Configuration Method, Device, Equipment, Storage Medium and Product of Firewall Policy
By creating an IP address pool for the container namespace and dynamically adjusting the hardware firewall policy, the problem of low firewall policy management caused by changes in container IP address is solved, and refined management and efficient IP address control are achieved.
Patent Information
- Application Number
- CN202411824214.0
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-11
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2044-12-11
AI Technical Summary
Under the dynamic changes in the IP address of the container, traditional firewall policy management is inefficient and it is difficult to achieve precise access control.
By creating an IP address pool for the target namespace, configuring IP allocation policies and verifying IP address ranges, dynamically adjusting hardware firewall policies to ensure that the IP address of the container instance meets the predefined ranges.
It realizes refined management of container firewall policies, avoids IP conflicts and resource waste, simplifies the definition and maintenance of firewall rules, and improves management efficiency.
Smart Images

Figure CN119628947B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of network security technologies, and in particular, to a method, device, equipment, storage medium, and product for configuring firewall policies. Background Art
[0002] In the bank data center environment, to ensure the security of information systems, an architecture design of network security zoning is usually adopted. Different business systems are deployed in different security zones according to their security levels, and firewalls are used to isolate and control access between security zones.
[0003] Traditionally, business systems in bank data centers are mainly deployed using virtualization technology. Since virtual machines have fixed IP addresses, access control policies can be configured on the firewall based on the IP addresses to achieve precise access control across security zones. However, with the development of cloud-native technologies, more and more bank data centers are turning to containerized deployment methods. During the operation of this method, the lifecycle of containers is usually short, and the creation and destruction processes of containers may be accompanied by changes in IP addresses, which makes it difficult for firewall policies based on static IPs to adapt to the dynamic characteristics of containers, resulting in complex and inefficient firewall policy management.
[0004] Therefore, how to improve the management efficiency of container firewall policies when IP addresses change dynamically is an urgent problem to be solved at present. Summary of the Invention
[0005] The main purpose of this application is to provide a method, device, equipment, storage medium, and product for configuring firewall policies, aiming to solve the technical problem of low management efficiency of container firewall policies when IP addresses change dynamically.
[0006] To achieve the above object, this application proposes a method for configuring firewall policies, and the method includes:
[0007] Create an IP address pool for the target namespace, where the IP address pool is used to define the IP address range of container instances in the target namespace;
[0008] Configure the IP allocation policy of the target namespace by adding annotations, where the adding of annotations is used to bind the IP address pool to the target namespace;
[0009] Apply the IP address pool and the IP allocation policy of the target namespace in the target cluster system, and verify whether the IP addresses of container instances in the target namespace conform to the predefined IP address range;
[0010] If the IP address of the container instance in the target namespace meets the predefined IP address range, configure the hardware firewall policy based on the predefined IP address range;
[0011] If the IP address of the container instance in the target namespace does not meet the predefined IP address range, reconfigure the IP address pool, and return to the step of configuring the IP allocation policy of the target namespace by adding annotations until the IP address of the container instance in the target namespace meets the predefined IP address range.
[0012] In one embodiment, the step of configuring the IP allocation policy of the target namespace by adding annotations includes:
[0013] Add the identification information of the IP address pool to the target namespace in the form of an annotation, and obtain the added annotation information;
[0014] Based on the added annotation information, allocate the IP addresses in the IP address pool to the container instances in the target namespace correspondingly.
[0015] In one embodiment, the step of verifying whether the IP address of the container instance in the target namespace meets the predefined IP address range includes:
[0016] Start at least one container instance in the target namespace and obtain the IP address corresponding to the container instance;
[0017] Compare the IP address corresponding to the container instance with the predefined IP address range to obtain a first comparison result;
[0018] According to the first comparison result, verify whether the IP address of the container instance in the target namespace meets the predefined IP address range.
[0019] In one embodiment, the step of, if the IP address of the container instance in the target namespace meets the predefined IP address range, configuring the hardware firewall policy based on the predefined IP address range includes:
[0020] If the IP address of the container instance in the target namespace meets the predefined IP address range, determine the configuration requirements of the firewall rules based on the predefined IP address range;
[0021] Based on the configuration requirements of the firewall rules, set the firewall rules through the firewall management interface or the target interface;
[0022] Apply the firewall rules to the firewall system and verify whether the firewall rule configuration meets the preset requirements.
[0023] In one embodiment, the step of applying the firewall rule to the firewall system and verifying whether the firewall rule configuration meets the preset requirements includes:
[0024] Initiate a network connection request to the target address through the container instance to verify whether the firewall policy configuration meets the preset requirements, and obtain a verification result;
[0025] If the verification result does not meet the preset requirements, return to the step of determining the configuration requirements of the firewall rule based on the predefined IP address range until the verification result meets the preset requirements.
