Method and device for updating routing configuration, electronic device, and storage medium

By updating the routing table on the container orchestration platform, the problem of complex configuration and low flexibility of container private IP exposed to the outside is solved, and simplifying network configuration and improving the maintainability and scalability of the container orchestration platform is achieved.

CN119652811BActive Publication Date: 2025-05-09JINAN INSPUR DATA TECH CO LTD
View PDF 1 Cites 0 Cited by

Patent Information

Application Number
CN202510160099.X
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2025-02-13
Publication Date
2025-05-09
Estimated Expiration
2045-02-13

AI Technical Summary

Technical Problem

In a multi-tenant environment, container private IP exposure has the problems of complex configuration and low flexibility, and the existing technology is difficult to adapt to frequent changes in large-scale clusters.

Method used

When the broadcast tag is added after the initial routing table of the container orchestration platform is completed, the controller collects the IP address information corresponding to the target resource transmitted through the current node, updates the routing table based on this information, generates the target routing table, and distributes it to the network device, and supports the network device to initiate external access to the container orchestration platform through private addresses.

Benefits of technology

It simplifies the network configuration process for the external exposure of container private IP addresses, improves the maintainability and scalability of the container orchestration platform, and solves the problems of complex configuration and low flexibility.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119652811B_ABST
    Figure CN119652811B_ABST
Patent Text Reader

Abstract

The present application discloses a method and device for updating routing configuration, an electronic device, and a storage medium, and relates to the field of computer network communication technology, including: when the initial routing table corresponding to the container orchestration platform completes the addition of broadcast labels, the IP address information corresponding to the target resource transmitted through the current node is collected through the controller; the controller is associated with the current node; the adjustment table item set is determined according to the IP address information and the initial routing table synchronously stored in the controller; based on the adjustment table item set, the initial routing table synchronously stored in the controller is updated to obtain the target routing table, and the target routing table is distributed to the network device associated with the current node. That is, by automatically collecting IP address information and updating routing tables, the network configuration process of exposing the private IP address of the container to the outside is simplified, and the technical problem of complex configuration and low flexibility of the private IP of the container being exposed to the outside is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer network communication technology, and in particular to a method and device for updating routing configuration, an electronic device, and a storage medium. Background Art

[0002] With the widespread application of container technology, container orchestration platforms (such as Kubernetes) have become core components of modern cloud-native applications. Containers make application deployment, expansion, and management more flexible and efficient. However, in a multi-tenant environment, container network management faces many challenges, especially in terms of external exposure of container private IP (Internet Protocol Address, IP for short).

[0003] In traditional network architecture, the private IP address of the container is usually limited to the internal network, and external access requires solutions such as NodePort, LoadBalancer, Ingress, and Service Mesh. Although these methods are effective, they are complex to configure and lack flexibility, and cannot meet dynamically changing needs. In traditional methods, the exposure of private IPs often relies on manually configured static routes, which are difficult to adapt to frequent changes in large-scale clusters. NodePort, LoadBalancer, and Ingress each have their own shortcomings, cannot meet complex routing and policy requirements, and are costly. Although ServiceMesh provides rich routing and policy control, it introduces additional complexity and resource overhead, making management and debugging difficult.

[0004] Regarding the related technologies, the exposure of container private IP has the problems of complex configuration and low flexibility, and no effective solution has been proposed yet. Summary of the invention

[0005] The embodiments of the present application provide a method and device for updating routing configuration, an electronic device, and a storage medium, so as to at least solve the problem of complex configuration and low flexibility in external exposure of private IP addresses of containers in related technologies.

[0006] The present application provides a method for updating routing configuration, comprising: when the initial routing table corresponding to the container orchestration platform completes the addition of a broadcast label, collecting IP address information corresponding to a target resource transmitted through a current node through a controller; wherein the controller is associated with the current node, the broadcast label includes at least one of the following: a first label corresponding to a cluster broadcast mode, a second label corresponding to a local broadcast mode, the initial routing table includes multiple routing table items, and each routing table item includes at least: subnet configuration data, service configuration data, and container configuration data; determining an adjustment table item set according to the IP address information and the initial routing table synchronously stored in the controller; updating the initial routing table synchronously stored in the controller based on the adjustment table item set to obtain a target routing table, and distributing the target routing table to a network device associated with the current node; wherein the target routing table is used to support the network device to initiate external access to the container orchestration platform through a private address.

