Kubernetes-based DMZ zone dynamic configuration access system, method, device and storage medium

By creating Ingress objects and Service objects in Kubernetes cluster and configuring CoreDNS components, a dynamic access system for the DMZ area is realized, solving the problem of complex configuration of traditional DMZ gateways and improving security and convenience.

CN120223423BActive Publication Date: 2025-08-19ZHEJIANG LAB
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202510496548.8
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-04-21
Publication Date
2025-08-19
Estimated Expiration
2045-04-21

AI Technical Summary

Technical Problem

Traditional DMZ gateway configuration and management are complex, and errors are prone to occur, resulting in network security risks, and it is difficult to meet the needs of rapid online launch under cloud computing and microservice architectures.

Method used

The access system is dynamically configured with the Kubernetes-based DMZ area, and the deployment module creates Ingress objects and Service objects in the Kubernetes cluster, configures the domain name resolution information of the CoreDNS component, and uses the Ingress controller and CoreDNS components to achieve dynamic forwarding and security verification of access requests.

Benefits of technology

It reduces the difficulty of gateway service configuration, supports dynamic configuration of access rules, realizes the convenience and expansion of the application's external services, shortens the online cycle, and improves the security of the internal network.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120223423B_ABST
    Figure CN120223423B_ABST
Patent Text Reader

Abstract

The present application relates to a DMZ zone dynamic configuration access system, method, device and storage medium based on Kubernetes, wherein the system creates Ingress objects and Service objects corresponding to each computing service in the Kubernetes cluster through a deployment module, wherein the Ingress objects and Service objects are configured with corresponding forwarding rules; and the domain name resolution information of the CoreDNS component is configured; the terminal user's access request is forwarded to the Ingress controller through the Kubernetes cluster; the Ingress controller matches the corresponding forwarding rule based on the access request, and obtains the IP address of the computing service through the CoreDNS component, and the Ingress controller forwards the access request to the IP address, thereby realizing the convenience and scalability of the application in providing services to the outside world and improving the security of access to the internal network.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer network security technology, and in particular to a Kubernetes-based DMZ zone dynamic configuration access system, method, device and storage medium. Background Art

[0002] The DMZ (Demilitarized Zone) is a key concept in network security architecture. It is used to establish a buffer zone between the internal network and the external network. Its main purpose is to enhance network security by isolating servers that provide external services (such as web servers and mail servers) to prevent external attacks from directly threatening the internal network.

[0003] In today's network environment, with the rapid development of cloud computing and microservices architectures, enterprises are facing increasing network security challenges and the need for rapid rollout. Traditional DMZ gateways often require manual configuration and management, which is relatively complex. This not only increases management workload but also makes configuration errors and vulnerabilities more likely to occur, leading to network security risks. Summary of the Invention

[0004] Based on this, it is necessary to provide a Kubernetes-based DMZ zone dynamic configuration access system, method, device and storage medium to address the above technical problems.

[0005] In a first aspect, an embodiment of the present application provides a DMZ zone dynamic configuration access system based on Kubernetes, including a deployment module, a Kubernetes cluster, a CoreDNS component, an Ingress controller, and a computing cluster, wherein the computing cluster includes multiple computing services, and the Kubernetes cluster, the CoreDNS component, and the Ingress controller are located in the DMZ zone;

[0006] The deployment module is configured to create an Ingress object and a Service object corresponding to each of the computing services in the Kubernetes cluster, wherein the Ingress object and the Service object are configured with corresponding forwarding rules; and configure domain name resolution information of the CoreDNS component;

[0007] The Kubernetes cluster is used to forward the access request of the terminal user to the Ingress controller;

[0008] The Ingress controller is configured to match a corresponding forwarding rule based on the access request, determine the internal domain name of the corresponding computing service based on the matched forwarding rule, and send a domain name resolution request to the CoreDNS component;

[0009] The CoreDNS component is used to obtain the IP address of the computing service based on the internal domain name resolution information and send the IP address to the Ingress controller; the Ingress controller is used to forward the access request to the IP address.

[0010] In one embodiment, the access request includes authentication information, and the system further includes an authentication module.

