Processing of gateway service requests, management method and apparatus for cloud-native gateway system
Patent Information
- Application Number
- CN202310288631.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-03-22
- Publication Date
- 2026-09-15
- Estimated Expiration
- 2043-03-22
AI Technical Summary
[0004]在实现本公开构思的过程中,发明人发现相关技术中至少存在如下问题:无法保障Kubernetes中资源和服务的高可用
[0074] According to another aspect of this disclosure, a computer-readable storage medium is provided having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the methods described in this disclosure.
Smart Images

Figure CN116389599B_ABST
Abstract
Description
Technical Field
[0001] This disclosure relates to the fields of network technology and cloud-native technology, and more specifically, to a method for processing service requests, a method and apparatus for managing a cloud-native gateway system, an electronic device, a computer-readable storage medium, and a computer program product. Background Technology
[0002] An API (Application Programming Interface) gateway refers to a unified entry point at the system boundary that provides external access to internal interface services. Kubernetes can include collections of API resources based on different gateway definitions.
[0003] For example, there are Ingress API resource sets defined under the Ingress gateway and Gateway API resource sets defined under the Gateway gateway.
[0004] In realizing the concept disclosed herein, the inventors discovered at least the following problems in the related technologies: the high availability of resources and services in Kubernetes cannot be guaranteed. Summary of the Invention
[0005] In view of this, the present disclosure provides a method for processing service requests, a method and apparatus for managing cloud-native gateway systems, an electronic device, a computer-readable storage medium, and a computer program product.
[0006] According to one aspect of this disclosure, a method for processing gateway service requests is provided, comprising:
[0007] In response to receiving a pending gateway service request, based on the preset mapping relationship and the pending gateway service configuration information in the pending gateway service request, the target gateway cluster information corresponding to the target gateway cluster, the target gateway information corresponding to the target gateway, and the target service information corresponding to the target service are determined.
[0008] Based on the target gateway cluster information, the target gateway information, and the target service information, determine the running status of at least one container group corresponding to the target service.
[0009] Based on the operational status of each of the at least one container group corresponding to the target service, the target container group is determined from among the at least one container group; and
[0010] The aforementioned pending gateway service request is sent to the aforementioned target container group so that the aforementioned target container group can process the aforementioned pending gateway service request.
[0011] According to embodiments of this disclosure, in response to receiving a pending gateway service request, determining the target gateway cluster information corresponding to the target gateway cluster, the target gateway information corresponding to the target gateway, and the target service information corresponding to the target service, based on a preset mapping relationship and the pending gateway service configuration information in the pending gateway service request, includes:
[0012] Based on the above gateway service configuration information to be processed, determine the target virtual Internet Protocol address information;
[0013] Based on the first preset mapping relationship and the aforementioned target virtual Internet Protocol address information, determine the target gateway cluster information corresponding to the target gateway cluster;
[0014] Based on the target gateway cluster information mentioned above, determine the gateway address information corresponding to the target gateway and the service port information corresponding to the target service mentioned above.
[0015] Based on the second preset mapping relationship and the aforementioned gateway address information, the aforementioned target gateway information is determined; and
[0016] Based on the third preset mapping relationship and the above service port information, the above target service information is determined.
[0017] According to embodiments of this disclosure, the target gateway cluster includes at least one gateway, each of the at least one gateway corresponds to at least one service, each of the at least one gateway corresponds to gateway address information, and each of the at least one service corresponds to service port information.
[0018] According to embodiments of this disclosure, determining the gateway address information corresponding to the target gateway and the service port information corresponding to the target service based on the target gateway cluster information includes:
[0019] Based on the target gateway cluster information above, determine the network segment range of the target gateway cluster.
[0020] For each of the at least one of the aforementioned gateways, based on the network segment range of the target gateway cluster, determine the gateway address information corresponding to that gateway; and
[0021] For each of the at least one services corresponding to the aforementioned gateway, the service port information of the service corresponding to the aforementioned gateway is determined based on the gateway address information corresponding to the aforementioned gateway.
[0022] According to embodiments of this disclosure, the above response to receiving the pending service request, determining the target virtual Internet Protocol address information based on the pending gateway service configuration information includes:
[0023] In response to receiving the aforementioned pending gateway service request, the configuration information of the pending gateway service is parsed to obtain the domain name information corresponding to the pending gateway service request; and
[0024] Based on the domain name information above, the target virtual network address information is determined.
[0025] According to embodiments of this disclosure, the first preset mapping relationship includes at least one second key-value relationship, the second key-value relationship including second key information and second value information, and the at least one second key-value relationship is constructed in the following manner:
[0026] For each second key-value relationship in at least one second key-value relationship, in response to receiving a gateway creation instruction, obtain the gateway identifier, gateway configuration information and gateway cluster identifier;
[0027] Based on the aforementioned gateway cluster identifier, determine the virtual network address information corresponding to the aforementioned gateway cluster identifier;
[0028] Based on the target routing protocol and the aforementioned virtual network address information, determine the gateway address information corresponding to the aforementioned gateway identifier;
[0029] The aforementioned virtual gateway address information is determined as the aforementioned second key information;
[0030] The aforementioned gateway configuration information is determined as the aforementioned second value information; and
[0031] Based on the aforementioned second key information and the aforementioned second value information, the aforementioned second key-value relationship is constructed.
[0032] According to embodiments of this disclosure, when the target routing protocol is a border gateway protocol, determining the gateway address information corresponding to the gateway identifier based on the target routing protocol and the virtual network address information includes:
[0033] Based on the aforementioned virtual Internet Protocol address information, a first resource pool is configured, wherein the first resource pool includes at least one first candidate address information;
[0034] Based on the aforementioned first resource pool, target address information is determined from at least one first candidate address information; and
[0035] According to the aforementioned border gateway protocol, the target address information is published via any two front-end proxies so that the target address information can be identified as the gateway address information.
[0036] According to embodiments of this disclosure, when the target routing protocol is an equal-cost multi-path routing protocol, determining the gateway address information corresponding to the gateway identifier based on the target routing protocol and the virtual network address information includes:
[0037] Based on the aforementioned virtual Internet Protocol address information, a second resource pool is configured, wherein the aforementioned second resource pool includes at least one second candidate address information;
[0038] Based on the aforementioned second resource pool, the target address information is determined from the aforementioned at least one second candidate address information;
[0039] Configure the equivalent-cost multipath routing information corresponding to the aforementioned destination address information according to the above-described equivalent-cost multipath routing protocol; and
[0040] The equivalent routing information mentioned above is determined as the gateway address information mentioned above.
[0041] According to embodiments of this disclosure, the second preset mapping relationship includes at least one third key-value relationship, which includes third key information and third value information. The at least one third key-value relationship is constructed in the following manner:
[0042] For each third key-value relationship in at least one third key-value relationship, in response to receiving a service creation instruction, obtain the service identifier, service configuration information and gateway identifier;
[0043] Based on the aforementioned gateway identifier, determine the gateway address information corresponding to the aforementioned gateway identifier;
[0044] Based on the gateway address information above, determine the service port information corresponding to the service identifier above;
[0045] The above service port information is identified as the above third key information;
[0046] The above service configuration information is determined as the above third value information; and
[0047] Based on the aforementioned third key information and the aforementioned third value information, construct the aforementioned third key-value relationship.
[0048] According to embodiments of this disclosure, the target service information includes container group address information corresponding to each of the at least one container group.
[0049] According to embodiments of this disclosure, determining the operating status of at least one container group corresponding to the target service based on the target gateway cluster information, the target gateway information, and the target service information includes:
[0050] For each container group address in at least one container group address information, establish a probe network connection with the container group based on the container group address information.
[0051] If a heartbeat detection packet is received from the aforementioned container group within a predetermined time period, it is determined that the container group is in a normal operating state; and
[0052] If no heartbeat detection packet is received from the container group within the aforementioned predetermined time period, the operating status of the container group is determined to be abnormal.
[0053] According to embodiments of this disclosure, determining the target container group among the at least one container group based on the respective operating states of the at least one container group corresponding to the target service includes:
[0054] In response to the fact that the above container group is in a normal operating state, the above container group is identified as the target container group.
[0055] According to embodiments of this disclosure, sending the aforementioned pending gateway service request to the aforementioned target container group includes:
[0056] Determine the target container group address information corresponding to the above target container group;
[0057] Based on the target container group address information, establish an actual network connection with the target container group; and
[0058] Based on the actual network connection described above, the service requests to be processed are sent to the target container group.
[0059] According to another aspect of this disclosure, a management method for a cloud-native gateway system is provided, comprising:
[0060] The target gateway service request is processed using the gateway service request processing method to obtain the processing result. The target gateway service request includes target gateway service configuration information, which is associated with the cloud-native gateway system.
[0061] Based on the above processing results, the cloud-native gateway system is managed.
[0062] According to another aspect of this disclosure, a gateway service request processing apparatus is provided, comprising:
[0063] The first determining module is used to respond to receiving a request for a gateway service to be processed, and determine the target gateway cluster information corresponding to the target gateway cluster, the target gateway information corresponding to the target gateway, and the target service information corresponding to the target service based on the preset mapping relationship and the configuration information of the gateway service to be processed in the request for the gateway service to be processed.
[0064] The second determining module is used to determine the running status of at least one container group corresponding to the target service based on the target gateway cluster information, the target gateway information and the target service information.
[0065] The third determining module is used to determine the target container group from among the at least one container groups based on the respective running states of the at least one container group corresponding to the target service; and
[0066] The sending module is used to send the aforementioned gateway service request to be processed to the aforementioned target container group, so that the aforementioned target container group can process the aforementioned gateway service request.
[0067] According to another aspect of this disclosure, a management device for a cloud-native gateway system is provided, comprising:
[0068] The processing module is used to process the target gateway service request using the gateway service request processing device, and obtain the processing result, wherein the target gateway service request includes target gateway service configuration information, and the target gateway service configuration information is associated with the cloud-native gateway system; and
[0069] The management module is used to manage the cloud-native gateway system based on the above processing results.
