Accounts and Services

Avoiding Commercial Cloud Hosting Specification Pitfalls: CPU Credits, IOPS, One-Way and Two-Way Billing, and Route Matching

Compiled by VPSMap Editors · Updated 2026-09-26 · 26-minute read · Plain-Text Version

When choosing a commercial VPS (Virtual Private Server), specification sheets often hide significant information gaps. Many plans advertised as “4 cores, 8G, 1Gbps bandwidth, and a few dozen US dollars per year” suffer serious production problems such as sluggish responses under concurrency, frequent database lockups, and widespread evening peak packet loss. The root causes lie in opaque underlying mechanisms: how hardware is virtualized and divided, host oversubscription ratios, traffic accounting, and the quality of cross-border backbone routes.

This article draws on underlying cloud server architecture and network engineering practice, together with leading premium hosting providers BandwagonHost( BandwagonHost ) and DMIT actual products, panel policies, and billing rules to fully explain commercial cloud hosting performance pitfalls and provide a quantitative, practical model for matching plans to workloads.


One. The Reality of Compute Capacity: vCPU Scheduling and Fair Share Principles#

On virtually all virtual servers without Dedicated Cores, the advertised vCPUs are time slices of the host's physical cores. Providers generally limit instance CPU quotas using Linux KVM virtualization and cgroups (Completely Fair Scheduler, CFS).

1. Physical Cores, vCPUs, and Time-Slice Quotas#

A host's physical CPU, such as the AMD EPYC 9654 or 7003 series, has dozens of physical cores and over a hundred threads. Cloud providers use KVM to virtualize a single physical thread into multiple vCPUs allocated to different tenants.

In the underlying cgroups controls, CPU resources are limited primarily through two parameters:

  • cpu.cfs_period_us:调度周期的总时长(微秒,默认通常为 100,000 微秒,即 100ms)。
  • cpu.cfs_quota_us: The total CPU runtime this container/virtual machine may use within a single period.

When a provider advertises “1 vCPU limited to 50%,” the VPS receives only 50ms of execution time in each 100ms period; its threads are forcibly suspended for the remaining 50ms (Throttling), causing millisecond-level application stalls.

2. How the Fair Share Policy Works Under the Hood#

  • Burst Load: providers allow instances to use 100% of their vCPU capacity for short tasks such as compiling software, extracting files, or starting the operating system.
  • Long-Term Baseline Limits (Sustained Usage): If the instance remains fully loaded for tens of minutes, such as during prolonged video transcoding, scientific computing, or unauthorized background mining, the host's automated protection system intervenes.

Differences in Provider Implementations:#

  • BandwagonHost( BandwagonHost ):在 KiwiVM 架构下,针对不同 Plan 执行严格的平均 CPU 负载上限表(Load Average Limits)。其监控系统以数 hours 为时间窗口统计平均利用率。对于低配置基础 Plan ,长期占用常被限制在 17%~25% 的基线算力;中高端 Enterprise(CN2 GIA-E)及高 Specification 机型则具备更高的持续突发容忍度。若长期超标,KiwiVM 将对该 VM 的 vCPU 实施硬件级降频,严重违规甚至会直接自动关机并向控制面板发送超载告警。
  • DMIT: Focused on high-performance compute nodes, with broad adoption of high-frequency AMD EPYC platforms (Zen 3 / Zen 4). DMIT is relatively tolerant of peak single-core performance, but its TOS explicitly prohibit prolonged CPU Abuse. Host-level smooth traffic scheduling and dynamic core affinity provide smoother short bursts, with direct disconnection for momentary overload being rare.

3. How to Detect CPU Overselling and Quota Contention Inside the System#

After connecting to the VPS, do not look only at uptime or top reported utilization, and focus on CPU Steal Time(%st):

bash
# 实时监控 CPU 各状态时间占比
top
# 观察第三行 CPU 状态中的 %st
# %Cpu(s):  3.2 us,  1.0 sy,  0.0 ni, 94.8 id,  0.0 wa,  0.0 hi,  0.0 si,  1.0 st
bash
# 使用 vmstat 观察持续负载下的调度延迟
vmstat 1 10
  • %stWhat (Steal Time) Means: The proportion of time a virtual CPU is ready to execute instructions but must wait because the physical CPU is serving other virtual machines on the host.
  • Evaluate the Threshold: If, when no resource-intensive tasks are running, %st 长期大于 3%~5%,或者自身跑满任务时 %st surges to 20%+, indicating severe overselling of physical CPU cores or an overloaded “noisy neighbor” on the same host.

