Traffic Control Method, System, Device and Medium Based on Cloud Native Gateway

Through the traffic control method based on cloud-native gateways, the domain name is parsed to obtain the IP address and forwarded to the gateway node, solving the complex problem of pod traffic management in the Kubernetes cluster, and realizing simplified gate configuration and refined traffic control.

CN118555267BActive Publication Date: 2025-07-22安徽省大数据中心
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410830410.2
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-06-25
Publication Date
2025-07-22
Estimated Expiration
2044-06-25

AI Technical Summary

Technical Problem

In Kubernetes clusters, existing network models cannot effectively implement fine-grained management of pod traffic, especially in Overlay and Underlay models, the gate gate configuration is complex and cannot recognize and control pod traffic.

Method used

Through the traffic control method based on cloud-native gateways, the domain name access request is resolved, the IP address is obtained, and the traffic is forwarded to the gateway node based on routing forwarding and address conversion rules, and the IP address of the gateway node is used for access, reducing the difficulty of gateway configuration and realizing refined traffic control.

Benefits of technology

It realizes simplified network gate configuration and refined management of pod traffic, reduces configuration complexity, and can adapt to changes in dynamic domain name resolution.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118555267B_ABST
    Figure CN118555267B_ABST
Patent Text Reader

Abstract

The present invention provides a traffic control method, system, device and medium based on a cloud-native gateway. The method includes: when receiving a domain name resolution request, resolving the to-be-accessed domain name carried in the domain name resolution request to obtain the IP address corresponding to the to-be-accessed domain name, where the domain name resolution request is sent by a pod when receiving a domain name access request; based on the IP address, matching a target route from the routing forwarding rules and matching a target conversion rule from the address conversion rules; based on the target route, forwarding the traffic corresponding to the domain name access request to a gateway node; based on the target conversion rule, converting the IP address of the traffic to the IP address of the gateway node, so that the pod accesses the to-be-accessed domain name based on the IP address of the gateway node. The method, system, device and medium provided by the present invention can reduce the configuration difficulty of the network gateway and achieve refined pod traffic control.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the field of network communication technologies, and in particular, to a traffic control method, system, device, and medium based on a cloud-native gateway. Background Art

[0002] In a cloud environment, the deployment and operation and maintenance of a Kubernetes (abbreviated as K8s) cluster have become one of the key infrastructures. With the popularization of cloud-native technologies, K8s has been widely used in various fields with its powerful pod (i.e., an application container in K8s) orchestration ability. However, in cloud scenarios with high security requirements, when a pod in the K8s cluster accesses external resources, traffic control and management need to be carried out through a network gateway, and specified traffic is allowed to pass through.

[0003] Currently, the network model of K8s is generally divided into two types: Overlay and Underlay. The Overlay model forwards the traffic of the pod to the host IP (Internet Protocol) address through NAT (Network Address Translation) technology, so as to communicate with the external network through the host. The Underlay model allows the pod to directly use its independent IP to communicate with the external network without passing through the host for transit.

[0004] However, both of the above two network models have certain defects. In the Underlay model, the network gateway needs to configure corresponding pass-through rules for the IP address of each pod, resulting in a large number of configuration rules and complex management; in the Overlay model, although the traffic of the pod is uniformly converted to the host IP address for external access through NAT, simplifying the configuration of the network gateway, the network gateway cannot specify the pod to be allowed to pass through, resulting in the inability to finely control the traffic of the pod. Summary of the Invention

[0005] The present invention provides a traffic control method, system, device, and medium based on a cloud-native gateway to solve the defects in the related technologies that traffic control is cumbersome and complex and cannot be finely managed.

[0006] The present invention provides a traffic control method based on a cloud-native gateway, including:

[0007] When receiving a domain name resolution request, resolving the to-be-accessed domain name carried in the domain name resolution request to obtain the IP address corresponding to the to-be-accessed domain name, where the domain name resolution request is sent by a pod when receiving a domain name access request;

[0008] Based on the IP address, match the target route from the routing forwarding rules and match the target conversion rule from the address conversion rules;

[0009] Based on the target route, forward the traffic corresponding to the domain name access request to the gateway node;

[0010] Based on the target conversion rule, convert the IP address of the traffic to the IP address of the gateway node, so that the pod accesses the domain name to be accessed based on the IP address of the gateway node.

[0011] According to a traffic control method based on a cloud-native gateway provided by the present invention, the configuration steps of the routing forwarding rules and the address conversion rules include:

[0012] When a gateway rule configuration request is monitored, resolve the destination domain name carried in the gateway rule configuration request to obtain the IP address corresponding to the destination domain name;

[0013] Update the IP address to the routing resource configuration information and the rule resource configuration information;

[0014] Based on the updated routing resource configuration information, configure the routing forwarding rules;

[0015] Based on the updated rule resource configuration information, obtain the pod set, and apply the pod set and the IP address to configure the address conversion rules.

[0016] According to a traffic control method based on a cloud-native gateway provided by the present invention, after obtaining the IP address corresponding to the destination domain name, it further includes:

[0017] Store the destination domain name and the resolution result of the destination domain name in the cache, where the resolution result includes the IP address and the resolution time of the destination domain name.

[0018] According to a traffic control method based on a cloud-native gateway provided by the present invention, when a gateway rule configuration request is monitored, resolving the destination domain name carried in the gateway rule configuration request to obtain the IP address corresponding to the destination domain name includes:

[0019] When a gateway rule configuration request is monitored, compare the destination domain name carried in the gateway rule configuration request with the destination domain name in the cache to obtain a domain name comparison result, and compare the current time with the resolution time of the destination domain name in the cache to determine the time difference;

[0020] In the case where the domain name comparison result is the same and the time difference is less than a preset threshold, based on the cache, obtain the IP address corresponding to the destination domain name;

[0021] In the case where the domain name comparison result is different or the time difference is greater than the preset threshold, resolve the destination domain name carried in the gateway configuration request to obtain the IP address corresponding to the destination domain name.

