Communication method and device for computing node, equipment and storage medium
By creating multiple virtual network interfaces in the virtual switch and combining them with physical network cards and flow control queues, the problem of insufficient physical network card resources is solved, efficient reuse and normal communication of multiple virtualized networks are achieved, and network performance is improved.
Patent Information
- Application Number
- CN202510884753.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-27
- Publication Date
- 2025-09-05
AI Technical Summary
The physical network card resources on the physical server are insufficient, and multiple types of virtualized networks cannot be independently deployed, resulting in difficulties in network reuse and degraded network performance.
Create multiple virtual network interfaces in the virtual switch, each corresponding to a business network, and send data packets to other nodes through the physical network card. Combined with the flow control queue and flow table, bandwidth control is performed to achieve network multiplexing.
It has realized the deployment of multiple business networks in the virtual switch, ensuring the normal communication of each business network, reducing network latency and avoiding congestion, and improving network performance.
Smart Images

Figure CN120602440A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of computer network technology, and in particular to a communication method, apparatus, device and storage medium for computing nodes. Background Art
[0002] In cloud computing, the types and functions of networks hosted on physical servers (i.e., host machines or compute nodes) are extremely complex to meet requirements such as virtualization, resource isolation, performance optimization, and high availability. Common network types on physical servers include management networks, storage networks, data networks, migration networks, backup networks, mirror networks, security networks, service networks, overlay networks, and dedicated networks.
[0003] The aforementioned multiple networks must be deployed on the same physical server, and each network deployment requires redundancy (i.e., aggregation). Due to the limited number of PCIe slots provided by physical servers, the number of physical network cards on the server is limited, making it impossible to independently deploy multiple types of networks. Summary of the Invention
[0004] In view of this, the present application provides a communication method, apparatus, device and storage medium for a computing node to solve the problem that the physical network card resources of the computing node are insufficient and multiple virtualized networks cannot be provided.
[0005] In the first aspect, the present application provides a communication method for a computing node, which is applied to a computing node, the computing node includes a virtual switch and a physical network card, multiple virtual network interfaces are created in the virtual switch, the multiple virtual network interfaces correspond one-to-one to multiple business networks, and the physical network card is connected to at least one other node. The method includes: receiving a target data packet of a target business network through a target virtual network interface of the virtual switch, the target business network is one of multiple business networks, and the target virtual network interface is a virtual network interface corresponding to the target business network; sending the target data packet to a corresponding node in at least one other node through the physical network card.
[0006] The communication method for computing nodes of the present application is to create multiple virtual network interfaces in the virtual switch and one virtual network interface corresponds to one business network, so that multiple business networks can be deployed in the virtual switch, thereby realizing network multiplexing in the virtual switch, thereby solving the problem that the physical network card resources of the computing node are insufficient and cannot provide multiple virtualized networks. Then, the target virtual network interface of the virtual switch can be used to receive the target data message on the target business network, and the target data message on the target business network can be sent to the corresponding node in one or more other nodes connected to the physical network card through the physical network card. This solution cleverly realizes the forwarding of the target data message on the target business network to the corresponding node in at least one other node through the virtual switch and the physical network card, ensuring that each business network can perform business communications normally without the need for a long link forwarding path, and ensuring that the network performance of multiple business networks multiplexed on the virtual switch is good.
[0007] In an optional implementation, the service network is configured according to the following process: configuring a corresponding virtual network interface using network configuration information of the service network to obtain the service network.
[0008] By configuring the network configuration information of the corresponding business network on the virtual network interface, the business network can be deployed on the virtual switch more cleverly and efficiently, further realizing network multiplexing on the virtual switch.
[0009] In an optional implementation, the network configuration information includes virtual local area network information, network address information, and routing address information.
[0010] By configuring the virtual network interface using the virtual LAN information, network address information, and routing address information, the corresponding business network can be deployed on the virtual switch more quickly and efficiently.
[0011] In an optional embodiment, the physical network card is configured with a flow control queue corresponding to each business network, and the virtual switch is configured with a flow table, which includes a correspondence between data packets and flow control queues; sending the target data packet to a corresponding node in at least one other node through the physical network card includes: using the flow table to determine the target flow control queue corresponding to the target data packet; adding the target data packet to the target flow control queue, so as to send the target data packet in the target flow control queue to the corresponding node in at least one other node through the physical network card.
[0012] Since a flow table is configured on the virtual switch, after the target data packet passes through the virtual switch, the target flow control queue corresponding to the target data packet can be determined based on the flow table, and then the target data packet can be sent to the corresponding node in at least one other node through the target flow control queue on the physical network, thereby better realizing bandwidth control of each network through the target flow control queue, reducing network latency, and avoiding network congestion and packet loss.
[0013] In an optional embodiment, the flow control queues corresponding to each business network are configured according to the following process: creating an initial control queue for each business network; obtaining flow control parameters corresponding to each business network; and configuring the corresponding initial control queue for each business network using the flow control parameters of the business network to obtain the flow control queue corresponding to the business network.
[0014] By creating an initial control queue for each business network and then configuring the initial control queue using the flow control parameters of each business network, it is possible to design a corresponding flow control queue for each business network. Furthermore, precise bandwidth control can be achieved through the flow control queue.
[0015] In an optional implementation manner, the traffic control parameter includes at least one of a minimum guaranteed bandwidth, a maximum preempted bandwidth, a burst traffic buffer, a committed burst volume, and a scheduling weight value.
[0016] Flow control parameters are key for regulating data traffic, optimizing network performance, and ensuring Quality of Service (QoS). Configuring at least one of the following flow control parameters in the initial control queue, including minimum guaranteed bandwidth, maximum preempted bandwidth, burst buffer, committed burst size, and scheduling weight, ensures bandwidth for each service network and efficient utilization of physical bandwidth.