[0070] According to another aspect of this disclosure, an electronic device is provided, comprising:
[0071] One or more processors;
[0072] Memory, used to store one or more instructions.
[0073] When one or more of the above instructions are executed by one or more processors, the one or more processors cause the one or more processors to implement the method as described in this disclosure.
[0074] According to another aspect of this disclosure, a computer-readable storage medium is provided having executable instructions stored thereon, which, when executed by a processor, cause the processor to perform the methods described in this disclosure.
[0075] According to another aspect of this disclosure, a computer program product is provided, which includes computer-executable instructions that, when executed, are used to perform the methods described in this disclosure.
[0076] According to embodiments of this disclosure, since the target container group is determined based on the running status of at least one container group corresponding to the target service, and the running status is determined based on the target gateway cluster information, target gateway information, and target service information, it is possible to determine the target container group whose running status is normal. Based on this, by sending the gateway service request to be processed to the target container group, automatic routing of the gateway service request is achieved. By utilizing the target container group to process the gateway service request to be processed, automatic processing of the gateway service request is achieved. Therefore, this at least partially overcomes the technical problem in related technologies that cannot guarantee the high availability of resources and services in Kubernetes, improves the stability of request processing, and thus ensures the high availability of resources and services. Attached Figure Description
[0077] The above and other objects, features and advantages of this disclosure will become clearer from the following description of embodiments with reference to the accompanying drawings, in which:
[0078] Figure 1 The illustration schematically shows the system architecture of a gateway service request processing method and a cloud-native gateway system management method applicable to embodiments of the present disclosure;
[0079] Figure 2 A flowchart illustrating a method for processing gateway service requests according to an embodiment of this disclosure is shown schematically.
[0080] Figure 3 This illustration shows an example diagram illustrating how, according to an embodiment of the present disclosure, target gateway cluster information, target gateway information, and target service information are determined based on a preset mapping relationship and the gateway service configuration information in the service request to be processed.
[0081] Figure 4 This illustration schematically shows an example diagram of constructing a second key-value relationship according to an embodiment of the present disclosure;
[0082] Figure 5A This illustration schematically shows an example diagram of determining gateway address information corresponding to a gateway identifier based on a target routing protocol and virtual network address information according to an embodiment of the present disclosure.
[0083] Figure 5B This illustration schematically shows an example diagram of determining gateway address information corresponding to a gateway identifier based on a target routing protocol and virtual network address information, according to another embodiment of this disclosure.
[0084] Figure 6 This illustration schematically shows an example diagram of constructing a third key-value relationship according to an embodiment of the present disclosure;
[0085] Figure 7 This illustration schematically shows an example diagram of determining the running status of at least one container group corresponding to a target service based on target gateway cluster information, target gateway information, and target service information, according to an embodiment of the present disclosure.
[0086] Figure 8 The illustration shows an example diagram of a gateway service request processing method according to an embodiment of the present disclosure;
[0087] Figure 9 This schematic diagram illustrates an example of a management method for a cloud-native gateway system according to an embodiment of the present disclosure;
[0088] Figure 10 A block diagram of a service request processing apparatus according to an embodiment of the present disclosure is shown schematically.
[0089] Figure 11 This schematically illustrates an example diagram of a management device for a cloud-native gateway system according to embodiments of the present disclosure; and
[0090] Figure 12 The diagram illustrates an electronic device suitable for implementing a gateway service request processing method and a cloud-native gateway system management method according to embodiments of the present disclosure. Detailed Implementation
[0091] The embodiments of the present disclosure will now be described with reference to the accompanying drawings. However, it should be understood that these descriptions are exemplary only and are not intended to limit the scope of the disclosure. In the following detailed description, numerous specific details are set forth to provide a thorough understanding of the embodiments of the present disclosure for ease of explanation. However, it will be apparent that one or more embodiments may be practiced without these specific details. Furthermore, descriptions of well-known structures and techniques are omitted in the following description to avoid unnecessarily obscuring the concepts of the present disclosure.
[0092] The terminology used herein is for the purpose of describing particular embodiments only and is not intended to limit this disclosure. The terms “comprising,” “including,” etc., as used herein indicate the presence of the stated features, steps, operations, and / or components, but do not exclude the presence or addition of one or more other features, steps, operations, or components.
[0093] All terms used herein (including technical and scientific terms) have the meanings commonly understood by those skilled in the art, unless otherwise defined. It should be noted that the terms used herein are to be interpreted in a manner consistent with the context of this specification, and not in an idealized or overly rigid way.
[0094] When using expressions such as "at least one of A, B, and C," the expression should generally be interpreted in accordance with the meaning commonly understood by a person skilled in the art (e.g., "a system having at least one of A, B, and C" should include, but is not limited to, systems having A alone, having B alone, having C alone, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.). Similarly, when using expressions such as "at least one of A, B, or C," the expression should generally be interpreted in accordance with the meaning commonly understood by a person skilled in the art (e.g., "a system having at least one of A, B, or C" should include, but is not limited to, systems having A alone, having B alone, having C alone, having A and B, having A and C, having B and C, and / or having A, B, and C, etc.).
[0095] In the embodiments disclosed herein, the collection, updating, analysis, processing, use, transmission, provision, disclosure, and storage of data (e.g., including but not limited to user personal information) comply with relevant laws and regulations, are used for legitimate purposes, and do not violate public order and good morals. In particular, necessary measures have been taken to prevent unauthorized access to user personal information data and to safeguard user personal information security, network security, and national security.
[0096] In the embodiments disclosed herein, user authorization or consent is obtained before acquiring or collecting user personal information.
[0097] For example, after collecting the configuration information of the gateway service to be processed, user information can be desensitized using methods such as de-identification or anonymization to protect user information security.
[0098] An API gateway can receive client requests, forward them to the appropriate backend system services according to predefined policies and routes, and process the results returned by the backend services.
[0099] Resources in the Ingress API resource set and the gateway API resource set can work together to build models for various network use cases. The gateway API resource set can include at least one of the following: gatewayclass resources, gateway resources, HTTPRoute resources, TCPRoute resources, and Service resources. The gateway API can achieve configuration decoupling by separating resource objects, allowing resources to be managed by different roles.
[0100] However, because the Ingress gateway definition has limited attributes such as host domain, path, and port, features like header rewriting, hosts file rewriting, and weighting require additional annotations within the Ingress gateway definition, resulting in a poor user experience. Furthermore, the current gateway definition only specifies the standard and does not implement the actual gatewayController responsible for distributing routing rules.
[0101] In summary, during the process of realizing the present invention, the inventors discovered at least the following problems in the related technologies: the high availability of resources and services in Kubernetes cannot be guaranteed.
[0102] To at least partially address the technical problems existing in related technologies, this disclosure provides a method for processing gateway service requests, a management method and apparatus for a cloud-native gateway system, which can be applied to the fields of network technology and cloud-native technology. The method for processing gateway service requests includes: in response to receiving a gateway service request to be processed, determining, based on a preset mapping relationship and the gateway service configuration information to be processed in the request, target gateway cluster information corresponding to the target gateway cluster, target gateway information corresponding to the target gateway, and target service information corresponding to the target service; determining the running status of at least one container group corresponding to the target service based on the target gateway cluster information, target gateway information, and target service information; determining the target container group among the at least one container group based on the running status of the at least one container group corresponding to the target service; and sending the gateway service request to be processed to the target container group so that the target container group can process the gateway service request.
[0103] It should be noted that the gateway service request processing method, cloud-native gateway system management method, and apparatus provided in this disclosure can be used in the fields of network technology and cloud-native technology, such as in the field of container technology. The gateway service request processing method, cloud-native gateway system management method, and apparatus provided in this disclosure can also be used in any field other than network technology and cloud-native technology, such as in the field of information processing technology. The application fields of the gateway service request processing method, cloud-native gateway system management method, and apparatus provided in this disclosure are not limited.
[0104] Figure 1 This illustration schematically depicts a system architecture for a gateway service request processing method and a cloud-native gateway system management method applicable to embodiments of this disclosure. It should be noted that... Figure 1The examples shown are merely examples of system architectures that can be applied to the embodiments of this disclosure, in order to help those skilled in the art understand the technical content of this disclosure, but do not mean that the embodiments of this disclosure cannot be used in other devices, systems, environments or scenarios.
[0105] like Figure 1 As shown, the system architecture 100 according to this embodiment may include a first terminal device 101, a second terminal device 102, a third terminal device 103, a network 104, and a server 105. The network 104 serves as a medium for providing communication links between the first terminal device 101, the second terminal device 102, the third terminal device 103, and the server 105. The network 104 may include various connection types, such as wired or wireless communication links, or fiber optic cables, etc.
[0106] Users can interact with server 105 via network 104 using at least one of the first terminal device 101, second terminal device 102, and third terminal device 103 to receive or send messages, etc. Various communication client applications can be installed on the first terminal device 101, second terminal device 102, and third terminal device 103, such as shopping applications, web browser applications, search applications, instant messaging tools, email clients, social media platform software, etc. (for example only).
[0107] The first terminal device 101, the second terminal device 102, and the third terminal device 103 can be various electronic devices with displays and support web browsing, including but not limited to smartphones, tablets, laptops, and desktop computers.
[0108] Server 105 can be a server that provides various services, such as a backend management server that supports websites browsed by users using the first terminal device 101, the second terminal device 102, and the third terminal device 103 (this is just an example). The backend management server can analyze and process data such as received user requests, and feed back the processing results (such as web pages, information, or data obtained or generated according to user requests) to the terminal devices.
