A network access method, apparatus, device and medium

By using the target plug-in in the container network interface in the cloud computing scenario to determine whether the container group belongs to the same task based on the network card address, the problem of difficulty in achieving network isolation between different types of network cards of the container group is solved, and task-level network isolation and secure network access are achieved.

CN119071071BActive Publication Date: 2025-05-27BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202411204937.0
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2024-08-29
Publication Date
2025-05-27
Estimated Expiration
2044-08-29

AI Technical Summary

Technical Problem

In cloud computing scenarios, when container groups are configured with different types of network cards, it is difficult to achieve task-level network isolation.

Method used

By receiving target access requests between container groups, the target plug-in in the container network interface is used to determine whether the container group belongs to the same task based on the network card address. If so, access is allowed, and different types of network cards are processed through different plug-ins.

Benefits of technology

It realizes task-level network isolation, covers multiple network card types in container groups, and improves network access security.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119071071B_ABST
    Figure CN119071071B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure relate to a network access method, apparatus, device, and medium. The method includes: receiving a target access request sent by a first container group through a first network card, where the target access request includes a first network card address of the first network card and a second network card address of a second network card of the accessed second container group; sending the target access request to a target plugin corresponding to the container network interface of the first network card; if it is determined by the target plugin based on the first network card address and the second network card address that the first container group and the second container group belong to the same task, sending the target access request to the second network card corresponding to the second network card address of the second container group. Thus, access is only allowed between container groups of the same task, which not only achieves network isolation at the task level but also covers various network card types in the container group, realizes unified network access control with full coverage, and further improves the security of network access.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure relates to the field of cloud computing technology, and in particular, to a network access method, apparatus, device, and medium. Background Art

[0002] In a cloud computing scenario, a cloud service provider of Model as a Service (MaaS) can provide a large model as a service to a user. The user hopes that their model-related tasks run in an isolated network environment, and a task can consist of one or more Pods. In related technologies, it is possible to achieve task-level network isolation for a certain type of network card of a Pod. However, when a Pod is configured with different types of network cards, it is difficult to achieve task-level network isolation. Summary of the Invention

[0003] To solve the above technical problems, the present disclosure provides a network access method, apparatus, device, and medium.

[0004] An embodiment of the present disclosure provides a network access method, the method comprising:

[0005] Receiving a target access request sent by a first Pod through a first network card, wherein the target access request includes a first network card address of the first network card and a second network card address of a second network card of the accessed second Pod;

[0006] Sending the target access request to a target plugin corresponding to the first network card in the container network interface;

[0007] If it is determined by the target plugin based on the first network card address and the second network card address that the first Pod and the second Pod belong to the same task, sending the target access request to the second network card corresponding to the second network card address of the second Pod.

[0008] An embodiment of the present disclosure further provides a network access apparatus, the apparatus comprising:

[0009] A receiving module, configured to receive a target access request sent by a first Pod through a first network card, wherein the target access request includes a first network card address of the first network card and a second network card address of a second network card of the accessed second Pod;

[0010] A first sending module, configured to send the target access request to a target plugin corresponding to the first network card in the container network interface;

[0011] A second sending module, configured to, if it is determined by the target plugin that the first container group and the second container group belong to the same task based on the first network card address and the second network card address, send the target access request to a second network card corresponding to the second network card address of the second container group.

[0012] Embodiments of the present disclosure further provide an electronic device, including: a processor; a memory for storing executable instructions executable by the processor; the processor is configured to read the executable instructions from the memory and execute the instructions to implement the network access method provided by the embodiments of the present disclosure.

[0013] Embodiments of the present disclosure further provide a computer-readable storage medium, storing a computer program for executing the network access method provided by the embodiments of the present disclosure.

[0014] The technical solutions provided by the embodiments of the present disclosure have the following advantages compared with the prior art: The network access solution provided by the embodiments of the present disclosure receives a target access request sent by a first container group through a first network card, where the target access request includes a first network card address of the first network card and a second network card address of a second network card to be accessed; sends the target access request to a target plugin corresponding to the first network card in the container network interface; if it is determined by the target plugin that the first container group and the second container group belong to the same task based on the first network card address and the second network card address, sends the target access request to a second network card corresponding to the second network card address of the second container group. By adopting the above technical solutions, the received target access request can be sent to the target plugin in the container network interface of the first network card, and the target plugin determines whether the container groups belong to the same task according to the network card addresses of the network cards of the two container groups. If so, access is allowed, and the target access request is sent to the second network card. Different plugins are set through the container network interface to process access requests for different types of network cards in the container group. Only container groups of the same task are allowed to access, which not only realizes network isolation at the task level, but also covers multiple network card types in the container group, realizes unified network access control with full coverage, and further improves the security of network access. BRIEF DESCRIPTION OF THE DRAWINGS

[0015] In combination with the accompanying drawings and with reference to the following specific embodiments, the above and other features, advantages and aspects of the various embodiments of the present disclosure will become more obvious. Throughout the drawings, the same or similar reference numerals represent the same or similar elements. It should be understood that the drawings are schematic, and the original elements and elements are not necessarily drawn to scale.

