A method, apparatus, storage medium, and electronic device for data transmission
By constructing virtual communication ports on the target nodes of the computing cluster and assigning addresses and rules, the problem of direct data transmission between different computing clusters is solved, achieving efficient cross-cluster data transmission and ensuring the normal operation of applications.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-18
- Publication Date
- 2026-04-03
AI Technical Summary
Network isolation between different computing clusters prevents direct data transmission, impacting the deployment and operational efficiency of large applications.
Virtual communication ports are built on the target nodes of the computing cluster, and communication addresses and rules are assigned to these ports. Data transmission across the cluster is achieved by encapsulating data packets.
Direct data transmission between network-isolated computing clusters is achieved, ensuring the operational efficiency of applications.
Smart Images

Figure CN116074094B_ABST
Abstract
Description
Technical Field
[0001] This specification relates to the field of computer technology, and in particular to a method, apparatus, storage medium and electronic device for data transmission. Background Technology
[0002] With the development of technology, some large-scale applications have emerged. These applications usually contain a large amount of data and require the use of large-scale models, making it impossible for a single computing cluster to meet their computing tasks. Therefore, the multi-domain, multi-cluster program deployment mode has emerged, which allows these large applications to be allocated to computing nodes in different computing clusters to perform computing tasks.
[0003] However, to ensure the security of data transmission, the networks between different computing clusters are currently isolated from each other. This requires computing nodes deployed in different computing clusters to forward data through an additional third-party server, which prevents direct data transmission between different computing clusters. This seriously affects the deployment and operation of applications.
[0004] Therefore, how to enable computing nodes in different computing clusters to communicate directly and ensure the deployment and operation of large programs on different computing clusters is an urgent problem to be solved. Summary of the Invention
[0005] This specification provides a method, apparatus, storage medium, and electronic device for data transmission, in order to partially solve the aforementioned problems existing in the prior art.
[0006] The following technical solution is adopted in this specification:
[0007] This specification provides a method for data transmission, including:
[0008] At least one node is selected from the nodes in the first computing cluster as the target node, wherein the networks of different computing clusters are isolated from each other.
[0009] A virtual communication port is constructed on the target node as a first communication port, and a virtual communication port is constructed on at least some nodes in the second computing cluster as a second communication port;
[0010] Determine the first communication address to be assigned to the first communication port, and the second communication address to be assigned to the second communication port;
[0011] The first communication address is used as the source communication address corresponding to the target data that the first computing cluster needs to transmit, and the communication rules corresponding to the first communication port are determined according to the second communication address.
[0012] The target data is encapsulated to obtain encapsulated data, and the target communication address corresponding to the encapsulated data is determined based on the communication addresses corresponding to at least some nodes in the second computing cluster.
[0013] Based on the communication rules, the encapsulated data is sent from the source communication address to the target communication address.
[0014] Optionally, the target communication address corresponding to the encapsulated data is determined based on the communication addresses corresponding to at least some nodes in the second computing cluster, specifically including:
[0015] The Internet Protocol IP addresses corresponding to at least some of the nodes in the second computing cluster are used as the target communication addresses.
[0016] Optionally, based on the second communication address, the communication rules corresponding to the first communication port are determined, specifically including:
[0017] The communication rules are determined based on the IP addresses corresponding to at least some of the nodes, the Classless Inter-Domain Routing (CIDR) block value corresponding to the second computing cluster, the IP addresses corresponding to the container groups in at least some of the nodes, and the Media Access Control (MAC) address corresponding to the second communication port.
[0018] Optionally, based on the second communication address, the communication rules corresponding to the first communication port are determined, specifically including:
[0019] Based on the IP addresses corresponding to the at least some nodes, determine the bridge forwarding rule corresponding to the first communication port, determine the routing rule corresponding to the first communication port based on the Classless Inter-Domain Routing (CIDR) block value corresponding to the second computing cluster, and determine the address resolution rule corresponding to the first communication port based on the IP addresses corresponding to the container groups in the at least some nodes and the Media Access Control (MAC) address corresponding to the second communication port.
[0020] The communication rules are determined based on the bridge forwarding rules, the routing rules, and the address resolution rules.
[0021] Optionally, based on the second communication address, the communication rules corresponding to the first communication port are determined, specifically including:
[0022] Based on the CIDR block value corresponding to the second computing cluster, determine the routing rules corresponding to other nodes in the first computing cluster; and based on the IP address corresponding to the container group in each node of the second computing cluster and the MAC address corresponding to the cluster communication port built on the other nodes, determine the address resolution rules corresponding to the other nodes.
[0023] Based on the routing rules and address resolution rules of the other nodes, the communication rules of the other nodes are determined.
[0024] Optionally, based on the communication rules, sending the encapsulated data from the source communication address to the target communication address specifically includes:
[0025] Based on the communication rules corresponding to the first communication port and the communication rules corresponding to the other nodes, the target data is transmitted from the other nodes to the node corresponding to the target communication address.
[0026] Optionally, the method further includes: constructing intra-cluster communication ports on each node;
[0027] The communication rules further include: if the source IP address contained in the source communication address belongs to the same subnet as the IP address corresponding to the intra-cluster communication port deployed on the node of the second computing cluster, then the source MAC address and source IP address contained in the source communication address are replaced with the MAC address and IP address corresponding to the intra-cluster communication port deployed on the node of the second computing cluster.
[0028] Optionally, the target data is encapsulated to obtain encapsulated data, and the target communication address corresponding to the encapsulated data is determined based on the communication addresses corresponding to at least some nodes in the second computing cluster. Specifically, this includes:
[0029] The initial data packet of the target data is sent to the first communication port through the target node in the first computing cluster. The initial data packet carries the source IP address, source MAC address and target IP address of the target data.
[0030] Determine whether the target IP address and the IP address corresponding to the first communication port belong to the same subnet;
[0031] If not, the IP address and MAC address corresponding to the first communication port shall be used as the source IP address and the source MAC address;
[0032] The initial data packet is encapsulated in a first data packet, and the IP addresses corresponding to at least some nodes in the second computing cluster are set to the target IP addresses corresponding to the first data packet.
[0033] Optionally, based on the communication rules, sending the encapsulated data from the source communication address to the target communication address specifically includes:
[0034] Based on the communication rules, the first data packet is transmitted from the IP address corresponding to the first communication port to the target IP address corresponding to the first data packet.
[0035] Optionally, before sending the initial data packet of the target data to the first communication port via the target node in the first computing cluster, the method further includes:
[0036] Obtain the initial data packet sent by the specified container group in the first computing cluster through the specified device, and use the IP address corresponding to the specified container group as the source IP address of the initial data packet, and use the IP address corresponding to the transmission target as the destination IP address of the initial data packet;
[0037] The initial data packet is sent to the pre-built intra-cluster communication port on the node where the specified container group is located;
[0038] Determine whether the target IP address and the IP address corresponding to the communication port within the cluster belong to the same subnet. If not, use the IP address and MAC address corresponding to the communication port within the cluster as the source IP address and the source MAC address.
[0039] The initial data packet is encapsulated in a second data packet, and the IP address corresponding to the target node is set to the target IP address corresponding to the second data packet;
[0040] Through the cluster communication port, the second data packet is sent from the IP address corresponding to the cluster communication port to the target IP address corresponding to the second data packet, according to the communication rules corresponding to the specified node.
[0041] Optionally, the second data packet is sent from the IP address corresponding to the intra-cluster communication port to the target IP address corresponding to the second data packet according to the communication rules corresponding to the specified node via the intra-cluster communication port, specifically including:
[0042] After the target node receives the second data packet, it parses the second data packet to obtain the initial data packet.
[0043] Optionally, the method further includes:
[0044] After the target node in the second computing cluster receives the first data packet, it parses the first data packet to obtain the initial data packet;
[0045] The IP address and MAC address of the pre-configured intra-cluster communication port on the node in the computing cluster are used as the source IP address and source MAC address of the initial data packet.
[0046] The initial data packet is encapsulated in a third data packet, and the third data packet is sent to the transmission target.
[0047] Optionally, the initial data packet is encapsulated in a third data packet, and the third data packet is sent to the transmission target, specifically including:
[0048] After the transmission target receives the third data packet, it parses the third data packet to obtain the initial data packet;
[0049] The initial data packet is forwarded to the application deployed within the container group corresponding to the transmission target.
[0050] This specification provides a data transmission apparatus including:
[0051] The selection module selects at least one node from the nodes contained in the first computing cluster as the target node, wherein the networks of different computing clusters are isolated from each other.
[0052] The module constructs a virtual communication port on the target node as a first communication port, and constructs virtual communication ports on at least some nodes in the second computing cluster as second communication ports.
[0053] The first determining module determines a first communication address allocated to the first communication port and a second communication address allocated to the second communication port;
[0054] The second determining module uses the first communication address as the source communication address corresponding to the target data that the first computing cluster needs to transmit, and determines the communication rules corresponding to the first communication port based on the second communication address.
[0055] The encapsulation module encapsulates the target data to obtain encapsulated data, and determines the target communication address corresponding to the encapsulated data based on the communication addresses corresponding to at least some nodes in the second computing cluster.
[0056] The sending module, based on the communication rules, sends the encapsulated data from the source communication address to the target communication address.
[0057] This specification provides a computer-readable storage medium storing a computer program that, when executed by a processor, implements the above-described method for data transmission.
[0058] This specification provides an electronic device, including a memory, a processor, and a computer program stored in the memory and executable on the processor, wherein the processor executes the program to implement the aforementioned data transmission method.
[0059] The above-mentioned technical solutions adopted in this specification can achieve the following beneficial effects:
[0060] The data transmission method provided in this specification includes: selecting a target node among the nodes in a first computing cluster, constructing a first communication port on the target node, and constructing a second communication port on a node in a second computing cluster; determining a first communication address allocated to the first communication port and a second communication address allocated to the second communication port; using the first communication address as the source communication address; determining communication rules based on the second communication address; encapsulating the target data; determining the target communication address corresponding to the encapsulated data based on the communication addresses corresponding to at least some nodes in the second computing cluster; and then sending the encapsulated data from the source communication address to the target communication address based on the communication rules.
[0061] As can be seen from the above method, this solution can select target nodes from various nodes in different computing clusters and configure virtual communication ports. Based on the communication addresses of these virtual communication ports, communication rules between different clusters can be determined. This allows for data transmission between network-isolated computing clusters based on the configured communication rules, ensuring the operational efficiency of the application. Attached Figure Description
[0062] The accompanying drawings, which are included to provide a further understanding of this specification and form part of this specification, illustrate exemplary embodiments and are used to explain this specification, but do not constitute an undue limitation thereof. In the drawings:
[0063] Figure 1 This is a flowchart illustrating a data transmission method provided in this specification;
[0064] Figure 2 This is a schematic diagram of a communication structure between different computing clusters provided in this specification;
[0065] Figure 3 This is a schematic diagram of a communication rule provided in this specification;
[0066] Figure 4 This is a schematic diagram of a data transmission device provided in this specification;
[0067] Figure 5 The one provided in this specification corresponds to Figure 1 A schematic diagram of an electronic device. Detailed Implementation
[0068] To make the objectives, technical solutions, and advantages of this specification clearer, the technical solutions of this specification will be clearly and completely described below in conjunction with specific embodiments and corresponding drawings. Obviously, the described embodiments are only a part of the embodiments of this specification, and not all of them. Based on the embodiments in this specification, all other embodiments obtained by those skilled in the art without creative effort are within the scope of protection of this specification.
[0069] The technical solutions provided in the various embodiments of this specification are described in detail below with reference to the accompanying drawings.
[0070] Figure 1 This is a flowchart illustrating a data transmission method provided in this specification, including the following steps:
[0071] S101: Select at least one node from the nodes contained in the first computing cluster as the target node, wherein the networks of different computing clusters are isolated from each other.
[0072] S102: Construct a virtual communication port on the target node as a first communication port, and construct virtual communication ports on at least some nodes in the second computing cluster as second communication ports.
[0073] In container scheduling systems such as Kubernetes, multiple computing clusters are typically set up. To ensure data transmission security, different computing clusters are network isolated. That is, each computing cluster cannot directly access container groups in other computing clusters via the public network. Each cluster has one master node and multiple slave nodes. Each node can have multiple container groups for deploying applications. Furthermore, container groups on the same node are assigned unique IP addresses, and the subnet addresses of the nodes in different computing clusters are different.
[0074] In this specification, the execution entity for implementing the data transmission method can be a container scheduling system server, or other devices. For ease of description, this specification uses a server as the execution entity as an example to illustrate one data transmission method provided in this specification.
[0075] For each computing cluster, one or more nodes can be selected as target nodes from the nodes contained in the computing cluster. For example, several nodes with larger network bandwidth can be selected as target nodes. Of course, target nodes can also be selected in other ways, and this specification does not make specific limitations on this.
[0076] Since the communication method between any two computing clusters is the same, this specification describes the communication between two different computing clusters using a first computing cluster and a second computing cluster. Target nodes can be selected in the first computing cluster, and at least some nodes can be selected in the second computing cluster. Virtual communication ports can be constructed on the target nodes in the first computing cluster as the first communication port, and virtual communication ports can be constructed on at least some selected nodes in the second computing cluster as the second communication port.
