Container network packet capturing processing method, device and equipment and readable storage medium
By receiving attribute information from the source and destination container groups, the physical nodes are identified and target network interface data packets are captured, solving the problem of low efficiency in troubleshooting container network faults and enabling fast and accurate fault location and analysis.
Patent Information
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-01-10
- Publication Date
- 2026-03-27
AI Technical Summary
Troubleshooting container networks is inefficient, and existing technologies struggle to quickly pinpoint the root cause of problems, resulting in cumbersome and time-consuming maintenance processes.
By receiving the attribute information of the source and destination container groups input by the user, the physical node where they are located is determined, and a packet capture command is sent to the target network card to realize packet capture operation on a specific network link, simplifying the troubleshooting process.
It improves the efficiency of troubleshooting container network faults, simplifies packet capture analysis, lowers the learning threshold for operations and maintenance, and increases the speed of fault location.
Smart Images

Figure CN116192618B_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the field of container network operation and maintenance, and particularly relates to a container network packet capturing processing method and device, equipment and a readable storage medium. BACKGROUND
[0002] Container technology is a virtualization technology that can effectively improve resource utilization. When the container technology is used, some container groups are deployed on a physical machine, and each container group includes one or more containers. The container groups communicate with each other through a container network. When the container network fails, it is easy to cause the running of related tasks to be abnormal. Since the container network architecture is more complex than the physical network, it is difficult for an operation and maintenance personnel to quickly locate the root cause of the failure, and it is necessary to perform packet capturing analysis on a large number of physical machine network cards, which is a relatively cumbersome process, resulting in too long time for problem troubleshooting, and seriously affecting the network troubleshooting efficiency.
[0003] Therefore, the related art has the problem of low container network troubleshooting efficiency. In view of the above problem, no effective solution has been proposed so far.
[0004] The above information disclosed in the background section is only intended to enhance the understanding of the background of the technology described herein. Therefore, the background section can include some information that is not known to those skilled in the art as prior art. SUMMARY
[0005] The embodiments of the present application provide a container network packet capturing processing method, device, equipment and readable storage medium to at least solve the technical problem of low container network troubleshooting efficiency in the related art.
[0006] According to a first aspect of the embodiments of the present application, a container network packet capturing processing method is provided, comprising: receiving attribute information of a source container group and a destination container group input by a user, the source container group being a container group that sends access data, and the destination container group being a container group that receives access data, the source container group and the destination container group each including at least one container; determining physical nodes where the source container group and the destination container group are located according to the attribute information; determining a target network card according to the physical nodes where the source container group and the destination container group are located, the target network card being a network card through which the access data passes; and sending a packet capturing command for the target network card to a physical node where the target network card is located.
[0007] Further, the target network card includes a physical network card and / or a virtual network card, the virtual network card being a network card virtually output by a container network plug-in, and the virtual network card being used to implement communication between a container group to which the virtual network card belongs and other container groups.
[0008] Further, the target network card is determined according to the physical nodes where the source container group and the destination container group are located, the network path of the access data is determined according to the physical nodes where the source container group and the destination container group are located, and the target network card is determined according to the network path.
[0009] Further, the target network card is one or more, and / or the packet capturing command is used to control the physical node to capture the target network card.
[0010] Further, the attribute information includes the name of the container group and the namespace of the container group.
[0011] Further, after the packet capturing command for the target network card is sent to the physical node where the target network card is located, the container network packet capturing processing method further includes: receiving the data packet of the target network card captured by the physical node; storing the data packet to the target location, and / or analyzing the network fault reason between the source container group and the destination container group according to the data packet.
[0012] According to a second aspect of the embodiments of the present application, a container network packet capturing processing device is also provided, which includes: a first receiving unit configured to receive attribute information of a source container group and a destination container group input by a user, the source container group being a container group sending access data, the destination container group being a container group receiving the access data, and the source container group and the destination container group each including at least one container; a first determining unit configured to determine physical nodes where the source container group and the destination container group are located according to the attribute information; a second determining unit configured to determine a target network card according to the physical nodes where the source container group and the destination container group are located, the target network card being a network card through which the access data passes; and a sending unit configured to send a packet capturing command for the target network card to the physical node where the target network card is located.
