Service governance method and business node
By deploying a first governance device and an external second governance device in the business nodes, and selecting the appropriate governance device according to the service governance strategy, the problems of resource contention and access latency are solved, and efficient service governance and timely access are achieved.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- HUAWEI TECH CO LTD
- Filing Date
- 2024-12-30
- Publication Date
- 2026-06-30
AI Technical Summary
Existing service governance methods suffer from severe resource contention at business nodes, impacting performance. Meanwhile, independent governance devices increase access latency, making it difficult to balance resource utilization and timely access.
The first governance device is deployed in the business node, and the second governance device is set up externally. The appropriate governance device is selected to perform service governance according to the service governance strategy. The service governance method can be flexibly selected by utilizing the computing resources of the business node or external resources.
This effectively avoids resource competition between service governance and business operations, ensures the performance of business nodes, and improves the timeliness and efficiency of access.
Smart Images

Figure CN122317151A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer science, and more particularly to a service governance method and business node. Background Technology
[0002] With the development of network technology, computer technology, and cloud computing technology, the types and quantities of services are increasing. To manage and control these services, the industry has proposed the concept of service governance. Through service governance, enterprises and other users can improve the reusability and scalability of services, thereby facilitating business innovation and development.
[0003] In one related technology, the service governance device is deployed within the business nodes, leading to competition for resources between service governance and business operations. Since business node resources are limited, complex service governance consumes significant resources, impacting business node performance. In another related technology, the service governance device operates independently of the business nodes. While this avoids resource competition between service governance and business operations, it requires sending access requests generated by business nodes to the service governance device, increasing access latency. Summary of the Invention
[0004] This application provides a service governance method and business node, which allows for flexible selection of service governance methods to reduce the impact of service governance on node performance and improve access timeliness.
[0005] Firstly, a service governance method is provided, which can be applied to business nodes in a system. The system also includes a first governance device and a second governance device, wherein the first governance device is deployed within the business node, and the second governance device is independent of the business node. The first governance device can utilize the computing resources of the business node to perform service governance, and the second governance device can utilize computing resources other than those of the business node to perform service governance.
[0006] In this method, a user can input a service governance policy for a first application, and the service node can receive this input. The service governance policy can be used to select one of a first governance device and a second governance device to perform service governance related to the first application. Service governance related to the first application may include service governance required for access requests to the first application.
[0007] In this method, the business node deploys a second application, which can issue a service governance request. The business node can obtain this service governance request. This service governance request is used to perform service governance on the relevant application. Specifically, the business node can identify the relevant application targeted by the service governance request. If the relevant application targeted by the service governance request is the first application, then the business node can perform service governance on the service governance request based on the service governance policy of the first application.
[0008] Specifically, if the service governance strategy of the first application selects the first governance device to perform service governance related to the first application, then the business node performs service governance on the access request to be governed through the first governance device. If the service governance strategy of the first application selects the second governance device to perform service governance related to the first application, then the business node sends the access request to be governed to the second governance device so that the access request to be governed can be service governed through the second governance device.
[0009] In this method, users can configure the application's service governance policy and select the governance device to perform service governance related to that application. This allows for the selection of a service governance method that matches the services provided by the application, effectively avoiding resource competition between service governance and business operations, reducing the impact of service governance on node performance, and improving access timeliness.
[0010] In one possible implementation, the service governance strategy can select a governance device based on the resource requirements of service governance related to a first application. A first threshold can be set to identify the magnitude of the resource requirements for service governance. The service governance strategy includes: if the resource requirements for service governance related to the first application are greater than or equal to the first threshold, selecting a second governance device to perform service governance related to the first application; if the resource requirements for service governance related to the first application are less than the first threshold, selecting a first governance device to perform service governance related to the first application. Here, the resource requirements for service governance refer to the amount of computing resources needed to perform the service governance; in other words, the resource requirements for service governance refer to the size of the computing resources required to perform the service governance.
[0011] Thus, when the resource requirements for service governance of a pending access request are large, the second governance device is selected to perform service governance, avoiding the impact of service governance on the performance of business nodes and ensuring business performance. When the resource requirements for service governance of a pending access request are small, service governance is performed through the first governance device of the business node, improving the execution efficiency of service governance and ensuring the timeliness of access.
[0012] In one possible implementation, the service governance strategy can select a governance device based on the allowable access latency of the first application. A second threshold can be set to identify the magnitude of the allowable access latency for the application. A larger allowable access latency indicates that a greater latency is permissible, with lower latency requirements. A smaller allowable access latency indicates that a greater latency is not permissible, with higher latency requirements. The service governance strategy includes: if the allowable access latency of the first application is greater than or equal to the second threshold, selecting a second governance device to perform service governance related to the first application; if the allowable access latency of the first application is less than the second threshold, selecting a first governance device to perform service governance related to the first application.
[0013] Thus, when the application requested by the access request has a low latency requirement, a second governance device can be selected to perform service governance, saving resources on business nodes. When the application requested by the access request has a high latency requirement, a first governance device can be selected to perform service governance, improving the efficiency of service governance and ensuring timely access.
[0014] In one possible implementation, the first governance device can be deployed in the kernel of the business node.
