Communication method, device, computer equipment and storage medium based on VPC network
By creating a virtual bridge and configuring a virtual gateway in the host, the communication problem between virtual machines and containers or multiple virtual machines in the VPC network is solved, and smooth communication without the need to transform business code is achieved, ensuring interoperability between services.
Patent Information
- Application Number
- CN202211114442.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-09-14
- Publication Date
- 2025-05-23
- Estimated Expiration
- 2042-09-14
AI Technical Summary
It is difficult to smoothly handle the communication between virtual machines and containers or between multiple virtual machines in VPC networks, and business code modification is required to ensure normal communication between vm virtual machines and pod containers.
Create a virtual bridge in the host and configure a virtual gateway for the virtual network segment, bridge the gateway of the virtual machine to the virtual bridge, so that the virtual machine can communicate with the external or intranet through the virtual gateway and the host's network card.
It can smoothly handle the mutual communication between virtual machines and containers or multiple virtual machines without remodeling business code, solve the problem of network communication between virtual machines and containers or multiple virtual machines, and ensure that the services deployed on it can communicate and access each other.
Smart Images

Figure CN115473816B_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of communication technology, and in particular to a communication method, apparatus, computer equipment and storage medium based on a VPC network. Background Art
[0002] At present, cloud vendors' servers and related services usually adopt two service modes: KVM (Kernel-based Virtual Machine) virtualization and K8s (Kubernetes) containerization. K8s containerization uses the cloud vendor's container cloud, and KVM virtualization is virtualized by the cloud vendor's bare metal server. However, for VPC (Virtual Private Cloud) networks, KVM virtualization technology and CCE (Cloud Container Engine) containerization technology are deployed in a mixed manner, which does not support the management of KVM virtualization IPs built by users. In addition, in order to ensure normal communication between VM virtual machines and pod containers, business code transformation is required, which is likely to affect existing services. Summary of the invention
[0003] In view of this, the present application provides a communication method, apparatus, computer equipment and storage medium based on a VPC network to solve the problem of smoothly processing the mutual communication between virtual machines and containers or between multiple virtual machines in a VPC network.
[0004] In a first aspect, a communication method based on a VPC network is provided, where the VPC network serves a host machine and at least one virtual machine, the method comprising:
[0005] Create a virtual bridge in the host machine;
[0006] Configure the virtual gateway of the virtualized network segment for the virtual bridge;
[0007] Bridge the gateway of at least one virtual machine to the virtual network bridge;
[0008] In response to the communication instruction, at least one virtual machine communicates with the external network through the virtual gateway and the network card of the host machine, and / or at least one virtual machine communicates with the internal network through the virtual gateway.
[0009] Furthermore, a virtual bridge is created in the host machine, including:
[0010] Get the configuration file;
[0011] At the network layer of the OSI network model of the host machine, a virtual bridge is created according to the configuration file.
[0012] Furthermore, configuring a virtual gateway of the virtualized network segment for the virtual bridge includes:
[0013] Create a VPC network interface on the host machine, and connect the VPC network interface to the network card interface of the host machine;
[0014] Assign any available IP address in the virtualized network segment to the VPC network interface;
[0015] Connect the VPC network interface to the virtual bridge.
[0016] Furthermore, at least one virtual machine communicates with an external network through a virtual gateway and a network card of a host machine, including:
[0017] In the case where any virtual machine accesses the external network through the network card of any virtual machine, any virtual machine sends a first data acquisition request corresponding to the communication instruction to the IP address of the virtual gateway through the network card of any virtual machine;
[0018] The virtual gateway forwards the first data acquisition request to the IP address of the network card of the host machine;
[0019] Sending the first data acquisition request to the external network according to the network protocol of the VPC network through the IP address of the network card of the host machine;
[0020] The host machine sends the data packets fed back from the external network to the IP address of the network card of any virtual machine.
[0021] Furthermore, at least one virtual machine communicates with the intranet through the virtual gateway, including:
[0022] In the case where any virtual machine accesses the intranet through the network card of any virtual machine, any virtual machine sends a second data acquisition request corresponding to the communication instruction to the IP address of the virtual gateway through the network card of any virtual machine;
[0023] Sending the second data acquisition request to the intranet through the virtual gateway;
[0024] The host sends the data packet fed back from the intranet to the IP address of the network card of any virtual machine.
