A network controller, an HTTP probe detection system, method and medium

By designing a network controller that includes rule processing, message processing and translation detection modules, it solves the difficulty of implementing cloud-native HTTP health checks when traditional data centers expand cloud-native capabilities on virtualization platforms, and realizes HTTP probe detection in a three-network separation environment, improving security and compatibility, and simplifying the operation process.

CN115622913BActive Publication Date: 2025-06-13LANGCHAO ELECTRONIC INFORMATION IND CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202211292992.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2022-10-21
Publication Date
2025-06-13
Estimated Expiration
2042-10-21

AI Technical Summary

Technical Problem

When traditional data centers expand cloud-native capabilities based on virtualization platforms, it is difficult to implement cloud-native HTTP health checks, especially in the networking method of separate networks, HTTP probes cannot cross the Node network to reach the container network, resulting in cloud-native functions being unusable.

Method used

A network controller is designed, including a rule processing module, a message processing module and a translation detection module. Logical rules are created through the rule processing module, the HTTP probe is converted into a UDP probe, and the HTTP probe is reconverted to an HTTP probe on the target container through the translation detection module, realizing the detection of the HTTP service status information of the container.

Benefits of technology

On the premise of ensuring the separation of the three networks, HTTP probe detection of cloud-native containers is realized, container functions are improved, and data centers have higher security and compatibility. At the same time, it provides a simple and easy-to-use operation UI, unify operation habits, and improve user experience and management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN115622913B_ABST
    Figure CN115622913B_ABST
Patent Text Reader

Abstract

The present application discloses a network controller, which relates to the technical field of cloud computing and includes a rule processing module, a packet processing module, and a translation detection module. The packet processing module converts the original HTTP probe into a UDP probe according to the logical rules issued by the rule processing module; then, the translation detection module loaded on the target container reconverts the UDP probe into an HTTP probe and detects the specific HTTP service status on the target container; finally, the translation detection module returns the HTTP service status information of the target container to the packet processing module again. On the premise of ensuring the separation of the three networks, the reachability of the target container network is detected through the UDP probe, and then the translation detection module sends an HTTP probe to detect the real HTTP service status information of the target container. The operation is consistent with the native container platform without a sense of fragmentation, and the operation is simple without learning costs, while improving the network security. The present invention also discloses an HTTP probe detection system, method, and medium, which have corresponding technical effects.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical field of cloud computing, and particularly to a network controller, an HTTP probe detection system, a method and a medium. Background Art

[0002] In the era of cloud computing, new technologies emerge in an endless stream. Along with the advancement of the containerization process, more and more data centers have deployed and applied container technology, and more and more services have also been containerized. Virtualization technology has occupied the dominant position in data centers during its continuous development process. However, the advancement of the containerization process shows an increasingly fast pace. Under the continuous encroachment of containerization, the proportion of virtualization in data centers is continuously decreasing. However, due to its early development, maturity, and large base, its position in data centers cannot be ignored. This has led to the situation that when traditional services are containerized, some services may still be run in the form of virtualization. This situation has resulted in the coexistence of virtualization and containerization in more and more data centers. Although more and more data centers are developing in the direction of coexistence of virtualization and containerization, two different phenomena have been found at the present stage: First, the data center expands the virtualization ability based on the Kubernetes (abbreviated as k8s, an open-source container scheduling platform) cloud-native platform; Second: The data center expands the cloud-native ability based on the traditional virtualization platform.

[0003] Although the final results of these two phenomena are the same, the technical details behind them are very different. For the technical route of expanding virtualization ability based on the cloud-native platform, its network requirements fully meet the needs of modern containerization, and direct communication can be carried out between each network. When expanding the virtualization ability, the networking requirements of the traditional three-network separation of virtualization are not considered too much; while for the technical route of expanding cloud-native ability based on the traditional virtualization platform, its network requirements must meet the networking requirements of the traditional three-network separation of virtualization, which is very different from the requirement that direct communication can be carried out between each network in cloud-native, resulting in the inability to implement some basic functions of cloud-native. For example, when Liveness (liveness detection) and Readiness (readiness detection) in cloud-native sense the status of the backend container through the form of executing commands or sending HTTP (Hyper Text Transfer Protocol) probes by the Kubernetes Node node for the decision-making of service traffic scheduling, due to the networking method of three-network separation, the Node node network and the container network are naturally isolated. When sensing the status of the backend container by sending HTTP probes, the HTTP probes cannot cross the Node network to reach the container network, so the status of the backend container cannot be sensed, and the decision-making of service traffic scheduling cannot be carried out, directly resulting in the inability to use cloud-native functions.

