云計算及云原生虛擬化平臺概述_第1頁
云計算及云原生虛擬化平臺概述_第2頁
云計算及云原生虛擬化平臺概述_第3頁
云計算及云原生虛擬化平臺概述_第4頁
云計算及云原生虛擬化平臺概述_第5頁
已閱讀5頁,還剩25頁未讀, 繼續(xù)免費閱讀

下載本文檔

版權(quán)說明:本文檔由用戶提供并上傳,收益歸屬內(nèi)容提供方,若內(nèi)容存在侵權(quán),請進行舉報或認領

文檔簡介

1、云計算及云原生虛擬化平臺概述Cloud Hypervisor or Cloud Native HypervisorAgendaA Bunch of New Hypervisors and rust-vmmCloud Hypervisor with Cloud NativeFeature enabling in CLH: PMEM and vHost as exampleCommunity & RoadmapCloud Native HypervisorA Bunch of New Hypervisors and rust-vmmHypervisors and Virtual MachinesH

2、ardwareVirtual MachineVirtual MachineVirtual MachineHardwareClosed Source VMware ESXi Microsoft Hyper-VOpen SourceKVM/QEMUXen Project crosvm Firecracker Cloud HypervisorOpen Source Xen Project ACRNHypervisorApplicationHypervisorOperating SystemCrosVMAndroid application sandboxingRust implementationS

3、trong focus on securityLittle emulationCrosVMApril 2017FirecrackerAWS Lambda functionsRust implementationStrong focus on securityVery minimal emulationCrosVMApril 2017FirecrackerOctober 2017Common Virtualization ComponentsKVM API wrappersMemory/Device modelVirtio paravirtualizationKernel loaderCrosV

4、MApril 2017FirecrackerOctober 2017rust-vmmDecember 2018Rust-VMMcrosvmMemory ModelDevice ModelKVM Abstractionvirtio ParavirtualizationVMMGlue CodeACPIVFIOHotplugvhostPCIVMMGlue CodeFirecrackerCloud Hypervisor with Cloud NativeCloud workloads onlyNo legacy hardwareNo platform emulationSecurity, simpli

5、city, auditabilityEasy to be used in sandbox containersGoals11Narrow focusSecurity firstMinimal emulationHardware virtualization, no legacyModularityrust-vmm instance for the cloudShared Pattern12Cloud HypervisorA KVM-based Virtual Machine Monitor (VMM)Based on the rust-vmm cratesCloud workloadsClou

6、d images (Ubuntu, Centos, Windows)Containers (Kata)FunctionsSmall, simple, secure and fastReduced footprint, boot time, TCB and code baseminimal emulationLight and high-performance device modelCrosVMFirecrackerrust-vmmCloud HypervisorApril 2017October 2017December 2018May 2019Linux KernelHost Hardwa

7、reKVMHyper-VHypervisor abstractionKVMHyper-VVFIODeviceManagerCPUManagerMemoryManagerGuestPCIPassthroughvirtioACPIMigrationSnapshot/RestoreHotplugNUMAvhostImage LoaderVMM utilsBlock backendNetwork backendvhost-user backendsCloud HypervisorCloud Hypervisor Featuresx86_64 and aarch64Linux and windows g

8、uestHardware-reduced ACPISnapshot/Restore and Initial Live migrationGuest NUMA topology(CPU/MEMORY AFFNITY)Virtio-mem with multiple NUMA nodesGuest Persistent memory allocationNested guests (including VT-d)seccomp rules containedACPI-based hot plug (CPU, memory and devices)REST API control interface

9、Test Driven Development flow, Azure-based integration testsCloud Hypervisor Device ModelPCI-basedVirtio-memmemory hotplug and resizemultiple numa supportsDifferent memory types including PMEMVirtio-fs for container image sharingVhost-user for fast block/net transport with SPDK/DPDKParavirtualization

10、console, iommu, mem, pmem, rng, vsockvirtio (in VMM) and vhost-user=truevhost-user (Rust backends)Multi-queue, multi-threadedDevice passthrough through VFIOIO_uring supportMinimal legacy devices supportSerial, CMOS, ACPI virtual deviceFeature enabling in CLH: PMEM and vHost as examplePhysical NVDIMM

11、RawfsdaxdevdaxSectornamespace0.0namespace0.1namespace1.0namespace2.0DAX (Ext4/XFS)HostKMEMAbstractionDAXpartition ndctl modeOS LinuxStorage, No DAX/mmapstorageKMEMDRAMDRAMworkload. virtio-blkNuma node 0Numa node 1GuestCloud Hypervisornamespace1.1virtio-memFeature enabling in CLH: PMEMvirtio-memCommu

12、nity & RoadmapCloud Hypervisor Project StatusCurrently at version 0.11.0One new release every 6 weeksUnder the independent cloud-hypervisor github organizationIntel, ARM, Alibaba, Red Hat, Oracle, Microsoft, Coder, Phytium, etcNew governance modelInspired by Kata Containers modelArchitecture committ

13、eeDistributed commit access (Not only Intel)Cloud Hypervisor RoadmapTDX and Total Memory EncryptionLive Migration optimizationVMM live updateVM monitoringNet and block IO rate-limiting.Cloud Native HypervisorCloud NativeCloud HypervisorWhen Cloud Hypervisor falls in love with Cloud Native, they beco

14、me “Cloud Native Hypervisor”Container ImageContainer RuntimenydusrunCrunVrunEWhen OS virtualization cannot satisfy Cloud Nativesrequirements, what the plan?ualizationOSVirt (runC)Hardware Virtualization (runV/Kata Containers)IsrunV(Kata Containers) what the userneeds? Maybe not!Podcontainer containe

15、rHost Linux Kernelcgroup namespace seccompHost Linux Kernelcgroup namespace seccompKata RuntimeHardware virtualizationcgroup namespace seccomprunCKata ContainersagentPodagentcontaineragentcontainerGuest Linux KernelUnified Operation PlaneOpsdevsecuritymonitorlogsContainer runCLinux Native OS virtualizationContainer runDHardware enhanced OS virtualizaitonContainer runETrust enhanced OS virtualizationcontainerdkubeletUnified Control PlaneOS virtualization based container runtimeHardware VirtualizationLets talk ab

溫馨提示

  • 1. 本站所有資源如無特殊說明,都需要本地電腦安裝OFFICE2007和PDF閱讀器。圖紙軟件為CAD,CAXA,PROE,UG,SolidWorks等.壓縮文件請下載最新的WinRAR軟件解壓。
  • 2. 本站的文檔不包含任何第三方提供的附件圖紙等,如果需要附件,請聯(lián)系上傳者。文件的所有權(quán)益歸上傳用戶所有。
  • 3. 本站RAR壓縮包中若帶圖紙,網(wǎng)頁內(nèi)容里面會有圖紙預覽,若沒有圖紙預覽就沒有圖紙。
  • 4. 未經(jīng)權(quán)益所有人同意不得將文件中的內(nèi)容挪作商業(yè)或盈利用途。
  • 5. 人人文庫網(wǎng)僅提供信息存儲空間,僅對用戶上傳內(nèi)容的表現(xiàn)方式做保護處理,對用戶上傳分享的文檔內(nèi)容本身不做任何修改或編輯,并不能對任何下載內(nèi)容負責。
  • 6. 下載文件中如有侵權(quán)或不適當內(nèi)容,請與我們聯(lián)系,我們立即糾正。
  • 7. 本站不保證下載資源的準確性、安全性和完整性, 同時也不承擔用戶因使用這些下載資源對自己和他人造成任何形式的傷害或損失。

評論

0/150

提交評論