二、 Storage 与 Memory 深水区:4K 随机 IOPS 与 Linux 缓存模型#

1. 顺序读写(Sequential MB/s)与 4K 随机读写(IOPS)的本质差异#

Many beginners like to use the following when testing VPS performance: dd Command:

bash
dd if=/dev/zero of=test bs=64k count=16k conv=fdatasync

这种测试测出的仅是大文件顺序连续写入速度(Seq Write)。然而在实际业务中:

  • MySQL / PostgreSQL: Data persistence and index lookups involve random searches across numerous 4KB or 16KB pages scattered across disk sectors (Random Read/Write).
  • Web 静态文件并发: High concurrency generates enormous numbers of simultaneous small-file requests.

High-concurrency throughput is determined not by sequential speeds of 2000MB/s, but by 4K 随机 IOPS and fsync Write Latency。

Use fio perform standard storage stress testing:#

bash
# 测试 4K 随机读取 IOPS 与延迟(QD=1,模拟真实单线程数据库响应)
fio --ioengine=libaio --direct=1 --name=randread-4k --bs=4k --iodepth=1 --rw=randread --size=1G --runtime=30 --time_based

# 测试 4K 随机写入 IOPS(QD=32,模拟高并发写入场景)
fio --ioengine=libaio --direct=1 --name=randwrite-4k --bs=4k --iodepth=32 --rw=randwrite --size=1G --runtime=30 --time_based
Storage Architecture4K 随机读取 (QD=1)4K Random Writes (QD=32)Typical Application Performance
Low-End Budget VPS (SATA SSD / Oversold NVMe)800 ~ 2,500 IOPS2,000 ~ 5,000 IOPSMySQL Immediately Encounters Table Locking and High IO Wait as Concurrency Increases
BandwagonHost (Enterprise-Grade SSD/NVMe RAID10)12,000 ~ 25,000 IOPS40,000 ~ 80,000 IOPSMillisecond Responses to Complex Queries and Consistent High-Volume Log Writes
DMIT (High-Specification PCIe 4.0/5.0 NVMe RAID)20,000 ~ 35,000 IOPS60,000 ~ 120,000 IOPSExcellent I/O Latency for Heavy Database Workloads and Continuous Cache Persistence

2. Avoid Memory-Management Pitfalls: Understand buff/cache and Plan Swap Properly#

A Common Misconception in Linux Administration Is Using free -m 看到可用 Memory 变少就判定为“ Memory 泄漏”:

text
               total        used        free      shared  buff/cache   available
Mem:            1964         520          72          16        1372        1376
Swap:           2048           0        2048
  • free: physical memory pages currently not allocated by the system at all.
  • buff/cache: the Linux kernel automatically uses physical memory not occupied by processes for filesystem metadata buffers (Buffer) and disk-file read caching (Page Cache). When an application requests memory, the kernel reclaims this space without data loss within nanoseconds.
  • available:Total Memory Actually Available to New Processes. As long as available is sufficient, the system's performance is healthy.

小 Specification Memory (≤ 1GB)的 Swap 配置防线#

对于 768MB~1GB Memory 的 VPS instance ,一旦物理 Memory 耗尽,Linux 内核的 OOM-Killer(Out of Memory Killer)会根据打分机制直接终结 Memory 占用最大的进程(通常是 mysqld)。

must be addressed by configuring a local Swap file together with tuned kernel swappiness (swappiness) to build disaster-recovery redundancy:

bash
# 1. 创建 2GB 独立交换文件
fallocate -l 2G /swapfile || dd if=/dev/zero of=/swapfile bs=1M count=2048
chmod 600 /swapfile
mkswap /swapfile
swapon /swapfile

# 2. 持久化至 /etc/fstab
echo '/swapfile none swap sw 0 0' >> /etc/fstab

# 3. 调低换出积极度(默认 60,推荐设为 10~20,优先利用物理内存,紧急时刻才用 Swap)
sysctl vm.swappiness=15
echo 'vm.swappiness=15' >> /etc/sysctl.conf

Three. Bandwidth and Traffic Billing Pitfalls: One-Way/Two-Way Metering, Reset Cycles, and Exhaustion Cut-Offs#

Cloud server networking usually combines a peak port-speed limit with a monthly traffic allowance. However, providers differ fundamentally in how they count traffic and handle overages.

