vm containers

VM-per-container explained

There’s a common mental model when it comes to running containers: a single virtual machine (VM), hosting a full Linux OS, running containerd or Docker and managing multiple containers side by side. This is how tools like Docker Desktop, Colima, Lima, and Rancher Desktop work today.

But that’s not the only model—and it’s not the most secure.

With the introduction of Apple’s Container Framework (and the architectural direction we’ve taken at Edera), a new model is becoming more visible: a dedicated VM per container. It sounds heavier—but it isn’t. In fact, it’s more secure, easier to isolate, and opens the door for performance and management gains that the traditional shared-VM model can’t match.

This guide walks through the differences, clarifies common misconceptions, and explains why Edera chose the per-container VM model for production infrastructure.

Traditional model: one VM, many containers

In Docker-based systems like Docker Desktop, a single Linux VM is created (usually via hyperkit or QEMU). That VM runs containerd or dockerd, which orchestrates and executes all containers in a shared kernel and user space.

This works well for development—but it’s risky in production.

Apple Container Framework: a VM per container

Apple flips the model: each container runs inside its own lightweight VM.

Despite how it sounds, this is:

What Edera adds (beyond Apple)

Edera brings this architecture into production, adding:

That last point means:

Demo: Docker vs Apple Container Framework

In this demo:

Result:

What changes with micro-VMs?

Feature Docker / Colima / Lima Apple Container Edera
Kernel per container Shared Isolated Isolated
Nested virtualization needed Yes No No
Full distro inside VM Often Minimal Minimal
Observability + mgmt Limited Limited Built-in
Security boundary Namespace Hypervisor Hypervisor

When you run a VM per container, you’re not just isolating workloads—you’re redefining the threat model.

This is where containerization is headed. Edera’s already there.

To learn more check out our architecture overview.

Last updated on 2026-07-07