[0026] In one embodiment, the step of re-creating the IP address pool if the IP address of the container instance in the target namespace meets the predefined IP address range includes:
[0027] If the IP address of the container instance in the target namespace does not meet the predefined IP address range, then compare the current input configuration command with the correct configuration command according to the error prompt of the target cluster system to obtain a second comparison result;
[0028] Re-create the IP address pool for the target namespace according to the second comparison result and the correct configuration command.
[0029] In addition, to achieve the above object, the present application also proposes a configuration device for a firewall policy, and the configuration device for the firewall policy includes:
[0030] An address creation module, configured to create an IP address pool for the target namespace, and the IP address pool is used to define the IP address range of the container instance in the target namespace;
[0031] A first configuration module, configured to configure the IP allocation policy of the target namespace by adding an annotation, and the added annotation is used to bind the IP address pool to the target namespace;
[0032] An address verification module, configured to apply the IP address pool and the IP allocation policy of the target namespace in the target cluster system, and verify whether the IP address of the container instance in the target namespace meets the predefined IP address range;
[0033] A second configuration module, configured to configure the hardware firewall policy based on the predefined IP address range if the IP address of the container instance in the target namespace meets the predefined IP address range;
[0034] A reconfiguration module is used to reconfigure the IP address pool if the IP address of the container instance in the target namespace does not conform to the predefined IP address range, and return the step of configuring the IP allocation policy of the target namespace by adding annotations until the IP address of the container instance in the target namespace conforms to the predefined IP address range.
[0035] In addition, to achieve the above object, the present application also provides a device for configuring a firewall policy, the device including: a memory, a processor, and a computer program stored on the memory and executable on the processor, the computer program being configured to implement the steps of the firewall policy configuration method as described above.
[0036] In addition, to achieve the above object, the present application also provides a storage medium, the storage medium being a computer-readable storage medium, and a computer program being stored on the storage medium, the computer program implementing the steps of the firewall policy configuration method as described above when executed by a processor.
[0037] In addition, to achieve the above object, the present application also provides a computer program product, the computer program product including a computer program, the computer program implementing the steps of the firewall policy configuration method as described above when executed by a processor.
[0038] One or more technical solutions proposed by the present application have at least the following technical effects:
[0039] Create an IP address pool for the target namespace, which is used to define the IP address range of container instances in the target namespace; configure the IP allocation policy of the target namespace by adding annotations, and the added annotations are used to bind the IP address pool to the target namespace; apply the IP address pool and the IP allocation policy of the target namespace in the target cluster system, and verify whether the IP addresses of container instances in the target namespace conform to the predefined IP address range. If the IP addresses of container instances in the target namespace conform to the predefined IP address range, configure the hardware firewall policy based on the predefined IP address range; if the IP addresses of container instances in the target namespace do not conform to the predefined IP address range, recreate the IP address pool, and return to the step of configuring the IP allocation policy of the target namespace by adding annotations until the IP addresses of container instances in the target namespace conform to the predefined IP address range. By creating an exclusive IP address pool for the target namespace, it is possible to clearly distinguish the network resources of different namespaces, achieve refined management of IP addresses, and avoid IP conflicts and resource waste. Through the closed-loop configuration and verification steps, when the IP pool configuration fails, it can automatically return for reconfiguration, reducing human intervention. In the hardware firewall policy configuration link, using the precise range of the IP address pool can greatly simplify the definition and maintenance of firewall rules, avoiding the frequent manual creation and update of firewall rules caused by the dynamic IP allocation of container instances, simplifying the management process of firewall policies, and improving the management efficiency of container firewall policies. BRIEF DESCRIPTION OF THE DRAWINGS
[0040] The accompanying drawings herein are incorporated into the specification and form a part of the specification, showing embodiments consistent with the present application, and are used together with the specification to explain the principles of the present application.
[0041] To more clearly illustrate the technical solutions in the embodiments of the present application or the prior art, the following will briefly introduce the accompanying drawings required for use in the description of the embodiments or the prior art. Obviously, for those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0042] Figure 1 It is a schematic diagram of the network security partition architecture of the bank data center of the present application;
[0043] Figure 2 It is a schematic flowchart of the first embodiment of the method for configuring the firewall policy of the present application;
[0044] Figure 3 It is a schematic flowchart of the second embodiment of the method for configuring the firewall policy of the present application;
[0045] Figure 4Schematic flowchart of the third embodiment of the firewall policy configuration method of this application;
[0046] Figure 5 Schematic flowchart of the overall firewall policy configuration process of the embodiments of this application;
[0047] Figure 6 Schematic module structure diagram of the firewall policy configuration device of the embodiments of this application;
[0048] Figure 7 Schematic device structure diagram of the hardware operating environment involved in the firewall policy configuration method in the embodiments of this application.
[0049] The implementation, functional features, and advantages of the purpose of this application will be further described with reference to the embodiments and the accompanying drawings. Detailed implementation manners
[0050] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of this application and are not used to limit this application.
[0051] To better understand the technical solutions of this application, the following will be described in detail in conjunction with the accompanying drawings of the specification and specific implementation manners.