[0109] It should be noted that the gateway service request processing method and the cloud-native gateway system management method provided in this disclosure embodiment can generally be executed by server 105. Correspondingly, the gateway service request processing device and the cloud-native gateway system management device provided in this disclosure embodiment can generally be located in server 105. The gateway service request processing method and the cloud-native gateway system management method provided in this disclosure embodiment can also be executed by a server or server cluster that is different from server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105. Correspondingly, the gateway service request processing device and the cloud-native gateway system management device provided in this disclosure embodiment can also be located in a server or server cluster that is different from server 105 and can communicate with the first terminal device 101, the second terminal device 102, the third terminal device 103, and / or server 105.
[0110] Alternatively, the gateway service request processing method and the cloud-native gateway system management method provided in the embodiments of this disclosure can also be executed by the first terminal device 101, the second terminal device 102, or the third terminal device 103, or by other terminal devices different from the first terminal device 101, the second terminal device 102, or the third terminal device 103. Correspondingly, the gateway service request processing device and the cloud-native gateway system management device provided in the embodiments of this disclosure can also be located in the first terminal device 101, the second terminal device 102, or the third terminal device 103, or in other terminal devices different from the first terminal device 101, the second terminal device 102, or the third terminal device 103.
[0111] It should be understood that Figure 1 The number of terminal devices, networks, and servers shown is merely illustrative. Depending on implementation needs, any number of terminal devices, networks, and servers can be included.
[0112] It should be noted that the sequence numbers of the operations in the following methods are for descriptive purposes only and should not be considered as indicating the execution order of the operations. Unless explicitly stated otherwise, the method does not need to be executed in the exact order shown.
[0113] Figure 2 A flowchart illustrating a method for processing gateway service requests according to an embodiment of this disclosure is shown schematically.
[0114] like Figure 2 As shown, the gateway service request processing method 200 includes operations S210 to S240.
[0115] In operation S210, in response to receiving a pending gateway service request, the target gateway cluster information corresponding to the target gateway cluster, the target gateway information corresponding to the target gateway, and the target service information corresponding to the target service are determined according to the preset mapping relationship and the pending gateway service configuration information in the pending gateway service request.
[0116] In operation S220, based on the target gateway cluster information, target gateway information, and target service information, the running status of at least one container group corresponding to the target service is determined.
[0117] In operation S230, the target container group is determined in at least one container group based on the running status of each of the at least one container group corresponding to the target service.
[0118] In operation S240, the pending gateway service request is sent to the target container group so that the target container group can process the pending gateway service request.
[0119] According to embodiments of this disclosure, the method for processing gateway service requests can be implemented based on the Kubernetes container orchestration engine. In Kubernetes, multiple containers can be created, each running an application instance, and built-in mechanisms can be used to manage and access these application instances. For example, a gateway proxy can be used to expose services within Kubernetes to the outside of the cluster or forward requests from outside the cluster to the inside of the cluster for access by clients outside the cluster.
[0120] According to embodiments of this disclosure, the interaction between Kubernetes and the client can be implemented in at least one of the following ways: an Ingress-based approach and an Ingress Controller approach, or a gateway-based approach and a gatewayController approach. Ingress and gateway can refer to routing rules defined by the client. IngressController and gatewayController can be provided by a software vendor and can dynamically detect changes in routing rules within the cluster through interaction with Kubernetes.
[0121] According to embodiments of this disclosure, code for generating a gateway service request to be processed can be pre-written into a target script. In response to detecting a gateway service processing operation initiated by a target user using a target terminal, the target terminal can run the target script, generate a gateway service request message to be processed, and send the message to the server so that the server can process the gateway service request message to be processed.
[0122] According to embodiments of this disclosure, the preset mapping relationship may include at least one of the following: a preset mapping relationship between Virtual Internet Protocol Address (VIP) information and gateway cluster information, a preset mapping relationship between gateway address information and gateway information, and a preset mapping relationship between service port information and service information.
[0123] According to embodiments of this disclosure, gateway cluster information can be used to describe different gateway clusters. Gateway cluster information may include at least one of a gateway cluster identifier and a gateway cluster name. For example, based on a preset mapping relationship between virtual Internet Protocol (VPN) address information and gateway cluster information, a VPN address information matching the configuration information of the service to be processed can be determined. In this case, the gateway cluster information corresponding to the VPN address information can be determined as the target gateway cluster information.
[0124] According to embodiments of this disclosure, a gateway cluster may include at least one gateway. Each of the at least one gateway may have its own gateway address information. For example, a gateway may refer to an API gateway (i.e., an Application Programming Interface gateway). A gateway may include at least one of the following: a Spring Cloud Gateway gateway and an Nginx gateway. A gateway can route requests received from clients to forward them to the corresponding backend services. Furthermore, a gateway can route data received from backend services to forward the data to the corresponding clients.
[0125] According to embodiments of this disclosure, gateway information can be used to describe different gateways. Gateway information may include at least one of a gateway identifier and a gateway name. For example, a gateway address information matching the configuration information of the service to be processed can be determined based on a preset mapping relationship between gateway address information and gateway information. In this case, the gateway information corresponding to the gateway address information can be determined as the target gateway information.
[0126] According to embodiments of this disclosure, each of the at least one gateway may correspond to at least one service. Each of the at least one service may correspond to service port information. The service information may be used to describe different services. The service information may include at least one of a service identifier and a service name. For example, service port information matching the configuration information of the service to be processed can be determined based on a preset mapping relationship between service port information and service information. In this case, the service information corresponding to the service port information can be determined as the target service information.
[0127] According to embodiments of this disclosure, each of the at least one service may correspond to at least one container group (i.e., pod). A container group can represent the smallest deployable computing unit created and managed in a container cluster. Each of the at least one container group may include at least one container. Each of the at least one container group may have corresponding container group address information. After obtaining the target gateway cluster information, target gateway information, and target service information, the running status of each of the at least one container group can be determined based on the container group address information of each of the at least one container group corresponding to the target service. The running status can be used to characterize whether the container group is operating normally.
[0128] According to embodiments of this disclosure, after obtaining the operating status of at least one container group corresponding to the target service, the target container group can be determined from the at least one container group based on the operating status of each container group. For example, the container group whose operating status indicates normal operation can be determined as the target container group.
[0129] According to embodiments of this disclosure, after determining the target container group, a gateway service request to be processed can be sent to the target container group based on the container group address information corresponding to the target container group, so that the target container group can process the gateway service request to be processed and return a processing result message.
[0130] According to embodiments of this disclosure, since the target container group is determined based on the running status of at least one container group corresponding to the target service, and the running status is determined based on the target gateway cluster information, target gateway information, and target service information, it is possible to determine the target container group whose running status is normal. Based on this, by sending the gateway service request to be processed to the target container group, automatic routing of the gateway service request is achieved. By utilizing the target container group to process the gateway service request to be processed, automatic processing of the gateway service request is achieved. Therefore, this at least partially overcomes the technical problem in related technologies that cannot guarantee the high availability of resources and services in Kubernetes, improves the stability of request processing, and thus ensures the high availability of resources and services.
[0131] The following is for reference. Figure 3 , Figure 4 , Figure 5A , Figure 5B , Figure 6 , Figure 7 and Figure 8 The method 200 for processing gateway service requests according to an embodiment of the present invention will be further described.
[0132] According to embodiments of this disclosure, the gateway service request processing method 200 can be implemented based on a gatewayController. The gatewayController can listen for gateway update events, assign virtual Internet Protocol (IP) addresses to the gateway, and store gateway listening content in a distributed registry (e.g., ETCD). Furthermore, the gatewayController can monitor domain names, paths, request parameter rewriting, backends, and weights on HTTP routes, and store HTTP route listening content in a distributed registry.
[0133] According to embodiments of this disclosure, based on the native semantics of the v1beta version of the gateway, the code logic of the gatewayController is formed by extending and supplementing the k8s-gateway standard, thereby realizing the gateway control plane service. Data plane services are realized by dynamically adding and deleting open-source gateway listening ports using a front-end proxy. Based on this, the gatewayController and the front-end proxy work together to schedule VIPs, thus forming a complete cloud-native Layer 7 gateway service. This will be described below with reference to specific embodiments.
[0134] According to embodiments of this disclosure, operation S210 may include the following operations.
[0135] Based on the gateway service configuration information to be processed, determine the target virtual Internet Protocol (VPN) address information. Based on the first preset mapping relationship and the target VPN address information, determine the target gateway cluster information corresponding to the target gateway cluster. Based on the target gateway cluster information, determine the gateway address information corresponding to the target gateway and the service port information corresponding to the target service. Based on the second preset mapping relationship and the gateway address information, determine the target gateway information. Based on the third preset mapping relationship and the service port information, determine the target service information.
[0136] According to embodiments of this disclosure, gateway clusters, gateways, and services can belong to Custom Resource Definitions (CRDs). After obtaining the configuration information of the gateway service to be processed, the configuration information can be processed to obtain a processing result. Based on the processing result, the target virtual network address information is determined. The target virtual network address information can be used to indicate the target gateway cluster. The processing method for the configuration information of the service to be processed can be configured according to actual business needs and is not limited here. For example, the configuration information of the service to be processed can be parsed to obtain the domain name information corresponding to the service request to be processed. Based on this, the target virtual network address information is then determined according to the domain name information.
[0137] According to embodiments of this disclosure, a first preset mapping relationship can be used to represent a preset mapping relationship between virtual Internet Protocol (VPN) address information and gateway cluster information. The first preset mapping relationship may include at least one first key-value relationship. A first key-value relationship can be created based on the VPN address information and gateway cluster information. The first key-value relationship may include a one-to-one correspondence between the VPN address information and the gateway cluster information. A gateway cluster can be represented using a gatewayclass. A gatewayclass can refer to a group of gateways with common configurations and behaviors. Gateway clusters can be used to describe the definition of different gateway services by Kubernetes operations and maintenance, enabling selective authorization of gateway clusters that conform to business scenarios to business operations and maintenance.