[0013] Further, the target network card includes a physical network card and / or a virtual network card, the virtual network card being a network card virtually output by a container network plug-in, and the virtual network card being used to realize communication between a container group to which the virtual network card belongs and other container groups;
[0014] The second determining unit includes: a first determining module configured to determine a network path of the access data according to the physical nodes where the source container group and the destination container group are located; and a second determining module configured to determine the target network card according to the network path.
[0015] The packet capturing command is used to control the physical node to capture the target network card.
[0016] The attribute information includes the name of the container group and the namespace of the container group.
[0017] The container network packet capturing processing apparatus further comprises a second receiving unit, configured to receive the data packet of the target network card captured by the physical node after sending the packet capturing command for the target network card to the physical node where the target network card is located; a storage unit, configured to store the data packet to a target position; and / or an analysis unit, configured to analyze the cause of the network fault between the source container group and the destination container group according to the data packet.
[0018] According to a third aspect of the embodiments of the present application, a readable storage medium is provided, and the readable storage medium has computer instructions stored thereon, wherein the computer instructions are executed by a processor to implement the container network packet capturing processing method.
[0019] According to a fourth aspect of the embodiments of the present application, a container network packet capturing processing device is provided, and the container network packet capturing processing device comprises a memory and a processor, and the memory has computer instructions stored thereon, wherein the computer instructions are executed by the processor to implement the container network packet capturing processing method.
[0020] According to a fifth aspect of the embodiments of the present application, a computer program is provided, and the computer program is run by a processor to implement the container network packet capturing processing method.
[0021] The container network packet capturing processing method of the embodiment comprises the following steps: receiving attribute information of a source container group and a target container group input by a user, the source container group being a container group that sends access data, the target container group being a container group that receives the access data, the source container group and the target container group each comprising at least one container; determining physical nodes where the source container group and the target container group are located according to the attribute information; determining a target network card through which the access data passes according to the physical nodes where the source container group and the target container group are located; and sending a packet capturing command for the target network card to a physical node where the target network card is located. In the process of communication by means of the container network, different container groups send access data through the source container group and finally reach the target container group. When the user finds that a network link from a certain source container group to a certain target container group is faulty, the user only needs to input the attribute information of the source container group and the target container group, and according to the attribute information, the physical nodes where the source container group and the target container group are located can be located, wherein the source container group and the target container group can belong to the same physical node, or the source container group and the target container group can belong to different physical nodes. Since the network architecture of the container network is fixed, when the start end and the end of the access request are determined, the network path through which the access request passes is fixed. Therefore, the target network card through which the access request passes can be determined. On this basis, the packet capturing command for the target network card is sent to the physical node where the target network card is located, so that the packet capturing of the corresponding target network card is realized, which facilitates subsequent network troubleshooting. This way of narrowing the packet capturing range to a specific network link range according to the attribute information of the source container group and the target container group can realize targeted packet capturing operation for the specific faulty link, and the user only needs to input the attribute information of the source container group and the target container group to realize packet capturing operation on the target network card of the entire network link, which effectively simplifies the packet capturing analysis operation process in the container network troubleshooting process, is conducive to improving the container network troubleshooting efficiency, and solves the problem of low troubleshooting efficiency for the container network fault in the related art. BRIEF DESCRIPTION OF DRAWINGS
[0022] The accompanying drawings, which are included to provide a further understanding of the application and are incorporated in and constitute a part of this application, illustrate embodiments of the application and serve to explain the principles of the application. In the drawings:
[0023] Figure 1 A flowchart of a container network packet capturing processing method provided by the embodiment of the application;
[0024] Figure 2 A schematic diagram of a container network packet capturing processing device provided by the embodiment of the application. DETAILED DESCRIPTION
[0025] To enable those skilled in the art to better understand the present invention, the technical solutions of the present invention will be clearly and completely described below with reference to the accompanying drawings of the embodiments of the present invention. Obviously, the described embodiments are only some embodiments of the present invention, and not all embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those skilled in the art without creative effort should fall within the scope of protection of the present invention.
[0026] It should be noted that the terms "first," "second," etc., in the specification, claims, and drawings of this invention are used to distinguish different objects, rather than to limit a specific order.
[0027] Figure 1 This is a container network packet capture processing method according to an embodiment of the present invention. This method can be implemented on any physical machine in a container deployment cluster, wherein the container deployment cluster is a cluster composed of multiple physical nodes, and the physical nodes in the cluster are used to deploy containers, such as... Figure 1 As shown, the method includes the following steps:
[0028] Step S102: Receive the attribute information of the source container group and the destination container group input by the user. The source container group is the container group that sends access data, and the destination container group is the container group that receives access data. Both the source container group and the destination container group include at least one container.