[0052] In the bank data center environment, to ensure the security of the information system, a network security zoning architecture design is usually adopted. Different business systems are deployed in different security zones according to their security levels, and firewalls are used to isolate and control access between security zones. Traditionally, bank data centers mainly use virtualization technology to deploy business systems. Since virtual machines have fixed IP addresses, access control policies can be configured on the firewall based on the IP addresses to achieve precise access control across security zones.
[0053] With the development of cloud-native technology, more and more bank data centers are turning to containerized deployment methods and widely using Kubernetes (K8S) as the container management platform. In the network solution, Calico BGP (Border Gateway Protocol) is used to support communication between different nodes, such as Figure 1As shown in the figure. Since K8S by default uses a random allocation method to assign IP addresses to Pods, and the IP addresses of Pods will change dynamically during operation, this poses challenges to the configuration of firewall policies for cross-partition data streams initiated from containers: operation and maintenance personnel need to continuously identify and update the IP addresses of Pods and manually maintain firewall policies. This method is not only inefficient but also error-prone. In addition, in a hybrid environment where virtualization clusters and container clusters are deployed simultaneously in the same data center, virtual machines can perform effective firewall policy control through fixed IP addresses, while containers, due to the dynamic nature of their IP addresses, are difficult to achieve simple and efficient firewall policy management similar to virtual machines, increasing the operation and maintenance complexity of network security control in the container environment. Therefore, how to improve the management efficiency of container firewall policies in the case of dynamic changes in IP addresses is an urgent problem to be solved currently.
[0054] This application provides a solution. Create an IP address pool for the target namespace, where the IP address pool is used to define the IP address range of container instances in the target namespace; configure the IP allocation policy of the target namespace by adding annotations, and the added annotations are used to bind the IP address pool to the target namespace; apply the IP address pool and the IP allocation policy of the target namespace in the target cluster system, and verify whether the IP addresses of container instances in the target namespace conform to the predefined IP address range. If the IP addresses of container instances in the target namespace conform to the predefined IP address range, configure the hardware firewall policy based on the predefined IP address range; if the IP addresses of container instances in the target namespace do not conform to the predefined IP address range, recreate the IP address pool and return to the step of configuring the IP allocation policy of the target namespace by adding annotations until the IP addresses of container instances in the target namespace conform to the predefined IP address range. By creating a dedicated IP address pool for the target namespace, it is possible to clearly distinguish the network resources of different namespaces, achieve refined management of IP addresses, and avoid IP conflicts and resource waste. Through the closed-loop configuration and verification steps, when the IP pool configuration fails, it can automatically return for reconfiguration, reducing human intervention. In the hardware firewall policy configuration section, using the precise range of the IP address pool can greatly simplify the definition and maintenance of firewall rules, avoiding the frequent manual creation and update of firewall rules caused by the dynamic IP allocation of container instances, simplifying the management process of firewall policies, and improving the management efficiency of container firewall policies.
[0055] Based on this, an embodiment of this application provides a method for configuring a firewall policy, referring to Figure 2 , Figure 2 which is a schematic flowchart of the first embodiment of the method for configuring a firewall policy of this application.
[0056] In this embodiment, the method for configuring the firewall policy includes steps S10 to S50:
[0057] Step S10, create an IP address pool for the target namespace.
[0058] It should be noted that the target namespace can be understood as a logical grouping defined for organizing and isolating resources in a container orchestration system (such as Kubernetes). The IP address pool is used to define the IP address range of container instances in the target namespace. Container instances in the target namespace can be understood as the smallest operation unit (Pod) in Kubernetes and can be the specific objects for IP address allocation and network access. An IPPool (IP pool) resource can be created in the Kubernetes cluster for a specified namespace to define the IP address range of Pods within the namespace. Exemplarily, the following code segment defines a network segment of 192.168.1.0 / 24 for the IPPool configuration for subsequent application to a specific namespace.
[0059] apiVersion:projectcalico.org / v3
[0060] kind:IPPool
[0061] metadata:
[0062] name:example-ip-pool
[0063] spec:
[0064] blockSize:26
[0065] cidr:192.168.1.0 / 24
[0066] ipipMode:Never
[0067] natOutgoing:false
[0068] nodeSelector:all()
[0069] Step S20, configure the IP allocation policy for the target namespace by adding annotations.
[0070] It should be noted that the IP allocation policy is a rule or mechanism for determining how IP addresses are allocated to container instances within the target namespace. Annotations can be understood as adding specific annotation fields to the configuration file of the target namespace. Adding annotations is used to bind the IP address pool to the target namespace, so that container instances within the target namespace can allocate addresses from the specified IP address pool.
[0071] Step S30: Apply the IP address pool and the IP assignment policy of the target namespace in the target cluster system, and verify whether the IP addresses of the container instances in the target namespace conform to the predefined IP address range.