[0011] The authentication module is configured to receive a verification request from the Ingress controller, verify the authentication information carried in the access request, and send the verification result to the Ingress controller;

[0012] The Ingress controller is configured to determine the internal domain name of the corresponding computing service based on the matched forwarding rule if the verification result passes.

[0013] In one embodiment, the system further comprises:

[0014] A load balancing module is used to forward the terminal user's access request to multiple servers in the Kubernetes cluster based on preset distribution rules.

[0015] In one embodiment, the system further comprises:

[0016] Firewalls are used to monitor and control network traffic to protect the network security of the system.

[0017] In a second aspect, an embodiment of the present application further provides a method for dynamically configuring access to a DMZ zone based on Kubernetes, which is applied to the system described in the first aspect above, and the method includes:

[0018] Use the deployment module to create Ingress and Service objects corresponding to each computing service in the Kubernetes cluster, where the Ingress and Service objects are configured with corresponding forwarding rules; and configure the domain name resolution information of the CoreDNS component;

[0019] Utilize the Kubernetes cluster to forward the end user's access request to the Ingress controller;

[0020] Using the Ingress controller, based on the access request, it matches the corresponding forwarding rule, determines the internal domain name of the corresponding computing service based on the matched forwarding rule, and sends a domain name resolution request to the CoreDNS component;

[0021] Using the CoreDNS component, based on the internal domain name resolution information, obtain the IP address of the computing service, and send the IP address to the Ingress controller;

[0022] The Ingress controller is used to forward the access request to the IP address.

[0023] In one embodiment, using the Ingress controller to match a corresponding forwarding rule based on the access request, and determining the internal domain name of the corresponding computing service based on the matched forwarding rule includes:

[0024] Using the Ingress controller, based on the access request, a corresponding Ingress object is matched;

[0025] The Ingress controller is used to match a corresponding Service object according to the Service name specified in the Ingress object, and based on the Service object, the internal domain name of the corresponding computing service is determined.

[0026] In one embodiment, the method further comprises:

[0027] If the Ingress controller does not find that the access request matches the Ingress object, the end user rejects the access request.

[0028] In one embodiment, when the computing cluster is a Kubernetes computing cluster, the method further includes:

[0029] Using a deployment module to create a second Ingress object and a second Service object corresponding to each of the computing services in the Kubernetes computing cluster, wherein the second Ingress object and the second Service object are configured with a corresponding second forwarding rule;

[0030] After using the Ingress controller to forward the access request to the IP address exposed by the computing service, the Kubernetes computing cluster is used to match the second forwarding rule corresponding to the access request, and the access request is forwarded to the corresponding computing service based on the second forwarding rule.

[0031] In a third aspect, an embodiment of the present application further provides a computer device comprising a memory and a processor, wherein the memory stores a computer program, and the processor is configured to run the computer program to execute the method as described in the second aspect above.

[0032] In a fourth aspect, an embodiment of the present application further provides a computer-readable storage medium, wherein the storage medium stores a computer program, wherein when the computer program is executed by a processor, the method described in the second aspect above is implemented.

[0033] The above-mentioned Kubernetes-based DMZ zone dynamic configuration access system, method, device and storage medium, by using a deployment module to create Ingress objects and Service objects corresponding to each computing service in the Kubernetes cluster, wherein the Ingress objects and Service objects are configured with corresponding forwarding rules; and the domain name resolution information of the CoreDNS component is configured; the terminal user's access request is forwarded to the Ingress controller using the Kubernetes cluster; the Ingress controller is used to match the corresponding forwarding rule based on the access request, and based on the matched forwarding rule, the internal domain name of the corresponding computing service is determined, and a domain name resolution request is sent to the CoreDNS component; the CoreDNS component is used to obtain the IP address of the computing service based on the internal domain name resolution information, and send the IP address to the Ingress controller; the Ingress controller is used to forward the access request to the IP address, which reduces the difficulty of gateway service configuration, supports dynamic configuration of access rules, realizes the convenience and scalability of the application providing services to the outside world, and shortens the application online cycle; only forwards requests for specified rules, and directly rejects requests if no rules are found, which provides effective protection for the security within the data center and improves the security of access to the internal network.

