VPC network communication method and device, electronic equipment and storage medium
By creating VPCs, subnets, routing tables, cloud servers and dedicated gateways in the cloud, and configuring network communication, the problems of traffic management and control in the VPC network are solved, and network communication efficiency and security are improved.
Patent Information
- Application Number
- CN202510373000.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-27
- Publication Date
- 2025-06-13
AI Technical Summary
The prior art is difficult to effectively manage and control the traffic flow in the VPC network, resulting in limitations in network communication efficiency and security.
Through the switch, create a target VPC and its corresponding VPC routing table in the cloud, create a subnet and add routing entries, deploy a cloud server and create an elastic network card for it, establish a dedicated network gateway to achieve interoperability between the VPC and the external network, and configure network communication between the cloud server and the dedicated gateway.
It realizes effective control of the flow of VPC network traffic, improves network communication efficiency and security, and ensures stable interoperability between cloud servers and external networks.
Smart Images

Figure CN120151269A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network communication technologies, and in particular, to a VPC network communication method, apparatus, electronic device, and storage medium. Background Art
[0002] A Virtual Private Cloud (VPC) is a virtual network environment provided in a cloud platform that is isolated from the outside. Users can create multiple subnets in it, and subnets within the same VPC are defaultly interconnected. In a subnet, users can deploy cloud resources (such as virtual machines, containers, databases, etc.) and achieve a secure connection to the Internet or other cloud resources by controlling network settings, such as the Internet Protocol Address (IP Address) range, routing table policies, etc. Summary of the Invention
[0003] This application provides a VPC network communication method, apparatus, electronic device, and storage medium. The technical solutions are as follows:
[0004] According to one aspect of this application, a VPC network communication method is provided. The method includes:
[0005] Create a target VPC in the cloud through a switch, and create a VPC routing table corresponding to the target VPC, where the VPC routing table is used to control the traffic flow direction in the target VPC;
[0006] Create at least one subnet in the target VPC through the switch, and add a routing entry corresponding to each subnet to the VPC routing table;
[0007] Deploy a target cloud server inside a target subnet among the at least one subnet through the switch;
[0008] Create a target elastic network interface card for the target cloud server through the switch, where the target elastic network interface card is used to provide a network interface and an IP address for the target cloud server;
[0009] Create a target dedicated line gateway through the switch, where the target dedicated line gateway is a forwarding service component that provides interconnection between the target VPC and an external network;
[0010] Configure the network communication between the target cloud server and the target dedicated line gateway through the switch.
[0011] According to another aspect of this application, a VPC network communication apparatus is provided. The apparatus includes:
[0012] A first creation module, configured to create a target VPC in the cloud through a switch, and create a VPC routing table corresponding to the target VPC, where the VPC routing table is used to control the traffic flow direction in the target VPC;
[0013] A second creation module, configured to create at least one subnet in the target VPC through the switch, and add a routing entry corresponding to each subnet to the VPC routing table;
[0014] A third creation module, configured to deploy a target cloud server inside a target subnet among the at least one subnet through the switch;
[0015] A fourth creation module, configured to create a target elastic network interface card for the target cloud server through the switch, where the target elastic network interface card is used to provide a network interface and an IP address for the target cloud server;
[0016] A fifth creation module, configured to create a target dedicated line gateway through the switch, where the target dedicated line gateway is a forwarding service component that provides interconnection between the target VPC and an external network;
[0017] A configuration module, configured to configure network communication between the target cloud server and the target dedicated line gateway through the switch.
[0018] According to one aspect of the present application, there is provided an electronic device, including: a processor and a memory storing a program, where the program includes instructions, and when the instructions are executed by the processor, the processor executes the VPC network communication method as described above.
[0019] According to another aspect of the present application, there is provided a non-transitory computer-readable storage medium storing computer instructions, where the computer instructions are used to cause a computer to execute the VPC network communication method as described above.
[0020] According to another aspect of the present application, there is provided a computer program product, where the computer program product includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the above VPC network communication method.