1. Traffic Metering Models: One-Way versus Two-Way Billing#

流量的流动方向分为入网流量(Inbound,服务器接收数据)与出网流量(Outbound,服务器向外发送数据)。

Commands / Configuration
双向计费(Inbound + Outbound):
实际扣除配额 = 入网流量 (GB) + 出网流量 (GB)

单向计费(Max(Inbound, Outbound)):
实际扣除配额 = MAX [ 入网流量 (GB), 出网流量 (GB) ]

Cost Calculation for a Real-World Scenario:#

假设你 deployment 了一台反向代理服务器,每month从上游源站拉取 800GB 数据,同时向终端访客分发 800GB 静态内容:

  • Under Two-Way Metering: Total usage is $800 + 800 = 1600\text{ GB}$.
  • 在单向计费下: Total usage is $\max(800, 800) = 800\text{ GB}$.

Providers 产品矩阵中的计费规则:#

  • BandwagonHost( BandwagonHost ):All Product Lines Strictly Count Traffic in Both Directions. Whether in DC6, DC9, Japan Softbank, or Hong Kong, both incoming and outgoing traffic count in full. When users use rsync Account for Double the Traffic Cost When Synchronizing Off-Site or Downloading Large Files for a Mirror.
  • DMIT:
    • Pro Series / EB Series (优质优化 Networks ):实行Two-Way Metering, because the China Telecom CN2 GIA, China Unicom 9929, and China Mobile CMIN2 upstream bandwidth it purchases has a high monthly unit cost.
    • Tier 1 (T1) Series / 部分 Lite Series (国际大 Bandwidth Networks ):采用One-Way Traffic Accounting (Or Free Inbound Traffic with Only Outbound Counted). For workloads handling large volumes of images, overseas video streaming, or high-traffic off-site cold backups, DMIT T1 can deliver nearly twice the usable capacity from the same allowance.

2. 流量耗尽处置机制与 SLA 可用性影响#

When application traffic unexpectedly exceeds a plan's allowance, the two leading providers take fundamentally different approaches:

Commands / Configuration
                ┌──> 流量耗尽 ──> 硬性挂起 (Suspended) ──> 网络完全切断 ──> 业务不可用 (直至重置日)
                │    代表服务商: BandwagonHost
流量监控边界 ───┤
                │
                └──> 流量耗尽 ──> 弹性整形 (Traffic Shaping) ──> 端口限速 ──> 维持基本在线与管理
                     代表服务商: DMIT (Pro/EB降至2~10Mbps; T1仍有大带宽限速)
  • BandwagonHost's “Cut-Off and Suspend” Model:
    • Once the traffic allowance is exhausted, KiwiVM immediately sets the virtual machine's status to Suspended,虚拟网卡直接关闭,外部 Networking 请求与内部守护进程均无法维持。
    • There are only two ways to restore service: wait for the billing-cycle reset date, based on the calendar date your service started rather than day 1 of the calendar month, or pay the difference in the control panel to upgrade to the next plan tier.
    • Operational Requirements:必须在服务器内部安装如 vnstat 或设置外部 Prometheus 告警,在用量达 80% 时预警,防止生产网站无征兆离线。
  • DMIT's “Stay Online with Throttling” Traffic Shaping Model:
    • After the Traffic Quota Is ExhaustedNo Shutdown, No Disconnection, but instead automatically applies QoS traffic shaping to reduce speed.
    • Premium-route plans such as Pro and EB are throttled to between 2Mbps ~ 10Mbps; the basic Tier 1 series generally retains a higher bandwidth guarantee even when throttled.
    • Operational Advantages: Even if a sudden attack exhausts the traffic allowance, operations staff can still log in over SSH to diagnose problems, back up databases, or handle production incidents. The website can still respond to basic API requests at reduced speed, avoiding the critical risk of the system becoming completely unreachable.

三、 Networking 拓扑与路由工程:三大运营商回程专线匹配模型#

在跨国 Networking 传输中,物理距离并非决定延迟和丢包的关键, Networking 自治系统(AS)之间的路由协议与回程链路质量is what matters most. Many cheap hosts advertising gigabit bandwidth experience routine congestion at backbone Peering Points during evening peak hours (20:00 - 23:00), with packet loss suddenly exceeding 30%.