[0077] The aforementioned communication ports can be VXLAN Tunnel End Points (VTEPs) of Virtual eXtensible Local Area Networks (VXLANs), or other virtual communication ports such as Generic Routing Encapsulation (GRE) or IPIP. This specification does not specifically limit them. For ease of understanding, this specification also provides a schematic diagram of the communication structure between various computing clusters, such as... Figure 2 As shown.
[0078] Figure 2 This is a schematic diagram of a communication structure between different computing clusters provided in this specification.
[0079] In this way, target nodes can be selected in each computing cluster to build communication ports. In this way, communication tunnels can be built between different computing clusters through the corresponding communication ports, so that nodes in different computing clusters can transmit data directly through the public network based on the communication tunnel.
[0080] VXLAN can use tunneling technology on top of the underlying physical network to build a logical network based on VTEP, decoupling the logical network from the physical network and enabling flexible networking needs. It has almost no impact on the existing network architecture, requiring no modifications to the original network to establish a new network layer. By introducing an outer tunnel in User Datagram Protocol (UDP) format as the data link layer, the original datagram content is transmitted as the tunnel payload. Because the outer layer uses UDP as the transmission method, the payload data can be easily transmitted in Layer 2 and Layer 3 networks. This allows different computing clusters to communicate directly through VXLAN tunnels even when their networks are isolated.
[0081] S103: Determine the first communication address assigned to the first communication port and the second communication address assigned to the second communication port.
[0082] S104: Use the first communication address as the source communication address corresponding to the target data that the first computing cluster needs to transmit, and determine the communication rules corresponding to the first communication port according to the second communication address.
[0083] After constructing each communication port, a communication address can be assigned to each determined communication port. The communication address corresponding to the first communication port is used as the first communication address, and the communication address corresponding to the second communication port is used as the second communication address.
[0084] In this specification, the communication address may include at least one of the following: Internet Protocol Address (IP) address and Media Access Control Address (MAC) address, wherein the subnet address of the IP address corresponding to the communication port in different computing clusters may be the same.
[0085] In addition, the server can determine the communication rules corresponding to the first communication port based on the second communication address and the communication addresses corresponding to at least some of the nodes in the second computing cluster.
[0086] Specifically, the bridge forwarding rules (such as the bridge forwarding database (bridgefdb)) corresponding to the first communication port can be determined based on the IP addresses corresponding to at least some of the nodes in the second computing cluster. The routing rules corresponding to the first communication port can be determined based on the Classless Inter-Domain Routing (CIDR) block value corresponding to the second computing cluster. In addition, the IP addresses corresponding to the container groups in at least some of the nodes in the second computing cluster can be bound to the MAC addresses corresponding to the second communication port to determine the address resolution rules (such as Address Resolution Protocol (APR cache entries)) corresponding to the first communication port.
[0087] It should be noted that the IP addresses corresponding to at least some of the nodes mentioned above can be the public IP addresses of each node.
[0088] Then, based on the aforementioned bridge forwarding rules, routing rules, and address resolution rules, the communication rules corresponding to the first communication port can be determined.
[0089] In addition, for other nodes deployed in the first computing cluster, if the node is not the target node, when the data in the node is transmitted to the node in the second computing cluster, the data needs to be transmitted from the node to the target node in the first computing cluster first.
[0090] Therefore, servers can build intra-cluster communication ports on each node for data transmission between nodes within the same cluster. For example, a VXLAN network virtual device, VXLAN.Calico, can be created using the Calico Container Network Interface (CNI) as an intra-cluster communication port.
[0091] Based on the aforementioned intra-cluster communication ports, rules can be added to the IPTABLES NAT list to replace the source IP address of packets passing through the VXLAN network virtual device VXLAN.Calico created by CalicoCNI if the source IP address belongs to the same subnet as the IP address of the cross-cluster VXLAN virtual device (second communication port) of the second computing cluster.
[0092] Specifically, if the source IP address corresponding to the target data transmission target belongs to the same subnet as the IP address corresponding to the second communication port within the cluster on the target node of the second computing cluster, then the source IP address corresponding to the sending source of the target data is replaced with the IP address corresponding to the communication port within the cluster on the target node of the second computing cluster.
[0093] Furthermore, based on the CIDR block value corresponding to the second computing cluster, the routing rules corresponding to other nodes in the first computing cluster (excluding the target node) can be determined. Also, based on the IP addresses of each node in the second computing cluster and the MAC address of the target node in the first computing cluster, the address resolution rules corresponding to other nodes can be determined. Then, based on the routing rules and address resolution rules corresponding to these other nodes, the communication rules corresponding to them can be determined. For ease of understanding, this specification provides a schematic diagram of the communication rules, such as... Figure 3 As shown.
[0094] Figure 3 This is a schematic diagram of a communication rule provided in this specification.
[0095] It should be noted that all IP addresses and MAC addresses in this diagram are fictitious addresses, used only as examples to illustrate and explain the implementation of the present invention. Figure 2The system comprises two computing clusters, Cluster A and Cluster B, with CIDR block values of 10.241.0.0 / 16 and 10.242.0.0 / 16, respectively. Cluster A consists of two nodes: Node A1 has a public IP address of 100.10.0.11 and a CIDR block value of 10.241.10.0 / 24, while Node A2 has a public IP address of 100.10.0.12 and a CIDR block value of 10.241.20.0 / 24.
[0096] Cluster B also consists of two nodes, with node B1 having a public IP address of 202.10.11.11 and a CIDR block value of 10.242.10.0 / 24, and node B2 having a public IP address of 202.10.11.12 and a CIDR block value of 10.242.20.0 / 24.
[0097] Take node A1 in cluster A as the target node, and create a cross-cluster VXLAN virtual device VXLAN-A on the target node as the first communication port. Its IP address is 10.0.0.1 and its MAC address is aa:20:1e:c8:20:aa. Create a cross-cluster VXLAN virtual device VXLAN-B on node B1 in cluster B as the second communication port. Its IP address is 10.0.0.2 and its MAC address is bb:20:1e:c8:20:bb.
[0098] Then, you can configure bridge fdb (bridge forwarding rule) on nodes A1 and B1. On node A1, add the rule bridge fdb append 00:00:00:00:00:00dev VXLAN-A dst202.10.11.11, where the IP address 202.10.11.11 is the public IP address of node B1.
[0099] On node B1, add the rule bridge fdb append 00:00:00:00:00:00dev VXLAN-B dst100.10.0.11, where IP address 100.10.0.11 is the public IP address of node A1.