[0138] According to embodiments of this disclosure, a second preset mapping relationship can be used to represent a preset mapping relationship between gateway address information and gateway information. A gateway can be represented using the term "gateway". A gateway can refer to a point capable of redirecting traffic to services within the cluster. A gateway can be used to describe the scope of service operations' use of the gateway, for example, which namespace's services can use it. Furthermore, a gateway has a VIP and a listening port, allowing service operations to authorize service users within the specified scope through the gateway.
[0139] According to embodiments of this disclosure, a third preset mapping relationship can be used to represent a preset mapping relationship between service port information and service information. Routing can be represented using httproute. httproute can refer to how traffic obtained through a gateway is mapped to a service. httproute can be used to describe the matching rules between business users and business services; for example, domain names, paths, and backends can be bound to the gateway to expose services externally.
[0140] According to the embodiments of this disclosure, since the target gateway cluster information is determined based on the first preset mapping relationship and the target virtual Internet Protocol address information, the target gateway information is determined based on the second preset mapping relationship and the gateway address information, and the target service information is determined based on the third preset mapping relationship and the service port information, the target gateway cluster information, target gateway information and target service information are automatically determined based on the gateway service configuration information to be processed, thereby improving the efficiency of information processing and thus improving the efficiency of gateway service request processing.
[0141] Figure 3The illustration shows an example diagram illustrating how, according to an embodiment of the present disclosure, target gateway cluster information corresponding to a target gateway cluster, target gateway information corresponding to a target gateway, and target service information corresponding to a target service are determined based on a preset mapping relationship and the configuration information of the target gateway service in the request for the target gateway service.
[0142] like Figure 3 As shown in Figure 300, the information determination method of this disclosure embodiment is illustrated by taking at least one gateway cluster including gateway cluster 304_1 and gateway cluster 304_2, at least one gateway corresponding to gateway cluster 304_1 including gateway 304_11 and gateway 304_12, at least one service corresponding to gateway 304_11 including service 304_111, at least one service corresponding to gateway 304_12 including service 304_121 and service 304_122, at least one gateway corresponding to gateway cluster 304_2 including gateway 304_21 and gateway 304_22, at least one service corresponding to gateway 304_21 including service 304_211, service 304_212 and service 304_213, and at least one service corresponding to gateway 304_22 including service 304_221 as an example.
[0143] In response to receiving a pending gateway service request 301, the target virtual Internet Protocol (VPN) address information 302 can be determined based on the pending gateway service configuration information 301_1 in the request. Based on the target VPN address information 302 and a first preset mapping relationship, the target gateway cluster information corresponding to gateway cluster 304_2 can be determined. Based on the target gateway cluster information corresponding to gateway cluster 304_2, gateway address information 305 and service port information 307 can be determined. Based on the gateway address information 305 and a second preset mapping relationship 306, the target gateway information corresponding to gateway 304_21 can be determined. Based on the service port information 307 and a third preset mapping relationship 308, the target service information corresponding to service 304_212 can be determined.
[0144] According to embodiments of this disclosure, determining the target virtual Internet Protocol address information based on the gateway service configuration information to be processed may include the following operations.
[0145] Upon receiving a pending gateway service request, the system parses the pending gateway service configuration information to obtain the domain name information corresponding to the request. Based on the domain name information, the target virtual network address information is determined.
[0146] According to embodiments of this disclosure, domain name information can refer to the name of a computer or group of computers on the Internet, consisting of a string of names separated by dots. Domain name information can be used to identify the electronic location of a computer during data transmission.
[0147] According to embodiments of this disclosure, after obtaining domain name information, the domain name information can be further processed by domain name resolution to map the domain name information into an IP address, thereby obtaining the target virtual network address information. The domain name resolution processing method can be configured according to actual business needs and is not limited here. For example, the domain name resolution processing method may include at least one of the following: recursive resolution and iterative resolution. Recursive resolution may refer to completing the name and address transformation in one step. Iterative resolution may refer to requesting a single server each time.
[0148] According to embodiments of this disclosure, at least one second key-value relationship can be constructed in the following manner.
[0149] For each of at least one second key-value relationship, in response to receiving a gateway creation instruction, the gateway identifier, gateway configuration information, and gateway cluster identifier are obtained. Based on the gateway cluster identifier, the virtual network address information corresponding to the gateway cluster identifier is determined. Based on the target routing protocol and the virtual network address information, the gateway address information corresponding to the gateway identifier is determined. The gateway address information is determined as the second key information. The gateway configuration information is determined as the second value information. Based on the second key information and the second value information, the second key-value relationship is constructed.
[0150] According to embodiments of this disclosure, the second preset mapping relationship may include at least one second key-value relationship. The second key-value relationship may include second key information and second value information.
[0151] According to embodiments of this disclosure, a Kubernetes cluster can obtain the configuration information of a newly created gateway upon detecting its existence, and then generate a gateway creation command based on this information. The gateway configuration information may include at least one of the following: a gateway identifier and a gateway cluster identifier.
[0152] According to embodiments of this disclosure, the code for generating a gateway creation instruction can be pre-written into a first script. In response to detecting a gateway creation operation initiated by a target user using a target terminal, the target terminal can run the first script, generate a gateway creation instruction message, and send the message to the server so that the server can create a gateway based on the message.
[0153] According to embodiments of this disclosure, a target routing protocol can be used to translate between private IP addresses and public IP addresses to enable access to the Internet. A private IP address can refer to an address used within a local area network (LAN). A public IP address can refer to an address that can be directly accessed on the Internet.
[0154] According to embodiments of this disclosure, the target routing protocol can be configured according to actual business needs, and is not limited thereto. For example, the target routing protocol may include at least one of the following: ALL-IN mode routing protocol, Equal Cost Multi Path (ECMP) routing protocol, Border Gateway Protocol (BGP) routing protocol, and Open Shortest Path First (OSPF) routing protocol.
[0155] According to embodiments of this disclosure, gateway address information corresponding to a gateway identifier can be determined based on the target routing protocol and virtual network address information. After obtaining the virtual network address information and gateway address information, a second key-value relationship can be created based on the gateway address information and gateway configuration information. The second key-value relationship may include a one-to-one correspondence between the gateway address information and the gateway configuration information.
[0156] According to embodiments of this disclosure, in this case, determining the target gateway information based on the second preset mapping relationship and gateway address information may include: determining at least one first similarity based on the gateway address information and second key information corresponding to at least one second key-value relationship; determining target second key information based on the at least one first similarity; determining target second value information corresponding to target second value information based on the target second key information; and determining the target gateway information based on gateway configuration information corresponding to the target second value information.
[0157] According to embodiments of this disclosure, since the second preset mapping relationship may include at least one second key-value relationship, which is determined in response to receiving a gateway creation instruction, the second key-value relationship may include a one-to-one correspondence between gateway address information and gateway configuration information. This is beneficial for automatically determining the target gateway information using the second preset mapping relationship, thereby improving the efficiency of determining the target gateway information and thus improving the efficiency of processing gateway service requests.
[0158] Figure 4 The illustration shows an example diagram of constructing a second key-value relationship according to an embodiment of the present disclosure.
[0159] like Figure 4 As shown in 400, in response to receiving the gateway creation instruction 401, the gateway configuration information 401_1, the gateway cluster identifier 401_2, and the gateway identifier 401_3 can be obtained.
[0160] Based on the gateway cluster identifier 401_2, the virtual network address information 402 corresponding to the gateway cluster identifier 401_2 can be determined. After obtaining the virtual network address information 402, the gateway address information 404 corresponding to the gateway identifier 401_3 can be determined based on the target routing protocol 403 and the virtual network address information 402.
[0161] After obtaining the gateway address information 404, the gateway address information 404 can be determined as the second key information 405. The gateway configuration information 401_1 can be determined as the second value information 406. Based on the second key information 405 and the second value information 406, the second key-value relationship 407 is constructed.
[0162] According to embodiments of this disclosure, when the target routing protocol is a border gateway protocol, determining the gateway address information corresponding to the gateway identifier based on the target routing protocol and virtual network address information may include the following operations.
[0163] Based on the Virtual Internet Protocol (VIP) address information, a first resource pool is configured, wherein the first resource pool includes at least one first candidate address. Based on the first resource pool, target address information is determined from the at least one first candidate address. According to the Border Gateway Protocol (BGP), the target address information is published via any two front-end proxies to facilitate the determination of the target address information as the gateway address information.
[0164] According to embodiments of this disclosure, a border gateway protocol can refer to a dynamic routing protocol used for exchanging routing information between different Autonomous Systems (AS) or within the same Autonomous System. For example, when two Autonomous Systems need to exchange routing information, a node running a border gateway protocol can be designated for each Autonomous System, and this node can exchange routing information with other Autonomous Systems on behalf of the Autonomous System.
[0165] According to embodiments of this disclosure, a node running a border gateway protocol may include at least one of a host and a router. Taking a router as an example, after receiving routing information from an upstream neighbor, the router can download the optimal route from the dynamic routing protocol learned by the device to the driver to guide traffic forwarding, and can also advertise the optimal route from the dynamic routing protocol learned by the device to its neighbors.
[0166] According to embodiments of this disclosure, the first resource pool may include at least one first candidate address information. The first candidate address information may refer to a VIP address. At least one first candidate address information may be managed and scheduled by the gatewayController. The first resource pool may include at least one of the following: a first dynamic resource pool and a first static resource pool.
[0167] According to embodiments of this disclosure, after receiving a gateway creation instruction, a corresponding first resource pool can be configured for the terminal based on the Virtual Internet Protocol (VIP) address information. After determining the first resource pool, target address information can be determined from at least one first candidate address information, and the target address information is returned to the gateway. Furthermore, the task of publishing the gateway address information corresponding to the gateway can be notified to any two front-end agents (i.e., agents), and the target address information can be published to the switch via these two front-end agents based on the Border Gateway Protocol (BGP) and bound to the local loopback interface. The nodes of any two front-end agents can be configured according to actual business needs and are not limited here, as long as they are an even number of nodes. For example, they can be the 2nth node and the 2n+1th node.