[0015] In this way, the first governance device is located in the kernel mode of the business node, which is highly efficient and can efficiently handle access requests issued by applications in the business node, thereby improving the efficiency of service governance.
[0016] In one possible implementation, the encoding languages of the first application and the second application can be different.
[0017] This method does not require the application making the access request to use the same encoding language as the application to which the access request is targeted, and thus has broad applicability.
[0018] Secondly, a business node is provided, which is equipped with a first governance device. The system in which the business node resides also includes a second governance device independent of the business node. The first governance device is used to perform service governance using the computing resources of the business node, and the second governance device is used to perform service governance using computing resources other than those of the business node. The service governance device includes: a receiving module, used to receive a service governance policy for a first application input by a user, the service governance policy being used to select one of the first and second governance devices to perform service governance related to the first application; wherein the service governance related to the first application includes service governance required for access requests to the first application; an obtaining module, used to obtain access requests to be governed issued by a second application in the business node; wherein the access requests to be governed are used for service governance of the first application; and a governance module, used to perform service governance on the access requests to be governed through the first governance device based on the service governance policy, or to send the access requests to be governed to the second governance device so that the second governance device can perform service governance on the access requests to be governed.
[0019] In one possible implementation, the service governance strategy includes: if the resource requirement for service governance related to the first application is greater than or equal to a first threshold, selecting a second governance device to perform service governance related to the first application; if the resource requirement for service governance related to the first application is less than the first threshold, selecting a first governance device to perform service governance related to the first application.
[0020] In one possible implementation, the service governance strategy includes: if the allowed access latency of the first application is greater than or equal to a second threshold, selecting a second governance device to perform service governance related to the first application; if the allowed access latency of the first application is less than the second threshold, selecting a first governance device to perform service governance related to the first application.
[0021] In one possible implementation, the first governance device is deployed in the kernel of the business node.
[0022] In one possible implementation, the encoding languages of the first application and the second application are different.
[0023] Thirdly, a computing device cluster is provided, including at least one computing device, each computing device including a processor and a memory; the processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster performs the method provided in the first aspect.
[0024] Fourthly, a computer-readable storage medium is provided, including computer program instructions that, when executed by a cluster of computing devices, execute the method provided in the first aspect.
[0025] Fifthly, a computer program product containing instructions is provided, which, when executed by a cluster of computer devices, causes the cluster of computer devices to perform the method provided in the first aspect.
[0026] The beneficial effects of the second to fifth aspects can be referred to the introduction of the beneficial effects of the first aspect above, and will not be repeated here. Attached Figure Description
[0027] Figure 1 This is a schematic diagram of a system architecture provided in an embodiment of this application;
[0028] Figure 2 This is a schematic diagram of a system architecture provided in an embodiment of this application;
[0029] Figure 3 This is a schematic diagram of a treatment device provided in an embodiment of this application;
[0030] Figure 4 This is a schematic diagram of a treatment device provided in an embodiment of this application;
[0031] Figure 5 This is a flowchart of a service governance method provided in an embodiment of this application;
[0032] Figure 6 This application provides a schematic diagram of the structure of a service node.
[0033] Figure 7 This is a schematic diagram of the structure of a computing device provided in an embodiment of this application;
[0034] Figure 8 This is a schematic diagram of the structure of a computing device cluster provided in an embodiment of this application;
[0035] Figure 9 This is a schematic diagram of the structure of a computing device cluster provided in an embodiment of this application. Detailed Implementation
[0036] The solutions provided in the embodiments of this application will now be described with reference to the accompanying drawings. In the embodiments of this application, "multiple" refers to two or more objects, and "various types" refers to two or more types. Terms such as "first," "second," etc., are only used to distinguish similar objects and are not necessarily used to describe a specific order or number of objects.
[0037] To facilitate understanding of the solutions provided in the embodiments of this application, the technical terms that may be involved in the embodiments of this application will be introduced first.
[0038] Service governance, in microservice architectures or enterprise service-oriented architectures, involves the comprehensive and systematic management, monitoring, and control of services to ensure they meet business needs and compliance requirements, and to improve their availability, scalability, maintainability, and security. The goals of service governance include improving service quality, increasing service efficiency, reducing service costs, and ensuring service security and stability. Through service governance, enterprises and other users can better manage and control services, improve service reusability and scalability, thereby accelerating business innovation and development. In microservice architectures, service governance, also known as SOA governance, is a collective term for the means used to ensure that each microservice instance in the microservice architecture can function properly and that different microservice instances can communicate normally. Microservice instances can also be called service instances or business container instances.
[0039] Cluster: also known as a node cluster, which can consist of multiple business nodes. Nodes can be added or deleted from the cluster.
[0040] Node: Also known as a business node, it is a device, equipment, or platform with resources that can run applications and manage governance functions. A node can be a virtual computing device, such as a virtual machine (VM) or an elastic cloud server (ECS). A node can also be a physical computing device, such as a computer or a bare metal server. Applications within a node can perform related business functions, such as providing or accessing services.
