Is there a way to pin a container’s CPU to a physical core instead of a vCPU/Hyperthread core?
If there are 2 vCPUs per core with a HT based CPU, would the following work to put that container on one physical core:
lxc config set container limits.cpu 0-1 for first physical core
lxc config set container limits.cpu 2-3 for second physical core
My assumption is that each sequential two vCPU cores = 1 hardware core?
Secondly, would this be of any defense against the new Spectre leaks that have came out recently until software or hardware mitigations are implemented. My understanding is that this new vulnerability can’t cross physical cores?
Thank you for any insight!