1. Comparison of Core Dedicated Network Protocol Families#

  • China Telecom CN2 GIA (AS4809 - ChinaNet Next Carrying Network Global Internet Access):
    • China Telecom's highest-tier premium backbone, with an independent transport network, dedicated international gateways, direct routes in both directions, and the highest QoS priority. It maintains extremely low jitter and virtually zero packet loss even during evening backbone congestion.
  • China Unicom AS9929 (CUII / China Unicom Industrial Internet Backbone):
    • The former China Netcom core backbone (Network A) has light utilization and ample spare capacity. Its evening peak packet loss and latency are comparable to China Telecom CN2 GIA, delivering an excellent experience for China Unicom and some northern China network users.
  • China Mobile CMIN2 (AS58807 - China Mobile International New Generation Network):
    • China Mobile's second-generation premium backbone, launched to compete with China Telecom CN2 GIA and China Unicom AS9929. It eliminates the longstanding evening peak congestion and stalls at Guangzhou/Hong Kong gateways on standard CMI routes.
  • Standard Backbones (China Telecom 163 / AS4134, China Unicom 169 / AS4837, China Mobile CMI / AS9808):
    • Carries enormous volumes of public internet traffic. Speed tests may reach a full gigabit during the day, but international interconnection points become extremely congested during evening peak hours, causing packet loss to rise sharply.

2. The Golden Rule of Return Routing: Inbound Routing Determines Protection; Return Routing Determines the Experience#

Commands / Configuration
去程 (客户端 -> 服务器): 主要受访客本地 ISP 出口与 ANYCAST 防护调度影响
回程 (服务器 -> 客户端): 决定响应数据包能否快速送达,95% 的网络卡顿源于回程变异!

When choosing a server for business use,Ensure That Connections Between the Server and All Three Local Carriers Have Bidirectional or Core Return-Route Optimization。

Use mtr 进行多路由节点回程深度分析:#

bash
# 在 VPS 上向本地客户端公网 IP 执行链路追踪
# -r 报告模式, -c 100 发送100个测试包, -w 显示完整域名
mtr -r -c 100 -w [您的本地公网IP]

Key Metrics to Watch:

  1. 最后一跳的 Loss%(丢包率): Packet loss at intermediate hops usually reflects the router's ICMP rate limiting; packet loss at the final hop represents the actual loss rate.
  2. AS Path Changes:
    • China Telecom return-path packets must show 59.43.*.*(CN2 backbone nodes);
    • Premium China Unicom Return Routes Must Show 218.105.*.* or 210.51.*.*(AS9929 nodes);
    • Premium China Mobile Return Routes Must Use 223.120.*.* or 223.119.*.* and is labeled CMIN2.

3. 三网用户精准选型匹配矩阵#

Based on BandwagonHost's and DMIT's actual offerings, the following model matches workloads with network access needs:

Commands / Configuration
                                  ┌── 电信 (宽带/移动蜂窝) ──────> 核心锁定【电信 CN2 GIA (AS4809)】
                                  │                               首选: 搬瓦工 DC6/DC9 / DMIT Pro 系列
                                  │
                                  ├── 联通 (北方/全国骨干) ──────> 核心锁定【AS9929 / 大阪软银 (BBTEC)】
您的本地网络主力或终端访客画像 ───┼                               首选: 搬瓦工 大阪软银 / DMIT EB 系列
                                  │
                                  ├── 移动 (家宽/5G网络) ────────> 核心锁定【移动 CMIN2 (AS58807)】
                                  │                               首选: DMIT EB 系列 / 搬瓦工 MegaBox
                                  │
                                  └── 跨国企业出海 / 纯外网 ─────> 核心锁定【国际 Tier 1 大带宽】
                                                                  首选: DMIT T1 系列 (低成本海量吞吐)
Use Case / Target VisitorsCore Network Reliability RequirementsRecommended Provider Product LinesTechnical Basis for Selection
Highly Available Enterprise Production, Overseas Independent Websites, and Cross-Border APIsTop-Tier Dedicated Routes with Direct Connectivity in Both Directions for All Three Carriers, with Very Low Packet Loss and JitterBandwagonHost DC6 / DC9 CN2 GIA-E or DMIT LAX/HKG/TYO Prooffers full CN2 GIA dedicated-route coverage, delivering millisecond-level SLA responses even during extreme evening peak congestion.
Cost-Effective Mixed Production Workloads (Serving Both China Mobile and China Unicom)The Winning Combination of China Unicom 9929 + China Mobile CMIN2DMIT EB (Eyeball) Series Replaces costly China Telecom CN2 with next-generation CMIN2 and AS9929, lowering costs while delivering an exceptional experience for China Mobile users.
Ultra-Fast Nearby Asia-Pacific Development Environments (Shanghai / Northern Coastal China)Extremely Short Physical RTT in Asia-Pacific, with High Bandwidth and Low LatencyBandwagonHost Japan SoftBank (JPOS_1)Japan SoftBank (BBTEC) benefits from direct physical peering with China Unicom in northern China, keeping round-trip latency stable at 35ms~55ms.
Overseas 跨境 CDN 边缘节点、大容量数据同步Massive One-Way Traffic Throughput with No Requirement for Direct China ConnectivityDMIT Tier 1(T1) Series Connects to leading international backbones such as Cogent, Arelion (Telia), and NTT, with one-way metering and a substantial cost advantage for high bandwidth.