[0029] Step S104: Determine the physical nodes where the source container group and the destination container group are located based on the attribute information;
[0030] Step S106: Determine the target network interface card (NIC) based on the physical nodes where the source container group and the destination container group are located. The target NIC is the NIC through which the access data passes.
[0031] Step S108: Send a packet capture command for the target network card to the physical node where the target network card is located.
[0032] In the process of communication by relying on the container network, the access data is sent by the source container group and finally reaches the destination container group. When the user finds that the network link from a source container group to a destination container group is faulty, only the attribute information of the source container group and the destination container group needs to be input, and according to the attribute information, the physical node where the source container group and the destination container group are located can be located. The source container group and the destination container group can belong to the same physical node, and the source container group and the destination container group can also belong to different physical nodes. Since the network architecture of the container network is fixed, when the start and end of the access request are determined, the network path through which the access request passes is fixed. Therefore, the target network card through which the access request passes can be determined. On this basis, a packet capture command for the target network card is sent to the physical node where the target network card is located, so as to realize the packet capture of the corresponding target network card, which is convenient for subsequent network troubleshooting. This way of narrowing the packet capture range to a specific network link range according to the attribute information of the source container group and the target container group can realize targeted packet capture operation for the specific fault link. The user only needs to input the attribute information of the source container group and the destination container group to realize the packet capture operation of the destination network card of the entire network link, which effectively simplifies the packet capture and analysis operation process in the container network troubleshooting process, is conducive to improving the container network troubleshooting efficiency, and solves the problem of low troubleshooting efficiency of the container network fault in the related art.
[0033] In the process of realizing the communication between the container groups in the cluster, for any two container groups generating interaction, the access data is sent by the source container group and finally received by the destination container group. For example, for a kubernets cluster, the above-mentioned container group, i.e. pod, is a set of one or more containers, and the pod is the smallest resource object in the kubernets cluster. The smallest running unit that can be seen by the kubernets cluster is the pod, and the kubernets cluster management is performed in units of pods. The attribute information of the above-mentioned source container group and destination container group, i.e. the information used to describe the source container group and the destination container group, can be various information, as long as the user can effectively represent the source container group and the destination container group after inputting the attribute information. After inputting the attribute information, the source container group and the destination container group corresponding to the attribute information can be determined, and since the deployment position of the container group is fixed, the fixed container group is deployed on the fixed physical node, and after the source container group and the destination container group are determined, the physical nodes to which the two belong can be determined. That is, there is a determined corresponding relationship between the specific attribute information and the specific source container group and the destination container group, and there is also a determined corresponding relationship between the specific source container group and the destination container group and the physical node. After the user inputs the attribute information of the source container group and the destination container group, the physical nodes where the two are located can be determined according to the corresponding relationship. The physical node is a physical machine, and each container group runs on a physical machine.
[0034] In one embodiment, the target network card includes a physical network card and / or a virtual network card, the virtual network card being a network card virtually provided by a container network plugin, and the virtual network card being used to implement communication between the container group to which the virtual network card belongs and other container groups. In order to implement communication between the container group and other container groups, the container network plugin virtually provides the virtual network card corresponding to the container group. The container network plugin is a plugin that provides inter-container network communication capability for the cluster, and can run in any physical machine of the cluster. The physical network card is an entity network card installed in the physical machine, and is used to implement communication between the physical machine and other physical machines. In actual implementation, the network card through which the access data passes can have different situations. For example, if the source container group and the destination container group are in the same physical machine, the access data only passes through the virtual network card. For another example, if the source container group and the destination container group are in different physical machines, the access data passes through the physical network card and the virtual network card. That is, if the physical machines where the source container group and the destination container group are located change, the network card through which the access data passes also changes. In this embodiment, the target network card is the physical network card and / or the virtual network card, so that the data packets on the physical network card and / or the virtual network card can be flexibly captured according to the physical machines where the source container group and the destination container group are located and the specific packet capturing requirements, thereby facilitating subsequent fault analysis. In a preferred embodiment, the target network card includes a physical network card and a virtual network card. By capturing the physical network card and the virtual network card through which the access data passes, the data forwarding process under the faulty link can be completely captured, thereby facilitating more comprehensive analysis of the container network fault and avoiding affecting the container network operation and maintenance effect due to missing data.
