netkit paper: container network namespaces cost up to 31% throughput on Linux

tianyin_xu · x · 2026-10-01

A blog post by pchaigno previews his eBPF workshop paper on netkit, co-written with Daniel, showing how netkit devices and the bpfredirectpeer helper can tailor the Linux datapath for container networks. Benchmarks found two processes in one namespace achieve 31% higher TCPCRR throughput than two containers on the same host, and two hosts beat containers-over-the-wire by 26%. Since namespace switches are logical boundaries, this overhead has no fundamental reason to exist — the paper traces causes in per-CPU backlog queues and RPS/RSS handling, and shows how netkit specializes packet delivery to eliminate it.

Original post →

More from Infra

Infra channel →