[0034] The details of one or more embodiments of the present application are set forth in the following drawings and description to make other features, objects, and advantages of the present application more readily apparent. BRIEF DESCRIPTION OF THE DRAWINGS

[0035] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:

[0036] Figure 1 This is a hardware structure diagram of a DMZ zone dynamic configuration access system based on Kubernetes in one embodiment;

[0037] Figure 2 This is a hardware structure diagram of a DMZ zone dynamic configuration access system based on Kubernetes in another embodiment;

[0038] Figure 3 This is a flowchart of a method for dynamically configuring access to a DMZ zone based on Kubernetes in one embodiment;

[0039] Figure 4 This is a hardware structure diagram of a DMZ zone dynamic configuration access system based on Kubernetes in another embodiment;

[0040] Figure 5 This is a hardware structure diagram of a DMZ zone dynamic configuration access system based on Kubernetes in another embodiment;

[0041] Figure 6 It is a schematic diagram of the structure of a computer device in an embodiment.

[0042] Among them, 10, deployment module; 20, Kubernetes cluster; 30, CoreDNS component; 40, Ingress controller; 50, computing cluster; 60, authentication module; 70, load balancing module; 80, firewall. DETAILED DESCRIPTION

[0043] In order to make the purpose, technical solutions and advantages of this application more clearly understood, the present application is described and illustrated below in conjunction with the accompanying drawings and examples. It should be understood that the specific embodiments described herein are merely used to explain this application and are not intended to limit this application. Based on the embodiments provided in this application, all other embodiments obtained by those of ordinary skill in the art without making any creative efforts are within the scope of protection of this application.

[0044] Obviously, the drawings described below are merely examples or embodiments of the present application. Those skilled in the art can, without inventive effort, apply the present application to other similar scenarios based on these drawings. Furthermore, it is also understood that, although the effort involved in such a development process may be complex and lengthy, for those skilled in the art related to the content disclosed in this application, changes in design, manufacturing, or production based on the technical content disclosed in this application are merely conventional technical means and should not be construed as an insufficiency of the content disclosed in this application.

[0045] References to "embodiments" in this application mean that a particular feature, structure, or characteristic described in connection with the embodiment may be included in at least one embodiment of the application. The appearance of this phrase in various places in the specification does not necessarily refer to the same embodiment, nor does it refer to independent or alternative embodiments that are mutually exclusive of other embodiments. It is understood, both explicitly and implicitly, by those skilled in the art that the embodiments described in this application may be combined with other embodiments unless there is a conflict.

[0046] Unless otherwise defined, technical or scientific terms used herein shall have the ordinary meaning as understood by persons of ordinary skill in the art to which this application belongs. The terms "a," "an," "an," "the," and similar expressions used herein do not denote quantitative limitations and may refer to either the singular or the plural. The terms "comprise," "include," "have," and any variations thereof, used herein, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or modules (units) is not limited to the listed steps or units but may also include steps or units not listed, or may include other steps or units inherent to the process, method, product, or apparatus. The terms "connected," "connected," "coupled," and similar expressions used herein are not limited to physical or mechanical connections but may include electrical connections, whether direct or indirect. As used herein, "plurality" means two or more. "And / or" describes an association between associated objects, indicating that three possible relationships exist. For example, "A and / or B" may mean: A exists alone; A and B exist simultaneously; or B exists alone. The character " / " generally indicates that the objects before and after are in an "or" relationship. The terms "first", "second", "third", etc. involved in this application are only used to distinguish similar objects and do not represent a specific order for the objects.

[0047] The following is an explanation of the relevant terms that appear in the embodiments of this application:

[0048] Kubernetes: It is an open source container orchestration platform used to automate the deployment, expansion, and management of containerized applications. Currently, Kubernetes has become the de facto standard in the field of container orchestration and is widely used in the development and operation of cloud-native applications.

[0049] Ingress: An API object used to manage external access to services within a cluster. It acts as an entry point for HTTP / HTTPS traffic, provides hostname- or path-based routing rules, and forwards external requests to services or pods within the cluster. It can also forward requests to outside the cluster using ExternalName. Ingress is typically used in conjunction with an Ingress controller.

[0050] The embodiment of the present application provides a DMZ zone dynamic configuration access system based on Kubernetes, such as Figure 1 As shown, it includes a deployment module 10, a Kubernetes cluster 20, a CoreDNS component 30, an Ingress controller 40, and a computing cluster 50. The computing cluster 50 includes multiple computing services. The Kubernetes cluster 20, the CoreDNS component 30, and the Ingress controller 40 are located in the DMZ area.

