025 09:11:36 GMT</pubDate><enclosure url="https://substackcdn.com/image/fetch/$s_!aPmR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg" length="0" type="image/jpeg"/><content:encoded><![CDATA[<div class="captioned-image-container"><figure><a class="image-link image2 is-viewable-img" target="_blank" href="https://substackcdn.com/image/fetch/$s_!aPmR!,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg" data-component-name="Image2ToDOM"><div class="image2-inset"><picture><source type="image/webp" srcset="https://substackcdn.com/image/fetch/$s_!aPmR!,w_424,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aPmR!,w_848,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aPmR!,w_1272,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aPmR!,w_1456,c_limit,f_webp,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg 1456w" sizes="100vw"><img src="https://substackcdn.com/image/fetch/$s_!aPmR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg" width="1456" height="819" data-attrs="{&quot;src&quot;:&quot;https://substack-post-media.s3.amazonaws.com/public/images/dc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg&quot;,&quot;srcNoWatermark&quot;:null,&quot;fullscreen&quot;:null,&quot;imageSize&quot;:null,&quot;height&quot;:819,&quot;width&quot;:1456,&quot;resizeWidth&quot;:null,&quot;bytes&quot;:10604544,&quot;alt&quot;:null,&quot;title&quot;:null,&quot;type&quot;:&quot;image/jpeg&quot;,&quot;href&quot;:null,&quot;belowTheFold&quot;:false,&quot;topImage&quot;:true,&quot;internalRedirect&quot;:&quot;https://nativly.substack.com/i/176905104?img=https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg&quot;,&quot;isProcessing&quot;:false,&quot;align&quot;:null,&quot;offset&quot;:false}" class="sizing-normal" alt="" srcset="https://substackcdn.com/image/fetch/$s_!aPmR!,w_424,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg 424w, https://substackcdn.com/image/fetch/$s_!aPmR!,w_848,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg 848w, https://substackcdn.com/image/fetch/$s_!aPmR!,w_1272,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg 1272w, https://substackcdn.com/image/fetch/$s_!aPmR!,w_1456,c_limit,f_auto,q_auto:good,fl_progressive:steep/https%3A%2F%2Fsubstack-post-media.s3.amazonaws.com%2Fpublic%2Fimages%2Fdc2e169e-043c-4df2-b0d6-3f036c63db7f_5280x2970.jpeg 1456w" sizes="100vw" fetchpriority="high"></picture><div class="image-link-expand"><div class="pencraft pc-display-flex pc-gap-8 pc-reset"><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container restack-image"><svg role="img" width="20" height="20" viewBox="0 0 20 20" fill="none" stroke-width="1.5" stroke="var(--color-fg-primary)" stroke-linecap="round" stroke-linejoin="round" xmlns="http://www.w3.org/2000/svg"><g><title></title><path d="M2.53001 7.81595C3.49179 4.73911 6.43281 2.5 9.91173 2.5C13.1684 2.5 15.9537 4.46214 17.0852 7.23684L17.6179 8.67647M17.6179 8.67647L18.5002 4.26471M17.6179 8.67647L13.6473 6.91176M17.4995 12.1841C16.5378 15.2609 13.5967 17.5 10.1178 17.5C6.86118 17.5 4.07589 15.5379 2.94432 12.7632L2.41165 11.3235M2.41165 11.3235L1.5293 15.7353M2.41165 11.3235L6.38224 13.0882"></path></g></svg></button><button tabindex="0" type="button" class="pencraft pc-reset pencraft icon-container view-image"><svg xmlns="http://www.w3.org/2000/svg" width="20" height="20" viewBox="0 0 24 24" fill="none" stroke="currentColor" stroke-width="2" stroke-linecap="round" stroke-linejoin="round" class="lucide lucide-maximize2 lucide-maximize-2"><polyline points="15 3 21 3 21 9"></polyline><polyline points="9 21 3 21 3 15"></polyline><line x1="21" x2="14" y1="3" y2="10"></line><line x1="3" x2="10" y1="21" y2="14"></line></svg></button></div></div></div></a></figure></div><p></p><p>On my way to VDS 2025 (Valencia Digital Summit), I caught myself wondering: <em>how do you navigate a conference this big?</em></p><p>With over 3,000 startups, 12,000 professionals from more than 120 countries, 150 corporations, and 800 investors, VDS sets the tone for an event of real impact - one that can help businesses in their quest for growth, launch new startups, connect entrepreneurs with contracts, guide students toward new opportunities, and, at the very least, inspire anyone open enough to listen.