[0021] The beneficial effects brought by the technical solution provided by the embodiments of the present application at least include:
[0022] Create a target VPC in the cloud through a switch, and create a VPC route table corresponding to the target VPC, where the VPC route table is used to control the traffic flow in the target VPC; create at least one subnet in the target VPC through the switch, and add a route entry corresponding to each subnet to the VPC route table; deploy a target cloud server inside a target subnet in at least one subnet through the switch; create a target elastic network interface card for the target cloud server through the switch, where the target elastic network interface card is used to provide a network interface and an IP address for the target cloud server; create a target dedicated line gateway through the switch, where the target dedicated line gateway is a forwarding service component that provides interconnection between the target VPC and an external network; configure the network communication between the target cloud server and the target dedicated line gateway through the switch. Through the creation and configuration process provided by the embodiments of the present application, a communication path of target cloud server - target subnet - target VPC - target dedicated line gateway - external network is constructed, thereby realizing network communication based on VPC. BRIEF DESCRIPTION OF THE DRAWINGS
[0023] In the following description of exemplary embodiments with reference to the accompanying drawings, more details, features, and advantages of the present application are disclosed. In the drawings:
[0024] Figure 1 Shows a flowchart of a VPC network communication method according to an exemplary embodiment of the present application;
[0025] Figure 2 Is a schematic diagram of the VPC life cycle provided by an exemplary embodiment of the present application;
[0026] Figure 3 Shows a flowchart of another VPC network communication method according to an exemplary embodiment of the present application;
[0027] Figure 4 Is a schematic diagram of the process of binding, unbinding, and changing subnets provided by an exemplary embodiment of the present application;
[0028] Figure 5 Is a schematic diagram of the structure of a VPC network communication device provided by an embodiment of the present application;
[0029] Figure 6 Shows a structural block diagram of an exemplary electronic device that can be used to implement the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0030] Embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present application are shown in the drawings, it should be understood that the present application can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present application. It should be understood that the drawings and embodiments of the present application are only for exemplary purposes and are not used to limit the protection scope of the present application.
[0031] It should be understood that the various steps recorded in the method embodiments of the present application can be executed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present application is not limited in this regard.
[0032] As used herein, the term "including" and its variants are open-ended, that is, "including but not limited to". The term "based on" means "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts such as "first" and "second" mentioned in the present application are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships. It should be noted that the modifications of "one" and "multiple" mentioned in the present application are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly specified in the context, it should be understood as "one or more". The names of the messages or information exchanged between multiple devices in the embodiments of the present application are only for illustrative purposes and are not used to limit the scope of these messages or information.
[0033] The following describes the solution of the present application with reference to the accompanying drawings, and details the technical solutions provided by the embodiments of the present application through specific embodiments and their application scenarios.
[0034] Please refer to Figure 1 , which shows a flowchart of a VPC network communication method according to an exemplary embodiment of the present application. This method is exemplarily described by taking its application to a cloud platform as an example. As Figure 1 shown, the method includes:
[0035] Step 101, create a target VPC in the cloud through a switch, and create a VPC route table corresponding to the target VPC. The VPC route table is used to control the traffic flow direction in the target VPC.
[0036] Among them, VPC is a virtual network environment provided in the cloud platform that is isolated from the outside. Users can create multiple subnets in it, and the subnets within the same VPC are defaultly interconnected. In a subnet, users can deploy cloud resources (such as virtual machines, containers, databases, cloud servers, and other cloud products), and achieve secure connections to the Internet or other cloud resources by controlling network settings such as IP address ranges and routing table policies.
[0037] It should be noted that VPC is a logical concept that mainly exists in the control plane for the convenience of users' understanding. In the forwarding plane of the physical switch, there is no such structure as VPC.
[0038] In a possible implementation, the user triggers a creation instruction for the target VPC in the cloud platform. This creation instruction is sent to the switch, and the switch executes the operation of creating the target VPC in the cloud. Optionally, after creating the target VPC, the cloud platform will automatically create a system routing table through the switch to control the routing of the target VPC. All subnets within the target VPC defaultly use the system routing table, and users cannot create or delete the system routing table. This system routing table can also be called the VPC routing table, and the VPC routing table can manage and control the traffic flow direction in the target VPC by specifying the target network segment and the next hop.
[0039] Figure 2 It is a schematic diagram of the VPC life cycle provided by an exemplary embodiment of the present application. As Figure 2 shown, triggering the VPC creation operation in the control panel - VPC component will allocate a tenant VPC ID; triggering the VPC deletion operation in the control panel - VPC component will check whether there are resources such as subnets and routing tables under the VPC through the control panel - other components. If not, the control panel - VPC component will release the tenant VPC ID.
[0040] Step 102, create at least one subnet in the target VPC through the switch, and add a routing entry corresponding to each subnet in the VPC routing table.