[0051] The deployment module 10 is used to create Ingress objects and Service objects corresponding to each of the computing services in the Kubernetes cluster 20, wherein the Ingress objects and Service objects are configured with corresponding forwarding rules; and the domain name resolution information of the CoreDNS component 30 is configured; the Kubernetes cluster 20 is used to forward the terminal user's access request to the Ingress controller 40; the Ingress controller 40 is used to match the corresponding forwarding rule based on the access request, determine the internal domain name of the corresponding computing service based on the matched forwarding rule, and send a domain name resolution request to the CoreDNS component 30; the CoreDNS component 30 provides DNS service, which is used to obtain the IP address of the computing service based on the internal domain name resolution information, and send the IP address to the Ingress controller 40; the Ingress controller 40 is used to forward the access request to the IP address.

[0052] This application uses the open source features of Kubernetes in the DMZ area, which can quickly build a system that supports dynamic configuration of access to the DMZ area. Both configuration and management use open source technologies, which reduces the difficulty of gateway service configuration; the deployment module 10 supports dynamic configuration of access rules, realizes the convenience and scalability of the application's external service provision, and shortens the application launch cycle; the Ingress controller 40 only forwards requests for specified rules, and directly rejects requests if no rules are found, which provides effective protection for the security within the data center and improves the security of access to the internal network.

[0053] In one embodiment, the access request includes authentication information, such as Figure 2As shown, the system also includes an authentication module 60, which is configured to receive a verification request from the ingress controller 40, verify the authentication information carried in the access request, and send the verification result to the ingress controller 40. If the verification result passes, the ingress controller 40 is configured to determine the internal domain name of the corresponding computing service based on the matching forwarding rule. The system of this embodiment reduces the workload of developing the application authentication system by integrating into a unified authentication system.

[0054] For further information, please see Figure 2 The system further includes a load balancing module 70 for forwarding the end user's access request to multiple servers in the Kubernetes cluster based on preset distribution rules. The load balancing module 70 in the system distributes network or application traffic across multiple servers to optimize resource usage, maximize throughput, reduce response time, and avoid overloading any single resource.

[0055] For further information, please see Figure 2 The system further includes a firewall 80, which is used to monitor and control network traffic to protect the internal network from unauthorized access and potential network attacks, thereby protecting the network security of the system.

[0056] In the second aspect, the embodiment of the present application further provides a method for dynamically configuring access to the DMZ zone based on Kubernetes, which is applied to the system as described in the first aspect above. Figure 3 As shown, the method includes the following steps:

[0057] Step 201: Use the deployment module to create Ingress objects and Service objects corresponding to each computing service in the Kubernetes cluster, wherein the Ingress objects and Service objects are configured with corresponding forwarding rules; and configure the domain name resolution information of the CoreDNS component.

[0058] First, use the deployment module to deploy the Ingress and Service forwarding rules in the DMZ area. The deployment method specifically includes the following: the user sends a request to deploy the computing service forwarding rules to the deployment module, including configuration information such as whether to provide authentication services, server address, and external access; the deployment module creates the corresponding Ingress object, Service object, and Secret object in the Kubernetes cluster in the DMZ area. The Service object is of ExternalName type, and the Ingress and Service forwarding rules are written in the corresponding Ingress object and Service object. The Secret object stores the user-specified TLS certificate. The deployment module is also used to dynamically configure the domain name resolution information of the CoreDNS component.

[0059] Step 202: Use the Kubernetes cluster to forward the terminal user's access request to the Ingress controller.

[0060] In step 203, the Ingress controller matches the corresponding forwarding rule based on the access request, determines the internal domain name of the corresponding computing service based on the matched forwarding rule, and sends a domain name resolution request to the CoreDNS component.

[0061] In this step, the Ingress controller only forwards requests that match the specified rules. Requests that do not match the specified rules are rejected directly. This effectively protects the security within the data center and improves the security of accessing the internal network.

[0062] Step 204: Utilize the CoreDNS component to obtain the IP address of the computing service based on the internal domain name resolution information, and send the IP address to the Ingress controller.

