Umeå University's logo

umu.sePublications
Change search
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf
Security-Performance Trade-offs of Kubernetes Container Runtimes
Umeå University, Faculty of Science and Technology, Department of Computing Science. (Autonomous Distributed Systems Lab)
Umeå University, Faculty of Science and Technology, Department of Computing Science. Elastisys AB. (Autonomous Distributed Systems Lab)ORCID iD: 0000-0003-0106-3049
Umeå University, Faculty of Science and Technology, Department of Computing Science. Elastisys AB. (Autonomous Distributed Systems Lab)ORCID iD: 0000-0002-5970-7276
2020 (English)In: 2020 28th International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems (MASCOTS), IEEE, 2020, p. 1-4Conference paper, Published paper (Refereed)
Abstract [en]

The extreme adoption rate of container technologies along with raised security concerns have resulted in the development of multiplealternative container runtimes targeting security through additional layers of indirection. In an apples-to-apples comparison, we deploy three runtimesin the same Kubernetes cluster, the security focused Kata and gVisor, as well as the default Kubernetes runtime runC. Our evaluation based on three real applications demonstrate that runC outperforms the more secure alternatives up to 5x, that gVisor deploys containers up to 2x faster than Kata, but that Kata executes container up to 1.6x faster than gVisor. Our work illustrates that alternative, more secure, runtimes can be used in a plug-and-play manner in Kubernetes, but at a significant performance penalty. Our study is useful both to practitioners - to understand the current state of the technology in order to make the right decision in the selection, operation and/or design of platforms - and to scholars to illustrate how these technologies evolved over time.

Place, publisher, year, edition, pages
IEEE, 2020. p. 1-4
Series
IEEE International Symposium on Modeling, Analysis, and Simulation of Computer and Telecommunication Systems, ISSN 1526-7539, E-ISSN 2375-0227
National Category
Computer Systems Software Engineering
Research subject
Computer Science
Identifiers
URN: urn:nbn:se:umu:diva-175194DOI: 10.1109/MASCOTS50786.2020.9285946ISI: 000664043400027Scopus ID: 2-s2.0-85098852994ISBN: 978-1-7281-9238-3 (electronic)ISBN: 978-1-7281-9239-0 (print)OAI: oai:DiVA.org:umu-175194DiVA, id: diva2:1469183
Conference
2020 Symposium on Modelling, Analysis, and Simulation of Computer and Telecommunication Systems, Nice, France, November 17-19, 2020
Funder
Wallenberg AI, Autonomous Systems and Software Program (WASP)Available from: 2020-09-21 Created: 2020-09-21 Last updated: 2024-01-04Bibliographically approved

Open Access in DiVA

fulltext(1317 kB)1241 downloads
File information
File name FULLTEXT01.pdfFile size 1317 kBChecksum SHA-512
2e4721589ee5c981142b09537df5e9f921aa3002a52641c957c8199663111a2a3cda74e6fd578e6bed8d9ded30711bdb89bb2aadd51bf0af7c3fe1e569f39122
Type fulltextMimetype application/pdf

Other links

Publisher's full textScopus

Authority records

Viktorsson, WilliamKlein, CristianTordsson, Johan

Search in DiVA

By author/editor
Viktorsson, WilliamKlein, CristianTordsson, Johan
By organisation
Department of Computing Science
Computer SystemsSoftware Engineering

Search outside of DiVA

GoogleGoogle Scholar
Total: 1247 downloads
The number of downloads is the sum of all downloads of full texts. It may include eg previous versions that are now no longer available

doi
isbn
urn-nbn

Altmetric score

doi
isbn
urn-nbn
Total: 957 hits
CiteExportLink to record
Permanent link

Direct link
Cite
Citation style
  • apa
  • ieee
  • vancouver
  • Other style
More styles
Language
  • de-DE
  • en-GB
  • en-US
  • fi-FI
  • nn-NO
  • nn-NB
  • sv-SE
  • Other locale
More languages
Output format
  • html
  • text
  • asciidoc
  • rtf