Tag: Container

Last updated by at .

Docker Windows Server Container Images

Docker Container Images for Windows Server 1709 and new tagging

Last week Microsoft announced new Windows Server 1709 and the new Windows Server 1709 container images. The new container images in Windows Server version 1709 are highly optimized, especially in size. So for example the new Nano Server Container Image in 1709 is 5x smaller than the Nano Server Container Image in Windows Server 2016.

Microsoft also made some changes to tagging which is interesting.

If you want to use the latest images of the container images based on the Windows Server 2016 (which is in the Long-Term Servicing Channel, LTSC) you just run:

This will give you the latest images of the Windows Server and Nano server container images. If you want to run a specific patch level of the Windows Server 2016 (LTSC)m images, you can run the following:

Docker Windows Server Container Images Size

If you want to use the new Windows Server 1709 container images from the Semi-Annual Channel you can run the following

and again you cans also add a specific base OS container image by using a KB number:

If you already tried out the new container images during the development using the insider images, they still existing:

However, I am not sure what the plan for the insider images is going forward.



Docker for Windows Update Linux Containers

How to run Docker Linux Container on Windows 10 Fall Creator Update

I just blogged about how to run a Docker Linux Container natively on the new Windows Server version 1709. Docker today released a new update for Docker on Windows which also enables this scenario a little bit easier on your Windows 10 machine. It will ask you if you want to use the new feature to run Linux Containers natively on a Hyper-V Container running on Windows 10 (without the Moby VM).

As you can see the only thing right now you have to turn the feature on and off, since in this technical preview it is not yet possible to run Linux and Windows containers in parallel. But I guess soon that will be the case.

What you need is:

  • Windows 10 Fall Creators Update (Build 16299, Version 1709, RS3)
  • Docker for Windows 17.10.0-ce-win36 (13788) or higher

Enable Linux Containers on Windows

You can change the settings in the Docker Settings:

Docker for Windows Settings Enable Linux contianers on Windows

With hat setting on you can now run Linux Containers such as ubuntu on Windows directly, without having a Linux Virutal Machine running in the background to host the Linux containers.

Docker Run Ubuntu on Windows 10 Verions

Now you can also do some other fancy things like run the Azure CLI in a Linux Container on Windows 10.

Docker Azure CLI on Linux on Windows 10 Container

Simple and effective, and it will be even more powerful when you can run Linux and Windows Container in parallel on Windows Sever and on Windows 10.



How to run Docker Linux Container on Windows Server 1709

As mentioned Microsoft released the final version of Windows Server 1709 in the last week. Windows Server 1709 brings a couple of new improvements, especially in the container space. Microsoft and Docker are working on bringing Linux Container support to Windows Server, so you can now run Windows and Linux Container at the same time on a Windows Server Container Host running Windows Server 1709 or Windows 10 with the Fall Creators Update (1709).

In this post I want to show you how you setup up a Container Host to run Windows and Linux Containers at the same time using Docker.

Create Container Host Virtual Machine

Enable Nested Virtualization

If you run Docker on a physical server you can skip this step. If you want to run Docker Containers using Linux inside a Virtual Machine running on Hyper-V you should enable Nested Virtualization for the Container Host Virtual Machine. You can do this by running the following command:

if you want to do this on a Hyper-V Server in Azure, check out this post: How to setup Nested Virtualization in Microsoft Azure

Install Docker Enterprise Edition Preview on Windows Server 1709

First you have to install Docker Enterprise Edition Preview on your Windows Server 1709 container host. You can install the Docker EE preview using PowerShell package management, using the following commands:

As mentioned this is a preview version of Docker EE which enables a bunch of new features, to run Docker in production environments please use Docker EE 17.06.

Enable Docker Linux Containers on Windows

The preview Docker EE package includes a full LinuxKit system (13MB) for use when running Docker Linux containers. To enable this use the following command:

to disable it again use the following:

Run Linux Docker Container on Windows Server

Docker Ubuntu Container on Windows Server

Now you are able to run Linux Containers on Windows Server 1709.

for fun you can also run Nyancat!

Docker Nyan Cat on Windows Server

Things are still in preview, so don’t expect to work 100% 🙂



Windows Server 1709

Microsoft released Windows Server 1709

Microsoft just released the new Windows Server version 1709 which is the first release in the Semi-Annual Channel. The Semi-Annual Channel release cadence to deliver innovation at a faster pace, but you will also need to keep updating your systems to newer versions of Windows Server. As of today, you can download Windows Server 1709 from the Volume license portal or deploy it in Microsoft Azure, since it is available in the Azure Marketplace.