[0063] Step 205: Utilize the Ingress controller to forward the access request to the IP address.

[0064] This application uses the open source features of Kubernetes in the DMZ area to quickly build a system that supports dynamic configuration of access to the DMZ area. Both configuration and management use open source technologies, which reduces the difficulty of configuring gateway services; supports dynamic configuration of access rules, realizes the convenience and scalability of the application's external services, and shortens the application launch cycle; only forwards requests with specified rules, and directly rejects requests if no rules are found, which provides effective protection for the security within the data center and improves the security of access to the internal network.

[0065] In one embodiment, using the Ingress controller to match a corresponding forwarding rule based on the access request, and determining the internal domain name of the corresponding computing service based on the matched forwarding rule includes the following steps:

[0066] In step 301, the Ingress controller is used to match the corresponding Ingress object based on the access request. That is, after receiving the terminal user request, the Ingress controller searches for the matching Ingress object based on the requested domain name and route.

[0067] Furthermore, the Ingress controller also uses the TLS certificate specified in the Ingress object to perform TLS certificate authentication with the terminal user's client. After the authentication is successful, step 302 is performed.

[0068] In step 302, the Ingress controller is used to match a corresponding Service object according to the Service name specified in the matched Ingress object, and based on the Service object, the internal domain name of the corresponding computing service is determined.

[0069] In one embodiment, the method further includes: if the Ingress controller does not find that the access request matches the Ingress object, the terminal user rejects the access request.

[0070] Specifically, after receiving a request from an end user, the Ingress controller queries the Ingress object based on the requested domain name and route. If no matching Ingress object is found, the connection is rejected. If a match is found, the next step is performed. Specifically, the controller matches the Service name specified in the matching Ingress object to a corresponding Service object. Based on this Service object, the controller then determines the internal domain name of the corresponding Compute service.

[0071] In a specific embodiment, the DMZ zone dynamic configuration access method based on Kubernetes is applied to Figure 4 The dynamic configuration forwarding system based on the Kubernetes container cloud platform, the method includes the following steps:

[0072] Step 1: The end user initiates an https access request to the service domain name;

[0073] Step 2: The domain name is resolved to the public IP address of the firewall in the data center through the public DNS domain name resolution service.

[0074] Step 3: The access request is forwarded to the firewall in the data center.

[0075] Step 4: The firewall forwards the request to the load balancing module;

[0076] In step 5, the load balancing module forwards the access request to the designated port in the DMZ zone according to the distribution rules. The port can be specified in the Service object configured by the Ingress controller in the Kubernetes cluster.

[0077] Step 6: After receiving the access request from the terminal user, the Ingress controller queries the Ingress object based on the requested domain name and route. If no matching Ingress object is found, the connection is rejected. If a match is found, the next step is performed.

[0078] In step 7, the Ingress controller uses the TLS certificate specified in the Ingress object to perform TLS certificate authentication with the end user's client.

[0079] Step 8: The Ingress controller verifies the authentication information carried in the request. If the verification fails, the connection is rejected. If the verification succeeds, the next step is carried out.

[0080] Step 9: The Ingress controller finds the corresponding Service object based on the service name specified in the Ingress object, and finds the internal domain name of the corresponding service based on the ExternalName field in the Service object;

[0081] Step 10: The Ingress controller sends a domain name resolution request to the CoreDNS component to obtain the IP address of the corresponding service.

[0082] Step 11: The Ingress controller forwards the http request, i.e., the access request, to the IP address of the corresponding service.

[0083] Preferably, in step 8, the Ingress controller verifies the authentication information carried in the request, including the following sub-steps:

[0084] In step 8.1, if the matching Ingress object does not indicate that authentication verification is required, the verification is successful by default. If authentication verification is required, proceed to the next step.

[0085] In step 8.2, the Ingress controller initiates an authentication request to the authentication module based on the "nginx.ingress.kubernetes.io / auth-signin" and "nginx.ingress.kubernetes.io / auth-method" fields filled in the Ingress object;

[0086] Step 8.3: The authentication module authenticates the request and returns 200 OK if the authentication is successful, or 401 if the authentication fails.

[0087] In step 8.4, if the Ingress controller receives a 200OK response, the verification is successful and ends. Otherwise, proceed to the next step.