[0025] Furthermore, the intranet includes at least one virtual machine; the extranet includes an LXC cluster, a k8s cluster and / or an Internet device.
[0026] Furthermore, the virtual bridge includes a linuxbridge bridge or an OVS bridge.
[0027] In a second aspect, a communication device based on a VPC network is provided, where the VPC network serves at least one virtual machine and a host machine, and the device includes:
[0028] Create a module to create a virtual bridge in the host machine;
[0029] A configuration module, used for configuring a virtual gateway of a virtualized network segment for a virtual network bridge;
[0030] a communication module, configured to bridge a gateway of at least one virtual machine to a virtual network bridge; and
[0031] In response to the communication instruction, at least one virtual machine communicates with the external network through the virtual gateway and the network card of the host machine, and / or at least one virtual machine communicates with the internal network through the virtual gateway.
[0032] Furthermore, the communication device based on the VPC network further includes:
[0033] The acquisition module is used to obtain the configuration file;
[0034] The creation module is specifically used to create a virtual bridge at the network layer of the OSI network model of the host machine according to the configuration file.
[0035] Furthermore, the creation module is also used to create a VPC network interface on the host machine, and the VPC network interface is connected to the network card interface of the host machine;
[0036] A configuration module, specifically configured to assign any available IP address in the virtualized network segment to the VPC network interface; and,
[0037] Connect the VPC network interface to the virtual bridge.
[0038] Further, the communication module is specifically used for sending the first data acquisition request to the IP address of the virtual gateway through the network card of any virtual machine when any virtual machine accesses the external network through the network card of any virtual machine;
[0039] The virtual gateway forwards the first data acquisition request corresponding to the communication instruction to the IP address of the network card of the host machine;
[0040] Sending the first data acquisition request to the external network according to the network protocol of the VPC network through the IP address of the network card of the host machine;
[0041] The host machine sends the data packets fed back from the external network to the IP address of the network card of any virtual machine.
[0042] Further, the communication module is specifically used for sending a second data acquisition request corresponding to the communication instruction to the IP address of the virtual gateway through the network card of any virtual machine when any virtual machine accesses the intranet through the network card of any virtual machine;
[0043] Sending the second data acquisition request to the intranet through the virtual gateway;
[0044] The host sends the data packet fed back from the intranet to the IP address of the network card of any virtual machine.
[0045] Furthermore, the intranet includes at least one virtual machine; the extranet includes an LXC cluster, a k8s cluster and / or an Internet device.
[0046] Furthermore, the virtual bridge includes a linuxbridge bridge or an OVS bridge.
[0047] In a third aspect, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the steps of the above-mentioned VPC network-based communication method when executing the computer program.
[0048] In a fourth aspect, a computer-readable storage medium is provided, wherein the computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the above-mentioned communication method based on the VPC network are implemented.
[0049] In the scheme implemented by the communication method, device, computer equipment and storage medium based on the VPC network, a virtual bridge is created in the host machine so that at least one virtual machine (vm) can be bridged with the network of the host machine through the virtual bridge. Then a virtual gateway of the virtualized network segment is configured for the virtual bridge, and the gateway of the virtualized IP communication of at least one virtual machine is set on the virtual bridge. Thus, by building a virtual bridge and a virtual gateway, the host machine is used as a switch between at least one virtual machine and the internal and external networks, so that at least one virtual machine can communicate with the external network through the virtual gateway and the network card of the host machine, and at least one virtual machine can communicate with the internal network through the virtual gateway. Then, a kvm virtualization scheme based on a virtual private cloud service is realized, as well as mutual access and communication between IPs of different network segments of the host machine and the virtual machine. At the same time, the network intercommunication between the virtual machine and the container or multiple virtual machines is solved, so that the services deployed thereon can communicate and access each other, and the purpose of smoothly processing the communication between the virtual machine and the container, or multiple virtual machines, is achieved without modifying the business code.