[0168] According to embodiments of this disclosure, the front-end proxy can be deployed within the same container as an open-source gateway (e.g., Apisix), using Kubernetes StatefulSets for multi-replica deployment. Host-based network mode is selected, and Kubernetes taints and anti-affinity can be used to exclude other containers, achieving exclusive node access. Multi-replica deployment can refer to master election through Kubernetes leases, meaning only the master node is responsible for listening to events and reading / writing to the distributed registry service center. The front-end proxy can reload its listening port to the open-source gateway, thereby enabling dynamic addition and deletion of the open-source gateway's listening port.
[0169] According to embodiments of this disclosure, the gatewayController can work with a front-end agent to schedule VIPs. For example, the Kubernetes downward API can be used to map PodIP and PodName to the container's environment variables. The front-end agent can extract the sequence number from the PodName and report its own heartbeat and sequence number to the gatewayController. The gatewayController can perform bitwise operations on the VIP to obtain the decimal sum of the four IP segments, and then perform a modulo operation on the number of Apisix nodes to obtain the corresponding node. The gatewayController can then write the VIP to the distributed registry service center directory of the corresponding node to complete the scheduling of the VIP.
[0170] According to embodiments of this disclosure, since the target address information is determined from at least one first candidate address based on a first resource pool, automatic determination of the target address information is achieved, thereby shortening the VIP address scheduling time, improving the processing efficiency of VIP address scheduling, and further improving the efficiency of gateway address information determination. Furthermore, since the gateway address information is determined according to the Border Gateway Protocol by publishing target address information through any two front-end proxies, optimization for operations and maintenance and business users is achieved.
[0171] Figure 5A The illustration shows an example diagram of determining gateway address information corresponding to a gateway identifier based on a target routing protocol and virtual network address information according to an embodiment of the present disclosure.
[0172] like Figure 5A As shown, in 500A, a first resource pool 502 can be configured based on the virtual Internet Protocol address information 501. The first resource pool 502 can include at least one first candidate address information. At least one first candidate address information can include first candidate address information 502_1, first candidate address information 502_2, ..., first candidate address information 502_p, ..., first candidate address information 502_P. P can be an integer greater than or equal to 1, where p∈{1, 2, ..., (P-1), P}.
[0173] The target address information 503 can be determined from the first candidate address information 502_1, first candidate address information 502_2, ..., first candidate address information 502_p, ..., first candidate address information 502_P. According to the border gateway protocol 504, the target address information 503 is published via front-end agent 505_1 and front-end agent 505_2 so that the target address information 503 can be identified as the gateway address information 506.
[0174] According to embodiments of this disclosure, when the target routing protocol is an equal-cost multipath routing protocol, determining the gateway address information corresponding to the gateway identifier based on the target routing protocol and the virtual network address information may include the following operations.
[0175] Based on the Virtual Internet Protocol (VIP) address information, a second resource pool is configured, wherein the second resource pool includes at least one second candidate address. Based on the second resource pool, target address information is determined from the at least one second candidate address. According to the Equal-Cost Multi-Path (ECM) routing protocol, equal-cost routing information corresponding to the target address information is configured. The equal-cost routing information is then determined as the gateway address information.
[0176] According to embodiments of this disclosure, an equal-cost multi-path routing protocol can refer to a network environment in which multiple links are used simultaneously in any network environment, i.e., a network environment where multiple different links lead to the same destination address. The path selection method of the equal-cost multi-path routing protocol can be configured according to actual business needs and is not limited herein. For example, the path selection method may include at least one of the following: a hash-based path selection method, a round-robin-based path selection method, and a path weight-based path selection method.
[0177] According to embodiments of this disclosure, the second resource pool may include at least one second candidate address information. The second candidate address information may refer to a VIP address. At least one second candidate address information may be managed and scheduled by the gatewayController. The second resource pool may include at least one of the following: a second dynamic resource pool (i.e., Dynamic Pool) and a second static resource pool (i.e., Static Pool).
[0178] According to embodiments of this disclosure, VIP network segments can be equivalently routed to all nodes of apisix by configuring equal-cost routing on the switch. After receiving the gateway creation instruction, a corresponding second resource pool can be configured for the terminal based on the virtual Internet Protocol address information. After determining the second resource pool, target address information can be determined from at least one second candidate address information, and equal-cost routing information corresponding to the target address information can be configured via an equal-cost multipath routing protocol, and the equal-cost routing information can be returned to the gateway.
[0179] According to embodiments of this disclosure, when the target routing protocol is an ALL-IN mode routing protocol, all apisix node IPs reported by the front-end agent can be returned to the gateway, allowing business users to select one or more of these IP gateway address information. The implementation in this case is relatively simple.
[0180] According to embodiments of this disclosure, since the target address information is determined from at least one second candidate address based on a second resource pool, automatic determination of the target address information is achieved, thereby shortening the VIP address scheduling time, improving the processing efficiency of VIP address scheduling, and consequently improving the efficiency of gateway address information determination. Furthermore, since the gateway address information is determined according to an equal-cost multipath routing protocol by configuring equal-cost routing information corresponding to the target address information, it is more user-friendly and improves the user experience.
[0181] Figure 5B The illustration shows an example diagram of determining gateway address information corresponding to a gateway identifier based on a target routing protocol and virtual network address information, according to another embodiment of the present disclosure.
[0182] like Figure 5B As shown, in 500B, a second resource pool 508 can be configured based on the Virtual Internet Protocol (VIP) address information 507. The second resource pool 508 can include at least one second candidate address information. The at least one second candidate address information can include second candidate address information 508_1, second candidate address information 508_2, ..., second candidate address information 508_q, ..., second candidate address information 508_Q. Q can be an integer greater than or equal to 1, where q∈{1, 2, ..., (Q-1), Q}.
[0183] The target address information 509 can be determined from the second candidate address information 508_1, second candidate address information 508_2, ..., second candidate address information 508_q, ..., second candidate address information 508_Q. According to the equal-cost multipath routing protocol 510, the equal-cost routing information 511 corresponding to the target address information 509 is configured. The equal-cost routing information 511 is then determined as the gateway address information 512.
[0184] According to embodiments of this disclosure, determining the gateway address information corresponding to the target gateway and the service port information corresponding to the target service based on the target gateway cluster information may include the following operations.
[0185] Based on the target gateway cluster information, determine the network segment range of the target gateway cluster. For each gateway among at least one gateway, determine the gateway address information corresponding to the gateway based on the network segment range of the target gateway cluster. For each service among at least one service corresponding to a gateway, determine the service port information of the service corresponding to the gateway based on the gateway address information corresponding to the gateway.
[0186] According to embodiments of this disclosure, a target gateway cluster may include at least one gateway. Each of the at least one gateway may correspond to at least one service. Each of the at least one gateway may correspond to gateway address information. Each of the at least one service may correspond to service port information.
[0187] According to embodiments of this disclosure, after obtaining target gateway cluster information, the network segment range of the target gateway cluster can be determined based on the target gateway cluster information. The network segment range can be represented using WXYZ, where W, X, Y, and Z ∈ [0, 255]. For example, the network segment range can be set to W ∈ [0, 10], X ∈ [0, 10], Z ∈ [0, 10], and Z ∈ [0, 255], meaning the network segment range can include Internet Protocol addresses within the range of 0.0.0.0 to 10.10.10.255. After obtaining the network segment range of the target gateway cluster, gateway address information corresponding to each gateway in at least one gateway can be determined.
[0188] According to embodiments of this disclosure, at least one third key-value relationship can be constructed in the following manner.
[0189] For each third key-value relationship in at least one third key-value relationship, in response to receiving a service creation instruction, obtain the service identifier, service configuration information, and gateway identifier. Based on the gateway identifier, determine the gateway address information corresponding to the gateway identifier. Based on the gateway address information, determine the service port information corresponding to the service identifier. Use the service port information as the third key information. Use the service configuration information as the third value information. Construct the third key-value relationship based on the third key information and the third value information.
[0190] According to embodiments of this disclosure, the third preset mapping relationship may include at least one third key-value relationship. The third key-value relationship may include third key information and third value information.
[0191] According to embodiments of this disclosure, a Kubernetes cluster can obtain the configuration information of a newly created service upon detecting its existence, and then generate a service creation command based on this information. The service configuration information may include at least one of the following: container address, service domain name, service port, and service annotation information.
[0192] According to embodiments of this disclosure, the code for generating a service creation instruction can be pre-written into a second script. In response to detecting a service creation operation initiated by a target user using a target terminal, the target terminal can run the second script, generate a service creation instruction message, and send the message to the server so that the server can create a service based on the message.
[0193] According to embodiments of this disclosure, gateway address information corresponding to a gateway identifier can be determined based on the gateway identifier. Service port information corresponding to a service identifier can be determined based on the gateway address information. After obtaining the service port information, a third key-value relationship can be created based on the service port information and service configuration information. The third key-value relationship may include a one-to-one correspondence between the service port information and the service configuration information.
[0194] According to embodiments of this disclosure, in this case, determining the target service information based on the third preset mapping relationship and service port information may include: determining at least one second similarity based on the service port information and third key information corresponding to at least one third key value relationship; determining target third key information based on the at least one second similarity; determining target third value information corresponding to the target third value information based on the target third key information; and determining the target service information based on the service configuration information corresponding to the target third value information.
[0195] According to embodiments of this disclosure, since the third preset mapping relationship may include at least one third key-value relationship, which is determined in response to receiving a service creation instruction, the third key-value relationship may include a one-to-one correspondence between service port information and service configuration information. This is beneficial for automatically determining the target service information using the third preset mapping relationship, thereby improving the efficiency of determining the target service information and thus improving the efficiency of processing service requests.
[0196] Figure 6 The illustration shows an example diagram of constructing a third key-value relationship according to an embodiment of the present disclosure.
[0197] like Figure 6 As shown in 600, in response to receiving the service creation instruction 601, the gateway service configuration information 601_1, the gateway identifier 601_2, and the service identifier 601_3 can be obtained.