[0041] Computing resources, often simply referred to as resources, refer to the hardware, software, and data that support program execution and enable related functions. For example, computing resources can include processor resources, storage resources, and network resources. Processor resources can be central processing units (CPUs), graphics processing units (GPUs), etc. Storage resources can be memory, video memory, hard disks, etc. Network resources can be network interface controllers (NICs), bandwidth, etc. Furthermore, CPUs, GPUs, memory, hard disks, and NICs can be physical hardware or virtualized versions of physical hardware.
[0042] Microservice architecture, also known as a microservice system (MS), is a service-oriented architecture (SOA) that divides a complex system into multiple small services or applications. Each microservice is responsible for implementing independent business logic. Microservices are built around business functions and can be deployed independently. Microservices depend on each other to provide a range of functionalities. Microservices are easy to understand and modify, offering flexibility in language and framework selection. Microservices can run in containers. Multiple containers containing highly dependent microservices can form a container group. In Kubernetes (K8S) systems, container groups can be encapsulated as pods.
[0043] Layer 7 (L7): Also known as the application layer, it refers to the seventh layer in the Open Systems Interconnection (OSI) network model. Service governance at Layer 7 is high-level service governance, including protocol conversion and rate limiting.
[0044] Layer 4 (L4): Also known as the transport layer, it is the fourth layer in the OSI network model. Layer 4 service governance is low-level service governance, including traffic forwarding and load balancing.
[0045] Service governance is a crucial means of ensuring the normal operation of services. One approach utilizes pod-level or node-level sidecars to perform service governance. However, some service governance operations are complex (e.g., protocol conversion, rate limiting) and have high resource requirements. Pod-level or node-level sidecars incur significant resource overhead on business nodes, potentially impacting their performance. Another approach involves a data broker, independent of the business nodes, performing service governance. While this saves resources on business nodes, sending service access requests to the data broker increases latency, affecting service timeliness. This approach is unsuitable for services with high latency requirements.
[0046] This application provides a service governance method. In this method, two governance devices can be configured: one deployed within a business node, and the other independent of the business node. Users can configure a service governance strategy. This strategy selects one of the two governance devices to perform service governance for access requests. Therefore, the service governance method can be flexibly selected based on service requirements. For example, when the resource requirements for service governance in service access requests are high, a governance device independent of the business node can be selected to perform service governance, thus avoiding impact on the business performance of the business node. As another example, when the latency requirements for service access requests are high, a governance device within a business node can be selected to perform service governance, thereby ensuring service timeliness.
[0047] Next, the service governance method provided in the embodiments of this application will be described.
[0048] Figure 1 A system 100 for implementing this method is shown. System 100 includes at least one service node, such as service node 110, service node 120, etc. These at least one service node can form a cluster. Exemplarily, different service nodes in system 100 can have different architectures. A governance device A1 is deployed in some or all of the at least one service node. Figure 1 As shown, system 100 may further include a governance device A2 independent of the at least one service node. Both governance device A1 and governance device A2 can be used to perform service governance. Governance device A1 is used to perform service governance using the computing resources of the service node where governance device A1 is located, while governance device A2 is used to perform service governance using computing resources other than those of the service node. Furthermore, governance device A1 may be referred to as a first governance device, and governance device A2 may be referred to as a second governance device.
[0049] like Figure 1 As shown, some or all of the business nodes in system 100 are deployed with at least one application. For example, business node 110 is deployed with application 111, and business node 120 is deployed with applications 121, 122, etc. The different applications can be encoded in different languages. For example, application 111 can be encoded in Go (Golang), application 121 can be encoded in Java, and application 122 can be encoded in Python.
[0050] Applications can provide services or issue access requests. An access request is used to request access to a service provided by another application. In other words, an application within a business node can issue an access request, which can be used to access a service provided by another application. For example, application 121 can provide service B1, and application 111 can issue an access request for service B1, which is directed to application 121. As another example, application 122 can provide service B2, and application 111 can issue an access request for service B2, which is directed to application 122. An access request targeting a specific application is also called an application-specific access request; it refers to an access request whose target is that application.
[0051] Users can configure service governance policies for applications. These policies select one of governance devices, A1 or A2, to perform service governance related to the application. The application's service governance policy can be simply referred to as the governance policy. Application-related service governance refers to the service governance required for access requests to that application. For example, ... Figure 1 As shown, the service governance strategy of application 121 can select the governance device A2 to perform the service governance required for the access request to application 121; in other words, the access request to application 121 is used to request service governance for application 121. For example, as... Figure 2 As shown, the service governance strategy of application 122 can select the service governance required by the governance device A2 to perform the access request for application 122, or in other words, the access request for application 122 is used to request service governance for application 122.
[0052] In some embodiments, such as Figure 2 As shown, governance device A2 may include governance component A21. Governance component A21 is used to perform service governance required by the access request received by governance device A2.
[0053] In some embodiments, a user can configure an application's service governance policy through governance device A2, which then sends the configured policy to each service node in system 100. Upon receiving the application's service governance policy, the service node can record it. For example, governance device A1 deployed on a service node can be used to receive and record the application's service governance policy.