[0016] Figure 1 It is a flowchart of a network access method provided for some embodiments of the present disclosure;

[0017] Figure 2 Deployment schematic diagram of a network access method provided by some embodiments of the present disclosure;

[0018] Figure 3 Flow schematic diagram of another network access method provided by some embodiments of the present disclosure;

[0019] Figure 4 Schematic diagram of a network card in a node provided by some embodiments of the present disclosure;

[0020] Figure 5 Flow schematic diagram of yet another network access method provided by some embodiments of the present disclosure;

[0021] Figure 6 Architectural schematic diagram of a control panel platform provided by some embodiments of the present disclosure;

[0022] Figure 7 Structural schematic diagram of a network access device provided by some embodiments of the present disclosure;

[0023] Figure 8 Structural schematic diagram of an electronic device provided by some embodiments of the present disclosure. Detailed implementation manners

[0024] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although some embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Instead, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.

[0025] It should be understood that the various steps recited in the method embodiments of the present disclosure can be executed in a different order and / or in parallel. In addition, the method embodiments may include additional steps and / or omit the steps shown. The scope of the present disclosure is not limited in this regard.

[0026] The term "including" and its variations used herein are open-ended, i.e., "including but not limited to". The term "based on" is "at least partially based on". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one additional embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description.

[0027] It should be noted that concepts such as "first" and "second" mentioned in this disclosure are only used to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependent relationships.

[0028] It should be noted that the modifiers "a" and "multiple" mentioned in this disclosure are illustrative rather than restrictive. Those skilled in the art should understand that, unless otherwise clearly specified in the context, it should be understood as "one or more".

[0029] The names of the messages or information exchanged between multiple devices in the embodiments of this disclosure are only for illustrative purposes, and are not used to limit the scope of these messages or information.

[0030] The large model, also known as the Large Language Model (LLM), is a natural language-based processing model. Through the large model, it can automatically learn the rules and structures of language, understand the meaning of language, and generate coherent text with correct grammar and semantics according to the understood meaning. The large model can also realize generating images according to text, generating videos according to text, and so on.

[0031] In the cloud computing scenario, the cloud service provider (CSP) of model as a service can undertake the large model of the model provider (Vendor), and then provide services such as inference and fine-tuning based on this large model. The user hopes that their model-related tasks run in an isolated network environment. In the related art, it is possible to achieve task-level network isolation for a certain type of network card of a container group. However, when the container group has different network devices, the container group is usually configured with different types of network cards, and it is difficult to achieve task-level network isolation for these different types of network cards, that is, it is difficult to achieve fine-grained isolation in the east-west direction between tasks.

[0032] To solve the above problems, the embodiments of this disclosure provide a network access method, which will be introduced below in combination with specific embodiments.

[0033] Figure 1 It is a schematic flowchart of a network access method provided for some embodiments of this disclosure. This method can be executed by one of a network access device, a cloud service platform, and a Container Network Interface (CNI). The cloud service platform can be a software platform that provides cloud services. Among them, this device can be implemented by software and / or hardware and is generally integrated in an electronic device. As Figure 1 shown, this method includes:

[0034] Step 101: Receive a target access request sent by a first container group through a first network card. The target access request includes the first network card address of the first network card and the second network card address of a second network card of the accessed second container group.

[0035] Among them, the first container group can be the container group initiating network access. The second container group can be the container group receiving network access. A container group can be the smallest scheduling unit in container technology. A container group can include one or more containers. Each container in the same container group shares resources, and tasks such as model inference and supervised fine-tuning (SFT) can be performed in the container group. A container group can be used to execute tasks of the user.

[0036] The first network card can be used for network communication of the first container group, and this first network card can be the network card configured for the first container group. The first network card address can be the Internet Protocol (IP) address of the first network card. The second network card can be used for network communication of the second container group, and this second network card can be the network card configured for the second container group. The second network card address can be the Internet Protocol address of the second network card. The target access request can be a network access request sent by the first container group to access the second container group.

[0037] In the embodiment of the present disclosure, when the first container group needs to access the second container group, the first container group determines the first network card address of the first network card corresponding to itself and the second network card address of the second network card corresponding to the second container group. And a target access request is generated according to the first network card address and the second network card address. The first container group sends the target access request to the network access device through the first network card. The network access device receives the target access request.

[0038] Step 102: Send the target access request to the target plugin corresponding to the first network card at the container network interface.

[0039] Among them, the Container Network Interface (CNI) can be a standard interface providing network configuration for a container group. This container network interface can define a set of interface specifications and provide specification documents and standard implementations. Through this container network interface, a container group can interact with a Remote Network Interface Card (RNIC) or a Network Interface Card (NIC).

[0040] This container network interface can correspond to the node where the container group is located. Figure 2A deployment schematic diagram of a network access method provided by some embodiments of the present disclosure is as follows. Figure 2 As shown, if container group A and container group B are in node A, and container group C and container group D are in node B, container group A and container group B in node A can correspond to container network interface 1, and container group C and container group D in node B can correspond to container network interface 2.

[0041] The target plugin can be a plugin that processes access requests sent by the first network card. This target plugin can be used to determine whether the container group initiating the network access and the container group being accessed belong to the same task. The programming language of this target plugin is not limited in this embodiment.

[0042] In the embodiments of the present disclosure, after the network access device receives a target access request, it determines the target plugin corresponding to the first network card that sends the target access request in the container network interface, and sends the target access request to the target plugin.

