Non-continuous-flow thermal migration method for virtual machine and virtualization system
By creating a virtual machine identical to the source node on the target node and migrating the vswitch data plane flow table and connection tracking table, the problem of network traffic interruption during virtual machine hot migration is solved, achieving uninterrupted network traffic and improving user experience.
Patent Information
- Application Number
- CN202511117468.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-08-11
- Publication Date
- 2025-11-21
AI Technical Summary
When hot migration occurs after enabling security group functionality on a virtual machine, network traffic between the remote client and server is interrupted, causing connection timeouts. Existing technologies cannot guarantee uninterrupted network traffic.
Create a virtual machine identical to the source node on the target node and set its state to paused. Query and migrate the source node's vswitch data plane flow table and connection tracking table, and update the flow table entries on the target node to ensure network traffic continuity.
This ensures uninterrupted network traffic during virtual machine hot migration, improving user experience and the reliability of virtual network services.
Smart Images

Figure CN120994311A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application belongs to the technical field of cloud computing virtualization system, and particularly relates to a virtual machine live migration method and a virtualization system. BACKGROUND
[0002] In the existing virtualization system, when the virtual machine opens the security group function and the virtual machine is the service end of user service, the remote client and the service end are just transmitting data, at this time, the virtual machine as the service end occurs live migration, because the security group table of the virtual machine, that is, the vswitch data plane flow table and the connection tracking table, cannot be migrated from the source node to the target node, resulting in that the network traffic of the remote client accessing the virtual machine is interrupted, and the connection between the client and the service end is re-established after the connection timeout, and then the connection is connected. SUMMARY
[0003] The present application provides a virtual machine live migration method and a virtualization system, which can ensure the uninterrupted network traffic of the remote client accessing the service end when the virtual machine opens the security group function and occurs live migration as the service end, and improve the user experience of virtual machine service application.
[0004] The present application provides the following technical scheme:
[0005] In a first aspect, a virtual machine live migration method is provided, comprising:
[0006] Creating a virtual machine on the target node which is completely the same as the source node, and adjusting the state of the virtual machine to the pause state;
[0007] In the virtual machine live migration process, the source node security group table associated with the migrated virtual machine is queried, including the vswitch data plane flow table and the connection tracking table of the source node;
[0008] The source node security group table is written into a file and compressed, and then migrated from the source node to the virtual machine of the target node;
[0009] The virtual machine of the target node decompresses the received file and reads it into the memory, and updates the vswitch data plane flow table of the source node according to the port ID of the virtual machine of the target node;
[0010] The connection tracking table of the source node and the updated vswitch data plane flow table of the source node are added to the vswitch data plane of the target node;
[0011] After the virtual machine live migration is completed, the state of the virtual machine of the target node is adjusted to running, and the virtual machine of the source node is closed.
[0012] Optionally, the vswitch data plane flow table of the source node comprises: an Egress flow table and an Ingress flow table.
[0013] Optionally, the source node security group table item associated with the migrated virtual machine comprises:
[0014] The network information of the source node virtual machine is queried, comprising a virtual network, a MAC address of a virtual network card, and a vswitch data plane virtual port ID connected to the virtual machine network card.
[0015] The Egress flow table and the Ingress flow table associated with the migrated virtual machine are found on the source node, if the ingress port field in the vswitch flow table is consistent with the network information of the source node virtual machine, and the MAC address is a unicast address, it is considered that the current flow table is the Egress flow table associated with the migrated virtual machine; if the destination Mac address field in the vswitch flow table is equal to the MAC address of the virtual network card and the virtual network field in the flow table is equal to the virtual network where the virtual network card is located, it is considered that the current flow table is the Ingress flow table associated with the migrated virtual machine.
[0016] The vswitch connection tracking table of the source node is traversed using the virtual machine IP address as a key to find the connection tracking table associated with the migrated virtual machine.
[0017] Optionally, the vswitch connection tracking table of the source node is traversed using the virtual machine IP address as a key to find the connection tracking table associated with the migrated virtual machine, and the method comprises:
[0018] The conntrack tool provided by the linux system or the ovs-appctl tool provided by the vswitch is used to export all the connection tracking tables of the source node vswitch.