[0041] After creating the target VPC, continue to create at least one subnet in the target VPC through the switch. At the same time, after creating the subnet, the cloud platform will automatically add a routing entry corresponding to each subnet in the VPC routing table. This routing entry is an IPv4 routing entry with the subnet network segment corresponding to each subnet as the target network segment, and is used for communication between cloud products (such as cloud servers) within the subnet.
[0042] Exemplarily, the code for the switch to create the subnet configuration can be as follows:
[0043]
[0044]
[0045] Step 103, deploy the target cloud server within the target subnet in at least one subnet through a switch.
[0046] After creating the subnet, further trigger the instruction to deploy the cloud server in the subnet. Then, after the switch receives this creation instruction, it can perform the operation of deploying the target cloud server within the target subnet in at least one subnet.
[0047] Step 104, create a target elastic network interface card for the target cloud server through the switch. The target elastic network interface card is used to provide a network interface and an IP address for the target cloud server.
[0048] In order to locate the deployed target cloud server, it is also necessary to create a virtual network interface for the target cloud server. In a possible implementation, create a target elastic network interface card for the target cloud server through the switch. The target elastic network interface card is used to provide a network interface and an IP address for the target cloud server.
[0049] Optionally, the target elastic network interface card can be divided into a primary network interface card and a secondary elastic network interface card. Each server instance (target cloud server) has a default primary network interface card, and users cannot independently create or unbind the primary network interface card from the cloud server. Users can create secondary elastic network interface cards and bind them to the server. Each server can bind one or more secondary elastic network interface cards. Exemplarily, the code for the switch to create the configuration of the primary network interface card can be as follows:
[0050]
[0051] Exemplarily, the code for the switch to create the configuration of the secondary elastic network interface card is as follows:
[0052]
[0053] Step 105, create a target dedicated line gateway through the switch. The target dedicated line gateway is a forwarding service component that provides the interconnection between the target VPC and the external network.
[0054] After creating the VPC, the internal subnet, and the cloud server, if VPC communication is to be achieved, traffic exchange with the external network is also required. Correspondingly, a target dedicated line gateway is also created through the switch. The target dedicated line gateway is a forwarding service component that provides the interconnection function between the target VPC and the external network. That is to say, the target VPC can receive traffic (or data packets) sent by the external network through the target dedicated line gateway; the target VPC can also send traffic (or data packets) to the external network through the target dedicated line gateway.
[0055] Exemplarily, the code for the switch to create the configuration of the dedicated line gateway can be as follows:
[0056]
[0057] Step 106, configure the network communication between the target cloud server and the target dedicated line gateway through the switch.
[0058] After creating the target dedicated line gateway, in order to implement the communication path from the target cloud server to the external network, it is also necessary to establish the communication between the target cloud server and the target dedicated line gateway. Correspondingly, configure the network communication between the target cloud server and the target dedicated line gateway through the switch. Based on the fact that the target dedicated line gateway has the function of providing interconnection between the target VPC and the external network, the communication path of target cloud server - target subnet - target VPC - target dedicated line gateway - external network can be realized.
[0059] In summary, the embodiment of the present application provides a VPC network communication method: create a target VPC in the cloud through the switch, and create a VPC routing table corresponding to the target VPC, where the VPC routing table is used to control the traffic flow in the target VPC; create at least one subnet in the target VPC through the switch, and add a routing entry corresponding to each subnet in the VPC routing table; deploy the target cloud server inside the target subnet in at least one subnet through the switch; create a target elastic network interface card for the target cloud server through the switch, and the target elastic network interface card is used to provide a network interface and an IP address for the target cloud server; create a target dedicated line gateway through the switch, and the target dedicated line gateway is a forwarding service component that provides interconnection between the target VPC and the external network; configure the network communication between the target cloud server and the target dedicated line gateway through the switch. Through the creation and configuration processes provided by the embodiment of the present application, the communication path of target cloud server - target subnet - target VPC - target dedicated line gateway - external network is constructed, thereby realizing network communication based on the VPC.
[0060] Please refer to Figure 3 , which shows a flowchart of another VPC network communication method according to an exemplary embodiment of the present application. Taking the application of this method to a cloud platform as an example for exemplary illustration. As Figure 3 shown, this method includes:
[0061] Step 301, create a target VPC in the cloud through the switch, and create a VPC routing table corresponding to the target VPC, where the VPC routing table is used to control the traffic flow in the target VPC.
[0062] Step 302, create at least one subnet in the target VPC through the switch, and add a routing entry corresponding to each subnet in the VPC routing table.