[0100] Configure routing rules on nodes A1 and B1 respectively. On node A1, add the following routing rules: ip route add 10.0.0.0 / 24dev VXLAN-A and ip route add 10.242.0.0 / 16dev VXLAN-A, where the CIDR block 10.242.0.0 / 16 is the value of the CIDR block of cluster B.
[0101] On node B1, add the following routing rules: ip route add 10.0.0.0 / 24dev VXLAN-B and ip route add 10.241.0.0 / 16dev VXLAN-A, where the CIDR block 10.241.0.0 / 16 is the CIDR block value of cluster A.
[0102] On nodes A1 and B1, ARP cache entries (address resolution rules) can be set for each container group that needs to communicate and belongs to the second compute cluster. These entries bind the IP address of the container group in the other compute cluster to the MAC address of the cross-cluster VXLAN network virtual device (communication port) set on the node where the container group is located.
[0103] Specifically, add the following ARP cache table rules on node A1: `ip neigh add 10.242.10.100devVXLAN-A lladdr bb:20:1e:c8:20:bb` and `ip neigh add 10.242.20.10devVXLAN-A lladdr bb:20:1e:c8:20:bb`. Here, the IP addresses 10.242.10.100 and 10.242.20.10 are the IP addresses of container groups B1 and B2 in cluster B, respectively, and the MAC address `bb:20:1e:c8:20:bb` is the MAC address of the cross-cluster VXLAN virtual device (second communication port) VXLAN-B on node B1.
[0104] Add the following ARP cache table rules on node B1: `ip neigh add 10.241.10.60dev VXLAN-Blladdr aa:20:1e:c8:20:aa` and `ip neigh add 10.241.20.40dev VXLAN-B lladdr aa:20:1e:c8:20:aa`. Here, the IP addresses 10.241.10.60 and 10.241.20.40 are the IP addresses of container groups A1 and A2 in cluster A, respectively. The MAC address `aa:20:1e:c8:20:aa` is the MAC address of the cross-cluster VXLAN virtual device (first communication port) VXLAN-A on node A1.
[0105] Additionally, on nodes A1 and B1, rules can be added to the IPTABLES NAT table to ensure that packets passing through the VXLAN network virtual device VXLAN.Calico created by Calico CNI, if their source IP address is the cross-cluster VXLAN virtual device IP address of the first compute cluster, will have their source IP address replaced with the IP address corresponding to the intra-cluster communication port (VXLAN.Calico).
[0106] Specifically, on node A1, add the following IPTABLES rule: `iptables -t nat -A POSTROUTING -s 10.0.0.0 / 24 -o VXLAN.Calico -j MASQUERADE`. On node B1, add the following IPTABLES rule: `iptables -t nat -A POSTROUTING -s 10.0.0.0 / 24 -o VXLAN.Calico -j MASQUERADE`. The `MASQUERADE` rule replaces the source IP address with the IP address corresponding to `VXLAN.Calico`.
[0107] In addition, for non-target nodes (other nodes) in each cluster, communication rules can be set for the non-target nodes, including:
[0108] On nodes A2 and B2, configure routing rules to forward all packets with the CIDR block of the second compute cluster node as the destination IP address to VXLAN.Calico (internal communication port of the cluster). Specifically, on node A2, add the following routing rule: iproute add 10.242.0.0 / 16dev VXLAN.Calico, where 10.242.0.0.0 is the CIDR block value of cluster B.
[0109] On node B2, add the following routing rule: ip route add 10.241.0.0 / 16dev VXLAN.Calico, where 10.242.0.0.0 is the CIDR block value of cluster A.
[0110] Additionally, on nodes A2 and B2, add address resolution rules for each container group that needs to communicate and belongs to the second computing cluster. Specifically, on node A2, add the following ARP cache table rules: `ip neigh add 10.242.10.100 dev VXLAN.Calico lladdr a1:2a:fa:b1:9c:a1` and `ip neigh add 10.242.20.10 dev VXLAN.Calico lladdr a1:2a:fa:b1:9c:a1`. Here, the IP addresses 10.242.10.100 and 10.242.20.10 are the IP addresses of container groups B1 and B2 in cluster B, respectively, and the MAC address `a1:2a:fa:b1:9c:a1` is the MAC address of VXLAN.Calico on node A1.
[0111] On node B2, add the following ARP cache table rules: `ip neigh add 10.241.10.60devVXLAN.VXLAN.Calico lladdr b1:2a:fa:b1:9c:b1` and `ip neigh add 10.241.20.40devVXLAN.Calico lladdr b1:2a:fa:b1:9c:b1`. In these rules, the IP addresses 10.241.10.60 and 10.241.20.40 are the IP addresses of container groups A1 and A2 in cluster A, respectively. The MAC address `b1:2a:fa:b1:9c:b1` is the MAC address of VXLAN.Calico on node B1.
[0112] S104: Encapsulate the target data to obtain encapsulated data, and determine the target communication address corresponding to the encapsulated data based on the communication addresses corresponding to at least some nodes in the second computing cluster.
[0113] S105: Based on the communication rules, send the encapsulated data from the source communication address to the target communication address.
[0114] Specifically, target data can be sent from a specified container group in the first computing cluster through a specified device (such as a virtual network interface (VETH) device). In this case, the IP address of the container group can be used as the source IP address of the target data, and the IP address of the transmission target can be used as its destination IP address.
[0115] The initial data packet can then be sent to the pre-built intra-cluster communication port on the node corresponding to the aforementioned container group. Upon receiving the initial data packet, the intra-cluster communication port determines whether the target IP address of the data to be transmitted belongs to the same subnet as the IP address corresponding to the intra-cluster communication port. If not, the source IP address and source MAC address are updated, using the IP address and MAC address corresponding to the intra-cluster communication port as the source IP address and source MAC address. The initial data packet is then encapsulated in a second data packet, setting the IP address of the target node in the first computing cluster as the target IP address of the second data packet. Through the intra-cluster communication port of that node, the second data packet is sent from the IP address of the intra-cluster communication port to the target IP address according to the communication rules of that specified node, thus sending the second data packet to the target node.
[0116] After receiving the second data packet, the target node in the first computing cluster can parse it to obtain the initial data packet. Then, according to the target node's communication rules, the target node sends the initial data packet to the first communication port. This initial data packet carries the source IP address, source MAC address, and target IP address of the source sending the target data. Furthermore, the source IP address and source MAC address are updated to match the IP address and MAC address of the communication port within the cluster.
[0117] After receiving the initial data packet, the first communication port can determine whether the destination IP address of the initial data packet and the IP address corresponding to the first communication port belong to the same subnet. If not, the IP address and MAC address corresponding to the first communication port are used as the source IP address and source MAC address of the initial data packet. Then, the initial data packet can be encapsulated in the first data packet, and the IP addresses corresponding to at least some nodes in cluster B are set as the destination IP address of the first data packet.