[0019] The exported all connection tracking tables are filtered using the grep command provided by the linux system with the virtual machine IP address as a key to filter out the connection tracking table of the virtual machine.
[0020] Optionally, the vswitch data plane flow table of the source node is updated according to the port ID of the target node virtual machine, and the method comprises:
[0021] For the Ingress flow table, the ingress port of the Ingress flow table is modified to the kernel port of the uplink of the access bridge of the migrated virtual machine, and the action field of the Ingress flow table is modified to the kernel port of the migrated virtual machine.
[0022] For the Egress flow table, the ingress port in the Egress flow table is modified to the kernel port number of the virtual network card of the migrated virtual machine, and the action field in the Egress flow table is modified to the kernel port of the uplink of the access bridge of the migrated virtual machine.
[0023] Optionally, before the hot migration of the virtual machine, memory migration of the virtual machine also needs to be performed, specifically:
[0024] The source node and the target node are connected;
[0025] All the memory of the source node virtual machine is marked as dirty pages, and the dirty pages are copied to the target node, new memory dirty pages are generated in the copying process, and the memory dirty pages are iteratively copied to the target node, and when the remaining dirty pages are all migrated within the maximum downtime of the virtual machine, the iteration is stopped.
[0026] The CPU state and register content of the virtual machine are copied from the source node to the target node, and the memory migration is completed.
[0027] In a second aspect, a virtualization system is provided, comprising a virtualization management platform and a virtualization network service; the virtualization network service comprises a virtual port management module, a virtual machine management module, a virtual machine migration module and a security group flow table reconstruction module;
[0028] The virtualization management platform is configured to be responsible for virtual machine life cycle management, including creating a virtual machine identical to the source node on the target node, adjusting the state of the virtual machine to a pause state, and adjusting the state of the virtual machine on the target node to running after the hot migration of the virtual machine is completed, and closing the virtual machine on the source node;
[0029] The virtual port management module is configured to query the vswitch data plane flow table of the source node associated with the migrated virtual machine during the hot migration of the virtual machine;
[0030] The virtual machine management module is configured to save the network information of the virtual machine and query the connection tracking table related to the migrated virtual machine;
[0031] The virtual machine migration module is configured to write the source node security group table item to a file and compress it to migrate to the virtual machine on the target node from the source node; the virtual machine on the target node reads the received file to the memory after decompression;
[0032] The security group flow table reconstruction module is configured to update the vswitch data plane flow table of the source node according to the port ID of the virtual machine on the target node; and add the connection tracking table of the source node and the updated vswitch data plane flow table of the source node to the vswitch data plane of the target node.
[0033] Optionally, the virtual machine management module is further configured to: when a virtual machine is created or a virtual network card is mounted, assigning, by a cloud platform, a virtual network card IP address and a virtual network of the virtual machine, and saving, by the virtual machine management module, the assigned information; and when the virtual machine is destroyed or the virtual network card is unmounted, recycling, by the cloud platform, the virtual network card IP address and the virtual network of the virtual machine, and destroying, by the virtual machine management module, the recycled information of the virtual machine.
[0034] In a third aspect, a computer device is provided, comprising a processor and a memory; wherein the processor implements the steps of the virtual machine live migration method of any one of the first aspect when executing the computer program stored in the memory.
[0035] In a fourth aspect, a computer readable storage medium is provided for storing a computer program; the computer program is executed by a processor to implement the steps of the virtual machine live migration method of any one of the first aspect.