[0043] In some embodiments of the present disclosure, the container network interface includes multiple plugins, and each plugin corresponds to a network card type of a container group. For example, container network interface 1 corresponding to container group A includes plugin 1 and plugin 0. Plugin 1 corresponds to the primary network card of container group A, and plugin 0 corresponds to the secondary network card of container group A. Correspondingly, sending the target access request to the target plugin corresponding to the first network card in the container network interface includes: determining the target network card type of the first network card; determining the target plugin corresponding to the target network card type among the multiple plugins included in the container network interface, and sending the target access request to the target plugin.

[0044] Among them, the target network card type can be the network card type of the first network card, and this network card type includes but is not limited to the primary network card (eth0), secondary network card (eth1 - n), where n is a positive integer. The secondary network card can be a network card with Remote Direct Memory Access (RDMA) function. The plugin can correspond to the network card type, and the primary network card and the secondary network card can correspond to different plugins. Optionally, in the container network interface, one or more corresponding plugins are set for each network card type.

[0045] In some embodiments of the present disclosure, the second network card has the same network card type as the first network card. For example, the first network card and the second network card can both be primary network cards, or the first network card and the second network card can both be secondary network cards. This network access is implemented between network cards of the same network card type in two container groups.

[0046] In this embodiment, an address type correspondence relationship between a network card address and a network card type is preset. The network access device can perform a query process based on the first network card address in the address type correspondence relationship, and determine the network card type corresponding to the first network card address as the target network card type. Further, among the multiple plugins included in the container network interface, the plugin with the network port type being the target network card type is determined as the target plugin, and the target access request is sent to the target plugin.

[0047] In the above solution, when different types of network cards are configured for a container group, different plugins are used to process access requests sent by network cards of different network card types, achieving comprehensive processing of the content sent by the container group, and creating a basis for realizing task-level network isolation in this scenario.

[0048] Step 103: If the target plugin determines, based on the first network card address and the second network card address, that the first container group and the second container group belong to the same task, the target access request is sent to the second network card corresponding to the second network card address of the second container group.

[0049] Among them, a task can include one or more tasks issued or executed by a user on a cloud service platform. Exemplarily, the task is a task related to a model of the user, or the task can be a task related to computing of the user. For example, the task can include model inference and / or model fine-tuning. The task can have a single or multiple container groups.

[0050] In the embodiment of the present disclosure, after receiving the target access request, the target plugin checks the target access request through a preset access rule, and the embodiment does not limit the manner of implementing the access rule. Specifically, the target plugin can parse the target access request to obtain the first network card address and the second network card address, and determine whether the first container group and the second container group belong to the same task according to the first network card address and the second network card address. If so, since container groups within the same task can perform network access, the network access device will send the target access request of the first container group to the second network card of the second container group through a remote network interface card or a network interface card, and the second container group receives the target access request through the second network card. As Figure 2As shown, if the first container group is container group A, the first network interface card is the primary network interface card of container group A, and the second container group is container group C. Assume that it is determined through plug-in 0 in container network interface 1 that container group A and container group C belong to the same task. Then, plug-in 0 in container network interface 1 sends the target access request to the remote network interface card or network interface card corresponding to container network interface 1. The remote network interface card or network interface card corresponding to container network interface 1 sends the target access request to the remote network interface card or network interface card corresponding to container network interface 2. The remote network interface card or network interface card corresponding to container network interface 2 sends the target access request through container network interface 2 to the primary network interface card of container group C.

[0051] If the first container group and the second container group do not belong to the same task, since network isolation is required between container groups of different tasks, the network access device blocks the sending of the target access request to the second network interface card to prevent cross-task network access by the first container group.

[0052] Figure 3 It is a flowchart of another network access method provided by some embodiments of the present disclosure. As Figure 3 shown, in some embodiments of the present disclosure, determining that the first container group and the second container group belong to the same task based on the first network interface card address and the second network interface card address through the target plug-in includes:

[0053] Step 301: Obtain the mapping relationship library through the target plug-in.

[0054] In some embodiments of the present disclosure, the mapping relationship library includes multiple network interface card addresses and multiple task tags with mapping relationships. Each network interface card address has a mapping relationship with a task tag, that is, each network interface card address can correspond to a task. A task tag can have a mapping relationship with one or more network interface card addresses, that is, a task can correspond to multiple network interface cards. The task tag can be used to identify the task to which the container group corresponding to the network interface card address belongs. One or more plug-ins can jointly maintain a mapping relationship library and obtain the mapping relationships in the mapping relationship library. This embodiment does not limit the storage location of the mapping database. Optionally, the mapping relationships stored in the mapping relationship library can be dynamically adjusted according to the needs of the user.

[0055] In this embodiment, the target plug-in can obtain the mapping relationship library after receiving the target access request, or the target plug-in can obtain the target access request after obtaining the mapping relationship library. This embodiment does not make a limitation.

[0056] Step 302: Match the first network interface card address and the second network interface card address respectively in the mapping relationship library to determine the first task tag corresponding to the successfully matched first network interface card address and the second task tag corresponding to the second network interface card address.

[0057] Among them, the first task tag may characterize the task to which the first container group belongs. The second task tag may characterize the task to which the second container group belongs.

