GitXplorerGitXplorer
d

Slim

public
113 stars
20 forks
0 issues

Commits

List of commits on branch master.
Verified
641f6f1718b3adddb660e8cdadc4596d8d464b65

bug fix in accept4 (#5)

wwz30 committed 4 years ago
Verified
1c6cacd299f27513ae4defff3ed276a98f914e20

Instructions for using Slim in Kubernetes (#2)

ccaopeirui committed 5 years ago
Verified
3e80ae8c39069deda53adc1d5d1d185d990a2d6a

instruction to use the secure mode

ddanyangz committed 5 years ago
Verified
e5d27a90a5b354514aeaa1ae2c71b5aec963b657

a setup guide (#1)

ddanyangz committed 5 years ago
Unverified
6c44278b80f49ffd26e099a3f2e518232b61960a

add a pointer to NSDI19 paper

ddanyangz committed 6 years ago
Unverified
1afb4f4722e573f4f0784c11346bf02c36041d3f

MIT License

ddanyangz committed 6 years ago

README

The README file for this repository.

Slim: OS Kernel Support for a Low-Overhead Container Overlay Network

Slim is a low-overhead container overlay networking solution. Unlike traditional container overlay networks that rely on packet encapsulation (e.g., VXLAN), Slim virtualizes the network at a per-connection level, significantly improving throughput, latency, and CPU utilization.

Slim has two modes: secure mode and non-secure mode. Non-secure mode does not require kernel modifications and is easy to deploy. However, non-secure mode should be used only when a container is trusted because the container gets access to its host network. Secure mode addresses this security issue via a Linux kernel module.

Our NSDI 2019 paper (https://danyangzhuo.com/papers/NSDI19-Slim.pdf) describes the technical details of Slim.

Requirement

We have tested on:

  • Ubuntu 16.04
  • Docker
  • Weave Overlay Network

We have tested the following applications:

  • Memcached
  • Nginx
  • Postgres
  • Apache Kafka

How to use this code?

Here is an example to configure a cluster of two machines to use Slim in the non-secure mode. Let's assume machine A has IP address of IP1 and machine B has IP2.

Step 0: Clone the repo, build from source

On machine A and B:

git clone https://github.com/danyangz/slim
pushd slim/socket
make
popd
pushd slim/router
make
popd

Step 0: Secure mode (optional)

To use the secure mode, first compile and insert the kernel module on machine A and B:

git clone https://github.com/danyangz/slim
pushd slim/kern_module
make
sudo insmod slim_kern.ko 
popd

Uncomment the first lines in router/router.cpp and socket/socket.c. Then, compile the secure mode of SlimRouter and SlimSocket:

pushd slim/socket
make
popd
pushd slim/router
make
popd

Step 1: Start the weave network

On machine A:

weave launch

On machine B:

weave launch <IP1>

Step 2: Start the containers

Let's start a container on each machine. Here we simply use standard ubuntu 16.04 image to instantiate containers. We name the container on machine A as c1 and the container on machine B as c2.

On machine A:

eval $(weave env)
docker run --name c1 -v slim/:/slim/ -ti ubuntu:16.04

On machine B:

eval $(weave env)
docker run --name c2 -v slim/:/slim/ -ti ubuntu:16.04

Step 3: Start SlimRouter

On machine A:

cd slim/router
./router <IP1>

On machine B:

cd slim/router
./router <IP2>

Step 4: Speed test

Let's use iperf to test the network speed.

Inside the shell of container c1 on machine A:

apt update
apt install iperf
LD_PRELOAD=/slim/socket/SlimSocket.so VNET_PREFIX=10.32.0.0/12 iperf -s

Inside the shell of container c2 on machine B:

apt update
apt install iperf
LD_PRELOAD=/slim/socket/SlimSocket.so VNET_PREFIX=10.32.0.0/12 iperf -c c1

Support for Kubernetes

Slim supports Kubernetes, and the instructions are in k8s Setup.