[0004] In summary, when expanding the cloud-native capabilities based on a virtualization platform in a traditional data center, how to implement the health check of cloud-native HTTP is a problem to be solved at present. Summary of the Invention

[0005] In view of this, the purpose of the present invention is to provide a network controller, an HTTP probe detection system, method and medium, which can solve the problem of implementing the health check of cloud-native HTTP when expanding the cloud-native capabilities based on a virtualization platform in a traditional data center. The specific solutions are as follows:

[0006] In a first aspect, the present application discloses a network controller, including:

[0007] A rule processing module, configured to obtain the detection information created by a user terminal for a target container on a UI interface. When the detection method determined after parsing the detection information is to perform detection through an HTTP probe, create a logical rule according to the container information of the target container, so as to send the logical rule and the detection information to a message processing module; find the network interface of the target container according to the container information, so as to load a translation detection module on the network interface;

[0008] A message processing module, configured to perform conversion and parsing of the probe on the received and transmitted information, convert the HTTP probe into a first UDP probe based on the logical rule according to the detection information sent by the rule processing module, and forward the first UDP probe to the target container; parse the second UDP probe sent by the translation detection module to obtain the HTTP service status information;

[0009] A translation detection module, configured to intercept the first UDP probe sent by the message processing module to the target container, convert the first UDP probe into the HTTP probe, obtain the HTTP service status information of the target container by using the HTTP probe, then encapsulate the HTTP service status information into the first UDP probe to obtain the second UDP probe, and return the second UDP probe to the message processing module.

[0010] Optionally, the rule processing module is specifically configured to obtain the detection probe specified by the user terminal for the target container in the UI interface and the probe protocol corresponding to the detection probe. When it is determined that the corresponding probe protocol is HTTP after monitoring the detection probe and parsing the detection probe, it is determined that the detection method is to perform detection through the HTTP probe, and then a logical rule is created according to the container information of the target container, so as to send the logical rule and the HTTP probe to the message processing module; find the network interface of the target container according to the container information, so as to load the translation detection module on the network interface; wherein, the detection probe includes Liveness and Readiness.

[0011] Optionally, the rule processing module is specifically configured to obtain the detection information created by the user terminal for the target container in the UI interface. When it is determined that the detection method is to perform detection through the HTTP probe after parsing the detection information, a logical rule including the source IP address, the target container address, the target container port, and the probe detection URL is created according to the container information of the target container, so as to send the logical rule and the detection information to the message processing module; find the network interface of the target container according to the container information, so as to load the translation detection module on the network interface.

[0012] Optionally, the rule processing module is further configured to create a logical rule according to the container information of the target container, and after sending the logical rule and the detection information to the message processing module, issue an OpenFlow flow table according to the current network topology information.

[0013] Optionally, the message processing module is specifically configured to perform conversion and parsing of the probe on the received and transmitted information. According to the detection information sent by the rule processing module, convert the HTTP probe into a UDP packet, encapsulate the target container address and the probe detection URL into the UDP packet to obtain a first UDP probe, and then forward the first UDP probe to the target container; parse the second UDP probe sent by the translation detection module to obtain the HTTP service status information.

[0014] Optionally, the message processing module is specifically configured to perform conversion and parsing of the probe on the received and transmitted information. According to the detection information sent by the rule processing module, convert the HTTP probe into a first UDP probe based on the logical rule, and forward the first UDP probe to the target container according to the OpenFlow flow table through a first preset sending instruction; parse the second UDP probe sent by the translation detection module according to the OpenFlow flow table through a second preset sending instruction to obtain the HTTP service status information.

[0015] Optionally, the translation detection module is specifically configured to intercept the first UDP probe sent by the packet processing module to the target container, parse the first UDP probe to obtain the target container port and the probe detection URL; re-determine the HTTP probe according to the target container port and the probe detection URL, and use the HTTP probe to obtain the HTTP service status information of the target container, then encapsulate the HTTP service status information into the first UDP probe to obtain the second UDP probe, and return the second UDP probe to the packet processing module.

[0016] In a second aspect, the present application discloses an HTTP probe detection method, including:

[0017] After the rule processing module in the network controller receives the detection information created by the user terminal for the target container in the UI interface, when the detection method determined after parsing the detection information is to detect through an HTTP probe, create a logical rule according to the container information of the target container, so as to send the logical rule and the detection information to the packet processing module; find the network interface of the target container according to the container information, so as to load the translation detection module on the network interface;

[0018] The packet processing module converts the HTTP probe into a first UDP probe based on the logical rule according to the detection information, and forwards the first UDP probe to the target container;

[0019] The network interface of the target container intercepts the first UDP probe through the loaded translation detection module, converts the first UDP probe into the HTTP probe, uses the HTTP probe to obtain the HTTP service status information of the target container, then encapsulates the HTTP service status information into the first UDP probe to obtain the second UDP probe, and returns the second UDP probe to the packet processing module;

[0020] The packet processing module parses the second UDP probe to obtain the HTTP service status information.

