RunD: A Lightweight Secure Container Runtime for High-density Deployment and High-concurrency Startup in Serverless Computing
Zijun Li, Jiagan Cheng, Quan Chen, Eryu Guan, Zizheng Bian, Yi Tao, Bin Zha, Qiang Wang, Weidong Han, Minyi Guo
Abstract
The secure container that hosts a single container in a micro virtual machine (VM) is now used in serverless computing, as the containers are isolated through the microVMs. There are high demands on the high-density container deployment and high-concurrency container startup to improve both the resource utilization and user experience, as user functions are fine-grained in serverless platforms. Our investigation shows that the entire software stacks, containing the cgroups in the host operating system, the guest operating system, and the container rootfs for the function workload, together result in low deployment density and slow startup performance at high-concurrency. We propose and implement a lightweight secure container runtime, named RunD, to resolve the above problems through a holistic guest-tohost solution. With RunD, over 200 secure containers can be started in a second, and over 2,500 secure containers can be deployed on a node with 384GB of memory. RunD is adopted as Alibaba serverless container runtime to support high-density deployment and high-concurrency startup.
Ask about this paper
Your agent reads all of it.
Lune indexed this paper to the last equation, along with the top-tier papers that cite it. Ask a question and the answer quotes them.
Your agent calls
Luneget_paper_fulltext
Free to start. No credit card required.
Terminal
Install the CLIlune papers fulltext f83b2dd3-cdf0-4512-a4ba-1fc5beba2aa2Cited by top-tier papers28
- ServerlessLLM: Low-Latency Serverless Inference for Large Language ModelsYao Fu, Leyang Xue, Yeqi Huang, Andrei-Octavian Brabete et al.OSDI 2024 · 125 citations
- Nodens: Enabling Resource Efficient and Fast QoS Recovery of Dynamic Microservice Applications in DatacentersJiuchen Shi, Hang Zhang, Zhixin Tong, Quan Chen et al.USENIX ATC 2023 · 32 citations
- DataFlower: Exploiting the Data-flow Paradigm for Serverless Workflow OrchestrationZijun Li, Chuhao Xu, Quan Chen, Jieru Zhao et al.ASPLOS 2023 · 28 citations
- Fisc: A Large-scale Cloud-native-oriented File SystemQiang Li, Lulu Chen, Xiaoliang Wang, Shuo Huang et al.FAST 2023 · 18 citations
- Alibaba Stellar: A New Generation RDMA Network for Cloud AIJie Lu, Jiaqi Gao, Fei Feng, Zhiqiang He et al.SIGCOMM 2025 · 14 citations
Builds on11
- Serverless in the Wild: Characterizing and Optimizing the Serverless Workload at a Large Cloud ProviderMohammad Shahrad, Rodrigo Fonseca, Iñigo Goiri, Gohar Irfan Chaudhry et al.USENIX ATC 2020 · 946 citations
- Catalyzer: Sub-millisecond Startup for Serverless Computing with Initialization-less BootingDong Du, Tianyi Yu, Yubin Xia, Binyu Zang et al.ASPLOS 2020 · 280 citations
- Firecracker: Lightweight Virtualization for Serverless ApplicationsAlexandru Agache, Marc Brooker, Alexandra Iordache, Anthony Liguori et al.NSDI 2020 · 197 citations
- Benchmarking, analysis, and optimization of serverless function snapshotsDmitrii Ustiugov, Plamen Petrov, Marios Kogias, Edouard Bugnion et al.ASPLOS 2021 · 162 citations
- Help Rather Than Recycle: Alleviating Cold Startup in Serverless Computing Through Inter-Function Container SharingZijun Li, Linsong Guo, Quan Chen, Jiagan Cheng et al.USENIX ATC 2022 · 135 citations
Related papers
- Concurrency-Informed Orchestration for Serverless FunctionsQichang Liu, Yue Cheng, Haiying Shen, Ao Wang et al.ASPLOS 2025 · 7 citations
- Unifying serverless and microservice workloads with SigmaOSAriel Szekely, Adam Belay, Robert Morris, M. Frans KaashoekSOSP 2024 · 11 citations
- FastIOV: Fast Startup of Passthrough Network I/O Virtualization for Secure ContainersYunzhuo Liu, Junchen Guo, Bo Jiang, Yang Song et al.EuroSys 2025 · 5 citations
- DADI: Block-Level Image Service for Agile and Elastic Application DeploymentHuiba Li, Yifan Yuan, Rui Du, Kai Ma et al.USENIX ATC 2020 · 56 citations
- Serverless Functions Made Confidential and Efficient with Split ContainersJiacheng Shi, Jinyu Gu, Yubin Xia, Haibo ChenUSENIX Security 2025
