Netkit improves container network speed by removing delays

Netkit: Specializing Linux Packet Delivery for Container Networks

Operating SystemsNetworking and Internet Architecture

Summary

Communicating between small programs called containers usually slows down because of how data is handled across separate network spaces. The authors created netkit, which uses a special Linux feature called eBPF to let data move directly between containers without waiting in unnecessary queues. This change lets containers talk to each other as fast as programs running together in the same space, improving speed by up to 37%. netkit works without changing the container programs themselves and fits easily into existing cloud systems.

What this means in practice

  • For cloud infrastructure teams: Enhance Kubernetes container networking performance by integrating netkit to reduce communication delays between containers on the same host.
  • For software platform engineers: Optimize Linux-based container platforms by deploying netkit to achieve near native communication speeds without rewriting applications.

Authors

Daniel Borkmann, Paul Chaignon

Abstract

Cloud-native microservices architectures rely on network namespaces for isolation, with the overhead of container communications remaining a critical performance bottleneck. While colocating containers on the same host mitigates some of this overhead, it cannot match the performance of communication within a single network namespace. Existing solutions either require application rewrites or fail to support the full Linux network stack expected by containerized applications. In this paper, we present netkit, an eBPF-based datapath that specializes the Linux networking stack to eliminate redundant backlog queue traversals during network namespace transitions. netkit leverages eBPF to transparently redirect packets between namespaces, bypassing unnecessary buffering while preserving compatibility with existing container applications. Our implementation in the Linux kernel, integrated with minimal changes to the Cilium network plugin for Kubernetes, improves throughput by up to 37\% and achieves parity between container-to-container and process-to-process communications, effectively closing the performance gap introduced by namespace isolation.