A method and device for unloading load to DPU based on local storage volume
By establishing a shared file system in the cloud native container platform, the DPU can access and perceive the files on the host side in real time, solving the problem that the DPU cannot perceive and access the files on the host side in real time, realizing normal work after load unloading and data security guarantees.
Patent Information
- Application Number
- CN202311564539.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2023-11-22
- Publication Date
- 2025-05-06
- Estimated Expiration
- 2043-11-22
AI Technical Summary
In the cloud native container platform, the DPU cannot sense and access the specified files or file directories on the host side in real time, resulting in the load being unloaded and lacking a secure access policy, and the data lacks security guarantee.
By establishing a shared file system, the file system path on the host side is mounted on the local file system path of the DPU, so that the DPU can access the files on the host side in real time, and realize the host and DPU simultaneously when the file content is modified.
Real-time perception and automatic synchronization of the host side files by DPU are realized, enriching the types of loads that can be unloaded to the DPU, reducing the resource consumption of the host, improving business performance, and enhancing data security.
Smart Images

Figure CN117608474B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of computer technology, and in particular to a method and device for unloading a load to a DPU based on a local storage volume. Background Art
[0002] The role of the DPU network card in the cloud-native environment is to accelerate network traffic processing, improve container and microservice performance, enhance security, and provide higher performance and reliability for cloud-native applications. In the cloud-native container platform, in order to further improve the performance of business containers, some loads need to be offloaded to the DPU hardware, such as offloading the node agent of the container platform to the DPU. However, the node agent may need to communicate with each plug-in in a specific path of the hostpath volume, and the content under this path changes with the deployment of k8s. The DPU is outside the container cluster and cannot perform real-time synchronous perception, so it cannot achieve normal work after load offloading.
[0003] In other words, DPU is the new favorite in the cloud-native environment, and the industry has not yet formed a relatively mature and universal load unloading solution. If developers only do POC testing, they can directly copy the file of a specific hostpath to the DPU path through the scp command, or download the file through the wget command when the DPU network is accessible. However, such manual operations cannot change according to the file changes in the pod image deployed in the cluster, and there is no way to make the host and DPU perceive file modifications or automatically synchronize at the same time, which has no practical application value; at the same time, such manual operations do not set security access policies, and data lacks security protection. Summary of the invention
[0004] In view of this, the present invention provides a method and device for offloading loads to the DPU based on local storage volumes, which enables the DPU to perceive and access specified files or file directories on the host side in real time, thereby enriching the types of loads that can be offloaded to the DPU and reducing the resource consumption of the host.
[0005] In order to solve the above-mentioned technical problems, the present invention is achieved as follows:
[0006] A method for unloading a load to a DPU based on a local storage volume, comprising:
[0007] Obtain the file system path of the target file stored on the host machine through the local storage volume of the workload to be offloaded to the DPU;
[0008] Establishing a file system path of the target file and a shared file system between the DPU;
[0009] The workload offloaded to the DPU accesses the target file through the shared file system.
[0010] Preferably, establishing the shared file system includes: establishing the shared file system between the file synchronization client and the file synchronization server;
[0011] The file synchronization client running on the DPU sends an access request to the file synchronization server according to the operation requirements of the workload offloaded to the DPU;
[0012] The file synchronization server running on the host machine mounts the file system path of the target file to the local file system path of the DPU according to the access request for access by the workload offloaded to the DPU.
[0013] Preferably, when the workload is the workload kubelet, accessing the target file through the shared file system is: mounting the target file required by the workload kubelet and stored in the host host through the hostpath volume on the DPU through the shared file system.
[0014] Preferably, the container group types supported by the target file include: a device plug-in type container group, a container network plug-in type container group and a container storage plug-in type container group.
[0015] Preferably, the file synchronization client and the file synchronization server communicate with each other according to the Network File System protocol NFS.
[0016] Preferably, the method further comprises: when the workload offloaded to the DPU accesses the target file through the shared file system, when the number of times the file content of any specified path under the host machine is accessed is greater than a set value, the DPU locally caches the file content of the specified path.
[0017] Preferably, the method further comprises: after receiving the access request, the file synchronization server determines whether to restrict the access permission according to the type of the access request and the path permission to be accessed.