[0088] In step 8.5, the Ingress controller receives a 401 error, indicating verification failure. Based on the "nginx.ingress.kubernetes.io / auth-url" field in the Ingress object, the end user is prompted to jump to the login page.

[0089] In one embodiment, when the computing cluster is a Kubernetes computing cluster, the method further includes: using a deployment module to create a second Ingress object and a second Service object corresponding to each computing service in the Kubernetes computing cluster, wherein the second Ingress object and the second Service object are configured with a corresponding second forwarding rule; after using the Ingress controller to forward the access request to the IP address exposed to the outside of the computing service, using the Kubernetes computing cluster to match the second forwarding rule corresponding to the access request, and forwarding the access request to the corresponding computing service based on the second forwarding rule.

[0090] Specifically, the deployment module creates a computing service in the Kubernetes computing cluster, and creates corresponding Ingress objects and Service objects, and writes the Ingress and Service forwarding rules in the corresponding Ingress objects and Service objects.

[0091] In a specific embodiment, the DMZ zone dynamic configuration access method based on Kubernetes is applied to Figure 5 The dynamic configuration forwarding system based on the Kubernetes container cloud platform, wherein the computing cluster in the system is a Kubernetes computing cluster, the method includes the following steps:

[0092] Step 1: The end user initiates an https access request to the service domain name;

[0093] Step 2: The domain name is resolved to the public IP address of the firewall in the data center through the public DNS domain name resolution service.

[0094] Step 3: The access request is forwarded to the firewall in the data center.

[0095] Step 4: The firewall forwards the request to the load balancing module;

[0096] In step 5, the load balancing module forwards the access request to the designated port in the DMZ zone according to the distribution rules. The port can be specified in the Service object configured by the Ingress controller in the Kubernetes cluster.

[0097] Step 6: After receiving the access request from the terminal user, the Ingress controller queries the Ingress object based on the requested domain name and route. If no matching Ingress object is found, the connection is rejected. If a match is found, the next step is performed.

[0098] In step 7, the Ingress controller uses the TLS certificate specified in the Ingress object to perform TLS certificate authentication with the end user's client.

[0099] Step 8: The Ingress controller verifies the authentication information carried in the request. If the verification fails, the connection is rejected. If the verification succeeds, the next step is carried out.

[0100] Step 9: The Ingress controller finds the corresponding Service object based on the service name specified in the Ingress object, and finds the internal domain name of the corresponding service based on the ExternalName field in the Service object;

[0101] Step 10: The Ingress controller sends a domain name resolution request to the CoreDNS component to obtain the IP address of the corresponding service. The corresponding IP address is found to be the gateway IP of the k8s computing cluster.

[0102] Step 11: The Ingress controller forwards the HTTP request to the gateway of the Kubernetes computing cluster.

[0103] Step 12: After receiving the request, the Ingress controller in the k8s computing cluster queries the Ingress object based on the requested domain name and route. If no matching Ingress object is found, the connection is rejected. If a match is found, the next step is performed.

[0104] In step 13, the Ingress controller in the k8s computing cluster finds the corresponding Service object based on the Service name specified in the Ingress object, and finds the IP address of the final service Pod based on the Service object and its corresponding Endpoint object;

[0105] In step 14, the Ingress controller in the k8s computing cluster forwards the request to the service Pod in the cluster.

[0106] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as follows: Figure 6 As shown. The computer device includes a processor, a memory and a network interface connected via a system bus. The processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program and a database. The internal memory provides an environment for the operation of the operating system and computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external terminal via a network connection. When the computer program is executed by the processor, a DMZ zone dynamic configuration access method based on Kubernetes is implemented.

[0107] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above-mentioned embodiments of the method for dynamically configuring access to a DMZ zone based on Kubernetes are implemented.

[0108] Those skilled in the art will appreciate that all or part of the processes in the above-mentioned embodiment methods can be implemented by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application may include at least one of non-volatile and volatile memory. Non-volatile memory may include read-only memory (ROM), magnetic tape, floppy disk, flash memory or optical memory, etc. Volatile memory may include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM).

[0109] The technical features of the above-mentioned embodiments can be combined arbitrarily. In order to make the description concise, not all possible combinations of the technical features in the above-mentioned embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.