[0058] In this embodiment, the target plugin may query and process the mapping relationship library according to the first network card address, determine the task tag corresponding to the first network card address as the first task tag, and query and process the mapping relationship library according to the second network card address, and determine the task tag corresponding to the second network card address as the second task tag.

[0059] Step 303: If the first task tag and the second task tag are the same, it is determined that the first container group and the second container group belong to the same task.

[0060] In this embodiment, the target plugin may determine whether the first task tag and the second task tag are the same. If so, it is determined that the first container group corresponding to the first task tag and the second container group corresponding to the second task tag belong to the same task. Otherwise, it is determined that the first container group and the second container group do not belong to the same task.

[0061] For example, in the mapping relationship library, if there is a mapping relationship between IP1 and Grp1, a mapping relationship between IP2 and Grp1, and the first network card address is IP1 and the second network card address is IP2. Since the task tags corresponding to the first network card address and the second network card address are both Grp1, it is determined that the first container group and the second container group belong to the same task.

[0062] In the above solution, through the mapping relationship between the network card address and the task tag recorded in the mapping relationship library, the determination of whether the container groups belong to the same task is realized, and the mapping relationship can be dynamically adjusted, which improves the flexibility of network isolation between container groups and reduces the cost of adjusting the existing network isolation.

[0063] Take Figure 2 as an example, such as Figure 2As shown, container group A and container group C belong to the same task and form an isolated network X, corresponding to the same task label Grp1; container group B and container group D belong to the same task and form an isolated network Y, corresponding to the same task label Grp2. The plugin 0 in container network interface 1 has the same plugin type as the plugin 0 in container network interface 2, and the plugin 1 in container network interface 1 has the same plugin type as the plugin 1 in container network interface 2. The plugin corresponding to the primary network card of container group A is the plugin 0 in container network interface 1, and the plugin corresponding to the secondary network card of container group A is the plugin 1 in container network interface 1; the plugin corresponding to the primary network card of container group C is the plugin 0 in container network interface 2, and the plugin corresponding to the secondary network card of container group C is the plugin 1 in container network interface 2. Container network interface 1 and container network interface 2 perform data interaction through a remote network interface card or a network interface card.

[0064] When performing network access, the corresponding plugin in the container network interface processes the corresponding traffic, and determines the first network card address of the first network card that initiates the access, and the first task label corresponding to the first network card address according to the target access request. And determine the second network card address of the second network card as the access destination, and the second task label corresponding to the second network card address. Determine whether the first task label and the second task label match. If they match, the target access request is allowed to pass; if they do not match, the target access request is not allowed to pass.

[0065] Figure 4 A schematic diagram of a network card in a node provided by some embodiments of the present disclosure, as Figure 4 shown, each container group has a primary network card and a secondary network card. Within each node, the primary network card is mapped (Mapping) to a virtual machine network card (Secondary Elastic Network Interface). The secondary network card is mapped to a remote direct memory access network card (RDMAElasticNetwork Interface, RDMAENI). Figure 4 Among them, the host network card (Primary Elastic Network Interface) can be a network interface used by the host, and the virtual machine network card can be a network interface used by virtual machine containers.

[0066] The network access solution provided by the embodiments of the present disclosure receives a target access request sent by a first container group through a first network card. The target access request includes the first network card address of the first network card and the second network card address of the second network card of the second container group to be accessed. The target access request is sent to the target plugin corresponding to the container network interface of the first network card. If it is determined by the target plugin that the first container group and the second container group belong to the same task based on the first network card address and the second network card address, the target access request is sent to the second network card corresponding to the second network card address of the second container group. By adopting the above technical solution, the received target access request can be sent to the target plugin in the container network interface of the first network card. The target plugin determines whether the container groups belong to the same task according to the network card addresses of the two container groups. If so, access is allowed, and the target access request is sent to the second network card. Different plugins are set through the container network interface to process the access requests of different types of network cards in the container group. Only the container groups of the same task are allowed to access, which not only realizes network isolation at the task level, but also covers multiple network card types in the container group, realizes unified network access control with full coverage, and further improves the security of network access.

[0067] In some embodiments of the present disclosure, the network access method further includes: when the first container group is destroyed, the plugin in the container network interface corresponding to the first container group and the access rules corresponding to the container group will be destroyed. Thus, computer space is released, and the ineffective occupation of computer space is avoided.

[0068] In some embodiments of the present disclosure, after determining the first task label corresponding to the successfully matched first network card address and the second task label corresponding to the second network card address, the network access method further includes: if the first task label and / or the second task label is a service label, it is determined that the first container group and the second container group meet the access conditions.

[0069] Among them, the service label can be used to mark a service (Service) container group. This embodiment does not limit the service label. For example, the service label can be Grp-Service. The service container group can be a container group that provides system services. The system service can be understood as a service that is not directly related to the task and is related to the system itself. This embodiment does not limit the system service. For example, the system service can include system storage services, system network services, and so on.