[0018] A device for unloading a load to a DPU based on a local storage volume, the device comprising: a target path acquisition module, a shared file system module and a target file access module;
[0019] The target path acquisition module obtains the file system path of the target file stored in the host host machine through the local storage volume of the workload to be offloaded to the DPU;
[0020] The shared file system module establishes a file system path of the target file and a shared file system between the DPU;
[0021] The target file access module enables the workload offloaded to the DPU to access the target file through the shared file system.
[0022] Preferably, establishing the shared file system includes: establishing the shared file system between the file synchronization client and the file synchronization server;
[0023] The file synchronization client running on the DPU sends an access request to the file synchronization server according to the operation requirements of the workload offloaded to the DPU;
[0024] The file synchronization server running on the host machine mounts the file system path of the target file to the local file system path of the DPU according to the access request for access by the workload offloaded to the DPU.
[0025] Preferably, when the workload is the workload kubelet, accessing the target file through the shared file system is: mounting the target file required by the workload kubelet and stored in the host host through the hostpath volume on the DPU through the shared file system.
[0026] Beneficial effects:
[0027] 1. The present invention mounts the file system path on the host side to the local file system path of the DPU by establishing a shared file system, so that the DPU can access the files on the host side through the shared file system, just like accessing local files; and when the file content is modified, the host and DPU can perceive it at the same time, solving the problem of how to unload the load to the DPU hardware in the cloud native container platform. The DPU can also perceive in real time and automatically synchronize the files stored or modified by the containers deployed in the container cluster through the local storage volume.
[0028] 2. The present invention establishes a shared file system by adopting inter-process communication technology, and uses the file synchronization client and file synchronization server of the shared file system to realize the real-time perception of the files required by the cloud native container platform load by the DPU device originally located outside the k8s cluster, thereby reducing the difficulty of setting up the shared file system and improving the flexibility of selecting the physical interface between the DPU and the host.
[0029] 3. The present invention is particularly suitable for application scenarios in which kubelet is unloaded to DPU through flexible use of hostpath type local storage volumes. By handing over the kubelet load to DPU for processing, the resource consumption of the host is reduced, thereby improving the performance of the business and enabling the host to have sufficient resources to run the specific business implementation required.
[0030] 4. After receiving an access request at the file synchronization server, the present invention determines whether to start access permission restriction according to the type of access request and the path permission to be accessed by the current access request. That is, the present invention protects the security of host data by setting some reasonable security options, such as access control list (ACL), identity authentication and encryption.
[0031] 5. The present invention uses the DPU file synchronization client to locally cache the contents of part of the host file. When the same file is accessed multiple times, the DPU file synchronization client can obtain data from the cache, reducing requests to the host server and further improving the performance of the host server. BRIEF DESCRIPTION OF THE DRAWINGS
[0032] Figure 1 It is a schematic diagram of the overall process of the method for unloading load to the DPU based on an embodiment of the present invention;
[0033] Figure 2 This is a schematic diagram of implementing the method of unloading the kubelet load to the DPU based on an embodiment of the present invention;
[0034] Figure 3 A schematic diagram of a specific process of a method for unloading a load to a DPU based on an embodiment of the present invention;
[0035] Figure 4 It is a schematic diagram of the structure of a device for unloading load to a DPU based on an embodiment of the present invention. DETAILED DESCRIPTION
[0036] The present invention is described in detail below with reference to the accompanying drawings and embodiments.
[0037] The present invention provides a method for unloading loads to a DPU based on a local storage volume, and the core idea is as follows: the present invention takes into account that the files or file directories of the load unloaded to the DPU stored in the host machine through the local storage volume cannot be perceived by the DPU outside the cloud native container platform, resulting in the load not being able to work normally on the DPU and the DPU being unable to unload the load. A shared file system is established between the file system path of the target file required by the load and the DPU, and data communication between the DPU and the host machine is realized through the shared file system, so that the files or file directories required by the load stored on the host machine through the local storage volume can be accessed by the DPU in real time, thereby providing support for the normal operation of the load unloaded to the DPU.