[0072] It should be noted that the target cluster system can be understood as a cluster environment for running containerized applications, such as a Kubernetes cluster or other container orchestration platforms. The predefined IP address range can be understood as a standardized IP address interval set for the target namespace and its container instances. Exemplarily, the IP address pool and the IP assignment policy can be applied in a Kubernetes cluster (execution command example: kubectl apply -f ippool.yaml example - namespace.yaml), and some Pods can be started in the target namespace to verify whether their IP addresses are within the specified network segment (192.168.1.0 / 24).
[0073] Step S40: If the IP addresses of the container instances in the target namespace conform to the predefined IP address range, configure the hardware firewall policy based on the predefined IP address range.
[0074] It should be noted that the allowed or denied network access behaviors can be defined through firewall rules based on the IP address range of the target namespace, and the hardware firewall policy is used to control the communication between the container instances in the target namespace and the external or other networks.
[0075] Step S50: If the IP addresses of the container instances in the target namespace do not conform to the predefined IP address range, recreate the IP address pool, and return to the step of configuring the IP assignment policy of the target namespace by adding annotations until the IP addresses of the container instances in the target namespace conform to the predefined IP address range.
[0076] Exemplarily, in the case of incorrect IP address pool configuration or failed verification, re - define and set a new IP address pool to ensure that its range meets the requirements of the target namespace. At the same time, based on the re - configured IP address pool, re - configure the IP assignment policy of the target namespace by adding annotations.
[0077] In this embodiment, by creating a dedicated IP address pool for the target namespace, network resources of different namespaces can be clearly distinguished, enabling refined management of IP addresses, avoiding IP conflicts and resource waste. Through the closed-loop configuration and verification steps, when the IP pool configuration fails, it can automatically return for reconfiguration, reducing human intervention. In the hardware firewall policy configuration section, using the precise range of the IP address pool can greatly simplify the definition and maintenance of firewall rules, avoiding the frequent manual creation and update of firewall rules caused by the dynamic IP allocation of container instances, simplifying the management process of firewall policies, and improving the management efficiency of container firewall policies.
[0078] Refer to Figure 3 , Figure 3 which is a schematic flowchart of the second embodiment of the configuration method of the firewall policy of this application. Based on the first embodiment shown above Figure 2 a second embodiment of the configuration method of the firewall policy of this application is proposed.
[0079] In the second embodiment, step S20 includes:
[0080] Step S201, add the identification information of the IP address pool to the target namespace in the form of an annotation, and obtain the added annotation information.
[0081] It should be noted that the identification information of the IP address pool can be used to uniquely identify the metadata information of the IP address pool, such as the name of the IP address pool, CIDR range (Classless Inter-Domain Routing), block size, etc. The annotation form can be understood as recording additional metadata in the form of key-value pairs (such as Annotations in Kubernetes) in the configuration file of the target namespace.
[0082] Step S202, based on the added annotation information, allocate the IP addresses in the IP address pool to the container instances in the target namespace correspondingly.
[0083] It should be noted that, based on the annotation information of the target namespace, IP addresses can be dynamically allocated to container instances according to the defined rules from the bound IP address pool. Exemplarily, when allocating an IP for a Pod in a namespace, use the network segment 192.168.1.0 / 24 in the first embodiment. Taking the example-namespace namespace as an example, the configuration for adding an annotation is as follows:
[0084] apiVersion:v1
[0085] kind:Namespace
[0086] metadata:
[0087] name:example - namespace
[0088] annotations:
[0089] "cni.projectcalico.org / ipv4pools":"192.168.1.0 / 24"
[0090] In this embodiment, by adding the identification information of the IP address pool to the target namespace in the form of annotations, the binding information between the IP address pool and the target namespace is recorded, simplifying the configuration management process, facilitating quick location and adjustment of network resources, ensuring that container instances in the target namespace can allocate IP addresses from the specified IP address pool, and improving the management efficiency of IP allocation.
[0091] In one implementation manner, based on the above - mentioned embodiment, the step of verifying whether the IP address of a container instance in the target namespace conforms to a predefined IP address range includes: starting at least one container instance in the target namespace and obtaining the IP address corresponding to the container instance; comparing the IP address corresponding to the container instance with the predefined IP address range to obtain a first comparison result; and verifying whether the IP address of the container instance in the target namespace conforms to the predefined IP address range according to the first comparison result.
[0092] It should be noted that the first comparison result can be understood as the matching situation between the actual IP address of the container instance and the predefined IP address range, which is used to determine whether the configuration is correct. Exemplarily, set a container instance running in example - namespace as frontend - pod - 1. If the IP address of frontend - pod - 1 is 192.168.1.5, which falls within the range of 192.168.1.0 / 24, the first comparison result is conforming; if the IP address is 10.0.0.5, which is not within the range of 192.168.1.0 / 24, the first comparison result is non - conforming.