[0050] The above description is only an overview of the technical solution of the present application. In order to more clearly understand the technical means of the present application, it can be implemented in accordance with the contents of the specification. In order to make the above and other purposes, features and advantages of the present application more obvious and easy to understand, the specific implementation methods of the present application are listed below. BRIEF DESCRIPTION OF THE DRAWINGS
[0051] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the description of the embodiments of the present application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.
[0052] Figure 1 This is one of the flow diagrams of the communication method based on the VPC network in this application;
[0053] Figure 2 yes Figure 1 A schematic flow chart of a specific implementation of step S10;
[0054] Figure 3 yes Figure 1 A schematic flow chart of a specific implementation of step S20;
[0055] Figure 4 This is the second flow chart of the communication method based on the VPC network in this application;
[0056] Figure 5 This is the third flow chart of the communication method based on the VPC network in this application;
[0057] Figure 6 It is a schematic diagram of an application scenario of the communication method based on the VPC network in this application;
[0058] Figure 7 It is a communication diagram based on the VPC network in this application;
[0059] Figure 8 It is a schematic diagram of the structure of a communication device based on a VPC network in this application;
[0060] Fig. 9 It is a schematic diagram of the structure of the computer device in this application. DETAILED DESCRIPTION
[0061] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0062] See also Figure 1 As shown, Figure 1 A flow chart of a communication method based on a VPC network provided in an embodiment of the present application includes the following steps:
[0063] S10: Create a virtual bridge in the host machine;
[0064] It should be noted that the VPC network serves at least one virtual machine and a host. Each virtual machine (VM) has an Ethernet card and a default route, and the Ethernet card has a specified intranet IP address. For example, Figure 6 As shown in the figure, three virtual machines are deployed in the VPC (Virtual Private Cloud) network, namely VM-Guest1, VM-Guest2, and VM-Guest3. The Ethernet card IP addresses of the three virtual machines are 192.168.1.11, 192.168.1.12, and 192.168.1.13, respectively.
[0065] Specifically, the virtual bridge can be a linuxbridge bridge or an OVS (Open vSwitch) bridge. The linuxbridge bridge is a bridge created using the Linux tool brct; the OVS bridge is an openvswitch virtual switch created using the ovs-vsctl tool.
[0066] In one possible implementation, the VPC network can be applied to the Medical Cloud service scenario to meet the growing demand for medical communication efficiency. Medical Cloud refers to the use of "cloud computing" to create a medical and health service cloud platform based on new technologies such as cloud computing, mobile technology, multimedia, 4G communication, big data, and the Internet of Things, combined with medical technology, to achieve the sharing of medical resources and the expansion of medical scope. Because of the combination of cloud computing technology, the Medical Cloud improves the efficiency of medical institutions and facilitates residents' medical treatment. For example, the current hospital appointment registration, electronic medical records, and medical insurance are all products of the combination of cloud computing and the medical field. The Medical Cloud also has the advantages of data security, information sharing, dynamic expansion, and global layout.
[0067] In this embodiment, a virtual bridge is created in the host machine so that at least one virtual machine can be connected to the network of the host machine through the virtual bridge in Bridge wireless bridging mode, so as to facilitate communication between the at least one virtual machine and the host machine.
[0068] It is worth mentioning that the host has a kernel-level network card interface, which is used to communicate with the external network. For example, the kernel network card configuration file Ifcfg-br0 includes the following data:
[0069] DEVICE = "br0";
[0070] NM_CONTROLLED = "yes";
[0071] TYPE=Bridge;
[0072] BOOTPROTO = "static";
[0073] ONBOOT = "yes";
[0074] IPADDR = 192.168.0.5;
[0075] NETMASK=255.255.255.0.
[0076] In some embodiments of the present application, Figure 2 As shown, a specific entity alignment solution is provided. In S10, a virtual bridge is created in the host machine, which specifically includes the following steps:
[0077] S11: Obtain configuration file;
[0078] The configuration file includes routing parameters (such as network mask, activation or not, network configuration parameters), network type, name and other information.
[0079] S11: At the network layer of the OSI network model of the host machine, a virtual bridge is created according to the configuration file.