[0063] Step 303, deploy the target cloud server inside the target subnet in at least one subnet through the switch.
[0064] Step 304: Create a target elastic network interface for the target cloud server through a switch. The target elastic network interface is used to provide a network interface and an IP address for the target cloud server.
[0065] The implementation manners of Steps 301 to 304 can refer to the above embodiments, and are not elaborated herein.
[0066] After creating the target elastic network interface, in order to enable the target cloud server to communicate with the target subnet through the target elastic network interface, it is also necessary to bind the target elastic network interface to the target subnet and create an AC (Attachment Circuit). In a corresponding exemplary example, after creating the target elastic network interface for the target cloud server through a switch, the method may further include Steps 1 to 4:
[0067] Step 1: Bind the interface of the target elastic network interface to the target subnet through the switch and trigger an AC creation request.
[0068] After creating the target elastic network interface and binding the target elastic network interface to the target cloud server, the interface of the target elastic network interface will also be bound to the target subnet through the switch to establish a communication connection between the target cloud server and the target subnet through the target elastic network interface. After binding the interface of the target elastic network interface to the target subnet, an AC creation request will also be triggered. The AC creation request instructs to allocate AC hardware resources for the target cloud server. In VXLAN (Virtual Extensible LAN), the Ethernet service instance associated with the VSI (Virtual Switch Interface) is called an AC (Attachment Circuit).
[0069] Step 2: After receiving the AC creation request, determine whether there is a corresponding target VPC on the switch.
[0070] After receiving the AC creation request, first determine whether there is a corresponding target VPC on the switch. If it exists, execute Step 3 and continue to determine whether there is a corresponding target subnet on the switch; otherwise, if the target VPC does not exist, it is necessary to issue the routing configuration of the target VPC through the switch.
[0071] Step 3: If the target VPC exists, continue to determine whether there is a corresponding target subnet on the switch.
[0072] If a target VPC exists, continue to determine whether a corresponding target subnet exists on the switch; if the target subnet exists, continue to execute Step Four to create (or allocate) a target AC for the target cloud service; otherwise, if the target subnet does not exist, the routing configuration of the target subnet needs to be issued through the switch.
[0073] Step Four: If the target subnet exists, create a target AC for the target cloud server.
[0074] If the target subnet also exists, a target AC can be created for the target cloud server.
[0075] Steps One to Four are the binding process. In actual application scenarios, there are also operation scenarios such as unbinding and replacement. In an exemplary example, the process of unbinding the interface of the target elastic network card from the target subnet may include Steps Five to Eight:
[0076] Step Five: If a request to unbind the interface of the target elastic network card from the target subnet is received, trigger an AC deletion request.
[0077] If the user needs to unbind the target elastic network card from the target subnet, an unbinding instruction will be triggered. The corresponding switch receives the request to unbind the interface of the target elastic network card from the target subnet and unbinds the interface of the target elastic network card from the target subnet; corresponding to the AC creation request triggered during the binding phase, an AC deletion request will also be triggered during the unbinding phase.
[0078] Step Six: After receiving the AC deletion request, delete the target AC and determine whether there are other ACs under the target subnet.
[0079] After the switch receives the AC deletion request, it will first delete the target AC corresponding to the target cloud server; secondly, it will also determine whether there are other ACs under the target subnet. If there are other ACs, the configuration information of the target subnet will continue to be retained; otherwise, if there are no other ACs under the target subnet, the configuration information of the target subnet will be further cleared.
[0080] Step Seven: If there are no other ACs, clear the configuration information of the target subnet and determine whether there are other subnets under the target VPC.
[0081] If there are no other ACs under the target subnet except the target AC, continue to clear the configuration information of the target subnet; and determine whether there are other subnets under the target VPC except the target subnet.
[0082] Step Eight: If there are no other subnets, clear the configuration of the VPC routing table.
[0083] If there are no other subnets except the target subnet, continue to clear the configuration of the VPC route table; if there are other subnets except the target subnet, retain the configuration of the VPC route table.
[0084] In another exemplary example, the process of replacing the target subnet bound to the interface of the target elastic network interface card may include Step Nine and Step Ten:
[0085] Step Nine: If a replacement instruction for the target subnet bound to the interface of the target elastic network interface card is received, trigger an AC deletion request.