[0022] According to a traffic control method based on a cloud-native gateway provided by the present invention, the configuration steps of the routing forwarding rule and the address conversion rule further include:

[0023] Based on a preset frequency, obtain the current resolution results of all domain names, and compare the current resolution results with the resolution results in the cache;

[0024] In the case where the comparison result is inconsistent, based on the current resolution results, update the resolution results in the cache, and update the routing forwarding rule and the address conversion rule.

[0025] According to a traffic control method based on a cloud-native gateway provided by the present invention, the gateway rule uses the IP address of the pod as the source address and the domain name as the destination address.

[0026] The present invention also provides a traffic control system based on a cloud-native gateway, including:

[0027] A domain name server, configured to resolve the to-be-accessed domain name carried in the domain name resolution request to obtain the IP address corresponding to the to-be-accessed domain name when receiving the domain name resolution request, where the domain name resolution request is sent by a pod when receiving a domain name access request;

[0028] A domain name resolution module, configured to send the IP address to a routing management module and a rule management module when the IP address is queried;

[0029] A routing management module, configured to match a target route from the routing forwarding rules based on the IP address, and forward the traffic corresponding to the domain name access request to a gateway node based on the target route;

[0030] A rule management module, configured to match a target conversion rule from the address conversion rules based on the IP address, and convert the IP address of the traffic to the IP address of the gateway node based on the target conversion rule, and access the to-be-accessed domain name using the IP address of the gateway node.

[0031] A traffic control system based on a cloud-native gateway provided by the present invention, the domain name resolution module is further configured to send a domain name resolution request to the domain name server when a gateway rule configuration request is monitored;

[0032] The domain name server is configured to resolve the destination domain name carried in the gateway rule configuration request based on the domain name resolution request to obtain the IP address corresponding to the destination domain name;

[0033] The domain name resolution module is configured to update the received IP address into the routing resource configuration information and the rule resource configuration information;

[0034] The routing management module is configured to obtain the IP address corresponding to the destination domain name based on the updated routing resource configuration information, and configure the routing forwarding rule by applying the IP address;

[0035] The rule management module is configured to obtain the pod set and the IP address corresponding to the destination domain name based on the updated rule resource configuration information, and configure the address conversion rule by applying the pod set and the IP address.

[0036] The present invention also provides an electronic device, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the program, it implements the traffic control method based on the cloud-native gateway as described in any one of the above.

[0037] The present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it implements the traffic control method based on the cloud-native gateway as described in any one of the above.

[0038] The present invention also provides a computer program product, including a computer program. When the computer program is executed by a processor, it implements the traffic control method based on the cloud-native gateway as described in any one of the above.

[0039] The traffic control method, system, device, and medium based on the cloud-native gateway provided by the present invention resolve the to-be-accessed domain name to obtain the IP address corresponding to the to-be-accessed domain name, and automatically match the target route and the target conversion rule from the routing forwarding rule and the address conversion rule based on the IP address. Thus, according to the target route, the traffic can be forwarded to the gateway node, and according to the target conversion rule, the IP address of the traffic can be converted into the IP address of the gateway node, realizing the conversion of pod traffic into the IP address of the gateway node. The network gateway only needs to allow the IP address of the gateway node to pass through to achieve external access, reducing the configuration difficulty of the network gateway. In addition, by filtering the allowed pods at the gateway node, fine-grained pod traffic control is realized. Description of the Drawings

[0040] To more clearly illustrate the technical solutions in the present invention or related technologies, the following will briefly introduce the accompanying drawings required for use in the embodiments or related technology descriptions. Obviously, the accompanying drawings in the following descriptions are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.

[0041] Figure 1 is a schematic diagram of the cluster architecture provided by the present invention;

[0042] Figure 2 is a schematic flowchart of the traffic control method based on the cloud-native gateway provided by the present invention;

[0043] Figure 3 is a schematic flowchart of the configuration of the routing forwarding rules and address conversion rules provided by the present invention;

[0044] Figure 4 is a schematic diagram of the structure of the traffic control system based on the cloud-native gateway provided by the present invention;

[0045] Figure 5 is a schematic diagram of the structure of the electronic device provided by the present invention. Detailed implementation manners

[0046] To make the purpose, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the accompanying drawings in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the scope of protection of the present invention.

[0047] Kubernetes (K8s) is an open-source system used to manage containerized applications on multiple hosts in a cloud platform. The goal of K8s is to make the deployment of containerized applications simple and efficient, and it provides a mechanism for application deployment, planning, updating, and maintenance. In cloud scenarios with high security requirements, due to security and compliance requirements, when pods within the K8s cluster access external resources, traffic control needs to be performed through a network gateway to allow specified traffic to pass through.

[0048] At present, the network models of K8s are generally divided into two types: Overlay and Underlay. In the Overlay model, when a pod accesses externally, it is usually NATed to the IP of the host node and accesses through the host. In the Underlay model, the pod directly uses its own IP to access externally. However, in the Underlay model, each pod has an independent IP address, and the network gateway needs to configure corresponding allow rules for each pod's IP address. When the pod IP changes (such as pod restart, migration, etc.), the configuration of the network gateway also needs to be updated in a timely manner, resulting in a large number of configuration rules and frequent updates, increasing the management difficulty and complexity. Secondly, although the Overlay model accesses externally by NATing the pod to the IP address of the host, the network gateway only needs to configure the rules to allow the host to pass through. However, since NAT hides the true IP address of the pod, the network gateway cannot identify and finely control the traffic of the pod.