[0035] After the physical nodes where the source container group and the destination container group are located are determined according to the attribute information, how to determine the target network card according to the physical nodes where the source container group and the destination container group are located is an important link in the entire packet capturing method. In this embodiment, in order to accurately determine the target network card, the target network card is determined according to the physical nodes where the source container group and the destination container group are located, including: determining a network path of the access data according to the physical nodes where the source container group and the destination container group are located; and determining the target network card according to the network path. After the physical nodes to which the source container group and the destination container group belong are determined, since the start end and the end end of the access data are determined, and the network architecture of the container network is fixed, the network path through which the access request from the source container group to the destination container group passes is also determined, where the network path through which the access request from the source container group to the destination container group passes is a link through which the access data passes. On the basis of determining the network path, it can be determined which network cards are involved in the network path, so that the target network card is accurately determined.
[0036] In a specific implementation, the target network card can be one or multiple. That is, in the case that the link accessed by the data changes, the number of network cards through which the data passes on the link can also change. For each target network card, it corresponds to a physical node to which it belongs. By sending a packet capturing command to the physical node, the physical node can be controlled to capture the target network card.
[0037] In a preferred embodiment, in order to more concisely and clearly characterize the source container group and the destination container group, the attribute information includes the name of the container group and the namespace of the container group. In a kubernets cluster, the namespace of the container group is the namespace of the pod, and the name of the container group is the name of the pod. In this way, the user only needs to input the name and namespace of the source container group and the destination container group to realize the packet capturing operation of the container network link, effectively simplifying the container network packet capturing control process, and facilitating the reduction of the learning threshold of the container network operation and maintenance process. For example, in a kubernets cluster, by knowing the name and namespace of the source container group and the destination container group, the source container group and the destination container group can be conveniently queried by a query command.
[0038] In a preferred embodiment, after sending the packet capturing command for the target network card to the physical node where the target network card is located, the container network packet capturing processing method further includes: receiving the data packet of the target network card captured by the physical node; storing the data packet to a target position, and / or analyzing the network fault reason between the source container group and the destination container group according to the data packet. The target position can be any position capable of realizing data storage. By storing the captured data packet to the target position, the data packet can be used at any time in the subsequent process. After receiving the data packet captured by the physical node, by analyzing the data packet, the occurrence position of the container network fault can be determined, so as to locate the fault reason.
[0039] The container network packet capturing processing method of the present application is described below in combination with a specific embodiment:
[0040] Container network is used to realize communication between container groups, which is a virtual network (overlay) existing on the physical network (underlay). The container groups will build virtual networks in the physical machines. When the container groups communicate with each other, the data flow of the virtual network will be sent to the physical network, and then sent through the physical network. The container network failure can easily cause the related tasks to be unable to run normally. Since the container network architecture is more complex than the physical network, and most operation and maintenance personnel do not understand the container network, when the container network fails, they often have no way out, and often need to reproduce the problem with the network operation and maintenance personnel, and at the same time, packet capture analysis is performed on multiple network cards of multiple physical machines. The operation process is complicated, which leads to too long problem troubleshooting time, and there is a technical problem of low container network troubleshooting efficiency.
[0041] The container network packet capture processing method provided in the embodiment is used for automatic packet capture of the container network, and includes the following steps:
[0042] The container network packet capture script is installed on any physical machine of the container deployment cluster. In the process of packet capture, the user needs to fill in the name and namespace of the source container group initiating the access, and the name and namespace of the destination container group.
[0043] According to the name and namespace of the source container group and the destination container group, the physical node where the source container group and the destination container group are located is found.
[0044] Since the network architecture of the container network is fixed, the network path of the data packet is also fixed. That is, when designing the container network, all network paths are designed in advance. When the source container group accesses the destination container group, it must pass through a specific network card, which has been designed. Therefore, according to the architecture design of the container network, it can be determined which target network card of which physical node will be passed through in the access process. Here, the target network card includes a virtual network card and / or a physical network card.
[0045] After determining the target network card to be passed through, a packet capture command can be sent to the corresponding node, and a packet capture operation is performed on the target network card used on the network path. Subsequently, the captured data packet can be uploaded to a target position, which is convenient for troubleshooting the container network. In this way, the data packet of the faulty network path can be automatically and accurately captured, and the packet capture process does not require any network knowledge and is easy to operate. When a failure occurs, the captured data packet can be directly provided to the network operation and maintenance personnel, thereby improving the network troubleshooting efficiency.
