首页> 外文会议>IEEE International Conference on Distributed Computing Systems >SGX-Aware Container Orchestration for Heterogeneous Clusters
【24h】

SGX-Aware Container Orchestration for Heterogeneous Clusters

机译:SGX感知的异构集群容器编排

获取原文

摘要

Containers are becoming the de facto standard to package and deploy applications and micro-services in the cloud. Several cloud providers (e.g., Amazon, Google, Microsoft) begin to offer native support on their infrastructure by integrating container orchestration tools within their cloud offering. At the same time, the security guarantees that containers offer to applications remain questionable. Customers still need to trust their cloud provider with respect to data and code integrity. The recent introduction by Intel of Software Guard Extensions (SGX) into the mass market offers an alternative to developers, who can now execute their code in a hardware-secured environment without trusting the cloud provider. This paper provides insights regarding the support of SGX inside Kubernetes, an industry-standard container orchestrator. We present our contributions across the whole stack supporting execution of SGX-enabled containers. We provide details regarding the architecture of the scheduler and its monitoring framework, the underlying operating system support and the required kernel driver extensions. We evaluate our complete implementation on a private cluster using the real-world Google Borg traces. Our experiments highlight the performance trade-offs that will be encountered when deploying SGX-enabled micro-services in the cloud.
机译:容器正成为在云中打包和部署应用程序和微服务的事实上的标准。通过将容器编排工具集成到他们的云产品中,几个云提供商(例如,亚马逊,谷歌,微软)开始在其基础架构上提供本机支持。同时,安全性保证了容器提供给应用程序的问题仍然存在。客户仍然需要在数据和代码完整性方面信任其云提供商。英特尔最近将Software Guard Extensions(SGX)引入了大众市场,这为开发人员提供了另一种选择,他们现在可以在受硬件保护的环境中执行其代码,而无需信任云提供商。本文提供了有关SGX在Kubernetes(行业标准的容器编排器)内部的支持的见解。我们在整个堆栈中展示我们的贡献,以支持启用SGX的容器的执行。我们提供有关调度程序的体系结构及其监视框架,底层操作系统支持以及所需的内核驱动程序扩展的详细信息。我们使用真实的Google Borg跟踪评估在私有集群上的完整实现。我们的实验重点介绍了在云中部署支持SGX的微服务时将遇到的性能折衷。

著录项

相似文献

  • 外文文献
  • 中文文献
  • 专利
获取原文

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号