[0038] It can be seen that the present invention mounts the file system path on the host side to the local file system path of the DPU by establishing a shared file system, so that the DPU can access the files on the host side through the shared file system, just like accessing local files; and when the file content is modified, the host and DPU can perceive it at the same time, solving the problem of how to unload the load to the DPU hardware in the cloud native container platform, so that the DPU can also perceive in real time and automatically synchronize the files stored or modified by the containers deployed in the container cluster through the local storage volume. The present invention reduces the resource consumption of the host by handing over the workload unrelated to the business to the DPU, thereby improving the performance of the business and allowing the host to have sufficient resources to run the required business load.
[0039] The present invention is further described in detail below with reference to an embodiment.
[0040] The present invention provides a method for unloading load to DPU based on local storage volume, such as Figure 1 As shown, including:
[0041] S1: Obtain the file system path of the target file stored in the host machine through the local storage volume according to the workload offloaded to the DPU.
[0042] Among them, the local storage volume can be a storage volume type such as emptyDir, hostPath or local volume, and the workload unloaded to the DPU can be a node agent kubelet load, or it can be other workloads that need to be unloaded to the DPU and use local storage volumes for file storage. In some embodiments, when the workload is a workload kubelet, the file system path of the target file stored in the host host machine through the local storage volume of the workload to be unloaded to the DPU is obtained as follows: the target file required by the workload kubelet to be stored in the host host machine through the hostpath volume is mounted on the DPU through the shared file system.
[0043] According to the work requirements of the load kubelet, the types of container groups supported by the target file include: device plug-in type container groups, container network plug-in (cni) type container groups, and container storage plug-in (csi) type container groups. Depending on the type of container group, the host-side files required by kubelet will also be different. Figure 2As shown in the figure, the default path corresponding to the device plug-in class container group is / var / lib / kubelet / device-pligins, the default path corresponding to the container network plug-in class container group is / opt / cni / bin or / etc / cni / net.d, and the default path corresponding to the container storage plug-in class container group is / usr / libexec / kubernetes / kubelet-plugins / volume / exec.
[0044] S2: Establish a shared file system between the file system path of the target file and the DPU. Specifically:
[0045] The shared file system includes: a file synchronization client and a file synchronization server. The file synchronization client runs on the DPU and sends an access request to the file synchronization server according to the operating requirements of the workload unloaded to the DPU. The file synchronization server runs on the host and mounts the file system path of the target file to the local file system path of the DPU for access by the workload unloaded to the DPU according to the access request. Among them, the access request includes: a request to read a file, a request to write a file, and a request to list directory contents.
[0046] Through the shared file system, the target path on the host side can be mounted on the DPU side as needed, so that the loads unloaded to the DPU such as kubelet can perceive the dp interface, cni plug-in or other required file volume addresses under the required corresponding path.
[0047] S3: The workload offloaded to the DPU accesses the target file through the shared file system. Specifically:
[0048] In some embodiments, when the workload is kubelet, if the kubelet of the DPU needs to access the host file or directory on the specified path, the DPU will send a corresponding access request to the host server, such as reading files, writing files, listing directory contents, etc. After receiving the request, the host server performs the corresponding operation and transmits the data on the corresponding path back to the file synchronization client of the DPU to achieve the mounting of the target path and real-time access to the target file, where the data transmission may involve reading and writing data, as well as the data format defined in the protocol. For the file synchronization client of the DPU, there is no difference between accessing files shared by the host and accessing local files. The workload kubelet running on the DPU can perceive the access file in real time through the specified path in the client virtual file system without knowing where the file is actually stored. This transparency enables the kubelet to be unloaded to the DPU without any perception without affecting the implementation of any function.
[0049] It can be seen that the present invention realizes remote file synchronization perception on the host side and the DPU side through the network file protocol, allowing the DPU to access files stored on the host side in local storage volume types such as hostpath through the file synchronization client, just like accessing local files, solving the file perception problem encountered when unloading the load to the DPU hardware in the cloud native container platform. When the node proxy load of the container platform is unloaded to the DPU, the node proxy load on the DPU can obtain the same file directory as other host nodes in the cluster; and when the deployment of k8s changes, the file content under the DPU can also be synchronized with the deployment of the container cluster.
