Container network access control method, device, medium, equipment and program product
By using filters and network endpoint-level access control tables in the container network, the access actions of container network communication are determined and executed, and the problems of container network security isolation delay and quota restrictions are solved, and flexible and efficient network access control is achieved.
Patent Information
- Application Number
- CN202411018511.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-07-26
- Publication Date
- 2025-05-16
- Estimated Expiration
- 2044-07-26
AI Technical Summary
In the cloud network scenario, the security isolation delay of the container network is large, and the VPC security group has quota restrictions, so it cannot be adapted to a large-scale deployment environment.
The network endpoint identity information related to the container network communication link of the Pod is determined through the filter, and the target access action is found based on the preconfigured network endpoint-level access control table, and the action is performed.
It realizes flexible container network access control without relying on the network access control capabilities provided by the underlying infrastructure, and has stronger adaptability and can flexibly control network access to different network endpoints according to requirements.
Smart Images

Figure CN118713919B_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of computer technology, and in particular, to a container network access control method, apparatus, medium, device, and program product. Background Art
[0002] In cloud network scenarios, we usually rely on VPC (Virtual Private Cloud) security groups to achieve secure isolation of container networks. When containers are created and deleted frequently, we need to frequently operate security group rules, which leads to a long delay in the effectiveness of isolation. In addition, since VPC security groups have quota restrictions, they cannot be adapted to large-scale deployment environments. Therefore, we need to study a new method to achieve secure isolation of container networks. Summary of the invention
[0003] This summary is provided to introduce concepts in a brief form that will be described in detail in the detailed description below. This summary is not intended to identify key features or essential features of the claimed technical solution, nor is it intended to limit the scope of the claimed technical solution.
[0004] In a first aspect, the present disclosure provides a container network access control method, comprising:
[0005] Determine, by a filter, identity information of a first network endpoint and a second network endpoint related to a container network communication link across a container group Pod, wherein the Pod is configured with multiple network endpoints to support container communication across the Pod;
[0006] Based on the network endpoint-level access control table pre-configured for the Pod, searching for the target access action corresponding to the identity information, wherein the network endpoint-level access control table is used to maintain the access actions for network entry and exit between the network endpoints across the Pod, and the access actions include allowing access or denying access;
[0007] Execute the target access action.
[0008] In a second aspect, the present disclosure provides a container network access control device, including:
[0009] An acquisition module is configured to determine, through a filter, identity information of a first network endpoint and a second network endpoint related to a container network communication link across a container group Pod, wherein the Pod is configured with multiple network endpoints to support container communication across the Pod;
[0010] A search module is configured to search for a target access action corresponding to the identity information based on a network endpoint-level access control table preconfigured for the Pod, wherein the network endpoint-level access control table is used to maintain access actions for network access between network endpoints across the Pod, wherein the access action includes allowing access or denying access;
[0011] An execution module is configured to execute the target access action.
[0012] In a third aspect, the present disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processing device, implements the steps of the method described in the first aspect.
[0013] In a fourth aspect, the present disclosure provides an electronic device, including:
[0014] a storage device having a computer program stored thereon;
[0015] A processing device is used to execute the computer program in the storage device to implement the steps of the method described in the first aspect.
[0016] In a fifth aspect, the present disclosure provides a computer program product, including a computer program, which implements the steps of the method described in the first aspect when executed by a processor.
[0017] Based on the above technical solution, the identity information of the first network endpoint and the second network endpoint related to the container network communication link of the Pod is determined through the filter, and the target access action corresponding to the identity information is found based on the network endpoint-level access control table pre-configured for the Pod, and the target access action is executed. It can achieve network access control for the container without relying on the network access control capability provided by the underlying infrastructure, and has stronger adaptability. In addition, it is possible to perform network access control in the dimension of the container's network endpoint. In the scenario where the Pod has multiple network endpoints, it is possible to flexibly perform network access control on different network endpoints according to needs.
[0018] Other features and advantages of the present disclosure will be described in detail in the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS
[0019] The above and other features, advantages and aspects of the embodiments of the present disclosure will become more apparent with reference to the following detailed description in conjunction with the accompanying drawings. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic and the originals and elements are not necessarily drawn to scale. In the drawings:
[0020] Figure 1 The present invention is a flowchart of a container network access control method according to some embodiments.
[0021] Figure 2 It is a schematic diagram of the structure of a data plane according to some embodiments.
[0022] Figure 3 is a schematic diagram of a mapping table according to some embodiments.
[0023] Figure 4 is a schematic diagram illustrating RDMA communication according to some embodiments.
[0024] Figure 5 is a flowchart of determining a target access action according to some embodiments.
[0025] Figure 6 is a flowchart of determining a target access action according to some further embodiments.
[0026] Figure 7 It is a structural diagram of a container network access control device according to some embodiments.
[0027] Figure 8 is a schematic diagram of the structure of an electronic device according to some embodiments. DETAILED DESCRIPTION
[0028] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the accompanying drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as being limited to the embodiments described herein, which are instead provided for a more thorough and complete understanding of the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not intended to limit the scope of protection of the present disclosure.
[0029] It should be understood that the various steps described in the method embodiments of the present disclosure may be performed in different orders and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this respect.
[0030] The term "including" and its variations used herein are open inclusions, i.e., "including but not limited to". The term "based on" means "based at least in part on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.
[0031] It should be noted that the concepts such as "first" and "second" mentioned in the present disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units.
[0032] It should be noted that the modifications of "one" and "plurality" mentioned in the present disclosure are illustrative rather than restrictive, and those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more".
[0033] The names of the messages or information exchanged between multiple devices in the embodiments of the present disclosure are only used for illustrative purposes and are not used to limit the scope of these messages or information.
[0034] Figure 1 is a flow chart of a container network access control method according to some embodiments. Figure 1 As shown, the embodiment of the present disclosure provides a container network access control method, which can be executed by an electronic device, and specifically can be executed by a container network access control device, which can be implemented by software and / or hardware and configured in the electronic device. Figure 1 As shown, the method may include the following steps.
[0035] In step 110, identity information of a first network endpoint and a second network endpoint related to a container network communication link across the container group Pod is determined through a filter.
[0036] Here, Pod is the basic deployment unit in the container orchestration system. Pod can be understood as a container group that encapsulates one or more containers so that the containers in the Pod can share network and storage resources. Among them, Pod is configured with multiple network endpoints to support container communication across Pods. One or more network endpoints can be configured in a Pod, so the first network endpoint is any network endpoint in a Pod, and the second network endpoint is any network endpoint in another Pod.
[0037] Accordingly, a container network communication link across Pods may refer to a network communication link between a network endpoint of one Pod and a network endpoint of another Pod in a communication network.
[0038] A network endpoint is a logical interface point used by containers to communicate in a network. It should be noted that a network endpoint can actually be understood as an interface used by a container to communicate with other containers or external networks.
[0039] In the disclosed embodiment, the filter may be an eBPF (Extended Berkeley Packet Filter) program, which is a high-performance, secure, and programmable data packet filtering technology that runs in the Linux kernel. In the disclosed embodiment, the flow control of the network endpoint is implemented by the eBPF program.