[0080] Specifically, the OSI (Open System Interconnection) network model divides the computer network architecture into the following seven layers:
[0081] (1) The physical layer is used to convert data into electronic signals that can be transmitted through physical media. It determines the network connection type (end-to-end or multi-end connection) and the physical topology.
[0082] (2) Data Link Layer: It is used to determine the way to access the network medium. It can establish a data link connection between two hosts, transmit data signals to the physical layer, and process the signals to ensure error-free and reasonable transmission.
[0083] (3) Network Layer: It is used to facilitate data transmission between two different networks and can perform routing functions such as selecting appropriate paths and performing congestion control.
[0084] (4) Transport Layer: This layer is used to provide reliable end-to-end connections and shield the data communication details of the lower layers.
[0085] (5) Session Layer: It is used for communication between two session processes, that is, the exchange of information between two session layer entities, the exchange of management data, and allows users to establish connections using simple and easy-to-remember names.
[0086] (6) Presentation Layer: used to negotiate data exchange formats, such as data encryption and decryption, data compression and recovery.
[0087] (7) Application Layer, which is the interface between the user's application and the network. It is used to maintain the data records required to establish connections between applications and can be based on protocols such as NetBEUI, IPX / SPX, and TCP / IP.
[0088] In this embodiment, a virtual bridge for connecting virtual machines is created at the network layer according to the configuration file set by the user, so that the host machine can set up multiple virtual machines, and realize the intercommunication between the virtual machine and the intranet or the extranet at the network layer, which helps to enhance the communication strength of the VPC network.
[0089] For example, the bridge configuration file Ifcfg-br0:0 includes the following data:
[0090] DEVICE = "br0";
[0091] NM_CONTROLLED = "yes";
[0092] TYPE=Bridge;
[0093] BOOTPROTO = "static";
[0094] ONBOOT = "yes";
[0095] IPADDR = 192.168.1.1;
[0096] NETMASK=255.255.255.0.
[0097] route-br0:
[0098] default via 192.168.0.5 dev br0 table 1
[0099] 192.168.1.0 / 24 dev br0 proto kernel scope link src 192.168.1.1 table1.
[0100] After completing the bridge configuration file, restart the network or br0 to create the virtual bridge.
[0101] S20: configure a virtual gateway of the virtualized network segment for the virtual bridge;
[0102] In this embodiment, a virtual gateway is created on the host host where the virtual bridge is located, and the virtual gateway can be considered as a dedicated gateway for at least one virtual machine, so as to realize the interconnection of two networks with different high-level protocols at the network layer by using the virtual gateway.
[0103] It is understandable that if multiple virtual machines are mounted on the same host machine, only one virtual bridge is created.
[0104] In some embodiments of the present application, Figure 3 As shown, a specific entity alignment solution is provided. In S20, that is, configuring a virtual gateway of a virtualized network segment for a virtual bridge, specifically includes the following steps:
[0105] S21: Create a VPC network interface on the host;
[0106] Among them, the VPC network interface is connected to the network card interface of the host machine;
[0107] S22: Assign any available IP address in the virtualized network segment to the VPC network interface;
[0108] S23: Connect the VPC network interface to the virtual bridge.
[0109] In this embodiment, a kernel network card interface is created on the host machine using the Open vSwitch (OVS) instruction, and a VPC network interface directly connected to the kernel network card interface is created. Any available IP address in the virtualized network segment is used as the IP address of the VPC network interface, while ensuring that the IP address of the virtual machine can be in the same network segment as the host machine. The created VPC network interface is enabled and connected to the virtual bridge. This VPC network interface is the virtual gateway dedicated to the virtual machine.
[0110] S30: bridging a gateway of at least one virtual machine to a virtual network bridge;
[0111] S40: In response to the communication instruction, at least one virtual machine communicates with the external network through the virtual gateway and the network card of the host machine, and / or at least one virtual machine communicates with the internal network through the virtual gateway.