[0198] Based on the gateway identifier 601_2, the gateway address information 602 corresponding to the gateway identifier 601_2 can be determined. Based on the gateway address information 602, the service port information 603 corresponding to the service identifier 601_3 can be determined.
[0199] The service port information 603 can be identified as the third key information 604. The gateway service configuration information 601_1 can be identified as the third value information 605. Based on the third key information 604 and the third value information 605, a third key-value relationship 606 can be constructed.
[0200] According to embodiments of this disclosure, operation S220 may include the following operations.
[0201] For each container group address in at least one container group address information, a probe network connection is established with the container group based on the container group address information. If a heartbeat probe packet is received from the container group within a predetermined time period, the container group's operating status is determined to be in a normal operating state. If no heartbeat probe packet is received from the container group within the predetermined time period, the container group's operating status is determined to be in an abnormal operating state.
[0202] According to embodiments of this disclosure, the target service information may include container group address information corresponding to at least one container group.
[0203] According to embodiments of this disclosure, a probe network connection can be used to characterize short connections between the gatewayController and the container group. A short connection refers to a connection established only when data needs to be sent during data transmission, and then closed after the data transmission is complete; that is, each connection only completes the transmission of one service. After establishing the probe network connection, heartbeat probe packets can be sent to the container group based on the probe network connection.
[0204] According to embodiments of this disclosure, a heartbeat detection packet can refer to a custom command word that periodically notifies the gatewayController and the container group of their respective statuses. The heartbeat detection packets can be sent at predetermined time intervals. The predetermined time interval can be set according to actual business needs and is not limited here. The predetermined time interval can be a pre-set detection time range, for example, a predetermined time interval can be set to 30 minutes.
[0205] According to embodiments of this disclosure, operation S230 may include the following operations.
[0206] If the container group is in a normal operating state, the container group is identified as the target container group.
[0207] According to embodiments of this disclosure, an abnormal operating state can be determined when no heartbeat probe packet is received from the container group within a predetermined time period. A normal operating state can be determined when a heartbeat probe packet is received from the container group within a predetermined time period. A container group whose operating state is normal can be identified as the target container group.
[0208] Figure 7 The illustration shows an example diagram illustrating how, according to an embodiment of the present disclosure, the operating status of at least one container group corresponding to a target service is determined based on target gateway cluster information, target gateway information, and target service information.
[0209] like Figure 7 As shown, in step 700, for each container group address information 701 in at least one container group address information, a probe network connection 702 can be established between the container group and the container group based on the container group address information 701. After establishing the probe network connection 702, operation S710 can be performed.
[0210] During the operation of S710, a heartbeat detection packet sent by the container group is received within a predetermined time period?
[0211] If so, then the container group's operating status can be determined to be normal operating status 703.
[0212] If not, then the container group's operating status can be determined to be abnormal operating status 704.
[0213] According to embodiments of this disclosure, operation S240 may include the following operations.
[0214] Determine the target container group address information corresponding to the target container group. Establish the actual network connection between the target container group and the target container group based on the target container group address information. Send the service request to be processed to the target container group based on the actual network connection.
[0215] According to embodiments of this disclosure, a physical network connection can be established between the gatewayController and the target container group based on the target container group's address information. This physical network connection can characterize a persistent connection between the gatewayController and the target container group. A persistent connection can refer to a connection capable of continuously sending multiple data packets. After establishing the physical network connection, the gateway service request to be processed can be sent to the target container group through this physical network connection based on application layer protocols.
[0216] According to embodiments of this disclosure, the application layer protocol may include at least one of the following: WebSocket, HyperText Transfer Protocol (HTTP), and Message Queuing Telemetry Transport (MQTT).
[0217] Figure 8 The illustration shows an example diagram of a gateway service request processing method according to an embodiment of the present disclosure.
[0218] like Figure 8 As shown, operations S801 to S814 schematically illustrate a method for processing gateway service requests.
[0219] When operating S801, Kubernetes administrators can create gateway clusters.
[0220] When operating S802, Kubernetes administrators can point the gateway cluster identifier to this system component.
[0221] When operating S803, Kubernetes operations and maintenance personnel can authorize the gateway cluster to business operations and maintenance personnel.
[0222] When operating S804, business operations and maintenance personnel can create gateways.
[0223] When operating S805, business operations and maintenance personnel can point the gateway identifier to the gateway cluster operated by Kubernetes.
[0224] When operating S806, the gateway cluster of Kubernetes can assign gateway address information to the gateway.
[0225] When operating S807, Kubernetes operations and maintenance personnel can send gateway address information to business operations and maintenance personnel.
[0226] When operating S808, business operations and maintenance personnel can receive gateway address information.
[0227] When operating S809, business operations and maintenance personnel can authorize the gateway to business users.
[0228] When operating S810, business users can create services.
[0229] When operating S811, business users can point the service identifier to the gateway.
[0230] When operating S812, the gateway for business operations and maintenance can assign service port information to services.
[0231] When operating S813, business operations and maintenance personnel can send service port information to business users.
[0232] When operating S814, business users can receive service port information.
[0233] The above are merely exemplary embodiments, but are not limited thereto. Other gateway service request processing methods known in the art may also be included, as long as they can improve the stability of request processing and ensure the high availability of resources and services.
[0234] Figure 9 A flowchart illustrating a management method for a cloud-native gateway system according to an embodiment of the present disclosure is shown.
[0235] like Figure 9 As shown, the management method 900 of the cloud-native gateway system includes operations S910 to S920.
[0236] When operating S910, the gateway service request processing method is used to process the target gateway service request and obtain the processing result. The target gateway service request includes the target gateway service configuration information, which is associated with the cloud-native gateway system.
[0237] When operating the S920, the cloud-native gateway system is managed based on the processing results.
[0238] Figure 10 A block diagram of a gateway service request processing apparatus according to an embodiment of the present disclosure is shown schematically.
[0239] like Figure 10 As shown, the service request processing device 1000 may include a first determining module 1010, a second determining module 1020, a third determining module 1030, and a sending module 1040.
[0240] The first determining module 1010 is used to, in response to receiving a service request to be processed, determine the target gateway cluster information corresponding to the target gateway cluster, the target gateway information corresponding to the target gateway, and the target service information corresponding to the target service, based on the preset mapping relationship and the service configuration information to be processed in the service request to be processed.
[0241] The second determining module 1020 is used to determine the running status of at least one container group corresponding to the target service based on the target gateway cluster information, target gateway information, and target service information.
[0242] The third determining module 1030 is used to determine the target container group in at least one container group based on the running status of each of the at least one container group corresponding to the target service.
[0243] The sending module 1040 is used to send the service request to be processed to the target container group so that the target container group can process the service request.
[0244] According to embodiments of this disclosure, the first determining module 1010 may include a first determining submodule, a second determining submodule, a third determining submodule, a fourth determining submodule, and a fifth determining submodule.
[0245] The first determination submodule is used to determine the target virtual Internet Protocol address information based on the configuration information of the service to be processed.
[0246] The second determining submodule is used to determine the target gateway cluster information corresponding to the target gateway cluster based on the first preset mapping relationship and the target virtual Internet Protocol address information.
[0247] The third determination submodule is used to determine the gateway address information corresponding to the target gateway and the service port information corresponding to the target service based on the target gateway cluster information.
[0248] The fourth determination submodule is used to determine the target gateway information based on the second preset mapping relationship and the gateway address information.
[0249] The fifth determination submodule is used to determine the target service information based on the third preset mapping relationship and service port information.
[0250] According to embodiments of this disclosure, the target gateway cluster includes at least one gateway, each of the at least one gateway has at least one service, each of the at least one gateway has gateway address information, and each of the at least one service has service port information.
[0251] According to embodiments of this disclosure, the third determining submodule may include a first determining unit, a second determining unit, and a third determining unit.
[0252] The first determining unit is used to determine the network segment range of the target gateway cluster based on the target gateway cluster information.
[0253] The second determining unit is used to determine the gateway address information corresponding to each gateway in at least one gateway, based on the network segment range of the target gateway cluster.
[0254] The third determining unit is used to determine the service port information of the service corresponding to the gateway for each of at least one service corresponding to the gateway, based on the gateway address information corresponding to the gateway.
[0255] According to embodiments of this disclosure, the first determining submodule may include a processing unit and a fourth determining unit.
[0256] The processing unit is used to respond to a received service request by parsing the service configuration information to obtain the domain name information corresponding to the service request.
[0257] The fourth determining unit is used to determine the target virtual network address information based on the domain name information.
[0258] According to embodiments of this disclosure, the second preset mapping relationship includes at least one second key-value relationship, which includes second key information and second value information. At least one second key-value relationship can be constructed in the following manner.
[0259] For each of at least one second key-value relationship, in response to receiving a gateway creation instruction, the gateway identifier, gateway configuration information, and gateway cluster identifier are obtained. Based on the gateway cluster identifier, the virtual network address information corresponding to the gateway cluster identifier is determined. Based on the target routing protocol and the virtual network address information, the gateway address information corresponding to the gateway identifier is determined. The gateway address information is determined as the second key information. The gateway configuration information is determined as the second value information. Based on the second key information and the second value information, the second key-value relationship is constructed.
[0260] According to embodiments of this disclosure, when the target routing protocol is a border gateway protocol, determining the gateway address information corresponding to the gateway identifier based on the target routing protocol and virtual network address information may include:
[0261] Based on the Virtual Internet Protocol (VIP) address information, a first resource pool is configured, wherein the first resource pool includes at least one first candidate address. Based on the first resource pool, target address information is determined from the at least one first candidate address. According to the Border Gateway Protocol (BGP), the target address information is published via any two front-end proxies to facilitate the determination of the target address information as the gateway address information.
