Abstract:In view of the problem that the memory resource information in Docker container is not isolated,we design a resource information isolation method based on LKM technology.The method in the form of LKM uses system to call hijacking to modify the reading of the procfs file content,so as to realize the function of the Docker container resources information isolation,on which the containers run without any modification can achieve the purpose of resource information isolation.The experiments prove that the resource information isolation function is available.