[0112] In this embodiment, the host machine is used as a switch between at least one virtual machine and the internal and external networks, so that at least one virtual machine can communicate with the external network through the virtual gateway and the network card of the host machine, and at least one virtual machine can communicate with the internal network through the virtual gateway. Furthermore, a KVM virtualization solution based on a virtual private cloud service is implemented, and the IPs of different network segments of the host machine and the virtual machine can access and communicate with each other. At the same time, the network interconnection between the virtual machine and the container or multiple virtual machines is solved, so that the services deployed thereon can communicate and access each other, and the purpose of smoothly processing the communication between the virtual machine and the container, or between multiple virtual machines, is achieved without modifying the business code.
[0113] In actual application scenarios, the above configuration enables the kvm virtual machine to access external pod or vm data packets to achieve normal interactive communication, such as Figure 7 shown.
[0114] In some embodiments of the present application, Figure 4 As shown, S40, that is, at least one virtual machine communicates with the external network through the virtual gateway and the network card of the host machine, specifically includes:
[0115] S411: When any virtual machine accesses the external network through the network card of any virtual machine, any virtual machine sends a first data acquisition request corresponding to the communication instruction to the IP address of the virtual gateway through the network card of any virtual machine;
[0116] The first data acquisition request is used to acquire the first data of the external network. In a possible implementation, the first data may be medical data, such as personal health records, prescriptions, examination reports, etc., or financial data, such as transaction content, payment records, etc., so as to realize the interaction between the virtual machine and the external network for the first data. The embodiment of the present application does not specifically limit the first data.
[0117] Specifically, the external network is the environment network where the host machine is located. The external network may include LXC (Linux Container) clusters, k8s (Kubernetes) clusters and / or Internet devices. In LXC clusters or k8s clusters, containers (Pods) are the basis of all business types and the smallest unit level of cluster management. A cluster is a combination of one or more containers.
[0118] S412: The virtual gateway forwards the first data acquisition request to the IP address of the network card of the host machine;
[0119] S413: Sending the first data acquisition request to the external network according to the network protocol of the VPC network through the IP address of the network card of the host machine;
[0120] S414: The host machine sends the data packet fed back from the external network to the IP address of the network card of any virtual machine.
[0121] In this embodiment, if the communication instruction indicates that the virtual machine needs to communicate with the external network, any virtual machine generates a first data acquisition request using the identification information of the first data that needs to be obtained from the external network carried by the instruction, and then sends the first data acquisition request to the IP address of the virtual gateway through the network card of any virtual machine, and the virtual gateway forwards the first data acquisition request to the IP address of the network card of the host machine. Through the network protocol between the host machine and the external network, the first data acquisition request is sent to the external network using the IP address of the core network card of the host machine, so that the virtual machine can access the container (Pod) of the external network service through its own network card. After receiving the request, the container of the external network service returns the data packet corresponding to the request in sequence according to the routing and network protocol, and finally to the network card of the corresponding virtual machine, so that the virtual machine obtains the relevant data packet. Without modifying the business code, at least one virtual machine is completed to communicate with the external network, which improves the access success rate of PVC and effectively reduces the impact of virtual private cloud service failure.
[0122] Among them, external network services refer to various services based on software programs, such as web services, mail services, SSH remote login services, etc.
[0123] In some embodiments of the present application, Figure 5 As shown, S40, that is, at least one virtual machine communicates with the intranet through the virtual gateway, specifically includes:
[0124] S421: When any virtual machine accesses the intranet through the network card of any virtual machine, any virtual machine sends a second data acquisition request corresponding to the communication instruction to the IP address of the virtual gateway through the network card of any virtual machine;
[0125] The intranet is a private network segment used to create a virtual machine and set an IP address for it, and includes at least one virtual machine.
[0126] Specifically, the second data acquisition request is used to acquire the second data of the intranet. In a possible implementation, the second data may be medical data, such as personal health records, prescriptions, examination reports, etc., or financial data, such as transaction content, payment records, etc., so as to realize the interaction between the virtual machine and the external network for the second data. The embodiment of the present application does not specifically limit the second data.
[0127] S422: Sending the second data acquisition request to the intranet through the virtual gateway;
[0128] S423: The host machine sends the data packet fed back from the intranet to the IP address of the network card of any virtual machine.