[0070] In this embodiment, after determining the first task label and the second task label, the target plugin can determine whether at least one of the first task label and the second task label is a service label. If so, it indicates that at least one of the first container group and the second container group is a service container group. Specifically, if the first task label is a service label, it indicates that the first container group is a service container group. If the second task label is a service label, it indicates that the second container group is a service container group. If both the first task label and the second task label are service labels, it indicates that both the first container group and the second container group are service container groups. Since network access can be performed between the service container group and other container groups, it is determined that the first container group and the second container group meet the access conditions, and the target access request is sent to the second network card corresponding to the second network card address of the second container group. As Figure 2 shown, the host network includes a service container group in Node A and a service container group in Node B. This service container group can perform network access to other container groups.

[0071] Optionally, the task label of the service container group can be adjusted from a service label to other task labels to adjust the service container group to a container group to which the task belongs, perform network access between the container groups to which the task belongs, and no longer have the function of performing network access with all container groups.

[0072] In the above solution, when there is a service container group in the first container group and the second container group, network access between the two container groups is performed, ensuring that the system service can operate normally.

[0073] Figure 5 The flowchart of another network access method provided by some embodiments of the present disclosure is shown in Figure 5 as follows. The network access method further includes:

[0074] Step 501: In response to a creation operation of at least one target container group corresponding to a target task, assign a target task label to the at least one target container group.

[0075] Among them, the target task can be the task currently performing container group configuration. The target container group can be the container group configured to the target task. The creation operation can be an operation of creating a container group to which the task belongs. This embodiment places no restrictions on this creation operation. For example, the creation operation can be a triggering operation on a creation control, or the creation operation can be a start operation of the target container group. The target task label can be used to mark the target task to which the target container group belongs.

[0076] In this embodiment, the manager of the container group can select at least one target container group required to implement the target task, and then the manager performs the creation operation. The network access device, in response to this creation operation, assigns the target task label corresponding to the target task to the at least one target container group.

[0077] In some embodiments of the present disclosure, assigning a target task label to at least one target container group includes: assigning the task identifier of the target task as the target task label to each target container group. Wherein, the task identifier may be a unique identifier of the target task, the task identifier may be non-customized, and the task identifier may be an existing identifier. This embodiment does not limit the task identifier. For example, the task identifier may be the name or serial number of the target task.

[0078] In this embodiment, the network access device may obtain the task identifier of the target task and assign the task identifier as the target task label to the target container group to which the target task belongs. Thus, using the existing task identifier as the target task label avoids the identifier confusion caused by introducing other identifiers.

[0079] In some embodiments of the present disclosure, assigning a target task label to at least one target container group includes: assigning the customized identifier of the target task as the target task label to each target container group. Thus, the label can be customized according to the needs of the user, enhancing the comprehensibility of the label.

[0080] Step 502: Establish multiple mapping relationships between the multiple network card addresses of the multiple network cards included in each target container group and the target task label respectively.

[0081] In this embodiment, the network access device may obtain the network card address of the network card included in the target container group. For each network card address, the network access device establishes a mapping relationship between the network port address and the target task label.

[0082] For example, if the network card address of the main network card of a target container group is IP3 and the network card address of the auxiliary network card is IP4, and the target task label is Grp1. Then establish a mapping relationship between IP3 and Grp1, and a mapping relationship between IP4 and Grp1.

[0083] Step 503: Transmit the multiple mapping relationships to multiple plugins of the container network interface respectively, and store the multiple mapping relationships in the mapping relationship library through the container network interface, where each plugin stores at least one mapping relationship of at least one network card corresponding to the network card type.

[0084] In this embodiment, after determining the mapping relationship between the target container group to which the target task belongs and the target task label, the network access device may transmit the mapping relationship to multiple plugins of the container network interface corresponding to the container group, and store the mapping relationship in the mapping relationship library through the container network interface, realizing the dynamic update of the mapping relationship library.

[0085] In the above solution, a flexible establishment of the mapping relationship between the target task and its target container group and a dynamic update of the mapping relationship library based on the mapping relationship are achieved, and a flexible adjustment of network isolation is realized.

[0086] Next, a specific example is used to further illustrate the network access method in the embodiments of the present disclosure. Figure 6 The architecture diagram of the control plane platform provided by some embodiments of the present disclosure Figure 6 The hardware therein includes a central processing unit, a network interface card (NIC), and an accelerator (Accelerated Devices). Among them, the network interface card may include a data processing unit (DPU). The accelerator may include one of a graphics processing unit (GPU), a tensor processing unit (Tensor Processing Unit, TPU), a field programmable gate array (FPGA), and an application specific integrated circuit (ASIC). Figure 6 The storage service therein may be a cloud storage service implemented based on a cloud server. In this embodiment, no limitation is imposed on the specific hardware device for implementing the storage service. The storage service may include one or more databases. As Figure 6 shown, in this embodiment, the model of the control plane platform can undertake large models from various model providers as model as a service, and then use these large models to provide services such as inference services and fine-tuning services externally. Essentially, model as a service is platform as a service (PaaS).

[0087] On the data plane, it depends on infrastructure as a service (IaaS). On the data plane, there may be a corresponding software stack, which can be deployed as a service container group on the managed cloud server (Elastic Compute Service, ECS) nodes. In response to the scheduling of the user, it will be scheduled accordingly according to the scheduler. Figure 6 There are multiple user container groups (User Pod) and service container groups (Service Pod) in the elastic compute service volume manager (ECS VM).