[0040] Among them, the identity information may refer to the IP (Internet Protocol) addresses of the first network endpoint and the second network endpoint. Of course, the identity information may also refer to the uniquely specified security identifier of the first network endpoint and the second network endpoint in the communication network. The identity information is used to uniquely identify a communication entity in the communication network. In the embodiment of the present disclosure, the identity information of the first network endpoint and the second network endpoint is used to determine the communicating parties (the first network endpoint and the second network endpoint) in the container network communication link across the Pod in the communication network to establish a communication connection between the communicating parties.
[0041] It should be noted that one of the first network endpoint and the second network endpoint can be a source and the other can be a destination. For example, when the first network endpoint is a source, the second network endpoint is a destination. When the first network endpoint is a destination, the second network endpoint is a source.
[0042] When the first network endpoint and the second network endpoint are about to establish a communication connection, the identity information corresponding to the first network endpoint and the second network endpoint may be determined through an eBPF program.
[0043] In step 120, based on the network endpoint-level access control table preconfigured for the Pod, a target access action corresponding to the identity information is searched.
[0044] Here, the network endpoint-level access control list is used to maintain the access actions for network access between cross-Pod network endpoints. The access actions include allowing access or denying access. Among them, allowing access may mean allowing the first network endpoint to communicate with the second network endpoint, and denying access may mean denying the first network endpoint to communicate with the second network endpoint.
[0045] For Pod, you can configure the network endpoint-level access control list for the network endpoint according to the different network endpoints used by the Pod. In other words, the network endpoint-level access control list does not act on the Pod as a whole, but on a certain network endpoint in the Pod.
[0046] Based on this, in the communication scenario where a Pod uses multiple network endpoints (also called virtual network cards), corresponding network endpoint-level access control lists can be separately issued for different network endpoints on different network planes, so that the network endpoint-level access control list can perform network access control for different network endpoints.
[0047] Among them, the access control list (ACL) is a mechanism used for computer and network security, which is used to define and control the access rights of users or systems to resources. It should be understood that the access control list may include user-configured access control rules to determine whether the first network endpoint and the second network endpoint can communicate through the access control rules.
[0048] It is worth noting that the network endpoint-level access control table is configured with access control rules for network endpoints, and the target access action can be found in the access control rules configured in the network endpoint-level access control table corresponding to the identity information according to the identity information.
[0049] Exemplarily, the access control rules can indicate that a second network endpoint with specified identity information (IP address) can access a first network endpoint. If the determined identity information is the IP address specified in the access control rules, the target access action is to allow access; if the identity information is not the IP address specified in the access control rules, the target access action is to deny access.
[0050] In some embodiments, the network endpoint-level access control table may include a mapping relationship between identity information and network endpoints and target access actions. That is, in the network endpoint-level access control table, the identity information and the network endpoint are used as keys, and the target access action is used as the value corresponding to the key. Accordingly, the corresponding target access action can be queried in the network endpoint-level access control table through the identity information and the first network endpoint. That is, the corresponding value is searched in the network endpoint-level access control table with the identity information and the first network endpoint as keys to determine the target access action.
[0051] In some embodiments, based on the first network endpoint, a network endpoint-level access control list matching the first network endpoint can be determined in the mapping table of the eBPF program, and then the target access actions of the first network endpoint and the second network endpoint can be determined based on the identity information and the network endpoint-level access control list.
[0052] In the mapping table, the network endpoint-level access control table can be stored through a KV pair (Key-Value Pair). Exemplarily, the network endpoint can be used as a key, and the network endpoint-level access control table can be used as the value corresponding to the key, and the access control list for different network endpoints can be stored in the mapping table. After obtaining the identity information, the eBPF program searches for a network endpoint-level access control table that matches the first network endpoint in the mapping table of the eBPF program through the first network endpoint.
[0053] It should be noted that since the network endpoint-level access control list is configured for a specific network endpoint in the Pod, the corresponding network endpoint-level access control list can be found in the mapping table of the eBPF program through the identifier of the first network endpoint.
[0054] In step 130, a target access action is performed.
[0055] Here, after the eBPF program determines the target access action for the first network endpoint and the second network endpoint, the eBPF program executes the target access action.
[0056] Exemplarily, when the target access action is to allow access, the first network endpoint is allowed to communicate with the second network endpoint. When the target access action is to deny access, the first network endpoint is denied to communicate with the second network endpoint.
[0057] It is worth noting that, for network endpoints using different communication protocols, the target access action can be executed in a manner that matches the protocol used by the network endpoint. The specific manner will be described in detail in subsequent implementation methods.
[0058] Therefore, the identity information of the first network endpoint and the second network endpoint related to the container network communication link of the Pod is determined through the filter, and the target access action corresponding to the identity information is found based on the network endpoint-level access control table pre-configured for the Pod, and the target access action is executed. This can achieve network access control for the container without relying on the network access control capabilities provided by the underlying infrastructure, and has stronger adaptability. In addition, network access control can be performed in the dimension of the container's network endpoint. In the scenario where the Pod has multiple network endpoints, network access control can be flexibly performed on different network endpoints according to needs.
[0059] In some achievable implementations, the multiple network endpoints configured in the Pod support multiple network protocols, and the multiple network protocols include at least the TCP / IP protocol and the remote direct memory access RDMA protocol.
[0060] Here, in the communication network, each Pod can be configured with multiple network endpoints that support different network protocols for communication between containers in different Pods. Each network endpoint can use the TCP / IP (Transmission Control Protocol / Internet Protocol) protocol or the Remote Direct Memory Access (RDMA) protocol.
[0061] RDMA is a technology that allows network hardware to transfer data directly between two nodes without involving the CPU (Central Processing Unit) at the sender and receiver, thereby reducing latency and CPU load.
[0062] In some feasible implementations, in step 110, the extensible Berkeley packet filter eBPF mounted on the first network endpoint of the Pod can be used to obtain data packets passing through the TCP / IP protocol stack of the first network endpoint, and parse the data packets to determine the identity information of the first network endpoint and the second network endpoint.
[0063] Here, the eBPF program can be mounted (hooked) on the network endpoint of the Pod through the hook function to perform network access control on the traffic of the TCP / IP protocol stack.
[0064] It should be understood that TCP / IP traffic will be transmitted through the network endpoint of the Pod, so by mounting the eBPF program on the network endpoint of the Pod, the data packets of the TCP / IP traffic can be obtained, and the identity information of the first network endpoint and the second network endpoint can be determined by parsing the data packets.
[0065] Exemplarily, the identity information corresponding to the first network endpoint and the second network endpoint that communicate using the TCP / IP protocol stack can be obtained through the header information of the data packet, thereby performing network access control on the TCP / IP traffic.
[0066] The data packet passing through the first network endpoint of the Pod may be generated by a container in the Pod. For example, when a container in the Pod needs to communicate with the second network endpoint, the container generates a data packet to request to establish communication with the second network endpoint through the data packet. Of course, the data packet passing through the first network endpoint of the Pod may also be sent by the second network endpoint to the first network endpoint of the Pod to request to establish communication with the container in the Pod.