</p><p>We&#8217;ve all been there - attending a major event and, by the end, asking ourselves what went wrong. You see groups leaving excited, full of new ideas and energy, while you&#8217;re left feeling unchanged, wondering where you missed the mark.</p><p>So what is the difference between those who make the most of it and those who don&#8217;t? What drives everyone at these events - investors, founders, contractors, students - and what links them all together?</p><p>For me, it all boils down to <strong>purpose</strong>.</p><p>Looking around at VDS, I noticed three kinds of people:</p><ol><li><p><strong>The observers</strong> - those who walk slowly, look around, but stay on the sidelines. They want a piece of the pie but are too afraid to take it.</p></li><li><p><strong>The hesitant go-getters</strong> - they put themselves out there but still hold back, restrained by fear or self-doubt. They believe they&#8217;re doing the right things - maybe even pitching! - but forget that first impressions matter. People sense confidence before they hear your words. How can you trust someone who doesn&#8217;t fully trust themselves or their product?</p></li><li><p><strong>The purposeful ones</strong> - they know exactly why they&#8217;re here and move with intention. You can see it in their walk, hear it in their voice. Every action they take has direction. They hunt opportunities, and they&#8217;re not afraid to seize them.</p></li></ol><p>Purpose isn&#8217;t something you stumble upon - it&#8217;s something you prepare before you even step through the conference doors. The people who leave VDS with new partnerships, investments, or collaborations aren&#8217;t lucky; they&#8217;re clear on their goals, deliberate with their time, and confident in their story.</p><p>Before attending any event - especially one as dynamic as VDS - it helps to ask yourself a few key questions:</p><p>&#9989; <strong>What&#8217;s my mission?</strong> What&#8217;s the one key outcome I want - a connection, feedback, funding, or learning?</p><p>&#9989; <strong>How intentional am I with my time?</strong> Even a coffee break can lead to something big.</p><p>&#9989; <strong>Do I trust myself and my idea?</strong> Confidence always beats perfection.</p><p>&#9989; <strong>Am I listening as much as I&#8217;m talking?</strong> Genuine curiosity opens more doors than self-promotion.</p><p>As Day 1 comes to a close, I realize VDS isn&#8217;t just about startups, investors, or technology - it&#8217;s a mirror. It reflects your own clarity, confidence, and readiness to act. The more purposefully you walk through those halls, the more opportunities seem to find you.</p><p>Tomorrow, I plan to walk a little faster - and a little more certain.</p><p></p><p class="button-wrapper" data-attrs="{&quot;url&quot;:&quot;https://blog.nativly.cloud/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe now&quot;,&quot;action&quot;:null,&quot;class&quot;:null}" data-component-name="ButtonCreateButton"><a class="button primary" href="https://blog.nativly.cloud/subscribe?"><span>Subscribe now</span></a></p><p></p><div class="subscription-widget-wrap-editor" data-attrs="{&quot;url&quot;:&quot;https://blog.nativly.cloud/subscribe?&quot;,&quot;text&quot;:&quot;Subscribe&quot;,&quot;language&quot;:&quot;en&quot;}" data-component-name="SubscribeWidgetToDOM"><div class="subscription-widget show-subscribe"><div class="preamble"><p class="cta-caption">Thanks for reading nativly.cloud Blog! Subscribe for free to receive new posts and support my work.</p></div><form class="subscription-widget-subscribe"><input type="email" class="email-input" name="email" placeholder="Type your email&#8230;" tabindex="-1"><input type="submit" class="button primary" value="Subscribe"><div class="fake-input-wrapper"><div class="fake-input"></div><div class="fake-button"></div></div></form></div></div><p></p>]]></content:encoded></item></channel></rss>