[0129] In this embodiment, if the communication instruction indicates that the virtual machine needs to communicate with the intranet, any virtual machine generates a second data acquisition request using the identification information of the second data that needs to be obtained from the intranet carried by the instruction, and then sends the second data acquisition request to the IP address of the virtual gateway through the network card of any virtual machine. The second data acquisition request is sent to other virtual machines in the intranet through the virtual gateway. This enables the virtual machine to access the virtual machine of the intranet service through its own network card. After receiving the request, the virtual machine in the intranet returns the data packet corresponding to the request in sequence according to the route, and finally to the network card of the corresponding virtual machine, so that the virtual machine obtains the relevant data packet. In this way, the host machine is used as a switch between at least one virtual machine and the intranet, so that any virtual machine can communicate with other virtual machines in the intranet through the virtual gateway. Not only the user-built KVM virtualized IP in the VPC network is realized, but also the IPs of different network segments of the host and virtual machines can be satisfied to access and communicate with each other.
[0130] In a specific embodiment, Figure 6 As shown in the figure, the VPC network deploys three virtual machines, namely VM-Guest1, VM-Guest2, and VM-Guest3. The Ethernet card IP addresses of the three virtual machines are 192.168.1.11, 192.168.1.12, and 192.168.1.13, respectively. 192.168.0.5 is the IP address of the host network card, and 192.168.1.1 is the gateway IP address of the virtual machine vm on the host. For example, the three VM virtual machines access the external network through their respective eth0 network cards. The eth0 network cards of the three VM virtual machines forward the data packets to the virtual gateway br0: 192.168.1.1. The virtual gateway br0 forwards the data packets to the host network card IP address br0: 192.168.0.5. The data packets reach the gateway through the host network card IP address 192.168.0.5, and then request data from the external Internet. The requested data packets are returned in sequence according to the routing and network protocols, and finally arrive at eth0 corresponding to the vm virtual machine, thereby obtaining the relevant data packets. Based on the kvm virtualization solution, the IPs of different network segments of the host and the vm can access and communicate with each other, and the network interconnection between the virtual machine and the container or multiple virtual machines is solved, so that the services deployed on them can communicate and access each other, thereby achieving the technical effect of smoothly processing the mutual communication between the virtual machine and the container or the vm without modifying the business code.
[0131] It should be understood that the size of the serial numbers of the steps in the above embodiments does not mean the order of execution. The execution order of each process should be determined by its function and internal logic, and should not constitute any limitation on the implementation process of the embodiments of the present application.
[0132] In one embodiment, a communication device based on a VPC network is provided, and the communication device based on the VPC network corresponds one-to-one to the communication method based on the VPC network in the above embodiment. Figure 8 As shown, the communication device based on the VPC network includes a creation module 801, a configuration module 802, and a communication module 803. The detailed description of each functional module is as follows:
[0133] A creation module 801 is used to create a virtual network bridge in a host machine;
[0134] Configuration module 802, used to configure a virtual gateway of a virtualized network segment for a virtual network bridge;
[0135] The communication module 803 is used to bridge the gateway of at least one virtual machine to the virtual bridge; and, in response to the communication instruction, at least one virtual machine communicates with the external network through the virtual gateway and the network card of the host machine, and / or at least one virtual machine communicates with the intranet through the virtual gateway.
[0136] In one embodiment, the communication device based on the VPC network also includes: an acquisition module (not shown in the figure), which is used to obtain a configuration file; a creation module 801, which is specifically used to create a virtual bridge at the network layer of the OSI network model of the host machine according to the configuration file.
[0137] In one embodiment, the creation module 801 is also used to create a VPC network interface on the host machine, and the VPC network interface is connected to the network card interface of the host machine; the configuration module 802 is specifically used to assign any available IP address in the virtualized network segment to the VPC network interface; and, connect the VPC network interface to the virtual bridge.
[0138] In one embodiment, the communication module 803 is specifically used for, when any virtual machine accesses the external network through the network card of any virtual machine, any virtual machine sends a first data acquisition request corresponding to the communication instruction to the IP address of the virtual gateway through the network card of any virtual machine; the virtual gateway forwards the first data acquisition request to the IP address of the network card of the host machine; through the IP address of the network card of the host machine, the first data acquisition request is sent to the external network according to the network protocol of the VPC network; the host machine sends the data packet fed back from the external network to the IP address of the network card of any virtual machine.