[0086] The replacement operation scenario refers to unbinding the interface of the target elastic network interface card from the target subnet and then binding it to another subnet. It includes two types: an unbinding operation and a creation operation. In a possible implementation, if a replacement instruction for the target subnet bound to the interface of the target elastic network interface card is received, first, unbind the target subnet from the interface of the target elastic network interface card, and at the same time, trigger an AC deletion request. After triggering the AC deletion request, delete the target AC, and determine whether there are other ACs under the target subnet. If there are no other ACs, clear the configuration information of the target subnet, and determine whether there are other subnets under the target VPC. If there are no other subnets, clear the configuration of the VPC route table.
[0087] Step Ten: After executing the deletion process corresponding to the AC deletion request, trigger an AC creation request.
[0088] After executing the deletion process corresponding to the AC deletion request, rebind the interface of the target elastic network interface card to the new target subnet, and at the same time, trigger an AC creation request. Determine whether there is a corresponding target VPC on the switch. If there is a target VPC, continue to determine whether there is a corresponding target subnet on the switch. If there is a target subnet, create a new target AC for the target cloud server.
[0089] Figure 4 It is a schematic diagram of the process for binding, unbinding, and changing subnets provided by an exemplary embodiment of the present application. As Figure 4 shown, trigger the network interface card binding, replacement, and unbinding operations in the Control Panel - Server Network Component. After the Control Panel - Physical Switch Component receives the interface binding subnet request and performs the binding operation, it will also create an AC process. After the Control Panel - Physical Switch Component receives the interface replacing subnet request and performs the replacement operation, it will also delete the AC process and create an AC process. After the Control Panel - Physical Switch Component receives the interface unbinding subnet request and performs the unbinding operation, it will also delete the AC process. Optionally, the creation of the AC process and the deletion of the AC process can be as Figure 4 shown.
[0090] Step 305: Create a target dedicated line gateway through a switch. The target dedicated line gateway is a forwarding service component that provides interconnection between the target VPC and the external network.
[0091] For the implementation of step 305, reference can be made to the above embodiments, and details are not elaborated herein.
[0092] Step 306: Establish an interconnection configuration between the target dedicated line gateway and the external network through a switch.
[0093] In the process of creating a network path between the target cloud server and the target dedicated line gateway, first establish an interconnection configuration between the target dedicated line gateway and the external network through a switch, so that after the data packet reaches the target dedicated line gateway, the target dedicated line gateway can determine which external network to forward the data packet to based on this interconnection configuration.
[0094] Exemplarily, the code for the switch to create the interconnection configuration between the dedicated line gateway and the external network can be as follows:
[0095]
[0096] Step 307: Bind the target dedicated line gateway to the target VPC through a switch.
[0097] After that, the target dedicated line gateway can be bound to the target VPC through a switch. Exemplarily, the code for the switch to configure the binding of the dedicated line gateway to the target VPC can be as follows:
[0098]
[0099] Step 308: Configure the target route table to bind to the target dedicated line gateway through a switch.
[0100] In addition to binding the target VPC to the target dedicated line gateway, corresponding routing entries also need to be added to the route table, so that the data packets sent by the target cloud server can be forwarded to the external server through the target dedicated line gateway after passing through the target subnet and the target VPC. In a possible implementation, it is also necessary to configure the target route table to bind to the target dedicated line gateway through a switch.
[0101] Optionally, configuring the target route table to bind to the target dedicated line gateway through a switch may further include: configuring the target subnet in the target route table to receive the routing information of the target dedicated line gateway through the switch; configuring the target route table in the switch to receive the routing of the target dedicated line gateway and the routing information for forwarding data packets to the target dedicated line gateway.
[0102] Exemplarily, the code for the switch to configure the target route table to bind to the target dedicated line gateway can be as follows:
[0103]
[0104]
[0105] Step 309, configure default route information for the target dedicated line gateway through the switch.
[0106] Finally, it is also necessary to configure default route information for the target dedicated line gateway. This default route information is used to indicate the external network to which the data packets sent to the target dedicated line gateway are forwarded. Exemplarily, the code for the switch to configure the target dedicated line gateway to publish the default route configuration can be as follows:
[0107] "ip route-static vpn-instance ecr-{{ecr-id}} 0.0.0.0 0 {{INTERFACE}} / / Configure the default route to direct all traffic within the dedicated line gateway to the peer address by default
[0108] bgp {{4212004001}}
[0109] ipvpn-instance ecr-{{ecr-id}}
[0110] address-family ipv4 unicast
[0111] default-route imported" / / Configure bgp to publish the default route
[0112] In this embodiment, the interconnection configuration between the target dedicated line gateway and the external network is established through the switch; the target dedicated line gateway is bound to the target VPC through the switch; the target routing table is configured to bind the target dedicated line gateway through the switch; and the processes such as configuring default route information for the target dedicated line gateway through the switch can realize the network path from the target cloud server to the target dedicated line gateway and from the target dedicated line gateway to the external network, further ensuring the network communication ability of the target cloud server.
