Running thousands of snapshotted VMs pushes Linux networking primitives to their limits. This talk covers battle-tested strategies for designing large-scale network topologies that balance performance, isolation, and resource efficiency.
The session will dive into practical solutions for high-density VM environments, including the use of Geneve tunneling for scalable overlay networks, eBPF-accelerated networking to bypass kernel bottlenecks and achieve line-rate performance, and stateless NAT techniques that enable network reuse without connection tracking overhead. The speakers will also discuss smart firewall design using device prefix-based iptables/nftables rules and namespace pooling strategies to minimize operation costs during rapid VM snapshotting. Finally, the talk addresses RTNL lock contention and its operational impact on large-scale deployments. Attendees will learn how to architect network stacks where VMs are frequently cloned, restored, and migrated while maintaining security boundaries and predictable performance.
Target Audience: