Processing Method, Device and Storage Medium for Load Balancing of Kubernetes Cluster

By introducing proxy containers in the Kubernetes cluster, the data interaction between the API server and the controller is controlled according to the pre-configured traffic configuration rules, the problem of single-point operation and load balancing of the controller caused by the single master problem is solved, and the efficient parallel operation of the controller is achieved.

CN113312159BActive Publication Date: 2025-06-27ALIBABA (CHINA) CO LTD
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202110343763.6
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2021-03-30
Publication Date
2025-06-27
Estimated Expiration
2041-03-30

AI Technical Summary

Technical Problem

Due to the single master problem, the controllers in the Kubernetes cluster run single point, making it difficult to achieve load balancing, resulting in low efficiency.

Method used

The traffic configuration rules are obtained through the central control component of the Kubernetes cluster and sent to the corresponding proxy container of each controller. The data interaction between the API server and the controller is controlled according to the traffic configuration rules through the proxy container.

Benefits of technology

It realizes the parallel operation of multiple controllers, solves the load balancing problem, and improves the controller operation efficiency of Kubernetes cluster.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN113312159B_ABST
    Figure CN113312159B_ABST
Patent Text Reader

Abstract

The present invention discloses a processing method, device and storage medium for load balancing of a Kubernetes cluster. Among them, the method includes: the central control component of the Kubernetes cluster obtains the traffic configuration rules for the controllers in the Kubernetes cluster; sends the traffic configuration rules to the proxy containers corresponding to each controller; and controls the data interaction between the API server and the controllers through the proxy containers according to the traffic configuration rules. The present invention solves the technical problem that it is difficult to achieve load balancing due to the single-master problem, which causes the controllers to run singly.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of computer software, and in particular, to a method, apparatus, and storage medium for processing load balancing of a Kubernetes cluster. Background Art

[0002] As the application scale of Kubernetes continues to expand, the number and complexity of various controllers and components for processing resources towards the final state on it also gradually increase, making it increasingly difficult to understand and manage. For example, the single-master problem brings about the single-point operation of the controller, which will cause problems such as inability to achieve load balancing and horizontal scaling, resulting in low operating efficiency of the controller.

[0003] In view of the above problems, no effective solution has been proposed yet. Summary of the Invention

[0004] Embodiments of the present invention provide a method, apparatus, and storage medium for processing load balancing of a Kubernetes cluster, so as to at least solve the technical problem that it is difficult to achieve load balancing due to the single-point operation of the controller caused by the single-master problem.

[0005] According to an aspect of an embodiment of the present invention, a method for processing load balancing of a Kubernetes cluster is provided, including: a central control component of the Kubernetes cluster obtains a traffic configuration rule for a controller in the Kubernetes cluster; sends the traffic configuration rule to a proxy container corresponding to each controller; and controls data interaction between an API server and the controller through the proxy container according to the traffic configuration rule.

[0006] Further, before controlling data interaction between the API server and the controller through the proxy container according to the traffic configuration rule, the method further includes: receiving, by the proxy container, a data request instruction sent by at least one of the multiple controllers; sending, by the proxy container, the data request instruction to the API server, and receiving data sent by the API server.

[0007] Further, before controlling data interaction between the API server and the controller through the proxy container according to the traffic configuration rule, the method further includes: receiving, by the proxy container, a data request instruction triggered by the API server; and in response to the data request instruction, receiving, by the proxy container, data sent by the API server.

[0008] Further, controlling the data interaction between the API server and the controller by the proxy container according to the traffic configuration rules includes: filtering the received data based on the traffic configuration rules in the proxy container to obtain filtered data; and sending the filtered data to the controller corresponding to the proxy container.

[0009] Further, controlling the data interaction between the API server and the controller by the proxy container according to the traffic configuration rules includes: sending the data received by the proxy container to the controller corresponding to the proxy container; when the data processing is triggered in the controller corresponding to the proxy container, calling the interface of the proxy container to determine whether the data conforms to the traffic configuration rules, and if so, allowing the controller corresponding to the proxy container to perform data processing; if not, not allowing the controller corresponding to the proxy container to perform data processing.

[0010] Further, the traffic configuration rules include: a global restriction rule and a sharding routing rule. After sending the traffic configuration rules to the proxy container corresponding to each controller, the method further includes: the proxy container intercepts requests that do not conform to the global restriction rule and sends requests that conform to the global restriction rule to the API server; and / or, the proxy container intercepts webhook requests from the API server; determines whether the webhook request conforms to the sharding routing rule of the current instance; if so, forwards it to the local Webhook of the proxy container for processing; if not, forwards it to an instance that conforms to the rule for processing.

[0011] Further, the method further includes: setting a security protection policy in the proxy container, where the security protection policy includes at least one of the following: traffic limiting, circuit breaking, and one-key pause.

[0012] Further, the method further includes: monitoring the interaction information between the controller and the API server through the proxy container; and displaying the monitored information on a display interface.

[0013] According to one aspect of the embodiments of the present invention, there is provided a processing device for load balancing of a Kubernetes cluster, including: a first obtaining unit, configured to obtain traffic configuration rules for controllers in the Kubernetes cluster from a central control component of the Kubernetes cluster; a first sending unit, configured to send the traffic configuration rules to a proxy container corresponding to each controller; and a first control unit, configured to control data interaction between an API server and the controller through the proxy container according to the traffic configuration rules.

[0014] Further, the device further includes: a first receiving unit, configured to receive, via the proxy container, a data request instruction sent by at least one of the multiple controllers before controlling data interaction between the API server and the controller according to the traffic configuration rule through the proxy container; a second receiving unit, configured to send the data request instruction to the API server via the proxy container and receive data sent by the API server.

[0015] Further, the device further includes: a third receiving unit, configured to receive, via the proxy container, a data request instruction triggered by the API server before controlling data interaction between the API server and the controller according to the traffic configuration rule through the proxy container; a first response unit, configured to respond to the data request instruction and receive data sent by the API server via the proxy container.

[0016] Further, the first control unit includes: a first processing module, configured to perform filtering processing on the received data based on the traffic configuration rule in the proxy container to obtain filtered data; a first sending module, configured to send the filtered data to the controller corresponding to the proxy container.

[0017] Further, the first control unit includes: a first receiving module, configured to send the data received by the proxy container to the controller corresponding to the proxy container; a first calling module, configured to, when the controller corresponding to the proxy container triggers data processing, call the interface of the proxy container to determine whether the data conforms to the rule according to the traffic configuration rule. If it conforms, allow the controller corresponding to the proxy container to perform data processing; if it does not conform, do not allow the controller corresponding to the proxy container to perform data processing.

[0018] Further, the traffic configuration rule includes: a global limit rule and a sharding routing rule. After sending the traffic configuration rule to the proxy container corresponding to each controller, the device further includes: a second sending unit, configured to intercept requests that do not conform to the global limit rule by the proxy container and send requests that conform to the global limit rule to the API server; and / or, a first judging unit, configured to intercept a webhook request from the API server by the proxy container; judge whether the webhook request conforms to the sharding routing rule of the current instance; if it conforms, forward it to the local Webhook of the proxy container for processing; if it does not conform, forward it to an instance that conforms to the rule for processing.

[0019] Further, the device further includes: a first setting unit, configured to set a security protection policy in the proxy container, where the security protection policy includes at least one of the following: traffic limiting, fusing, and one-key pause.

[0020] Further, the device further includes: a first monitoring unit, configured to monitor the interaction information between the controller and the API server through the proxy container; and a first display unit, configured to display the monitored information on a display interface.

[0021] According to one aspect of the embodiments of the present invention, there is provided a storage medium, where the storage medium includes a stored program, and the program executes the method described in any one of the above.

[0022] According to one aspect of the embodiments of the present invention, there is provided a device, including: a processor; and a storage medium, connected to the processor, configured to provide instructions for the processor to perform the following processing steps: the central control component of the Kubernetes cluster obtains the traffic configuration rules for the controllers in the Kubernetes cluster; sends the traffic configuration rules to the proxy container corresponding to each controller; and controls the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules.

[0023] In the embodiments of the present invention, a method is adopted in which the proxy container controls the data interaction between the API server and the controller according to the pre-configured traffic configuration rules. Specifically, the central control component of the Kubernetes cluster obtains the traffic configuration rules for the controllers in the Kubernetes cluster; sends the traffic configuration rules to the proxy container corresponding to each controller; and controls the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules, so that multiple controllers can simultaneously request data from the API server, and the data received by the controllers conforms to the rules in the traffic configuration rules, thereby achieving the purpose of parallel operation of multiple controllers, and thus achieving the technical effect of load balancing of the controllers in the Kubernetes cluster, and further solving the technical problem that it is difficult to achieve load balancing due to the single-master problem, which causes the single-point operation of the controller. BRIEF DESCRIPTION OF THE DRAWINGS

[0024] The drawings described herein are used to provide a further understanding of the present invention, and constitute a part of this application. The illustrative embodiments of the present invention and their descriptions are used to explain the present invention, and do not constitute an improper limitation to the present invention. In the drawings:

[0025] Figure 1 is a hardware structure block diagram of a computer terminal according to an embodiment of the present invention;

[0026] Figure 2 It is a flowchart of a method for processing load balancing of a Kubernetes cluster provided in Embodiment 1 of the present invention;

[0027] Figure 3 It is a schematic diagram of a method for processing load balancing of a Kubernetes cluster provided in Embodiment 1 of the present invention Figure 1 ;

[0028] Figure 4 It is a schematic diagram of a method for processing load balancing of a Kubernetes cluster provided in Embodiment 1 of the present invention Figure 2 ;

[0029] Figure 5 It is a schematic diagram of hard limit in a method for processing load balancing of a Kubernetes cluster provided in Embodiment 1 of the present invention;

[0030] Figure 6 It is a schematic diagram of dynamic limit in a method for processing load balancing of a Kubernetes cluster provided in Embodiment 1 of the present invention;

[0031] Figure 7 It is a schematic diagram of Webhook traffic control in a method for processing load balancing of a Kubernetes cluster provided in Embodiment 1 of the present invention;

[0032] Figure 8 It is a schematic diagram of a device for processing load balancing of a Kubernetes cluster provided in Embodiment 2 of the present invention; and

[0033] Figure 9 It is a structural block diagram of an optional computer terminal according to an embodiment of the present invention. Detailed implementation manners

[0034] In order to enable those skilled in the art to better understand the solutions of the present invention, the technical solutions in the embodiments of the present invention will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without making creative efforts shall fall within the protection scope of the present invention.

[0035] It should be noted that the terms "first", "second", etc. in the description, claims and above-mentioned drawings of the present invention are used to distinguish similar objects, and do not necessarily have to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances, so that the embodiments of the present invention described here can be implemented in an order other than those illustrated or described here. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device comprising a series of steps or units does not have to be limited to those steps or units clearly listed, but may include other steps or units not clearly listed or inherent to these processes, methods, products or devices.

[0036] First, some nouns or terms that appear in the process of describing the embodiments of the present application are applicable to the following explanations:

[0037] Kubernetes: An open-source container orchestration engine that supports automated deployment, large-scale scalability, and application container management.

[0038] Controller: The controller in the present application refers to the controller in Kubernetes that processes resources towards the final state.

[0039] Webhook: The Hook hook in Kubernetes when a resource object submits a create / update / delete request to the Apiserver.

[0040] Operator: An extended custom addon component in Kubernetes, generally implemented as a controller and a Webhook.

[0041] Embodiment 1

[0042] According to an embodiment of the present invention, an embodiment of a method for processing load balancing of a Kubernetes cluster is provided. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than here.

[0043] The method embodiment provided by the first embodiment of the present application can be executed on a mobile terminal, a computer terminal or a similar computing device. Figure 1 A hardware structure block diagram of a computer terminal (or mobile device) for implementing a method for processing load balancing of a Kubernetes cluster is shown. As Figure 1 shown, the computer terminal 10 (or mobile device 10) may include one or more ( Figure 1In the figure, the processor 102 (the processor 102 may include, but is not limited to, a processing device such as a microprocessor MCU or a programmable logic device FPGA, etc.) is shown by 102a, 102b, ……, 102n, a memory 104 for storing data, and a transmission device for communication functions. In addition, it may further include: a display, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, a power supply, and / or a camera. Those of ordinary skill in the art can understand that Figure 1 The structure shown is only schematic and does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components than Figure 1 shown in the figure, or have a different configuration from Figure 1 shown in the figure.

[0044] It should be noted that the above one or more processors 102 and / or other data processing circuits can generally be referred to as "data processing circuits" in this article. The data processing circuit can be embodied in software, hardware, firmware, or any combination thereof, in whole or in part. In addition, the data processing circuit can be a single independent processing module, or be incorporated in whole or in part into any one of other elements in the computer terminal 10 (or mobile device). As involved in the embodiments of the present application, the data processing circuit is a kind of processor control (such as the selection of a variable resistance terminal path connected to an interface).

[0045] The memory 104 can be used to store software programs and modules of application software, such as the program instructions / data storage device corresponding to the processing method of load balancing of the Kubernetes cluster in the embodiments of the present invention. The processor 102 executes various functional applications and data processing by running the software programs and modules stored in the memory 104, that is, implements the processing method of load balancing of the Kubernetes cluster of the above-mentioned application program. The memory 104 may include a high-speed random access memory, and may further include a non-volatile memory, such as one or more magnetic storage devices, a flash memory, or other non-volatile solid-state memories. In some instances, the memory 104 may further include a memory remotely set relative to the processor 102, and these remote memories can be connected to the computer terminal 10 through a network. Examples of the above network include, but are not limited to, the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.

[0046] The transmission device 106 is used to receive or send data via a network. Specific examples of the above-mentioned network may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a Radio Frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0047] The display can be, for example, a touch-screen liquid crystal display (LCD), which enables the user to interact with the user interface of the computer terminal 10 (or mobile device).

[0048] Under the above operating environment, the present application provides a Figure 2 processing method for load balancing of a Kubernetes cluster as shown. Figure 2 It is a flowchart of the processing method for load balancing of a Kubernetes cluster according to Embodiment 1 of the present invention.

[0049] Step S201, the central control component of the Kubernetes cluster obtains the traffic configuration rules for the controllers in the Kubernetes cluster.

[0050] As Figure 3 shown, it is responsible for managing and configuring the traffic configuration rules of the controllers in the Kubernetes cluster on the control plane to adjust the routed traffic or data received by the controllers.

[0051] Step S202, send the traffic configuration rules to the proxy containers corresponding to each controller.

[0052] The traffic configuration rules include the traffic configuration rules for multiple controllers in the Kubernetes cluster, and the traffic configuration rules are transmitted to the proxy containers corresponding to each controller.

[0053] Step S203, through the proxy containers, control the data interaction between the API server and the controllers according to the traffic configuration rules.

[0054] Through the above steps, it is realized that multiple controllers can simultaneously request data from the API server, and the data received by the controllers conforms to the rules in the traffic configuration rules, so as to achieve the purpose of parallel operation of multiple controllers, thereby realizing the technical effect of load balancing of the controllers in the Kubernetes cluster, and further solving the technical problem that it is difficult to achieve load balancing due to the single-master problem resulting in single-point operation of the controllers.

[0055] Optionally, in the method for processing load balancing of the Kubernetes cluster provided in this application, before controlling the data interaction between the API server and the controller according to the traffic configuration rules through the proxy container, the method further includes: receiving, by the proxy container, a data request instruction sent by at least one of a plurality of controllers; sending, by the proxy container, the data request instruction to the API server, and receiving the data returned by the API server.

[0056] As Figure 4 shown, after the controller in the operator triggers a data request instruction to the API server, the data request instruction sent by the controller is intercepted through the iptables nat mechanism. It should be noted that the above data request instruction is an instruction for requesting data, and it can be used for data query requests, data reading and writing, etc. Forward the data request instruction to the proxy container corresponding to the controller, send the data request instruction to the API server through the proxy container, and receive the data returned by the API server. Filter the received data based on the traffic configuration rules in the proxy container to obtain the filtered data; send the filtered data to the controller corresponding to the proxy container. In addition, rule routing, circuit breaking, monitoring, etc. can also be performed based on the traffic configuration rules in the proxy container. These proxy containers together form a network for intercepting the network communication between the Operator and the API server.

[0057] After sending the data received by the proxy container to the controller corresponding to the proxy container, when the controller corresponding to the proxy container triggers data processing, call the interface of the proxy container to determine whether the data conforms to the traffic configuration rules. If it conforms, allow the controller corresponding to the proxy container to perform data processing; if it does not conform, do not allow the controller corresponding to the proxy container to perform data processing.

[0058] Optionally, in the method for processing load balancing of the Kubernetes cluster provided in this application, before controlling the data interaction between the API server and the controller according to the traffic configuration rules through the proxy container, the method further includes: receiving, by the proxy container, a data request instruction triggered by the API server; in response to the data request instruction, receiving, by the proxy container, the data requested by the API server.

[0059] As Figure 4 shown, after the API server sends a data request instruction to the webhook server in the operator, the data request instruction sent by the API server is intercepted through the iptables nat mechanism, and the data request instruction is forwarded to the proxy container corresponding to the controller, and the data request instruction is sent to the corresponding webhook server through the proxy container.

[0060] Optionally, in the method for processing load balancing of the Kubernetes cluster provided in this application, the traffic configuration rules include: global restriction rules and sharding routing rules. After sending the traffic configuration rules to the proxy containers corresponding to each controller, the method further includes: the proxy container intercepts requests that do not conform to the global restriction rules, and sends requests that conform to the global restriction rules to the API server; and / or, the proxy container intercepts the webhook requests from the API server; determines whether the webhook requests conform to the sharding routing rules of the current instance; if they conform, forwards them to the local webhook server of the proxy container for processing; if they do not conform, forwards them to the instance that conforms to the rules for processing.

[0061] From the dimension of traffic control, it is divided into: global restriction rules, that is, restriction rules that take effect for all such operator instances, used for overall isolation and restriction; sharding routing rules: different subsets process resources with different sharding rules, used for horizontal expansion or gray-scale upgrade. The traffic control of the controller is divided into two methods: The first: hard restriction, which completely performs traffic control on the proxy container side. For example, the proxy container intercepts requests triggered by the controller that do not conform to the global restriction rules, and sends requests that conform to the global restriction rules to the API server; and / or, the proxy container intercepts the data returned from the API server, returns the data that conforms to the global restriction rules to the controller, and filters out the data that does not conform to the global restriction rules. The second, dynamic restriction, completes the work queue request control through the interaction between the controller and the proxy container. For example, determines whether the data processing request conforms to the sharding routing rules of the current instance; if it conforms, allows the controller to process it; if it does not conform, does not allow the controller to process the data. It should be noted that the global traffic control can only be hard restriction, while the sharding traffic control can choose hard restriction or dynamic restriction.

[0062] Such as Figure 5As shown in the figure, hard limit performs traffic control on the proxy container side: the data request results of the controller will be filtered by the proxy container, and only the list that meets the rules will be returned to the controller for processing. At the same time, operations performed by the controller on objects that do not meet its own rules, such as getting, adding, updating, deleting, etc., will also be returned. Therefore, hard limit can be understood as a kind of isolation similar to multi-tenancy. The controller can only see and operate on resource objects that meet its own rules, and all other objects do not exist for this controller. The advantages of hard limit include: strong isolation and very thorough; the controller can only pull objects that meet the rules, that is, the controller will only cache these objects; there is no need to modify any code, and any number of controllers that process namespace-dimensional resources can be restricted. The disadvantages of hard limit are: if the controller needs to pay attention to cluster-dimensional resources and process other namespace-dimensional resources based on cluster-dimensional resources, hard limit cannot be used for gray-scale upgrade and horizontal sharding in this case; when adjusting the rules, the proxy container will disconnect the corresponding controller connection to trigger the controller to restart, so as to re-perform data pulling and attention operations, etc.

[0063] As Figure 6 shown in the figure, dynamic limit completes the control of the work queue request through the interaction between code dependencies and the proxy container. After configuring the sharding rules, the proxy container will still pass all objects that meet the global limit rules to the controller side. When the work queue of the controller enqueues and dequeues, it calls the interface of the local controller to determine whether this request meets the current sharding rules. If it does not meet, it will be directly discarded without processing. Dynamic limit has good compatibility and can support controllers with complex operations of namespace-dimensional and cluster-dimensional resource interactions. When adjusting the rules, the controller does not need to restart, and the new rules can take effect dynamically. The disadvantage of dynamic limit is that the local of the controller will cache all resource objects that meet the global limit, and the memory occupation is larger than that of hard limit. The isolation is not completely thorough. Although the actual processing ensures that it is processed according to the routing rules, all objects can be queried directly. The Operator code needs to be slightly modified, just replace one line of code dependency.

[0064] In addition, for Webhook server traffic control, as Figure 7As shown, the proxy container does not distinguish between hard limits or dynamic limits for traffic control of the controller. For the global limit rule: the proxy management will dynamically monitor the configuration in this VirtualOperator and write the filtering rule into it. After writing, for resource objects that do not conform to the global limit rule, the API server will not call this Webhook for processing. Since the writing is asynchronous, it is possible that the Operator will still receive requests for objects that do not conform to the rule from the API server within a short period of time. At this time, the proxy container will intercept the request and directly return success to the API server to ensure that it will not be passed to the Webhook service.

[0065] For the sharding routing rule: after the proxy container intercepts a request from the API server, it first determines whether the request conforms to the sharding rule of this instance. If it conforms, it will directly forward it to the local Webhook for processing. If it does not conform, it will be forwarded to an instance that conforms to the rule for processing. Additionally, it should be noted that in the Virtual Operator, information such as the local certificate address, listening port, configuration, and service name of this Webhook needs to be defined in advance.

[0066] In addition, in the method for processing load balancing of the Kubernetes cluster provided in this application, a failure scenario can also be injected on the proxy side to perform failure logic verification on one or more controller instances, thereby simulating a failure scenario to ensure the security of the controller.

[0067] Optionally, in the method for processing load balancing of the Kubernetes cluster provided in this application, the method further includes: setting a security protection policy in the proxy container, where the security protection policy includes at least one of the following: traffic limiting, circuit breaking, and one-key pause.

[0068] The above-mentioned traffic limiting is to prevent the controller from frequently requesting the API server, resulting in excessive pressure on the API server and service unavailability. The traffic to the API server called by the controller can be limited through the proxy container, such as the maximum number of allowed calls per second.

[0069] The above-mentioned circuit breaking means that when an exception occurs in the API server, all requests from the controller can be truncated through the proxy container, avoiding an avalanche-like pressure effect on the API server and facilitating the rapid recovery of the API server.

[0070] The above-mentioned one-key pause means that when a failure occurs in the controller, all requests and return data from the API server to the controller can be filtered through the proxy container, thereby stopping the controller from working.

[0071] Optionally, in the method for processing the load balancing of the Kubernetes cluster provided in this application, the method further includes: monitoring the interaction information between the controller and the API server through a proxy container; and displaying the monitored information on a display interface.

[0072] The data monitored by the proxy container can be divided into outer-layer monitoring and injection monitoring. By tracking the calls between the Operator and the API server through the outer layer of the proxy container, service request class metrics such as performance, latency, traffic, and errors are statistically analyzed. If the Operator replaces the code dependencies, logical-related metrics inside the controller and Webhook will also be collected, such as queue backlog, processing performance changes, memory consumption tracking, and job health status. All of the above metrics can be used as the monitored information and displayed on the display interface, thereby improving the speed at which users obtain effective information. Additionally, users can also configure the collection of the Prometheus server to meet their respective monitoring requirements.

[0073] It should be noted that for the foregoing method embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that the present invention is not limited by the described action sequence, because according to the present invention, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to the present invention.

[0074] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases the former is a better implementation method. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (such as ROM / RAM, magnetic disk, optical disk) and includes several instructions for causing a terminal device (which can be a mobile phone, computer, server, or network device, etc.) to execute the methods of the various embodiments of the present invention.

[0075] Embodiment 2

[0076] According to an embodiment of the present invention, there is also provided a device for implementing the above-mentioned processing of the load balancing of the Kubernetes cluster, as Figure 8 shown, the device includes: a first acquisition unit 301, a first sending unit 302, and a first control unit 303.

[0077] Specifically, a first obtaining unit 301 is configured to obtain traffic configuration rules for controllers in the Kubernetes cluster by a central control component of the Kubernetes cluster;

[0078] A first sending unit 302 is configured to send the traffic configuration rules to proxy containers corresponding to each controller;

[0079] A first control unit 303 is configured to control data interaction between an API server and the controller according to the traffic configuration rules through the proxy container.

[0080] Optionally, in the processing device for load balancing of the Kubernetes cluster provided in the second embodiment of the present application, the device further includes: a first receiving unit, configured to receive, through the proxy container, a data request instruction sent by at least one of multiple controllers before controlling data interaction between the API server and the controller according to the traffic configuration rules through the proxy container; a second receiving unit, configured to send the data request instruction to the API server through the proxy container and receive data sent by the API server.

[0081] Optionally, in the processing device for load balancing of the Kubernetes cluster provided in the second embodiment of the present application, the device further includes: a third receiving unit, configured to receive, through the proxy container, a data request instruction triggered by the API server before controlling data interaction between the API server and the controller according to the traffic configuration rules through the proxy container; a first response unit, configured to respond to the data request instruction and receive data sent by the API server through the proxy container.

[0082] Optionally, in the processing device for load balancing of the Kubernetes cluster provided in the second embodiment of the present application, the first control unit 303 includes: a first processing module, configured to filter the received data based on the traffic configuration rules in the proxy container to obtain filtered data; a first sending module, configured to send the filtered data to the controller corresponding to the proxy container.

[0083] Optionally, in the processing device for load balancing of the Kubernetes cluster provided in the second embodiment of the present application, the first control unit 303 includes: a first receiving module, configured to send the data received by the proxy container to the controller corresponding to the proxy container; a first calling module, configured to, when data processing is triggered by the controller corresponding to the proxy container, call an interface of the proxy container to determine whether the data conforms to the traffic configuration rules. If it conforms, allow the controller corresponding to the proxy container to perform data processing; if it does not conform, do not allow the controller corresponding to the proxy container to perform data processing.

[0084] Optionally, in the processing device for load balancing of the Kubernetes cluster provided in the second embodiment of the present application, the traffic configuration rules include: a global limit rule and a sharding routing rule. After sending the traffic configuration rules to the proxy containers corresponding to each controller, the device further includes: a second sending unit, configured to intercept requests that do not conform to the global limit rule by the proxy container and send requests that conform to the global limit rule to the API server; and / or, a first determination unit, configured to intercept a webhook request from the API server by the proxy container; determine whether the webhook request conforms to the sharding routing rule of the current instance; if it conforms, forward it to the local Webhook of the proxy container for processing; if it does not conform, forward it to an instance that conforms to the rule for processing.

[0085] Optionally, in the processing device for load balancing of the Kubernetes cluster provided in the second embodiment of the present application, the device further includes: a first setting unit, configured to set a security protection policy in the proxy container, where the security protection policy includes at least one of the following: traffic limiting, circuit breaking, and one-key pause.

[0086] Optionally, in the processing device for load balancing of the Kubernetes cluster provided in the second embodiment of the present application, the device further includes: a first monitoring unit, configured to monitor the interaction information between the controller and the API server through the proxy container; a first display unit, configured to display the monitored information on a display interface.

[0087] It should be noted here that the above-mentioned first obtaining unit 301, first sending unit 302, and first control unit 303 correspond to steps S201 to S203 in Embodiment 1. The instances and application scenarios implemented by the three units and the corresponding steps are the same, but are not limited to the content disclosed in the above-mentioned Embodiment 1. It should be noted that the above unit modules, as part of the device, can run in the computer terminal 10 provided in Embodiment 1.

[0088] Embodiment 3

[0089] An embodiment of the present invention may provide a computer terminal, and the computer terminal may be any computer terminal device in a computer terminal group. Optionally, in this embodiment, the above computer terminal may also be replaced with a terminal device such as a mobile terminal.

[0090] Optionally, in this embodiment, the above computer terminal may be located in at least one of multiple network devices in a computer network.

[0091] In this embodiment, the above computer terminal may execute the program code of the following steps in the method for processing load balancing of a Kubernetes cluster for an application program: The central control component of the Kubernetes cluster obtains the traffic configuration rules for the controllers in the Kubernetes cluster; sends the traffic configuration rules to the proxy containers corresponding to each controller; and controls the data interaction between the API server and the controllers through the proxy containers according to the traffic configuration rules.

[0092] The above computer terminal may also execute the program code of the following steps in the method for processing load balancing of a Kubernetes cluster for an application program: Before controlling the data interaction between the API server and the controllers through the proxy containers according to the traffic configuration rules, the proxy containers receive data request instructions sent by at least one of the multiple controllers; the proxy containers send the data request instructions to the API server and receive the data sent by the API server.

[0093] The above computer terminal may also execute the program code of the following steps in the method for processing load balancing of a Kubernetes cluster for an application program: Before controlling the data interaction between the API server and the controllers through the proxy containers according to the traffic configuration rules, the proxy containers receive data request instructions triggered by the API server; in response to the data request instructions, the proxy containers receive the data sent by the API server.

[0094] The above computer terminal may also execute the program code of the following steps in the method for processing load balancing of a Kubernetes cluster for an application program: Filter the received data in the proxy container based on the traffic configuration rules to obtain the filtered data; send the filtered data to the controller corresponding to the proxy container.

[0095] The above computer terminal may also execute the program code of the following steps in the method for processing load balancing of a Kubernetes cluster for an application program: Send the data received by the proxy container to the controller corresponding to the proxy container; when the controller corresponding to the proxy container triggers data processing, call the interface of the proxy container to determine whether the data conforms to the traffic configuration rules. If it conforms, allow the controller corresponding to the proxy container to perform data processing; if it does not conform, do not allow the controller corresponding to the proxy container to perform data processing.

[0096] The computer terminal can also execute the program code of the following steps in the method for processing the load balancing of the Kubernetes cluster of the application program: global restriction rules and sharding routing rules. After sending the traffic configuration rules to the proxy containers corresponding to each controller, the method further includes: the proxy container intercepts requests that do not conform to the global restriction rules, and sends requests that conform to the global restriction rules to the API server; and / or, the proxy container intercepts webhook requests from the API server; determines whether the webhook request conforms to the sharding routing rules of the current instance; if it conforms, forwards it to the local Webhook of the proxy container for processing; if it does not conform, forwards it to the instance that conforms to the rules for processing.

[0097] The computer terminal can also execute the program code of the following steps in the method for processing the load balancing of the Kubernetes cluster of the application program: setting a security protection policy in the proxy container, where the security protection policy includes at least one of the following: traffic limiting, circuit breaking, and one-key pause.

[0098] The computer terminal can also execute the program code of the following steps in the method for processing the load balancing of the Kubernetes cluster of the application program: monitoring the interaction information between the controller and the API server through the proxy container; displaying the monitored information on the display interface.

[0099] Optionally, Figure 9 is a structural block diagram of a computer terminal according to an embodiment of the present invention. As Figure 9 shown, the computer terminal may include: one or more ( Figure 9 only one is shown in the figure) processors, a memory.

[0100] Among them, the memory can be used to store software programs and modules, such as the program instructions / modules corresponding to the method and device for processing the load balancing of the Kubernetes cluster in the embodiment of the present invention. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory, that is, implements the above-mentioned method for processing the load balancing of the Kubernetes cluster. The memory may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memories, or other non-volatile solid-state memories. In some instances, the memory may further include a memory remotely set relative to the processor, and these remote memories can be connected to the terminal through a network. Examples of the above network include but are not limited to the Internet, enterprise intranets, local area networks, mobile communication networks, and combinations thereof.

[0101] The processor can call the information and application programs stored in the memory through the transmission device to execute the following steps: The central control component of the Kubernetes cluster obtains the traffic configuration rules for the controllers in the Kubernetes cluster; sends the traffic configuration rules to the proxy containers corresponding to each controller; and controls the data interaction between the API server and the controller through the proxy containers according to the traffic configuration rules.

[0102] Optionally, the above-mentioned processor can also execute the program code of the following steps: Before controlling the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules, receive a data request instruction sent by at least one of the multiple controllers through the proxy container; send the data request instruction to the API server through the proxy container, and receive the data sent by the API server.

[0103] Optionally, the above-mentioned processor can also execute the program code of the following steps: Before controlling the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules, receive a data request instruction triggered by the API server through the proxy container; in response to the data request instruction, receive the data sent by the API server through the proxy container.

[0104] Optionally, the above-mentioned processor can also execute the program code of the following steps: Filter the received data based on the traffic configuration rules in the proxy container to obtain the filtered data; send the filtered data to the controller corresponding to the proxy container.

[0105] Optionally, the above-mentioned processor can also execute the program code of the following steps: Send the data received by the proxy container to the controller corresponding to the proxy container; when the data processing is triggered by the controller corresponding to the proxy container, call the interface of the proxy container to determine whether the data conforms to the traffic configuration rules. If it conforms, allow the controller corresponding to the proxy container to perform data processing; if it does not conform, do not allow the controller corresponding to the proxy container to perform data processing.

[0106] Optionally, the above-mentioned processor can also execute the program code of the following steps: For the global restriction rules and sharding routing rules, after sending the traffic configuration rules to the proxy containers corresponding to each controller, the proxy container intercepts the requests that do not conform to the global restriction rules and sends the requests that conform to the global restriction rules to the API server; and / or, the proxy container intercepts the webhook requests from the API server; determines whether the webhook request conforms to the sharding routing rules of the current instance; if it conforms, forwards it to the local Webhook of the proxy container for processing; if it does not conform, forwards it to the instance that conforms to the rules for processing.

[0107] Optionally, the above-mentioned processor may also execute the program code of the following steps: set a security protection policy in the proxy container, where the security protection policy includes at least one of the following: traffic limiting, circuit breaking, and one-key pause.

[0108] Optionally, the above-mentioned processor may also execute the program code of the following steps: monitor the interaction information between the controller and the API server through the proxy container; display the monitored information on the display interface.

[0109] By adopting the embodiment of the present invention, a solution for a load balancing processing method of a Kubernetes cluster is provided. By adopting the method that the proxy container controls the data interaction between the API server and the controller according to the pre-configured traffic configuration rules, specifically, the central management and control component of the Kubernetes cluster obtains the traffic configuration rules for the controllers in the Kubernetes cluster; sends the traffic configuration rules to the proxy container corresponding to each controller; and the proxy container controls the data interaction between the API server and the controller according to the traffic configuration rules, so that multiple controllers can simultaneously request data from the API server, and at the same time, the data received by the controllers conforms to the rules in the traffic configuration rules, thereby achieving the purpose of parallel operation of multiple controllers, and thus realizing the technical effect of load balancing of the controllers in the Kubernetes cluster, and further solving the technical problem that it is difficult to achieve load balancing due to the single-master problem resulting in single-point operation of the controller.

