Mainframe Path Start learning free
Core10 min readLesson 3 of 3

Containers, OpenShift and co-location with z/OS

Containers and Kubernetes run on Linux on Z just as on other platforms, as long as images are built for s390x. Running Linux next to z/OS on the same machine allows fast, private connections such as HiperSockets, but it is not the right answer for every workload.

Containers on s390x

A container image contains binaries, so it is built for a particular architecture. Image registries handle this with multi-architecture images: one image name and tag points to a manifest list with a separate image for each platform, such as linux/amd64, linux/arm64 and linux/s390x. When a node on IBM Z pulls the image, the runtime chooses the s390x variant automatically. Many official base images on public registries publish an s390x variant; check before you depend on one.

Building a multi-architecture image (illustrative)
$ docker buildx build \
    --platform linux/amd64,linux/s390x \
    -t registry.example.com/payments/api:1.4.0 \
    --push .

$ docker buildx imagetools inspect registry.example.com/payments/api:1.4.0
  Platform:  linux/amd64
  Platform:  linux/s390x
Reading the build commandWhat it means
buildx build
Docker's builder that can produce images for several platforms in one go
--platform linux/amd64,linux/s390x
Build one image for x86 and one for IBM Z, published under the same tag
--push
Push the images and the manifest list to the registry
imagetools inspect
Show which platforms a tag actually contains, a quick check before deploying

Building for a foreign architecture on an x86 laptop usually uses emulation, which is slow but fine for small images. Many teams add a native s390x build agent to their CI/CD pipeline instead.

Kubernetes and OpenShift on Z

Upstream Kubernetes supports s390x, and Red Hat OpenShift Container Platform is supported on IBM Z and LinuxONE, with cluster nodes running as z/VM or KVM guests or in LPARs (supported combinations depend on the OpenShift version). From a developer's point of view an OpenShift cluster on Z is the same: the same oc and kubectl commands, the same deployments, routes and operators. The differences are that every image must have an s390x variant and that capacity is measured in IFLs.

Co-location with z/OS

When Linux and z/OS share a machine, they can talk without leaving the box. HiperSockets is a hardware feature that provides TCP/IP connections between LPARs on the same CPC through memory, with no physical network adapter, cable or switch involved. Applications see a normal IP network. For z/OS to Linux traffic, sites can also use SMC-D (Shared Memory Communications - Direct), which lets TCP connections between eligible LPARs on the same machine move data through shared memory, when both sides are configured for it.

A typical co-located design
Mobile appinternet
API layercontainers on Linux on Z
HiperSocketsin-memory TCP/IP
z/OSCICS, Db2, MQ

When not to use Linux on Z

SituationWhy it is a poor fit
Key software is x86-onlyNo s390x build means no deployment, whatever the other benefits
GPU-dependent workThese workloads are generally better served elsewhere
A single small application with no link to z/OSLittle consolidation benefit to justify the platform skills and setup
Team has no Linux on Z skills and no support modelOperational risk outweighs gains until skills and ownership exist
Highly elastic, short-lived capacityPublic cloud bursting may be simpler and cheaper

Common mistakes

Assuming every public image runs on Z

Many images publish s390x variants, but not all. Inspect the manifest list before relying on an image.

Treating HiperSockets as a security control by itself

It keeps traffic off physical networks, but authentication, authorisation and usually encryption are still required.

Choosing the platform before checking the workload

Start from the workload's dependencies and its relationship to z/OS data. If the answer is no s390x support or no link to z/OS, another platform may be better.

What you will see at work

Key terms

Check your understanding.
Take this lesson's quiz and save your progress. Free.

Take the lesson quiz
← Hosting Linux: LPARs, z/VM, KVM and s390xBack to Linux on Z and containers