[0110] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present invention. It should be noted that a person skilled in the art could make various modifications and improvements without departing from the spirit of the present application, all of which fall within the scope of protection of the present application. Therefore, the scope of protection of the present patent application shall be determined by the appended claims.

Claims

1. A DMZ zone dynamic configuration access system based on Kubernetes, characterized in that: It includes a deployment module, a Kubernetes cluster, a CoreDNS component, an Ingress controller, and a computing cluster. The computing cluster includes multiple computing services. The Kubernetes cluster, the CoreDNS component, and the Ingress controller are located in the DMZ area. The deployment module is configured to create an Ingress object and a Service object corresponding to each of the computing services in the Kubernetes cluster, wherein the Ingress object and the Service object are configured with corresponding forwarding rules; and configure domain name resolution information of the CoreDNS component; The Kubernetes cluster is used to forward the access request of the terminal user to the Ingress controller; The Ingress controller is configured to match a corresponding forwarding rule based on the access request, determine the internal domain name of the corresponding computing service based on the matched forwarding rule, and send a domain name resolution request to the CoreDNS component; The CoreDNS component is used to obtain the IP address of the computing service based on the internal domain name resolution information and send the IP address to the Ingress controller; the Ingress controller is used to forward the access request to the IP address.

2. The system according to claim 1, wherein: The access request includes authentication information, and the system further includes an authentication module, The authentication module is configured to receive a verification request from the Ingress controller, verify the authentication information carried in the access request, and send the verification result to the Ingress controller; The Ingress controller is configured to determine the internal domain name of the corresponding computing service based on the matched forwarding rule if the verification result passes.

3. The system according to claim 1, wherein: The system further comprises: A load balancing module is used to forward the terminal user's access request to multiple servers in the Kubernetes cluster based on preset distribution rules.

4. The system according to claim 1, wherein: The system further comprises: Firewalls are used to monitor and control network traffic to protect the network security of the system.

5. A DMZ zone dynamic configuration access method based on Kubernetes, applied to the system according to any one of claims 1 to 4, characterized in that: The method comprises: Use the deployment module to create Ingress and Service objects corresponding to each computing service in the Kubernetes cluster, where the Ingress and Service objects are configured with corresponding forwarding rules; and configure the domain name resolution information of the CoreDNS component; Utilize the Kubernetes cluster to forward the end user's access request to the Ingress controller; Using the Ingress controller, based on the access request, it matches the corresponding forwarding rule, determines the internal domain name of the corresponding computing service based on the matched forwarding rule, and sends a domain name resolution request to the CoreDNS component; Using the CoreDNS component, based on the internal domain name resolution information, obtain the IP address of the computing service, and send the IP address to the Ingress controller; The Ingress controller is used to forward the access request to the IP address.

6. The method according to claim 5, characterized in that Using the Ingress controller, based on the access request, matching a corresponding forwarding rule, and determining the internal domain name of the corresponding computing service based on the matched forwarding rule includes: Using the Ingress controller, based on the access request, a corresponding Ingress object is matched; The Ingress controller is used to match a corresponding Service object according to the Service name specified in the Ingress object, and based on the Service object, the internal domain name of the corresponding computing service is determined.

7. The method according to claim 6, characterized in that The method further comprises: If the Ingress controller does not find that the access request matches the Ingress object, the end user rejects the access request.

8. The method according to claim 6, characterized in that When the computing cluster is a Kubernetes computing cluster, the method further includes: Using a deployment module, create a second Ingress object and a second Service object corresponding to each of the computing services in the Kubernetes computing cluster, wherein the second Ingress object and the second Service object are configured with corresponding second forwarding rules; After forwarding the access request to the IP address exposed by the computing service using the Ingress controller, the Kubernetes computing cluster is used to match the second forwarding rule corresponding to the access request, and forward the access request to the corresponding computing service based on the second forwarding rule.

9. A computer device comprising a memory and a processor, wherein the memory stores a computer program, wherein: When the processor executes the computer program, the method according to any one of claims 5 to 8 is implemented.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the method according to any one of claims 5 to 8 is implemented.

Citation Information

Patent Citations

  • Method and device for accessing k8s container environment based on transport layer routing

    CN115242882A

  • Domain name resolution management method, program product, device and medium

    CN119342035A