[0017] In an optional implementation, an initial control queue is created for each business network, including: obtaining an inclusion relationship between multiple networks, the multiple networks including multiple business networks, and when the computing node includes a virtual machine, the multiple networks also include a virtual machine network; creating a root queue for the physical network card; and using the inclusion relationship to create multiple initial control queues subordinate to the root queue.
[0018] The inclusion relationship between multiple networks can be a logical hierarchical relationship between multiple networks. By using the logical hierarchical relationship between multiple networks to create corresponding initial control queues, the logical hierarchical relationship between the initial control queues can be determined more accurately. After the flow control parameters are configured for each initial control queue to obtain the corresponding flow control queue, the bandwidth of each network can be better controlled, thereby further avoiding network congestion and reducing network latency.
[0019] In the second aspect, the present application provides a communication device for a computing node, which is applied to a computing node. The computing node includes a virtual switch and a physical network card. Multiple virtual network interfaces are created in the virtual switch. The multiple virtual network interfaces correspond one-to-one to multiple business networks. The physical network card is connected to at least one other node. The device includes: a receiving module, which is used to receive a target data packet of a target business network through a target virtual network interface of the virtual switch. The target business network is one of multiple business networks, and the target virtual network interface is a virtual network interface corresponding to the target business network; a sending module, which is used to send the target data packet to a corresponding node in at least one other node through the physical network card.
[0020] In a third aspect, the present application provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, computer instructions being stored in the memory, and the processor executing the communication method for computing nodes of the above-mentioned first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0021] In a fourth aspect, the present application provides a computer-readable storage medium having computer instructions stored thereon, the computer instructions being used to enable a computer to execute the communication method for computing nodes of the above-mentioned first aspect or any corresponding embodiment thereof. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] In order to more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the specific embodiments or the description of the prior art. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.
[0023] Figure 1 It is a multi-layer bridge model provided for Neutron in OpenStack;
[0024] Figure 2 is a schematic diagram of multiplexing a service network on a computing node according to an embodiment of the present application;
[0025] Figure 3 1 is a flow chart of a communication method for computing nodes provided in accordance with an embodiment of the present application;
[0026] Figure 4 is a flow chart of another communication method for computing nodes provided in accordance with an embodiment of the present application;
[0027] Figure 5is a schematic diagram of allocating minimum guaranteed bandwidth to each network according to an embodiment of the present application;
[0028] Figure 6 is a structural diagram of a communication device for a computing node according to an embodiment of the present application;
[0029] Figure 7 It is a schematic diagram of the hardware structure of the computer device of an embodiment of the present application. DETAILED DESCRIPTION
[0030] To make the purpose, technical solutions, and advantages of the embodiments of the present invention more clear, the technical solutions in the embodiments of the present invention will be clearly and completely described below in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of the present invention.
[0031] First, the terms involved in one or more embodiments of the present application are explained.
[0032] OVS (Open Virtual Switch): Open Virtual Switch;
[0033] QoS (Quality of Service): Quality of service;
[0034] TC (Traffic Controller): Traffic control in the Linux kernel;
[0035] HTB (Hierarchical Token Bucket): Hierarchical token bucket;
[0036] VM (Virtual Machine): virtual machine;
[0037] vCenter (VMware vCenter Server): the core management platform for VMware virtualization solutions;
[0038] CVM (Cloud Virtual Machine): cloud virtual machine;
[0039] VXLAN (Virtual eXtensible Local Area Network): Virtual eXtensible Local Area Network;
[0040] GRE (Generic Routing Encapsulation): Generic Routing Encapsulation Protocol;
[0041] PCIE (Peripheral Component Interconnect Express): High-speed serial computer expansion bus standard.
[0042] In conjunction with the application scenarios on which the execution of the communication method for computing nodes depends, the application scenarios are described herein.
[0043] In cloud computing, the types and functions of networks hosted on physical servers (i.e., host machines or compute nodes) are extremely complex to meet requirements such as virtualization, resource isolation, performance optimization, and high availability. Common networks on physical servers include, but are not limited to, management networks, storage networks, data networks, migration networks, backup networks, mirror networks, security networks, service networks, overlay networks, and dedicated networks. Among them, the management network is used to manage computing nodes and communicate with cloud management platforms (such as OpenStack, VMware, vCenter, and CVM); the storage network is used to access shared storage resources (such as block storage, file storage, and object storage); the data network is used to carry the business traffic of virtual machines or containers, enabling communication between virtual machines and between virtual machines and external networks; the migration network is used for virtual machine migration (Live Migration) to achieve high availability (HA); the backup network is used to carry the backup traffic of virtual machines to achieve virtual machine data recovery after an exception occurs; the mirror network is used to transmit mirror messages and send important messages to specific network elements for traffic auditing and cleaning; the security network is used for security-related communications and can be used for intrusion detection systems (IDS) and firewall log transmission; the service network is used for services provided by the cloud management platform (such as databases and message queues) to implement third-party service requests and responses; the overlay network is used to use tunneling technologies (such as VXLAN, GRE, and Geneve) to implement cross-physical machine communication networks; and the dedicated network is used to carry some special traffic, such as VMware FT, or to provide virtual machine diversion services for specific scenarios.
[0044] These multiple networks must be implemented on the same physical server, and each network deployment requires redundancy (i.e., aggregation). Due to the limited number of PCIe slots available on physical servers, the number of physical network cards on a server is limited, making it impossible to independently deploy multiple types of networks, such as all types of networks. Therefore, multiplexing multiple networks on a physical server (i.e., carrying multiple network traffic on a single physical network card) is essential.