[0050] In order to improve the reliability of the shared file system, in some embodiments, the file synchronization client and the file synchronization server communicate according to the Network File System (NFS) protocol. There are different protocol versions of the NFS protocol, such as NFSv3, NFSv4, etc. The NFS protocol defines the specific implementations such as the communication method, data transmission format and error handling between the file synchronization client and the file synchronization server. In some embodiments, the file synchronization client and the file synchronization server are connected through a PCIE interface, and inter-process communication technology is used for data transmission. The file synchronization client and the file synchronization server communicate access requests and mount data through rpc Stub.
[0051] When mounting a remote NFS shared directory, the file synchronization client will mount the remote file system onto the client's local file system to form a virtual directory structure. This virtual directory structure is part of the client file system, and it contains the files and directories shared on the remote file synchronization server. That is, accessing the mount path on the file synchronization client will access the virtual file system, and then the file synchronization client kernel will be called. The file synchronization client kernel uses the NFS protocol to communicate with the file synchronization server, which includes encapsulating the NFS request into an NFS protocol message and transmitting it to the file synchronization server through the network. The file synchronization server receives the request sent by the file synchronization client, parses it and performs the corresponding file system operation (virtual file system-file system), which may involve operations such as reading, writing, creating, and deleting files; when the file synchronization server completes the requested file operation, it will encapsulate the result of the operation into an NFS response message and send it back to the file synchronization client. The virtual file system obtained by the method of the present invention provides a unified interface for file systems on different hardware sides, so that applications can access files and data without knowing the underlying file system.
[0052] In order to optimize communication efficiency and improve processing performance, in some embodiments, the DPU's file synchronization client can locally cache the contents of part of the host file. Specifically, after the S3 implementation workload accesses the target file through the shared file system, such as Figure 3 As shown, further comprising:
[0053] S301: Determine whether the number of times the file content on any specified path in the client virtual file system has been accessed is greater than a set value; if yes, continue to execute S302, otherwise wait for subsequent access requests to repeat S3.
[0054] S302: The file synchronization client of the DPU stores the file content of the specified path in a local cache.
[0055] It can be seen that when the same file is accessed multiple times, the DPU file synchronization client can obtain data from the cache and forward it to the workload, thereby reducing requests to the host server. At the same time, data synchronization management is also required to avoid data consistency issues that may be caused by the cache.
[0056] In order to protect the security of host data, in some embodiments, after receiving the access request at the file synchronization server, the present invention determines whether to restrict the access rights according to the type of access request and the path permissions to be accessed. Specifically, before the S3 workload accesses the target file through the shared file system, it further includes:
[0057] S300: After receiving the access request, determine the access permission.
[0058] By setting reasonable security options for the file synchronization server, such as access control lists (ACLs), authentication, and encryption, the security of host data can be guaranteed. Restricting access rights includes: when the type of access request is to read only files and the path permission to be accessed is to write files, or when the type of access request is to write only files and the path permission to be accessed is to read files, the file synchronization server initiates access rights restriction to terminate access, thereby limiting access, verifying user identity, and protecting the privacy of data transmission.
[0059] In order to avoid functional failure after the device is restarted, in some embodiments, when the device is restarted, the file synchronization client on the DPU side will trigger automatic mounting. Automatic mounting attempts to reestablish communication with the file synchronization server to prevent functional failure caused by failure of mounting after restart. Automatic mounting is set with an access security policy to ensure that only the DPU corresponding to the host has the authority to access files under a specific directory path, ensuring data security.
[0060] The present invention also proposes a device for unloading load to DPU based on local storage volume, such as Figure 4As shown, the device includes: a target path acquisition module, a shared file system module and a target file access module.
[0061] The target path acquisition module obtains the file system path of the target file stored in the host machine through the local storage volume of the workload to be offloaded to the DPU.
[0062] In some embodiments, when the workload is a workload kubelet, accessing the target file through the shared file system is: mounting the target file required by the workload kubelet and stored in the host host through the hostpath volume on the DPU through the shared file system. The container group types supported by the target file include: device plug-in class container group, container network plug-in class container group, and container storage plug-in class container group.
[0063] The shared file system module establishes the file system path of the target file and the shared file system between the DPU.
[0064] In some embodiments, a shared file system is established as follows: a shared file system is established between a file synchronization client and a file synchronization server. The file synchronization client running on the DPU sends an access request to the file synchronization server according to the operating requirements of the workload unloaded to the DPU; the file synchronization server running on the host machine mounts the file system path of the target file to the local file system path of the DPU for access by the workload unloaded to the DPU according to the access request. The access request includes: a file read request, a file write request, and a directory content list request.