[0021] In a third aspect, the present application discloses an HTTP probe detection system, including: the network controller as described above, and a UI interface, a coordination module, an OVS bridge, and a target container;

[0022] The UI interface is used to create detection information for the target container;

[0023] The collaboration module is used to monitor the detection information and synchronize the detection information to the network controller;

[0024] The network controller is used to receive the detection information synchronized by the collaboration module and obtain the HTTP service status information of the target container;

[0025] The OVS bridge is used to provide a network interface for the target container, load the translation detection module in the network controller, and request an HTTP service from the target container through the OVS bridge;

[0026] The target container is used to return the HTTP service status information to the network controller through the OVS bridge.

[0027] In a fourth aspect, the present application discloses a computer-readable storage medium for storing a computer program; wherein when the computer program is executed by a processor, the HTTP probe detection method described above is implemented.

[0028] The network controller provided by the present invention includes a rule processing module, a message processing module, and a translation detection module. The rule processing module is used to obtain the detection information created by the user terminal for the target container in the UI interface. When the detection method determined after parsing the detection information is to detect through an HTTP probe, a logical rule is created according to the container information of the target container, so as to send the logical rule and the detection information to the message processing module; the network interface of the target container is found according to the container information, so as to load the translation detection module on the network interface; The message processing module is used to convert and parse the probe for the received and sent information. According to the detection information sent by the rule processing module, based on the logical rule, the HTTP probe is converted into a first UDP probe, and the first UDP probe is forwarded to the target container; the second UDP probe sent by the translation detection module is parsed to obtain the HTTP service status information; the translation detection module is used to intercept the first UDP probe sent by the message processing module to the target container, convert the first UDP probe into the HTTP probe, use the HTTP probe to obtain the HTTP service status information of the target container, and then encapsulate the HTTP service status information into the first UDP probe to obtain the second UDP probe, and return the second UDP probe to the message processing module. Thus, it can be seen that the message processing module of the network controller converts the original HTTP probe into a UDP probe according to the logical rule issued by the rule processing module, and then the translation detection module loaded on the target container converts the UDP probe back into an HTTP probe and detects the specific HTTP service status on the target container; finally, the translation detection module returns the HTTP service status information of the target container to the message processing module. On the premise of ensuring the separation of the three networks, the reachability of the target container network is detected through the UDP probe, and then the translation detection module sends an HTTP probe to detect the real HTTP service status information of the target container. Without destroying the separation of the three networks, the container function is improved, so that the data center has higher security and compatibility while having virtualization and container capabilities. In addition, a simple and easy-to-use operation UI is provided, which shields the underlying differences. The container is consistent with the native container platform when using the HTTP probe for detection, without a sense of fragmentation, and the operation is simple and there is no learning cost. The user cannot perceive the underlying differences. Since the network topology has not changed, the traditional virtualization services have no changes when using the system, unifying the operation habits and greatly improving the user experience and management efficiency.

[0029] Correspondingly, the embodiment of the present invention also provides an HTTP probe detection system, method, and readable storage medium corresponding to the above network controller, which have the above technical effects and will not be repeated here. Description of the Drawings

[0030] To more clearly illustrate the technical solutions in the embodiments of the present invention or in the prior art, the following will briefly introduce the accompanying drawings required for the description of the embodiments or the prior art. Obviously, the accompanying drawings in the following description are only the embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can be obtained according to the provided accompanying drawings.

[0031] Figure 1 Schematic diagram of a network controller structure disclosed in the present application;

[0032] Figure 2 Flowchart of an HTTP probe detection method disclosed in the present application;

[0033] Figure 3 Schematic diagram of an HTTP probe detection system structure disclosed in the present application. Detailed implementation manners

[0034] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.

[0035] Currently, for the technical route of expanding the capabilities of cloud native based on traditional virtualization platforms, the requirements for its network meet the networking requirements of the traditional virtualization three-network separation, which is very different from the requirement that direct communication can be achieved between various networks in cloud native, resulting in the inability to implement some basic functions of cloud native.

[0036] Therefore, the present application provides a network controller, which can solve the problem of realizing the health check of cloud native HTTP when expanding the capabilities of cloud native based on a virtualization platform in a traditional data center.