[0045] like Figure 1The figure shows the multi-layer bridge model provided by Neutron in OpenStack, which can reuse some compute node networks in certain scenarios. Specifically, after virtual machines (such as VM1 and VM2) are created on a compute node, the virtual network cards (such as A and Q) of the virtual machines are connected to the tap devices (such as B and R) of the Linux bridge (such as the security bridges qbr-XXX and qbr-YYY). The tap devices (such as C and S) of the Linux bridge are connected to the tap devices (such as D and T) of br-int. The patch-tun of br-int (such as E) is connected to the patch-int of br-tun (such as F). br-tun is connected to the physical network card (eth) through tunnel encapsulation (such as G), thus enabling communication between the virtual machines and other compute nodes. qbr-XXX and qbr-YYY are security bridges, br-int is an integrated bridge, and br-tun is a tunnel bridge. In this way, OpenStack only implements the combination of virtual machine-related networks on a physical network card. For example, the security network deployed on the security bridges qbr-XXX and qbr-YYY, the overlay network deployed on br-tun, and the data network deployed on br-int. However, it does not support the reuse of common virtualized computing node networks such as management networks, storage networks, and migration networks. This greatly limits the use scenarios of this multi-bridge model.
[0046] In addition, Neutron allows administrators to set rules such as bandwidth limits and priorities for virtual machine network traffic. For example, QoS policies and QoS rules (such as bandwidth rate limiting policies) can be created and defined using the Neutron API. Neutron then distributes the QoS rules to compute nodes. Neutron agents on the compute nodes (such as the Open vSwitch Agent or Linux BridgeAgent) receive the QoS rules and configure the virtual switch or Linux TC. Virtual machine traffic reaches the virtual switch, which controls the traffic based on the QoS rules. This shows that OpenStack's QoS rules can only control virtual machine traffic. They cannot limit the traffic of physical network cards, nor do they support bandwidth allocation, and cannot guarantee bandwidth for traffic on individual networks. Furthermore, OpenStack uses a multi-layer network with long forwarding paths, which can degrade network performance.
[0047] In view of this, the present application proposes a communication method, apparatus, device, and storage medium for a computing node. The method is applied to a computing node, wherein the computing node includes a virtual switch and a physical network card, wherein multiple virtual network interfaces are created in the virtual switch, and the multiple virtual network interfaces correspond one-to-one to multiple business networks, and the physical network card is connected to at least one other node. The method comprises: receiving a target data packet of a target business network through a target virtual network interface of the virtual switch, wherein the target business network is one of the multiple business networks, and the target virtual network interface is a virtual network interface corresponding to the target business network; and sending the target data packet to a corresponding node in at least one other node through the physical network card.
[0048] The communication method for computing nodes of the present application is to create multiple virtual network interfaces in the virtual switch and one virtual network interface corresponds to one business network, so that multiple business networks can be deployed in the virtual switch, thereby realizing network multiplexing in the virtual switch, thereby solving the problem that the physical network card resources of the computing node are insufficient and cannot provide multiple virtualized networks. Then, the target virtual network interface of the virtual switch can be used to receive the target data message on the target business network, and the target data message on the target business network can be sent to the corresponding node in one or more other nodes connected to the physical network card through the physical network card. This solution cleverly realizes the forwarding of the target data message on the target business network to the corresponding node in at least one other node through the virtual switch and the physical network card, ensuring that each business network can perform business communications normally without the need for a long link forwarding path, and ensuring that the network performance of multiple business networks multiplexed on the virtual switch is good.
[0049] In order to facilitate understanding of the communication method for computing nodes of this application, the computing nodes are first introduced below. Figure 2 As shown in the figure, it is a schematic diagram of multiplexing multiple business networks on the virtual switch of the computing node. After creating virtual machines (such as VM1 and VM2) on the computing node, the virtual machines are connected to the virtual switch vswitch. For example, the virtual network card A of the virtual machine VM1 is connected to the TAP device B of the virtual switch, and the virtual network card C of the virtual machine VM2 is connected to the TAP device D of the virtual switch. In this way, communication between virtual machines is realized inside the virtual switch, and a data network between virtual machines is realized on the virtual switch. Then, by creating multiple virtual network interfaces in the virtual switch, multiple business networks (such as Figure 2 The virtual switch communicates with the physical network card (eth) through the flow table control (such as E), thereby enabling each business network to communicate with other nodes through the physical network card. It should be understood that Figure 2N1, N2, and N3 represent service networks reused on virtual switches, typically carrying network traffic from physical servers (referred to as hosts in virtualization scenarios). Compute nodes can be physical servers, also referred to as compute nodes in cloud computing.
[0050] According to an embodiment of the present application, an embodiment of a communication method for computing nodes is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0051] In this embodiment, a communication method for a computing node is provided, which can be used in the above-mentioned computing node. The computing node includes a virtual switch and a physical network card. Multiple virtual network interfaces are created in the virtual switch. The multiple virtual network interfaces correspond one-to-one to multiple business networks. The physical network card is connected to at least one other node. Figure 3 is a flow chart of a communication method for computing nodes according to an embodiment of the present application, such as Figure 3 As shown, the process includes the following steps:
[0052] Step S301: receiving a target data packet of a target business network through a target virtual network interface of a virtual switch, where the target business network is one of a plurality of business networks, and the target virtual network interface is a virtual network interface corresponding to the target business network.
[0053] A virtual switch is a network switching device that simulates a physical switch through software. It is used to connect virtual machines, physical servers, and other network devices in a virtualized environment to achieve data packet forwarding and network communication.
[0054] A virtual network interface can be an interface that can be created in a virtual switch and configured with related network information. For example, the virtual network interface can be an OVS internal interface. An internal interface is a virtual network interface created within OVS that can transmit and process data packets through collaboration between user space and the kernel, and supports a variety of network functions and configurations such as VLAN, VXLAN, and GRE. Specifically, tunnel protocols can be applied to internal interfaces through OVS configuration to implement complex network topologies. As a specific example, the OVS internal interface, i.e., virtual network interface N1, can be created using the command ovs-vsctl add-port vswitch N1 --set interface N1type=internal.
