eve-kvm:core-isolation
Differences
This shows you the differences between two versions of the page.
| Both sides previous revisionPrevious revisionNext revision | Previous revision | ||
| eve-kvm:core-isolation [2026/09/18 17:52] – mc | eve-kvm:core-isolation [2026/09/19 17:35] (current) – mc | ||
|---|---|---|---|
| Line 6: | Line 6: | ||
| **Time required.** About 20 minutes, including one reboot. | **Time required.** About 20 minutes, including one reboot. | ||
| + | |||
| + | **Just here to run the demo?** Use the four-act script immediately below. The numbered steps in Parts 1-4 are the full procedure behind it. | ||
| + | |||
| + | ---- | ||
| + | |||
| + | ===== Quick demo script — 1, 2, 3, 4 ===== | ||
| + | |||
| + | Four commands-and-a-sentence. Run them in order, with the pinned VM **not yet deployed**. | ||
| + | |||
| + | Set this up first so every command is a single keystroke away: | ||
| + | |||
| + | <code bash> | ||
| + | alias iso=' | ||
| + | alias pools=' | ||
| + | alias plan=' | ||
| + | alias ticks=' | ||
| + | </ | ||
| + | |||
| + | ==== 1. BEFORE — a plain node: no isolation, no assignment ==== | ||
| + | |||
| + | <code bash> | ||
| + | iso | ||
| + | pools | ||
| + | ticks | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | isolated: [] | ||
| + | {" | ||
| + | {" | ||
| + | cpu0=73851 | ||
| + | </ | ||
| + | |||
| + | **Say:** "The kernel isolates nothing. There is one pool — all eight threads, shared. Every CPU is doing work. Any workload can be scheduled anywhere, and so can the kernel' | ||
| + | |||
| + | //This is the state before any configuration. If your node is already configured and you want to rehearse the whole arc, revert it with:// '' | ||
| + | |||
| + | ==== 2. AFTER the config — the isolated pool exists, and nobody may use it ==== | ||
| + | |||
| + | Enable per Part 2 (property, '' | ||
| + | |||
| + | <code bash> | ||
| + | iso | ||
| + | pools | ||
| + | ticks | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | isolated: [4-7] | ||
| + | {" | ||
| + | {" | ||
| + | {" | ||
| + | cpu0=9525 | ||
| + | </ | ||
| + | |||
| + | **Say:** "Now there are three pools. Four CPUs are isolated. Look at the housekeeping pool — of eight threads, six are gone: two reserved for EVE, four withheld for isolation. Only one whole core is left for ordinary work. And cores 4 through 7 have executed **zero** cycles since boot — not the scheduler, not a workload, nothing." | ||
| + | |||
| + | **Point at:** '' | ||
| + | |||
| + | ==== 3. DEPLOY — a pinned VM takes an isolated core ==== | ||
| + | |||
| + | Deploy a **2-vCPU** app with CPU pinning enabled, then: | ||
| + | |||
| + | <code bash> | ||
| + | plan | ||
| + | pools | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | { " | ||
| + | " | ||
| + | |||
| + | {" | ||
| + | {" | ||
| + | {" | ||
| + | </ | ||
| + | |||
| + | **Say:** "Two vCPUs, one whole physical core, taken from the isolated set — cores 4 and 5. The isolated pool drops from two free cores to one. The app asked for nothing but 'CPU pinning'; | ||
| + | |||
| + | ==== 4. PROVE IT — the kernel agrees, down to the thread ==== | ||
| + | |||
| + | <code bash> | ||
| + | PID=$(pgrep -f qemu-system | head -1) | ||
| + | for t in / | ||
| + | printf '%-18s %s | ||
| + | ' "$(cat $t/ | ||
| + | done | sort -u | ||
| + | cat / | ||
| + | ticks | ||
| + | </ | ||
| + | |||
| + | < | ||
| + | qemu-system-x86 | ||
| + | qemu-system-x86 | ||
| + | qemu-system-x86 | ||
| + | vhost-7981 | ||
| + | |||
| + | 4-5 | ||
| + | |||
| + | cpu0=9525 | ||
| + | </ | ||
| + | |||
| + | **Say:** "One vCPU thread per hardware thread, pinned 1:1. Everything else the VM needs is confined to the same core. The cgroup agrees. And the second isolated core is **still at zero** — it is reserved and untouchable, | ||
| + | |||
| + | **The closing line:** cores 6 and 7 are idle and cannot be used by anything that did not ask for isolation. On this node, a workload that needs guaranteed CPU gets it — not by priority, not by best effort, but because nothing else is allowed to run there. | ||
| ---- | ---- | ||
| Line 15: | Line 120: | ||
| ^ # ^ Switch ^ Where it is set ^ What it does ^ Needs reboot? ^ | ^ # ^ Switch ^ Where it is set ^ What it does ^ Needs reboot? ^ | ||
| | 1 | '' | | 1 | '' | ||
| - | | 2 | '' | + | | 2 | '' |
| A third thing is often confused with these: | A third thing is often confused with these: | ||
| Line 154: | Line 259: | ||
| ==== Step 6 — Set the controller property ==== | ==== Step 6 — Set the controller property ==== | ||
| - | **In Terraform** — a '' | + | **This property is not exposed in the ZedControl UI.** Do not go looking for it there — the UI only offers properties it knows about, and this one is new in the feature branch. It can only be set via **Terraform** or the **REST API**. |
| + | |||
| + | **Terraform** — a '' | ||
| < | < | ||
| Line 169: | Line 276: | ||
| Then '' | Then '' | ||
| - | **Use '' | + | **Use '' |
| + | |||
| + | ^ Hop ^ Schema ^ Fields ^ | ||
| + | | you → controller | '' | ||
| + | | controller → device | eve-api '' | ||
| + | |||
| + | The controller has to collapse the typed fields into a single string '' | ||
| + | |||
| + | **REST** — '' | ||
| + | |||
| + | <code javascript> | ||
| + | { " | ||
| + | </ | ||
| + | |||
| + | **This is a full-object PUT, not a patch.** The body carries the whole edge node — '' | ||
| + | |||
| + | So the REST procedure is read-modify-write: | ||
| + | |||
| + | - '' | ||
| + | - append '' | ||
| + | - '' | ||
| + | |||
| + | This is why Terraform | ||
| + | |||
| + | **Do not expect | ||
| - | **In the UI:** edge node → configuration properties → add '' | + | Whichever route you use, **Step 7 is what confirms it** — do not assume it landed. |
| ==== Step 7 — Confirm the property reached the node ==== | ==== Step 7 — Confirm the property reached the node ==== | ||
| Line 446: | Line 577: | ||
| ^ Symptom ^ Cause ^ Fix ^ | ^ Symptom ^ Cause ^ Fix ^ | ||
| + | | Cannot find the property in the controller UI | it is not exposed there | set it via Terraform or REST (Step 6) | | ||
| | Property set in Terraform, node still shows '' | | Property set in Terraform, node still shows '' | ||
| | Property set on the application instead of the node | '' | | Property set on the application instead of the node | '' | ||
eve-kvm/core-isolation.1789753944.txt.gz · Last modified: by mc