Windows Server 1709 Features and Improvements

Windows Server 1709 will drive innovation in the container space and in the Windows Subsystem for Linux, as well as some Cloud Host improvements in Hyper-V with new support for Storage Class Memory and more. Windows Server 1709 will be only available as Windows Server Core (Standard and Datacenter).

If you want to know more about the new features and improvements in Windows Server 1709, check out my blog post and check also out the Microsoft What’s new in Windows Server 1709 page.

Windows Server news from Microsoft Build 2017 – It is all about Container!

New Windows Server Management Experience

If you want to know more about the new Management Experience called Project Honolulu, check out my blog post:

Microsoft Project Honolulu – The new Windows Server Management Experience

Windows Server Servicing

For more information about the Semi-Annual Channel and Windows Server Servicing check out my blog posts:

Windows Server release information – Windows Server Semi-Annual Channel and LTSC

 

What is next for Windows Server and System Center with a faster release cadence

Windows Server, version 1709 is only the first step in this new world of faster release cadences. The most important aspect of having new releases twice a year is customer feedback will shape the product. You can try the preview builds of Windows Server in the Semi-Annual Channel and provide feedback by joining the Windows Insiders program. You can also join the conversation in the Microsoft Tech Community where we have tons of professionals and experts sharing their learnings and answering questions.



Hyper-V Enhanced Session Mode

10 hidden Hyper-V features you should know about!

Microsoft added some amazing new features and improvements to Hyper-V over the past few years. A lot of them you can use in Windows Server 2016 Hyper-V today, but there are also a lot of features hidden in the user interface and they are also included in Windows 10 Pro or Enterprise. I think this list should you a good idea about some of them.

Nested Virtualization

Hyper-V Nested Virtualization

Hyper-V Nested Virtualization allows you to run Hyper-V in a Hyper-V Virtual Machine. This is great for testing, demo and training scenarios and it work on Windows Server 2016 and Windows 10 Pro and Enterprise. Microsoft Azure will also offer some new Virtual Machine which will offer the Nested Virtualization feature in the Azure public cloud. Nested Virtualization is not just great if you want to run virtual machines inside a virtual machine, it is also great (and I think this will be the largest use case in the future) you can also run Hyper-V Container inside a Hyper-V or Azure Virtual Machine. Hyper-V Containers are a feature will brings the isolation of a Virtual Machine to a fast, light and small footprint container. To enable Nested Virtualization you have the following requirements:

  • At least 4 GB RAM available for the virtualized Hyper-V host.
  • To run at least Windows Server 2016 or Windows 10 build 10565 (and higher) on both the physical Hyper-V host and the virtualized host. Running the same build in both the physical and virtualized environments generally improves performance.
  • A processor with Intel VT-x (nested virtualization is available only for Intel processors at this time).
  • Other Hypervisors will not work

Configure the Virtual Machine for Nested Virtualization follow the following steps:

  • disable Dynamic Memory on Virtual Machine
  • enable Virtualization Extensions on the vCPU
  • enable MAC Address Spoofing
  • set Memory of the Virtual Machine to a minimum of 4GB RAM

To enable the Virtualization Extensions on the vCPU you can run the following PowerShell command

PowerShell Direct

PowerShell Direct Enter-PSSession

Hyper-V PowerShell Direct is also one of the great new features in Windows 10 and Windows Server 2016 Hyper-V. PowerShell Direct allows you to connect to a Virtual Machine using PowerShell without connecting over the network. Instead of the network, PowerShell Direct uses the Hyper-V VMBus to connect from the Hyper-V host to the virtual machine. This is handy if you are doing some automation or you don’t have network access to the virtual machine. In terms of security, you will still need to provide credentials to access the virtual machine.

To use PowerShell Direct you have the following requirements:

  • The virtual machine must be running locally on the Hyper-V host and must be started.
  • You must be logged into the host computer as a Hyper-V administrator.
  • You must supply valid user credentials for the virtual machine.
  • The host operating system must run Windows 10, Windows Server 2016, or a higher version.
  • The virtual machine must run Windows 10, Windows Server 2016, or a higher version.

To use PowerShell Direct just use the Enter-PSSession or Invoke-Command cmdlets with the -VMName, -VMId or VM parameter.