[0088] Typical model-as-a-service related tasks can be divided into inference tasks and training tasks (e.g., dynamic fine-tuning tasks), etc. And there are three types of roles in this task: cloud service providers, model providers, and users.

[0089] Specifically, cloud service providers provide cloud services (e.g., infrastructure as a service or platform as a service) to serve entities of different model suppliers. Model suppliers own large models and use cloud service providers to build entities such as their own inference tasks and other services. Users are entities that run applications provided by cloud service providers and model suppliers. Users have corresponding network environment isolation requirements for model suppliers and cloud service providers. Specifically, when users obtain model-as-a-service from cloud service providers, users hope that their tasks can run in an isolated network environment such as a secure sandbox.

[0090] A task can be implemented based on one or more container groups. To achieve mandatory isolation, an isolated network environment needs to be provided for the customer's load. For example, for network cards that do not have remote direct memory access capabilities, a Virtual Private Cloud (VPC) network environment can be provided. However, for model-as-a-service, model suppliers directly provide models to cloud service providers, and cloud service providers will build services based on the models. Therefore, it is not convenient and costly to provide a virtual private network for each model. Therefore, many large model applications will be deployed in the same virtual private network. For network cards with remote direct memory access capabilities, access control lists (ACLs) can be used for isolation, and the granularity of this isolation method is relatively large. However, even if the model-as-a-service of the same model is deployed in a virtual private network, there are still network isolation requirements for services owned by different users.

[0091] The network access method provided by the embodiments of the present disclosure can achieve network isolation at the task level with a relatively fine granularity when different types of network cards are configured in a container group. The method specifically includes:

[0092] Step a1: Group the target container group. Specifically, divide the service container groups in the cluster into corresponding groups; divide the container groups corresponding to different tasks into different groups.

[0093] Step a2: When the target container group starts, a pre-set component in the cluster assigns a unique label to the container groups in the same group. The network access device transmits the association relationship between the network card address corresponding to the container group and the task label to different corresponding plugins and maintains the corresponding association relationship in the plugins.

[0094] Step a3: If there is a target access request routed to the container network interface, the container network interface will use the corresponding plugin to process the target access request. The plugin determines whether the target access request meets the corresponding access conditions, and allows the target access requests between container groups in the same group to pass through in the access conditions.

[0095] Step a3: When a container group is destroyed, the corresponding plugin and the corresponding access conditions in each container network interface will be destroyed.

[0096] The network access solution provided by the embodiments of the present disclosure improves the security of network isolation and the security of model providers and model users using model as a service, making model providers and model users more at ease.

[0097] Figure 7 FIG. is a schematic structural diagram of a network access device provided by some embodiments of the present disclosure. The device can be implemented by software and / or hardware and is generally integrated in an electronic device. As Figure 7 shown, the network access device includes:

[0098] A receiving module 701, configured to receive a target access request sent by a first container group through a first network card, where the target access request includes a first network card address of the first network card and a second network card address of a second network card of the accessed second container group;

[0099] A first sending module 702, configured to send the target access request to a target plugin corresponding to the first network card in the container network interface;

[0100] A second sending module 703, configured to, if it is determined by the target plugin based on the first network card address and the second network card address that the first container group and the second container group belong to the same task, send the target access request to a second network card corresponding to the second network card address of the second container group.

[0101] In some embodiments of the present disclosure, the container network interface includes multiple plugins, and each plugin corresponds to a network card type of a container group. The first sending module 702 is configured to:

[0102] Determine the target network card type of the first network card;

[0103] Determine a target plugin corresponding to the target network card type among the multiple plugins included in the container network interface, and send the target access request to the target plugin.

[0104] In some embodiments of the present disclosure, the second network card has the same network card type as the first network card.

[0105] In some embodiments of the present disclosure, the determination by the target plugin that the first container group and the second container group belong to the same task based on the first network card address and the second network card address includes:

[0106] Obtaining, by the target plugin, a mapping relationship library;

[0107] Matching, by the target plugin, the first network card address and the second network card address respectively in the mapping relationship library, and determining a first task label corresponding to the successfully matched first network card address and a second task label corresponding to the second network card address;

[0108] If the first task label and the second task label are the same, it is determined that the first container group and the second container group belong to the same task.

[0109] In some embodiments of the present disclosure, the mapping relationship library includes a plurality of network card addresses and a plurality of task labels with mapping relationships, and each network card address has a mapping relationship with one task label.

[0110] In some embodiments of the present disclosure, the network access device further includes:

[0111] A condition judgment module, configured to, after determining a first task label corresponding to the successfully matched first network card address and a second task label corresponding to the second network card address, if the first task label and / or the second task label is a service label, determine that the first container group and the second container group meet the access conditions.

[0112] In some embodiments of the present disclosure, the network access device further includes:

[0113] An allocation module, configured to, in response to a creation operation of at least one target container group corresponding to a target task, allocate a target task label to the at least one target container group;

[0114] A mapping module, configured to establish a plurality of mapping relationships between a plurality of network card addresses of a plurality of network cards included in each target container group and the target task label respectively;

[0115] A transmission module, configured to transmit the plurality of mapping relationships to a plurality of plugins of the container network interface respectively, and store the plurality of mapping relationships in the mapping relationship library through the container network interface, where each plugin stores at least one mapping relationship of at least one network card corresponding to the network card type.