[0067] In the disclosed embodiment, whether it is a data packet generated by the container of the Pod of the first network endpoint or a data packet generated by the container of the Pod corresponding to the second network endpoint, when passing through the first network endpoint, it will be acquired by the eBPF program to obtain the identity information of the first network endpoint and the second network endpoint through the eBPF program.
[0068] It is worth noting that for network endpoints using different network protocols, the form of their identity information is different. For example, for the TCP / IP protocol stack, the identity information may be the IP addresses of the first network endpoint and the second network endpoint obtained through the header information of the data packet of the TCP / IP protocol stack. For the RDMA protocol, the identity information may be the IP address used to establish the RDMA communication, and the IP address includes the source IP address and the destination IP address.
[0069] The data packet of the TCP / IP protocol stack can be obtained through the eBPF program, and the corresponding identity information can be obtained through the header information of the data packet. Then, according to the identity information, the network endpoint-level access control table matching the first network endpoint stored in the mapping table of the eBPF program is used to determine the target access action corresponding to the first network endpoint and the second network endpoint.
[0070] The header information of a data packet may refer to a set of information attached to the front of a data packet in data communication, which is used to describe the properties of the data packet. In the embodiment of the present disclosure, the header information of a data packet may include information such as IP Address, Protocol, and Port Number. The IP address may include the source IP address and the destination IP address of the data packet (the identity information of the first network endpoint and the identity information of the second network endpoint).
[0071] During the Pod creation process, the eBPF program can be mounted on the Pod's network endpoint, and then the unique endpoint identifier of the locally assigned network endpoint is written into the read-only data (rodata). When the eBPF program obtains a data packet passing through the first network endpoint of the Pod, the corresponding identity information can be obtained through the header information of the data packet, and then the network endpoint-level access control table corresponding to the endpoint identifier is found in the mapping table of the eBPF program according to the endpoint identifier of the first network endpoint, and the target access action is determined and executed according to the network endpoint-level access control table and the identity information, thereby realizing network access control for TCP / IP traffic.
[0072] In some practicable implementations, the identity information of the first network endpoint and the second network endpoint that communicate using the RDMA protocol may be obtained through an extensible Berkeley packet filter eBPF mounted on a system kernel probe.
[0073] Here, the eBPF program can be mounted on the kernel probe (kprobe) of the system through the hook function to obtain the identity information of the first network endpoint and the second network endpoint that communicate using the RDMA protocol, thereby performing network access control on the RDMA communication.
[0074] It should be understood that in RDMA communication, the system obtains the identity information of both parties in RDMA communication (including the first network endpoint and the second network endpoint) by calling a function, and then establishes RDMA communication between the two parties through the obtained identity information. By hooking the kernel probe of the system, in the process of the system obtaining the identity information of both parties in RDMA communication by calling a function, the call of the eBPF program is triggered so that the eBPF program obtains the corresponding identity information. The eBPF program can obtain the identity information of both parties in RDMA communication, thereby inserting the inspection process for RDMA CM traffic and realizing network access control for RDMA CM traffic.
[0075] It should be noted that in a communication network, some network endpoints can support both RDMA and TCP / IP protocol stacks. Generally, network endpoints that support RDMA are called network endpoints using the RDMA protocol.
[0076] When the eBPF program obtains the identity information of the two communicating parties using the RDMA protocol from the kernel probe, it can search for the corresponding network endpoint-level access control table in the mapping table of the eBPF program based on the first network endpoint of the Pod, and determine and execute the target access action based on the network endpoint-level access control table and identity information, thereby realizing network access control of RDMA traffic.
[0077] Figure 2 FIG. 1 is a schematic diagram showing a structure of a data plane according to some embodiments. Figure 2 As shown, the first eBPF program is mounted on the first network endpoint through a hook function, and is used to perform network access control on the outbound traffic and inbound traffic of the first network endpoint. The second eBPF program is mounted on the second network endpoint through a hook function, and is used to perform network access control on the outbound traffic and inbound traffic of the second network endpoint. When inbound traffic or outbound traffic arrives at the network endpoint of the Pod, the eBPF program will be called to check whether the inbound traffic or outbound traffic complies with the defined network endpoint-level access control list. If the inbound traffic or outbound traffic is allowed to access, the inbound traffic will enter the Pod through the network endpoint. If the inbound traffic or outbound traffic is denied access, the inbound traffic or outbound traffic will be blocked from passing through the Pod.
[0078] A Network Interface Card (NIC) is a hardware device used to connect to a network. It can be used to communicate with external networks or local containers.
[0079] The third eBPF program is mounted on the system's kernel probe through a hook function. The kernel probe allows custom code to be attached at the entry of the kernel function to monitor and analyze kernel behavior. By mounting the third eBPF program on the kernel probe, the identity information of the RDMA traffic can be obtained and network access control can be performed on the RDMA traffic.
[0080] It is worth noting that the first eBPF program, the second eBPF program and the third eBPF program may be different eBPF programs or the same eBPF program.
[0081] Therefore, by mounting the eBPF program on the first network endpoint of the Pod, network access control for TCP / IP traffic can be implemented. By mounting the eBPF program on the system's kernel probe, network access control for RDMA CM traffic can be implemented to support secure isolation of the RDMA network, thereby helping users introduce better-performing RDMA networks in container networks and making container networks more scalable.
[0082] In some feasible implementations, a network endpoint-level access control table may be pre-issued and stored in a mapping table of an eBPF program, where the network endpoint-level access control table is generated by a container orchestration system for the network endpoint configuration of a Pod.
[0083] Here, the mapping table of the eBPF program (also called map) is a data structure in the eBPF program, which is used to transfer data between the user space and the kernel space. The mapping table stores the network endpoint-level access control table configured for different network endpoints of the Pod.
[0084] In some embodiments, custom resources provided by the container orchestration system can be combined with an access control list configuration template to configure corresponding configuration information based on the network protocols supported by the network endpoints in the Pod. The configuration information includes access control rules and network endpoints that specify the application of the access control rules, and a network endpoint-level access control list is generated based on the configuration information.
[0085] Here, the container orchestration system can be Kubernetes. Kubernetes is an open source container orchestration system for automating the deployment, expansion, and management of containerized applications. The Pod of the Kubernetes cluster serves as the host of the container, and the Pod is the basic deployment unit in the Kubernetes cluster.
[0086] Custom Resource (CR) is a concept in Kubernetes that allows users to extend the Kubernetes API (interface) to create and use user-defined resource types. Custom resources can usually be defined through Custom Resource Definitions (CRD), which is a Kubernetes API resource used to register and define custom resource types.
[0087] Custom resources can be defined in a container orchestration system, and corresponding configuration information can be configured in the custom resources through a pre-configured access control column configuration template, where the configuration information includes access control rules and network endpoints of the Pods to which the access control rules are applied.
[0088] The access control list configuration template is used to provide multiple sets of parameters to configure access control rules for network endpoints. Exemplarily, the access control list configuration template is used to configure access control rules for network endpoints of different network protocols in a Pod and network endpoints to which the access control rules are applied through multiple sets of predefined parameters.