[0055] It should be understood that this application does not limit the number of virtual network interfaces. Specifically, according to business needs, a corresponding number of virtual network interfaces can be created in the virtual switch, thereby deploying the same number of business networks as the number of virtual network interfaces in the virtual switch.
[0056] A business network is a logical network unit built to carry a specific type of business traffic. For example, a business network can be the aforementioned management network, storage network, migration network, backup network, mirror network, security network, service network, overlay network, and dedicated network, etc. In other words, the present application multiplexes the data network between virtual machines on a virtual switch, thereby realizing the deployment of multiple types of business networks such as management network, storage network, backup network, etc. on a virtual switch. For example, Figure 2 As shown, the management network is deployed in the virtual switch through the virtual network interface N1, the storage network is deployed in the virtual switch through the virtual machine network interface N2, and the backup network is deployed in the virtual switch through the virtual network interface N3. Specifically, according to actual business needs, virtual network interfaces can be repeatedly created and configured on the virtual switch to deploy the corresponding business network.
[0057] Since each business network is deployed on a virtual switch, data packets on each business network can enter the virtual switch through its corresponding virtual network interface, and then be forwarded to the physical network card according to relevant forwarding rules on the virtual switch, such as the flow table.
[0058] Step S302: Send the target data message to a corresponding node in at least one other node through the physical network card.
[0059] like Figure 2As shown, the physical network card communicates with the virtual switch vswitch, which in turn communicates with the physical switch. Multiple nodes can be connected to the physical switch, meaning that the compute node can communicate with other nodes through the physical switch. Thus, target data packets on the virtual switch can be sent to a corresponding node in at least one other node via the physical network card and the physical switch. For example, the other nodes that communicate with the compute node via the physical switch are nodes F1, F2, and F3, and the destination address of a data packet on the management network is node F1. Thus, the data packet can be sent to node F1 via the physical network card and the physical switch. Similarly, data packets from other nodes are forwarded through the physical network card into the virtual switch, where they are then forwarded to the corresponding service network according to relevant forwarding rules. For example, a data packet from node F2 is forwarded through the physical switch to the physical network card of the compute node, then enters the virtual switch, and is then forwarded from the virtual switch to the corresponding service network, such as the management network, according to relevant forwarding rules.
[0060] The communication method for computing nodes of the present application is to create multiple virtual network interfaces in the virtual switch and one virtual network interface corresponds to one business network, so that multiple business networks can be deployed in the virtual switch, thereby realizing network multiplexing in the virtual switch, thereby solving the problem that the physical network card resources of the computing node are insufficient and cannot provide multiple virtualized networks. Then, the target virtual network interface of the virtual switch can be used to receive the target data message on the target business network, and the target data message on the target business network can be sent to the corresponding node in one or more other nodes connected to the physical network card through the physical network card. This solution cleverly realizes the forwarding of the target data message on the target business network to the corresponding node in at least one other node through the virtual switch and the physical network card, ensuring that each business network can perform business communications normally without the need for a long link forwarding path, and ensuring that the network performance of multiple business networks multiplexed on the virtual switch is good.
[0061] As an optional implementation manner, the service network is configured according to the following process: the corresponding virtual network interface is configured using the network configuration information of the service network to obtain the service network.
[0062] Network configuration information defines the network parameters associated with a service network. The number of service networks corresponds to the number of network configuration information. For example, using the management network as an example, the network configuration parameters of the management network are used to configure virtual network interface N1, thereby deploying the management network on the virtual switch.
[0063] As a specific example, you can use the OVS internal interface to first create virtual network devices such as management devices, storage devices, and migration devices on the virtual switch. Then, you can configure the corresponding network configuration information on the virtual network devices to deploy the corresponding service networks on the virtual network devices. Finally, you can deploy the service networks on the virtual switch. For example, you can use the OVS internal interface to first create a management device on the virtual switch, then configure the management device using the network configuration information corresponding to the management network to deploy the management network on the virtual switch.
[0064] By configuring the network configuration information of the corresponding business network on the virtual network interface, the business network can be deployed on the virtual switch more cleverly and efficiently, further realizing network multiplexing on the virtual switch.
[0065] As an optional implementation, the network configuration information includes virtual local area network information, network address information and routing address information.
[0066] VLAN information is used to assign a virtual network interface (e.g., N1) to a specific VLAN (e.g., VLAN 100). Only traffic with the same VLAN ID (e.g., 100) can communicate through this virtual network interface. Network address information can be an Internet Protocol (IP) address, a numerical label used to uniquely identify devices on the internet. Routing address information is a key identifier used to determine the transmission path of data packets in network communications.
[0067] Network configuration information may also include, but is not limited to, firewall information. Firewall information is used to define which traffic is allowed to pass through the virtual network interface and which traffic is not allowed to pass through the virtual network interface. It should be understood that virtual local area network information and firewall information can be flexibly selected based on networking requirements.
[0068] By configuring the virtual network interface using the virtual LAN information, network address information, and routing address information, the corresponding business network can be deployed on the virtual switch more quickly and efficiently.
[0069] As a specific example, taking the deployment of a management network on a virtual switch through virtual network interface N1 as an example, VLAN isolation (such as VLAN 100) can be configured on the N1 interface through commands such as ovs-vsctl set port N1 tag=100; the IP address of the management network can be configured on the N1 interface through commands such as ip addr add 172.16.51.111 / 24dev N1 or ifconfig N1172.16.51.111netmask 255.255.255.0; the routing address of the management network can be configured on the N1 interface through commands such as ip route add dev N1 172.20.0.0 / 24via 172.16.51.1; of course, if there are security requirements, iptables -I INPUT -p tcp-s172.20.51.0 / 24 --dport 22-j can also be used. Run commands such as DROP to prevent devices on the 172.20.51.0 / 24 network segment from accessing the management network corresponding to the N1 interface.