[0036] Compared with the prior art, the present application has the following beneficial effects:
[0037] The present application optimizes and extends the virtual machine live migration process of the virtualization system, and migrates the source node security group table item, including the vswitch data plane flow table and the connection tracking table of the source node, from the source node to the target node, so that the network live migration of the virtual machine with the security group function enabled in the virtualization system is realized, the reliability of the virtual network service flow is ensured, and the user experience of the virtual machine service application is improved. BRIEF DESCRIPTION OF DRAWINGS
[0038] Figure 1 is a flowchart of the virtual machine live migration method of the present application;
[0039] Figure 2 is a structural block diagram of the virtualization system of the present application. DETAILED DESCRIPTION
[0040] The present application will be further described below in conjunction with the drawings. The following examples are only used to more clearly illustrate the technical solutions of the present application, and cannot be used to limit the protection scope of the present application. It should be noted that the terms "comprise" and any variations thereof in the specification and claims of the present application and the above drawings are intended to cover non-exclusive inclusion, for example, a process, method, system, product or device comprising a series of steps or units does not have to be limited to only those steps or units clearly listed, but can include other steps or units not clearly listed or inherent to these processes, methods, products or devices.
[0041] Before describing the embodiments of the present application, some terms appearing later are first explained:
[0042] Vswitch: Virtual switch, responsible for the openflow flow table forwarding of the virtual network in the virtualization platform, realizing the network functions such as flat, vlan and vxlan of the virtualization layer, and in general, the openflow protocol switch adopts the openvswitch technology of open source.
[0043] Security group: Security group, also known as state firewall, is a set of rules for controlling the access traffic of virtual machines, which checks the tuple information and connection state in the data packet, and the security group mentioned in the application realizes this function based on the vswitch data plane flow table and the connection tracking table (conntrack). After the virtual port of the virtual machine is associated with the security group, the rules of the security group will filter the network packets in and out of the virtual machine network card, and only the packets allowed by the rules can pass, that is, the traffic is passed in the form of white list.
[0044] Vswitch data plane flow table, namely openvswitch flow table, its main function is to quickly match and forward the incoming data packet according to the flow table entry. When the data packet enters the vswitch data plane, it will be matched according to the matching field of the flow table entry, and the corresponding processing action will be executed. The vswitch data plane flow table is mainly composed of multiple flow table entries, each flow table entry contains a matching field (match field) and a processing action (action). The matching conditions of the flow table entry usually include the ingress port, source / destination Mac address, VLAN, source / destination IP address, protocol type, port number and other network layer and transport layer information, and the processing action can be forwarding the data packet to the specified port or performing other processing.
[0045] Connection tracking table: English full name is connection tracking, abbreviated as CT, which is represented by conntrack table in the application. The connection tracking table realizes the tracking of the connection state of the data packet. Generally, the contents of the connection tracking table include packet protocol, source / destination IP address, source / destination port, connection state (such as new, est, etc.). The connection state includes but is not limited to the following: new: refers to the new state of the packet, usually refers to the first data packet of the tracked data flow. Est: refers to the established state of the packet, usually refers to the tracking of bidirectional data flow.
[0046] Embodiment 1
[0047] As shown in Figure 1 A continuous flow hot migration method of virtual machine, comprising the following steps:
[0048] Step S1: Create a virtual machine identical to the source node on the target node, and adjust its state to the pause state.
[0049] Copy the XML configuration file of the virtual machine from the source node to the target node, create the same virtual machine on the target host as on the source host, and start the created virtual machine, and set the virtual machine state to the suspended state.
[0050] Step S2: In the virtual machine live migration process, the source node security group table item associated with the migrated virtual machine is queried, including the vswitch data plane flow table and connection tracking table of the source node.
[0051] The vswitch data plane flow table of the source node includes: Egress flow table and Ingress flow table. The vswitch flow table sent from the virtual machine is the Egress flow table, and the vswitch flow table entering the virtual machine is the Ingress flow table.
[0052] Step S2, specifically includes:
[0053] S21: Query the network information of the virtual machine of the source node, including the virtual network (such as VLAN, etc.) of the virtual network card, the MAC address, and the vswitch data plane virtual port ID connected to the virtual machine network card.
[0054] S22: Find the Egress flow table and Ingress flow table associated with the migrated virtual machine on the source node. If the ingress port field in the vswitch flow table is consistent with the network information of the virtual machine of the source node, and the MAC address is a unicast address, it is considered that the current flow table is the Egress flow table associated with the migrated virtual machine. If the destination Mac address field in the vswitch flow table is equal to the MAC address of the virtual network card and the virtual network field in the flow table is equal to the virtual network where the virtual network card is located, it is considered that the current flow table is the Ingress flow table associated with the migrated virtual machine.