[0089] Through the access control list configuration template, users can configure corresponding access control rules for network endpoints of different network protocols, so as to issue access control rules separately for network endpoints of different network protocols.
[0090] Exemplarily, a custom resource is created in the container orchestration system corresponding to the Pod, and the corresponding configuration information is configured in the custom resource through a pre-configured access control list configuration template, and the custom resource is obtained from the container orchestration system through a user-state program of the container orchestration system. A network endpoint-level access control list is generated according to the configuration information carried in the custom resource, and the network endpoint-level access control list is stored in the mapping table of the eBPF program.
[0091] Figure 3 is a schematic diagram of a mapping table according to some embodiments. Figure 3As shown in the figure, the user-mode program deployed on each node of the container orchestration system (Kubernetes cluster) can monitor (watch) the custom resources in the container orchestration system, and the user-mode program receives a notification when the state of the custom resources changes. When the user-mode program receives the notification, it obtains the custom resources from the container orchestration system, and calculates the network endpoint-level access control list for the network endpoint of the Pod based on the access control rules defined by the custom resources and the network endpoint of the Pod to which the access control rules are applied, and stores the network endpoint-level access control list in the mapping table of the eBPF program. The eBPF program can then read the corresponding network endpoint-level access control list from the mapping table.
[0092] Therefore, through custom resources, users can configure custom network endpoint-level access control lists, and through user-state programs, changes in custom resources can be detected. User-state programs can update network endpoint-level access control lists in real time without manual intervention, thereby automatically managing complex network access control policies in large-scale container deployments and improving efficiency.
[0093] In some practicable implementations, for a network endpoint using a TCP / IP protocol stack, the access control list configuration template includes the following parameters:
[0094] The first parameter is used to indicate the inbound access control rule of the Pod's network endpoint, the second parameter is used to indicate the outbound access control rule of the Pod's network endpoint, the third parameter is used to specify the Pod to which the access control rule is applied, and the fourth parameter is used to specify the network endpoint in the Pod to which the access control rule is applied by creating the CNI name of the network endpoint.
[0095] Here, the inbound access control rule refers to the access control rule for the traffic entering the Pod through the network endpoint. The inbound access control rule of the Pod's network endpoint can be indicated by the first parameter to allow or deny a specific remote endpoint to communicate with the container in the Pod.
[0096] It should be noted that the remote endpoint refers to another communication endpoint of the network endpoint of the Pod in the network. In other words, the remote endpoint can be a network endpoint in another Pod or an external network that needs to communicate with the network endpoint of the Pod.
[0097] Exemplarily, in the access control list configuration template, the inbound access control rule may be configured by the following first parameter.
[0098] {
[0099] ingress: (define inbound access control rules)
[0100] - fromGroups: (Allow traffic from specific network endpoint groups)
[0101] - "group3" (traffic from network endpoint group 3)
[0102] - fromEntities: (Allow traffic from specific entities)
[0103] - "sys-node" (traffic from system nodes)
[0104] - fromCIDRs: (Allow traffic from a specific IP range)
[0105] - "192.168.0.0 / 16" (traffic from 192.168.0.0 to 192.168.255.255)
[0106] }
[0107] Outbound access control rules refer to access control rules for traffic going out of the Pod through the network endpoint. The outbound access control rules of the Pod's network endpoint can be indicated by the second parameter, thereby allowing or denying the container in the Pod to actively communicate with the remote endpoint.
[0108] Exemplarily, the second parameter in the access control list configuration template may configure the outbound access control rule through the following fields.
[0109] {
[0110] egress: (define outbound access control rules)
[0111] - toGroups: (Allow traffic to specific network endpoint groups)
[0112] - "group3" (traffic sent to network endpoint group 3)
[0113] - toEntities: (Allow traffic to specific entities)
[0114] - "sys-node" (traffic sent to system nodes)
[0115] - toCIDRs: (Allow traffic to specific IP ranges)
[0116] - "172.168.0.0 / 16" (traffic destined for 172.168.0.0 to 172.168.255.255)
[0117] }
[0118] It is worth noting that the inbound access control rules and the outbound access control rules actually indicate which network endpoints corresponding to which identity information can communicate with each other and / or which network endpoints corresponding to which identity information cannot communicate with each other.
[0119] The third parameter is used to specify the Pod to which the above inbound access control rules and outbound access rules are applied, and the fourth parameter is used to specify the network endpoint in the Pod to which the access control rules are applied by creating the CNI name of the network endpoint. Among them, CNI (Container Network Interface) is a specification for container networks, which defines the interface standard between container management and network plug-ins, so that different container runtimes can interact with various network plug-ins through a unified interface.
[0120] Exemplarily, the third parameter and the fourth parameter in the access control list configuration template can be configured through the following fields to configure the access control rules applying the above configuration:
[0121] {
[0122] spec: (specify specific configuration)
[0123] endpointSelector: (selector used to select the network endpoint to which the access control rules are applied)
[0124] networkSelector: (network selector, used to select a specific network)
[0125] cniName:RDMA (select the network endpoint in the Pod to which the access control rule is applied by specifying the name of the network endpoint CNI. Here, it is RDMA, indicating that the RDMA type network endpoint is the network endpoint in the Pod to which the access control rule is applied)
[0126] labelSelector: (label selector, used to specify the Pod to which the access control rules are applied)
[0127] matchLabels: (key-value pairs of matching labels)
[0128] networking.k8s.volcengine.com / acl-group: "group1" (label key, value is group1)
[0129] matchExpressions: (expression selector)
[0130] - key: app (label key, here is app)
[0131] operator: In (operator, here In, indicating that the value is in the list)
[0132] values: (value list, here is ["nccl"])
[0133] - "nccl"
[0134] }
[0135] It is worth noting that since the label is on the Pod, the Pod to which the access control rules are applied can be filtered through labelSelector. Moreover, the CNI name of the network endpoint can be used to select the network endpoint with the specified CNI name in the specified Pod to apply the access control rules. For example, in the above example, cniName:RDMA can be used to indicate that the network endpoint using the RDMA communication protocol in the specified Pod applies the above inbound access control rules and outbound access control rules.
[0136] It should be noted that by specifying the network endpoints to which the access control rules apply in the Pod through the CNI name, it can be understood that the above access control rules apply to the network endpoints corresponding to all the specified CNI names in the Pod. In other words, the network endpoints created using the CNI named RDMA all use the above inbound access control rules and outbound access control rules.
[0137] Therefore, through the above access control list configuration template, the user can define the access control rules for TCP / IP traffic.
[0138] In some practicable implementations, for a network endpoint of a container that communicates using a remote direct memory access protocol, an access control list configuration template includes the following parameters:
[0139] A fifth parameter for indicating the access control rules of the destination network endpoint group in RDMA, a sixth parameter for indicating the source network endpoint group in RDMA, and a seventh parameter for indicating the network endpoint to which the access control rules are applied in the source network endpoint group by creating the CNI name of the network endpoint.