[0007] The present application also provides a routing configuration update device, including: a collection module, which is used to collect IP address information corresponding to the target resource transmitted through the current node through a controller when the initial routing table corresponding to the container orchestration platform completes the addition of a broadcast label; wherein the controller is associated with the current node, and the broadcast label includes at least one of the following: a first label corresponding to a cluster broadcast mode, a second label corresponding to a local broadcast mode, and the initial routing table includes multiple routing table items, each routing table item includes at least: subnet configuration data, service configuration data, and container configuration data; a determination module, which is used to determine an adjustment table item set based on the IP address information and the initial routing table synchronously stored in the controller; an update module, which is used to update the initial routing table synchronously stored in the controller based on the adjustment table item set, obtain a target routing table, and distribute the target routing table to the network device associated with the current node; wherein the target routing table is used to support network devices to initiate external access to the container orchestration platform through private addresses.

[0008] The present application also provides an electronic device, comprising: a memory for storing a computer program; and a processor for implementing the steps of any of the above-mentioned methods for updating routing configurations when executing the computer program.

[0009] The present application also provides a computer-readable storage medium, in which a computer program is stored, wherein when the computer program is executed by a processor, the steps of any of the above-mentioned methods for updating routing configurations are implemented.

[0010] The present application also provides a computer program product, including a computer program, which implements the steps of any of the above-mentioned routing configuration updating methods when the computer program is executed by a processor.

[0011] Through this application, when the initial routing table corresponding to the container orchestration platform completes the addition of broadcast labels, the IP address information corresponding to the target resource transmitted through the current node is collected through the controller; wherein the controller is associated with the current node, the broadcast label includes at least one of the following: the first label corresponding to the cluster broadcast mode, the second label corresponding to the local broadcast mode, the initial routing table includes multiple routing table items, each routing table item includes at least: subnet configuration data, service configuration data, container configuration data; according to the IP address information and the initial routing table synchronously stored in the controller, the adjustment table item set is determined; based on the adjustment table item set, the initial routing table synchronously stored in the controller is updated to obtain the target routing table, and the target routing table is distributed to the network device associated with the current node; wherein the target routing table is used to support the network device to initiate external access to the container orchestration platform through a private address. That is, by automatically collecting IP address information and updating routing tables, the network configuration process of exposing the private IP address of the container to the outside is simplified, and the technical problems of complex configuration and low flexibility of the private IP of the container to the outside are solved, and the IP address information is collected through the controller, and the target routing table is updated to support the external access of the network device to the container orchestration platform. This enables external exposure of the container's private IP, simplifies network configuration, and improves the maintainability and scalability of the current container orchestration platform. BRIEF DESCRIPTION OF THE DRAWINGS

[0012] In order to more clearly illustrate the embodiments of the present application, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative work.

[0013] Figure 1 A hardware structure block diagram of a computer terminal for a method for updating routing configuration provided in an embodiment of the present application;

[0014] Figure 2 A flowchart of a method for updating a routing configuration according to an embodiment of the present application;

[0015] Figure 3 It is a structural diagram of a system for exposing private IP of a container to the outside based on a label mechanism and dynamic routing configuration according to an embodiment of the application;

[0016] Figure 4 is a schematic diagram of the structure of a container network management system according to an embodiment of the present application;

[0017] Figure 5 A schematic diagram of a process for performing routing configuration on a container network management system according to an embodiment of the present application;

[0018] Figure 6 This is a flow chart of a method for exposing a container private IP to the outside based on a label mechanism and dynamic routing configuration according to an embodiment of the present application;

[0019] Figure 7 A flow chart of a method for dynamic routing configuration according to an embodiment of the present application;

[0020] Figure 8 The present invention is a structural block diagram of a routing configuration updating device according to an embodiment of the present application. DETAILED DESCRIPTION

[0021] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0022] It should be noted that, in the description of this application, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in this application are used to distinguish similar objects, and are not used to describe a specific order or sequence.

[0023] In order to enable those skilled in the art to better understand the present application, Figure 1 The present application is further described in detail with specific implementation methods.

[0024] In conjunction with the specific application environment architecture or the specific hardware architecture on which the execution of the routing configuration update method depends, the specific application environment architecture or the specific hardware architecture is described herein.

[0025] The method embodiments provided in the embodiments of the present application can be executed in a computer terminal or a similar computing device. Taking running on a computer terminal as an example, Figure 1 FIG. 1 is a hardware structure block diagram of a computer terminal according to a method for updating a routing configuration according to an embodiment of the present application. Figure 1 As shown, the computer terminal may include one or more ( Figure 1Only one is shown in the figure) a processor 102 (the processor 102 may include but is not limited to a processing device such as a microprocessor MCU or a programmable logic device FPGA) and a memory 104 for storing data, wherein the above-mentioned computer terminal may also include a transmission device 106 and an input and output device 108 for communication functions. It can be understood by those skilled in the art that Figure 1 The structure shown is only for illustration and does not limit the structure of the above-mentioned computer terminal. Figure 1 More or fewer components as shown, or with Figure 1 Different configurations are shown.