[0055] Specifically, query the Egress flow table. If the ingress port field in the vswitch flow table is equal to the kernel mode virtual port of the migrated virtual machine, the source MAC address field is equal to the MAC address of the virtual network card, the virtual network field is equal to the virtual network of the virtual network card, and the destination MAC field is a unicast address, it is considered that it is the Egress flow table associated with the migrated virtual machine, otherwise it is not.
[0056] Query the Ingress flow table. If the destination Mac address field in the vswitch flow table is equal to the mac address of the virtual network card and the virtual network field in the flow table is equal to the virtual network where the virtual network card is located, it is considered that it is the Ingress flow table related to the migrated virtual machine, otherwise it is not.
[0057] S23: traverse the vswitch connection tracking table of the source node using the virtual machine IP address as the key to find the connection tracking table associated with the migrated virtual machine.
[0058] Find the connection tracking table related to the virtual machine on the source node. Specifically, traverse the vswitch connection tracking table of the source node using the virtual machine network card IP address as the key.
[0059] Step S23, specifically:
[0060] S231: use the conntrack tool provided by the linux system or the ovs-appctl tool provided by the vswitch to export all connection tracking tables of the source node vswitch.
[0061] Use the conntrack tool provided by the linux system, such as conntrack-L conntrack, or the ovs-appctl tool provided by the vswitch, such as ovs-appctl conntrack / dump, to obtain the connection tracking table of the source node vswitch and write it to a file.
[0062] S232: use the grep command provided by the linux system to filter out the connection tracking table of the virtual machine using the virtual machine IP address as the key.
[0063] Specifically, if the IP address of the virtual machine is the same as the source IP address in the connection tracking table or the IP address of the virtual machine is the same as the destination IP address in the connection tracking table, it is determined that these connection tracking entries are the connection tracking table associated with the migrated virtual machine.
[0064] Step S3: write the source node security group table entries to a file and migrate the virtual machine from the source node to the target node after compression.
[0065] Specifically, write the virtual machine Ingress flow table and Egress flow table messages queried in step S22 to a file, and package and compress the flow table file, then copy it from the source node to the target node. Write the connection tracking table associated with the migrated virtual machine queried in step S23 to a file and package and compress the virtual machine connection tracking table file, then migrate it from the source node to the target node.
[0066] Step S4: the virtual machine of the target node reads the received file into memory after decompression, and updates the vswitch data plane flow table of the source node according to the port ID of the virtual machine of the target node.
[0067] Step S5: Add the connection tracking table of the source node and the updated vswitch data plane flow table of the source node to the vswitch data plane of the target node.
[0068] The target node decompresses the connection tracking table file of the virtual machine after receiving it, and adds it to the vswitch data plane connection tracking table of the target node, thereby realizing the migration of the connection tracking table of the virtual machine.
[0069] The target node decompresses the vswitch flow table file and reads it into memory. The target node finds the kernel port number of the virtual machine network card according to the mac address of the virtual machine network card, modifies the port number in the Ingress flow table and the Egress flow table, and completes the reconstruction of the security group flow table. Specifically, for the Ingress flow table (the reference object is the virtual machine), the ingress port in the Ingress flow table is modified to the kernel port of the uplink of the access bridge of the migrated virtual machine, and the action field in the flow table is modified to the kernel port of the uplink of the access bridge of the migrated virtual machine; for the Egress flow table (the reference object is the virtual machine), the ingress port in the Egress flow table is modified to the kernel port number of the virtual network card of the migrated virtual machine, and the action field in the flow table is modified to the kernel port of the uplink of the access bridge of the migrated virtual machine. Then the Ingress flow table and the Egress flow table of the virtual machine are issued to the vswitch data plane of the target node, thereby realizing the migration of the vswitch data plane flow table of the virtual machine.
[0070] Step S6: After the hot migration of the virtual machine is completed, the state of the virtual machine on the target node is adjusted to running, and the virtual machine on the source node is closed.