[0140] Here, the fifth parameter is used to indicate the access control rules of the specified destination network endpoint group (Remote Endpoint) in the remote direct memory access protocol RDMA, wherein the specified destination network endpoint group may refer to a specific network endpoint group in the RDMA network. Through the fifth parameter, it can be indicated whether communication is allowed or denied between the specified destination network endpoint groups. The sixth parameter indicates the source network endpoint group (groupSelector) to which the access control rules are applied in RDMA. The seventh parameter indicates the network endpoint to which the access control rules are applied in the source network endpoint group by creating the CNI name of the network endpoint. For example, if groupA is specified in groupSelector and groupB is specified in remoteEndpoints, it means that the network endpoint group of groupA can pass through the network endpoint group of groupB.
[0141] Exemplarily, the access control list configuration template may be configured with the following fields to configure the corresponding access control rules and the network endpoints to which the access control rules are applied.
[0142] {
[0143] spec: (specify the specific configuration of access control rules)
[0144] endpointSelector: (selector used to select the network endpoint to which the access control rules are applied)
[0145] networkSelector: (network selector, used to select a specific network)
[0146] cniName:rdma (select the network endpoint to which the access control rule is applied by specifying the name of the network endpoint CNI, which is RDMA here, indicating that the RDMA type network endpoint is the network endpoint to which the access control rule is applied)
[0147] groupSelector: (used to select a specific RDMA source network endpoint group. Access control rules will be applied to the network entities defined in these source network endpoint groups, here group2 and group1)
[0148] -"group2"
[0149] -"group1"
[0150] remoteEndpoints: (defines the destination network endpoint group, indicating which other groups of nodes are allowed to communicate with RDMA, here group1 and group2)
[0151] -groups:
[0152] -"group1"
[0153] -"group2"
[0154] }
[0155] It is worth noting that the access control rules of the specified destination network endpoint group in the RDMA network can be indicated by remoteEndpoints: (the fifth parameter). For example, in the above example, the network endpoints in group1 and group2 in the RDMA network can communicate. The CNI name of the network endpoint can be used to select the network endpoint with the specified CNI name in the specified groupSelector to apply the above access control rules. For example, in the above example, cniName:rdma can be used to indicate that the network endpoint in the specified source network endpoint group that supports the RDMA communication protocol applies the above access control rules.
[0156] It should be noted that the access control rules for the destination network endpoint group in RDMA actually indicate which network endpoints corresponding to which identity information can communicate and / or which network endpoints corresponding to which identity information cannot communicate in RDMA communication.
[0157] Therefore, through the above access control list configuration template, users can define access control rules for RDMA traffic, implement network access control for RDMA traffic, support secure isolation of RDMA networks, and help users introduce better-performing RDMA networks in container networks, so that container networks can have better scalability.
[0158] It should be noted that each access control list configuration template can include fields for defining custom resources. For example, you can create a custom resource for configuring access control rules in the custom resources of the container orchestration system through the following fields.
[0159] {
[0160] apiVersion: apiversion (API version number, used to inform the Kubernetes API server which version of the specification should be used to parse and process this resource definition)
[0161] kind: ClusterNetworkACL (resource type, indicating that this is a cluster-level access control list)
[0162] metadata: (name of the resource)
[0163] name:name
[0164] }
[0165] It should be understood that, through the above fields, a custom resource can be defined in the container orchestration system, so as to configure the corresponding access control rules and the network endpoints to which the access control rules are applied through the custom resource in combination with the access control list configuration template.
[0166] In some practicable implementations, in step 130, the target access action may be performed based on the network protocol of the first network endpoint and the second network endpoint.
[0167] In some embodiments, if the first network endpoint and the second network endpoint use the RDMA protocol, a target access action is performed to allow or interrupt the first network endpoint and the second network endpoint to establish a communication connection.
[0168] Here, RDMA communication needs to exchange communication control information before transmitting information. If the communication control information cannot be exchanged, the subsequent data information transmission cannot be successful. Before the two communicating parties of RDMA exchange communication control information, it is necessary to determine the identity information of the two communicating parties (the first network endpoint and the second network endpoint). The eBPF program of the embodiment of the present disclosure inserts a process of checking the identity information during the process of determining the identity information to determine whether the two communicating parties of RDMA can perform the subsequent communication process.
[0169] Figure 4 FIG. 4 is a schematic diagram of RDMA communication according to some embodiments. Figure 4 As shown in the figure, at network endpoint A and network endpoint B, the RDMA communication application relies on the CM (Connection Management) API to complete the establishment of the connection. The process of establishing the connection is a process of handshake and trust between the two parties involved in the protocol (network endpoint A and network endpoint B). During the handshake process, the CM management of network endpoint A and network endpoint B exchanges communication control information through protocol messages to obtain the other party's QPN (Queue Pair Number), Virtual Address, and Remote Key (a security mechanism for accessing remote memory in RDMA communication) and other information.
[0170] Therefore, by managing the RDMA traffic between two network endpoints in the Kubernetes cluster, the information exchange process between the two network endpoints can be managed. If the target access action is to allow access, the first network endpoint is allowed to establish a communication connection with the remote endpoint through the corresponding identity information. If the target access action is to deny access, the connection process of the first network endpoint and the remote endpoint through the corresponding identity information is interrupted.
[0171] For example, when network endpoint A actively communicates with network endpoint B, the eBPF program obtains the identity information of network endpoint A and network endpoint B for requesting to establish RDMA communication, and uses the identity information and the corresponding network endpoint-level access control table to check whether network endpoint A is allowed to communicate with network endpoint B. If communication is allowed, the connection is opened and the connection establishment process continues. If communication is not allowed, the connection establishment process is interrupted and the original connection establishment process fails.
[0172] For another example, assuming that network endpoint A and the node itself are open, network endpoint B will passively receive the connection request sent by network endpoint A. When network endpoint B plans to agree and respond to the connection request of network endpoint A, the identity information of network endpoint A and network endpoint B used to request the establishment of RDMA communication is obtained through the eBPF program, and the identity information and the corresponding network endpoint-level access control table are used to check whether network endpoint A and network endpoint B are allowed to communicate. If communication is allowed, the connection is opened and the connection establishment process continues. If communication is not allowed, the connection establishment process is interrupted and the original connection establishment process fails.
[0173] Therefore, through the above implementation, network access control of RDMA traffic can be implemented, so that the RDMA communication protocol can be used in the Kubernetes cluster.
[0174] In some embodiments, if the first network endpoint and the second network endpoint use the TCP / IP protocol, a target access action is performed to allow the TCP / IP data packet to be transmitted through the first network endpoint or to discard the TCP / IP data packet.
[0175] Here, when performing network access control on TCP / IP traffic, if the access action determined by the eBPF program is to allow access, the eBPF program allows the data packet to pass through the first network endpoint. Among them, allowing the data packet to pass through the first network endpoint may mean allowing the data packet to enter the first network endpoint to establish a connection between the first network endpoint and the second network endpoint through the data packet. Of course, passing through the first network endpoint may mean allowing the data packet to be sent from the first network endpoint to the second network endpoint to request the second network endpoint to establish a connection with the first network endpoint through the data packet. If the access action determined by the eBPF program is to deny access, the eBPF program discards the data packet and refuses the first network endpoint to communicate with the second network endpoint.