[0113] Please refer to Figure 5 , which is a schematic structural diagram of a VPC network communication device provided in an embodiment of the present application. Exemplarily, as Figure 5 shown, the device 500 includes:
[0114] The first creation module 501 is used to create a target VPC in the cloud through the switch and create a VPC routing table corresponding to the target VPC. The VPC routing table is used to control the traffic flow direction in the target VPC;
[0115] A second creation module 502, configured to create at least one subnet in the target VPC through the switch, and add a routing entry corresponding to each subnet to the VPC routing table;
[0116] A third creation module 503, configured to deploy a target cloud server inside a target subnet among the at least one subnet through the switch;
[0117] A fourth creation module 504, configured to create a target elastic network interface card for the target cloud server through the switch, where the target elastic network interface card is used to provide a network interface and an IP address for the target cloud server;
[0118] A fifth creation module 505, configured to create a target dedicated line gateway through the switch, where the target dedicated line gateway is a forwarding service component that provides interconnection between the target VPC and an external network;
[0119] A configuration module 506, configured to configure network communication between the target cloud server and the target dedicated line gateway through the switch.
[0120] Optionally, the configuration module 506 is further configured to:
[0121] Establish an interconnection configuration between the target dedicated line gateway and the external network through the switch;
[0122] Bind the target dedicated line gateway to the target VPC through the switch;
[0123] Configure the target routing table to bind to the target dedicated line gateway through the switch;
[0124] Configure default routing information for the target dedicated line gateway through the switch.
[0125] Optionally, the configuration module 506 is further configured to:
[0126] Configure the target subnet in the target routing table to receive routing information of the target dedicated line gateway through the switch;
[0127] Configure routing information in the target routing table to receive the routing of the target dedicated line gateway and forward data packets to the target dedicated line gateway through the switch.
[0128] Optionally, the apparatus further includes:
[0129] A binding module, configured to bind an interface of the target elastic network interface card to the target subnet through the switch, and trigger an AC creation request;
[0130] A first judgment module, configured to judge whether the corresponding target VPC exists on the switch after receiving the AC creation request;
[0131] A second judgment module, configured to, if the target VPC exists, continue to judge whether the corresponding target subnet exists on the switch;
[0132] A sixth creation module, configured to, if the target subnet exists, create a target AC for the target cloud server.
[0133] Optionally, the apparatus further includes:
[0134] A first trigger module, configured to trigger an AC deletion request if receiving an unbinding instruction for the interface of the target elastic network card from the target subnet;
[0135] A third judgment module, configured to, after receiving the AC deletion request, delete the target AC and judge whether there are other ACs under the target subnet;
[0136] A first clearing module, configured to, if there are no other ACs, clear the configuration information of the target subnet and judge whether there are other subnets under the target VPC;
[0137] A second clearing module, configured to, if there are no other subnets, clear the configuration of the VPC routing table.
[0138] Optionally, the apparatus further includes:
[0139] A second trigger module, configured to trigger the AC deletion request if receiving a replacement instruction for the target subnet bound to the interface of the target elastic network card;
[0140] A third trigger module, configured to trigger the AC creation request after executing the deletion process corresponding to the AC deletion request.
[0141] In summary, the embodiments of the present application provide a VPC network communication method: creating a target VPC in the cloud through a switch, and creating a VPC routing table corresponding to the target VPC, where the VPC routing table is used to control the traffic flow in the target VPC; creating at least one subnet in the target VPC through the switch, and adding a routing entry corresponding to each subnet to the VPC routing table; deploying a target cloud server inside a target subnet among the at least one subnet through the switch; creating a target elastic network interface card for the target cloud server through the switch, where the target elastic network interface card is used to provide a network interface and an IP address for the target cloud server; creating a target dedicated line gateway through the switch, where the target dedicated line gateway is a forwarding service component that provides interconnection between the target VPC and an external network; configuring network communication between the target cloud server and the target dedicated line gateway through the switch. Through the creation and configuration processes provided by the embodiments of the present application, a communication path of target cloud server - target subnet - target VPC - target dedicated line gateway - external network is constructed, thereby realizing network communication based on VPC.
