High-density Multi-tenant Bare-metal Cloud
Xiantao Zhang, Xiao Zheng, Zhi Wang, Hang Yang, Yibin Shen, Xin Long
Abstract
Virtualization is the cornerstone of the infrastructure-as-a-service (IaaS) cloud, where VMs from multiple tenants share a single physical server. This increases the utilization of data-center servers, allowing cloud providers to provide cost-efficient services. However, the multi-tenant nature of this service leads to serious security concerns, especially in regard to side-channel attacks. In addition, virtualization incurs non-negligible overhead in the performance of CPU, memory, and I/O. To this end, the bare-metal cloud has become an emerging type of service in the public clouds, where a cloud user can rent dedicated physical servers. The bare-metal cloud provides users with strong isolation, full and direct access to the hardware, and more predicable performance. However, the existing single-tenant bare-metal service has poor scalability, low cost efficiency, and weak adaptability because it can only lease entire physical servers to users and have no control over user programs after the server is leased. In this paper, we propose the design of a new high-density multi-tenant bare-metal cloud called BM-Hive. In BM-Hive, each bare-metal guest runs on its own compute board, a PCIe extension board with the dedicated CPU and memory modules. Moreover, BM-Hive features a hardware-software hybrid virtio I/O system that enables the guest to directly access the cloud network and storage services. BM-Hive can significantly improve the cost efficiency of the bare-metal service by hosting up to 16 bare-metal guests in a single physical server. In addition, BM-Hive strictly isolates the bare-metal guests at the hardware level for better security and isolation. We have deployed BM-Hive in one of the largest public cloud infrastructures. It currently serves tens of thousands of users at the same time. Our evaluation of BM-Hive demonstrates its strong performance over VMs.
Ask about this paper
Ask your agent about it.
Lune has read the top-tier papers around this one, so every answer names the papers it rests on.
Cited by top-tier papers15
- TwinVisor: Hardware-isolated Confidential Virtual Machines for ARMDingji Li, Zeyu Mi, Yubin Xia, Binyu Zang et al.SOSP 2021 · 39 citations
- What's the Story in EBS Glory: Evolutions and Lessons in Building Cloud Block StoreWeidong Zhang, Erci Xu, Qiuping Wang, Xiaolu Zhang et al.FAST 2024 · 37 citations
- LuoShen: A Hyper-Converged Programmable Gateway for Multi-Tenant Multi-Service Edge CloudsTian Pan, Kun Liu, Xionglie Wei, Yisong Qiao et al.NSDI 2024 · 27 citations
- Fisc: A Large-scale Cloud-native-oriented File SystemQiang Li, Lulu Chen, Xiaoliang Wang, Shuo Huang et al.FAST 2023 · 18 citations
- μManycore: A Cloud-Native CPU for Tail at ScaleJovan Stojkovic, Chunao Liu, Muhammad Shahbaz, Josep TorrellasISCA 2023 · 16 citations
Related papers
- Core slicing: closing the gap between leaky confidential VMs and bare-metal cloudZiqiao Zhou, Yizhou Shan, Weidong Cui, Xinyang Ge et al.OSDI 2023 · 12 citations
- Bluebird: High-performance SDN for Bare-metal Cloud ServicesManikandan Arumugam, Deepak Bansal, Navdeep Bhatia, James Boerner et al.NSDI 2022
- HD-IOV: SW-HW Co-designed I/O Virtualization with Scalability and Flexibility for Hyper-Density CloudZongpu Zhang, Jiangtao Chen, Banghao Ying, Yahui Cao et al.EuroSys 2024 · 7 citations
- FVM: FPGA-assisted Virtual Device Emulation for Fast, Scalable, and Flexible Storage VirtualizationDongup Kwon, Junehyuk Boo, Dongryeong Kim, Jangwoo KimOSDI 2020 · 6 citations
- BlueGuard: Accelerated Host and Guest Introspection Using DPUsMeni Orenbach, Rami Ailabouni, Nael Masalha, Thanh Nguyen et al.USENIX Security 2025