[0262] According to embodiments of this disclosure, when the target routing protocol is an equal-cost multi-path routing protocol, determining the gateway address information corresponding to the gateway identifier based on the target routing protocol and the virtual network address information may include:
[0263] Based on the Virtual Internet Protocol (VIP) address information, a second resource pool is configured, wherein the second resource pool includes at least one second candidate address. Based on the second resource pool, target address information is determined from the at least one second candidate address. According to the Equal-Cost Multi-Path (ECM) routing protocol, equal-cost routing information corresponding to the target address information is configured. The equal-cost routing information is then determined as the gateway address information.
[0264] According to embodiments of this disclosure, the third preset mapping relationship includes at least one third key-value relationship, which includes third key information and third value information. The at least one third key-value relationship can be constructed in the following manner.
[0265] For each third key-value relationship in at least one third key-value relationship, in response to receiving a service creation instruction, obtain the service identifier, service configuration information, and gateway identifier. Based on the gateway identifier, determine the gateway address information corresponding to the gateway identifier. Based on the gateway address information, determine the service port information corresponding to the service identifier. Use the service port information as the third key information. Use the service configuration information as the third value information. Construct the third key-value relationship based on the third key information and the third value information.
[0266] According to embodiments of this disclosure, the target service information includes container group address information corresponding to at least one container group.
[0267] According to embodiments of this disclosure, the second determining module 1020 may include a first establishing submodule, a sixth determining submodule, and a seventh determining submodule.
[0268] The first establishment submodule is used to establish a probe network connection with the container group based on the container group address information for each container group address information in at least one container group address information.
[0269] The sixth determination submodule is used to determine that the container group is in normal operating condition when a heartbeat detection packet is received from the container group within a predetermined time period.
[0270] The seventh determination submodule is used to determine that the container group's operating status is abnormal if no heartbeat detection packet is received from the container group within a predetermined time period.
[0271] According to embodiments of this disclosure, the third determining module 1030 may include an eighth determining submodule.
[0272] The eighth determination submodule is used to determine the container group as the target container group in response to the container group's running status being in a normal operating state.
[0273] According to embodiments of this disclosure, the sending module 1040 may include a ninth determining submodule, a second establishing submodule, and a sending submodule.
[0274] The ninth determination submodule is used to determine the target container group address information corresponding to the target container group.
[0275] The second submodule is used to establish an actual network connection with the target container group based on the target container group address information.
[0276] The sending submodule is used to send pending service requests to the target container group based on the actual network connection.
[0277] Figure 11 A block diagram of a gateway service request processing apparatus according to an embodiment of the present disclosure is shown schematically.
[0278] like Figure 11 As shown, the management device 1100 of the cloud-native gateway system may include a processing module 1110 and a management module 1120.
[0279] The processing module 1110 is used to process the target gateway service request using the gateway service request processing device and obtain the processing result. The target gateway service request includes target gateway service configuration information, which is associated with the cloud-native gateway system.
[0280] The management module 1120 is used to manage the cloud-native gateway system based on the processing results.
[0281] Any one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure, or at least part of the functions of any one or more of them, can be implemented in one module. Any one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure can be implemented by dividing them into multiple modules. Any one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure can be at least partially implemented as hardware circuitry, such as Field Programmable Gate Arrays (FPGAs), Programmable Logic Arrays (PLAs), Systems-on-Chip, Systems-on-Substrate, Systems-on-Package, Application-Specific Integrated Circuits (ASICs), or implemented in hardware or firmware by any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, one or more of the modules, submodules, units, and subunits according to embodiments of the present disclosure can be at least partially implemented as computer program modules, which, when run, can perform corresponding functions.
[0282] For example, any plurality of the first determining module 1010, the second determining module 1020, the third determining module 1030, and the transmitting module 1040 can be combined into one module / unit / subunit, or any one of these modules / units / subunits can be split into multiple modules / units / subunits. Alternatively, at least part of the functionality of one or more of these modules / units / subunits can be combined with at least part of the functionality of other modules / units / subunits and implemented in one module / unit / subunit. According to embodiments of this disclosure, at least one of the first determining module 1010, the second determining module 1020, the third determining module 1030, and the transmitting module 1040 can be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or implemented in hardware or firmware by any other reasonable means of integrating or packaging the circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of the first determining module 1010, the second determining module 1020, the third determining module 1030, and the sending module 1040 may be implemented at least partially as a computer program module, which can perform corresponding functions when the computer program module is run.
[0283] It should be noted that the gateway service request processing device part in the embodiments of this disclosure corresponds to the gateway service request processing method part in the embodiments of this disclosure. For a detailed description of the gateway service request processing device part, please refer to the gateway service request processing method part, which will not be repeated here.
[0284] For example, any plurality of processing modules 1110 and management modules 1120 may be combined into one module / unit / subunit, or any one of these modules / units / subunits may be split into multiple modules / units / subunits. Alternatively, at least a portion of the functionality of one or more of these modules / units / subunits may be combined with at least a portion of the functionality of other modules / units / subunits and implemented in one module / unit / subunit. According to embodiments of this disclosure, at least one of processing module 1110 and management module 1120 may be at least partially implemented as hardware circuitry, such as a field-programmable gate array (FPGA), a programmable logic array (PLA), a system-on-a-chip, a system-on-a-substrate, a system-on-package, an application-specific integrated circuit (ASIC), or any other reasonable means of integrating or packaging circuitry, or implemented in software, hardware, or firmware, or in any suitable combination of any of these three implementation methods. Alternatively, at least one of processing module 1110 and management module 1120 may be at least partially implemented as a computer program module that, when run, can perform corresponding functions.
[0285] It should be noted that the management device part of the cloud-native gateway system in the embodiments of this disclosure corresponds to the management method part of the cloud-native gateway system in the embodiments of this disclosure. For a detailed description of the management device part of the cloud-native gateway system, please refer to the management method part of the cloud-native gateway system, which will not be repeated here.
[0286] Figure 12 The diagram illustrates an electronic device suitable for implementing a gateway service request processing method and a cloud-native gateway system management method according to embodiments of the present disclosure. Figure 12 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments disclosed herein.
[0287] like Figure 12 As shown, a computer electronic device 1200 according to an embodiment of the present disclosure includes a processor 1201, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 1202 or a program loaded from a storage portion 1209 into a random access memory (RAM) 1203. The processor 1201 may include, for example, a general-purpose microprocessor (e.g., a CPU), an instruction set processor and / or an associated chipset and / or a special-purpose microprocessor (e.g., an application-specific integrated circuit (ASIC)), etc. The processor 1201 may also include onboard memory for caching purposes. The processor 1201 may include a single processing unit or multiple processing units for performing different actions of the method flow according to an embodiment of the present disclosure.
[0288] RAM 1203 stores various programs and data required for the operation of electronic device 1200. Processor 1201, ROM 1202, and RAM 1203 are interconnected via bus 1204. Processor 1201 performs various operations of the method flow according to embodiments of the present disclosure by executing programs in ROM 1202 and / or RAM 1203. It should be noted that the programs may also be stored in one or more memories other than ROM 1202 and RAM 1203. Processor 1201 may also perform various operations of the method flow according to embodiments of the present disclosure by executing programs stored in said one or more memories.
[0289] According to embodiments of this disclosure, the electronic device 1200 may further include an input / output (I / O) interface 1205, which is also connected to the bus 1204. The electronic device 1200 may also include one or more of the following components connected to the I / O interface 1205: an input section 1206 including a keyboard, mouse, etc.; an output section 1207 including a cathode ray tube (CRT), liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 1208 including a hard disk, etc.; and a communication section 1209 including a network interface card such as a LAN card, modem, etc. The communication section 1209 performs communication processing via a network such as the Internet. A drive 1210 is also connected to the I / O interface 1205 as needed. A removable medium 1211, such as a disk, optical disk, magneto-optical disk, semiconductor memory, etc., is installed on the drive 1210 as needed so that computer programs read from it can be installed into the storage section 1208 as needed.
[0290] According to embodiments of this disclosure, the method flow according to embodiments of this disclosure can be implemented as a computer software program. For example, embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable storage medium, the computer program containing program code for performing the methods shown in the flowchart. In such embodiments, the computer program can be downloaded and installed from a network via communication section 1209, and / or installed from removable medium 1211. When the computer program is executed by processor 1201, it performs the functions defined in the system of embodiments of this disclosure. According to embodiments of this disclosure, the systems, devices, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0291] This disclosure also provides a computer-readable storage medium, which may be included in the device / apparatus / system described in the above embodiments; or it may exist independently and not assembled into the device / apparatus / system. The computer-readable storage medium carries one or more programs that, when executed, implement the method according to the embodiments of this disclosure.
[0292] According to embodiments of this disclosure, the computer-readable storage medium can be a non-volatile computer-readable storage medium. Examples include, but are not limited to: portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination thereof. In this disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program that can be used by or in conjunction with an instruction execution system, apparatus, or device.
[0293] For example, according to embodiments of this disclosure, a computer-readable storage medium may include the ROM 1202 and / or RAM 1203 described above and / or one or more memories other than ROM 1202 and RAM 1203.
[0294] Embodiments of this disclosure also include a computer program product comprising a computer program containing program code for performing the methods provided in the embodiments of this disclosure. When the computer program product is run on an electronic device, the program code enables the electronic device to implement the gateway service request processing method and the cloud-native gateway system management method provided in the embodiments of this disclosure.
[0295] When the computer program is executed by the processor 1201, it performs the functions defined in the system / apparatus of this disclosure embodiments. According to embodiments of this disclosure, the systems, apparatuses, modules, units, etc., described above can be implemented by computer program modules.
[0296] In one embodiment, the computer program may rely on a tangible storage medium such as an optical storage device or a magnetic storage device. In another embodiment, the computer program may also be transmitted and distributed in the form of signals over a network medium, and may be downloaded and installed via the communication section 1209, and / or installed from the removable medium 1211. The program code contained in the computer program can be transmitted using any suitable network medium, including but not limited to: wireless, wired, etc., or any suitable combination thereof.