[0093] In this implementation manner, by verifying whether the IP address of the container instance matches the predefined IP address range, it can be ensured that container instances in the target namespace can allocate IPs from the correct IP address pool, avoiding IP conflicts or misallocations caused by configuration errors. Through the comparison and verification mechanism, IP address allocation problems caused by configuration errors can be discovered and corrected in a timely manner, ensuring that the allocated IP addresses are consistent with the predefined range, providing a reliable basis for configuring hardware firewall policies based on the IP address range in the subsequent stage.
[0094] Refer to Figure 4 ,Figure 4 This is a flowchart of the third embodiment of the configuration method for the firewall policy of this application. Based on the above Figure 3 shown second embodiment, the third embodiment of the configuration method for the firewall policy of this application is proposed.
[0095] In the third embodiment, step S40 includes:
[0096] Step S401, if the IP address of the container instance in the target namespace meets the predefined IP address range, determine the configuration requirements for the firewall rule based on the predefined IP address range.
[0097] It should be noted that the firewall rule is used to define the specific policy for network access control, including allowing or denying access requests for certain IP address ranges. The configuration requirements for the firewall rule can be understood as determining the parameters that need to be configured in the firewall rule based on the IP address range and communication requirements of the target namespace, including at least one of the source address range, target address range, protocol type, port number, and access action. Exemplarily, the firewall rule that allows the 192.168.1.0 / 24 network segment to access port 2881 of the 192.168.2.0 / 24 network segment can be represented as the following code segment.
[0098] yaml
[0099] - name: allow - example - namespace - to - obdb
[0100] type: ipv4
[0101] origin: 192.168.1.0 / 24
[0102] action: permit
[0103] destination: 192.168.2.0 / 24
[0104] protocol: tcp / 2881
[0105] Step S402, based on the configuration requirements of the firewall rule, set the firewall rule through the firewall management interface or the target interface.
[0106] It should be noted that the firewall management interface can be understood as the graphical user interface (GUI) provided by the firewall system for intuitively configuring and managing firewall rules. The target interface can be understood as the API (Application Programming Interface) interface. The API interface is a programming interface provided by the firewall system for automatically configuring firewall rules in a code-based manner. Exemplarily, a firewall rule can be added through a Web interface, setting parameters such as source address, target address, and protocol type, or a rule can be submitted through the API with a source address of 192.168.1.0 / 24 and a target address of 192.168.2.0 / 24. Exemplarily, if the firewall policy is configured through the management interface, the submitted form needs to contain the following field information:
[0107] Name: allow-example-namespace-to-obdb
[0108] Type: IPv4
[0109] Source Address: 192.168.1.0 / 24
[0110] Target Address: 192.168.2.0 / 24
[0111] Protocol / Port Number: tcp / 2881
[0112] Operation: permit
[0113] Step S403, apply the firewall rule to the firewall system and verify whether the firewall rule configuration meets the preset requirements.
[0114] It should be noted that the firewall system can be a hardware or software system for managing and implementing network access control policies, controlling traffic based on the configured firewall rules. Through actual network access tests or simulated traffic, check whether the firewall rules take effect correctly according to the preset requirements.
[0115] In this embodiment, determining the configuration requirements of the firewall rule based on the predefined IP address range can dynamically adjust the firewall rule requirements according to the actual IP address range of the target namespace, enhancing the flexibility and adaptability of the configuration. Providing two methods, the firewall management interface or the API interface, can meet different demand scenarios. Through the verification mechanism, it is ensured that the applied firewall rules are strictly executed according to the configuration requirements, realizing a closed-loop process from IP verification to rule configuration and verification, and being able to dynamically adapt to the network environment changes of the target namespace.
[0116] In one implementation manner, based on the above embodiments and implementation manners, step S403 includes: initiating a network connection request through a container instance to a target address to verify whether the firewall policy configuration meets the preset requirements, and obtaining a verification result; if the verification result does not meet the preset requirements, return to the step of determining the configuration requirements of the firewall rules based on the predefined IP address range until the verification result meets the preset requirements.
[0117] It should be noted that the network connection request is a network communication attempt sent by the container instance, used to test whether it can successfully connect to the target address. The request usually uses a specific protocol (such as TCP) and port. Exemplarily, frontend-pod-1 sends a TCP connection request to the target address 192.168.2.10:2881. If frontend-pod-1 successfully connects to the target address 192.168.2.10:2881, the verification result meets the preset requirements; if the connection request fails, the verification result does not meet the preset requirements. If frontend-pod-1 cannot access the target address 192.168.2.10:2881, return to the requirement of reconfiguring the firewall rules. For example, change the source IP range in the firewall rules from 192.168.1.0 / 24 to 192.168.1.0 / 23, and then re-verify until the test is successful.
[0118] In this implementation manner, through actual network connection tests, it is ensured that the container instances in the target namespace can access the target address stably and normally. By verifying whether the firewall policy configuration meets the preset requirements, network access failures caused by configuration errors are avoided. If the verification result does not meet the preset requirements, the requirement of redefining the firewall rules can be returned and the configuration can be adjusted to form a closed-loop adjustment process. The dynamic adjustment mechanism can support the elastic requirements of the container network, improving the system adaptability and configuration efficiency.
