arrow
Return

Characterizing and optimizing Kernel resource isolation for containers

delete2023-04-01
delete4
PRE
AI
王琨 cover
王琨 (Kun Wang)
S
Song Wu *
K
Kun Suo
Y
Yijie Liu
H
Hang Huang
Z
Zhuo Huang
金海 (Hai Jin)
DOI:10.1016/j.future.2022.11.018delete
deleteOriginal
deleteOriginal request for help
deleteShare
deleteSave
Abstract

Abstract

En 中文
Container-based virtualization has become increasingly popular as a lightweight alternative to hyper -visor-based virtualization in cloud computing. Isolation is a fundamental property for consistent and reliable performance for cloud environment. However, the isolation between containers is much weaker than virtual machines as containers on the same host share one underlying host kernel. Existing works have mainly focused on the isolation problems at physical resources (e.g. CPU) level and almost not discussed with kernel resources (e.g. lock). In this paper, we perform a study to quantify kernel resource isolation for containers with a new microbenchmark, KRIBench. Then we describe kernel resource isolation issues and identify several kernel resources competition behind the poor isolation. Furthermore, we design and implement Valve, a general and flexible system that reduces kernel resources competition through limiting usage of system calls. Valve adopts Pareto-based container identification to locate misbehaving containers and supply-demand model to manage usage of system calls. The evaluation results demonstrate that our system can effectively enhance the kernel resource isolation for containers with negligible performance overhead.(c) 2022 Elsevier B.V. All rights reserved.
Keywords:
Container
Isolation
Kernel resource
System call
Performance interference
Cloud computing

Journal

F
Future Generation Computer Systems-The International Journal of eScience
IF:
6.1
Papers:
6.8K
Citations:
2.3W

Organization

U
university system of georgia
Scholars:
7.3W
Papers: 6.5W
Citations: 101