[0054] In some embodiments, such as Figure 2As shown, governance device A2 can also obtain application service metadata from the registry center. This service metadata may include the number of service instances, the addresses of the service instances, and the routing rules for the service instances. A service instance is an application instance providing the service. Governance device A2 can send the service instance routing rules, etc., to each business node in system 100. Upon receiving the application's routing rules, the business node can record them. For example, a business node can use a service discovery service (xDiscovery Service, xDS) protocol based on different data sources to receive service governance policies and routing rules sent by governance device A2. For example, governance device A2 can send the service instance routing rules, etc., to governance device A1 within the business node. Governance device A1 can record the application's routing rules, etc.
[0055] In some embodiments, such as Figure 2 As shown, the governance device A2 may further include a control component A22. The control component A22 can configure service governance policies for applications and obtain service metadata, etc. The control component A22 can also send service governance policies, routing rules, etc., to service nodes. For example, the governance device A1 in the service node is used to receive and record the service governance policies, routing rules, etc., sent by the control component A22.
[0056] In some embodiments, such as Figure 3 As shown, governance device A1 may include control component A11 and governance component A12. Control component A11 can receive service governance policies, routing rules, etc., sent by governance device A2, and record the received service governance policies, routing rules, etc., in governance component A12. Governance component A12 can perform service governance on access requests for the application based on the application's service governance policy, or send access requests for the application to governance device A2. Furthermore, when governance component A12 performs service governance on an access request, after completing the service governance, it can forward the access request to the application according to the routing rules of the application to which the access request is targeted. For example, control component A11 is located in user mode of the service node, and governance component A12 is located in kernel mode of the service node. In one example, governance component A12 may be implemented based on an extended Berkeley packet filter (eBPF). Governance component A12 can be called an eBPF program, and control component A11 can be called an eBPF program controller.
[0057] In one example of this embodiment, control component A11 is also used to maintain the lifecycle of service governance policies, routing rules, etc. For example, the service governance policies, routing rules, etc., of an offline application can be deleted.
[0058] In another example of this embodiment, such as Figure 3 As shown, governance component A12 includes a mapping table and a governance module. The mapping table records the mapping relationship between the application's identifier (ID) and its service governance policies and routing rules. In one example, the application's service governance policies and routing rules can be stored in a key-value pair structure, where the key is the application's identifier and the value is the application's service governance policy and routing rule, etc. In another example, the application's identifier can be the domain of the services provided by the application.
[0059] In yet another example of this embodiment, such as Figure 4 As shown, control component A11 includes a subscriber module, multiple handler modules, a routing logic processing module, and a redirect address injector module. Governance component A12 includes an application programming interface (API), a mapping table, and a governance plugin. The multiple handler modules may include a configuration handler module, a routing handler module, etc.
[0060] The subscription module can dynamically obtain application service governance policies, routing rules, and other information from governance device A2 in real time based on the xDS protocol. The subscription module can then send the information obtained from governance device A2 to the corresponding operation modules, such as sending service governance policies to the configuration operation module and routing rules to the routing operation module.
[0061] The operation module is used to convert the received xDS format information into a key-value pair structure, maintain and preserve the hierarchical structure of the xDS format, and then record the key-value pairs into the mapping table through the API, thereby realizing the dynamic hot update of information such as service governance policies and routing rules from user space to kernel space.
[0062] The API can be built based on the Berkeley packet filter (BPF) C language library. It can record governance policies, routing rules and other information into a mapping table in real time, and assign a unique ID to the governance policies and routing rules of each application.
[0063] In one example, in a Kubernetes (K8S) scenario, the API code could be as follows.
[0064]
[0065] The routing logic processing module can be used to determine, based on the application's service governance policy, whether access requests for that application need to be forwarded to governance device A2 for service governance. Specifically, if it is necessary to forward access requests for that application to governance device A2, the routing logic processing module can generate a redirection policy, which is used to forward the access request to governance device A2. The routing logic processing module can record the redirection policy in a mapping table through the redirection address injection module.
[0066] In one example, the code for the routing logic processing module could look like this.
[0067]
[0068]
[0069] When the governance plugin receives an access request, it can retrieve the corresponding service governance policy from the mapping table based on the target application ID carried in the access request. Then, it selects either governance device A1 or governance device A2 to perform service governance based on the policy. Specifically, when governance device A1 is selected, the plugin performs service governance on the access request. When governance device A2 is selected, the access request is forwarded to governance device A2 according to the redirection policy, where governance device A2 performs service governance.
[0070] The above example illustrates a system architecture provided by an embodiment of this application. Next, taking implementation within this system architecture as an example, the flow of the service governance method provided by this embodiment of the application will be described. This method can be configured to be executed by business node 110. Wherein, business node 110 deploys a governance device A1, which can also be referred to as the first governance device. For example... Figure 5 As shown, the method includes the following steps.
[0071] Step 501: Service node 110 receives a service governance policy for the first application input by the user. This service governance policy is used to select one of governance device A1 and governance device A2 to perform service governance related to the first application. The service governance related to the first application includes service governance required for access requests to the first application. An access request for the first application can mean that the target of the access request is the first application. Governance device A2 can also be referred to as the second governance device.
[0072] Users can configure the same or different service governance policies for different applications, and the service governance policies for different applications are independent of each other. For example, the first application can be application 121, and the service governance policy of application 121 is used to select governance device A1 to perform service governance related to application 121. As another example, the first application can be application 122, and the service governance policy of application 122 is used to select governance device A2 to perform service governance related to application 122.
