Scalable rule management for data centers
Masoud Moshref, Minlan Yu, Abhishek B. Sharma, Ramesh Govindan · 2013
Cloud operators increasingly need more and more fine-grained rules to better control individual network flows for various traffic management policies. In this paper, we explore automated rule management in the context of a system called vCRIB (a virtual Cloud Rule Informa-tion Base), which provides the abstraction of a central-ized rule repository. The challenge in our approach is the design of algorithms that automatically off-load rule processing to overcome resource constraints on hypervi-sors and/or switches, while minimizing redirection traf-fic overhead and responding to system dynamics. vCRIB contains novel algorithms for finding feasible rule place-ments and adapting traffic overhead induced by rule placement in the face of traffic changes and VM migra-tion. We demonstrate that vCRIB can find feasible rule placements with less than 10 % traffic overhead even in cases where the traffic-optimal rule placement may be in-feasible with respect to hypervisor CPU or memory con-straints. 1