[0119] In one implementation manner, based on the above embodiments and implementation manners, the step of re-creating an IP address pool if the IP address of the container instance in the target namespace meets the predefined IP address range includes: if the IP address of the container instance in the target namespace does not meet the predefined IP address range, compare the current input configuration command with the correct configuration command according to the error prompt of the target cluster system to obtain a second comparison result; re-create the IP address pool for the target namespace according to the second comparison result and the correct configuration command.
[0120] It should be noted that the error prompt of the target cluster system can be understood as the diagnostic information generated by the target cluster system when detecting configuration errors, which is used to prompt the specific problems of the current configuration. The current input configuration command can be the command or parameter input by the user when configuring the IP address pool and the allocation policy. The correct configuration command can be the standardized command generated according to the predefined IP address range and configuration requirements, which is used to repair the incorrect configuration. The second comparison result can be understood as the result of comparing the differences between the current input configuration command and the correct configuration command, which is used to clearly locate the specific content of the configuration error. To make the specification clearer, a flowchart is provided on the basis of this embodiment ( Figure 5 ), which is used to represent the overall configuration process of the firewall policy.
[0121] In this embodiment, through the system error prompt and command comparison, the problems in the IP address pool configuration can be quickly discovered and located, reducing the possibility of human intervention and operation errors. The closed-loop mechanism for re-creating the IP address pool effectively prevents IP address allocation conflicts or network anomalies caused by configuration errors, improving the reliability of network resource management. Through the error prompt, configuration command comparison and the mechanism of automatically re-creating the IP address pool, not only the configuration accuracy and operation efficiency are improved, but also a strong technical guarantee is provided for the security and stability of the dynamic container network.
[0122] It should be noted that the above examples are only used to understand this application and do not constitute a limitation on the configuration method of the firewall policy of this application. Based on this technical concept, more forms of simple transformations are within the protection scope of this application.
[0123] This application also provides a configuration device for the firewall policy. Please refer to Figure 6 , the configuration device for the firewall policy includes:
[0124] An address creation module 10, which is used to create an IP address pool for the target namespace, and the IP address pool is used to define the IP address range of the container instances in the target namespace;
[0125] A first configuration module 20, which is used to configure the IP allocation policy of the target namespace by adding annotations, and the adding of annotations is used to bind the IP address pool to the target namespace;
[0126] An address verification module 30, which is used to apply the IP address pool and the IP allocation policy of the target namespace in the target cluster system, and verify whether the IP addresses of the container instances in the target namespace conform to the predefined IP address range;
[0127] A second configuration module 40, configured to configure a hardware firewall policy based on the predefined IP address range if the IP address of the container instance in the target namespace conforms to the predefined IP address range;
[0128] A reconfiguration module 50, configured to reconfigure the IP address pool if the IP address of the container instance in the target namespace does not conform to the predefined IP address range, and return to the step of configuring the IP assignment policy of the target namespace by adding annotations until the IP address of the container instance in the target namespace conforms to the predefined IP address range.
[0129] The firewall policy configuration device provided in this application adopts the firewall policy configuration method in the above embodiment, and can solve the technical problem of low management efficiency of the container firewall policy when the IP address changes dynamically. Compared with the prior art, the beneficial effects of the firewall policy configuration device provided in this application are the same as those of the firewall policy configuration method provided in the above embodiment, and other technical features in the firewall policy configuration device are the same as the features disclosed in the above embodiment method, and will not be elaborated here.
[0130] This application provides a firewall policy configuration device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the at least one processor can execute the firewall policy configuration method in Embodiment 1 above.
[0131] Next, refer to Figure 7 , which shows a schematic structural diagram of a firewall policy configuration device suitable for implementing the embodiments of this application. The firewall policy configuration device in the embodiments of this application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 7 The firewall policy configuration device shown is only an example and should not impose any limitations on the functions and usage scope of the embodiments of this application.
[0132] As Figure 7As shown, the configuration device of the firewall policy may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which can perform various appropriate actions and processes according to the program stored in the read-only memory (ROM: Read Only Memory) 1002 or the program loaded from the storage device 1003 into the random access memory (RAM: Random Access Memory) 1004. In the RAM 1004, various programs and data required for the operation of the configuration device of the firewall policy are also stored. The processing device 1001, the ROM 1002, and the RAM 1004 are connected to each other through a bus 1005. The input / output (I / O) interface 1006 is also connected to the bus. Generally, the following systems may be connected to the I / O interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 can allow the configuration device of the firewall policy to communicate with other devices wirelessly or wiredly to exchange data. Although Figure 7 a configuration device of the firewall policy with various systems is shown, it should be understood that it is not required to implement or have all the shown systems. Instead, more or fewer systems may be implemented or had.
