Network Control for Large-Scale Container Clusters

被引:1
作者
Zhang, Weiqi [1 ]
Wang, Baosheng [1 ]
Deng, Wenping [1 ]
Zeng, Hao [1 ]
机构
[1] Natl Univ Def Technol, Coll Comp, Changsha, Hunan, Peoples R China
来源
WIRELESS ALGORITHMS, SYSTEMS, AND APPLICATIONS (WASA 2018) | 2018年 / 10874卷
关键词
Data center; Container network control; Network model; Security isolation;
D O I
10.1007/978-3-319-94268-1_74
中图分类号
TP18 [人工智能理论];
学科分类号
081104 ; 0812 ; 0835 ; 1405 ;
摘要
The recent rise of container systems like Docker has created a lot of excitement in data center. Its ability to package, transfer and run application code across many different environments enables new levels of fluidity in how we manage applications. However, container's easy-to-manage and second-boot features increase the degree of network dispersion and management difficulties, which causes the networking and security issues in container network. Aiming at the lack of control in container network, this paper designs a network control architecture for large-scale container clusters to solve the key issue of large-scale container clusters deployment in the network adapter and isolation control. Specifically, we design two different container network models and a policy-based security isolation by using VLAN partition and iptables. The experimental results show that our network control architecture could achieve rapid VLAN division and accurate isolation of node-to-node communication.
引用
收藏
页码:827 / 833
页数:7
相关论文
共 18 条
[1]   Docker [J].
Anderson, Charles .
IEEE SOFTWARE, 2015, 32 (03) :102-105
[2]   Containers and Cloud: From LXC to Docker to Kubernetes [J].
Bernstein, David .
IEEE CLOUD COMPUTING, 2014, 1 (03) :81-84
[3]  
Bhimani J, 2017, IEEE HIGH PERF EXTR
[4]  
Boettiger Carl, 2015, ACM SIGOPS Operating Systems Review, V49, P71
[5]  
Bui Thanh, 2015, ARXIV150102967
[6]  
de Bruijn N., 2017, EBPF BASED NETWORKIN
[7]   Virtualization vs Containerization to support PaaS [J].
Dua, Rajdeep ;
Raja, A. Reddy ;
Kakadia, Dharmesh .
2014 IEEE INTERNATIONAL CONFERENCE ON CLOUD ENGINEERING (IC2E), 2014, :610-614
[8]   Network Quality of Service in Docker Containers [J].
Dusia, Ayush ;
Yang, Yang ;
Taufer, Michela .
2015 IEEE INTERNATIONAL CONFERENCE ON CLUSTER COMPUTING - CLUSTER 2015, 2015, :527-528
[9]  
Felter W, 2015, INT SYM PERFORM ANAL, P171, DOI 10.1109/ISPASS.2015.7095802
[10]  
Fink J., 2014, CODE4LIB J, V25, P29