绕过conntrack,使用eBPF增强 IPVS优化K8s网络性能
Skb’s pointer to route is NULL during PREROUTING • No de-fragment is done during PREROUTING IPVS bypass conntrack (con.) • Egress • Original way • Nf local-out -> ip_output nf post-route -> ip_finish_output The new way • Call ip_finish_output directly Pre-route Conntrack Pre-route route IPVS entry Post-route Iptables snat Conntrack Post-route Pre-route IPVS entry BPF SNAT IPVS mode data path IPVS-eBPF0 码力 | 24 页 | 1.90 MB | 1 年前3
共 1 条
- 1