Is the Network the Limit? Dealing with Weave, CoreOS and Azure
arjanschaaf.github.io
arjanschaaf.github.io
Also, you can get equivalent "IP per container" using advanced routing with GCE. Flannel has a GCE specific back end where it inserts routes for each subnet assigned to each range. That will eliminate the extra level of encap.
(Disclaimer: I started GCE but am no longer at Google.)
Conveniently, Amin Vahdat recently shared some content publicly about why it should scale to lots of VMs: https://www.youtube.com/watch?v=FaAZAII2x0w
(And, to others, disclaimer: I work on some bits of GCE networking at Google)
Weave aims to deliver a completely portable network. In other words if you create an application using Docker container and a Weave network, that should be able to run anywhere. And all this should be 'magically simple'. Once you have decided where to run your app, you may wish to trade portability for performance gains. For example by using GCE networking (or Azure, or ...).
To date Weave achieved portability by sending some packets (inter host) through user space. This has big benefits in terms of ease of use eg. dealing with wide area networks, multicast and firewalls. But under load it performs worse than kernel-only models.
We now have Weave "fast data path" - http://blog.weave.works/2015/06/12/weave-fast-datapath/ ... This aims to deliver close to line performance with portability and extreme ease of use.
There may of course be yet more optimisations that end users wish to investigate. If you are willing to sacrifice some portability you could certainly make use of fast networks provided by a specific public cloud. We haven't yet seen a strong need to support this, but it is certainly a reasonable thing.
(Disclaimer: I work at Weaveworks)
Our answer to weave performance concerns is on its way: http://blog.weave.works/2015/06/12/weave-fast-datapath/
We're really interested to hear how weave fast datapath works out in all kinds of environments, which is why we put the preview out. It's a shame that Arjan's post did not include numbers for FDP, but maybe he'll be able to include them in an update.
The best networking performance is achieved by binding directly to the metal using SOCK_RAW, but that also gives you the least flexibility.
I think seeing Weave implemented in something like say, Snabb Switch, would at the very least be interesting -- from a performance standpoint.