[0049] Furthermore, in actual business, users usually access services through domain names rather than directly using IP addresses. After resolving the domain name through DNS (Domain Name System), the IP address is obtained and then the service is requested. When external applications provide services, they may not provide only one IP address to carry the access of the service, that is, the resolution result of the domain name may have more than one IP, and multiple allow rules need to be configured, resulting in cumbersome and complex rule configuration. In addition, the resolution result of the domain name may change (such as the service provider changes the IP address), which requires the configuration of the network gateway to be updated accordingly. The traditional allow rules based on IP or CIDR (Classless Inter-Domain Routing) cannot meet the needs of this dynamic change, bringing challenges to traffic control.

[0050] In response to this, the present invention provides a traffic control method based on a cloud-native gateway. By NATing the pod traffic to the IP address of the gateway node, the network gateway only needs to allow the IP of the gateway node to pass through, reducing the configuration difficulty of the network gateway, and filtering the allowed pods at the gateway node to achieve fine-grained pod traffic control, thereby overcoming the above defects.

[0051] Figure 1 It is a schematic diagram of the cluster architecture provided by the present invention, as Figure 1As shown, the cluster includes CoreDNS, DNS resolution module, ApiServer, worker nodes, gateway nodes, NatRoute Manager, NatRule Manager, etc. Among them, CoreDNS is an open-source DNS server in the cluster, mainly used to resolve domain names into IP addresses. The DNS resolution module is deployed on the Nat gateway (a network address translation service) and is used to resolve the domain names in the gateway rules, store the IP addresses obtained by CoreDNS resolution in the cache, and configure them back into the routing forwarding rules and address translation rules. ApiServer is an interface service in the cluster, used to configure NAT rules, query NAT status, or perform other operations related to the Nat gateway. NatRoute Manager is deployed on the worker nodes of the cluster and is used to specify the IP to be accessed to set up the route and configure the route to forward traffic to the Nat gateway node. NatRule Manager is deployed on the Nat gateway node of the cluster, used to specify a set of pods, select the IP after network address translation (NAT), and then forward the pod traffic to the gateway. The gateway can pass through the IP after NAT. It should be understood that the worker nodes are part of the K8s cluster and are responsible for running application programs. The Nat gateway (i.e., the Nat gateway node) is a network service that supports IP address translation and is not a specific physical node.

[0052] In addition, Figure 1 Internet DNS in is a service of the Internet. When a domain name query that cannot be resolved by the local DNS server is encountered, the DNS forwarder will send the query to the DNS server (i.e., Internet DNS) connected to the forwarder in the network for resolution. If the resolution is successful, the result will be returned. This mechanism makes the DNS system more flexible and efficient and can handle domain name resolution requests across networks or domains.

[0053] It should be noted that the traffic control method provided by the present invention can be applied to a traffic control system based on a cloud-native gateway. The system may include a domain name server (i.e., CoreDNS), a domain name resolution module (i.e., DNS resolution module), a routing management module (i.e., NatRoute Manager), and a rule management module (i.e., NatRule Manager). Before executing the method provided by the embodiments of the present invention, two types of CRDs (Custom Resource Definition) of NatRoute and NatRule can be predefined in the K8s cluster to describe an access flow from a pod to an actual service, including a set of pods allowed to access, the domain name to be accessed, and NAT rules. Among them, the set of pods can be specified by one or more of ns, labelselector, and CIDR. When the IP address of a pod changes, the routing forwarding rule and the address conversion rule can be automatically updated; the destination end supports specifying using a domain name or CIDR.

[0054] Here, in the K8s cluster, CRD is a powerful K8s API (Application Programming Interface) extension mechanism that allows users to create and manage custom resources that do not belong to the K8s standard API. Through CRD, users can define their own resource types and operate on these custom resources in the same way as operating K8s built-in resources (such as Pod, Service, etc.). The above-mentioned set of pods allowed to access refers to the set of pods that have the permission to initiate external access; the above-mentioned domain name to be accessed refers to the target domain name specified for access, which can be the domain name of an external application; the above-mentioned NAT rule refers to the specific rule defined for network address translation.

[0055] It can be understood that ns, labelselector, and CIDR are different ways to specify the set of pods allowed to access. Among them, ns restricts by namespace, labelselector matches pods with specific labels through a label selector, and CIDR is used to specify an IP address range. Here, ns (Namespace) is a namespace in K8s. In NatRoute or NatRule, the pods in which namespaces can be accessed can be restricted by specifying the namespace. A label is a key-value pair attached to a resource in K8s and is used to identify the attributes of the resource. A labelselector is an expression used to query and filter a set of resources with specific labels.

[0056] Figure 2It is a schematic flowchart of the traffic control method based on the cloud-native gateway provided by the present invention. As Figure 2 shown, the method includes:

[0057] Step 210, when receiving a domain name resolution request, resolve the to-be-accessed domain name carried in the domain name resolution request to obtain the IP address corresponding to the to-be-accessed domain name. The domain name resolution request is sent by a pod when receiving a domain name access request;

[0058] Specifically, the domain name access request is sent by a user through an application on the pod, and it is a request to access a certain network resource (such as a web page, service, file, etc.). In this request, the user usually provides a domain name instead of the IP address of the target server. When the pod receives a domain name access request, it sends a domain name resolution request to the domain name server (i.e., CoreDNS). The request contains the domain name to be accessed, and it hopes that CoreDNS returns the IP address corresponding to this domain name.

[0059] The above to-be-accessed domain name is the domain name that the user specifies in the domain name access request and hopes to access. The pod includes this to-be-accessed domain name in the domain name resolution request and sends it to CoreDNS for resolution. After receiving the domain name resolution request, CoreDNS resolves the to-be-accessed domain name carried in the request to obtain the IP address corresponding to this domain name. It should be understood that this domain name resolution process can be completed through a DNS query, that is, the pod sends a DNS query request containing the to-be-accessed domain name to CoreDNS, and CoreDNS will search for and return the IP address corresponding to this domain name.