[0176] It should be noted that in the TCP / IP protocol stack, its identity information is obtained through the header information of the data packet. Accordingly, if the access action determined by the eBPF program is to allow access, the eBPF program allows the data packet to pass through the first network endpoint. If the access action determined by the eBPF program is to deny access, the eBPF program discards the data packet and denies the first network endpoint from communicating with the second network endpoint.
[0177] Therefore, through the above implementation, network access control of TCP / IP traffic can be achieved.
[0178] Accordingly, in step 120, if the first network endpoint and the second network endpoint use the RDMA protocol, the first network endpoint group to which the first network endpoint belongs and the second network endpoint group to which the second network endpoint belongs are determined based on the identity information; based on the first network endpoint group and the second network endpoint group, an access control rule that allows the first network endpoint group and the second network endpoint group to communicate is searched in the network endpoint-level access control table; in response to finding the access control rule, the access action is determined to be allowing access, and in response to not finding the access control rule, the access action is determined to be denying access.
[0179] Here, when the first network endpoint and the second network endpoint use the RDMA protocol, the identity information may be a first IP address of the first network endpoint and a second IP address of the second network endpoint, wherein one of the first IP address and the second IP address is a source IP address and the other is a destination IP address.
[0180] A mapping relationship between IP addresses and network endpoint groups can be maintained. For example, the network endpoint group ID to which the container in the Pod belongs can be obtained from the Pod's Annotation, and the IP address corresponding to the container can be obtained from the Pod. Then, a mapping relationship between the IP address and the network endpoint group can be constructed based on the obtained IP address and the network endpoint group ID. The network endpoint group ID can also be called the network security identifier corresponding to the network endpoint group.
[0181] Through the first IP address and the second IP address, the first network endpoint group to which the first IP address belongs and the second network endpoint group to which the second IP address belongs can be queried in the mapping relationship between the IP address and the network endpoint group.
[0182] Then, using the IDs corresponding to the first network endpoint group and the second network endpoint group, search the network endpoint-level access control table that matches the first network endpoint to see whether there is an access control rule in the network endpoint-level access control table that allows the first network endpoint group and the second network endpoint group to communicate.
[0183] It should be noted that there is an access control rule that allows the first network endpoint group and the second network endpoint group to communicate, indicating that the network endpoints in the first network endpoint group and the second network endpoint group can perform RDMA communication.
[0184] Accordingly, when there is a corresponding access control rule in the network endpoint-level access control table, the access action is determined to be access permission, and when there is no access control rule in the network endpoint-level access control table, the access action is determined to be access denial.
[0185] Figure 5 FIG. 4 is a flowchart of determining a target access action according to some embodiments. Figure 5 As shown, the first network endpoint group is recorded as groupA and the second network endpoint group is recorded as groupB. If groupA is not found, groupA==0, and if groupB is not found, groupB==0. Therefore, according to the query result, there are four situations: groupA!=0&&groupB!=0, groupA!=0&&groupB==0, groupA==0&&groupB!=0, and groupA==0&&groupB==0.
[0186] For the case of groupA!=0&&groupB!=0, if groupA is equal to groupB, it means that the network endpoints of the same network endpoint group are communicating, and the access action is to allow access. If groupA is not equal to groupB, then the sequence<groupA,groupB> Query the corresponding network endpoint-level access control table (groupAccpet). If the sequence is found in the network endpoint-level access control table, determine whether the query result is deny. If so, the access action is deny access. If not, the access action is allow access.<groupA,groupB> If it misses, use the sequence<groupA,0> Query the network endpoint level access control table. If no hit is found, continue to query the network endpoint level access control table using the sequence <0,groupB>. If no hit is found, continue to query the network endpoint level access control table using the sequence <0,0>.
[0187] It should be noted that in the sequence<groupA,0> In the example, groupA is set to 0, indicating whether there is an access control rule in the network endpoint-level access control table that allows groupA to communicate with all network endpoint groups. Similarly, the sequence <0,groupB> indicates whether there is an access control rule in the network endpoint-level access control table that allows all network endpoint groups to communicate with groupB, and the sequence <0,0> indicates whether there is an access control rule in the network endpoint-level access control table that allows any two network endpoint groups to communicate.
[0188] For the remaining cases of groupA!=0&&groupB==0, groupA==0&&groupB!=0, and groupA==0&&groupB==0, the above method is also used to query the corresponding network endpoint-level access control table to see whether there is an access control rule that enables groupA and groupB to communicate.
[0189] Therefore, through the above implementation, network access control can be performed on RDMA traffic, thereby introducing RDMA communication in the Kubernetes cluster.
[0190] In some practicable implementations, for a network endpoint-level access control list of a TCP / IP protocol stack, the access control rules may include at least one of a sec_id (security identifier) rule and a CIDR (Classless Inter-Domain Routing) rule.
[0191] Among them, sec_id rules refer to rules based on network security identifiers of network endpoint groups. Network security identifiers are identifiers of users, groups, or services. Identifiers are used to identify entities in security contexts. CIDR rules are a way to specify IP addresses and subnet masks for network access control. CIDR rules are often used to define which IP address ranges are allowed or denied access to specific network resources.
[0192] Accordingly, when network access control is performed on TCP / IP traffic, access control rules may be used one by one to determine whether an access action is allowed between the first network endpoint and the remote endpoint.
[0193] Figure 6 FIG. 4 is a flowchart of determining an access action according to some other embodiments. Figure 6As shown, the eBPF program obtains a data packet to determine the identity information through the header information of the data packet, and determines whether to enable the ACL. If the ACL is not enabled, the access action is to allow access. If the ACL is enabled, the ACL corresponding to the first network endpoint is searched. If the corresponding ACL is not found, the access action is to allow access. If the corresponding ACL is found, it is further determined whether the ID rule is set (equivalent to setting the sec_id rule). If the ID rule is set, the sec_id of the remote endpoint is queried according to the IP address of the remote endpoint. If the sec_id is not queried, it is checked whether the CIDR rule is set. If the CIDR rule is set, the CIDR rule is matched, and whether the corresponding rule is hit in the CIDR rule. If the query result is denied, the access action is to deny access. If the query result is not denied, the access action is to allow access. If the corresponding rule is not hit in the CIDR rule, the access action is determined by the default policy. Among them, the default policy is user-defined. If any rule is not matched, the access action is determined by the default policy.
[0194] If sec_id is found, check whether the sec_id of the remote endpoint is the same as the sec_id of the first network endpoint. If they are the same, the access action is to allow access. If they are not the same, query the network endpoint-level access control table corresponding to the first network endpoint according to the sec_id of the remote endpoint. If the corresponding rule is hit, determine whether the query result is denied. If it is denied, the access action is to deny access. If the query result is not denied, the access action is to allow access. If the corresponding rule is not hit in the CIDR rule, the access action is determined by the default policy.
[0195] If the network endpoint-level access control table corresponding to the first network endpoint is queried according to the sec_id of the remote endpoint and no corresponding rule is hit, the sec_id of the remote endpoint is set to 0 and an attempt is made to match all rules.