[0133] Specifically, according to the embodiments disclosed in the present application, the process described above with reference to the flowchart can be implemented as a computer software program. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the method shown in the flowchart. In such an embodiment, the computer program can be downloaded and installed from the network through the communication device, or installed from the storage device 1003, or installed from the ROM 1002. When the computer program is executed by the processing device 1001, the above-mentioned functions defined in the method of the embodiments disclosed in the present application are executed.
[0134] The configuration device of the firewall policy provided by the present application adopts the configuration method of the firewall policy in the above-mentioned embodiment, and can solve the technical problem of low management efficiency of the container firewall policy when the IP address changes dynamically. Compared with the prior art, the beneficial effects of the configuration device of the firewall policy provided by the present application are the same as those of the configuration method of the firewall policy provided by the above-mentioned embodiment, and other technical features in the configuration device of the firewall policy are the same as the features disclosed in the method of the previous embodiment, and will not be elaborated here.
[0135] It should be understood that each part disclosed in this application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples.
[0136] As described above, the above are only specific embodiments of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art within the technical scope disclosed in this application can easily think of changes or substitutions, which should all be covered within the protection scope of this application. Therefore, the protection scope of this application should be subject to the protection scope of the claims.
[0137] This application provides a computer-readable storage medium having computer-readable program instructions (i.e., computer programs) stored thereon, and the computer-readable program instructions are used to execute the firewall policy configuration method in the above embodiments.
[0138] The computer-readable storage medium provided by this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor systems, systems, or devices, or any combination of the above. More specific examples of computer-readable storage media can include, but are not limited to: electrical connections with one or more wires, portable computer disks, hard disks, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM) or flash memory, optical fibers, portable compact disk read-only memory (CD-ROM), optical storage devices, magnetic storage devices, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or combined with an instruction execution system, system, or device. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (radio frequency), etc., or any suitable combination of the above.
[0139] The above computer-readable storage medium can be included in the firewall policy configuration device; it can also exist separately without being assembled into the firewall policy configuration device.
[0140] The above computer-readable storage medium carries one or more programs, which, when executed by a configuration device for firewall policies, cause the configuration device for firewall policies to: create an IP address pool for a target namespace, where the IP address pool is used to define the IP address range of container instances in the target namespace; configure the IP allocation policy of the target namespace by adding an annotation, where the adding of the annotation is used to bind the IP address pool to the target namespace; apply the IP address pool and the IP allocation policy of the target namespace in a target cluster system, and verify whether the IP addresses of container instances in the target namespace conform to a predefined IP address range; if the IP addresses of container instances in the target namespace conform to the predefined IP address range, configure the hardware firewall policy based on the predefined IP address range; if the IP addresses of container instances in the target namespace do not conform to the predefined IP address range, recreate the IP address pool, and return to the step of configuring the IP allocation policy of the target namespace by adding an annotation until the IP addresses of container instances in the target namespace conform to the predefined IP address range.
[0141] Computer program code for performing the operations of this application can be written in one or more programming languages or combinations thereof. The above programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, executed as a stand-alone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In the case of a remote computer, the remote computer can be connected to the user's computer through any type of network, including a local area network (LAN) or a wide area network (WAN), or can be connected to an external computer (for example, by using an Internet service provider to connect through the Internet).
[0142] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the blocks may occur in a different order than that marked in the accompanying drawings. For example, two consecutive blocks shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, as well as combinations of blocks in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.
[0143] The modules described in the embodiments of the present application can be implemented in software or in hardware. Among them, the name of the module does not constitute a limitation to the unit itself in some cases.
[0144] The readable storage medium provided by the present application is a computer-readable storage medium, and the computer-readable storage medium stores computer-readable program instructions (i.e., computer programs) for executing the above-mentioned configuration method of the firewall policy, which can solve the technical problem of low management efficiency of the container firewall policy when the IP address changes dynamically. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided by the present application are the same as those of the configuration method of the firewall policy provided by the above embodiments, and will not be elaborated here.
[0145] The present application also provides a computer program product, including a computer program, and when the computer program is executed by a processor, it implements the steps of the configuration method of the firewall policy as described above.
[0146] The computer program product provided by the present application can solve the technical problem of low management efficiency of the container firewall policy when the IP address changes dynamically. Compared with the prior art, the beneficial effects of the computer program product provided by the present application are the same as those of the configuration method of the firewall policy provided by the above embodiments, and will not be elaborated here.
[0147] The above are only some embodiments of the present application, and do not limit the patent scope of the present application. All equivalent structural transformations made under the technical concept of the present application by using the content of the specification and drawings of the present application, or directly / indirectly applied in other related technical fields, are included in the patent protection scope of the present application.