[0060] It can be understood that a caching mechanism can also be applied in this step. If CoreDNS has previously resolved the same domain name, then the IP address can be directly obtained through the cache of CoreDNS without performing domain name resolution again, thereby improving the resolution speed.

[0061] Step 220, based on the IP address, match the target route from the routing forwarding rules and match the target conversion rule from the address conversion rules;

[0062] It should be noted that the routing forwarding rule refers to a set of rules in a network for determining how data packets are forwarded from one node to another. The address translation rule refers to the Network Address Translation (NAT) rule, which is a technology for rewriting the source IP address and / or destination IP address when an IP data packet passes through a router or firewall. In the embodiments of the present invention, pods run on worker nodes. The routing forwarding rule is used to forward the traffic of the pods to the Nat gateway node, and the address translation rule is used to convert the IP address of the pods into the IP address of the Nat gateway node, and through the IP address of the Nat gateway, forward the pod traffic to the network isolation device, so that the traffic can access external resources through the network isolation device.

[0063] Specifically, after CoreDNS resolves to obtain the IP address, the DNS resolution module can detect the IP address through the DNS query service, and notify the IP address to the routing management module (i.e., NatRoute Manager) and the rule management module (i.e., NatRule Manager) through the ApiServer. After receiving the resolved IP address, the routing management module will match the target route from the routing forwarding rules according to the IP address. Here, the target route refers to the specified routing path matched from the routing forwarding rules according to the destination IP address of the data packet (i.e., traffic), and this path determines the transmission path of the traffic in the network. After receiving the resolved IP address, the rule management module will match the target conversion rule from the address translation rules according to the IP address. Here, the target conversion rule refers to the specified conversion rule matched from the address translation rules according to the destination IP address of the data packet (i.e., traffic), and this rule determines whether the traffic needs to perform address conversion during the transmission process and how to perform the address conversion.

[0064] Step 230: Based on the target route, forward the traffic corresponding to the domain name access request to the gateway node; Step 240: Based on the target conversion rule, convert the IP address of the traffic into the IP address of the gateway node, so that the pod can access the to-be-accessed domain name based on the IP address of the gateway node.

[0065] Specifically, according to the matched target route, the gateway node (i.e., the target gateway node) to which the traffic (i.e., the data packet generated based on the domain name access request) should be forwarded can be determined. This usually involves finding and establishing a path to the target gateway node in a physical or virtual network, and then sending the encapsulated traffic to the gateway node specified by this path.

[0066] Subsequently, according to the obtained target conversion rule by matching, the IP address of the traffic (i.e., the IP address of the pod) can be replaced with the IP address of the specified gateway node. Here, it can be achieved by parsing the IP header in the traffic and then modifying the destination IP address field therein. Finally, the converted traffic is sent to the target server to complete the access to the domain name requested by the user. It should be understood that the DNS resolver can adopt the same configuration as CoreDNS Forward to ensure that the result of the pod accessing the domain name is consistent with the result resolved by the DNS resolution controller, and the pod can match the issued rules.

[0067] The method provided by the embodiment of the present invention parses the domain name to be accessed to obtain the IP address corresponding to the domain name to be accessed, and automatically matches the target route and the target conversion rule from the routing forwarding rule and the address conversion rule based on the IP address. Thus, according to the target route, the traffic can be forwarded to the gateway node, and according to the target conversion rule, the IP address of the traffic can be converted into the IP address of the gateway node, realizing the conversion of the pod traffic into the IP address of the gateway node. The network gateway only needs to allow the IP address of the gateway node to achieve external access, reducing the configuration difficulty of the network gateway. In addition, by filtering the pods allowed to pass through at the gateway node, refined pod traffic control is realized.

[0068] Based on any of the above embodiments, Figure 3 is a schematic flow diagram of the configuration of the routing forwarding rule and the address conversion rule provided by the present invention, as Figure 3 shown, including:

[0069] Step 310, when a gateway rule configuration request is monitored, parse the destination domain name carried in the gateway rule configuration request to obtain the IP address corresponding to the destination domain name;

[0070] Specifically, the user can configure the Nat gateway rule based on the access domain name through the CMS (Cloud Management System), set the namespace, labelselector or CIDR in K8s as the source address, and set the domain name to be accessed as the destination address. Here, the source address refers to the network address of the device or host sending the data packet; the destination address refers to the network address of the device or host to which the data packet is sent. In the embodiment of the present invention, the source address is the IP address of the pod. When a certain pod initiates an external access, its IP address will be used as the source address.

[0071] It can be understood that the gateway rule configuration request refers to an event or operation used to trigger or request an update of the gateway configuration. Users can find the configuration interface of the Nat gateway in the CMS, create or edit Nat gateway rules to generate a gateway rule configuration request. After the DNS resolution module listens for a gateway rule configuration request with a domain name as the destination address through the ApiServer, it will initiate a DNS resolution request to CoreDNS. After receiving this resolution request, CoreDNS will resolve the destination domain name carried in the request to obtain the IP address corresponding to the destination domain name. Here, the destination domain name is the domain name of the website that the user or application hopes to access when initiating a network request. When the user creates or modifies a gateway rule in the CMS, the domain name will be used as the destination address, and this domain name will be carried as the destination domain name in the domain name resolution request.

[0072] Step 320: Update the IP address into the routing resource configuration information and the rule resource configuration information;

[0073] Specifically, after CoreDNS resolves to obtain the IP address corresponding to the destination domain name, it will return this IP address to the DNS resolution module. Subsequently, the DNS resolution module can update this IP address into the routing resource configuration information and the rule resource configuration information through the ApiServer. Here, the routing resource configuration information is the resource configuration information of NatRoute, and the rule resource configuration information is the resource configuration information of NatRule. Both are user-defined resource types. The routing resource configuration information describes an access flow from a pod to the actual service, which can include a set of pods allowed to access, the domain name to be accessed, etc.; the rule resource configuration information can include a set of pods allowed to access, NAT rule definitions, etc.