[0071] The source node virtualization libvirt module notifies the target node that the hot migration of the virtual machine is completed, modifies the state of the virtual machine on the target node from pause to running, and closes the virtual machine on the source node, thereby completing the hot migration of the virtual machine.
[0072] In some other embodiments, before the virtual machine is hot migrated, the memory of the virtual machine also needs to be migrated, specifically: establish a connection between the source node and the target node; mark all the memory of the source node virtual machine as dirty pages, copy all the dirty pages to the target node, generate new memory dirty pages in the copying process, iterate the copying of the memory dirty pages to the target node, and stop iteration when all the remaining dirty pages are migrated to the target node within the maximum downtime of the virtual machine; copy the CPU state and register content of the virtual machine from the source node to the target node, and complete the memory migration.
[0073] Embodiment 2
[0074] As Figure 2As shown, a virtualization system is provided, comprising a virtualization management platform and a virtualization network service; the virtualization network service comprises: a virtual port management module, a virtual machine management module, a virtual machine migration module and a security group flow table reconstruction module.
[0075] I. Virtualization management platform
[0076] For responsible for virtual machine life cycle management, such as virtual machine start, shutdown, restart, pause, wake up, clone, backup, snapshot, migration, etc., including creating a virtual machine exactly the same as the source node on the target node, and adjusting its state to the pause state, and after the end of virtual machine live migration, adjusting the virtual machine state of the target node to running, and closing the virtual machine of the source node.
[0077] The virtualization management platform is provided with the following functions:
[0078] Libvirtd service: responsible for unified management of various virtualization platforms. Vswitchd service: responsible for vswitch user state first packet processing, generation and deletion of data plane flow table and other functions. Vswitch data plane: responsible for virtual network transceiver packet processing.
[0079] II. Virtualization network service
[0080] In the virtualization system, a lightweight virtual network service is added, responsible for the migration of security group forwarding table items, i.e. vswitch data plane flow table and connection tracking table during virtual machine live migration. This service includes four functional modules: (virtual port management module, virtual machine management module, virtual machine migration module and security group flow table reconstruction module). The functions of each module are as follows:
[0081] (1) Virtual port management module.
[0082] Used to query the vswitch data plane flow table of the source node associated with the migrated virtual machine during the virtual machine live migration process.
[0083] Abstract a virtual network card of a virtual machine. This module is responsible for maintaining information such as virtual machine network card name, IP address, Mac address, virtual network (such as vlan, etc.), user space port number, kernel space port number, etc., which is used to find the vswitch data plane flow table corresponding to the virtual machine network card during virtual machine migration.
[0084] (2) Virtual machine management module.
[0085] Responsible for maintaining information such as virtual machine name, virtual network card name, virtual network, virtual machine network card IP address, etc., which is used to save the network information of the virtual machine and query the connection tracking table related to the migrated virtual machine.
[0086] When the virtual machine is created or the virtual network card is mounted, the cloud platform allocates the virtual network card IP address and the virtual network of the virtual machine, and the virtual machine management module saves the information.
[0087] When the virtual machine is destroyed or the virtual network card is unmounted, the cloud platform recycles the virtual network card IP address and the virtual network of the virtual machine, and the virtual machine management module destroys the information of the virtual machine.
[0088] (3) Virtual machine migration module.
[0089] The virtual machine is used for writing the source node security group table item into a file and migrating from the source node to the target node after compression; the virtual machine of the target node reads the received file into the memory after decompression; that is, responsible for the packaging, compression and decompression of the virtual machine security group forwarding table item, that is, the vswitch data plane flow table and the connection tracking table, and migrating the security forwarding table item from the source node to the target node.
[0090] Specifically, the source node queries the vswitch data plane flow table and the connection tracking table used by the migrated virtual machine according to the IP address, MAC address, virtual network and other information of the virtual machine, writes into a file and packages and compresses, and copies to the target node. The target node receives the flow table and connection tracking table file of the migrated virtual machine, decompresses and reads into the memory, and updates and issues to the local vswitch data plane through the security group flow table reconstruction module. The query method of the connection tracking table is: traversing the vswitch connection tracking table according to the virtual machine IP address, and querying the matching items in the connection tracking table respectively with the virtual machine IP address as the source IP and the target IP. These matching items are the connection tracking table associated with the virtual machine.