[0065] In order to improve the reliability of the shared file system, in some embodiments, the file synchronization client and the file synchronization server communicate according to the NFS protocol. In some embodiments, the file synchronization client and the file synchronization server are connected through a PCIE interface, and the inter-process communication technology is used for data transmission. The file synchronization client and the file synchronization server communicate access requests and mount data through rpc stub.
[0066] The target file access module enables the workload offloaded to the DPU to access the target file through the shared file system.
[0067] In order to optimize communication efficiency and improve processing performance, in some embodiments, when the workload offloaded to the DPU accesses the target file through a shared file system, when the number of times the file content of any specified path under the host host is accessed is greater than a set value, the DPU locally caches the file content of the specified path.
[0068] In order to protect the security of host data, in some embodiments, after receiving an access request, the file synchronization server determines whether to restrict access rights according to the type of access request and the path permissions to be accessed.
[0069] In order to avoid functional failure after the device is restarted, in some embodiments, when the device is restarted, the file synchronization client on the DPU side will trigger automatic mounting.
[0070] In summary, the above are only preferred embodiments of the present invention and are not intended to limit the protection scope of the present invention. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for offloading load to a DPU based on a local storage volume, characterized in that: include: Obtain the file system path of the target file stored on the host machine through the local storage volume of the workload to be offloaded to the DPU; Establishing a file system path of the target file and a shared file system between the DPU; The workload offloaded to the DPU accesses the target file through the shared file system; Establishing the shared file system includes: establishing the shared file system between the file synchronization client and the file synchronization server; The file synchronization client running on the DPU sends an access request to the file synchronization server according to the operation requirements of the workload offloaded to the DPU; The file synchronization server running on the host machine mounts the file system path of the target file to the local file system path of the DPU according to the access request for access by the workload offloaded to the DPU.
2. The method for unloading load to DPU based on local storage volume according to claim 1, characterized in that: When the workload is the workload kubelet, accessing the target file through the shared file system is: mounting the target file required by the workload kubelet stored in the host host through the hostpath volume on the DPU through the shared file system.
3. The method for unloading load to DPU based on local storage volume according to claim 2, characterized in that: The container group types supported by the target file include: a device plug-in class container group, a container network plug-in class container group, and a container storage plug-in class container group.
4. The method for offloading load to a DPU based on a local storage volume according to claim 1, characterized in that: The file synchronization client and the file synchronization server communicate with each other according to the network file system protocol NFS.
5. The method for unloading load to DPU based on local storage volume according to claim 1, characterized in that: The method further includes: when the workload unloaded to the DPU accesses the target file through the shared file system, when the number of times the file content of any specified path under the host host is accessed is greater than a set value, the DPU locally caches the file content of the specified path.
6. The method for unloading load to DPU based on local storage volume according to claim 1, characterized in that: The method further includes: after receiving the access request, the file synchronization server determines whether to restrict the access rights according to the type of the access request and the path permission to be accessed.
7. A device for unloading load to a DPU based on a local storage volume, characterized in that: The device comprises: a target path acquisition module, a shared file system module and a target file access module; The target path acquisition module obtains the file system path of the target file stored in the host host machine through the local storage volume of the workload to be offloaded to the DPU; The shared file system module establishes a file system path of the target file and a shared file system between the DPU; The target file access module enables the workload offloaded to the DPU to access the target file through the shared file system; Establishing the shared file system includes: establishing the shared file system between the file synchronization client and the file synchronization server; The file synchronization client running on the DPU sends an access request to the file synchronization server according to the operation requirements of the workload offloaded to the DPU; The file synchronization server running on the host machine mounts the file system path of the target file to the local file system path of the DPU according to the access request for access by the workload offloaded to the DPU.
8. The device for unloading load to DPU based on local storage volume according to claim 7, characterized in that: When the workload is the workload kubelet, accessing the target file through the shared file system is: mounting the target file required by the workload kubelet stored in the host host through the hostpath volume on the DPU through the shared file system.
Citation Information
Patent Citations
System configuration method, intelligent network card, electronic equipment and storage medium
CN116170312A
Techniques for extending system memory via use of available device memory
CN116342365A