[0037] An embodiment of the present invention discloses a network controller. Refer to Figure 1 As shown, the network controller includes: a rule processing module, a message processing module, and a translation detection module;

[0038] The rule processing module 11 is configured to obtain the detection information created by the user terminal for the target container on the UI interface. When the detection method determined after parsing the detection information is to perform detection through an HTTP probe, create a logical rule according to the container information of the target container, so as to send the logical rule and the detection information to the message processing module; find the network interface of the target container according to the container information, so as to load the translation detection module on the network interface.

[0039] At present, due to various factors such as a large number of existing services in traditional data centers that cannot be interrupted and security considerations, when expanding cloud-native capabilities, the network topology of the separation of the three networks will not be changed. This results in the inability to implement some cloud-native capabilities during the separation of the three networks, restricting the application of cloud-native in data centers. For example, the Liveness and Readiness of cloud-native normally sense the status of backend containers through commands executed by Kubernetes Node nodes or by sending TCP (Transmission Control Protocol) / HTTP probes to make decisions on service traffic scheduling. However, in the networking mode of the separation of the three networks, the Node node network and the container network are naturally isolated. When sensing the status of backend containers by sending TCP / HTTP probes, due to network isolation, the TCP / HTTP probes cannot cross the Node network to reach the container network, so the status of the backend containers cannot be sensed, and decisions on service traffic scheduling cannot be made, directly resulting in the inability to use cloud-native functions.

[0040] It can be understood that the Openflow flow table supports network functions below the fourth layer well. Through the network controller, the Openflow flow table can be issued to send UDP (User Datagram Protocol), TCP and other packets to implement the detection function of the backend. However, for advanced network protocols such as HTTP, they cannot be processed by the flow table. This enables the TCP probe detection to conveniently use the functions of the network controller, but for HTTP probe detection, the current network controller cannot implement it yet.

[0041] Therefore, the embodiments of this application can implement the HTTP probe detection network function of containers through the network controller while retaining the separation of the three networks in traditional virtualization. First, the user can conveniently and quickly specify the detection probe and the detection protocol for the virtual container through the UI (User Interface) interface. Among them, the detection probe is the Liveness detection or Readiness detection specified according to the user's needs. The user can specify to detect in the way of command line, TCP or HTTP. The command line and TCP detections can be implemented using current technologies, but the HTTP method has no current technology implementation in the three-network separation environment. Therefore, the detection method of detecting through the HTTP probe will be specifically described.

[0042] In an embodiment of the present application, when the corresponding probe protocol is determined to be HTTP after parsing the detection probe, it is determined that the current detection method is to detect through the HTTP probe. At this time, the rule processing module of the network controller creates a logical rule based on the container information of the target container. It should be pointed out that the container information of the target container can be obtained through preset instructions, and the created logical rules are mainly source IP address, target container address, target container port, probe detection URL (Uniform Resource Locator) and other information.

[0043] It is understandable that sending flow tables is a common technology for network controllers, that is, sending Openflow flow tables based on the existing network topology information of the network controller to open up the network forwarding link to the target container. Therefore, after creating the logical rules, the flow tables are sent to guide the forwarding of the HTTP probe, and finally the network interface of the target container is found, and the translation detection module is loaded on the target network interface. In addition, when the container is deleted, the rule processing module of the network controller will synchronously delete the corresponding logical rules and flow tables.

[0044] The message processing module 12 is used to convert and parse the probe of the sent and received information. According to the detection information sent by the rule processing module, the HTTP probe is converted into a first UDP probe based on the logical rule, and the first UDP probe is forwarded to the target container; the second UDP probe sent by the translation detection module is parsed to obtain the HTTP service status information.

[0045] In an embodiment of the present application, the message processing module of the network controller will obtain the rules issued by the rule processing module of the network controller, and will be responsible for converting and parsing the sent and received information. Since the network controller cannot directly establish a socket connection with the container and send an HTTP probe, the message processing module converts the HTTP probe into a UDP message and sends it out. Then, the UDP message can be forwarded according to the flow table to realize the back-end detection function, that is, the reachability of the target container network is realized through UDP probe detection. The message processing module can obtain the target container address, such as MAC address, IP address, etc., and then encapsulate the UDP message, and at the same time encapsulate the HTTP probe detection URL into the UDP message to obtain the first UDP probe.

[0046] In the embodiment of the present application, the message processing module also receives the response message returned by the translation detection module, that is, the second UDP probe including the HTTP service status information of the target container returned by the translation detection module. After parsing the second UDP probe, the message processing module obtains the HTTP probe detection result, obtains the HTTP service status information and saves it.

