在托管 Kubernetes 中采用 VPC 原生网络的舰队级 Pod 部署
Fleet-Scale Pod Deployment with VPC-Native Networking in Managed Kubernetes
浏览论文内容
中文总结 AI 辅助
本文在亚马逊 EKS 上对比三种 VPC 原生 Pod 部署模式,发现前缀委派模式部署速率快,地址配置不依赖 Pod 创建关键路径,且地址使用效率高。
中文摘要 AI 辅助
托管 Kubernetes 的 Pod 部署通常需在 VPC 原生网络与叠加网络之间做选择。公开的 EKS 文档介绍了前缀模式的容量与配置,而现有 CNI 研究主要测量稳态吞吐量和延迟。本文针对亚马逊 EKS 上三种 VPC 原生模式(单个辅助 IP 分配、ENI 预分配、IPv4 前缀委派)开展舰队级 Pod 部署的操作测量研究,以 Cilium 和 Calico 作为叠加网络基线。我们对比了代表性的模式专属暖池设置,因此结果反映了组合操作点。在 400 节点规模下,测试的三地址辅助 IP 暖池需 7403 秒才能部署 80000 个 Pod;采用测试的 ENI 预分配和前缀委派设置时,相同工作负载约 495 秒即可完成,将地址配置移出 Pod 创建关键路径。在已报告的 400 节点运行中,前缀委派实现了约 162 Pod/s 的速率,与最快的叠加网络基线和 ENI 预分配运行处于同一观测范围内,且由于按 /28 块分配地址,每个 Pod 所需的成功 EC2 配置调用比单个 IP 分配更少。因为每个 /28 包含 16 个地址且占用 1 个 IPv4 槽位,拥有 30 个槽位的接口可承载 29 个前缀,对应最多 464 个潜在 Pod 地址;相比之下,当 kubelet 和 CNI 限制相应配置时,单个 IP 分配每个 ENI 约有 30 个 IPv4 槽位。前缀委派还具有更低的已记录网络地址使用率,保留直接 VPC 可达性和流日志可见性,但缺点是 /28 分配需要连续的子网空间。
英文摘要
Managed Kubernetes pod deployment is often presented as a choice between VPC-native and overlay networking. Public EKS documentation describes prefix-mode capacity and configuration, while prior CNI studies primarily measure steady-state throughput and latency. This paper presents an operational measurement study of fleet-scale pod deployment across three VPC-native modes on Amazon EKS: individual secondary-IP allocation, ENI preallocation, and IPv4 prefix delegation, using Cilium and Calico as overlay baselines. We compare representative mode-specific warm-pool settings, so the results describe combined operating points. At 400 nodes, the tested three-address secondary-IP warm pool required 7,403 seconds to place 80,000 pods. With the tested ENI-preallocation and prefix-delegation settings, the same workload completed in approximately 495 seconds, moving address provisioning off the pod-creation critical path. In the reported 400-node runs, prefix delegation achieved approximately 162 pods/s, within the same observed range as the fastest overlay baseline and ENI-preallocation runs, while requiring fewer successful EC2 provisioning calls per pod than individual-IP allocation by allocating addresses in /28 blocks. Because each /28 contains 16 addresses and occupies one IPv4 slot, an interface with 30 slots carries 29 prefixes, representing up to 464 potential pod addresses, compared with approximately 30 IPv4 slots per ENI for individual-IP allocation when kubelet and CNI limits are configured accordingly. Prefix delegation also has lower documented network-address usage and retains direct VPC reachability and flow-log visibility but the trade-off is that /28 allocations require contiguous subnet space.