[0139] In one embodiment, the communication module 803 is specifically used for sending a second data acquisition request corresponding to the communication instruction to the IP address of the virtual gateway through the network card of any virtual machine when any virtual machine accesses the intranet through the network card of any virtual machine; sending the second data acquisition request to the intranet through the virtual gateway; and the host machine sending the data packet fed back from the intranet to the IP address of the network card of any virtual machine.
[0140] In one embodiment, the intranet includes at least one virtual machine; the extranet includes an LXC cluster, a k8s cluster and / or an Internet device.
[0141] In one embodiment, the virtual bridge comprises a linuxbridge bridge or an OVS bridge.
[0142] The present application provides a communication device based on a VPC network, which creates a virtual bridge in a host machine so that at least one virtual machine (vm) can be connected to the network of the host machine through the virtual bridge. Then configure the virtual gateway of the virtualized network segment for the virtual bridge, and set the gateway of the virtualized IP communication of at least one virtual machine on the virtual bridge. Thus, by building a virtual bridge and a virtual gateway, the host machine is used as a switch between at least one virtual machine and the internal and external networks, so that at least one virtual machine can communicate with the external network through the virtual gateway and the network card of the host machine, and at least one virtual machine can communicate with the internal network through the virtual gateway. Furthermore, a kvm virtualization solution based on a virtual private cloud service is realized, as well as mutual access and communication between IPs of different network segments of the host machine and the virtual machine. At the same time, the network intercommunication between a virtual machine and a container or multiple virtual machines is solved, so that the services deployed thereon can communicate and access each other, and the purpose of smoothly processing the communication between virtual machines and containers, or multiple virtual machines, is achieved without modifying the business code.
[0143] For the specific definition of the communication device based on the VPC network, please refer to the definition of the communication method based on the VPC network above, which will not be repeated here. Each module in the above-mentioned communication device based on the VPC network can be implemented in whole or in part by software, hardware and a combination thereof. The above-mentioned modules can be embedded in or independent of the processor in the computer device in the form of hardware, or can be stored in the memory of the computer device in the form of software, so that the processor can call and execute the operations corresponding to the above modules.
[0144] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor implements the following steps when executing the computer program:
[0145] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented: creating a virtual bridge in a host machine; configuring a virtual gateway of a virtualized network segment for the virtual bridge; bridging the gateway of at least one virtual machine to the virtual bridge, so that at least one virtual machine communicates with an external network through the virtual gateway and a network card of the host machine, and / or at least one virtual machine communicates with an internal network through the virtual gateway.
[0146] In one embodiment, a computer device is provided. The computer device may be a client, and its internal structure is shown in FIG. Fig. 9 As shown. The computer device includes a processor, a memory, a network interface, a display screen and an input device connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external server through a network connection. When the computer program is executed by the processor, it implements the functions or steps of a communication method based on a VPC network.
[0147] It should be noted that the above functions or steps that can be implemented by the computer-readable storage medium or computer device can correspond to the relevant description of the communication method based on the VPC network in the aforementioned method embodiment. To avoid repetition, they will not be described one by one here.
[0148] Those skilled in the art can understand that all or part of the processes in the above-mentioned embodiment methods can be completed by instructing the relevant hardware through a computer program, and the computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above-mentioned methods. Among them, any reference to memory, storage, database or other media used in the embodiments provided in this application can include non-volatile and / or volatile memory. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM) or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. As an illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDRSDRAM), enhanced SDRAM (ESDRAM), synchronous link (Synchlink) DRAM (SLDRAM), memory bus (Rambus) direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and memory bus dynamic RAM (RDRAM).
[0149] Those skilled in the art can clearly understand that for the convenience and simplicity of description, only the division of the above-mentioned functional units and modules is used as an example. In actual applications, the above-mentioned functions can be distributed and completed by different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0150] The embodiments described above are only used to illustrate the technical solutions of the present invention rather than to limit the same. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein; and these modifications or replacements do not deviate the essence of the corresponding technical solutions from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.