[0070] In this embodiment, a communication method for a computing node is provided, which can be used in the above-mentioned computing node. The computing node includes a virtual switch and a physical network card. Multiple virtual network interfaces are created in the virtual switch. The multiple virtual network interfaces correspond one-to-one to multiple business networks. The physical network card is connected to at least one other node. Figure 4 is a flow chart of a communication method for computing nodes according to an embodiment of the present application, such as Figure 4 As shown, the process includes the following steps:
[0071] Step S401: Receive a target data packet of a target service network through a target virtual network interface of a virtual switch. The target service network is one of multiple service networks, and the target virtual network interface is a virtual network interface corresponding to the target service network. Figure 3 Step S301 of the illustrated embodiment will not be described in detail here.
[0072] Step S402: Send the target data message to a corresponding node in at least one other node through the physical network card.
[0073] Because physical NICs have limited bandwidth resources and serve as the gateway to all networks within a compute node, bandwidth control can be implemented for each service network on the physical NIC. For example, you can configure flow control queues for each service network on the physical NIC. Furthermore, if a compute node has multiple physical NICs, you can configure flow control queues for each service network on each physical NIC.
[0074] After configuring flow control queues for each service network on the physical network card, if data packets from different service networks can enter the corresponding flow control queues to implement corresponding bandwidth control, this can be achieved by configuring a flow table including the correspondence between data packets and flow control queues on the virtual switch.
[0075] Specifically, the above step S402 includes:
[0076] Step S4021: Using the flow table, determine the target flow control queue corresponding to the target data packet.
[0077] The flow table uses a predefined set of rules to determine how data packets are processed, thereby implementing network traffic scheduling. Specifically, a flow table can be a rule table that maps service networks to flow control queues. This allows the virtual switch to determine which flow control queue on the physical network interface card to assign target data packets from the service network.
[0078] Table 1 Correspondence between service networks and target sequence numbers of flow control queues
[0079]
[0080] In actual applications, the flow control queue can be uniquely identified by the serial number. However, since the flow control queue is created and configured on the physical network card, and the communication protocols of the physical network card and the virtual switch are different, the serial number of the same flow control queue on the physical network card and the serial number on the virtual switch are represented differently. For example, the physical network card uses decimal, while the virtual switch uses hexadecimal conversion. Therefore, if a flow table is configured for each business network in the virtual switch, the serial number of the flow control queue needs to be converted into a base. As a specific example, the flow table is configured in the virtual switch through the following process: obtain the serial number of the flow control queue corresponding to each business network; convert the serial number of each flow control queue into a base to obtain the target serial number of each flow control queue; use the target serial number of each flow control queue and its corresponding business network to create the flow table shown in Table 1.
[0081] For example, the target data packet of the management network (N1 network) needs to enter the flow control queue 1:200. At this time, 1:200 needs to be converted to 1:512. Since the TC queue starts at 0, the target sequence number of the flow control queue 1:200 is 1:511 according to 512-1=511. That is, the target data packet of the management network needs to enter the flow control queue with the target sequence number 1:511. Similarly, the target data packet of the storage network (N2 network) can enter the flow control queue with the target sequence number 1:512, and the target data packet of the migration network (N3 network) needs to enter the flow control queue with the target sequence number 1:513.
[0082] This solution uses flow tables to allocate data packets from each service network to the corresponding flow control queue on the physical network card, thereby performing corresponding bandwidth control. For data packets from other nodes entering each service network, flow control can be performed on the physical network card, or it can be omitted, and this application does not limit this.
[0083] Step S4022: Add the target data message to the target flow control queue, so as to send the target data message in the target flow control queue to a corresponding node in at least one other node through the physical network card.
[0084] After determining the target flow control queue corresponding to the target data packet, the target data packet can be sent to the target flow control queue by specifying the target sequence number and using set_queue in the OVS code. For example, run the ovs-ofctl add-flow vswitch "cookie = 1000, in_port = N1 actions = set_queue: 511, normal command to configure a flow table for the service network corresponding to virtual network interface N1; run the ovs-ofctl add-flow vswitch "cookie = 1000, in_port = N2 actions = set_queue: 512, normal command to configure a flow table for the service network corresponding to virtual network interface N2; run the ovs-ofctl add-flow vswitch "cookie = 1000, in_port = N3 actions = set_queue: 513, normal command to configure a flow table for the service network corresponding to virtual network interface N3; and run the ovs-ofctl add-flow vswitch "cookie = 1000, in_port = vnetx actions = set_queue: 63, normal command to configure a flow table for a virtual machine network. vnetx is the name of the VM's TAP device. In a scenario with multiple VMs, use the above command to set a flow table for the corresponding vnet device. It should be understood that it's also possible to consider the VM network's service model and implement a multi-level flow table based on the service flow table to queue data packets for each VM.
[0085] Since a flow table is configured on the virtual switch, after the target data packet passes through the virtual switch, the target flow control queue corresponding to the target data packet can be determined based on the flow table, and then the target data packet can be sent to the corresponding node in at least one other node through the target flow control queue on the physical network, thereby better realizing bandwidth control of each network through the target flow control queue, reducing network latency, and avoiding network congestion and packet loss.
[0086] The communication method for computing nodes of the present application is to create multiple virtual network interfaces in the virtual switch and one virtual network interface corresponds to one business network, so that multiple business networks can be deployed in the virtual switch, thereby realizing network multiplexing in the virtual switch, thereby solving the problem that the physical network card resources of the computing node are insufficient and cannot provide multiple virtualized networks. Then, the target virtual network interface of the virtual switch can be used to receive the target data message on the target business network, and the target data message on the target business network can be sent to the corresponding node in one or more other nodes connected to the physical network card through the physical network card. This solution cleverly realizes the forwarding of the target data message on the target business network to the corresponding node in at least one other node through the virtual switch and the physical network card, ensuring that each business network can perform business communications normally without the need for a long link forwarding path, and ensuring that the network performance of multiple business networks multiplexed on the virtual switch is good.
