Wednesday, 2021-10-13

kata-irc-bot<yan632> Hi, I saw some resources saying that Kata can only run if nested virtualization is enabled. Can someone explain this? If Kata is run on bare-metal, one level of HW virtualization should suffice in order to provide the isolation for the containers, no?03:49
kata-irc-bot<fidencio> Hey @yan632!06:10
kata-irc-bot<fidencio> That's a misconception, kata-containers requires *only* one level of virtualization.06:10
kata-irc-bot<fidencio> The misconception was originated as folks try to run kata-containers on, for instance, AWS VMs.  In this case it won't fly as the host itself is the first level of virt, and kata-containers then would need to be nested.  But if you're running on baremetal, as you mentioned, *only one level of virtualization is needed*.06:12
kata-irc-bot<shuo.chen> Hi guys, have anybody ever run kata in Azure nested virtualization environment and met any performance issue?17:16
kata-irc-bot<wmoschet> I have a CI job running on Azure nested but I don't measure performance ...17:37
kata-irc-bot<shuo.chen> OK, we saw a severe e2e performance loss (more than 3x perf loss) running kata container comparing with runc container and we are trying to figure out the root cause. Want to get some suggestions from the community17:44

Generated by irclog2html.py 2.17.2 by Marius Gedminas - find it at https://mg.pov.lt/irclog2html/!