[0142] An exemplary embodiment of the present application further provides an electronic device, including: at least one processor; and a memory communicatively connected to the at least one processor. The memory stores a computer program capable of being executed by the at least one processor, and when the computer program is executed by the at least one processor, it is used to cause the electronic device to execute the VPC network communication method according to the embodiments of the present application.
[0143] An exemplary embodiment of the present application further provides a non-transitory computer-readable storage medium storing a computer program, where when the computer program is executed by a processor of a computer, it is used to cause the computer to execute the VPC network communication method according to the embodiments of the present application.
[0144] An exemplary embodiment of the present application further provides a computer program product, including a computer program, where when the computer program is executed by a processor of a computer, it is used to cause the computer to execute the VPC network communication method according to the embodiments of the present application.
[0145] Reference Figure 6, a block diagram of an electronic device 600 that can be a server or a client of the present application will now be described. It is an example of a hardware device that can be applied to various aspects of the present application. The electronic device is intended to represent various forms of digital electronic computer devices, such as, laptop computers, desktop computers, workstations, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as, personal digital processors, cellular phones, smart phones, wearable devices, and other similar computing devices. The components shown herein, their connections and relationships, and their functions are merely examples and are not intended to limit the implementation of the present application described and / or claimed herein.
[0146] As Figure 6 shown, the electronic device 600 includes a computing unit 601, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 602 or a computer program loaded from a storage unit 608 into a random access memory (RAM) 603. In the RAM 603, various programs and data required for the operation of the electronic device 600 can also be stored. The computing unit 601, the ROM 602, and the RAM 603 are connected to each other through a bus 604. An input / output (I / O) interface 605 is also connected to the bus 604.
[0147] A plurality of components in the electronic device 600 are connected to the I / O interface 605, including: an input unit 606, an output unit 607, a storage unit 608, and a communication unit 609. The input unit 606 can be any type of device that can input information into the electronic device 600. The input unit 606 can receive input digital or character information, and generate key signal inputs related to the user settings and / or function controls of the electronic device. The output unit 607 can be any type of device that can present information, and can include but is not limited to a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 608 can include but is not limited to magnetic disks, optical disks. The communication unit 609 allows the electronic device 600 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks, and can include but is not limited to a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a Bluetooth device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.
[0148] Optionally, a single-channel electroencephalogram signal acquisition module (not shown in the figure) is also provided in the electronic device 600. It is used to acquire electroencephalogram signals and transmit the electroencephalogram signals to the signal processor of the electronic device 600 for electroencephalogram signal processing.
[0149] The computing unit 601 can be various general-purpose and / or special-purpose processing components with processing and computing capabilities. Some examples of the computing unit 601 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various dedicated artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, a digital signal processor (DSP), and any suitable processor, controller, microcontroller, etc. The computing unit 601 executes the various methods and processes described above. For example, in some embodiments, Figure 1 , Figure 3 the method shown can be implemented as a computer software program tangibly embodied in a machine-readable medium, such as the storage unit 608. In some embodiments, part or all of the computer program can be loaded and / or installed onto the electronic device 600 via the ROM 602 and / or the communication unit 609. In some embodiments, the computing unit 601 can be configured to execute Figure 1 , Figure 3 the method shown in any other suitable manner (e.g., by means of firmware).
[0150] The program code for implementing the methods of the present application can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, such that when the program codes are executed by the processor or controller, the functions / operations specified in the flowchart and / or block diagram are implemented. The program code can be executed entirely on the machine, partially on the machine, as an independent software package partially on the machine and partially on a remote machine, or entirely on a remote machine or server.
[0151] In the context of the present application, a machine-readable medium can be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium can include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0152] As used in this application, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., a magnetic disk, an optical disk, a memory, a programmable logic device (PLD)) used to provide machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal used to provide machine instructions and / or data to a programmable processor.
[0153] For purposes of providing an interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and a pointing device (e.g., a mouse or a trackball) by which the user can provide input to the computer. Other kinds of devices can also be used to provide for interaction with the user; for example, feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic, speech, or tactile input).