[0073] In some embodiments, the service governance strategy may select a governance device based on the resource requirements of the service governance related to the first application. The resource requirements of service governance refer to the amount of computing resources required to perform the service governance; in other words, the resource requirements of service governance refer to the size of computing resources required to perform the service governance.
[0074] Specifically, if the service governance related to the first application is a service governance with high resource requirements (such as protocol conversion, rate limiting, or other Layer 7 service governance), then governance device A2 is selected to perform the service governance. In other words, the service governance strategy may include: if the resource requirements of the service governance related to the first application are greater than or equal to the threshold Y1, then governance device A2 is selected to perform the service governance related to the first application. This avoids the impact of the service governance related to the first application on the performance of business node 110.
[0075] Specifically, if the service governance related to the first application is a service governance with low resource requirements (such as Layer 4 service governance like traffic forwarding, or Layer 7 service governance like load balancing), then governance device A1 is selected to perform the service governance. In other words, if the resource requirements of the service governance related to the first application are less than the threshold Y1, governance device A1 is selected to perform the service governance related to the first application. In this way, without affecting the performance of the service governance related to the first application on business node 110, access requests are no longer forwarded to governance device A2, and the service governance related to the first application is executed locally, which can ensure that the service governance related to the first application is completed in a timely manner and reduce access latency.
[0076] The threshold Y1 can be preset based on experiments or experience.
[0077] In some embodiments, the service governance strategy can select a governance device based on the access latency allowed by the first application. The access latency refers to the time between sending the access request and receiving the access result. This time includes the transmission time of the access request, the service governance time, and the processing time of the target application.
[0078] If the allowed access latency for the first application is greater than or equal to the threshold Y2, then governance device A2 is selected to perform service governance related to the first application. An allowed access latency greater than or equal to the threshold Y2 indicates that the latency requirement for access requests to the first application is not high. Governance device A1 can forward access requests to governance device A2, allowing governance device A2 to perform service governance related to the first application, thereby saving resources on business node 110.
[0079] If the allowed access latency for the first application is less than the threshold Y2, then governance device A1 is selected to perform service governance related to the first application. The allowed access latency being less than the threshold Y1 indicates that the latency requirement for access requests to the first application is high. Governance device A1 performs service governance related to the first application, and access requests to the first application are no longer forwarded to governance device A2. This ensures that service governance for the access request is completed in a timely manner, reducing access latency.
[0080] The threshold Y2 can be preset based on experiments or experience. Allowable access latency greater than or equal to threshold Y2 can mean that the maximum allowed access latency is greater than or equal to threshold Y2. Allowable access latency less than threshold Y2 can mean that the maximum allowed access latency is less than threshold Y2.
[0081] In other embodiments, users may adopt service governance strategies for the first application based on other considerations, which will not be elaborated here.
[0082] In some embodiments, service node 110 can receive service governance policies through the governance device A1 deployed in service node 110.
[0083] Step 502: Business node 110 obtains a pending access request from the second application within business node 110. This pending access request is used for service governance of the first application; specifically, the pending access request is directed at the first application. The second application can be application 111. The pending access request refers to an access request that has not yet undergone service governance.
[0084] In some embodiments, a governance device A1 deployed in service node 110 can acquire access requests to be governed. Specifically, governance device A1 can intercept access requests issued by applications in service node 110. For example, applications in service node 110 can send access requests through a port. Governance device A1 can intercept access requests sent through that port, thereby acquiring the access requests sent by applications in service node 110.
[0085] In some embodiments, as described above, the governance device A1 is deployed in the kernel of the service node 110, and the governance device A1 can obtain access requests issued by applications in the service node where it is located.
[0086] The governance device A1 can identify the application targeted by the access request to be governed. Specifically, it is identified that the access request to be governed is targeted at the first application.
[0087] The access request carries identification information of the access target. The governance device A1 can identify the access target of the access request based on the ID of the access target carried in the access request, thereby confirming that the access request is for the first application.
[0088] In some embodiments, the ID of the access target carried in the access request may be the domain of the service. The service node 110 can identify the application providing the service based on the domain of the service, thereby confirming that the service is for the first application.
[0089] Step 503: Based on the service governance strategy of the first application, the service node 110 performs service governance on the access request to be governed through the governance device A1, or sends the access request to be governed to the governance device A2 so that the access request to be governed can be governed through the governance device A2.
[0090] When it is confirmed that the access request to be governed is for a first application, the service governance policy of the first application can be obtained. In some embodiments, the governance device A1 records the service governance policy of the first application, and the governance device A1 can obtain the recorded service governance policy of the first application. In some embodiments, the governance device A1 may record the service governance policies of multiple applications, wherein the service governance policies of the applications and the identifiers of the applications have a mapping relationship. The governance device A1 can obtain the service governance policy of the first application from the service governance policies of the multiple applications based on the identifier of the first application.
[0091] When the service governance strategy of the first application is to select governance device A1 to perform service governance related to the first application, business node 110 can directly perform the service governance required for the access request to be governed through governance device A1 deployed in business node 110. After governance device A1 completes the service governance required for the access request, business node 110 can forward the service-governed access request to the access target, such as the first application. Business node 110 can obtain the application's routing rules from governance device A2 or the registry center, and can send the access request for that application to the application based on the application's routing rules.
