[08:44:32] <_joe_> FYI, I'm starting to look into gvisor/kata containers (but mostly the former) to run high risk payloads in production. For now I won't focus at all on GPU support because I'm focusing on wikikube, where the risk is higher; but potentially this is interesting also for e.g. ML payloads where we allow insecure input from the internet [09:52:23] _joe_: Nice. Please CC me on stuff that I can read to follow along, if convenient. Thanks. [09:56:48] <_joe_> btullis: subscribe to https://phabricator.wikimedia.org/T435044 I'd say [12:27:54] Thank you. [13:03:39] NICE! [13:04:26] And as far as my comments about Openstack, I'm not a hater. I say that with love from years of supporting a very odd variant (XenServer/XAPI instead of KVM/Libvirt) at a scale of tens of thousands [13:13:29] Re: Ganeti storage. Users have to pay a large I/O penalty (software RAID-5 -> network RAID-1 -> software RAID-5) to get storage redundancy. I think there are better ways to get these storage guarantees. I know virtualization isn't sexy in a k8s world, but anytime someone wants to kick it around LMK. I've done the VMWare/Openstack/XenServer thing at scale for many years.