netkit paper: container network namespaces cost up to 31% throughput on Linux
tianyin_xu · x · 2026-10-01
A blog post by pchaigno previews his eBPF workshop paper on netkit, co-written with Daniel, showing how netkit devices and the bpfredirectpeer helper can tailor the Linux datapath for container networks. Benchmarks found two processes in one namespace achieve 31% higher TCPCRR throughput than two containers on the same host, and two hosts beat containers-over-the-wire by 26%. Since namespace switches are logical boundaries, this overhead has no fundamental reason to exist — the paper traces causes in per-CPU backlog queues and RPS/RSS handling, and shows how netkit specializes packet delivery to eliminate it.
More from Infra
- E2B open-sources Embed, packaging full agent sandbox stack on a single node — badphilosopher · 2026-10-01
- ByteDance Seed finds phase sensitivity in chunked KV-cache compression, retrieval accuracy swings 40 points — ByteDance-Seed · 2026-10-01
- HPE/Broadcom Tomahawk trays for AMD Helios racks: six per rack, copper-heavy scale-up — BenBajarin · 2026-10-01
- The most advanced part of ASML machines, the light source, is made in San Diego — Darpinian · 2026-10-01
- Agent plugin /who-ate-my-flops speeds PyTorch jobs up to 3.6x, PRs merged into six OSS repos — ruilong_li · 2026-10-01
- Starcloud to fly NVIDIA H100 aboard Firefly spacecraft to validate lunar-orbit data center — ycombinator · 2026-10-01