[0110] Those of ordinary skill in the art can understand that Figure 9 the structure shown is only schematic, and the computer terminal may also be a smart phone (such as an Android phone, an iOS phone, etc.), a tablet computer, a palm computer, and a mobile Internet device (Mobile Internet Devices, MID), a PAD and other terminal devices. Figure 9 It does not limit the structure of the above-mentioned electronic device. For example, the computer terminal 10 may further include more or fewer components (such as a network interface, a display device, etc.) than those shown Figure 9 in the figure, or have a different configuration from that shown Figure 9 in the figure.

[0111] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructing the relevant hardware of the terminal device through a program, and the program can be stored in a computer-readable storage medium, and the storage medium may include: a flash drive, a read-only memory (Read-Only Memory, ROM), a random access memory (Random Access Memory, RAM), a magnetic disk or an optical disc, etc.

[0112] Embodiment 4

[0113] An embodiment of the present invention further provides a storage medium. Optionally, in this embodiment, the above storage medium may be used to store the program code executed by the method for processing the load balancing of the Kubernetes cluster provided in the first embodiment above.

[0114] Optionally, in this embodiment, the above storage medium may be located in any one of the computer terminals in the computer terminal group in the computer network, or in any one of the mobile terminals in the mobile terminal group.

[0115] Optionally, in this embodiment, the storage medium is set to store the program code for performing the following steps: the central control component of the Kubernetes cluster obtains the traffic configuration rules for the controllers in the Kubernetes cluster; sends the traffic configuration rules to the proxy containers corresponding to each controller; and controls the data interaction between the API server and the controller according to the traffic configuration rules through the proxy containers.

[0116] Optionally, in this embodiment, the storage medium is set to store the program code that is further used to perform the following steps: the above processor may also execute the program code of the following steps: before controlling the data interaction between the API server and the controller according to the traffic configuration rules through the proxy containers, receiving, through the proxy containers, data request instructions sent by at least one of the multiple controllers; sending the data request instructions to the API server through the proxy containers, and receiving the data sent by the API server.

[0117] Optionally, in this embodiment, the storage medium is set to store the program code that is further used to perform the following steps: before controlling the data interaction between the API server and the controller according to the traffic configuration rules through the proxy containers, receiving, through the proxy containers, the data request instructions triggered by the API server; and in response to the data request instructions, receiving the data sent by the API server through the proxy containers.

[0118] Optionally, in this embodiment, the storage medium is set to store the program code that is further used to perform the following steps: filtering the received data based on the traffic configuration rules in the proxy containers to obtain the filtered data; and sending the filtered data to the controller corresponding to the proxy containers.

[0119] Optionally, in this embodiment, the storage medium is configured to store program code further for performing the following steps: sending the data received by the proxy container to the controller corresponding to the proxy container; when the controller corresponding to the proxy container triggers data processing, calling the interface of the proxy container to determine whether the data conforms to the traffic configuration rule, and if so, allowing the controller corresponding to the proxy container to perform data processing; if not, not allowing the controller corresponding to the proxy container to perform data processing.

[0120] Optionally, in this embodiment, the storage medium is configured to store program code further for performing the following steps: global restriction rules and sharding routing rules. After sending the traffic configuration rules to the proxy container corresponding to each controller, the proxy container intercepts requests that do not conform to the global restriction rules and sends requests that conform to the global restriction rules to the API server; and / or, the proxy container intercepts webhook requests from the API server; determines whether the webhook request conforms to the sharding routing rule of the current instance; if so, forwards it to the local Webhook of the proxy container for processing; if not, forwards it to an instance that conforms to the rule for processing.

[0121] Optionally, in this embodiment, the storage medium is configured to store program code further for performing the following steps: setting a security protection policy in the proxy container, where the security protection policy includes at least one of the following: traffic limiting, circuit breaking, and one-key pause.

[0122] Optionally, in this embodiment, the storage medium is configured to store program code further for performing the following steps: monitoring the interaction information between the controller and the API server through the proxy container; displaying the monitored information on the display interface.

[0123] The serial numbers of the above embodiments of the present invention are only for description and do not represent the advantages or disadvantages of the embodiments.

[0124] In the above embodiments of the present invention, the descriptions of the various embodiments have their own emphases. For parts not detailed in a certain embodiment, reference may be made to the relevant descriptions of other embodiments.

[0125] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. Among them, the device embodiments described above are only illustrative. For example, the division of units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point, the displayed or discussed coupling or direct coupling or communication connection between each other can be through some interfaces, and the indirect coupling or communication connection of units or modules can be in an electrical or other form.

[0126] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or may be distributed over multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.

[0127] In addition, each functional unit in various embodiments of the present invention may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit. The above integrated units can be implemented in the form of hardware or in the form of software functional units.

[0128] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods in various embodiments of the present invention. The aforementioned storage medium includes: USB flash drives, read-only memories (ROMs), random access memories (RAMs), mobile hard disks, magnetic disks, or optical discs and other various media that can store program codes.

[0129] The above is only the preferred embodiment of the present invention. It should be noted that for those of ordinary skill in the art, without departing from the principle of the present invention, several improvements and refinements can be made, and these improvements and refinements should also be regarded as the protection scope of the present invention.

Claims

1. A method for processing load balancing of a Kubernetes cluster, characterized in that Including: The central control component of the Kubernetes cluster obtains the traffic configuration rules for the controllers in the Kubernetes cluster; Sends the traffic configuration rules to the proxy containers corresponding to each controller; Controls the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules; Wherein, the number of the controllers is multiple, the number of the proxy containers is multiple, and the number of the API servers is one; Before controlling the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules, the method further includes: Receiving, by the proxy container, a data request instruction triggered by the API server; Responding to the data request instruction, and receiving, by the proxy container, the data sent by the API server; Wherein, controlling the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules includes: Sending the data received by the proxy container to the controller corresponding to the proxy container; When the data processing is triggered by the controller corresponding to the proxy container, calling the interface of the proxy container to determine whether the data conforms to the traffic configuration rules. If it conforms, allowing the controller corresponding to the proxy container to perform data processing; if not, not allowing the controller corresponding to the proxy container to perform data processing.

