4 ms·
That's still really massive. It would only make sense in very high security environments. Honestly running system services in VMs would be cheaper and just as
by api 1y ago
That's still really massive. It would only make sense in very high security environments.
Honestly running system services in VMs would be cheaper and just as good, or an OS like Qubes. VM hit is much smaller, less than 1% in some cases on newer hardware.
- riedel 1y agoFrom reading the article that is the exactly also the feeling of the people involved. The question is if they are on track towards e.g. the 1% eventually.
- eptcyka 1y agoVMs suffer from memory use overhead. Would be cool if the guest kernel would cooperate with the host on that.
- traverseda 1y agoIt will! For Linux hosts and Linux guests, if you use virtio and memory ballooning.
- shortrounddev2 1y agoThis was an issue for me a few years ago running docker on macOS. macOS required you to allocate memory to docker ahead of time, whereas Windows/Hyper-V was able to use memory ballooning in WSL2
- api 1y agoIt's possible to address this to some extent with ballooning memory drivers, etc.
- jeroenhd 1y agoThere's KSM that should help: https://pve.proxmox.com/wiki/Kernel_Samepage_Merging_(KSM) https://pve.proxmox.com/wiki/Kernel_Samepage_Merging_(KSM) Probably works best running VMs with the same kernel and software version.
- infogulch 1y agoBut that just seems to reintroduce the same problem again: > However, while KSM can reduce memory usage, it also comes with some security risks, as it can expose VMs to side-channel attacks. ...
- gpapilion 1y agoIt makes sense in any environment you have two workloads sharing compute from two parties, public clouds. The protection here is to ensure the vms are isolated. Without doing this there is the potential you can leak data via speculative execution across guests.
- russdill 1y agoLook at it this way, any time a new side channel attack comes out the situation changes. Having this as a mitigation that can be turned on is helpful
- bjackman 1y agoThe next steps should make this much faster. Google's internal version generally gives us a sub-1% hit on everything we measure. If the community is up for merging this (which is a genuine question - the complexity hit is significant) I expect it to become the default everywhere and for most people it should be a performance win Vs the current default. But, yes. Not there right now, which is annoying. I'm hoping the community is willing to start merging this anyway with the trust we can get it to be really fast later. But they might say "no, we need a full prototype that's super fast right now", which would be fair.