Claims
1. A method for configuring a firewall policy, characterized in that, The method described above includes: Creating an IP address pool for a user-specified target namespace, where the IP address pool is used to define the IP address range of container instances in the target namespace, and the target namespace is a logical grouping defined in the container orchestration system for organizing and isolating resources; Configuring the IP allocation policy of the target namespace by adding annotations, where the addition of annotations is used to bind the IP address pool to the target namespace; Applying the IP address pool and the IP allocation policy of the target namespace in the target cluster system, and verifying whether the IP addresses of container instances in the target namespace conform to the predefined IP address range; If the IP addresses of container instances in the target namespace conform to the predefined IP address range, configuring the hardware firewall policy based on the predefined IP address range; If the IP addresses of container instances in the target namespace do not conform to the predefined IP address range, recreate the IP address pool, and return to the step of configuring the IP allocation policy of the target namespace by adding annotations until the IP addresses of container instances in the target namespace conform to the predefined IP address range; Among them, the step of configuring the IP allocation policy of the target namespace by adding annotations includes: Adding the identification information of the IP address pool to the target namespace in the form of an annotation, and obtaining the added annotation information. The identification information of the IP address pool is used to uniquely identify the metadata information of the IP address pool, and the annotation form is to record additional metadata in the form of key-value pairs in the configuration file of the target namespace; Based on the added annotation information, allocating the IP addresses in the IP address pool to the container instances in the target namespace.
2. The method according to claim 1, wherein The step of verifying whether the IP addresses of container instances in the target namespace conform to the predefined IP address range includes: Starting at least one container instance in the target namespace and obtaining the IP address corresponding to the container instance; Comparing the IP address corresponding to the container instance with the predefined IP address range to obtain a first comparison result; Based on the first comparison result, verifying whether the IP addresses of container instances in the target namespace conform to the predefined IP address range.
3. The method according to claim 1, characterized in that The step of, if the IP addresses of container instances in the target namespace conform to the predefined IP address range, configuring the hardware firewall policy based on the predefined IP address range includes: If the IP addresses of container instances in the target namespace conform to the predefined IP address range, determining the configuration requirements of the firewall rules based on the predefined IP address range; Based on the configuration requirements of the firewall rules, setting the firewall rules through the firewall management interface or the target interface; Applying the firewall rules to the firewall system and verifying whether the configuration of the firewall rules meets the preset requirements.
4. The method according to claim 3, wherein The step of applying the firewall rules to the firewall system and verifying whether the configuration of the firewall rules meets the preset requirements includes: Initiate a network connection request to the target address through the container instance to verify whether the firewall policy configuration meets the preset requirements, and obtain a verification result; If the verification result does not meet the preset requirements, return to the step of determining the configuration requirements of the firewall rule based on the predefined IP address range until the verification result meets the preset requirements.
5. The method according to claim 4, wherein The step of re-creating the IP address pool if the IP address of the container instance in the target namespace meets the predefined IP address range includes: If the IP address of the container instance in the target namespace does not meet the predefined IP address range, compare the current input configuration command with the correct configuration command according to the error prompt of the target cluster system to obtain a second comparison result; Re-create the IP address pool for the target namespace according to the second comparison result and the correct configuration command.
6. A configuration device for firewall policies, characterized in that, The device includes: An address creation module for creating an IP address pool for a user-specified target namespace, where the IP address pool is used to define the IP address range of container instances in the target namespace, and the target namespace is a logical grouping defined in the container orchestration system for organizing and isolating resources; A first configuration module for configuring the IP allocation policy of the target namespace by adding an annotation, where the added annotation is used to bind the IP address pool to the target namespace; An address verification module for applying the IP address pool and the IP allocation policy of the target namespace in the target cluster system, and verifying whether the IP address of the container instance in the target namespace meets the predefined IP address range; A second configuration module for configuring the hardware firewall policy based on the predefined IP address range if the IP address of the container instance in the target namespace meets the predefined IP address range; A re-configuration module for re-configuring the IP address pool if the IP address of the container instance in the target namespace does not meet the predefined IP address range, and returning to the step of configuring the IP allocation policy of the target namespace by adding an annotation until the IP address of the container instance in the target namespace meets the predefined IP address range; The first configuration module is further configured to add the identification information of the IP address pool to the target namespace in the form of an annotation, obtain the added annotation information, where the identification information of the IP address pool is used to uniquely identify the metadata information of the IP address pool, and the annotation form is to record additional metadata in the form of key-value pairs in the configuration file of the target namespace; based on the added annotation information, allocate the IP addresses in the IP address pool to the container instances in the target namespace.
7. A configuration device for firewall policies, characterized in that, The device includes: a memory, a processor, and a computer program stored on the memory and executable on the processor, and the computer program is configured to implement the steps of the firewall policy configuration method according to any one of claims 1 to 5.
8. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a computer program is stored on the storage medium. When the computer program is executed by a processor, the steps of the firewall policy configuration method according to any one of claims 1 to 5 are implemented.
9. A computer program product, characterized in that, The computer program product includes a computer program. When the computer program is executed by a processor, the steps of the firewall policy configuration method according to any one of claims 1 to 5 are implemented.
Citation Information
Patent Citations
Network dynamic sensing device, system and method
CN114039751A
Network isolation control system and method of container, electronic equipment and storage medium
CN115048188A