[0092] When the service governance strategy of the first application is to select governance device A2 to perform service governance related to the first application, the business node 110 can send the access request to be governed to governance device A2. After receiving the access request to be governed, governance device A2 performs service governance on the access request. For example, after completing the service governance required for the access request, governance device A2 can forward the service-governed access request to the access target, such as the first application. As mentioned above, governance device A2 can obtain the application's routing rules from the registry center, and governance device A2 can send the access request for the application to the application based on the application's routing rules. In some embodiments, business node 110 can send the access request to be governed to governance device A2 through governance device A1 deployed in business node 110.
[0093] In summary, the service governance method provided in this application embodiment can select a suitable governance device to perform application-related service governance according to the user's configuration. Thus, the service governance method can be flexibly selected, which can not only effectively avoid resource competition between service governance and business, and ensure the performance of business nodes, but also ensure the timeliness of access.
[0094] In some embodiments, service governance can also be carried out through the following schemes.
[0095] Combining sidecar-based microservice architecture with eBPF-based governance methods, a sidecar-less microservice system and methodology based on eBPF is proposed. This architecture consists of cluster control components, cluster governance components, components supporting dynamic eBPF configuration updates, and on-demand routing components. It supports heterogeneous frameworks and languages, and features high performance and lightweight characteristics, while also supporting both low- and high-level service governance capabilities.
[0096] The system architecture of this solution can include the following two aspects:
[0097] System control plane
[0098] Governance components: responsible for high-level governance of Layer 7 traffic, such as protocol conversion and rate limiting;
[0099] Controller: Responsible for configuring / routing policies, managing governance components, etc.
[0100] System Data Plane
[0101] eBPF Program Controller (User Space): Obtains and parses service configurations / routing policies from the control plane and dynamically writes them into the eBPF mapping in real time; responsible for maintaining the lifecycle of eBPF programs;
[0102] eBPF program (kernel mode): intercepts service requests and is responsible for Layer 4 traffic forwarding and some Layer 7 traffic management capabilities, such as load balancing;
[0103] System Features
[0104] The system control plane enables real-time configuration of governance strategies. For complex scenarios (such as protocol conversion, rate limiting, etc.), it can be configured to be governed by the cluster governance component to improve governance capabilities. For simple scenarios (such as load balancing, no governance required, etc.), it can be configured to be governed by eBPF at the OS layer to improve governance performance.
[0105] Therefore, this solution achieves sidecarless governance while improving the system's governance capabilities. Compared with existing solutions, it has advantages such as high performance, lightweight design, and support for heterogeneous frameworks and languages.
[0106] The main workflow of this solution is as follows.
[0107] Service A calls Service C
[0108] After Go framework service A sends a call request to Java framework service C, the request is intercepted by the eBPF program, which retrieves the routing configuration from the eBPF mapping based on the request.
[0109] Because this request is configured with an advanced governance strategy, eBPF will redirect the request to the governance component. Ultimately, the request will reach service C through the governance component, thus achieving advanced traffic governance.
[0110] Service A calls Service B
[0111] Similarly, the A->B request is intercepted by the eBPF program, which then queries the routing configuration.
[0112] Since no advanced governance strategy is configured for this request, the request will either go directly to target service B or reach target service B after traffic management such as load balancing.
[0113] This solution provides a new eBPF program controller component that may include the following parts.
[0114] Subscriber:
[0115] Based on the xDS protocol, the Subscriber can dynamically obtain changes to service clusters, endpoints, routing rules, etc., from the system control plane in real time and distribute them to the corresponding Handler components.
[0116] Handlers:
[0117] Each Handler is responsible for converting the corresponding xDS format configuration into a Key-Value structure defined in the eBPF Map, while also maintaining and preserving the hierarchical structure of xDS rules, and writing it into the system kernel's eBPF Map via API. This enables dynamic hot updates from user to kernel space.
[0118] eBPF map hot update API (for hot update map API):
[0119] Built on the BPF C Library, it refreshes service configuration / routing policies to the eBPF map in real time, assigning a unique ID to each map.
[0120]
[0121] eBPF program:
[0122] It is responsible for handling user requests, retrieving the corresponding route configuration from the eBPF map based on the map ID of the request, and performing route forwarding or traffic management based on the configuration.
[0123] The solution also provides components that support on-demand routing.
[0124] This component dynamically determines whether there is a governance policy based on the routing configuration information, and redirects requests to the cluster-level governance component in the system control plane for unified service governance as needed, depending on whether there is a governance policy.
[0125] The code execution logic is as follows:
[0126]
[0127]
[0128] In summary, this solution supports heterogeneous frameworks and languages. Furthermore, it improves the overall system's governance performance and reduces resource consumption. Additionally, it allocates governance strategies on demand and supports both low-level and high-level governance capabilities. Moreover, the governance strategies are updated in real-time as needed, enhancing system governance efficiency.
