Seawall: performance isolation for cloud datacenter networks
Alan Shieh, Srikanth Kandula, Albert G. Greenberg, Changhoon Kim · 2010
Abstract – While today’s virtual datacenters have hypervi-sor based mechanisms to partition compute resources be-tween the tenants co-located on an end host, they provide little control over how tenants share the network. is opens cloud applications to interference from other tenants, re-sulting in unpredictable performance and exposure to de-nial of service attacks. is paper explores the design space for achieving performance isolation between tenants. We nd that existing schemes for enterprise datacenters suer from at least one of these problems: they cannot keep up with the numbers of tenants and the VM churn observed in cloud datacenters; they impose static bandwidth limits to obtain isolation at the cost of network utilization; they require switch and/or NIC modications; they cannot tol-erate malicious tenants and compromised hypervisors. We propose Seawall, an edge-based solution, that achieves max-min fairness across tenant VMs by sending trac through congestion-controlled, hypervisor-to-hypervisor tunnels.