[0118] Then, based on the communication rules, the first data packet can be transmitted from the IP address corresponding to the first communication port to the target IP address corresponding to the first data packet, thereby sending the first data packet to the target node in the computing cluster where the transmission target is located through the public network.
[0119] After receiving the first data packet, the target node can parse it to obtain the initial data packet. Then, it uses the IP address and MAC address of the intra-cluster communication port pre-set on the target node in the computing cluster where the transmission target is located as the source IP address and source MAC address of the initial data packet. After that, the initial data packet is encapsulated in the third data packet, the IP address of the transmission target is used as the target IP address of the third data packet, and the third data packet is sent to the transmission target.
[0120] After the transmission target receives the third data packet, it can parse the third data packet to obtain the target data, and then forward the target data to the application deployed in the container group corresponding to the transmission target.
[0121] Of course, the target data can also be transmitted from the target node in the first computing cluster to the target node in the second computing cluster. The target node can send the target data to the first communication port according to the communication rules corresponding to the target node. The source IP address and source MAC address corresponding to the target data can be the IP address and MAC address corresponding to the target node in the first computing cluster, and the IP address corresponding to at least some nodes in the second computing cluster can be used as the target communication address.
[0122] After receiving the target data, the first communication port can determine whether the target IP address of the target data and the IP address corresponding to the first communication port belong to the same subnet. If not, the IP address and MAC address corresponding to the first communication port are used as the source IP address and source MAC address of the target data. Then, the target data can be encapsulated to obtain encapsulated data, and the IP addresses corresponding to at least some of the nodes in the second computing cluster are set as the target IP address of the encapsulated data.
[0123] Then, through the first communication port, based on the source IP address, source MAC address, destination IP address, and the communication rules corresponding to the first communication port, the encapsulated data can be sent to at least some nodes in the second computing cluster via the public network.
[0124] It should be noted that the target data mentioned above can be sent to the first communication port in the form of an initial data packet. Then, the first communication port can encapsulate the initial data packet in another data packet and send the other data packet to the target node in the second computing cluster.
[0125] return Figure 3Taking the communication addresses in the cluster as an example, when data is transferred from container group A-2 of node A2 to container group B-2 of node B2, the target data needs to send an initial data packet from container group A-2 of node A2 to container group B-2 of node B2. This initial data packet can be an IP data packet with a source IP address of 10.241.20.40 and a destination IP address of 10.242.20.10. This initial data packet can be sent from the veth-PODA virtual device to the root network namespace of the host machine of node A2. Since the destination IP address 10.242.10.10 is not the IP address of the local machine, the initial data packet can be sent to the VXLAN.Calico network virtual device (inter-cluster communication port) through the communication rules corresponding to A2. This virtual device is created by the CalicoCNI plugin and is used for inter-cluster container group communication.
[0126] Since the target IP address and the IP address of the VXLAN.Calico virtual device do not belong to the same subnet, the source MAC address and source IP address of the initial data packet can be replaced with the MAC address and IP address of the VXLAN.Calico virtual device, i.e., 10.241.20.1.
[0127] The initial data packet can be encapsulated within another IP data packet (the second data packet) and sent via eth0. The destination IP address of the second data packet is 100.10.0.11 (node A1), and the source IP address is 100.10.0.12 (node A2).
[0128] After node A1 receives the second data packet, it can extract the inner initial data packet and then forward the initial data packet to the VXLAN-A virtual network device (first communication port) according to the communication rules corresponding to node A1.
[0129] Since the destination IP address of the initial data packet and the IP address of VXLAN-A are not in the same subnet, the source MAC address and IP address of the initial data packet are replaced with the MAC address and IP address of VXLAN-A, i.e., 10.0.0.1.
[0130] VXLAN-A can encapsulate the initial data packet into another IP data packet (the first data packet). The destination IP address of the first data packet is the public IP address 202.10.11.12 of node B1 in cluster B, and it is sent to the public network through eth0 based on the communication rules corresponding to the first communication port.
[0131] When node B1 on cluster B receives an IP data packet, it can extract the inner initial data packet and then forward the initial data packet to the VXLAN.Calico virtual network device on node B1 according to the communication rules corresponding to node B1.
[0132] Since the target IP address and the IP address of VXLAN.Calico on node B1 belong to the same subnet, the source MAC address and IP address of the IP packet will not be automatically replaced. Therefore, it is necessary to use the IPTABLES rule to replace the source MAC address and source IP address of the initial packet with the MAC address and IP address of VXLAN.Calico on node B1, i.e., 10.242.10.1.
[0133] The initial data packet can then be encapsulated in another IP data packet (the third data packet) and sent through eth0. The destination IP address of the third data packet is the IP address of node B2, 202.10.11.12, and the source IP address is the IP address of node B1, 202.10.11.11.
[0134] After receiving the third data packet, node B2 can extract the inner initial data packet and then forward the data packet to the veth-PODB virtual network device according to the communication rules corresponding to node B2. This rule can be added through the Calico plugin, so that the IP data packet is forwarded to the application in container group-B2.
[0135] It should be noted that the above explanation only uses the example of data transfer from A2 to B2. In practical applications, data transfer between nodes deployed in different clusters can be achieved in the same way, and this manual will not elaborate further on this.
[0136] In addition, the same application can be deployed on nodes of different clusters in this specification. In this way, even if the networks between the clusters are isolated, the application can still communicate with each other on different nodes.
[0137] As can be seen from the above method, this solution can select target nodes from various nodes in different computing clusters and configure virtual communication ports. Based on the communication addresses of these virtual communication ports, the communication rules between different clusters can be determined. This allows for data transmission between network-isolated computing clusters according to the configured communication rules, enabling applications to be deployed across these network-isolated clusters.
[0138] The above describes one or more methods for implementing data transmission as outlined in this specification. Based on the same approach, this specification also provides corresponding data transmission devices, such as... Figure 4 As shown.
[0139] Figure 4 This is a schematic diagram of a data transmission device provided in this specification, including:
[0140] The selection module 401 is used to select at least one node from the nodes contained in the first computing cluster as the target node, wherein the networks of different computing clusters are isolated from each other.
[0141] The construction module 402 is used to construct a virtual communication port on the target node as a first communication port, and to construct a virtual communication port on at least some nodes in the second computing cluster as a second communication port;
[0142] The first determining module 403 is used to determine a first communication address allocated to the first communication port and a second communication address allocated to the second communication port;
[0143] The second determining module 404 is used to take the first communication address as the source communication address corresponding to the target data that the first computing cluster needs to transmit, and to determine the communication rules corresponding to the first communication port according to the second communication address.