[0091] (4) Security group flow table reconstruction module.
[0092] Used for updating the vswitch data plane flow table of the source node according to the port ID of the virtual machine of the target node; adding the connection tracking table of the source node and the updated vswitch data plane flow table of the source node to the vswitch data plane of the target node.
[0093] Because the virtual machine is migrated from the source node to the target node, the user mode port and the kernel mode port of the virtual machine will change, and the old virtual port in the migrated virtual machine flow table will be modified to the newly generated virtual port of the target node, and then issued to the local vswitch data plane.
[0094] Embodiment 3
[0095] The application provides a computer device, comprising a processor and a memory; wherein the processor implements the steps of the above-mentioned virtual machine continuous live migration method when executing the computer program saved in the memory.
[0096] More specific processes of the above method can refer to the corresponding content disclosed in the foregoing embodiments, which will not be repeated here.
[0097] Embodiment 4
[0098] The application provides a computer readable storage medium for storing a computer program; the computer program is executed by a processor to implement the steps of the continuous flow live migration method of the virtual machine.
[0099] More specific processes of the above method can refer to the corresponding content disclosed in the foregoing embodiments, which will not be repeated here.
[0100] The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts of each embodiment can be referred to each other. For the system, device and storage medium disclosed by the embodiments, since it corresponds to the method disclosed by the embodiments, the description is relatively simple, and the related parts can be referred to the method part.
[0101] Those skilled in the art can clearly understand that the technology in the embodiments of the present application can be realized by means of software and necessary general hardware platforms. Based on such understanding, the technical solutions in the embodiments of the present application can be embodied in the form of software products, which can be stored in storage media such as ROM / RAM, magnetic disks, optical disks, etc., and include a number of instructions to make a computer device (which can be a personal computer, a server, or a network device, etc.) execute the methods described in the various embodiments or some parts of the embodiments.
[0102] The above is only the preferred embodiment of the present application, and the protection scope of the present application is not limited to the above-mentioned embodiments. Any technical solution falling within the concept of the present application shall fall within the protection scope of the present application. It should be noted that, for ordinary skilled in the art, some improvements and refinements without departing from the principles of the present application shall be considered as the protection scope of the present application.
Claims
1. A method for live hot migration of virtual machines without interruption, characterized in that, include: Create a virtual machine on the target node that is exactly the same as the source node, and set its state to paused. During the live migration of a virtual machine, query the source node security group table entries associated with the migrated virtual machine, including the source node's vswitch data plane flow table and connection tracking table; The virtual machine that migrates from the source node to the target node after writing the security group entries of the source node to a file and compressing them; The virtual machine on the target node decompresses the received file, reads it into memory, and updates the source node's vswitch data plane flow table according to the target node's virtual machine's port ID. Add the connection tracking table of the source node and the updated vswitch data plane flow table of the source node to the vswitch data plane of the target node; After the virtual machine hot migration is complete, the virtual machine status on the target node is adjusted to running, and the virtual machine on the source node is shut down.
2. The virtual machine non-current hot migration method according to claim 1, characterized in that, The source node's vswitch data plane flow table includes: the Egress flow table and the Ingress flow table.
3. The virtual machine non-current hot migration method according to claim 2, characterized in that, The query for the source node security group table entries associated with the migrated virtual machine specifically includes: Query the network information of the source node virtual machine, including the virtual network of the virtual network card, MAC address, and virtual port ID of the vswitch data plane connected to the virtual machine network card; On the source node, search for the Egress and Ingress flow tables associated with the migrated virtual machine. If the ingress port field in the vswitch flow table matches the network information of the virtual machine on the source node, and the MAC address is a unicast address, then the current flow table is considered to be the Egress flow table associated with the migrated virtual machine. If the destination MAC address field in the vswitch flow table is equal to the MAC address of the virtual network card, and the virtual network field in the flow table is equal to the virtual network where the virtual network card is located, then the current flow table is considered to be the Ingress flow table associated with the migrated virtual machine. The virtual machine's IP address is used as the key to traverse the source node's vswitch connection tracking table to find the connection tracking table associated with the migrated virtual machine.
