发表机构
Isovalent at Cisco(思科旗下 Isovalent)
机构由 AI 辅助整理,请以论文原文为准。AI 中文总结
本文提出基于eBPF的netkit数据通路,特化Linux网络栈以消除命名空间转换中的冗余队列遍历,提升容器间吞吐量达37%,实现与进程间通信性能对等。
AI 中文摘要
云原生微服务架构依赖网络命名空间实现隔离,而容器通信的开销仍然是关键的性能瓶颈。虽然将容器部署在同一主机上可以缓解部分开销,但仍无法达到单一网络命名空间内通信的性能。现有解决方案要么需要重写应用程序,要么无法支持容器化应用所期望的完整Linux网络栈。在本文中,我们提出了netkit,一个基于eBPF的数据通路,它特化了Linux网络栈,以消除网络命名空间转换期间冗余的待处理队列遍历。netkit利用eBPF在命名空间之间透明地重定向数据包,绕过不必要的缓冲,同时保持与现有容器应用的兼容性。我们在Linux内核中的实现,以及对Kubernetes的Cilium网络插件进行最小改动集成,将吞吐量提升了高达37%,并实现了容器间通信与进程间通信的性能对等,有效消除了命名空间隔离带来的性能差距。
英文摘要
Cloud-native microservices architectures rely on network namespaces for isolation, with the overhead of container communications remaining a critical performance bottleneck. While colocating containers on the same host mitigates some of this overhead, it cannot match the performance of communication within a single network namespace. Existing solutions either require application rewrites or fail to support the full Linux network stack expected by containerized applications. In this paper, we present netkit, an eBPF-based datapath that specializes the Linux networking stack to eliminate redundant backlog queue traversals during network namespace transitions. netkit leverages eBPF to transparently redirect packets between namespaces, bypassing unnecessary buffering while preserving compatibility with existing container applications. Our implementation in the Linux kernel, integrated with minimal changes to the Cilium network plugin for Kubernetes, improves throughput by up to 37\% and achieves parity between container-to-container and process-to-process communications, effectively closing the performance gap introduced by namespace isolation.
CommentsAccepted for publication at eBPF'26
Journal refProceedings of the 4th Workshop on eBPF and Kernel Extensions (eBPF'26). September 29th, 2026. Prague, Czech Republic. Pages 83-89