[0047] In an embodiment of the present application, when converting an HTTP probe into a first UDP probe, after the packet encapsulation is completed, the controller sends a packet instruction through the pkt_out network controller according to the flow table to send out the first UDP probe and perform network forwarding. Correspondingly, when parsing the received second UDP probe, the second UDP probe is matched by the flow table issued by the rule processing module, and the packet instruction is received through the pkt_in network controller and sent to the packet processing module through the translation detection module.

[0048] The translation detection module 13 is configured to intercept the first UDP probe sent by the packet processing module to the target container, convert the first UDP probe into the HTTP probe, obtain the HTTP service status information of the target container by using the HTTP probe, then encapsulate the HTTP service status information into the first UDP probe to obtain the second UDP probe, and return the second UDP probe to the packet processing module.

[0049] In an embodiment of the present application, the translation detection module is responsible for intercepting the first UDP probe sent by the packet processing module. Since the UDP probe cannot detect the true state of the HTTP service, the first UDP probe is converted into an HTTP probe. Specifically, after intercepting the first UDP probe, the translation module parses the first UDP probe to obtain the target container port and the probe detection URL requested by the HTTP probe; according to the above information, the HTTP probe packet is re-encapsulated, that is, the HTTP probe is re-determined to request the HTTP service status information of the target container.

[0050] It should be noted that the translation detection module does not process other normal data packets. When the HTTP service of the target container returns a packet, the translation detection module parses the response packet to obtain the HTTP service status information of the target container, and then encapsulates the HTTP service status information into the first UDP probe to obtain the second UDP probe and sends it back to the packet processing module of the controller.

[0051] The network controller provided by the present invention includes a rule processing module, a message processing module, and a translation detection module. The rule processing module is used to obtain the detection information created by the user terminal for the target container in the UI interface. When the detection method determined after parsing the detection information is to detect through an HTTP probe, a logical rule is created according to the container information of the target container, so as to send the logical rule and the detection information to the message processing module; the network interface of the target container is found according to the container information, so as to load the translation detection module on the network interface; the message processing module is used to perform conversion and parsing of the probe on the received and sent information. According to the detection information sent by the rule processing module, the HTTP probe is converted into a first UDP probe based on the logical rule, and the first UDP probe is forwarded to the target container; the second UDP probe sent by the translation detection module is parsed to obtain the HTTP service status information; the translation detection module is used to intercept the first UDP probe sent by the message processing module to the target container, convert the first UDP probe into the HTTP probe, use the HTTP probe to obtain the HTTP service status information of the target container, then encapsulate the HTTP service status information into the first UDP probe to obtain the second UDP probe, and return the second UDP probe to the message processing module. Thus, it can be seen that the message processing module of the network controller converts the original HTTP probe into a UDP probe according to the logical rule issued by the rule processing module, and then the translation detection module loaded on the target container converts the UDP probe back into an HTTP probe and detects the specific HTTP service status on the target container; finally, the translation detection module returns the HTTP service status information of the target container to the message processing module. On the premise of ensuring the separation of the three networks, the reachability of the target container network is detected through the UDP probe, and then the translation detection module sends the HTTP probe to detect the real HTTP service status information of the target container. Without destroying the separation of the three networks, the container function is improved, so that the data center has higher security and compatibility while having virtualization and container capabilities. In addition, a simple and easy-to-use operation UI is provided, which shields the underlying differences. The container is consistent with the native container platform when using the HTTP probe for detection without a sense of fragmentation, and the operation is simple and there is no learning cost. The user cannot perceive the underlying differences. Since the network topology has not changed, the traditional virtualization services have no changes when using the system, unifying the operation habits and greatly improving the user experience and management efficiency.

[0052] The embodiment of the present application discloses an HTTP probe detection method. Refer to Figure 2 as shown, the method includes:

[0053] Step S11: After the rule processing module in the network controller receives the detection information created by the user terminal for the target container in the UI interface, when the detection method determined after parsing the detection information is detection through an HTTP probe, a logical rule is created according to the container information of the target container, so as to send the logical rule and the detection information to the packet processing module.

[0054] In the embodiment of the present application, it is mainly applied to the scenario of hybrid deployment of virtualization and cloud native in a large-scale data center environment. The user creates the detection information of the target container through the UI interface. For example, the user can specify Liveness or Readiness for the container and specify the detection protocol. In this way, a simple and easy-to-use operation UI is provided, shielding the underlying differences. The container is consistent with the native Kubernetes in using the HTTP probe for detection, shielding the underlying technical implementation details and reducing the user's learning cost.