Claims
1. A communication method based on a VPC network, It is characterized in that The VPC network serves a host machine and at least one virtual machine, and the method includes: Creating a virtual network bridge in the host machine; Configuring a virtual gateway of a virtualized network segment for the virtual network bridge; Bridging the gateway of the at least one virtual machine to the virtual network bridge; In response to the communication instruction, the at least one virtual machine communicates with the network card of the host machine through the virtual gateway to communicate with the external network through the network card of the host machine, and the at least one virtual machine communicates with any virtual machine in the intranet through the virtual gateway, wherein the intranet includes the at least one virtual machine; The at least one virtual machine communicates with the intranet through the virtual gateway, including: In the case where any virtual machine accesses the intranet through the network card of any virtual machine, any virtual machine sends a second data acquisition request corresponding to the communication instruction to the IP address of the virtual gateway through the network card of any virtual machine; Sending the second data acquisition request to the intranet through the virtual gateway; The host machine sends the data packet fed back from the intranet to the IP address of the network card of any virtual machine.
2. The VPC network-based communication method according to claim 1, It is characterized in that The step of creating a virtual network bridge in the host machine includes: Get the configuration file; At the network layer of the OSI network model of the host machine, the virtual bridge is created according to the configuration file.
3. The communication method based on the VPC network according to claim 1, It is characterized in that The step of configuring a virtual gateway of a virtualized network segment for the virtual network bridge includes: Creating a VPC network interface on the host machine, wherein the VPC network interface is connected to the network card interface of the host machine; Allocate any available IP address in the virtualized network segment to the VPC network interface; Connect the VPC network interface to the virtual bridge.
4. The communication method based on the VPC network according to claim 1, It is characterized in that The at least one virtual machine communicates with an external network through the virtual gateway and the network card of the host machine, including: In the case where any virtual machine accesses the external network through the network card of any virtual machine, any virtual machine sends the first data acquisition request corresponding to the communication instruction to the IP address of the virtual gateway through the network card of any virtual machine; The virtual gateway forwards the first data acquisition request to the IP address of the network card of the host machine; Sending the first data acquisition request to the external network according to the network protocol of the VPC network through the IP address of the network card of the host machine; The host machine sends the data packet fed back from the external network to the IP address of the network card of any virtual machine.
5. The VPC network-based communication method according to any one of claims 1 to 4, It is characterized in that The external network includes an LXC cluster, a k8s cluster and / or Internet devices.
6. The VPC network-based communication method according to any one of claims 1 to 4, It is characterized in that The virtual bridge includes a Linux bridge or an OVS bridge.
7. A communication device based on a VPC network, It is characterized in that The VPC network serves at least one virtual machine and a host machine, and the device includes: A creation module, used to create a virtual network bridge in the host machine; A configuration module, used to configure a virtual gateway of a virtualized network segment for the virtual network bridge; a communication module, configured to connect a gateway of the at least one virtual machine to the virtual bridge; and In response to the communication instruction, the at least one virtual machine communicates with the network card of the host machine through the virtual gateway to communicate with the external network through the network card of the host machine, and the at least one virtual machine communicates with any virtual machine in the intranet through the virtual gateway, wherein the intranet includes the at least one virtual machine; The communication module is specifically used for sending the second data acquisition request corresponding to the communication instruction to the IP address of the virtual gateway through the network card of any virtual machine when any virtual machine accesses the intranet through the network card of any virtual machine; Sending the second data acquisition request to the intranet through the virtual gateway; The host machine sends the data packet fed back from the intranet to the IP address of the network card of any virtual machine.
8. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, It is characterized in that When the processor executes the computer program, the steps of the VPC network-based communication method according to any one of claims 1 to 6 are implemented.
9. A computer-readable storage medium storing a computer program. It is characterized in that When the computer program is executed by a processor, the steps of the VPC network-based communication method as claimed in any one of claims 1 to 6 are implemented.
Citation Information
Patent Citations
Method for virtual machines to share IP (Internet Protocol) of host machine to provide outer net services
CN105721630A
Container orchestration engine cluster management system based on virtual network bridge
CN112491984A