Using the latest lxd snap on Ubuntu 18.04 (patched and current everything). My networking hardware is an ixgbe 10 Gbps Intel X450-AT2.
I have containers using macvlan, and I have containers using SR-IOV for ethernet. Both work great (except, the first time a container using SR-IOV starts on each boot, there’s often a long (30-60s) “dead zone” of packets across the NIC while the virtual functions get created by the driver.)
Performance seems similar on the surface. Can anyone explain how these two approaches to LXD networking are likely to differ, both in terms of performance and network isolation?
Are SR-IOV guest NICs more isolated / more secure than macvlan?