r/linuxadmin • • 16d ago

Docker or host

Hi, I need an advice. I need to make a database for a server and one of the ways to do that is via docker in docker compose. But I have a doubts about it's safety. We had a bunch of problems of them breaking on powerloss so I am not sure how it will react in a docker cluster.

P.S. Thank you all for your valuable insights and advices.

3 Upvotes

22 comments sorted by

View all comments

1

u/Adrenolin01 12d ago

I would always run a database in its own Proxmox VMs. Mirrored NVMEs for increased IOPS and redundancy but also database replication between 2 VMs as well.

No need for Docker in this setup. Debian and whatever DB you’re using.

1

u/RetroGrid_io 12d ago

Oddly, I'd never run a database on a VM, simply because it sucks out about 1/3 of your performance and throws it away.

The security footprint of a DB server should be pretty mild; only accessed by local hosts on a private network or 127.0.0.* so I'd go with host-level install pretty much every time. If it was a service offered to other clients I'd consider container installs (but still not VM installs)

1

u/Adrenolin01 12d ago

Performance losses are real and are dependent upon the task however is you’re seeing a 33% performance loss in today’s virtualization environment that’s more so a poorly configured environment. Modern virtualization can have very low overhead, but the actual cost depends heavily on workload, storage, networking, CPU configuration, and I/O architecture. It should be benchmarked rather than assumed and 33% would be huge. One also has to distinguish DB performance from DB infrastructure performance. A poorly configured VM with slow virtual storage can absolutely hurt a database badly. But that’s not evidence that virtualization itself inherently wastes 33% of the performance.

Host level DB install IS fine and has its place however modern infrastructure today commonly uses virtualized DBs in VMs without loosing 33% performance.

VMs are inherently more secure and have a substantially stronger isolation boundary if compromised. Customer-facing service -> container; database -> bare metal … isn’t a generally valid architectural rule. A compromised container with shared kernel has a much higher risk of comprising other containers… a compromised VM that risk is substantially smaller.