[0046] In addition, as Figure 2As shown, the embodiment of the application also provides a container network packet capturing processing device, which comprises: a first receiving unit configured to receive attribute information of a source container group and a destination container group input by a user, the source container group being a container group that sends access data, the destination container group being a container group that receives the access data, and the source container group and the destination container group each comprising at least one container; a first determining unit configured to determine physical nodes where the source container group and the destination container group are located according to the attribute information; a second determining unit configured to determine a target network card through which the access data passes according to the physical nodes where the source container group and the destination container group are located; and a sending unit configured to send a packet capturing command for the target network card to a physical node where the target network card is located. In the process of communication between different container groups relying on a container network, the access data is sent by the source container group and finally reaches the destination container group. When the user finds that a network link from a certain source container group to a certain destination container group is faulty, the user only needs to input the attribute information of the source container group and the destination container group. After the first receiving unit receives the information, the first determining unit can locate the physical nodes where the source container group and the destination container group are located according to the attribute information. Since the network architecture of the container network is fixed, the network path through which the access request passes is fixed in the case where the start end and the end of the access request are determined. Therefore, the second determining unit can determine the target network card through which the access request passes. On this basis, the sending unit sends a packet capturing command for the target network card to the physical node where the target network card is located, so as to realize packet capturing of the corresponding target network card, facilitating subsequent network troubleshooting. This way of narrowing the packet capturing range to a specific network link range according to the attribute information of the source container group and the destination container group can realize targeted packet capturing operation for a specific faulty link. The user only needs to input the attribute information of the source container group and the destination container group to realize packet capturing operation on the destination network card of the entire network link, effectively simplifying the packet capturing and analysis operation process in the container network troubleshooting process, which is conducive to improving the container network troubleshooting efficiency and solving the problem of low troubleshooting efficiency for the container network fault in the related art.
[0047] In the embodiment, the target network card comprises a physical network card and / or a virtual network card, the virtual network card being a network card virtually output by a container network plug-in, and the virtual network card being used to realize communication between a container group to which the virtual network card belongs and other container groups.
[0048] The second determining unit comprises: a first determining module configured to determine a network path of the access data according to the physical nodes where the source container group and the destination container group are located; and a second determining module configured to determine the target network card according to the network path.
[0049] The packet capturing command is used to control the physical node to perform packet capturing on the target network card.
[0050] The attribute information comprises a name of the container group and a namespace of the container group.
[0051] The container network packet capturing processing apparatus further comprises a second receiving unit configured to receive the data packet of the target network card captured by the physical node after sending the packet capturing command for the target network card to the physical node where the target network card is located; a storage unit configured to store the data packet to a target position; and / or an analysis unit configured to analyze the cause of the network fault between the source container group and the destination container group according to the data packet.
[0052] In addition, the embodiment of the present application further provides a readable storage medium, which has computer instructions stored thereon, wherein the computer instructions are executed by a processor to realize the container network packet capturing processing method.
[0053] Again, the embodiment of the present application further provides a container network packet capturing processing device, which comprises a memory and a processor, and the memory has computer instructions stored thereon, wherein the computer instructions are executed by the processor to realize the container network packet capturing processing method.
[0054] Finally, the embodiment of the present application further provides a computer program, wherein the computer program is run by a processor to realize the container network packet capturing processing method.
[0055] It should be noted that the user information (including but not limited to user equipment information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in the present application are all information and data authorized by the user or authorized by all parties, and the collection, use and processing of related data need to comply with relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation portal for user to choose authorization or refusal.
[0056] The above-mentioned serial numbers of the embodiments of the present application are only for description, not representing the advantages and disadvantages of the embodiments. Moreover, the steps shown in the flowchart of the accompanying drawings can be executed in a computer system such as a group of computer executable instructions, and although the logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in different order from here.
[0057] In the above-mentioned embodiments of the present application, the description of each embodiment has its own emphasis, and the parts not described in detail in a certain embodiment can be referred to the relevant description of other embodiments.
[0058] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0059] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0060] Furthermore, the functional units in the various embodiments of the present invention can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0061] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present invention. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0062] The above description is only a preferred embodiment of the present invention. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of the present invention, and these improvements and modifications should also be considered within the scope of protection of the present invention.
