Docker has always used microVMs (well since 2016)
avsm
30 points
22 comments
October 03, 2026
Related Discussions
Found 5 related stories in 82.8ms across 8,416 title embeddings via pgvector HNSW
- MicroVM sandbox on Win, Mac, Linux, with policy engine pploug · 12 pts · July 14, 2026 · 59% similar
- How microVMs work, by building one in the browser nikhilunni · 15 pts · July 09, 2026 · 58% similar
- You can now run same OCI images as containers or Firecracker microVMs pullrun · 52 pts · July 23, 2026 · 57% similar
- Docker releases cloud sandboxes, enabling safe agentic workloads in the cloud pheonixblade9 · 17 pts · September 24, 2026 · 54% similar
- JetKVM Mini taubek · 538 pts · September 13, 2026 · 52% similar
Discussion Highlights (13 comments)
cr125rider
Is all of docker one “micro” VM though? Or does each container get a clean, fresh one?
sudb
One reason I think a distinction is made is that native Docker-in-Docker can be a real pain, but Docker in a Firecracker microVM "just works".
yjftsjthsd-h
> What if I told you that Docker Desktop has always used microVMs? Then I would say your title is wildly misleading.
unsnap_biceps
Article title is a bit click-baity. The article is only talking about Docker Desktop on Mac or Windows. Docker Linux have not been using microVMs for a decade.
rvz
...*on macOS only and runs qemu as the emulator. We know. But of course the hype of "microVMs" is just a rebranding of existing technologies with some modifications, macOS needed extra virtualization technologies just for containers for years: Docker Desktop macOS (until 2025): QEMU + Virtualization.framework + Linux kernel (without extra drivers) = "microVM". Now they use the native Apple virtualization libraries instead of QEMU for both containers and microVMs. [0] Linux never needed to use KVM for containers, but requires it for microVMs: Linux: KVM + Linux kernel (without extra drivers) = Firecracker "microVM". In reality, it is different depending on the OS that you are using. [0] https://www.docker.com/blog/docker-desktop-for-mac-qemu-virt...
garypdx
Yawn. IBM/AIX's WPARs & LPARs, Sun/Solaris' dynamic system domains & zones, BSD jails. How many times are we going to pat ourselves on the back for reinventing the wheel?
kj4ips
I often wonder what would have happened if rkt had been more successful.
Betelbuddy
Its bending history to call what before were Linux Vms inside Mac or Windows to have containers to that is a real MicroVM. And the current Sandboxes dont offer the same security model - See Docker Sandboxes 0.42.0 security update: CVE-2026-77179 and CVE-2026-79994 https://docs.docker.com/security/security-announcements/
davoneus
I wonder if this is due to Microsoft pushing forward with wslc in the past week or so. I tried pure wslc for a project or two this past week. It got me 90% of the way but not all the way. Still pretty impressive, even if it is another example of extend and extinguish.
screm
And yet it's never picked by coding agents for sandboxes -> https://armature.tech/leaderboards#app/sandboxes
segmondy
I was just exploring the new docker sandbox and saw that they could retain all your data in/out of the sandbox for 30 days. I wash my hand of docker, use with care. Data is gold and lots of companies are now going to be giving their "free" products as a sort of trojan horse to steal your data.
otterley
Docker *Desktop*, not Docker Engine. Most uses of Docker, at least until Kubernetes shifted to containerd, were the latter. The reality is that most running production containers today share a kernel.
jeswin
Dynamic memory hot-plugging is still not as efficient. So if you don't want strict isolation between containers or individual sandboxes around each one of them, avoid VMs to achieve the highest density per box.