Upgrade to Pro
— share decks privately, control downloads, hide ads and more …
Speaker Deck
Sign up for free
Menu
Search
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Features
All features
Private URLs
Password Protection
Custom URLS
Scheduled publishing
Remove Branding
Restrict embedding
Deck Collections
Notes
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Explore
Featured decks
Featured speakers
Programming
Technology
Storyboards
Pricing
Search
Sign in
Sign up for free
Docker_Meetup_Tokyo_23_gVisor_network_traffic_b...
Search
Sponsored
·
SiteGround - Reliable hosting with speed, security, and support you can count on.
→
makocchi
May 15, 2018
Technology
6.3k
3
Share
Embed
Copy iframe code
Copy JS code
Copy link
Start on current slide
Docker_Meetup_Tokyo_23_gVisor_network_traffic_benchmark
makocchi
May 15, 2018
More Decks by makocchi
See All by makocchi
TiDBの始め方 〜今からでも遅くない分散SQL〜
makocchi
0
220
いまこそNewSQLを使ってみよう
makocchi
0
1.8k
Argo Workflowsコトハジメ
makocchi
0
500
クラウドネイティブなDBを使ってみよう!Kubernetes で TiDB を構築・運用する際のポイントを紹介 / how to use tidb with kubernetes
makocchi
2
5.5k
使いこなせ!Argo Workflows / How to use Argo Workflows
makocchi
6
21k
Kubernetes で TiDB を使ってみよう / TiDB on Kubernetes
makocchi
0
970
Kubernetes の Runtime Class について知ろう
makocchi
0
1.2k
GKE Autopilot Gatekeeper の Rego を眺めてみる
makocchi
2
1.2k
CRI についておさらいしよう
makocchi
3
1.6k
Other Decks in Technology
See All in Technology
作品が生態系になった ─ Mini Tokyo 3D から世界へ
nagix
0
180
[2026-09-11]SREは誰のもの?運用エンジニアが始める 「SRE領域への越境」とチームの進化の軌跡 〜Road to NEXT CRE
tosite
0
190
安心して変更できるWebフロントエンドの作り方
pirosikick
4
2k
絵ではじめるKubernetesセキュリティ
aoi1
3
320
2026_devsumi_ozono.pdf
o3
3
460
HRC_Frontend_Conference_Fukuoka_2026.pdf
ts020
0
660
WAF 運用改善の承認サイクル/SRE_BizReach_MIXI_1
visional_engineering_and_design
2
630
AIを活用するために決めた "やらないこと" - 価値に注目する / Not betting on AI
soudai
PRO
1
460
AI時代、データエンジニアが一番おもろい
genshun9
0
470
Tab5をRubyで動くパソコンにする
kishima
2
360
OpenTelemetryのメトリクスをCloudWatchに送ってPromQLで見てみた
ota1022
0
140
Sigmaで作る業務アプリ
kazushiro_honma
0
130
Featured
See All Featured
Why Mistakes Are the Best Teachers: Turning Failure into a Pathway for Growth
auna
0
280
How to Think Like a Performance Engineer
csswizardry
28
2.8k
Building Better People: How to give real-time feedback that sticks.
wjessup
370
20k
Thoughts on Productivity
jonyablonski
76
5.4k
How to Create Impact in a Changing Tech Landscape [PerfNow 2023]
tammyeverts
56
3.5k
Distributed Sagas: A Protocol for Coordinating Microservices
caitiem20
333
23k
How to Build an AI Search Optimization Roadmap - Criteria and Steps to Take #SEOIRL
aleyda
1
2.2k
Large-scale JavaScript Application Architecture
addyosmani
515
110k
30 Presentation Tips
portentint
PRO
1
390
Fight the Zombie Pattern Library - RWD Summit 2016
marcelosomers
234
17k
Building a Scalable Design System with Sketch
lauravandoore
464
34k
The B2B funnel & how to create a winning content strategy
katarinadahlin
PRO
1
510
Transcript
Docker Meetup Tokyo #23 / makocchi Docker Meetup Tokyo #23
LT: gVisor の Network Traffic の性能を比較してみた makocchi
Docker Meetup Tokyo #23 / makocchi about gVisor Google が公開した
OSS のコンテナ runtime Application 側の system call を gVisor が hook し、実行する (Host の Kernel には直接渡されな い) gVisor の中身は 「Sentry」と「Gofer」という 2 つの process に分かれている https://github.com/google/gvisor/blob/master/README.md
Docker Meetup Tokyo #23 / makocchi install gVisor gVisor の導入の仕方は簡単
・「bazel build runsc」で binary を作成することができる ・が、最近は nightly build で手に入るようになった https://storage.googleapis.com/gvisor/releases/nightly/latest/runsc ・Docker で動かす場合は runtime を追加してあげれば OK 追加したら run 時に --runtime=runsc で gVisor を使うことができる docker run --runtime=runsc hello-world
Docker Meetup Tokyo #23 / makocchi limitation of gVisor Docker
で動かすなら 17.09 以上が必要 まだ Pod の中に 1 つのコンテナしかサポートしていない まだ一部の system call (ioctl(FIOASYNC)) が動かない GCP 上では GAE の node.js と java8 で動いているらしい EXPERIM ENTAL
Docker Meetup Tokyo #23 / makocchi gVisor’s Network Performance Network
の性能を検証するにあたり・・・ ・iperf3 を使ってコンテナの中と外の通信トラフィックを計測 (今回はコンテナ同士のトラフィックではなく、コンテナと VM 間) ・比較のために VM 同士及び runc(docker-runc) も計測 (実は kata(cc)-runtime も検証したかったが、iperf3 が動かなかった)
Docker Meetup Tokyo #23 / makocchi gVisor’s Network Performance
Docker Meetup Tokyo #23 / makocchi gVisor’s Network Performance 通常の
gVisor(runsc) だとかなり Network 性能が落ちる ・これは Sentry が packet を処理するからそこがネックになっていると 思われる ・独自の network stack(user space) が実装されていて Host kernel とは隔離されている ・隔離性を犠牲にすれば --network=host を使うことで性能を出すことが可能
Docker Meetup Tokyo #23 / makocchi gVisor’s Network Performance
Docker Meetup Tokyo #23 / makocchi gVisor’s Network Performance 稼働させる時に
2 つの platform を指定することができる --platform=ptrace (default) ・アプリケーションの system call が SYSEMU で実行される ptrace() が実行できる環境であれば gVisor(runsc) を実行することができる --platform=kvm (experimental) ・仮想化支援(Intel-VT とか)を使うことができる ・kvm module が load されてないと実行できない
Docker Meetup Tokyo #23 / makocchi Wrap-up ・gVisor の性能は Sentry
の出来次第 ・Network はかなり性能が落ちるが、--network=host を設定することで ある程度はパフォーマンスを出すことができる ・実は Disk IO も計測したが、やはり他の runtime に比べると性能が劣る ・ptrace と kvm という2つの実行の仕方がある 仮想化支援を使える kvm の方が性能が出そうだが、検証した環境では ptrace の方が性能が良かった (まぁ platform=kvm はまだ experimental ) ・まだ完成度は低いので今後に期待
Docker Meetup Tokyo #23 / makocchi Docker Meetup Tokyo #23
LT: gVisor の Network Traffic の性能を比較してみた makocchi ご清聴ありがとうございました!