四、 控制面板与自动化运维实操:KiwiVM vs DMIT Client Area#

控制面板不仅是开机与关机的工具,它直接决定了突发故障排查、容灾快照转移与 IP 资产维护的运维成本。

1. Engineering Features of BandwagonHost's Proprietary KiwiVM Panel#

BandwagonHost 自研的 KiwiVM 经过十余年迭代,功能高度偏向底层运维人员与自动化需求:

  • One-Click Online Migration Between Data Centers (Datacenter Migration):
    • Without losing existing disk data or changing the operating system environment, users can perform a seamless, one-click live migration directly in KiwiVM from Los Angeles, USA (such as DC6), to the Netherlands, Canada, or Osaka, Japan, depending on the migration destinations allowed by their plan.
    • The migration system automatically synchronizes hot and cold data in the background, remounts storage, and assigns an available public IP at the new data center. This greatly reduces the cost of switching away from a specific network single point of failure.
  • 免费快照(Snapshot)与快照锁定:
    • KiwiVM provides system snapshots. Snapshots expire by default, but users can manually lock multiple snapshots permanently using “Set sticky.”
    • Snapshots support generating a dedicated Token to enable跨 accounts 、跨 instance 的快速恢复与克隆, providing an efficient way to deploy identical server environments horizontally.
  • 应急运维: Provides an interactive Root shell - interactive and an underlying VNC terminal, allowing one-click recovery if a firewall misconfiguration locks out the SSH port.

2. DMIT Client Area 现代化控制架构#

DMIT uses a modern cloud management architecture with an experience closer to standard public clouds:

  • Automated SSH Key Injection:
    • When initially purchasing an instance or rebuilding its operating system through the panel, DMIT requires or recommends associating a public SSH Key and automatically uses, during initial system provisioning, cloud-init Eliminates Weak-Password Remote Login and Enforces a Stronger Default Security Baseline for Internet-Exposed Hosts.
  • Networking 与反向 DNS(rDNS)自主控制:
    • The DMIT control panel lets you quickly configure PTR records (rDNS) directly for assigned IPv4 and IPv6 addresses. For self-hosted email gateways or production systems requiring strict forward/reverse DNS verification, changes can take effect in seconds without a support ticket.
  • More Flexible Native IPv6 Access:
    • 相比 BandwagonHost 部分机房将重点主要集中在 IPv4 专线上,DMIT 几乎全线原生提供优化的 IPv6 块,并在双栈路由层面进行对等优化,适合新一代 IPv6-Only 或双栈容器 Networking 编排。

五、 Commercial VPS 选型四步避坑排查清单#

Before making a final purchase or migrating a server, verify the specifications using these four steps to avoid most misleading claims in commercial hosting promotions:

Commands / Configuration
[步骤一:算力基准测试]
□ 确认 vCPU 是专用(Dedicated)还是共享(Shared)。
□ 查验服务商 TOS 是否有严格的持续 CPU 满载熔断或降频规则。
□ 交付后执行 %st 检测,确保宿主机没有超售争抢。

[步骤二:存储与 I/O 验证]
□ 拒绝以 Sequential MB/s 为唯一标准,通过 fio 压测 4K 随机 IOPS (QD=1 及 QD=32)。
□ 检查服务器磁盘阵列级别(企业级 NVMe RAID10 为佳)。
□ 小于 2GB 内存实例务必第一时间挂载 1~2GB Swap,调低 swappiness 规避 OOM。

[步骤三:流量结算与可用性容灾]
□ 核算业务出入站比例:双向计费需准备双倍预算,单向计费优选 DMIT T1 等大吞吐产品。
□ 明确超量处置:生产核心系统若选搬瓦工需做好用量预警防止断网;若容忍降速保活则首选 DMIT。
□ 确认流量重置周期锚点是以订单日还是自然月计算。

[步骤四:真实路由质量判定]
□ 拒绝白天单次 ping,必须在晚高峰(20:00 - 23:00)运行 mtr 查看回程 100 个包的真实 Loss% 与抖动。
□ 核心电信流量认准 AS4809 (CN2 GIA),移动认准 AS58807 (CMIN2),联通认准 AS9929。
□ 商业站点坚决避开单程优化线路,必须验证去程与回程的双向路由对等性。

相关 Providers 与 Plan 入口

The following are referral links, and this site may earn a commission after a purchase. Pricing, stock, and terms of service are governed by the provider's checkout page.