[0055] In the embodiment of the present application, due to the particularity of HTTP probe detection, when the detection method determined after parsing the detection information is detection through an HTTP probe, a logical rule is created according to the container information of the target container, so as to send the logical rule and the detection information to the packet processing module. Correspondingly, when the user deletes the container or deletes the Liveness or Readiness detection specified for the container on the UI, the rule processing module is responsible for cleaning up the issued logical rules.

[0056] Step S12: Find the network interface of the target container according to the container information, so as to load the translation detection module on the network interface.

[0057] In the embodiment of the present application, the rule processing module of the network controller finds the container network interface according to the container information, issues a flow table to guide the forwarding of the HTTP probe, and at the same time loads the translation detection module on the network interface of the target container.

[0058] Step S13: The packet processing module converts the HTTP probe into a first UDP probe based on the logical rule according to the detection information, and forwards the first UDP probe to the target container.

[0059] In the embodiment of the present application, due to the particularity of HTTP detection, high-level network protocols such as HTTP cannot be processed through the flow table. Therefore, the HTTP probe is converted into a first UDP probe and sent, and at the same time, information such as the HTTP probe detection URL and the target container port is encapsulated into the UDP packet and sent to the target container. In this way, the backend detection function can be realized by using the flow table to send UDP packets.

[0060] Step S14: The network interface of the target container intercepts the first UDP probe through the load translation detection module, converts the first UDP probe into an HTTP probe, obtains the HTTP service status information of the target container by using the HTTP probe, then encapsulates the HTTP service status information into the first UDP probe to obtain a second UDP probe, and returns the second UDP probe to the packet processing module.

[0061] In the embodiment of the present application, after the first UDP probe sent by the packet processing module is forwarded to the target container network interface through the flow table, the translation detection module captures and intercepts the first UDP probe. Since the UDP probe cannot detect the true state of the HTTP service, the translation detection module will parse the intercepted first UDP probe, extract the true HTTP request information from the packet, then re-encapsulate the HTTP packet to obtain an HTTP probe, use the HTTP probe to request the URL page specified by the target container, and wait for the return of the page at the same time. After receiving the return information, the translation detection module parses the return information to obtain the detection result, and re-encapsulates the detection result into a UDP packet to obtain a second UDP probe and send it out. Finally, the second UDP probe is matched by the flow table issued by the rule processing module of the network controller and sent to the packet processing module of the network controller through the pkt_in action.

[0062] Step S15: The packet processing module parses the second UDP probe to obtain the HTTP service status information.

[0063] In the embodiment of the present application, after receiving the responded second UDP probe, the packet processing module parses the second UDP probe, obtains the HTTP service status information specified by the target container encapsulated in the packet and saves it.

[0064] The HTTP probe detection method provided by the present invention converts the original HTTP probe into a UDP probe through the message processing module of the network controller according to the logical rules issued by the rule processing module, and then the translation detection module loaded on the target container reconverts the UDP probe into an HTTP probe and detects the specific HTTP service status on the target container; finally, the translation detection module returns the HTTP service status information of the target container to the message processing module. On the premise of ensuring the separation of the three networks, the reachability of the target container network is detected through the UDP probe, and then the translation detection module sends an HTTP probe to detect the real HTTP service status information of the target container. Without damaging the separation of the three networks, the container function is improved, so that the data center has higher security and compatibility while having virtualization and container capabilities. In addition, a simple and easy-to-use operation UI is provided, which shields the underlying differences. The container is consistent with the native container platform when using the HTTP probe detection without a sense of fragmentation, and the operation is simple and there is no learning cost. Users cannot perceive the underlying differences. Since the network topology has not changed, the traditional virtualization services have no changes when using the system, unifying the operation habits and greatly improving the user experience and management efficiency.

[0065] Correspondingly, an embodiment of the present application discloses an HTTP probe detection system. Refer to Figure 3 As shown, the HTTP probe detection system described below can be correspondingly referred to the network controller described above.

[0066] The system includes: the network controller as described above, and a UI interface, a coordination module, an OVS bridge, and a target container;

[0067] The UI interface is used to create detection information for the target container;

[0068] In this embodiment, a simple and easy-to-use operation UI is provided, which shields the underlying differences. The UI interface is responsible for providing a configuration entry for users. Through the UI interface, users can specify Liveness or Readiness for the container and specify the detection protocol.