[0074] Step 330: Configure the routing forwarding rule based on the updated routing resource configuration information;

[0075] Specifically, after the routing management module listens for the update of the routing resource configuration information, it will read the updated routing resource configuration information, obtain the IP address corresponding to the destination domain name from it, and set the corresponding routing forwarding rules according to these IP addresses.

[0076] Step 340: Based on the updated rule resource configuration information, obtain a set of pods, and apply the set of pods and the IP address to configure the address conversion rule.

[0077] Specifically, after the rule management module monitors the update of the rule resource configuration information, it will read the updated rule resource configuration information and obtain the source pod set and the IP address corresponding to the destination domain name from it. Subsequently, the rule management module can set the ipset according to the source pod set, that is, add the IP addresses of each pod in the source pod set to the ipset. At the same time, on the gateway node, use the ipset and the parsed IP address to configure the iptables rule to achieve traffic forwarding. The iptables rule here is the above-mentioned address conversion rule.

[0078] The method provided by the embodiments of the present invention configures the Nat gateway rule with the domain name as the destination address in a cloud-native manner, without the user manually configuring a large number of IP gateway rules, and at the same time automatically configures the pod set and all forwarding and Nat rules relied on for domain name access.

[0079] Based on any of the above embodiments, after step 310, the method further includes:

[0080] Store the destination domain name and the resolution result of the destination domain name in the cache, where the resolution result includes the IP address and the resolution time of the destination domain name.

[0081] Specifically, in order to reduce the frequent queries to CoreDNS and improve the resolution efficiency, after the DNS resolution module detects the resolution result of the destination domain name, it can store the resolution result in the cache of the DNS resolution module. Here, the resolution result of the destination domain name refers to the result obtained by resolving the destination domain name (that is, the domain name that the user hopes to access) through the DNS server (that is, CoreDNS), which can include the IP address corresponding to the destination domain name and the resolution time of the destination domain name. Among them, the resolution time of the destination domain name can be the time when the DNS server resolves to obtain the corresponding IP address.

[0082] It can be understood that a cache is a storage mechanism used to store recently accessed data or results so that these data can be obtained more quickly when needed again in the future. In a computer system, a cache is usually used to store data with high access frequency and low update frequency to reduce the number of accesses to slow storage devices, thereby improving the overall performance of the system.

[0083] In the embodiments of the present invention, by storing the destination domain name and the resolution result in the cache, when the user accesses the domain name again, the IP address can be directly obtained from the cache without sending a query request to the DNS server again. This can greatly reduce the time delay of network access, improve the user experience, and at the same time reduce the burden on the DNS server.

[0084] Based on any of the above embodiments, step 310 specifically includes:

[0085] Step 311, when a gateway rule configuration request is monitored, compare the destination domain name carried in the gateway rule configuration request with the destination domain name in the cache to obtain a domain name comparison result, and compare the current time with the resolution time of the destination domain name in the cache to determine the time difference;

[0086] It should be noted that when there are multiple configured gateway rules with the same domain name, the resolution time in the cache can be compared. In this way, no new DNS requests are sent within a short period of time, and the resolution result in the cache is directly used, thereby reducing the number of DNS requests and alleviating the pressure on the DNS server.

[0087] Specifically, when the DNS resolution module monitors a gateway rule configuration request, it can parse the destination domain name from the gateway rule and compare the destination domain name with the destination domain name in the cache of the DNS resolution module to obtain a domain name comparison result. Here, the domain name comparison result refers to the result obtained by comparing the destination domain name carried in the monitored gateway rule configuration request with the destination domain name stored in the cache. This comparison result has two types: the same or different. If the destination domain name carried in the gateway rule configuration request exists in the cache, the comparison result is the same; otherwise, the comparison result is different.

[0088] When the domain name comparison result is the same, the current time can be further compared with the resolution time of the destination domain name in the cache to determine the time difference. Here, the current time refers to the system time or server time when this comparison and judgment operation is executed. The time difference refers to the difference between the current time and the resolution time of the destination domain name in the cache, and this difference is used to measure the length of time elapsed since the last resolution to determine whether the cached resolution result is still valid.

[0089] Step 312, when the domain name comparison result is the same and the time difference is less than a preset threshold, obtain the IP address corresponding to the destination domain name based on the cache;

[0090] Specifically, when the domain name comparison result is the same and the calculated time difference is less than the preset threshold, it indicates that the destination domain name and its corresponding IP address in the cache are still valid, and the resolution result has not expired. Therefore, the IP address in the cache can be directly used without sending another resolution request to the DNS server. It should be understood that the preset threshold is a preset time value used to determine whether the domain name resolution result in the cache is still valid. When the storage time of the resolution result in the cache exceeds this threshold, domain name resolution needs to be performed again.

[0091] It can be understood that if the domain name comparison result is the same and the time difference is less than the preset threshold, then the IP address corresponding to the destination domain name can be directly obtained from the cache. This is because the cache stores the mapping relationship between the domain name and the IP address obtained from the previous resolution. When the domain name needs to be accessed again, the corresponding IP address can be directly found from the cache.

[0092] Step 313, in the case where the domain name comparison result is different or the time difference is greater than the preset threshold, resolve the destination domain name carried in the gateway configuration request to obtain the IP address corresponding to the destination domain name.

[0093] Specifically, when the domain name comparison result is different or the time difference is greater than the preset threshold, it indicates that there is no valid resolution result for the destination domain name in the cache, or the resolution result in the cache has expired. In this case, it is necessary to re-resolve the destination domain name carried in the gateway configuration request to obtain the latest IP address. That is, the DNS resolution module will send a query request to CoreDNS and wait for CoreDNS to return the resolution result.

