Score
Designs, implements, and evaluates container runtime components and their integration with orchestration and host systems, addressing runtime internals, compatibility, and containerized execution (including edge deployments). Builds and operates runtime management, configuration, tuning, optimization and debugging tooling, and performs security hardening and pod snapshotting to support reliable, secure containerized workloads.
Containerization enhances operational efficiency but intensifies multidimensional security challenges—including runtime protection, network isolation, configuration compliance, software supply chain security, and monitoring-response capabilities. To address these, this paper proposes a five-dimensional collaborative governance model for production-grade container security, deeply integrating DevSecOps across the entire lifecycle and transcending traditional perimeter-based defense paradigms. Methodologically, the model unifies eBPF-based real-time runtime detection, OCI image signature verification, SBOM-driven supply chain auditing, zero-trust network policy enforcement, and a tightly coupled Prometheus–Falco incident response mechanism. Evaluated on mainstream cloud-native platforms, the approach reduces critical misconfigurations by 92%, shortens mean vulnerability response time to 3.7 minutes, and enables construction of a CNCF Sig-Security-certified hardened baseline—delivering a practical, layered defense framework for containerized environments.
In the context of HPC–cloud convergence, containers improve deployment portability but suffer performance degradation due to ABI compatibility constraints that hinder hardware-specific optimization. To address this, we propose XaaS (eXecution-as-a-Service), a performance-portable container framework that defers critical compilation decisions—such as architecture-specific optimizations—to deployment time via source-code and intermediate representation (IR) containerization. Our approach integrates LLM-assisted identification of HPC software specialization mechanisms with IR-level deferred specialization and compiler pipeline analysis, enabling end-to-end automated, system-wide optimization across diverse architectures. Experiments demonstrate that XaaS preserves container deployment agility while achieving performance on par with native, hand-tuned builds—effectively breaking the longstanding “portability-at-the-cost-of-performance” bottleneck of conventional containers in HPC environments.
To address the challenges of difficult development and debugging, complex integration testing environments, and high pedagogical barriers in the GlideinWMS distributed system, this paper proposes the “Workspace Container” methodology—a unified, lightweight, containerized environment for development and education. Built upon a multi-container architecture—including Factory, Frontend, compute nodes, and batch systems—it integrates Docker and VS Code to enable one-click local deployment, offline debugging, and seamless IDE collaboration. The key contribution lies in abstracting development, testing, and teaching workflows into reusable, composable, standardized container units, thereby substantially reducing onboarding overhead for new users. Empirical validation across multiple workshops confirms that the full system runs efficiently on commodity laptops, accelerates development and debugging cycles, and significantly improves instructional interactivity and experimental reproducibility.
Existing container solutions for resource-constrained microcontrollers lack runtime dynamic configurability, making them ill-suited for multi-tenant scenarios in dynamic heterogeneous environments. This work proposes and implements a lightweight container runtime middleware that, for the first time, enables container-granularity dynamic scheduling and fine-grained resource access control on Cortex-M microcontrollers. The system employs a metadata-driven architecture and a runtime abstraction layer, ensuring compatibility with execution environments such as RIOT OS and integrating WebAssembly via WAMR. Experimental results on mainstream IoT development boards demonstrate that container-to-host service invocation incurs less than 4 ms of overhead. Furthermore, the system successfully validates a novel application paradigm in TinyML contexts, where native RTOS executes inference while containers retain model weights.
Research on containerization in multi-cloud environments remains fragmented, lacking a systematic, up-to-date synthesis. Method: We conduct a Systematic Mapping Study (SMS) spanning 2013–2024, analyzing 121 high-quality publications through bibliometric analysis, thematic coding, and ISO/IEC 25010 quality attribute modeling. Contribution/Results: We propose the first four-level classification framework—“Theme–Strategy–Quality Attribute–Tactic”—identifying four core research themes, 98 implementation strategies, 10 critical quality attributes, and 47 corresponding architectural tactics. Innovatively, we introduce a two-dimensional challenge-solution taxonomy organized along Security, Automation, Deployment, and Monitoring dimensions. This yields the first structured, reusable landscape of multi-cloud containerization, bridging theoretical research and industrial practice by supporting architecture design and technology selection—thereby addressing a longstanding gap in systematic knowledge integration for this domain.
This work addresses the challenges in edge and embedded application development—namely, heterogeneous software stacks, multi-language runtimes, and difficult debugging—which lead to rigid deployment workflows and complex fault diagnosis. To overcome these limitations, the paper proposes a novel architecture enabling unified end-edge-cloud development. Its core components include a single programming language, a retargetable runtime system, a local recording and replay mechanism for distributed events, and a cross-platform deployment framework. This design breaks down traditional debugging barriers in edge–cloud collaborative development, facilitating seamless scalability, consistent testing, and flexible deployment across heterogeneous environments. Evaluation of the prototype system demonstrates that the proposed approach significantly simplifies deployment procedures and enhances fault diagnosis efficiency.
This work addresses the fragmentation in existing confidential container systems, which often rely on virtual machines or specific trusted execution environments (TEEs), thereby disrupting unified management with standard OCI runtimes. The paper proposes EBCC, an architecture that treats the rich execution environment (REE) anchor and the TEE-side confidential stage as a unified containerized entity. By introducing a TEE backend adapter to abstract underlying heterogeneity, EBCC enables OCI-compliant lifecycle operations. It is the first framework to seamlessly integrate diverse TEEs—including Keystone, SGX, TDX, and OP-TEE—while avoiding significant expansion of the trusted computing base. Experimental results demonstrate EBCC’s functional correctness and strong concurrency on Keystone, broad cross-TEE portability, and only modest, manageable latency overheads, with additional costs primarily confined to host-side management operations.
研究探讨了保护Docker容器和Kubernetes Pod免受中间人攻击的方法,通过使用通信和加密原语的概念模型、AnBxJ Java安全库及七层防火墙,并基于系统性审查提出了零信任架构。
This work addresses the challenge that existing AI systems struggle to dynamically observe, intervene in, and optimize agent behavior at runtime, making it difficult to simultaneously achieve high task success rates, low latency, token efficiency, reliability, and safety. To overcome this limitation, the paper proposes a novel runtime infrastructure layer situated between the model and the application, which treats the AI execution process itself as an optimizable object—departing from conventional approaches that restrict optimization to static model or log-level adjustments. This layer enables proactive intervention and multi-dimensional performance co-optimization through mechanisms such as runtime monitoring, real-time inference, adaptive memory management, fault recovery, and policy enforcement. Experimental results demonstrate that the proposed approach significantly enhances the holistic performance of long-horizon agent workflows across task success rate, response latency, token efficiency, system reliability, and safety compliance.
该研究比较了Docker容器与虚拟机在架构、性能、配置和安全方面的差异,分析了两者在隔离性与效率上的权衡,并提出混合架构作为解决方案。