[0116] In some embodiments of the present disclosure, the allocation of the target task label to the at least one target container group includes: allocating the task identifier of the target task as the target task label to each target container group.

[0117] The network access device provided by the embodiments of the present disclosure can execute the network access method provided by any embodiment of the present disclosure, and has the corresponding functional modules and beneficial effects for executing the method.

[0118] A computer program product includes a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the above-mentioned network access method are implemented.

[0119] Figure 8 It is a schematic structural diagram of an electronic device provided by some embodiments of the present disclosure.

[0120] Specifically refer to the following Figure 8 , which shows a schematic structural diagram of an electronic device 800 suitable for implementing the embodiments of the present disclosure. The electronic device 800 in the embodiments of the present disclosure may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Tablet Computers), PMPs (Portable Multimedia Players), in-vehicle terminals (such as in-vehicle navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 8 The electronic device shown is only an example, and should not bring any limitations to the functions and usage scopes of the embodiments of the present disclosure.

[0121] As Figure 8 shown, the electronic device 800 may include a processing device (such as a central processing unit, a graphics processing unit, etc.) 801, which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM) 802 or the program loaded from the storage device 808 into the random access memory (RAM) 803. In the RAM 803, various programs and data required for the operation of the electronic device 800 are also stored. The processing device 801, the ROM 802, and the RAM 803 are connected to each other through a bus 804. The input / output (I / O) interface 805 is also connected to the bus 804.

[0122] Generally, the following devices may be connected to the I / O interface 805: an input device 806 including, for example, a touch screen, a touchpad, a keyboard, a mouse, a camera, a microphone, an accelerometer, a gyroscope, etc.; an output device 807 including, for example, a liquid crystal display (LCD), a speaker, a vibrator, etc.; a storage device 808 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 809. The communication device 809 can allow the electronic device 800 to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 8 shows the electronic device 800 having various devices, it should be understood that it is not required to implement or include all the shown devices. Instead, more or fewer devices may be implemented or included.

[0123] In particular, according to an embodiment of the present disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, an embodiment of the present disclosure includes a computer program product that includes a computer program carried on a non-transitory computer-readable medium, and the computer program includes program code for performing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network via the communication device 809, or installed from the storage device 808, or installed from the ROM 802. When the computer program is executed by the processing device 801, the above functions defined in the network access method of the embodiment of the present disclosure are performed.

[0124] It should be noted that the computer-readable medium in the present disclosure can be a computer-readable signal medium or a computer-readable storage medium or any combination of the two. The computer-readable storage medium can be, for example, but not limited to, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination of the above. More specific examples of the computer-readable storage medium can include, but are not limited to: an electrical connection with one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the above. In the present disclosure, the computer-readable storage medium can be any tangible medium that contains or stores a program, and the program can be used by or in combination with an instruction execution system, apparatus, or device. In the present disclosure, the computer-readable signal medium can include a data signal propagated in a baseband or as part of a carrier wave, which carries computer-readable program code. Such a propagated data signal can take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination of the above. The computer-readable signal medium can also be any computer-readable medium other than the computer-readable storage medium, and the computer-readable signal medium can send, propagate, or transmit a program for use by or in combination with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted by any suitable medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.

[0125] In some embodiments, the client and the server can communicate using any currently known or future-developed network protocol such as HTTP (HyperText Transfer Protocol), and can be interconnected with digital data communication in any form or medium (e.g., a communication network). Examples of communication networks include local area networks ("LANs"), wide area networks ("WANs"), the Internet (e.g., the Internet), and end-to-end networks (e.g., ad hoc end-to-end networks), as well as any currently known or future-developed networks.

[0126] The above computer-readable medium can be included in the above electronic device; or it can exist separately and not be assembled into the electronic device.

[0127] The above computer-readable medium carries one or more programs. When the above one or more programs are executed by the electronic device, the electronic device is caused to: receive a target access request sent by a first container group through a first network card, where the target access request includes the first network card address of the first network card and the second network card address of a second network card of the second container group being accessed; send the target access request to a target plugin corresponding to the container network interface of the first network card; if it is determined by the target plugin based on the first network card address and the second network card address that the first container group and the second container group belong to the same task, send the target access request to the second network card corresponding to the second network card address of the second container group.

[0128] Computer program code for performing the operations of the present disclosure can be written in one or more programming languages or combinations thereof. The above programming languages include, but are not limited to, object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or it can be connected to an external computer (e.g., by using an Internet service provider to connect through the Internet).

[0129] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that, in some alternative implementations, the functions noted in the blocks may occur in a different order than noted in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or by a combination of dedicated hardware and computer instructions.

[0130] The units involved in the embodiments described in the present disclosure can be implemented in software or in hardware. In some cases, the name of the unit does not constitute a limitation on the unit itself.

[0131] The functions described above herein can be performed, at least in part, by one or more hardware logic components. By way of example and not limitation, the types of hardware logic components that may be used include: field-programmable gate arrays (FPGAs), application-specific integrated circuits (ASICs), application-specific standard products (ASSPs), systems on a chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0132] In the context of the present disclosure, a machine-readable medium may be a tangible medium that can contain or store a program for use by or in connection with an instruction execution system, apparatus, or device. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, electronic, magnetic, optical, electromagnetic, infrared, or semiconductor systems, apparatus, or devices, or any suitable combination of the foregoing. More specific examples of a machine-readable storage medium would include an electrical connection based on one or more wires, a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), an optical fiber, a portable compact disc read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0133] It is understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the information involved in the present disclosure should be informed to users and the authorization of users should be obtained in an appropriate manner in accordance with relevant laws and regulations.