4. The virtual machine non-current hot migration method according to claim 1, characterized in that, The process of using the virtual machine's IP address as the key to traverse the source node's vswitch connection tracking table and find the connection tracking table associated with the migrated virtual machine is as follows: Use the conntrack tool provided by the Linux system or the ovs-appctl tool provided by vswitch to export all connection tracking tables of the source node vswitch; For all exported connection tracking tables, use the grep command provided by the Linux system to filter out the connection tracking tables of the virtual machines using the virtual machine IP address as the keyword.
5. The virtual machine non-current hot migration method according to claim 2, characterized in that, The step of updating the source node's vswitch data plane flow table based on the target node's virtual machine port ID is as follows: For the Ingress flow table, modify the ingress port of the Ingress flow table to the kernel port of the uplink of the access bridge of the migrated virtual machine, and at the same time modify the action field of the Ingress flow table to the kernel port of the migrated virtual machine. For the Egress flow table, modify the ingress port in the Egress flow table to the kernel port number of the virtual network interface card of the migrated virtual machine, and at the same time modify the action field in the Egress flow table to the kernel port of the uplink of the access bridge of the migrated virtual machine.
6. The virtual machine hot migration method without interruption of power supply according to claim 1, characterized in that, Before performing a live migration of a virtual machine, a memory migration of the virtual machine is also required, specifically: Establish a connection between the source node and the target node; Mark all memory of the source node virtual machine as dirty pages, copy all dirty pages to the target node, and generate new dirty pages during the copying process. Iterate through the copying of dirty pages to the target node. Stop the iteration when all remaining dirty pages have been migrated within the maximum downtime of the virtual machine. The CPU state and register contents of the virtual machine are copied from the source node to the target node to complete the memory migration.
7. A virtualization system, characterized in that, It includes a virtualization management platform and virtualization network services; the virtualization network services include: a virtual port management module, a virtual machine management module, a virtual machine migration module, and a security group flow table reconstruction module; The virtualization management platform is responsible for virtual machine lifecycle management, including creating a virtual machine on the target node that is exactly the same as the source node and adjusting its status to a paused state, and after the virtual machine hot migration is completed, adjusting the virtual machine status of the target node to running and shutting down the virtual machine on the source node. The virtual port management module is used to query the vswitch data plane flow table of the source node associated with the migrated virtual machine during the virtual machine hot migration process. The virtual machine management module is used to store network information of virtual machines and query the connection tracking table related to virtual machine migration; The virtual machine migration module is used to write the security group table entries of the source node to a file, compress them, and migrate them from the source node to the virtual machine of the target node; the virtual machine on the target node decompresses the received file and reads it into memory; The security group flow table reconstruction module is used to update the source node's vswitch data plane flow table based on the port ID of the target node's virtual machine; and to add the source node's connection tracking table and the updated source node's vswitch data plane flow table to the target node's vswitch data plane.
8. The virtualization system according to claim 1, characterized in that, The virtual machine management module is also used to allocate a virtual network card IP address and a virtual network to a virtual machine when the virtual machine is created or a virtual network card is mounted. The virtual machine management module saves the allocated information. When the virtual machine is destroyed or the virtual network card is unmounted, the cloud platform reclaims the virtual network card IP address and virtual network of the virtual machine, and the virtual machine management module destroys the reclamation information of the virtual machine.
9. A computer device, characterized in that, It includes a processor and a memory; wherein, when the processor executes a computer program stored in the memory, it implements the steps of the virtual machine continuous hot migration method according to any one of claims 1-6.
10. A computer-readable storage medium, characterized in that, Used to store computer programs; when the computer programs are executed by a processor, they implement the steps of the virtual machine continuous hot migration method according to any one of claims 1-6.