绕过conntrack,使用eBPF增强 IPVS优化K8s网络性能Performance measurement Test topology Test result Service type Short connection cps Short connection P99 latency Long connection pps ClusterIP +40% -31% not available NodePort +64% -47% +22% Test IPVS-BPF IPVS 0 20000 40000 60000 80000 100000 120000 140000 160000 180000 Nodeport short connection Instructions/req Lessons from eBPF • No loop support in eBPF verifier (Linux 4.14) • #param0 码力 | 24 页 | 1.90 MB | 1 年前3
多雲一體就是現在:
GOOGLE CLOUD 的
KUBERNETES
混合雲戰略with Google Cloud Console On-Prem/Public Cloud Provider Any K8s Cluster GCP Connection Proxy K8s API Server Connection Agent End-User Single-Pane of Glass Market- place & Service- Catalog & Builder Stackdriver GCP Services Securing Your Connection to GCP ● GKE Connect Agent installs in your cluster ● Encrypted connection from the K8s cluster to GCP ● No public IP required0 码力 | 32 页 | 2.77 MB | 1 年前3
Kubernetes 管理 Docker 容器kubectl delete deployment hello-node 服务停⽤ minikube stop 遇到问题处理 1. kubectl get nodes 报错 The connection to the server 127.0.0.1:55000 was refused - did you specify the right host or port? 解决⽅法:0 码力 | 5 页 | 675.91 KB | 1 年前3
运维上海2017-Kubernetes 在大规模场景下的service性能优化实战 - 杜军UDP�SCTP���IPV4�IPV6 • ���������� Ø rr, wrr, lc, wlc, sh, dh, lblc… • ������ Ø persistent connection���� IPVS��� IPVS������ • ����LB��: Direct Routing(DR), Tunneling, NAT Ø DR�����L2������������0 码力 | 38 页 | 3.39 MB | 1 年前3
Putting an Invisible Shield on Kubernetes Secretssgx-device- plugin daemonset [1] • kms-plugins deployed as deployment • Interfaces • https + connection reuse • certificate: similar to apiserver ó etcd (X.509) • Version-based key synchronization0 码力 | 33 页 | 20.81 MB | 1 年前3
石墨文档Go在K8S上微服务的实践-彭友顺Server Resolver • DNS resolver is builtin in gRPC framework and its out-of-box for users • When connection fail DNS Resolver can resolve name immediately • In scale-up scenario, DNS Resolver will not resolve0 码力 | 41 页 | 3.20 MB | 1 年前3
共 6 条
- 1