[0129] Based on the above description, this application embodiment also provides a service node 600. The service node 600 is deployed with a first governance device, and the system in which the service node resides further includes a second governance device independent of the service node; wherein, the first governance device is used to perform service governance using the computing resources of the service node, and the second governance device is used to perform service governance using computing resources other than those of the service node. Figure 6 As shown, business node 600 includes:
[0130] The receiving module 610 is configured to receive a service governance policy for a first application input by a user. The service governance policy is used to select one of the first governance device and the second governance device to perform service governance related to the first application. The service governance related to the first application includes service governance required for access requests to the first application.
[0131] The acquisition module 620 is used to acquire a governance access request issued by the second application in the business node; wherein the governance access request is used to perform service governance on the first application;
[0132] The governance module 630 is used to perform service governance on the access request to be governed through the first governance device based on the service governance strategy, or to send the access request to be governed to the second governance device so that the access request to be governed can be service governed through the second governance device.
[0133] In some embodiments, the service governance strategy includes: if the resource requirement for the service governance of the first application is greater than or equal to a first threshold, selecting the second governance device to perform the service governance of the first application; if the resource requirement for the service governance of the first application is less than the first threshold, selecting the first governance device to perform the service governance of the first application.
[0134] In some embodiments, the service governance strategy includes: if the allowed access latency of the first application is greater than or equal to a second threshold, selecting the second governance device to perform service governance related to the first application; if the allowed access latency of the first application is less than the second threshold, selecting the first governance device to perform service governance related to the first application.
[0135] In some embodiments, the service governance device 600 is deployed in the kernel of the service node.
[0136] In some embodiments, the encoding languages of the first application and the second application are different.
[0137] The receiving module 610, acquiring module 620, and governing module 630 can all be implemented in software or in hardware. For example, the implementation of the receiving module 610 will be described below. Similarly, the implementation of the acquiring module 620 and the governing module 630 can refer to the implementation of the receiving module 610.
[0138] As an example of a software functional unit, the receiving module 610 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, or a container. Further, the aforementioned computing instance may be one or more. For example, the receiving module 610 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one or more geographically proximate data centers. Typically, a region may include multiple AZs.
[0139] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same Virtual Private Cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, as well as between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.
[0140] As an example of a hardware functional unit, the receiving module 610 may include at least one computing device, such as a server. Alternatively, the receiving module 610 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be implemented using a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.
[0141] The multiple computing devices included in the receiving module 610 can be distributed in the same region or in different regions. Similarly, the multiple computing devices included in the receiving module 610 can be distributed in the same Availability Zone (AZ) or in different AZs. Likewise, the multiple computing devices included in the receiving module 610 can be distributed in the same Virtual Private Cloud (VPC) or in multiple VPCs. These multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0142] It should be noted that, in other embodiments, the receiving module 610 can be used to perform... Figure 5 In any step of the method shown, module 620 can be used to execute Figure 5 The governance module 630 can be used to execute any step in the method shown. Figure 5 Any step in the method shown. The steps implemented by the receiving module 610, the acquiring module 620, and the governance module 630 can be specified as needed, and implemented by the receiving module 610, the acquiring module 620, the confirming module 630, and the governance module 630 respectively. Figure 5 The different steps in the method shown are used to implement all the functions of business node 600.
[0143] This application also provides a computing device 700. For example... Figure 7 As shown, the computing device 700 includes a bus 702, a processor 704, a memory 706, and a communication interface 708. The processor 704, the memory 706, and the communication interface 708 communicate with each other via the bus 702. The computing device 700 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 700.
[0144] The 702 bus can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of representation, Figure 7 The bus 702 may be represented by a single line, but this does not mean that there is only one bus or one type of bus. The bus 702 may include a path for transmitting information between various components of the computing device 700 (e.g., memory 706, processor 704, communication interface 708).
[0145] Processor 704 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0146] Memory 706 may include volatile memory, such as random access memory (RAM). Memory 706 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0147] The memory 706 stores executable program code, and the processor 704 executes the executable program code to implement the functions of the aforementioned receiving module 610, acquiring module 620, and managing module 630, thereby achieving... Figure 5 The method shown. That is, the memory 706 stores the method for execution. Figure 5 The instructions for the method shown.
[0148] The communication interface 708 uses transceiver modules, such as, but not limited to, network interface cards and transceivers, to enable communication between the computing device 700 and other devices or communication networks.
[0149] This application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.
[0150] like Figure 8 As shown, the computing device cluster includes at least one computing device 700. The memory 706 in one or more computing devices 700 of the computing device cluster may store the same memory for executing... Figure 5 The instructions for the method shown.
[0151] In some possible implementations, the memory 706 of one or more computing devices 700 in the computing device cluster may also store memory for execution. Figure 5The instructions of the method shown are partial. In other words, a combination of one or more computing devices 700 can jointly execute instructions for performing... Figure 5 The instructions for the method shown.
[0152] It should be noted that the memory 706 in different computing devices 700 within the computing device cluster can store different instructions, each used to execute a portion of the functions of the device 700. That is, the instructions stored in the memory 706 of different computing devices 700 can implement the functions of one or more modules among the receiving module 610, the acquiring module 620, and the governing module 630.