[0196] It should be noted that setting the sec_id of the remote endpoint to 0 indicates whether there is an access control rule in the network endpoint-level access control table that allows the network endpoint to which the access control rule is applied to access all network endpoints.
[0197] Figure 7 is a schematic diagram of the structure of a container network access control device according to some embodiments. Figure 7 As shown, the embodiment of the present disclosure provides a container network access control device 700, and the container network access control device 700 may include:
[0198] The acquisition module 701 is configured to determine, through the filter eBPF, identity information of a first network endpoint and a second network endpoint related to a container network communication link across a container group Pod, wherein the Pod is configured with multiple network endpoints to support container communication across the Pod;
[0199] A search module 702 is configured to search for a target access action corresponding to the identity information based on a network endpoint-level access control table preconfigured for the Pod, wherein the network endpoint-level access control table is used to maintain access actions for network access between network endpoints across the Pod, and the access action includes allowing access or denying access;
[0200] The execution module 703 is configured to execute the target access action.
[0201] Optionally, the multiple network endpoints configured in the Pod support multiple network protocols, and the multiple network protocols include at least TCP / IP protocol and remote direct memory access RDMA protocol.
[0202] Optionally, the acquisition module 701 is specifically configured to:
[0203] By using an extensible Berkeley packet filter eBPF mounted on the first network endpoint of the Pod, a data packet passing through the TCP / IP protocol stack of the first network endpoint is obtained, and the data packet is parsed to determine the identity information of the first network endpoint and the second network endpoint.
[0204] Optionally, the acquisition module 701 is specifically configured to:
[0205] The identity information of the first network endpoint and the second network endpoint that communicate using the RDMA protocol is obtained through an extensible Berkeley packet filter eBPF mounted on a system kernel probe.
[0206] Optionally, the container network access control device 700 further includes:
[0207] The sending module is configured to pre-send the network endpoint-level access control table and store it in the mapping table of the eBPF program, where the network endpoint-level access control table is generated by the container orchestration system for the network endpoint configuration of the Pod.
[0208] Optionally, the sending module is specifically configured as follows:
[0209] Through the custom resources provided by the container orchestration system, combined with the access control list configuration template, the corresponding configuration information is configured according to the network protocol supported by the network endpoint in the Pod. The configuration information includes access control rules and the network endpoints specified to apply the access control rules. The access control list configuration template is used to provide multiple groups of parameters to configure the access control rules of the network endpoints;
[0210] The network endpoint-level access control list is generated according to the configuration information.
[0211] Optionally, the execution module 703 is specifically configured to:
[0212] The target access action is performed based on a network protocol of the first network endpoint and the second network endpoint.
[0213] Optionally, the execution module 703 is specifically configured to:
[0214] If the first network endpoint and the second network endpoint use the RDMA protocol, executing the target access action to allow or interrupt the first network endpoint and the second network endpoint to establish a communication connection;
[0215] If the first network endpoint and the second network endpoint use the TCP / IP protocol, the target access action is performed to allow the TCP / IP data packet to be transmitted through the first network endpoint or to discard the TCP / IP data packet.
[0216] Optionally, the search module 702 is specifically configured to:
[0217] If the first network endpoint and the second network endpoint use the RDMA protocol, determining a first network endpoint group to which the first network endpoint belongs and a second network endpoint group to which the second network endpoint belongs according to the identity information;
[0218] According to the first network endpoint group and the second network endpoint group, searching the network endpoint-level access control table for an access control rule that allows the first network endpoint group and the second network endpoint group to communicate;
[0219] In response to finding the access control rule, the access action is determined to be the access permission, and in response to not finding the access control rule, the access action is determined to be the access denial.
[0220] The logic of the method executed by each functional module in the above-mentioned container network access control device 700 can refer to the part of the method related to the above-mentioned embodiment, and will not be repeated here.
[0221] Reference below Figure 8, which shows a schematic diagram of the structure of an electronic device (such as a terminal device or a server) 800 suitable for implementing the embodiment of the present disclosure. The terminal device in the embodiment of the present disclosure may include but is not limited to mobile terminals such as mobile phones, notebook computers, digital broadcast receivers, PDAs (personal digital assistants), PADs (tablet computers), PMPs (portable multimedia players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 8 The electronic device shown is only an example and should not bring any limitation to the functions and scope of use of the embodiments of the present disclosure.
[0222] like Figure 8 As shown, the electronic device 800 may include a processing device (e.g., a central processing unit, a graphics processing unit, etc.) 801, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 802 or a program loaded from a storage device 808 to a random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 are also stored. The processing device 801, the ROM 802, and the RAM 803 are connected to each other via a bus 804. An input / output (I / O) interface 805 is also connected to the bus 804.
[0223] Typically, the following devices may be connected to the I / O interface 805: an input device 806 including, for example, a touch screen, a touch pad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 807 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 808 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 809. The communication device 809 may allow the electronic device 800 to communicate with other devices wirelessly or by wire to exchange data. Although Figure 8 The electronic device 800 is shown with various devices, but it should be understood that it is not required to implement or possess all the devices shown. More or fewer devices may be implemented or possessed instead.
[0224] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program carried on a non-transitory computer-readable medium, and the computer program contains program code for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from a network through a communication device 809, or installed from a storage device 808, or installed from a ROM 802. When the computer program is executed by the processing device 801, the above-mentioned functions defined in the method of the embodiment of the present disclosure are executed.
[0225] It should be noted that the computer-readable medium mentioned above in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium or any combination of the above two. The computer-readable storage medium may be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, device or device, or any combination of the above. More specific examples of computer-readable storage media may include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in combination with an instruction execution system, device or device. In the present disclosure, a computer-readable signal medium may include a data signal propagated in a baseband or as part of a carrier wave, which carries a computer-readable program code. This propagated data signal may take a variety of forms, including but not limited to an electromagnetic signal, an optical signal, or any suitable combination of the above. Computer readable signal media may also be any computer readable medium other than computer readable storage media, which may send, propagate or transmit a program for use by or in conjunction with an instruction execution system, apparatus or device. The program code contained on the computer readable medium may be transmitted using any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0226] In some embodiments, the electronic devices may communicate using any currently known or future developed network protocol such as HTTP (HyperText Transfer Protocol), and may be interconnected with any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include a local area network ("LAN"), a wide area network ("WAN"), an internet (e.g., the Internet), and a peer-to-peer network (e.g., an ad hoc peer-to-peer network), as well as any currently known or future developed network.
[0227] The computer-readable medium may be included in the electronic device, or may exist independently without being incorporated into the electronic device.
[0228] The computer-readable medium carries one or more programs. When the one or more programs are executed by the electronic device, the electronic device: determines the identity information of the first network endpoint and the second network endpoint related to the container network communication link across the container group Pod through a filter, and the Pod is configured with multiple network endpoints to support container communication across the Pod; based on the network endpoint-level access control table pre-configured for the Pod, searches for the target access action corresponding to the identity information, and the network endpoint-level access control table is used to maintain the access action of network entry and exit between the network endpoints across the Pod, and the access action includes allowing access or denying access; executes the target access action.
