Skip to content
lesson Cloud computing Intermediate 3 min read

What is a container?

A container packages one application with the files it needs. How it differs from a virtual machine, why developers use containers, and what to ask about yours.

A container is a package that holds one application together with the files it needs to run, kept apart from everything else on the computer. The US National Institute of Standards and Technology (NIST) describes containers as a portable, reusable and automatable way to package and run applications.

How a container differs from a virtual machine

Both let several applications share one physical computer. NIST explains that they keep those applications apart in different ways.

  • A virtual machine sees its own virtual hardware and includes a complete operating system as well as the application and its data.
  • A container does not bring a whole operating system. Containers share the kernel, the core of the operating system, of the machine they run on. The operating system keeps each container separate, so an application sees only itself and its own files.

Sharing the kernel has a consequence. A container built for Linux needs a Linux host, and a Windows container needs a Windows host. Virtual machines have no such limit, so Linux and Windows can run side by side on the same hardware.

The two are often combined. NIST shows containers running inside a virtual machine as one of the standard arrangements.

Why the name fits

NIST says the term is borrowed from shipping containers, which give a standard way of grouping different contents while keeping them apart from each other. A ship or a truck does not need to know what is inside the box. In the same way, a computer set up to run containers can run any of them. Docker is one of the tools NIST names for doing this.

Why developers use them

  • It runs the same everywhere. The packaged application, called an image, can be built on a developer’s machine, moved to a test system and then copied to the live system without being changed.
  • Updates are replacements. A running container is not patched in place. It is destroyed and a new one with the update takes over. NIST notes that this lets teams release changes at a much faster pace.
  • Applications can be split up. A large application is often divided into smaller parts, each with one job and each in its own container, which makes the parts easier to change and scale separately.

What a business owner should know

You will rarely handle a container yourself. You may be told that your website, your booking system or a piece of custom software runs in them. Three things follow from the way they work.

  • Your data is not in the container. Because containers are thrown away and replaced, NIST says the data they use should be kept outside them, in a database or separate storage. Ask where that is and how it is backed up.
  • Someone has to rebuild them. Fixes arrive by building a new image and replacing the old containers. Ask who does that, and how often.
  • There is more to manage. NIST points out that splitting an application into many containers creates many more things to look after and secure.

If the answer on backups is unclear, the 3-2-1 backup rule is the place to start. For applications built and hosted this way, see software development.

Sources

  1. SP 800-190: Application container security guide (National Institute of Standards and Technology) nvlpubs.nist.gov
  2. SP 800-125: Guide to security for full virtualization technologies (National Institute of Standards and Technology) nvlpubs.nist.gov
  3. Containers vs. virtual machines (Microsoft Learn) learn.microsoft.com

Written by Only Tech Solutions.

This is general information, not advice for your situation. See the terms and conditions.

We can sort this for you

More lessons

All lessons

Tell us what needs sorting.

Book a call or send an email. We reply within one business day.