[0087] As an optional implementation, the flow control queues corresponding to each business network are configured according to the following process: creating an initial control queue for each business network; obtaining the flow control parameters corresponding to each business network; for each business network, using the flow control parameters of the business network, configuring the corresponding initial control queue to obtain the flow control queue corresponding to the business network.
[0088] Traffic Control (TC) is a tool and framework provided by the Linux kernel for traffic rate limiting, shaping, and policy control. TC uses a hierarchical structure and flow control algorithms based on queueing disciplines (Qdiscs), classifiers (classes), and filters to achieve refined network traffic management. Queuing disciplines (Qdiscs) buffer packets in queues, controlling the speed of network transmission and reception, and determining packet delivery order, delay, and drop policies. Classifiers classify traffic into different classes, each of which can be subject to different Qdiscs or policies. Filters assign packets to specific classes or Qdiscs based on packet attributes such as IP address, port number, and protocol. Qdiscs also support multiple algorithms, and Hierarchical Token Bucket (HTB) supports hierarchical flow control, allowing multiple classes to share bandwidth. As a specific example, you can create a TC queue and configure it with flow control parameters specific to each service network, thereby configuring a flow control queue for each service network on the physical network interface card.
[0089] Flow control parameters are key parameters used to regulate data traffic, optimize network performance, and ensure Quality of Service (QoS). As an optional implementation, the flow control parameters include at least one of the following: minimum guaranteed bandwidth, maximum preempted bandwidth, burst buffer, committed burst size, and scheduling weight.
[0090] like Figure 5 As shown, for Figure 2 The diagram shows how to allocate minimum guaranteed bandwidth to each network (such as virtual machine network, host network, management network, storage network, and migration network). The total bandwidth of the physical network card is 10G, the minimum guaranteed bandwidth of the virtual machine network is 3G, and the maximum preempted bandwidth is 10G (in the example Figure 5 In [3G, 10G], the minimum guaranteed bandwidth of the host network is 7G and the maximum preempted bandwidth is 10G. Figure 2 VM1 and VM2) share a virtual machine network, and multiple business networks (such as Figure 2 As shown, the management network (corresponding to virtual network interface N1), the storage network (corresponding to virtual network interface N2), and the migration network (corresponding to virtual network interface N3) share the host network. The management network has a minimum guaranteed bandwidth of 1G and a maximum preempted bandwidth of 10G. The storage network has a minimum guaranteed bandwidth of 4G and a maximum preempted bandwidth of 10G. The migration network has a minimum guaranteed bandwidth of 2G and a maximum preempted bandwidth of 10G.
[0091] After obtaining the flow control parameters corresponding to each service network, the flow control parameters corresponding to each service can be used to configure the created initial control queue. As a specific example, according to Figure 5To demonstrate the inclusion relationship between multiple networks, first, run the tc qdisc add dev ethx root handle1:htb default 11 command to create a root queue for the physical network adapter. Then, run the tc class add dev ethx parent 1:1classid1:1htb rate 10000Mbit ceil 10000Mbit burst 125Kb cburst1375b quantum 2000 command to configure flow control parameters for the root queue. This will determine the flow control queues corresponding to the physical network adapter's total network.After that, you can run the tc class add dev ethx parent 1:1classid1:100htb rate 3000Mbit ceil 10000Mbit burst 125Kb cburst 1375b quantum 2000 command to create a flow control queue for the virtual machine network and configure the flow control parameters for the virtual machine network. To obtain the flow control queue corresponding to the virtual machine network, run the tcclass add dev ethx parent 1:1classid1:fffe htb rate 7000Mbit ceil 10000Mbitburst 125Kb cburst 1375b quantum 2000 command to create a flow control queue for the host network and configure the flow control parameters for the host network. To obtain the flow control queue corresponding to the host network, run the tc class adddev ethx parent 1:fffe classid1:200htb rate 1000Mbit ceil 10000Mbit burst125Kb cburst 1375b Run commands such as "quantum 2000" to create a flow control queue for the management network corresponding to virtual network interface N1 and configure flow control parameters for the management network, obtaining the flow control queue for the management network. Run commands such as "tcclass add dev ethx parent 1:fffe classid 1:201htb rate 4000Mbit ceil 10000Mbit burst 125Kb cburst 1375b quantum 2000" to create a flow control queue for the storage network corresponding to virtual network interface N2 and configure flow control parameters for the storage network, obtaining the flow control queue for the storage network. Run commands such as "tc class add dev ethx parent 1:fffe classid 1:202htb rate 2000Mbitceil 10000Mbit burst 125Kb cburst 1375b quantum 2000" to create a flow control queue for the migration network corresponding to virtual network interface N3 and configure flow control parameters for the migration network, obtaining the flow control queue for the migration network. Among them, rate is used to indicate the minimum guaranteed bandwidth, ceil is used to indicate the maximum preempted bandwidth, burst is used to indicate the burst traffic buffer, cburst is used to indicate the committed burst volume, and quantum is used to indicate the scheduling weight.
[0092] By creating an initial control queue for each business network and then configuring the initial control queue using the flow control parameters of each business network, it is possible to design a corresponding flow control queue for each business network. Furthermore, precise bandwidth control can be achieved through the flow control queue.
[0093] As an optional implementation, an initial control queue is created for each business network, including: obtaining an inclusion relationship between multiple networks, the multiple networks including multiple business networks, and when the computing node includes a virtual machine, the multiple networks also include a virtual machine network; creating a root queue for the physical network card; and using the inclusion relationship to create multiple initial control queues belonging to the root queue.
[0094] Because the virtual machine network and the host network share the total bandwidth of the physical network card, it is necessary to create initial control queues for the virtual machine network, the host network, and the multiple business networks that carry the host network. Then, the initial control queues are configured according to the flow control parameters of each network to obtain the corresponding flow control queues for each network.