[0153] In some possible implementations, one or more computing devices in a computing device cluster can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc. Figure 9 One possible implementation is shown. For example... Figure 9 As shown, two computing devices 700A and 700B are connected via a network. Specifically, they are connected to the network through communication interfaces in each computing device. In this possible implementation, the memory 706 in computing device 700A stores instructions for performing the functions of the receiving module 610. Simultaneously, the memory 706 in computing device 700B stores instructions for performing the functions of the acquisition module 620 and the management module 630.
[0154] It should be understood that Figure 9 The functions of the computing device 700A shown can also be performed by multiple computing devices 700. Similarly, the functions of the computing device 700B can also be performed by multiple computing devices 700.
[0155] This application also provides another computing device cluster. The connection relationships between the computing devices in this computing device cluster can be similarly referred to... Figure 8 and Figure 9 The connection method of the computing device cluster. The difference is that the memory 706 in one or more computing devices 700 within this computing device cluster can store the same data for execution. Figure 5 The instructions for the method shown.
[0156] In some possible implementations, the memory 706 of one or more computing devices 700 in the computing device cluster may also store memory for execution. Figure 5 The instructions of the method shown are partial. In other words, a combination of one or more computing devices 700 can jointly execute instructions for performing... Figure 5 The instructions for the method shown.
[0157] This application also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions, capable of running on a computing device or stored on any usable medium. When the computer program product is run on at least one computing device, it causes the at least one computing device to perform... Figure 5 The method shown.
[0158] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store, or a host migration device such as a data center that includes one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute... Figure 5 The method shown.
[0159] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of this application.
Claims
1. A service governance method, characterized in that, The method is applied to a business node, which is equipped with a first governance device. The system in which the business node resides also includes a second governance device independent of the business node. The first governance device is used to perform service governance using the computing resources of the business node, and the second governance device is used to perform service governance using computing resources other than those of the business node. The method includes: The system receives a service governance policy for a first application from user input. The service governance policy is used to select one of the first governance device and the second governance device to perform service governance related to the first application. The service governance related to the first application includes service governance required for access requests to the first application. Obtain the access request to be governed issued by the second application in the business node; wherein the access request to be governed is used for service governance of the first application; Based on the service governance strategy, the first governance device performs service governance on the access request to be governed, or the access request to be governed is sent to the second governance device so that the second governance device performs service governance on the access request to be governed.
2. The method according to claim 1, characterized in that, The service governance strategy includes: If the resource requirements for the governance of the services related to the first application are greater than or equal to the first threshold, the second governance device is selected to perform the governance of the services related to the first application. If the resource requirements for the governance of the services related to the first application are less than the first threshold, the first governance device is selected to perform the governance of the services related to the first application.
3. The method according to claim 1, characterized in that, The service governance strategy includes: If the allowed access latency of the first application is greater than or equal to the second threshold, the second governance device is selected to perform service governance related to the first application. If the allowed access latency of the first application is less than the second threshold, the first governance device is selected to perform service governance related to the first application.
4. The method according to any one of claims 1-3, characterized in that, The first governance device is deployed in the kernel of the service node.
5. The method according to any one of claims 1-4, characterized in that, The encoding language of the first application is different from that of the second application.
6. A business node, characterized in that, The service node is equipped with a first governance device, and the system in which the service node resides also includes a second governance device independent of the service node; wherein, the first governance device is used to perform service governance using the computing resources of the service node, and the second governance device is used to perform service governance using resources other than the computing resources of the service node; the service governance device includes: A receiving module is configured to receive a service governance policy for a first application input by a user. The service governance policy is used to select one of the first governance device and the second governance device to perform service governance related to the first application. The service governance related to the first application includes service governance required for access requests to the first application. The acquisition module is used to acquire the access request to be governed issued by the second application in the business node; wherein the access request to be governed is used to perform service governance on the first application; The governance module is used to perform service governance on the access request to be governed through the first governance device based on the service governance policy, or to send the access request to be governed to the second governance device so that the access request to be governed can be service governed through the second governance device.
7. The business node according to claim 6, characterized in that, The service governance strategy includes: If the resource requirements for the governance of the services related to the first application are greater than or equal to the first threshold, the second governance device is selected to perform the governance of the services related to the first application. If the resource requirements for the governance of the services related to the first application are less than the first threshold, the first governance device is selected to perform the governance of the services related to the first application.
8. The business node according to claim 6, characterized in that, The service governance strategy includes: If the allowed access latency of the first application is greater than or equal to the second threshold, the second governance device is selected to perform service governance related to the first application. If the allowed access latency of the first application is less than the second threshold, the first governance device is selected to perform service governance related to the first application.
9. The business node according to any one of claims 6-8, characterized in that, The first governance device is deployed in the kernel of the service node.
10. The service node according to any one of claims 6-9, characterized in that, The encoding language of the first application is different from that of the second application.
11. A computing device cluster, characterized in that, It includes at least one computing device, each computing device including a processor and memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the cluster of computing devices to perform the method as described in any one of claims 1 to 5.
12. A computer-readable storage medium, characterized in that, Includes computer program instructions, which, when executed by a cluster of computing devices, perform the method as described in any one of claims 1 to 5.
13. A computer program product containing instructions, characterized in that, When the instruction is executed by a cluster of computer devices, the cluster of computer devices causes the cluster of computer devices to perform the method as described in any one of claims 1 to 5.