What is the difference between a Docker container and a virtual machine?
- Technology:
- Docker
Quick answer
A virtual machine runs a full guest operating system on virtualised hardware, while a container shares the host鈥檚 kernel and isolates only the process, its filesystem and resources, which makes containers much lighter and faster to start.
Detailed explanation
A hypervisor gives each virtual machine its own virtual CPU, memory and disk, and each VM boots a complete operating system. That gives strong isolation and lets you run different operating systems side by side, but each VM costs gigabytes and takes time to boot.
A container is an ordinary process on the host that the Linux kernel isolates with namespaces (its own view of processes, network and filesystem) and limits with cgroups (CPU and memory). Because there is no guest kernel, containers start in milliseconds to seconds and image sizes are often tens of megabytes.
The trade-off is isolation: containers share the kernel, so a kernel vulnerability can affect every container on the host. In practice the two are combined: cloud providers run containers inside VMs.
How to explain it in an interview
A VM virtualises hardware and runs its own operating system, so it is heavy but strongly isolated. A container is just an isolated process that shares the host kernel, using namespaces and cgroups, so it starts quickly and uses far fewer resources. I use containers to package applications consistently, and they usually run inside VMs in the cloud anyway.
Key points
- VM: full guest OS on a hypervisor
- Container: isolated process sharing the host kernel
- Namespaces isolate, cgroups limit resources
- Containers are lighter; VMs isolate more strongly
Common mistakes
- Saying a container contains its own operating system kernel.
- Claiming containers are as isolated as VMs.