filmov
tv
Building high efficient storage infrastructure for secure container on top of SPDK
Показать описание
--
Secure container, like Kata Containers, provides stronger workload isolation using virtualization technology. It requires more overhead when providing storage service due to the extra virtualization layer. SPDK provides a full userspace storage stack with plentiful block features and vhost-user virtualization solutions.
This presentation will introduce how to use SPDK build the storage infrastructure for secure container instead of traditional OS kernel based solutions. It can assign vhost-user type storage device directly to secure container, then provide storage volumes through OCI runtime spec by SPDK. It meets the container image service and provides rootfs to containers without the involvement of OS kernel storage services.
The storage infrastructure building on top of SPDK is efficient and robust for container usage scenarios.
Speakers: Xiaodong Liu, Changpeng Liu
Track: Container Infrastructure
Secure container, like Kata Containers, provides stronger workload isolation using virtualization technology. It requires more overhead when providing storage service due to the extra virtualization layer. SPDK provides a full userspace storage stack with plentiful block features and vhost-user virtualization solutions.
This presentation will introduce how to use SPDK build the storage infrastructure for secure container instead of traditional OS kernel based solutions. It can assign vhost-user type storage device directly to secure container, then provide storage volumes through OCI runtime spec by SPDK. It meets the container image service and provides rootfs to containers without the involvement of OS kernel storage services.
The storage infrastructure building on top of SPDK is efficient and robust for container usage scenarios.
Speakers: Xiaodong Liu, Changpeng Liu
Track: Container Infrastructure