Hyper-V Virtual Switch using NAT

Hyper-V Virtual Switch NAT Configuration

If you are running Hyper-V on your workstation, laptop you know that networking could have been kind of a problem. With the Hyper-V Virtual Switch using NAT, you can now create an internal network for your virtual machines and still allow them to for example have internet access, like you would run your virtual machines behind a router. To use this feature you have the following requirements:

  • Windows 10 and Windows Server 2016 build 14295 or later
  • Enabled Hyper-V role

To enable you can first create an internal switch using PowerShell, the the IP Address on the Virtual NIC on the Management OS and then set the NAT configuration:

To create NAT forwarding rules you can for example use the following command:

Virtual Battery for Virtual Machines

Hyper-V VM battery

With the Windows 10 Insider Build XXXX and later with the release of the Windows 10 Fall Creators Update, Microsoft enabled a Virtual Battery feature for Hyper-V Virtual Machines. This will allow Hyper-V VMs to see the battery status of the host. This is great when you are running Hyper-V on a notebook or if you have a SUV battery on your server

Hyper-V VMConnect – Enhanced Session Mode

Hyper-V Enhanced Session Mode

Interacting with Virtual Machines can be difficult and time consuming using the default VM console, since you can not copy paste or connect devices. VMConnect lets you use a computer’s local resources in a virtual machine, like a removable USB flash drive or a printer and in addition to this, Enhanced session mode also lets you resize the VMConnect window and use copy paste. This makes it almost as if you would use the Remote Desktop Client to connect to the Virtual Machine, without a network connection, instead you will make use of the VMBus.

The Enhanced Session Mode feature was introduced with Windows Server 2012 R2 and Windows 8.1. Enhanced session mode basically provides your Virtual Machine Connection with RDP (Remote Desktop Protocol) capabilities over the Hyper-V VMBus, including the following:

  • Display Configuration
  • Audio redirection
  • Printer redirection
  • Full clipboard support (improved over limited prior-generation clipboard support)
  • Smart Card support
  • USB Device redirection
  • Drive redirection
  • Redirection for supported Plug and Play devices

Requirements for the Enhanced Session Mode are:

  • The Hyper-V host must have Enhanced session mode policy and Enhanced session mode settings turned on
  • The computer on which you use VMConnect must run Windows 10, Windows 8.1, Windows Server 2016, or Windows Server 2012 R2 or higher
  • The virtual machine must have Remote Desktop Services enabled, and run Windows 8.1 (or higher) and Windows Server 2012 R2 (or higher) as the guest operating system.

You can simply use it, by pressing the enhanced session button (if you have all the requirementsOn the Windows 10 Client this is enabled by default on the “host”. On Windows Server you have to enable it first in the Hyper-V Manager under Hyper-V Settings

Hyper-V Manager Zoom Level

Hyper-V VMConnect Zoom Level

In the Windows 10 Creators Update, Microsoft introduced a new feature to the VMConnect Console. This feature allows you to control the zoom level of the Virtual Machine console, this is especially handy if you have a high DPI screen.

Virtual TPM Chip

Hyper-V Virtual TPM

If you are running Windows 10 or Windows Server 2016 or higher you can make use of a feature called Shielded Virtual Machines. This allows you to protect your virtual machines form being accessed from the outside. With this feature Microsoft added different levels of security enhancements. One of them is the possibility to add a Virtual TPM chip to the virtual machine. With that enabled you can use BitLocker or another encryption technology to encrypt your virtual machine disks from inside the VM.

Enable Hyper-V vTPM PowerShell

You can enable the Virtual TPM chip using the Hyper-V Manager or PowerShell. The virtual machine needs to be shut down.

Just to make sure, if you really need full protection, have a look at Shielded Virtual Machines with the Host Guardian Service (HGS).

VM Resource Metering

Hyper-V VM Resource Metering

With Windows Server 2012 Hyper-V Microsoft introduced a new feature in Hyper-V called VM Resource Metering which allows you to measure the usage of a virtual machine. This allows you to track CPU, Memory, Disk and network usage. This is a great feature especially if you need to do charge back or maybe even for trouble shooting.

You can enable VM Resource Metering using PowerShell

To measure the virtual machine, you can used the following command

Export and Share Hyper-V Virtual Machines

Export and Share Hyper-V Virtual Machine

Another feature a lot of people do not know about is that you can export Hyper-V Virtual Machines to copy them to another computer or server. The great thing about this, this can even be done while the virtual machine is running and you can even export the state of the virtual machine with it. You can use the UI to do this, or you just run PowerShell using the Export-VM cmdlet.

In the Windows 10 Fall Creators Update Microsoft also added a button to shared the Virtual Machine. This does not only export the virtual machine but it also create a compressed VM Export File (.vmcz).