[0094] Based on any of the above embodiments, the configuration steps of the routing forwarding rule and the address conversion rule further include: obtaining the current resolution results of all domain names based on a preset frequency, and comparing the current resolution results with the resolution results in the cache;

[0095] In the case where the comparison result is inconsistent, update the resolution results in the cache based on the current resolution results, and update the routing forwarding rule and the address conversion rule.

[0096] It should be noted that considering that the service provider may change the IP address resolved by the domain name, in order to meet the scenario requirements where the domain name resolution result may change, a timer can be set for the DNS resolution module to request all domain names regularly, update the resolution results to maintain the accuracy of the domain name resolution, solve the problem that the domain name resolution result may change, and automatically complete the update of the routing forwarding rule and the address conversion rule without the user manually adjusting the Nat gateway rule.

[0097] Specifically, the preset frequency refers to a preset time interval used to control the period of the DNS resolution module for regular detection. The setting of the preset frequency aims to ensure the timeliness and accuracy of the DNS resolution result, and at the same time avoid resource waste caused by overly frequent detection. By setting a timer for the DNS resolution module, it can regularly detect the DNS server to obtain the current resolution results of all domain names, and compare them with the resolution results in the cache of the DNS resolution module. If there is a change, the resolution results in the cache, the routing forwarding rule, and the address conversion rule will be updated.

[0098] It is understandable that the current resolution results of all domain names refer to the IP addresses or other relevant information corresponding to each domain name obtained through DNS queries at the current time point. After obtaining the current resolution results, they can be compared with the resolution results in the cache. When the comparison result is inconsistent, it indicates that the resolution results in the cache are outdated or no longer accurate, and there are differences from the resolution results obtained through DNS queries currently. In this case, it is necessary to update the resolution results in the cache according to the current resolution results to ensure that the correct IP address can be used when accessing the domain name subsequently. At the same time, since changes in DNS resolution results will affect routing forwarding rules and address conversion rules, these rules also need to be updated. Specifically, the resource configuration information of NatRoute and NatRule can be updated according to the current resolution results, so as to update the corresponding routing forwarding rules and address conversion rules according to the updated resource configuration information.

[0099] Based on any of the above embodiments, the present invention provides a traffic control method based on a cloud-native gateway. This method can be applied to a traffic control system based on a cloud-native gateway, and the system can include a domain name server (i.e., CoreDNS), a domain name resolution module (i.e., DNS resolution module), a routing management module (i.e., NatRoute Manager), and a rule management module (i.e., NatRule Manager). The method specifically includes:

[0100] Step S1, configure the Nat gateway rule based on the access domain name through CMS, set the namespace, labelelector, or CIDR in K8s as the source address, and set the domain name as the destination address.

[0101] Step S2, when the DNS resolution module in the Nat gateway detects the creation or update of a Nat gateway rule with a domain name as the destination, it sends a DNS resolution request to CoreDNS. Here, when multiple rules have the same domain name, it is compared with the resolution timestamp in the Cache. No new DNS requests are sent within a short time, and the resolution results in the cache are directly used to reduce the number of DNS requests and relieve the pressure on the DNS service.

[0102] Step S3, the DNS resolution module stores the detected resolution results and the resolution timestamp in the Cache, and then updates the resource configuration information of NatRoute and NatRule to add the resolved IP results to the rules.

[0103] Step S4, the routing management module obtains the IP address resolved from the destination domain name according to the resource configuration information of NatRoute, and sets the routing forwarding rule according to the IP address.

[0104] Step S5: The rule management module obtains the source pod set and the IP address resolved from the destination domain name according to the resource configuration information of NatRule, sets up an ipset based on the source pod set, and configures the iptables nat rule (i.e., the address translation rule) on the gateway node using the ipset and the resolved IP address.

[0105] Step S6: When a pod in the cluster accesses a certain domain name, it will first be resolved by CoreDNS. Utilizing the cache of CoreDNS, the result can be the same as that of the Nat gateway DNS resolution, obtaining the resolved IP address, and matching the target route and target conversion rule according to this IP address.

[0106] Step S7: According to the target route, forward the pod traffic to the Nat gateway node. According to the target conversion rule, convert the IP address of the pod traffic to the IP address of the Nat gateway node, enabling the traffic to access external applications through the network gateway.

[0107] Step S8: Set a timer for the DNS resolution module to detect DNS regularly, compare the resolution result with the Cache. If there is a change, update the Cache and the resource configuration information of NatRoute and NatRule, thereby updating the corresponding route forwarding rule and address conversion rule.

[0108] The method provided by the embodiment of the present invention converts the pod traffic into the IP address of the Nat gateway. The network gateway only needs to allow the IP address of the Nat gateway to pass through, reducing the configuration difficulty of the network gateway, and filtering and allowing the passing of pods at the Nat gateway to achieve refined pod traffic control. In addition, by configuring the Nat gateway rule with the domain name as the destination address in a cloud-native manner, there is no need for users to manually configure a large number of IP gateway rules. At the same time, when the DNS resolution result of the service provider changes, there is no need for users to adjust the Nat gateway rule, and the rule update is automatically completed.

[0109] Based on any of the above embodiments, Figure 4 is a schematic structural diagram of a traffic control system based on a cloud-native gateway provided by the present invention, as Figure 4 shown, the system includes:

[0110] A domain name server 410, configured to resolve the to-be-accessed domain name carried in the domain name resolution request when receiving the domain name resolution request, to obtain the IP address corresponding to the to-be-accessed domain name, where the domain name resolution request is sent by a pod when receiving a domain name access request;

[0111] A domain name resolution module 420, configured to send the IP address to a route management module 430 and a rule management module 440 when the IP address is queried;

[0112] A routing management module 430, configured to match a target route from routing forwarding rules based on the IP address, and forward the traffic corresponding to the domain name access request to a gateway node based on the target route;

[0113] A rule management module 440, configured to match a target conversion rule from address conversion rules based on the IP address, convert the IP address of the traffic to the IP address of the gateway node based on the target conversion rule, and access the to-be-accessed domain name by using the IP address of the gateway node.