[0095] In order to accurately create the initial control queues for each network, it is necessary to know the inclusion relationship between the virtual machine network, the host network, and the multiple business networks that carry the host network. Then, based on the inclusion relationship between multiple networks, multiple initial control queues belonging to the root queue are created based on the root queue corresponding to the physical network card. For example, Figure 5 As shown, the physical NIC itself corresponds to a main network, so a root queue needs to be created for the physical network. Secondly, the networks on the physical NIC include the host network and the virtual machine network. Based on this, an initial control queue 1:fffe for the host network and an initial control queue 1:100 for the virtual machine network can be created based on the root queue corresponding to the physical NIC. Since the host network includes the management network, storage network, and migration network, based on the inclusion relationship between the host and management network, and the storage network and migration network, an initial control queue 1:200 for the management network, an initial control queue 1:201 for the storage network, and an initial control queue 1:202 for the migration network can be created.
[0096] The inclusion relationship between multiple networks can be a logical hierarchical relationship between multiple networks. By using the logical hierarchical relationship between multiple networks to create corresponding initial control queues, the logical hierarchical relationship between the initial control queues can be determined more accurately. Subsequently, after configuring flow control parameters for each initial control queue to obtain the corresponding flow control queue, the bandwidth of each network can be better controlled to further avoid network congestion.
[0097] As a specific embodiment of the present application, Figure 2 As shown in the figure, first create virtual machines (such as VM1 and VM2) and a virtual switch on the computing node. Then, connect the virtual machines to the virtual switch and deploy the data network on the virtual switch to enable communication between virtual machines (such as VM1) and virtual machines (such as VM2). Then, create multiple virtual machines (such as VM1 and VM2) on the virtual switch according to business needs. Figure 2 The three virtual network interfaces shown in the figure are configured with network configuration information to reuse the data network on the virtual switch, thereby deploying the management network, storage network, migration network, and so on. Next, initial control queues corresponding to each network (including each business network, virtual machine network, host network, etc.) are created on the physical network card, and corresponding flow control parameters are configured for each flow control queue to implement rate limit management for each network. To ensure that data packets entering each data network of the virtual switch can be correctly allocated to the corresponding flow control queue, a flow table is configured on the virtual switch. Finally, each business network communicates with other nodes through the virtual switch and physical network card.
[0098] In this embodiment, a communication device for a computing node is also provided, which is used to implement the above-mentioned embodiments and preferred embodiments. Details already described are not repeated here. As used below, the term "module" may refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.
[0099] This embodiment provides a communication device for a computing node, which is applied to a computing node. The computing node includes a virtual switch and a physical network card. Multiple virtual network interfaces are created in the virtual switch. The multiple virtual network interfaces correspond to multiple service networks one by one. The physical network card is connected to at least one other node. Figure 6 As shown, the device includes:
[0100] A receiving module 610 is configured to receive a target data packet of a target service network through a target virtual network interface of the virtual switch, where the target service network is one of the multiple service networks, and the target virtual network interface is a virtual network interface corresponding to the target service network;
[0101] The sending module 620 is configured to send the target data message to a corresponding node in at least one other node through the physical network card.
[0102] In some optional implementations, the service network is configured according to the following process: configuring a corresponding virtual network interface using network configuration information of the service network to obtain the service network.
[0103] In some optional implementations, the network configuration information includes virtual local area network information, network address information, and routing address information.
[0104] In some optional embodiments, the physical network card is configured with a flow control queue corresponding to each business network, and the virtual switch is configured with a flow table, which includes a correspondence between data packets and flow control queues; the sending module 620 is also used to use the flow table to determine the target flow control queue corresponding to the target data packet; add the target data packet to the target flow control queue, so as to send the target data packet in the target flow control queue to the corresponding node in at least one other node through the physical network card.
[0105] In some optional implementations, the flow control queues corresponding to each business network are configured according to the following process: creating an initial control queue for each business network; obtaining flow control parameters corresponding to each business network; and configuring the corresponding initial control queue for each business network using the flow control parameters of the business network to obtain the flow control queue corresponding to the business network.
[0106] In some optional implementations, the traffic control parameter includes at least one of a minimum guaranteed bandwidth, a maximum preempted bandwidth, a burst traffic buffer, a committed burst volume, and a scheduling weight value.
[0107] In some optional embodiments, the sending module 620 is also used to obtain the inclusion relationship between multiple networks, where the multiple networks include multiple business networks. When the computing node includes a virtual machine, the multiple networks also include a virtual machine network; create a root queue for the physical network card; and use the inclusion relationship to create multiple initial control queues belonging to the root queue.
[0108] The communication device for computing nodes of the present application has multiple virtual network interfaces created in the virtual switch, and one virtual network interface corresponds to one business network. In this way, multiple business networks are deployed in the virtual switch, thereby realizing network multiplexing in the virtual switch, thereby solving the problem that the physical network card resources of the computing node are insufficient and cannot provide multiple virtualized networks. Then, the target virtual network interface of the virtual switch can be used to receive the target data message on the target business network, and the target data message on the target business network can be sent to the corresponding node in one or more other nodes connected to the physical network card through the physical network card. This solution cleverly realizes the forwarding of the target data message on the target business network to the corresponding node in at least one other node through the virtual switch and the physical network card, ensuring that each business network can perform business communications normally without the need for a long link forwarding path, and ensuring that the network performance of multiple business networks multiplexed on the virtual switch is good.
[0109] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0110] The communication device for computing nodes in this embodiment is presented in the form of functional units, where the units refer to ASIC (Application Specific Integrated Circuit) circuits, processors and memories that execute one or more software or fixed programs, and / or other devices that can provide the above functions.
[0111] The present application also provides a computer device having the above Figure 6 The communication device for computing nodes shown in FIG. Figure 7 , Figure 7 This is a schematic diagram of the structure of a computer device provided by an optional embodiment of the present application. Figure 7 As shown, the computer device includes: one or more processors 710, memory 720, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in the memory or on the memory to display the graphical information of a GUI on an external input / output device (such as, a display device coupled to an interface). In some optional embodiments, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides the necessary operations of a part (for example, as a server array, a group of blade servers, or a multi-processor system). Figure 7 A processor 710 is taken as an example.