[0297] According to embodiments of this disclosure, program code for executing the computer programs provided in embodiments of this disclosure can be written in any combination of one or more programming languages. Specifically, these computational programs can be implemented using high-level procedural and / or object-oriented programming languages, and / or assembly / machine languages. Programming languages include, but are not limited to, languages such as Java, C++, Python, "C", or similar programming languages. The program code can execute entirely on the user's computing device, partially on the user's device, partially on a remote computing device, or entirely on a remote computing device or server. In cases involving remote computing devices, the remote computing device can be connected to the user's computing device via any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computing device (e.g., via the Internet using an Internet service provider).
[0298] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in a block diagram or flowchart, and combinations of blocks in a block diagram or flowchart, may be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions. Those skilled in the art will understand that the features recited in the various embodiments and / or claims of this disclosure can be combined and / or combined in various ways, even if such combinations or combinations are not expressly described in this disclosure. In particular, the features described in the various embodiments and / or claims of this disclosure may be combined and / or combined in various ways without departing from the spirit and teachings of this disclosure. All such combinations and / or combinations fall within the scope of this disclosure.
[0299] The embodiments of this disclosure have been described above. However, these embodiments are for illustrative purposes only and are not intended to limit the scope of this disclosure. Although various embodiments have been described above, this does not mean that the measures in the various embodiments cannot be used advantageously in combination. The scope of this disclosure is defined by the appended claims and their equivalents. Various substitutions and modifications can be made by those skilled in the art without departing from the scope of this disclosure, and all such substitutions and modifications should fall within the scope of this disclosure.
Claims
1. A method for processing gateway service requests, comprising: In response to receiving a pending gateway service request, based on a preset mapping relationship and the pending gateway service configuration information in the pending gateway service request, the system determines the target gateway cluster information corresponding to the target gateway cluster, the target gateway information corresponding to the target gateway, and the target service information corresponding to the target service. The preset mapping relationship includes: a preset mapping relationship between virtual Internet Protocol address information and gateway cluster information, a preset mapping relationship between gateway address information and gateway information, and a preset mapping relationship between service port information and service information. The gateway address information is determined based on the target routing protocol and virtual network address information. The target routing protocol includes border gateway protocol or equal cost multipath routing protocol. Based on the target gateway cluster information, the target gateway information, and the target service information, determine the running status of at least one container group corresponding to the target service; Based on the operational status of each of the at least one container group corresponding to the target service, determine the target container group from the at least one container group; and The pending gateway service request is sent to the target container group so that the target container group can process the pending gateway service request.
2. The method according to claim 1, wherein, In response to receiving a pending gateway service request, the process of determining the target gateway cluster information corresponding to the target gateway cluster, the target gateway information corresponding to the target gateway, and the target service information corresponding to the target service, based on a preset mapping relationship and the pending gateway service configuration information in the pending gateway service request, includes: Based on the gateway service configuration information to be processed, determine the target virtual Internet Protocol address information; Based on the first preset mapping relationship and the target virtual Internet Protocol address information, determine the target gateway cluster information corresponding to the target gateway cluster; Based on the target gateway cluster information, determine the gateway address information corresponding to the target gateway and the service port information corresponding to the target service; The target gateway information is determined based on the second preset mapping relationship and the gateway address information; and The target service information is determined based on the third preset mapping relationship and the service port information.
3. The method according to claim 2, wherein, The target gateway cluster includes at least one gateway, each of the at least one gateway has at least one service, each of the at least one gateway has gateway address information, and each of the at least one service has service port information. The step of determining the gateway address information corresponding to the target gateway and the service port information corresponding to the target service based on the target gateway cluster information includes: Based on the target gateway cluster information, determine the network segment range of the target gateway cluster; For each of the at least one gateway, Based on the network segment range of the target gateway cluster, determine the gateway address information corresponding to the gateway; and For each of the at least one service corresponding to the gateway, Based on the gateway address information corresponding to the gateway, determine the service port information of the service corresponding to the gateway.
4. The method according to claim 2, wherein, The step of determining the target virtual Internet Protocol (VPN) address information based on the gateway service configuration information received includes: In response to receiving the pending gateway service request, the pending gateway service configuration information is parsed to obtain the domain name information corresponding to the pending gateway service request; and Based on the domain name information, the target virtual network address information is determined.
5. The method according to claim 2, wherein, The second preset mapping relationship includes at least one second key-value relationship, which includes second key information and second value information. The at least one second key-value relationship is constructed in the following manner: For each of at least one second key-value relation, Upon receiving a gateway creation command, obtain the gateway identifier, gateway configuration information, and gateway cluster identifier; Based on the gateway cluster identifier, determine the virtual network address information corresponding to the gateway cluster identifier; Based on the target routing protocol and the virtual network address information, determine the gateway address information corresponding to the gateway identifier; The gateway address information is determined as the second key information; The gateway configuration information is determined as the second value information; as well as The second key-value relationship is constructed based on the second key information and the second value information.
6. The method according to claim 5, wherein, When the target routing protocol is the border gateway protocol. The step of determining the gateway address information corresponding to the gateway identifier based on the target routing protocol and the virtual network address information includes: Based on the virtual Internet Protocol address information, a first resource pool is configured, wherein the first resource pool includes at least one first candidate address information; Based on the first resource pool, target address information is determined from the at least one first candidate address information; and According to the border gateway protocol, the target address information is published via any two front-end proxies so that the target address information can be identified as the gateway address information.
7. The method according to claim 5, wherein, When the target routing protocol is the equal-cost multipath routing protocol. The step of determining the gateway address information corresponding to the gateway identifier based on the target routing protocol and the virtual network address information includes: Based on the virtual Internet Protocol address information, a second resource pool is configured, wherein the second resource pool includes at least one second candidate address information; Based on the second resource pool, the target address information is determined from the at least one second candidate address information; Configure equal-cost routing information corresponding to the target address information according to the equal-cost multi-path routing protocol; and The equivalent routing information is determined as the gateway address information.
8. The method according to claim 2, wherein, The third preset mapping relationship includes at least one third key-value relationship, which includes third key information and third value information. The at least one third key-value relationship is constructed in the following manner: For each third key-value relation in at least one third key-value relation, Upon receiving a service creation instruction, obtain the service identifier, service configuration information, and gateway identifier; Based on the gateway identifier, determine the gateway address information corresponding to the gateway identifier; Based on the gateway address information, determine the service port information corresponding to the service identifier; The service port information is determined as the third key information; The service configuration information is determined as the third value information; as well as The third key-value relationship is constructed based on the third key information and the third value information.
9. The method according to any one of claims 1 to 8, wherein, The target service information includes container group address information corresponding to each of the at least one container group; The step of determining the running status of at least one container group corresponding to the target service based on the target gateway cluster information, the target gateway information, and the target service information includes: For each container group address in at least one container group address information, Based on the container group address information, establish a probe network connection with the container group; If a heartbeat detection packet is received from the container group within a predetermined time period, it is determined that the container group is in a normal operating state; and If no heartbeat detection packet is received from the container group within the predetermined time period, the operating status of the container group is determined to be an abnormal operating state.
10. The method according to claim 9, wherein, Determining the target container group from the at least one container group based on the respective running status of the at least one container group corresponding to the target service includes: In response to the container group being in a normal operating state, the container group is identified as the target container group.
11. The method according to any one of claims 1 to 8, wherein, Sending the pending gateway service request to the target container group includes: Determine the target container group address information corresponding to the target container group; Based on the target container group address information, establish an actual network connection with the target container group; and Based on the actual network connection, the gateway service request to be processed is sent to the target container group.
12. A management method for a cloud-native gateway system, comprising: Using the method of any one of claims 1 to 11, a target gateway service request is processed to obtain a processing result, wherein the target gateway service request includes target gateway service configuration information, and the target gateway service configuration information is associated with a cloud-native gateway system; and Based on the processing results, the cloud-native gateway system is managed.
13. A gateway service request processing apparatus, comprising: The first determining module is configured to, in response to receiving a pending gateway service request, determine, based on a preset mapping relationship and the pending gateway service configuration information in the pending gateway service request, target gateway cluster information corresponding to the target gateway cluster, target gateway information corresponding to the target gateway, and target service information corresponding to the target service. The preset mapping relationship includes: a preset mapping relationship between virtual Internet Protocol address information and gateway cluster information, a preset mapping relationship between gateway address information and gateway information, and a preset mapping relationship between service port information and service information. The gateway address information is determined based on the target routing protocol and virtual network address information. The target routing protocol includes a border gateway protocol or an equal-cost multipath routing protocol. The second determining module is used to determine the running status of at least one container group corresponding to the target service based on the target gateway cluster information, the target gateway information, and the target service information. The third determining module is configured to determine the target container group from the at least one container group based on the respective running states of the at least one container group corresponding to the target service; and The sending module is used to send the pending gateway service request to the target container group so that the target container group can process the pending gateway service request.
14. A management device for a cloud-native gateway system, comprising: A processing module is configured to process a target gateway service request using the apparatus of claim 13, and obtain a processing result, wherein the target gateway service request includes target gateway service configuration information, and the target gateway service configuration information is associated with a cloud-native gateway system; and The management module is used to manage the cloud-native gateway system based on the processing results.
15. An electronic device comprising: One or more processors; Memory, used to store one or more instructions. When the one or more instructions are executed by the one or more processors, the one or more processors cause the one or more processors to implement the method of any one of claims 1 to 11 or claim 12.
16. A computer-readable storage medium having stored thereon executable instructions that, when executed by a processor, cause the processor to perform the method of any one of claims 1 to 11 or claim 12.
17. A computer program product comprising computer-executable instructions, which, when executed, are used to perform the method of any one of claims 1 to 11 or claim 12.
Citation Information
Patent Citations
Load balancing method, system and device
CN113783922A
Method and device for accessing k8s container environment based on transport layer routing
CN115242882A