[0114] The system provided by the embodiment of the present invention resolves the to-be-accessed domain name to obtain the IP address corresponding to the to-be-accessed domain name, and automatically matches a target route and a target conversion rule from routing forwarding rules and address conversion rules based on the IP address. Thus, the traffic can be forwarded to a gateway node according to the target route, and the IP address of the traffic can be converted to the IP address of the gateway node according to the target conversion rule, realizing the conversion of pod traffic to the IP address of the gateway node. The gateway only needs to allow the IP address of the gateway node to pass through to realize external access, reducing the configuration difficulty of the gateway. In addition, by filtering the pods allowed to pass through at the gateway node, refined pod traffic control is realized.

[0115] Based on any of the above embodiments, the domain name resolution module 420 is further configured to send a domain name resolution request to the domain name server 410 when a gateway rule configuration request is monitored;

[0116] The domain name server 410 is configured to resolve the destination domain name carried in the gateway rule configuration request based on the domain name resolution request to obtain the IP address corresponding to the destination domain name;

[0117] The domain name resolution module 420 is configured to update the received IP address into the routing resource configuration information and the rule resource configuration information;

[0118] The routing management module 430 is configured to obtain the IP address corresponding to the destination domain name based on the updated routing resource configuration information, and configure the routing forwarding rule by using the IP address;

[0119] The rule management module 440 is configured to obtain a pod set and the IP address corresponding to the destination domain name based on the updated rule resource configuration information, and configure the address conversion rule by using the pod set and the IP address.

[0120] Based on any of the above embodiments, the domain name resolution module 420 is further configured to store the destination domain name and the resolution result of the destination domain name in a cache, where the resolution result includes the IP address and the resolution time of the destination domain name.

[0121] Based on any of the above embodiments, the domain name resolution module 420 is specifically configured to:

[0122] In the case of monitoring a gateway rule configuration request, compare the destination domain name carried in the gateway rule configuration request with the destination domain names in the cache to obtain a domain name comparison result, and compare the current time with the resolution time of the destination domain name in the cache to determine the time difference;

[0123] In the case where the domain name comparison result is the same and the time difference is less than a preset threshold, obtain the IP address corresponding to the destination domain name based on the cache;

[0124] In the case where the domain name comparison result is different or the time difference is greater than a preset threshold, send a domain name resolution request to the domain name server 410, so that the domain name server 410 resolves the destination domain name carried in the gateway configuration request to obtain the IP address corresponding to the destination domain name.

[0125] Based on any of the above embodiments, the domain name resolution module 420 is further configured to:

[0126] Obtain the current resolution results of all domain names based on a preset frequency, and compare the current resolution results with the resolution results in the cache;

[0127] In the case where the comparison result is inconsistent, update the resolution results in the cache based on the current resolution results, and update the routing forwarding rules and the address translation rules.

[0128] Based on any of the above embodiments, the gateway rule uses the IP address of the pod as the source address and the domain name as the destination address.

[0129] Figure 5 Illustrates a schematic physical structure diagram of an electronic device, such as Figure 5As shown in the figure, the electronic device may include: a processor 510, a communications interface 520, a memory 530, and a communication bus 540. Among them, the processor 510, the communications interface 520, and the memory 530 communicate with each other through the communication bus 540. The processor 510 may call the logical instructions in the memory 530 to execute a traffic control method based on a cloud-native gateway. The method includes: when receiving a domain name resolution request, resolving the to-be-accessed domain name carried in the domain name resolution request to obtain the IP address corresponding to the to-be-accessed domain name, where the domain name resolution request is sent by a pod when receiving a domain name access request; based on the IP address, matching a target route from the routing forwarding rules and matching a target conversion rule from the address conversion rules; based on the target route, forwarding the traffic corresponding to the domain name access request to a gateway node; based on the target conversion rule, converting the IP address of the traffic to the IP address of the gateway node, so that the pod accesses the to-be-accessed domain name based on the IP address of the gateway node.

[0130] In addition, when the logical instructions in the foregoing memory 530 can be implemented in the form of a software functional unit and sold or used as an independent product, they may be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the related technology, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present invention. The foregoing storage medium includes: various media such as a USB flash drive, a mobile hard disk, a read-only memory (ROM, Read-Only Memory), a random access memory (RAM, Random Access Memory), a magnetic disk, or an optical disc that can store program codes.

[0131] On the other hand, the present invention also provides a computer program product, which includes a computer program. The computer program can be stored on a non-transitory computer-readable storage medium. When the computer program is executed by a processor, the computer can execute the traffic control method based on a cloud-native gateway provided by the above-mentioned various methods. The method includes: when receiving a domain name resolution request, resolving the to-be-accessed domain name carried in the domain name resolution request to obtain the IP address corresponding to the to-be-accessed domain name, where the domain name resolution request is sent by a pod when receiving a domain name access request; based on the IP address, matching a target route from routing forwarding rules and matching a target conversion rule from address conversion rules; based on the target route, forwarding the traffic corresponding to the domain name access request to a gateway node; based on the target conversion rule, converting the IP address of the traffic to the IP address of the gateway node, so that the pod accesses the to-be-accessed domain name based on the IP address of the gateway node.