[0069] The coordination module is used to monitor the detection information and synchronize the detection information to the network controller;

[0070] In this embodiment, the coordination module is a bridge from the native detection method to the detection method using the network controller, and is mainly responsible for monitoring the creation of detection information and the rule of synchronizing the detection information to the rule processing module of the network controller. Specifically, the coordination module monitors the Liveness or Readiness specified when Kubernetes creates a container and parses the detection method. When the detection method is specified as HTTP, the coordination module synchronizes the container information and the detection information to the rule processing module of the network controller.

[0071] The network controller is configured to receive the detection information synchronized by the collaboration module and obtain the HTTP service status information of the target container;

[0072] Among them, for the more specific working process of the above network controller, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details are not described herein again.

[0073] The OVS bridge is configured to provide a network interface for the target container, load the translation detection module in the network controller, and request the HTTP service from the target container through the OVS bridge;

[0074] In this embodiment, the OVS (Open vSwitch) bridge is a bridge for communication between the target container and the network controller. The HTTP probe passes through the interface from the network controller to the OVS bridge, and then performs flow table matching to determine the network interface of the target container, enabling the network controller to load the translation detection module on the network interface of the target container. In addition, the target container also returns its actual HTTP service status information to the network controller through the OVS bridge.

[0075] The target container is configured to return the HTTP service status information to the network controller through the OVS bridge.

[0076] Through the close cooperation of the above-mentioned modules, in a three-network separation environment, the network controller provides Liveness or Readiness HTTP probe detection for the target container.

[0077] It can be seen that through the above solution of this embodiment, the message processing module of the network controller converts the original HTTP probe into a UDP probe according to the logical rules issued by the rule processing module, and then the translation detection module loaded on the target container converts the UDP probe back into an HTTP probe and detects the specific HTTP service status on the target container. Finally, the translation detection module returns the HTTP service status information of the target container to the message processing module. On the premise of ensuring the separation of the three networks, the reachability of the target container network is detected through the UDP probe, and then the translation detection module sends an HTTP probe to detect the real HTTP service status information of the target container. Without destroying the separation of the three networks, the container function is improved, so that the data center has higher security and compatibility while having virtualization and container capabilities. In addition, a simple and easy-to-use operation UI is provided, which shields the underlying differences. The container is consistent with the native container platform when using the HTTP probe for detection without a sense of fragmentation, and the operation is simple and there is no learning cost. Users cannot perceive the underlying differences. Since the network topology has not changed, the traditional virtualization services have no changes when using the system, unifying the operation habits and greatly improving the user experience and management efficiency.

[0078] Furthermore, the embodiment of the present application also discloses a computer-readable storage medium. The computer-readable storage medium mentioned here includes random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disks, magnetic disks, or optical discs or any other form of storage medium well-known in the technical field. Among them, when the computer program is executed by the processor, the foregoing HTTP probe detection method is implemented. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.

[0079] The various embodiments in this specification are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. The same or similar parts among the various embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the description of the method part.

[0080] The steps of the HTTP probe detection or algorithm described in combination with the embodiments disclosed in this article can be implemented directly by hardware, software modules executed by a processor, or a combination of both. The software module can be placed in random access memory (RAM), memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disks, removable disks, CD-ROMs, or any other form of storage medium well-known in the technical field.

[0081] Finally, it should also be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variant thereof is intended to cover non-exclusive inclusion, such that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the said element.

[0082] The above has introduced in detail a network controller, an HTTP probe detection system, a method and a medium provided by the present invention. Specific examples are used in this document to elaborate on the principle and implementation manner of the present invention. The description of the above embodiments is only used to help understand the method and its core idea of the present invention; at the same time, for those of ordinary skill in the art, according to the idea of the present invention, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present invention.

Claims

1. A network controller, characterized in that, it includes: A rule processing module, configured to obtain the detection information created by the user terminal for the target container in the UI interface. When the detection method determined after parsing the detection information is detection through an HTTP probe, create a logical rule according to the container information of the target container, so as to send the logical rule and the detection information to the message processing module; find the network interface of the target container according to the container information, so as to load a translation detection module on the network interface; the logical rule includes a source IP address, a target container address, a target container port, and a probe detection URL; A message processing module, configured to perform conversion and parsing of the probe on the received and transmitted information, and based on the logical rule, convert the HTTP probe into a first UDP probe according to the detection information sent by the rule processing module, and forward the first UDP probe to the target container; Parse the second UDP probe sent by the translation detection module to obtain the HTTP service status information; A translation detection module, configured to intercept the first UDP probe sent by the message processing module to the target container, convert the first UDP probe into the HTTP probe, use the HTTP probe to obtain the HTTP service status information of the target container, and then encapsulate the HTTP service status information into the first UDP probe to obtain the second UDP probe, and return the second UDP probe to the message processing module.

