Back to articles
Technology Insight

Linux VPS Optimization: Eradicating Bufferbloat with CAKE (Common Applications Kept Enhanced)

June 4, 2026

Introduction to Network Latency and the Hidden Bottleneck

In enterprise cloud infrastructure, Virtual Private Servers (VPS) serve as the backbone for web applications, databases, and communication platforms. While system administrators frequently optimize CPU utilization, RAM allocation, and disk I/O, network performance is often reduced to a single metric: bandwidth. However, high throughput does not guarantee a responsive network. Many businesses experience baffling latency spikes, dropped VoIP calls, and sluggish API responses even when their bandwidth utilization is well below maximum capacity.

This paradox is frequently caused by a phenomenon known as Bufferbloat. To mitigate this issue and unlock the true potential of your network stack, modern Linux environments offer an advanced Queueing Discipline (qdisc) called CAKE (Common Applications Kept Enhanced). This guide provides a comprehensive framework for understanding bufferbloat and configuring CAKE on a Linux VPS to achieve optimal network responsiveness.

Understanding Bufferbloat: The Silent Performance Killer

Bufferbloat occurs when network equipment—such as routers, switches, or virtual network interfaces—is configured with excessively large buffers. Buffers are designed to prevent packet loss during temporary traffic bursts. However, when a server continuously transmits data faster than the upstream network can handle, these buffers fill up entirely.

Instead of dropping packets to signal the sender to slow down (the standard TCP congestion control mechanism), the system holds packets in a long queue. This introduces severe artificial latency. Critical, time-sensitive packets (such as DNS queries, SSH commands, and TLS handshakes) become trapped behind massive bulk data transfers like backups or file uploads.

The Impact on Business Operations

  • Degraded User Experience: Web pages load slower because HTTP requests are stuck in virtual queues.
  • Erratic API Performance: Microservices communicating across servers experience variable round-trip times (RTT), leading to timeouts.
  • Unreliable Real-Time Traffic: Voice over IP (VoIP), video conferencing, and live streaming suffer from jitter and packet lag, rendering them unusable.
---

Enter CAKE: Common Applications Kept Enhanced

Historically, system administrators relied on complex Traffic Control (tc) frameworks like HTB (Hierarchical Token Bucket) combined with fq_codel (Fair Queueing Controlled Delay) to combat bufferbloat. While effective, these solutions required intricate configuration scripts and manual calculation of bandwidth ceilings.CAKE represents the next generation of Smart Queue Management (SQM). Designed as a top-down replacement for older queuing disciplines, CAKE combines traffic shaping, fair queueing, and Active Queue Management (AQM) into a single, highly optimized kernel module. It is explicitly engineered to be easy to configure while delivering superior performance under heavy load.

Key Advantages of CAKE

  1. Integrated Shaper: CAKE shapes traffic precisely to your available bandwidth, ensuring that buffers on intermediate nodes never saturate.
  2. Flow Isolation: It automatically separates traffic into distinct queues based on connection identifiers (IP addresses, ports). This prevents a single heavy download from starving other active connections.
  3. DiffServ Awareness: CAKE natively understands Differentiated Services Code Point (DSCP) markings, prioritizing critical traffic categories (like voice and interactive video) without complex firewall rules.
  4. Ack Filtering: It optimizes asymmetric connections by filtering redundant TCP acknowledgments, freeing up valuable upload bandwidth.
---

Prerequisites and System Verification

Before implementing CAKE, ensure your Linux VPS environment meets the necessary requirements. CAKE is integrated into the mainline Linux kernel (version 4.19 and higher) and is fully supported by modern distributions such as Ubuntu 20.04+, Debian 10+, and RHEL 8+.

1. Verify Kernel Support

Run the following command to verify that the CAKE module is available in your system kernel:

modinfo sch_cake

If the command returns metadata about the module, your kernel is ready. If not, you may need to update your kernel or install the extra modules package (e.g., linux-modules-extra on Ubuntu).

2. Diagnose Existing Bufferbloat

To quantify the severity of bufferbloat before optimization, utilize network diagnostic tools such as ping during a simulated heavy load, or use automated network benchmarking suites that measure latency under load (such as the Waveform Bufferbloat Test from a client perspective, or netperf internally).

---

Step-by-Step Configuration of CAKE on Linux

Configuring CAKE involves utilizing the tc (Traffic Control) subsystem in Linux. We will establish a shaper on the primary network interface of your VPS.

Step 1: Identify the Active Network Interface

Determine the name of your primary internet-facing interface using the ip command:

ip route show | grep default

Look for the identifier following the word dev (common names include eth0, ens3, or enp0s3).

Step 2: Determine Target Bandwidth

To eliminate bufferbloat, you must configure CAKE to shape traffic slightly below the absolute maximum capacity of your VPS network link. This forces the queue management to occur within the Linux kernel (where CAKE can manage it) rather than in unmanaged provider buffers. A standard rule of thumb is to set the shaper to 90% to 95% of your allocated port speed.

For example, if your VPS features a symmetrical 100 Mbps port, your target shaping speed should be 95mbit.

Step 3: Apply the CAKE Configuration

Execute the following command to apply CAKE to your outgoing interface (replace eth0 with your actual interface name and 95mbit with your calculated speed):

sudo tc qdisc add dev eth0 root cake bandwidth 95mbit besteffort triple-isolate wash

Let us break down the parameters used in this configuration:

  • bandwidth 95mbit: Enables the shaper and sets the hard throughput ceiling.
  • besteffort: The default traffic handling mode, suitable for general-purpose server workloads.
  • triple-isolate: An advanced flow-isolation mode that segregates queues based on source IP, destination IP, and transport protocol ports combined. This guarantees absolute fairness between different clients and services.
  • wash: Automatically strips excess DSCP markings at the gateway to prevent malicious or misconfigured internal traffic from tricking the shaper.

Step 4: Verify the Implementation

Confirm that the queuing discipline has been successfully attached to the interface:

tc -s qdisc show dev eth0

The output should display qdisc cake along with real-time statistics, including the number of sent packets, dropped packets, and current backlog status.

---

Making the Configuration Persistent

By default, changes made via the tc command are volatile and will be lost upon system reboot. To make the CAKE configuration permanent, you must integrate it into your system's network configuration framework.

Method A: For Systems Using systemd-networkd

If your distribution relies on systemd-networkd, you can add the qdisc configuration directly to your network interface file (typically found in /etc/systemd/network/):

[Network]
KeepConfiguration=yes

[QDisc]
Parent=root
Kind=cake

[CAKE]
Bandwidth=95M

Method B: Using a Crontab or Startup Script

For a distribution-agnostic approach, you can create a shell script and invoke it at boot time using cron. Create a script at /usr/local/bin/enable-cake.sh:

#!/bin/bash
/sbin/tc qdisc add dev eth0 root cake bandwidth 95mbit besteffort triple-isolate wash

Make the script executable with chmod +x, and add the following entry to the root crontab (via sudo crontab -e):

@reboot /usr/local/bin/enable-cake.sh
---

Conclusion and Performance Analysis

Implementing the CAKE algorithm on your Linux VPS is a highly efficient, low-overhead method to ensure predictable network performance. By intentionally capping bandwidth slightly below peak capacity, you eliminate the catastrophic latency spikes associated with bufferbloat. The result is an infrastructure that remains highly responsive, maintaining low round-trip times even under maximum operational stress. Monitor your network performance consistently, and adjust the bandwidth parameters as your provider modifies your network allocation.