[0134] The above description is only a preferred embodiment of the present disclosure and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of disclosure involved in the present disclosure is not limited to the technical solutions formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the above disclosure concept. For example, the technical solutions formed by mutually replacing the above features with the technical features (but not limited to) having similar functions disclosed in the present disclosure.

[0135] In addition, although the operations are depicted in a specific order, this should not be construed as requiring that the operations be performed in the specific order shown or in sequential order. In certain circumstances, multitasking and parallel processing may be advantageous. Similarly, although a number of specific implementation details are included in the above discussion, these should not be construed as limiting the scope of the present disclosure. Certain features described in the context of separate embodiments may also be implemented in combination in a single embodiment. Conversely, the various features described in the context of a single embodiment may also be implemented separately or in any suitable sub-combination in multiple embodiments.

[0136] Although the subject matter has been described in language specific to structural features and / or methodological logical acts, it should be understood that the subject matter defined in the appended claims is not necessarily limited to the specific features or acts described above. On the contrary, the specific features and acts described above are merely example forms of implementing the claims.

Claims

1. A network access method, characterized in that: include: Receiving a target access request sent by a first container group through a first network card, wherein the target access request includes a first network card address of the first network card and a second network card address of a second network card of a second container group to be accessed; wherein the first container group is configured with network cards of different types; Sending the target access request to a target plug-in corresponding to the first network card in the container network interface; wherein the container network interface includes multiple plug-ins, each of which corresponds to a network card type of the container group; If it is determined by the target plug-in based on the first network card address and the second network card address that the first container group and the second container group belong to the same task, the target access request is sent to the second network card corresponding to the second network card address of the second container group.

2. The method according to claim 1, characterized in that Sending the target access request to a target plug-in corresponding to the first network card in the container network interface includes: Determining a target network card type of the first network card; A target plug-in corresponding to the target network card type is determined from a plurality of plug-ins included in the container network interface, and the target access request is sent to the target plug-in.

3. The method according to claim 2, characterized in that The second network card is of the same type as the first network card.

4. The method according to claim 1, characterized in that: Determining, by the target plug-in based on the first network card address and the second network card address, that the first container group and the second container group belong to the same task includes: Acquire a mapping relationship library through the target plug-in; Matching the first network card address and the second network card address in a mapping relationship library respectively through the target plug-in, and determining a first task label corresponding to the first network card address and a second task label corresponding to the second network card address that are successfully matched; If the first task label and the second task label are the same, it is determined that the first container group and the second container group belong to the same task.

5. The method according to claim 4, characterized in that The mapping relationship library includes a plurality of network card addresses and a plurality of task labels having a mapping relationship, and each of the network card addresses has a mapping relationship with one of the task labels.

6. The method according to claim 4, characterized in that After determining the first task tag corresponding to the first network card address and the second task tag corresponding to the second network card address that are successfully matched, the method further includes: If the first task tag and / or the second task tag is a service tag, it is determined that the first container group and the second container group meet an access condition.

7. The method according to claim 1, characterized in that The method further comprises: In response to a creation operation of at least one target container group corresponding to the target task, assigning a target task label to the at least one target container group; Establishing multiple mapping relationships between multiple network card addresses of multiple network cards included in each target container group and the target task label respectively; The multiple mapping relationships are respectively transmitted to multiple plug-ins of the container network interface, and the multiple mapping relationships are stored in a mapping relationship library through the container network interface, wherein each of the plug-ins stores at least one mapping relationship of at least one network card of the corresponding network card type.

8. The method according to claim 7, characterized in that The assigning of the target task label to the at least one target container group includes: The task identifier of the target task is assigned to each of the target container groups as a target task label.

9. A network access device, characterized in that: include: A receiving module, configured to receive a target access request sent by a first container group through a first network card, wherein the target access request includes a first network card address of the first network card and a second network card address of a second network card of a second container group to be accessed; wherein the first container group is configured with network cards of different types; A first sending module, configured to send the target access request to a target plug-in corresponding to the first network card in the container network interface; wherein the container network interface includes a plurality of plug-ins, each of which corresponds to a network card type of the container group; a second sending module, configured to send the target access request to a second network card corresponding to the second network card address of the second container group if it is determined by the target plug-in based on the first network card address and the second network card address that the first container group and the second container group belong to the same task.

10. An electronic device, characterized in that: The electronic device comprises: processor; a memory for storing instructions executable by the processor; The processor is used to read the executable instructions from the memory and execute the instructions to implement the network access method described in any one of claims 1-8.

11. A computer-readable storage medium, characterized in that: The storage medium stores a computer program, and the computer program is used to execute the network access method described in any one of claims 1 to 8.

Citation Information

Patent Citations

  • Container group creation method and device, electronic equipment and storage medium

    CN115469961A

  • Method and device for processing access request, electronic equipment and program product

    CN118041616A