2. The network controller according to claim 1, characterized in that, The rule processing module is specifically configured to obtain the detection probe specified by the user terminal for the target container in the UI interface and the probe protocol corresponding to the detection probe. When it is determined that the corresponding probe protocol is HTTP after monitoring the detection probe and parsing the detection probe, it is determined that the detection method is detection through an HTTP probe, and then create a logical rule according to the container information of the target container, so as to send the logical rule and the HTTP probe to the message processing module; find the network interface of the target container according to the container information, so as to load a translation detection module on the network interface; wherein, the detection probe includes Liveness and Readiness.

3. The network controller according to claim 1, characterized in that, The rule processing module is specifically configured to obtain the detection information created by the user terminal for the target container in the UI interface. When the detection method determined after parsing the detection information is detection through an HTTP probe, create a logical rule including a source IP address, a target container address, a target container port, and a probe detection URL according to the container information of the target container, so as to send the logical rule and the detection information to the message processing module; find the network interface of the target container according to the container information, so as to load a translation detection module on the network interface.

4. The network controller according to claim 1, It is characterized in that the rule processing module is further configured to create a logical rule according to the container information of the target container, so that after sending the logical rule and the detection information to the message processing module, an OpenFlow flow table is issued according to the current network topology information.

5. The network controller according to claim 3, It is characterized in that the message processing module is specifically configured to convert and analyze the probe of the received and transmitted information, and convert the HTTP probe into a UDP packet according to the detection information sent by the rule processing module, and encapsulate the target container address and the probe detection URL into the UDP packet to obtain a first UDP probe, and then forward the first UDP probe to the target container; Analyze the second UDP probe sent by the translation detection module to obtain the HTTP service status information.

6. The network controller according to claim 4, It is characterized in that the message processing module is specifically configured to convert and analyze the probe of the received and transmitted information, convert the HTTP probe into a first UDP probe based on the logical rule according to the detection information sent by the rule processing module, and forward the first UDP probe to the target container through a first preset sending instruction according to the OpenFlow flow table; Analyze the second UDP probe sent by the translation detection module through a second preset sending instruction according to the OpenFlow flow table to obtain the HTTP service status information.

7. The network controller according to claim 3, It is characterized in that the translation detection module is specifically configured to intercept the first UDP probe sent by the message processing module to the target container, and analyze the first UDP probe to obtain the target container port and the probe detection URL; Redetermine the HTTP probe according to the target container port and the probe detection URL, and use the HTTP probe to obtain the HTTP service status information of the target container, then encapsulate the HTTP service status information into the first UDP probe to obtain the second UDP probe, and return the second UDP probe to the message processing module.

8. An HTTP probe detection method, It is characterized in that including: After the rule processing module in the network controller receives the detection information created by the user terminal for the target container on the UI interface, when the detection method determined after analyzing the detection information is detection through an HTTP probe, a logical rule is created according to the container information of the target container, so as to send the logical rule and the detection information to the message processing module; find the network interface of the target container according to the container information, so as to load the translation detection module on the network interface; the logical rule includes the source IP address, the target container address, the target container port, and the probe detection URL; The message processing module converts the HTTP probe into a first UDP probe based on the logical rule according to the detection information, and forwards the first UDP probe to the target container; The network interface of the target container intercepts the first UDP probe through the loading and translation detection module, converts the first UDP probe into the HTTP probe, obtains the HTTP service status information of the target container by using the HTTP probe, then encapsulates the HTTP service status information into the first UDP probe to obtain a second UDP probe, and returns the second UDP probe to the message processing module; The message processing module parses the second UDP probe to obtain the HTTP service status information.

9. An HTTP probe detection system, characterized in that, it includes: the network controller according to any one of claims 1 to 7, and a UI interface, a collaboration module, an OVS bridge and a target container; the UI interface is used to create detection information for the target container; the collaboration module is used to monitor the detection information and synchronize the detection information to the network controller; the network controller is used to receive the detection information synchronized by the collaboration module and obtain the HTTP service status information of the target container; the OVS bridge is used to provide a network interface for the target container and load the translation detection module in the network controller, and request the HTTP service from the target container through the OVS bridge; the target container is used to return the HTTP service status information to the network controller through the OVS bridge.

10. A computer-readable storage medium, characterized in that, it is used to store a computer program; wherein when the computer program is executed by a processor, it implements the HTTP probe detection method according to claim 8.

Citation Information

Patent Citations

  • Method, server and system for measuring network performance and network probe

    CN103929341A

  • Network fault processing system

    CN106789177A