1 kernel 1.1 virtualization , isolation 1.2 resource management 1.2.1 two-level disk quota 1.2.2 cpu scheduler 1.2.3 i/o scheduler 1.2.4 user beancounters 1.3 checkpointing , live migration kernel the openvz kernel linux kernel, modified add support openvz containers. modified kernel provides virtualization, isolation, resource management, , checkpointing. of vzctl 4.0, openvz can work unpatched linux 3.x kernels, reduced feature set. virtualization , isolation each container separate entity, , behaves largely physical server would. each has own: files system libraries, applications, virtualized /proc , /sys, virtualized locks, etc. users , groups each container has own root user, other users , groups. process tree a container sees own processes (starting init). pids virtualized, init pid 1 should be. network virtual network device, allows container have own ip addresses, set of netfilter (iptables), , routing rules. devices if needed, container can granted access real devices network ...