2. The method according to claim 1, characterized in that, Before controlling the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules, the method further includes: Receiving, by the proxy container, a data request instruction sent by at least one of the multiple controllers; Sending the data request instruction to the API server through the proxy container, and receiving the data sent by the API server.

3. The method according to claim 2, wherein Controlling the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules includes: Performing filtering processing on the received data in the proxy container based on the traffic configuration rules to obtain filtered data; Sending the filtered data to the controller corresponding to the proxy container.

4. The method according to claim 1, wherein The traffic configuration rules include: a global limit rule and a sharding routing rule. After sending the traffic configuration rules to the proxy containers corresponding to each controller, the method further includes: The proxy container intercepts requests that do not conform to the global limit rule and sends requests that conform to the global limit rule to the API server; and / or, The proxy container intercepts a webhook request from the API server; determines whether the webhook request conforms to the sharding routing rule of the current instance; if it conforms, forwards it to the local Webhook of the proxy container for processing; if not, forwards it to an instance that conforms to the rule for processing.

5. The method according to claim 1, characterized in that, The method further includes: Setting a security protection policy in the proxy container, wherein the security protection policy includes at least one of the following: traffic limiting, circuit breaking, one-key pause.

6. The method according to claim 1, wherein The method further includes: Monitor the interaction information between the controller and the API server through the proxy container; Display the monitored information on the display interface.

7. A processing device for load balancing of a Kubernetes cluster, characterized in that, It includes: The first acquisition unit is used to acquire the traffic configuration rules for the controllers in the Kubernetes cluster by the central control component of the Kubernetes cluster; The first sending unit is used to send the traffic configuration rules to the proxy container corresponding to each controller; The first control unit is used to control the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules; Among them, the number of the controllers is multiple, and the number of the API servers is one; The device further includes: a third receiving unit, which is used to receive the data request instruction triggered by the API server through the proxy container before controlling the data interaction between the API server and the controller according to the traffic configuration rules through the proxy container; a first response unit, which is used to respond to the data request instruction and receive the data sent by the API server through the proxy container; Among them, the number of the proxy containers is multiple; The first control unit includes: a first receiving module, which is used to send the data received by the proxy container to the controller corresponding to the proxy container; The first calling module is used to, when the controller corresponding to the proxy container triggers data processing, call the interface of the proxy container to judge whether the data conforms to the rules according to the traffic configuration rules. If it conforms, allow the controller corresponding to the proxy container to perform data processing; if it does not conform, do not allow the controller corresponding to the proxy container to perform data processing.

8. The device according to claim 7, characterized in that, The device further includes: The first receiving unit is used to receive the data request instruction sent by at least one of the multiple controllers through the proxy container before controlling the data interaction between the API server and the controller according to the traffic configuration rules through the proxy container; The second receiving unit is used to send the data request instruction to the API server through the proxy container and receive the data sent by the API server.

9. The device according to claim 7, wherein The first control unit includes: The first processing module is used to filter the received data based on the traffic configuration rules in the proxy container to obtain the filtered data; The first sending module is used to send the filtered data to the controller corresponding to the proxy container.

10. The device according to claim 7, characterized in that, The traffic configuration rules include: global restriction rules and shard routing rules. After sending the traffic configuration rules to the proxy container corresponding to each controller, the device further includes: The second sending unit is used to intercept the requests that do not conform to the global restriction rules by the proxy container and send the requests that conform to the global restriction rules to the API server; and / or, A first judgment unit is configured to intercept a webhook request from an API server by the proxy container; determine whether the webhook request conforms to the sharding routing rules of the current instance; if it conforms, forward it to the local Webhook of the proxy container for processing; if it does not conform, forward it to an instance that conforms to the rules for processing.

11. The device according to claim 7, characterized in that, The device further includes: A first setting unit is configured to set a security protection policy in the proxy container, where the security protection policy includes at least one of the following: traffic limiting, circuit breaking, and one-key pause.

12. The device according to claim 7, wherein The device further includes: A first monitoring unit is configured to monitor the interaction information between the controller and the API server through the proxy container; A first display unit is configured to display the monitored information on a display interface.

13. A storage medium, characterized in that, The storage medium includes a stored program, where the program executes the method according to any one of claims 1 to 5.

14. A device, characterized in that, It includes: A processor; And A storage medium, connected to the processor, is configured to provide instructions for the processor to process the following steps: The central control component of the Kubernetes cluster obtains the traffic configuration rules for the controllers in the Kubernetes cluster; Send the traffic configuration rules to the proxy container corresponding to each controller; Control the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules; Wherein, the number of the controllers is multiple, and the number of the API servers is one; Before controlling the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules, receive a data request instruction triggered by the API server through the proxy container; In response to the data request instruction, receive the data sent by the API server through the proxy container; Wherein, the number of the proxy containers is multiple; Controlling the data interaction between the API server and the controller through the proxy container according to the traffic configuration rules includes: sending the data received by the proxy container to the controller corresponding to the proxy container; when the controller corresponding to the proxy container triggers data processing, call the interface of the proxy container to determine whether the data conforms to the traffic configuration rules, if it conforms, allow the controller corresponding to the proxy container to perform data processing; if it does not conform, do not allow the controller corresponding to the proxy container to perform data processing.

Citation Information

Patent Citations

  • Control method for application programming interface (API) gateway cluster, and API gateway cluster

    CN111386676A

  • Dynamic load balancing method and system for Kubernetes container cloud platform

    CN111800458A

  • Systems and methods for API routing and security

    US20160352867A1