Container Traffic Handling via Hypervisor QoS Tagging

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized computing environments, it is challenging to manage and differentiate network bandwidth usage among containers running on the same or different virtual machines, leading to issues where some containers may be starved of resources while others dominate, and traffic from different containers cannot be effectively differentiated.

Innovation Solution

Implementing Quality of Service (QoS) policies that allow for the configuration and enforcement of network bandwidth allocations, prioritization, and traffic handling for individual containers by tagging packets and using hypervisor and management entity interactions to manage network resource pools and traffic flows.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If network bandwidth is shared among containers without differentiation, then device complexity is reduced, but container traffic cannot be effectively differentiated and resource allocation becomes unfair

Engineering Contradiction:
Improvetraffic differentiation capabilityVSAvoidnetwork management complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The network bandwidth is segmented into multiple queues, each associated with a specific container. The hypervisor creates and maintains separate queue structures for different containers, allowing independent traffic management. This segmentation enables the system to differentiate traffic between containers while maintaining a relatively simple overall architecture by leveraging existing networking infrastructure.

Inventive Principle:
Principle #1Segmentation

2Reliability

If QoS policies are implemented for container bandwidth management, then fair resource allocation is achieved, but network management complexity increases

Engineering Contradiction:
Improveresource allocation fairnessVSAvoidQoS management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements feedback mechanisms where the hypervisor monitors network traffic statistics for each container and adjusts bandwidth allocation dynamically. When a container exceeds its allocated bandwidth or when network conditions change, the system receives feedback and modifies queue parameters accordingly, ensuring fair resource allocation without requiring complex manual configuration.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The QoS management system operates autonomously by automatically enforcing bandwidth policies based on pre-configured parameters. The hypervisor self-manages the network queues and bandwidth allocation without requiring continuous external intervention, reducing operational complexity while maintaining fair resource distribution.

Inventive Principle:
Principle #25Self-service

3Productivity

If network resources are pooled for multiple virtual machines, then resource utilization efficiency improves, but managing and differentiating bandwidth among containers becomes difficult

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidbandwidth management ease
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The network queue structure serves multiple functions simultaneously: it provides traffic differentiation, enforces QoS policies, manages bandwidth allocation, and maintains statistical monitoring all within a single unified framework. This multi-functionality allows the system to efficiently manage pooled resources across multiple virtual machines while keeping bandwidth management straightforward through a consistent approach.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10476845B2Traffic handling for containers in a virtualized computing environment
Publication Date: 2019.11.12 VMWARE INC
  • US10476845B2 patent drawing
  • US10476845B2 patent drawing
  • US10476845B2 patent drawing

AI summary

An example method is provided for a computing device to perform traffic handling for a container in a virtualized computing environment. The method may comprise receiving a traffic flow of packets from a virtual machine and identifying a container from which the traffic flow originates based on content of the received traffic flow of packets. The container may be supported by the virtual machine. The method may further comprise retrieving a policy configured for the identified container and handling the received traffic flow of packets according to the policy.