Hyper-V Containers

Hyper-V Windows Containers

In Windows 10 and Windows Server 2016 you can run Windows Containers using Docker. While on Windows Server you can choose between running a Windows Container or a Hyper-V Container, you will always run a Hyper-V Container on Windows 10. While Hyper-V Containers and Windows Containers are fully compatible with each other, what means you can start a Windows Container in a Hyper-V Container runtime and the other way around, the Hyper-V Container gives you an extra layer of isolation between your containers and your operating system. This makes running containers not just much more secure but since the Windows 10 Fall Creators Update and Windows Server RS3 (Redstone 3), it will also allow you to run Linux Containers on a Windows Container Host, which will make Windows the best platform to run Windows Containers and Linux Containers side by side.

I hope this short list was helpful and showed you some features you didn’t know were there in Hyper-V. Some of these features are still in preview and are might not available in production versions of Hyper-V. Leave your favorite secret Hyper-V features in the comments!



Azure Nested Virtualization

How to setup Nested Virtualization in Microsoft Azure

At the Microsoft Build Conference this year, Microsoft announced Nested Virtualization for Azure Virtual Machines, and last week Microsoft announced the availability of these Azure VMs, which support Nested Virtualization. Nested Virtualization basically allows you to run a Hypervisor in side a Virtual Machine running on a Hypervisor, which means you can run Hyper-V within a Hyper-V Virtual Machine or within a Azure Virtual Machine, kind a like Inception for Virtual Machines.

Azure Nested Virtualization

You can use Nested Virtualization since Windows Server 2016 or the same release of Windows 10, for more details on this, check out my blog post: Nested Virtualization in Windows Server 2016 and Windows 10

With the release of the Azure Dv3 and Ev3 VM sizes:

  • D2-64 v3 instances are the latest generation of General Purpose Instances. D2-64 v3 instances are based on the 2.3 GHz Intel XEON ® E5-2673 v4 (Broadwell) processor and can achieve 3.5GHz with Intel Turbo Boost Technology 2.0. D2-64 v3 instances offer the combination of CPU, memory, and local disk for most production workloads.
  • E2-64 v3 instances are the latest generation of Memory Optimized Instances. E2-64 v3 instances are based on the 2.3 GHz Intel XEON ® E5-2673 v4 (Broadwell) processor and can achieve 3.5GHz with Intel Turbo Boost Technology 2.0. E2-64 v3 instances are ideal for memory-intensive enterprise applications.

With the upgrade to new Intel Broadwell processors, Microsoft enabled Nested Virtualization, which will allows a couple of different scenarios, when you create a Virtual Machine running Windows Server 2016.

  • You can run Hyper-V Containers (Windows Containers with additional isolation) inside an Azure VM. With future releases we will also be able to run Linux Containers in Hyper-V Containers running on a Windows Server OS.
  • You can quickly spin up and shut down new demo and test environments, and you only pay when you use them (pas-per-use)

How to Setup Nested Virtualization in Azure

Deploy Azure VM

To setup Nested Virtualization inside an Azure Virtual Machine, you first need to create a new Virtual Machines using one of the new instance sizes like Ev3 or Dv3 and Windows Server 2016.I also recommend to install all the latest Windows Server patches to the system.

Optional: Optimize Azure VM Storage

This step is optional, but if you want to better performance and more storage for your Nested Virtual Machines to run on, this makes sense.

Azure VM Data Disks

In my case I attached 2 additional data disks to the Azure VM. Of course you can choose more or different sizes. Now you can see 2 new data disk inside your Azure Virtual Machine. Do not format them, because we gonna create a new storage spaces pool and a simple virtual disk, so we get the performance form both disks at the same time. In the past this was called disk striping.

Azure VM Storage Spaces

With that you can create a new Storage Spaces Storage Pool and a new Virtual Disk inside the VM using the storage layout “Simple” which basically configures it as striping.

Azure VM Storage Spaces PowerShell

I also formatted the disk and set the drive letter to V:, this will be the volume where I will place my nested virtual machines.

Install Hyper-V inside the Azure VM

Install Hyper-V on Windows Server using PowerShell

The next step would be to install the Hyper-V role in your Azure Virtual Machine. You can use PowerShell to do this since this is a regular Windows Server 2016.This command will install Hyper-V and restart the virtual machine.

Azure VM Hyper-V

After the installation you have Hyper-V installed and enabled inside your Azure Virtual Machine, now you need to configure the networking for the Hyper-V virtual machines. For this we will use NAT networking.

Configure Networking for the Nested Environment

Hyper-V NAT Network inside Azure VM

To allow the nested virtual machine to access the internet, we need to setup Hyper-V networking in the right why. For this we use the Hyper-V internal VM Switch and NAT networking. I described this here: Set up a Hyper-V Virtual Switch using a NAT Network

Create a new Hyper-V Virtual Switch

First create a internal Hyper-V VM Switch

Configure the NAT Gateway IP Address

The Internal Hyper-V VM Switch creates a virtual network adapter on the host (Azure Virtual Machine), this network adapter will be used for the NAT Gateway. Configure the NAT gateway IP Address using New-NetIPAddress cmdlet.