[0144] The encapsulation module 405 is used to encapsulate the target data to obtain encapsulated data, and to determine the target communication address corresponding to the encapsulated data based on the communication addresses corresponding to at least some nodes in the second computing cluster.
[0145] The sending module 406 is used to send the encapsulated data from the source communication address to the target communication address based on the communication rules.
[0146] Optionally, the encapsulation module 405 is specifically used to use the Internet Protocol IP addresses corresponding to at least some of the nodes in the second computing cluster as the target communication address.
[0147] Optionally, the second determining module 404 is specifically used to determine the communication rules based on the IP addresses corresponding to the at least some nodes, the Classless Inter-Domain Routing (CIDR) block value corresponding to the second computing cluster, the IP addresses corresponding to the container groups in the at least some nodes, and the Media Access Control (MAC) address corresponding to the second communication port.
[0148] Optionally, the second determining module 404 is specifically configured to: determine the bridge forwarding rule corresponding to the first communication port based on the public IP address corresponding to the at least some nodes, determine the routing rule corresponding to the first communication port based on the Classless Inter-Domain Routing (CIDR) block value corresponding to the second computing cluster, and determine the address resolution rule corresponding to the first communication port based on the IP address corresponding to the container group among the at least some nodes and the Media Access Control (MAC) address corresponding to the second communication port; and determine the communication rule based on the bridge forwarding rule, the routing rule, and the address resolution rule.
[0149] Optionally, the second determining module 404 is specifically used to: determine the routing rules corresponding to other nodes in the first computing cluster based on the CIDR block value corresponding to the second computing cluster; and determine the address resolution rules corresponding to the other nodes based on the IP address corresponding to the container group in each node of the second computing cluster and the MAC address corresponding to the cluster communication port built on the other nodes; and determine the communication rules corresponding to the other nodes based on the routing rules and the address resolution rules corresponding to the other nodes.
[0150] Optionally, the sending module 406 is specifically used to transmit the target data from the other nodes to the node corresponding to the target communication address based on the communication rules corresponding to the first communication port and the communication rules corresponding to the other nodes.
[0151] Optionally, the method further includes: constructing intra-cluster communication ports on each node;
[0152] The communication rules further include: if the source IP address contained in the source communication address belongs to the same subnet as the IP address corresponding to the intra-cluster communication port deployed on the node of the second computing cluster, then the source MAC address and source IP address contained in the source communication address are replaced with the MAC address and IP address corresponding to the intra-cluster communication port deployed on the node of the second computing cluster.
[0153] Optionally, the encapsulation module 405 is specifically configured to: send an initial data packet of target data to the first communication port through the target node in the first computing cluster, wherein the initial data packet carries the source IP address, source MAC address, and target IP address of the target data; determine whether the target IP address and the IP address corresponding to the first communication port belong to the same subnet; if not, use the IP address and MAC address corresponding to the first communication port as the source IP address and the source MAC address; encapsulate the initial data packet in a first data packet, and set the public IP address corresponding to at least some nodes in the second computing cluster as the target IP address corresponding to the first data packet.
[0154] Optionally, the sending module 406 is specifically used to transmit the first data packet from the IP address corresponding to the first communication port to the target IP address corresponding to the first data packet, based on the communication rules.
[0155] Optionally, the sending module 406 is further configured to: obtain an initial data packet sent by a specified container group in the first computing cluster through a specified device, and use the IP address corresponding to the specified container group as the source IP address of the initial data packet, and the IP address corresponding to the transmission target as the target IP address of the initial data packet; send the initial data packet to a pre-built intra-cluster communication port on the node where the specified container group is located; determine whether the target IP address and the IP address corresponding to the intra-cluster communication port belong to the same subnet; if not, use the IP address and MAC address corresponding to the intra-cluster communication port as the source IP address and the source MAC address; encapsulate the initial data packet in a second data packet, and set the IP address corresponding to the target node as the target IP address of the second data packet; and send the second data packet from the IP address corresponding to the intra-cluster communication port to the target IP address of the second data packet according to the communication rules corresponding to the specified node through the intra-cluster communication port.
[0156] Optionally, the sending module 406 is specifically used to parse the second data packet after the target node receives the second data packet to obtain the initial data packet.
[0157] Optionally, the sending module 406 is further configured to, after the target node in the second computing cluster receives the first data packet, parse the first data packet to obtain the initial data packet; use the IP address and MAC address corresponding to the pre-set intra-cluster communication port on the node in the computing cluster as the source IP address and source MAC address corresponding to the initial data packet; encapsulate the initial data packet in a third data packet and send the third data packet to the transmission target.
[0158] Optionally, the sending module 406 is specifically configured to, after the transmission target receives the third data packet, parse the third data packet to obtain the initial data packet; and forward the initial data packet to the application deployed in the container group corresponding to the transmission target.
[0159] This specification also provides a computer-readable storage medium storing a computer program that can be used to execute the above-described... Figure 1 This provides a method for data transmission.
[0160] This instruction manual also provides Figure 5 One of the corresponding Figure 1 A schematic diagram of the structure of an electronic device. (e.g.) Figure 5 At the hardware level, the electronic device includes a processor, internal bus, network interface, memory, and non-volatile memory, and may also include other hardware required for the business operations. The processor reads the corresponding computer program from the non-volatile memory into memory and then runs it to achieve the above-mentioned functions. Figure 1 The method of data transmission described herein. Of course, in addition to software implementation, this specification does not exclude other implementation methods, such as logic devices or a combination of hardware and software, etc. That is to say, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.
[0161] Improvements in a technology can be clearly distinguished as either hardware improvements (e.g., improvements to the circuit structure of diodes, transistors, switches, etc.) or software improvements (improvements to the methodology). However, with technological advancements, many improvements to the methodology can now be considered direct improvements to the hardware circuit structure. Designers almost always obtain the corresponding hardware circuit structure by programming the improved methodology into the hardware circuit. Therefore, it cannot be said that an improvement in methodology cannot be implemented using hardware physical modules. For example, a Programmable Logic Device (PLD) (such as a Field Programmable Gate Array (FPGA)) is such an integrated circuit whose logic function is determined by the user programming the device. Designers can program and "integrate" a digital system onto a PLD themselves, without needing chip manufacturers to design and manufacture dedicated integrated circuit chips. Furthermore, nowadays, instead of manually manufacturing integrated circuit chips, this programming is mostly implemented using "logic compiler" software. Similar to the software compiler used in program development, the original code before compilation must be written in a specific programming language, called a Hardware Description Language (HDL). There are many HDLs, such as ABEL (Advanced Boolean Expression Language), AHDL (Altera Hardware Description Language), Confluence, CUPL (Cornell University Programming Language), HDCal, JHDL (Java Hardware Description Language), Lava, Lola, MyHDL, PALASM, and RHDL (Ruby Hardware Description Language). Currently, VHDL (Very-High-Speed Integrated Circuit Hardware Description Language) and Verilog are the most commonly used. Those skilled in the art should understand that by simply performing some logic programming on the method flow using one of these hardware description languages and programming it into an integrated circuit, the hardware circuit implementing the logical method flow can be easily obtained.