[0132] In another aspect, the present invention also provides a non-transitory computer-readable storage medium, on which a computer program is stored. When the computer program is executed by a processor, it is implemented to execute the traffic control method based on a cloud-native gateway provided by the above-mentioned various methods. The method includes: when receiving a domain name resolution request, resolving the to-be-accessed domain name carried in the domain name resolution request to obtain the IP address corresponding to the to-be-accessed domain name, where the domain name resolution request is sent by a pod when receiving a domain name access request; based on the IP address, matching a target route from routing forwarding rules and matching a target conversion rule from address conversion rules; based on the target route, forwarding the traffic corresponding to the domain name access request to a gateway node; based on the target conversion rule, converting the IP address of the traffic to the IP address of the gateway node, so that the pod accesses the to-be-accessed domain name based on the IP address of the gateway node.

[0133] The device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed to multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. Those of ordinary skill in the art can understand and implement it without creative efforts.

[0134] Through the description of the above embodiments, those skilled in the art can clearly understand that each embodiment can be implemented by means of software plus a necessary general hardware platform, and of course, it can also be implemented by hardware. Based on such an understanding, the above technical solution, in essence, or the part that contributes to the relevant technology can be embodied in the form of a software product. This computer software product can be stored in a computer-readable storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute the methods described in each embodiment or some parts of the embodiments.

[0135] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention.

Claims

1. A traffic control method based on a cloud-native gateway, characterized in that, including: When receiving a domain name resolution request, resolving the to-be-accessed domain name carried in the domain name resolution request to obtain the IP address corresponding to the to-be-accessed domain name, where the domain name resolution request is sent by a pod when receiving a domain name access request; Based on the IP address, matching a target route from the route forwarding rules and matching a target conversion rule from the address conversion rules; Based on the target route, forwarding the traffic corresponding to the domain name access request to a gateway node; Based on the target conversion rule, converting the IP address of the traffic to the IP address of the gateway node, so that the pod accesses the to-be-accessed domain name based on the IP address of the gateway node; The configuration steps of the route forwarding rules and the address conversion rules include: When monitoring a gateway rule configuration request, resolving the destination domain name carried in the gateway rule configuration request to obtain the IP address corresponding to the destination domain name; Updating the IP address to the route resource configuration information and the rule resource configuration information; Based on the updated route resource configuration information, configuring the route forwarding rules; Based on the updated rule resource configuration information, obtaining a pod set, and applying the pod set and the IP address to configure the address conversion rules.

2. The traffic control method based on the cloud-native gateway according to claim 1, wherein, After obtaining the IP address corresponding to the destination domain name, it further includes: Storing the destination domain name and the resolution result of the destination domain name in a cache, where the resolution result includes the IP address and the resolution time of the destination domain name.

3. The traffic control method based on the cloud-native gateway according to claim 2, wherein The step of, when monitoring a gateway rule configuration request, resolving the destination domain name carried in the gateway rule configuration request to obtain the IP address corresponding to the destination domain name includes: When monitoring a gateway rule configuration request, comparing the destination domain name carried in the gateway rule configuration request with the destination domain names in the cache to obtain a domain name comparison result, and comparing the current time with the resolution time of the destination domain name in the cache to determine the time difference; When the domain name comparison result is the same and the time difference is less than a preset threshold, obtaining the IP address corresponding to the destination domain name based on the cache; When the domain name comparison result is different or the time difference is greater than the preset threshold, resolving the destination domain name carried in the gateway configuration request to obtain the IP address corresponding to the destination domain name.

4. The traffic control method based on the cloud-native gateway according to claim 2, wherein The configuration steps of the route forwarding rules and the address conversion rules further include: Based on a preset frequency, obtaining the current resolution results of all domain names and comparing the current resolution results with the resolution results in the cache; When the comparison result is inconsistent, updating the resolution results in the cache based on the current resolution results, and updating the route forwarding rules and the address conversion rules.

5. The traffic control method based on the cloud-native gateway according to any one of claims 1 to 4, characterized in that, The gateway rules use the IP address of the pod as the source address and the domain name as the destination address.

6. A traffic control system based on a cloud-native gateway, characterized in that, including: A domain name server, which is configured to resolve a domain name to be accessed carried in the domain name resolution request when receiving the domain name resolution request, so as to obtain an IP address corresponding to the domain name to be accessed, where the domain name resolution request is sent by a pod when receiving a domain name access request; A domain name resolution module, which is configured to send the IP address to a routing management module and a rule management module when the IP address is queried; The routing management module is configured to match a target route from routing forwarding rules based on the IP address, and forward the traffic corresponding to the domain name access request to a gateway node based on the target route; The rule management module is configured to match a target conversion rule from address conversion rules based on the IP address, and convert the IP address of the traffic to the IP address of the gateway node based on the target conversion rule, so that the pod accesses the domain name to be accessed based on the IP address of the gateway node; The domain name resolution module is further configured to send a domain name resolution request to the domain name server when detecting a gateway rule configuration request; The domain name server is configured to resolve a destination domain name carried in the gateway rule configuration request based on the domain name resolution request, so as to obtain an IP address corresponding to the destination domain name; The domain name resolution module is configured to update the received IP address into routing resource configuration information and rule resource configuration information; The routing management module is configured to obtain the IP address corresponding to the destination domain name based on the updated routing resource configuration information, and configure the routing forwarding rule by applying the IP address; The rule management module is configured to obtain a pod set and the IP address corresponding to the destination domain name based on the updated rule resource configuration information, and configure the address conversion rule by applying the pod set and the IP address; 7. An electronic device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, wherein, When the processor executes the program, it implements the traffic control method based on a cloud native gateway according to any one of claims 1 to 5; 8. A non-transitory computer-readable storage medium storing a computer program thereon, characterized in that, When the computer program is executed by a processor, it implements the traffic control method based on a cloud native gateway according to any one of claims 1 to 5.

Citation Information

Patent Citations

  • Domain name resolution method, domain name resolution device and electronic equipment

    CN112600868A

  • Domain name resolution method and system of container cloud platform, medium and electronic equipment

    CN114785753A