Configure the NAT rule

After that you have finally created your NAT network and you can now use that network to connect your virtual machines and use IP Address from 172.21.21.2-172.21.21.254.

Now you can use these IP Addresses to assign this to the nested virtual machines. You can also setup a DHCP server in one of the nested VMs to assign IP addresses automatically to new VMs.

Optional: Create NAT forwards inside Nested Virtual Machines

To forward specific ports from the Host to the guest VMs you can use the following commands.

This example creates a mapping between port 80 of the host to port 80 of a Virtual Machine with an IP address of 172.21.21.2.

This example creates a mapping between port 82 of the Virtual Machine host to port 80 of a Virtual Machine with an IP address of 172.21.21.3.

Optional: Configure default Virtual Machine path

Since I have created an extra volume for my nested virtual machines, I configure this as the default path for Virtual Machines and Virtual Hard Disks.

Create Nested Virtual Machines inside the Azure VM

Azure Nested Virtualization

Now you can basically start to create Virtual Machines inside the Azure VM. You can for example use an existing VHD/VHDX or create a new VM using an ISO file as you would do on a hardware Hyper-V host.

Some crazy stuff to do

There is a lot more you could do, not all of it makes sense for everyone, but it could help in some cases.

  • Running Azure Stack Development Kit – Yes Microsoft released the Azure Stack Development Kit, you could use a large enough Azure virtual machine and run it in there.
  • Configure Hyper-V Replica and replicate Hyper-V VMs to your Azure VM running Hyper-V.
  • Nested a Nested Virtual Machine in a Azure VM – You could enable nesting on a VM running inside the Azure VM so you could do a VM inside a VM inside a VM. Just follow my blog post to created a nested Virtual Machine: Nested Virtualization in Windows Server 2016 and Windows 10

In my opinion Nested Virtualization is mostly help full if you run Hyper-V Containers, but it also works great, if you want to run some Virtual Machines inside a Azure VM, for example to run a lab or test something.



Thomas Maurer Speaking

Speaking at Experts Live Europe 2017 in Berlin

I am proud to announce that I will speak at Experts Live Europe 2017 Conference at August 23-25 in Berlin. Experts Live, formerly known System Center Universe, is one of Europe’s largest community conferences with a focus on Microsoft cloud, datacenter and workplace management. Top experts from around the world present discussion panels, ask-the-experts sessions and breakout sessions and cover the latest products, technologies and solutions. It’s the time of the year to learn, network, share and make valuable connections. Experts Live presents top content with top presenters around Microsoft Windows Server, System Center, Microsoft Azure, Office 365, Intune and much more.

ExpertsLive Europe

After speaking at different System Center Universe and different Experts Live events in the past years around the world, such as Bern, Basel, Kuala Lumpur, Ede, Melbourne and many more, I am really happy to speak this year again at one of the greatest community conferences in Europe.

If you want to know more about the events from the past check out my blog posts:

This year I have the chance to speak in a couple of different sessions, about some really cool stuff focusing on Azure Stack, Windows Server vNext and Azure, Docker and Containers.

Azure Stack - Everything you need to know!

Microsoft released Azure Stack as a Azure appliance for your datacenter. Learn how you deploy, manage and operate a Azure Stack in your datacenter. Learn about the features and options you will get by offering Azure Stack to your customers.

Getting started with Windows Containers, Docker and Azure

In Windows Server 2016 you Microsoft released their first version of Windows and Hyper-V Containers. In this session you will get an overview about how containers work and how you can use them for your deployments and you will learn how you can get started with Containers and Docker on Windows 10, Windows Server or on Microsoft Azure.

Windows Server - What is next in Redstone 3

A little less than one year ago Microsoft released Windows Server 2016. This Fall Microsoft will update Windows Server to the next Current Branch for Business release with new features and improvements together with the Windows 10 Client release. Windows Server will also join the Windows Insider Program and we will see the first innovation coming this summer. Join this session for the best of Windows Server. You will get an overview about the new, exciting improvements that are in Windows Server and how they will improve your day-to-day job.

In this presentation Thomas Maurer (Microsoft MVP) will guide you through the highly anticipated innovations including:

Windows Server Containers, Hyper-V features, Nano Server, Storage, Networking, Security, Windows Server Containers and more!

enjoy summer and hopefully see you in Berlin!