[0162] The controller can be implemented in any suitable manner. For example, it can take the form of a microprocessor or processor and a computer-readable medium storing computer-readable program code (e.g., software or firmware) executable by the (micro)processor, logic gates, switches, application-specific integrated circuits (ASICs), programmable logic controllers, and embedded microcontrollers. Examples of controllers include, but are not limited to, the following microcontrollers: ARC 625D, Atmel AT91SAM, Microchip PIC18F26K20, and Silicon Labs C8051F320. A memory controller can also be implemented as part of the control logic of the memory. Those skilled in the art will also recognize that, in addition to implementing the controller in purely computer-readable program code form, the same functionality can be achieved by logically programming the method steps to make the controller take the form of logic gates, switches, application-specific integrated circuits, programmable logic controllers, and embedded microcontrollers. Therefore, such a controller can be considered a hardware component, and the means included therein for implementing various functions can also be considered as structures within the hardware component. Alternatively, the means for implementing various functions can be considered as both software modules implementing the method and structures within the hardware component.
[0163] The systems, devices, modules, or units described in the above embodiments can be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer. Specifically, a computer can be, for example, a personal computer, laptop computer, cellular phone, camera phone, smartphone, personal digital assistant, media player, navigation device, email device, game console, tablet computer, wearable device, or any combination of these devices.
[0164] For ease of description, the above devices are described in terms of function, divided into various units. Of course, in implementing this specification, the functions of each unit can be implemented in one or more software and / or hardware components.
[0165] Those skilled in the art will understand that embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0166] This specification is described with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of this specification. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, special-purpose computer, embedded processor, or other programmable data transfer apparatus to produce a machine, such that the instructions, which execute via the processor of the computer or other programmable data transfer apparatus, generate instructions for implementing the flowchart illustrations and / or block diagrams. Figure 1 One or more processes and / or boxes Figure 1 A device that provides the functions specified in one or more boxes.
[0167] These computer program instructions may also be stored in a computer-readable storage medium that can direct a computer or other programmable data transmission device to function in a particular manner, such that the instructions stored in the computer-readable storage medium produce an article of manufacture including instruction means, which are implemented in a process Figure 1 One or more processes and / or boxes Figure 1 The function specified in one or more boxes.
[0168] These computer program instructions may also be loaded onto a computer or other programmable data transmission device, causing a series of operational steps to be performed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions that execute on the computer or other programmable device for implementing the process. Figure 1 One or more processes and / or boxes Figure 1 The steps of the function specified in one or more boxes.
[0169] In a typical configuration, a computing device includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.
[0170] Memory may include non-persistent storage in computer-readable media, such as random access memory (RAM) and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory is an example of computer-readable media.
[0171] Computer-readable media includes both permanent and non-permanent, removable and non-removable media that can store information using any method or technology. Information can be computer-readable instructions, data structures, modules of programs, or other data. Examples of computer storage media include, but are not limited to, phase-change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, CD-ROM, digital versatile optical disc (DVD) or other optical storage, magnetic tape, magnetic magnetic disk storage or other magnetic storage devices, or any other non-transferable medium that can be used to store information accessible by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves.
[0172] It should also be noted that the terms "comprising," "including," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus that comprises a list of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such a process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising one..." does not exclude the presence of other identical elements in the process, method, article, or apparatus that includes said element.
[0173] Those skilled in the art will understand that the embodiments of this specification can be provided as methods, systems, or computer program products. Therefore, this specification may take the form of a completely hardware embodiment, a completely software embodiment, or an embodiment combining software and hardware aspects. Furthermore, this specification may take the form of a computer program product embodied on one or more computer-usable storage media (including, but not limited to, disk storage, CD-ROM, optical storage, etc.) containing computer-usable program code.
[0174] This specification can be described in the general context of computer-executable instructions that are executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc., that perform a specific task or implement a specific abstract data type. This specification can also be practiced in distributed computing environments, where tasks are performed by remote processing devices connected via a communication network. In distributed computing environments, program modules can reside in local and remote computer storage media, including storage devices.
[0175] The various embodiments in this specification are described in a progressive manner. Similar or identical parts between embodiments can be referred to interchangeably. Each embodiment focuses on describing the differences from other embodiments. In particular, the system embodiments are basically similar to the method embodiments, so the description is relatively simple; relevant parts can be referred to the descriptions in the method embodiments.
[0176] The above description is merely an embodiment of this specification and is not intended to limit this specification. Various modifications and variations can be made to this specification by those skilled in the art. Any modifications, equivalent substitutions, improvements, etc., made within the spirit and principles of this specification should be included within the scope of the claims of this specification.
Claims
1. A method for data transmission, characterized in that, include: At least one node is selected from the nodes in the first computing cluster as the target node, wherein the networks of different computing clusters are isolated from each other. A virtual communication port is constructed on the target node as a first communication port, and a virtual communication port is constructed on at least some nodes in the second computing cluster as a second communication port; Determine the first communication address to be assigned to the first communication port, and the second communication address to be assigned to the second communication port; The first communication address is used as the source communication address corresponding to the target data that the first computing cluster needs to transmit, and the communication rules corresponding to the first communication port are determined according to the second communication address. The target data is encapsulated to obtain encapsulated data, and the target communication address corresponding to the encapsulated data is determined based on the communication addresses corresponding to at least some nodes in the second computing cluster. Specifically, an initial data packet of the target data is sent to the first communication port via the target node in the first computing cluster. If the target IP address carried by the initial data packet does not belong to the same subnet as the IP address corresponding to the first communication port, the communication address corresponding to the first communication port is used as the source communication address. The initial data packet is encapsulated in a first data packet, and the IP address corresponding to at least some nodes in the second computing cluster is set as the target IP address corresponding to the first data packet. The target communication address includes the target IP address corresponding to the first data packet. Based on the communication rules, the encapsulated data is sent from the source communication address to the target communication address.
2. The method as described in claim 1, characterized in that, Determining the target communication address corresponding to the encapsulated data based on the communication addresses corresponding to at least some nodes in the second computing cluster specifically includes: The Internet Protocol IP addresses corresponding to at least some of the nodes in the second computing cluster are used as the target communication addresses.