[0112] Processor 710 may be a central processing unit (CPU), a network processor (NPU), or a combination thereof. Processor 710 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit (ASIC), a programmable logic device (PLD), or a combination thereof. The programmable logic device may be a complex programmable logic device (CPLD), a field programmable gate array (FPGA), a general purpose array logic (GAL), or any combination thereof.
[0113] The memory 720 stores instructions that can be executed by at least one processor 710, so that the at least one processor 710 executes the method shown in the above embodiment.
[0114] The memory 720 may include a program storage area and a data storage area, wherein the program storage area may store an operating system and application programs required for at least one function; the data storage area may store data created based on the use of the computer device, etc. In addition, the memory 720 may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some optional embodiments, the memory 720 may optionally include a memory remotely located relative to the processor 710, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0115] The memory 720 may include a volatile memory, such as a random access memory; the memory may also include a non-volatile memory, such as a flash memory, a hard disk or a solid-state drive; the memory 720 may also include a combination of the above types of memory.
[0116] The computer device also includes an input device 730 and an output device 740. The processor 710, the memory 720, the input device 730 and the output device 740 can be connected via a bus or other means. Figure 7 The bus connection is taken as an example.
[0117] The input device 730 can receive input digital or character information and generate key signal input related to user settings and function control of the computer device, such as a touch screen, a keypad, a mouse, a trackpad, a touch pad, an indicator stick, one or more mouse buttons, a trackball, a joystick, etc. The output device 40 may include a display device, an auxiliary lighting device (e.g., an LED), and a tactile feedback device (e.g., a vibration motor). The above-mentioned display device includes but is not limited to a liquid crystal display, a light emitting diode, a display, and a plasma display. In some optional embodiments, the display device can be a touch screen.
[0118] The embodiments of the present application also provide a computer-readable storage medium. The above-mentioned method according to the embodiment of the present application can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and downloaded through a network and will be stored in a local storage medium, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc.; further, the storage medium can also include a combination of the above-mentioned types of memory. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code. When the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.
[0119] Part of the present application may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present application through the operation of the computer. Those skilled in the art should understand that the form in which the computer program instruction exists in a computer-readable medium includes but is not limited to a source file, an executable file, an installation package file, etc. Accordingly, the way in which the computer program instruction is executed by the computer includes but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium that can be accessed by the computer.
[0120] Although the embodiments of the present application have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present application, and such modifications and variations shall fall within the scope defined by the appended claims.
Claims
1. A communication method for computing nodes, characterized in that Applied to a computing node, the computing node includes a virtual switch and a physical network card, the virtual switch has multiple virtual network interfaces created therein, the multiple virtual network interfaces correspond one-to-one to multiple service networks, and the physical network card is connected to at least one other node, the method comprising: receiving a target data packet of a target business network through a target virtual network interface of the virtual switch, wherein the target business network is one of the multiple business networks, and the target virtual network interface is the virtual network interface corresponding to the target business network; The target data packet is sent to a corresponding node in the at least one other node through the physical network card.
2. The method according to claim 1, characterized in that The business network is configured according to the following process: The corresponding virtual network interface is configured using the network configuration information of the service network to obtain the service network.
3. The method according to claim 2, characterized in that The network configuration information includes virtual local area network information, network address information and routing address information.
4. The method according to claim 1, wherein The physical network card is configured with a flow control queue corresponding to each of the service networks, and the virtual switch is configured with a flow table, wherein the flow table includes a correspondence between data packets and flow control queues; Sending the target data packet to a corresponding node in the at least one other node through the physical network card includes: Determine, by using the flow table, a target flow control queue corresponding to the target data packet; The target data packet is added to the target flow control queue, so as to send the target data packet in the target flow control queue to a corresponding node in the at least one other node through the physical network card.
5. The method according to claim 4, characterized in that The flow control queues corresponding to each of the service networks are configured according to the following process: Creating an initial control queue for each of the business networks; Obtaining flow control parameters corresponding to each of the service networks; For each of the service networks, the corresponding initial control queue is configured using the flow control parameters of the service network to obtain the flow control queue corresponding to the service network.
6. The method according to claim 5, characterized in that The flow control parameters include at least one of a minimum guaranteed bandwidth, a maximum preempted bandwidth, a burst traffic buffer, a committed burst volume, and a scheduling weight value.
7. The method according to claim 5, characterized in that Create an initial control queue for each of the business networks, including: Acquire an inclusion relationship between a plurality of networks, where the plurality of networks include a plurality of the service networks, and when the computing node includes a virtual machine, the plurality of networks also include a virtual machine network; Creating a root queue for the physical network card; By utilizing the inclusion relationship, a plurality of the initial control queues subordinate to the root queue are created.
8. A communication device for a computing node, characterized in that Applied to a computing node, the computing node includes a virtual switch and a physical network card, the virtual switch has multiple virtual network interfaces created, the multiple virtual network interfaces correspond one-to-one to multiple service networks, and the physical network card is connected to at least one other node, the device includes: A receiving module, configured to receive a target data packet of a target business network through a target virtual network interface of the virtual switch, wherein the target business network is one of the multiple business networks, and the target virtual network interface is the virtual network interface corresponding to the target business network; A sending module is used to send the target data message to a corresponding node in the at least one other node through the physical network card.
9. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the communication method for a computing node according to any one of claims 1 to 7 by executing the computer instructions.
10. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the communication method for computing nodes according to any one of claims 1 to 7.
Citation Information
Cited By
Network isolation method and device based on cloud native hyper-convergence platform
CN121585498A
A virtual network port data receiving method, electronic device and storage medium
CN122578559A