Claims
1. A method for packet capture processing in container networks, comprising: The system receives attribute information of a source container group and a destination container group input by the user. The source container group is the container group that sends access data, and the destination container group is the container group that receives the access data. Both the source container group and the destination container group include at least one container. Based on the attribute information, the physical nodes where the source container group and the destination container group are located are determined; the attribute information includes the name of the container group and the namespace of the container group. Based on the physical nodes where the source container group and the destination container group are located, a target network interface card (NIC) is determined. The target NIC is the NIC through which the access data passes. The target NIC includes a physical NIC and / or a virtual NIC. If the source container group and the destination container group are on the same physical machine, the access data only passes through the virtual NIC. If the source container group and the destination container group are on different physical machines, the access data will pass through both the physical NIC and the virtual NIC. Send a packet capture command for the target network card to the physical node where the target network card is located.
2. The container network packet capture processing method according to claim 1, wherein, The virtual network interface card (NIC) is a NIC created by the container networking plugin. The virtual NIC is used to enable communication between its own container group and other container groups.
3. The container network packet capture processing method according to claim 1, wherein, Based on the physical nodes where the source container group and the destination container group are located, the target network interface card is determined to include: The network path for accessing the data is determined based on the physical nodes where the source container group and the destination container group are located; The target network interface card is determined based on the network path.
4. The container network packet capture processing method according to claim 1, wherein, The target network interface card (NIC) may be one or more, and / or the packet capture command is used to control the physical node to capture packets on the target NIC.
5. The container network packet capture processing method according to any one of claims 1 to 4, wherein, After sending a packet capture command for the target network interface card (NIC) to the physical node where the target NIC is located, the method further includes: Receive data packets captured by the physical node from the target network interface card; The data packet is stored at the target location, and / or the cause of the network failure between the source container group and the destination container group is analyzed based on the data packet.
6. A container network packet capture and processing device, comprising: The first receiving unit is used to receive attribute information of a source container group and a destination container group input by a user. The source container group is a container group that sends access data, and the destination container group is a container group that receives the access data. Both the source container group and the destination container group include at least one container. The first determining unit is configured to determine the physical nodes where the source container group and the destination container group are located based on the attribute information; the attribute information includes the name of the container group and the namespace of the container group. The second determining unit is configured to determine a target network interface card (NIC) based on the physical nodes where the source container group and the destination container group are located. The target NIC is the NIC through which the access data passes. The target NIC includes a physical NIC and / or a virtual NIC. If the source container group and the destination container group are located on the same physical machine, the access data only passes through the virtual NIC. If the source container group and the destination container group are located on different physical machines, the access data will pass through both the physical NIC and the virtual NIC. The sending unit is used to send a packet capture command for the target network card to the physical node where the target network card is located.
7. The container network packet capture processing device according to claim 6, wherein, The virtual network interface card is a network interface card virtualized by the container network plugin. The virtual network interface card is used to enable communication between its own container group and other container groups. The second determining unit includes: a first determining module, configured to determine the network path of the access data based on the physical nodes where the source container group and the destination container group are located; and a second determining module, configured to determine the target network interface card based on the network path. The packet capture command is used to control the physical node to capture packets on the target network card; The attribute information includes the name of the container group and the namespace of the container group; The container network packet capture processing device further includes: a second receiving unit, configured to receive data packets of the target network card captured by the physical node after sending a packet capture command for the target network card to the physical node where the target network card is located; a storage unit, configured to store the data packets to a target location; and / or an analysis unit, configured to analyze the network fault causes between the source container group and the destination container group based on the data packets.
8. A readable storage medium having computer instructions stored thereon, wherein, When the computer instructions are executed by the processor, they implement the container network packet capture processing method according to any one of claims 1 to 5.
9. A container network packet capture and processing device, comprising a memory and a processor, wherein the memory stores computer instructions, When the computer instructions are executed by the processor, they implement the container network packet capture processing method according to any one of claims 1 to 5.
10. A computer program product, wherein, The computer program is executed by the processor to implement the container network packet capture processing method according to any one of claims 1 to 5.
Citation Information
Patent Citations
Kubernetes container network data packet index acquisition method and system based on dynamic service topology mapping
CN114143203A
Network packet capture fault positioning method and related device
CN114422337A