3. The method as described in claim 1, characterized in that, Based on the second communication address, the communication rules corresponding to the first communication port are determined, specifically including: The communication rules are determined based on the IP addresses corresponding to at least some of the nodes, the Classless Inter-Domain Routing (CIDR) block value corresponding to the second computing cluster, the IP addresses corresponding to the container groups in at least some of the nodes, and the Media Access Control (MAC) address corresponding to the second communication port.
4. The method as described in claim 1, characterized in that, Based on the second communication address, the communication rules corresponding to the first communication port are determined, specifically including: Based on the IP addresses corresponding to the at least some nodes, determine the bridge forwarding rule corresponding to the first communication port, determine the routing rule corresponding to the first communication port based on the Classless Inter-Domain Routing (CIDR) block value corresponding to the second computing cluster, and determine the address resolution rule corresponding to the first communication port based on the IP addresses corresponding to the container groups in the at least some nodes and the Media Access Control (MAC) address corresponding to the second communication port. The communication rules are determined based on the bridge forwarding rules, the routing rules, and the address resolution rules.
5. The method as described in claim 1, characterized in that, Based on the second communication address, the communication rules corresponding to the first communication port are determined, specifically including: Based on the CIDR block value corresponding to the second computing cluster, determine the routing rules corresponding to other nodes in the first computing cluster; and based on the IP address corresponding to the container group in each node of the second computing cluster and the MAC address corresponding to the cluster communication port built on the other nodes, determine the address resolution rules corresponding to the other nodes. Based on the routing rules and address resolution rules of the other nodes, the communication rules of the other nodes are determined.
6. The method as described in claim 5, characterized in that, Based on the communication rules, the encapsulated data is sent from the source communication address to the target communication address, specifically including: Based on the communication rules corresponding to the first communication port and the communication rules corresponding to the other nodes, the target data is transmitted from the other nodes to the node corresponding to the target communication address.
7. The method as described in claim 1, characterized in that, The method further includes: constructing intra-cluster communication ports on each node; The communication rules further include: if the source IP address contained in the source communication address belongs to the same subnet as the IP address corresponding to the intra-cluster communication port deployed on the node of the second computing cluster, then the source MAC address and source IP address contained in the source communication address are replaced with the MAC address and IP address corresponding to the intra-cluster communication port deployed on the node of the second computing cluster.
8. The method as described in claim 1, characterized in that, The target data is encapsulated to obtain encapsulated data, and the target communication address corresponding to the encapsulated data is determined based on the communication addresses corresponding to at least some nodes in the second computing cluster. Specifically, this includes: The initial data packet of the target data is sent to the first communication port through the target node in the first computing cluster. The initial data packet carries the source IP address, source MAC address and target IP address of the target data. Determine whether the target IP address and the IP address corresponding to the first communication port belong to the same subnet; If not, the IP address and MAC address corresponding to the first communication port shall be used as the source IP address and the source MAC address; The initial data packet is encapsulated in a first data packet, and the IP addresses corresponding to at least some nodes in the second computing cluster are set to the target IP addresses corresponding to the first data packet.
9. The method as described in claim 8, characterized in that, Before sending the initial data packet of the target data to the first communication port via the target node in the first computing cluster, the method further includes: Obtain the initial data packet sent by the specified container group in the first computing cluster through the specified device, and use the IP address corresponding to the specified container group as the source IP address of the initial data packet, and use the IP address corresponding to the transmission target as the destination IP address of the initial data packet; The initial data packet is sent to the pre-built intra-cluster communication port on the designated node where the designated container group is located; Determine whether the target IP address and the IP address corresponding to the communication port within the cluster belong to the same subnet. If not, use the IP address and MAC address corresponding to the communication port within the cluster as the source IP address and the source MAC address. The initial data packet is encapsulated in a second data packet, and the IP address corresponding to the target node is set to the target IP address corresponding to the second data packet; Through the cluster communication port, the second data packet is sent from the IP address corresponding to the cluster communication port to the target IP address corresponding to the second data packet, according to the communication rules corresponding to the specified node.
10. The method as described in claim 9, characterized in that, Through the cluster communication port, the second data packet is sent from the IP address corresponding to the cluster communication port to the target IP address corresponding to the second data packet according to the communication rules corresponding to the specified node. Specifically, this includes: After the target node receives the second data packet, it parses the second data packet to obtain the initial data packet.
11. The method as described in claim 8, characterized in that, The method further includes: After the target node in the second computing cluster receives the first data packet, it parses the first data packet to obtain the initial data packet; The IP address and MAC address of the pre-configured intra-cluster communication port on the node in the computing cluster are used as the source IP address and source MAC address of the initial data packet; The initial data packet is encapsulated in a third data packet, and the third data packet is sent to the transmission target.
12. The method as described in claim 11, characterized in that, Encapsulating the initial data packet in a third data packet and sending the third data packet to the transmission target specifically includes: After the transmission target receives the third data packet, it parses the third data packet to obtain the initial data packet; The initial data packet is forwarded to the application deployed within the container group corresponding to the transmission target.
13. A data transmission apparatus, characterized in that, include: The selection module selects at least one node from the nodes contained in the first computing cluster as the target node, wherein the networks of different computing clusters are isolated from each other. The module constructs a virtual communication port on the target node as a first communication port, and constructs virtual communication ports on at least some nodes in the second computing cluster as second communication ports. The first determining module determines a first communication address allocated to the first communication port and a second communication address allocated to the second communication port; The second determining module uses the first communication address as the source communication address corresponding to the target data that the first computing cluster needs to transmit, and determines the communication rules corresponding to the first communication port based on the second communication address. An encapsulation module encapsulates the target data to obtain encapsulated data, and determines the target communication address corresponding to the encapsulated data based on the communication addresses corresponding to at least some nodes in the second computing cluster. Specifically, an initial data packet of the target data is sent to the first communication port via the target node in the first computing cluster. If the target IP address carried by the initial data packet does not belong to the same subnet as the IP address corresponding to the first communication port, the communication address corresponding to the first communication port is used as the source communication address. The initial data packet is encapsulated in a first data packet, and the IP address corresponding to at least some nodes in the second computing cluster is set as the target IP address corresponding to the first data packet. The target communication address includes the target IP address corresponding to the first data packet. The sending module, based on the communication rules, sends the encapsulated data from the source communication address to the target communication address.
14. A computer-readable storage medium, characterized in that, The storage medium stores a computer program, which, when executed by a processor, implements the method described in any one of claims 1 to 12.
15. An electronic device comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the program, it implements the method described in any one of claims 1 to 12.
Citation Information
Patent Citations
Communication method between Kubernetes clusters, computer equipment and medium
CN113572831A