Files
docker_practice/17_ecosystem/README.md
T
yeasy 0b526c1674 docs: drop the as-of date stamps from prose
A reader dates a book by the book. An inline 截至 <date> or (核验日期:<date>)
tells them nothing they cannot infer, and it decays: this cluster's clearest
case is the eight files that carried 截至 2026-05-18 while git showed they were
written 33 days earlier, one commit having later nudged the date a day for
visual consistency.

Two kinds of date deliberately survive, because they are not as-of stamps:

- Forward-looking deadlines. "Sonnet 5 的 $2/$10 是截至 2026-08-31 的介绍价"
  states when a price expires; deleting that date would lose a fact.
- Ledger metadata. verified_at / expires_at / ttl_days in the volatile-facts
  appendices are inputs to check_volatile_facts(), which fails the build when
  they lapse. That is the right home for a verification date — machine-checked
  and self-expiring, rather than prose nothing re-earns.

Event dates are untouched throughout (2026-06-09 GA, 2026-06-12 暂停). Where a
sentence needed the sequence, "截至 2026-07-09 官方模型页已恢复" became
"官方模型页此后已恢复", which keeps the ordering without the observation date.
2026-07-28 11:38:02 -07:00

42 lines
2.0 KiB
Go
Raw Blame History

This file contains ambiguous Unicode characters
This file contains Unicode characters that might be confused with other characters. If you think that this is intentional, you can safely ignore this warning. Use the Escape button to reveal them.
# 第十七章 容器其它生态
> **版本说明**本章介绍的工具和运行时PodmanBuildahSkopeocontainerdKata ContainersgVisorWasmEdge 都保持活跃的开发建议
> - 查阅各项目官方文档获取最新版本
> - 在生产环境使用前验证版本兼容性
> - 关注官方发布说明了解重大变更
本章将介绍 Docker Kubernetes 之外的容器生态技术
同时Docker 自身的生态也在向云构建AI 本地推理和企业级桌面安全扩展当前需要额外关注
* **Docker Model Runner** Docker Desktop / Docker Engine 中管理运行和服务本地 AI 模型支持 OpenAI Ollama 兼容 API并可将 GGUFSafetensors 等模型文件作为 OCI Artifact 管理
* **Docker Build Cloud**通过远程 BuildKit 和共享构建缓存加速本地与 CI 构建适合多平台镜像和团队共享缓存场景
* **Docker Offload**把容器构建和运行卸载到云端适合 VDI受限本机或不支持嵌套虚拟化的开发环境
* **Hardened Docker Desktop / Enhanced Container Isolation (ECI)**通过更强的命名空间隔离敏感挂载保护和系统调用限制降低桌面容器逃逸风险
## 本章内容
* [Fedora CoreOS 简介](17.1_coreos_intro.md)
* 专为容器化工作负载设计的操作系统
* [Fedora CoreOS 安装与配置](17.2_coreos_install.md)
* CoreOS 的安装方式与基本配置
* [Podman](17.3_podman.md)
* 兼容 Docker CLI 的下一代无守护进程容器引擎
* [Buildah](17.4_buildah.md)
* 无需守护进程的 OCI 容器镜像构建工具
* [Skopeo](17.5_skopeo.md)
* 远程检查和管理容器镜像的利器
* [containerd](17.6_containerd.md)
* 作为现代容器生态基石的核心容器运行时
* [安全容器运行时](17.7_secure_runtime.md)
* 通过提供更强隔离性来保证安全的技术方案 Kata ContainersgVisor)。
* [WebAssembly](17.8_wasm.md)
* 一种极具潜力的轻量级跨平台二进制指令格式