[0154] The systems and techniques described herein can be implemented in a computing system that includes a back-end component (e.g., as a data server), or a computing system that includes a middleware component (e.g., an application server), or a computing system that includes a front-end component (e.g., a user computer having a graphical user interface or a web browser through which the user can interact with an implementation of the systems and techniques described herein), or in a computing system that includes any combination of such back-end, middleware, or front-end components. The components of the system can be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0155] A computer system can include a client and a server. The client and server are generally remote from each other and typically interact through a communication network. The client-server relationship is created by computer programs running on the respective computers and having a client-server relationship to each other.
Claims
1. A VPC network communication method, characterized in that: The method comprises: Creating a target VPC in the cloud through a switch, and creating a VPC routing table corresponding to the target VPC, wherein the VPC routing table is used to control the flow of traffic in the target VPC; Creating at least one subnet in the target VPC through the switch, and adding a routing entry corresponding to each subnet in the VPC routing table; Deploy a target cloud server in a target subnet in the at least one subnet through the switch; Creating a target elastic network card for the target cloud server through the switch, wherein the target elastic network card is used to provide a network interface and an IP address for the target cloud server; Create a target dedicated gateway through the switch, where the target dedicated gateway is a forwarding service component that provides intercommunication between the target VPC and the external network; The network communication between the target cloud server and the target dedicated gateway is configured through the switch.
2. The method according to claim 1, characterized in that The configuring the network communication between the target cloud server and the target dedicated gateway through the switch includes: Establishing an interconnection configuration between the target dedicated line gateway and the external network through the switch; Binding the target dedicated gateway to the target VPC through the switch; Configure the target routing table through the switch to bind the target dedicated line gateway; The default routing information is configured for the target dedicated line gateway through the switch.
3. The method according to claim 2, characterized in that The configuring the target routing table to bind the target dedicated line gateway through the switch includes: Configuring the target subnet in the target routing table through the switch to receive routing information of the target dedicated gateway; The switch configures the target routing table to receive the routing of the target dedicated gateway and forward the data packet to the routing information of the target dedicated gateway.
4. The method according to any one of claims 1 to 3, characterized in that: After creating a target elastic network card for the target cloud server through the switch, the method further includes: Binding the interface of the target elastic network card to the target subnet through the switch, and triggering an AC creation request; After receiving the AC creation request, determining whether the corresponding target VPC exists on the switch; If the target VPC exists, continue to determine whether the corresponding target subnet exists on the switch; If the target subnet exists, a target AC is created for the target cloud server.
5. The method according to claim 4, characterized in that The method further comprises: If an instruction to unbind the interface of the target ENI from the target subnet is received, an AC deletion request is triggered; After receiving the AC deletion request, deleting the target AC, and determining whether there are other ACs under the target subnet; If the other AC does not exist, clear the configuration information of the target subnet, and determine whether there are other subnets under the target VPC; If the other subnet does not exist, clear the configuration of the VPC routing table.
6. The method according to claim 5, characterized in that The method further comprises: If a replacement instruction of the target subnet bound to the interface of the target elastic network card is received, triggering the AC deletion request; After executing the deletion process corresponding to the AC deletion request, the AC creation request is triggered.
7. A VPC network communication device, characterized in that: The device comprises: A first creation module is used to create a target VPC in the cloud through a switch, and to create a VPC routing table corresponding to the target VPC, wherein the VPC routing table is used to control the flow direction of traffic in the target VPC; A second creation module is used to create at least one subnet in the target VPC through the switch, and add a routing entry corresponding to each subnet in the VPC routing table; A third creation module is used to deploy a target cloud server in a target subnet in the at least one subnet through the switch; A fourth creation module, configured to create a target elastic network card for the target cloud server through the switch, wherein the target elastic network card is used to provide a network interface and an IP address for the target cloud server; A fifth creation module, configured to create a target dedicated line gateway through the switch, wherein the target dedicated line gateway is a forwarding service component that provides intercommunication between the target VPC and an external network; A configuration module is used to configure the network communication between the target cloud server and the target dedicated gateway through the switch.
8. The device according to claim 7, characterized in that The configuration module is also used for: Establishing an interconnection configuration between the target dedicated line gateway and the external network through the switch; Binding the target dedicated gateway to the target VPC through the switch; Configure the target routing table through the switch to bind the target dedicated line gateway; The default routing information is configured for the target dedicated line gateway through the switch.
9. An electronic device, comprising: processor; as well as Memory for storing programs, The program includes instructions, which, when executed by the processor, cause the processor to execute the VPC network communication method according to any one of claims 1 to 6.
10. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to enable the computer to execute the VPC network communication method according to any one of claims 1 to 6.