[0229] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or a combination thereof, including, but not limited to, object-oriented programming languages, such as Java, Smalltalk, C++, and conventional procedural programming languages, such as "C" or similar programming languages. The program code may be executed entirely on the user's computer, partially on the user's computer, as a separate software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or may be connected to an external computer (e.g., through the Internet using an Internet service provider).
[0230] The flow chart and block diagram in the accompanying drawings illustrate the possible architecture, function and operation of the system, method and computer program product according to various embodiments of the present disclosure. In this regard, each square box in the flow chart or block diagram can represent a module, a program segment or a part of a code, and the module, the program segment or a part of the code contains one or more executable instructions for realizing the specified logical function. It should also be noted that in some implementations as replacements, the functions marked in the square box can also occur in a sequence different from that marked in the accompanying drawings. For example, two square boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each square box in the block diagram and / or flow chart, and the combination of the square boxes in the block diagram and / or flow chart can be implemented with a dedicated hardware-based system that performs a specified function or operation, or can be implemented with a combination of dedicated hardware and computer instructions.
[0231] The modules involved in the embodiments described in the present disclosure may be implemented by software or hardware, wherein the name of a module does not, in some cases, limit the module itself.
[0232] The functions described above herein may be performed at least in part by one or more hardware logic components. For example, without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chips (SOCs), complex programmable logic devices (CPLDs), and the like.
[0233] In the context of the present disclosure, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or device, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0234] The above description is only a preferred embodiment of the present disclosure and an explanation of the technical principles used. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by a specific combination of the above technical features, but should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosed concept. For example, the above features are replaced with the technical features with similar functions disclosed in the present disclosure (but not limited to) by each other to form a technical solution.
[0235] In addition, although each operation is described in a specific order, this should not be understood as requiring these operations to be performed in the specific order shown or in a sequential order. Under certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although some specific implementation details are included in the above discussion, these should not be interpreted as limiting the scope of the present disclosure. Some features described in the context of a separate embodiment can also be implemented in a single embodiment in combination. On the contrary, the various features described in the context of a single embodiment can also be implemented in multiple embodiments individually or in any suitable sub-combination mode.
[0236] Although the subject matter has been described in language specific to structural features and / or method logic actions, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or actions described above. On the contrary, the specific features and actions described above are merely example forms of implementing the claims. Regarding the device in the above embodiment, the specific manner in which each module performs the operation has been described in detail in the embodiment related to the method, and will not be elaborated here.
Claims
1. A container network access control method, characterized in that: include: Determine, by a filter, identity information of a first network endpoint and a second network endpoint related to a container network communication link across a container group Pod, wherein the Pod is configured with multiple network endpoints to support container communication across the Pod; Based on the network endpoint-level access control table pre-configured for the Pod, the target access action corresponding to the identity information is searched, the network endpoint-level access control table acts on the network endpoints in the Pod, including the identity information and the mapping relationship between the network endpoints and the target access action, and is used to maintain the access action of network access between the network endpoints across the Pod, and the access action includes allowing access or denying access; wherein allowing access is to allow the first network endpoint to communicate with the second network endpoint, and denying access is to deny the first network endpoint to communicate with the second network endpoint; Execute the target access action.
2. The method according to claim 1, characterized in that The multiple network endpoints configured by the Pod support multiple network protocols, and the multiple network protocols include at least the TCP / IP protocol and the remote direct memory access RDMA protocol.
3. The method according to claim 2, characterized in that Determining the identity information of the first network endpoint and the second network endpoint related to the container network communication link across the container group Pod through the filter includes: By using an extensible Berkeley packet filter eBPF mounted on the first network endpoint of the Pod, a data packet passing through the TCP / IP protocol stack of the first network endpoint is obtained, and the data packet is parsed to determine the identity information of the first network endpoint and the second network endpoint.
4. The method according to claim 2, characterized in that: Determining the identity information of the first network endpoint and the second network endpoint related to the container network communication link across the container group Pod through the filter includes: The identity information of the first network endpoint and the second network endpoint that communicate using the RDMA protocol is obtained through an extensible Berkeley packet filter eBPF mounted on a system kernel probe.
5. The method according to claim 1, characterized in that The method further comprises: The network endpoint-level access control table is issued in advance and stored in the mapping table of the filter, and the network endpoint-level access control table is generated by the container orchestration system for the network endpoint configuration of the Pod.
6. The method according to claim 5, characterized in that The method further comprises: Through the custom resources provided by the container orchestration system, combined with the access control list configuration template, the corresponding configuration information is configured according to the network protocol supported by the network endpoint in the Pod. The configuration information includes access control rules and the network endpoints specified to apply the access control rules. The access control list configuration template is used to provide multiple groups of parameters to configure the access control rules of the network endpoints; The network endpoint-level access control list is generated according to the configuration information.
7. The method according to claim 1, characterized in that The executing the target access action includes: The target access action is performed based on a network protocol of the first network endpoint and the second network endpoint.
8. The method according to claim 7, characterized in that The performing the target access action based on the communication protocol between the first network endpoint and the second network endpoint includes: If the first network endpoint and the second network endpoint use the RDMA protocol, executing the target access action to allow or interrupt the first network endpoint and the second network endpoint to establish a communication connection; If the first network endpoint and the second network endpoint use the TCP / IP protocol, the target access action is performed to allow the TCP / IP data packet to be transmitted through the first network endpoint or to discard the TCP / IP data packet.
9. The method according to claim 1, characterized in that: The searching for a target access action corresponding to the identity information based on a network endpoint-level access control table preconfigured for the Pod includes: If the first network endpoint and the second network endpoint use the RDMA protocol, determining a first network endpoint group to which the first network endpoint belongs and a second network endpoint group to which the second network endpoint belongs according to the identity information; According to the first network endpoint group and the second network endpoint group, searching the network endpoint-level access control table for an access control rule that allows the first network endpoint group and the second network endpoint group to communicate; In response to finding the access control rule, determining the target access action as the access permission, and in response to not finding the access control rule, determining the target access action as the access denial.
10. A container network access control device, characterized in that: include: An acquisition module is configured to determine, through a filter, identity information of a first network endpoint and a second network endpoint related to a container network communication link across a container group Pod, wherein the Pod is configured with multiple network endpoints to support container communication across the Pod; A search module is configured to search for a target access action corresponding to the identity information based on a network endpoint-level access control table preconfigured for the Pod, wherein the network endpoint-level access control table acts on the network endpoints in the Pod, including the identity information and a mapping relationship between the network endpoints and the target access action, and is used to maintain access actions for network access between network endpoints across the Pod, wherein the access action includes allowing access or denying access; wherein allowing access is allowing the first network endpoint to communicate with the second network endpoint, and denying access is denying the first network endpoint to communicate with the second network endpoint; An execution module is configured to execute the target access action.
11. A computer readable medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processing device, the steps of the method according to any one of claims 1 to 9 are implemented.
12. An electronic device, characterized in that: include: a storage device having a computer program stored thereon; A processing device, configured to execute the computer program in the storage device to implement the steps of the method according to any one of claims 1 to 9.
13. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 9 are implemented.
Citation Information
Patent Citations
Container access control method and system, electronic equipment and storage medium
CN113986459A