[0026] The memory 104 can be used to store computer programs, for example, software programs and modules of application software, such as the computer program corresponding to the upgrade method of the card in the visible area in the embodiment of the present application. The processor 102 executes various functional applications and data processing by running the computer program stored in the memory 104, that is, the update method of the above-mentioned routing configuration is realized. The memory 104 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include a memory remotely arranged relative to the processor 102, and these remote memories can be connected to the card in the visible area via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and a combination thereof.

[0027] The transmission device 106 is used to receive or send data via a network. The specific example of the above network may include a wireless network provided by a communication provider of a computer terminal. In one example, the transmission device 106 includes a network adapter (Network Interface Controller, referred to as NIC), which can be connected to other network devices through a base station so as to communicate with the Internet. In one example, the transmission device 106 can be a radio frequency (RF) module, which is used to communicate with the Internet wirelessly.

[0028] An embodiment of the present application provides a method for updating routing configuration, which is applied to the above-mentioned computer terminal. Figure 2 A flowchart of a method for updating a routing configuration according to an embodiment of the present application is shown in FIG. Figure 2 As shown, the process includes the following steps:

[0029] Step S202, when the initial routing table corresponding to the container orchestration platform completes the addition of the broadcast label, collect the IP address information corresponding to the target resource transmitted through the current node through the controller; wherein the controller is associated with the current node, the broadcast label includes at least one of the following: a first label corresponding to the cluster broadcast mode, a second label corresponding to the local broadcast mode, and the initial routing table includes multiple routing table items, each of which includes at least: subnet configuration data, service configuration data, and container configuration data;

[0030] Step S204, determining an adjustment table entry set according to the IP address information and the initial routing table synchronously stored in the controller;

[0031] Step S206, based on the adjustment table entry set, the initial routing table synchronously stored in the controller is updated to obtain a target routing table, and the target routing table is distributed to the network device associated with the current node; wherein the target routing table is used to support the network device to initiate external access to the container orchestration platform through a private address.

[0032] Through the above steps, when the initial routing table corresponding to the container orchestration platform completes the addition of broadcast labels, the IP address information corresponding to the target resource transmitted through the current node is collected through the controller; wherein the controller is associated with the current node, the broadcast label includes at least one of the following: the first label corresponding to the cluster broadcast mode, the second label corresponding to the local broadcast mode, the initial routing table includes multiple routing table items, each routing table item includes at least: subnet configuration data, service configuration data, container configuration data; determine the adjustment table item set according to the IP address information and the initial routing table synchronously stored in the controller; based on the adjustment table item set, the initial routing table synchronously stored in the controller is updated to obtain the target routing table, and the target routing table is distributed to the network device associated with the current node; wherein the target routing table is used to support the network device to initiate external access to the container orchestration platform through a private address. The above technical solution is adopted to solve the problem of complex configuration and low flexibility in the external exposure of the container private IP. Furthermore, the IP address information is collected by the controller, and the target routing table is updated to support the external access of the network device to the container orchestration platform. Thereby realizing the external exposure of the container private IP, simplifying the network configuration, and improving the maintainability and scalability of the current container orchestration platform.

[0033] In an exemplary embodiment, the initial routing table synchronously stored in the controller is updated based on the adjustment table item set, including: when the adjustment table item set are all newly added table items, the adjustment table item set is added before the associated existing routing table items in the initial routing table, and new routing rules of the adjustment table item set are configured; when the adjustment table item set is a table item to be deleted, the target table item in the initial routing table that matches the adjustment table item set is removed, and the old routing rules corresponding to the target table item are deleted.

[0034] It should be noted that the above “adding the set of adjustment entries before the associated existing routing entries in the initial routing table” means that when updating the routing table, the newly added routing information (routing rules corresponding to the new IP address or new service) is inserted before the existing routing entries associated therewith, that is, the newly added or updated entries are placed before the entries associated therewith, for example, before the existing routing rules that belong to the same subnet or service as the newly added IP address. This improves the search speed of the updated routing table. It is understandable that when the router searches for routes, it usually searches in the order of the routing table. If the newly added entries can be accessed more frequently, placing them in the front can reduce the search time and improve the efficiency of routing decisions. In addition, in some cases, the newly added routing rules may have a higher priority and need to be processed first. Therefore, placing them before the existing related entries can ensure that the traffic is forwarded according to the latest and more specific rules.

[0035] Optionally, in the above embodiment, if the initial routing table includes the following items:

[0036] The first table entry (destination address: 192.168.1.0, next hop address: 10.0.0.1, interface: eth0); the second table entry (destination address: 192.168.2.0, next hop address: 10.0.0.2, interface: eth1); at this time, adjust the table entry set to the newly added table entry, as follows: newly added table entry (destination address: 192.168.3.0, next hop address: 10.0.0.3, interface: eth2);

[0037] Add the above adjustment entry set to the initial routing table before the existing routing entry, and configure new routing rules for the new entry. The updated routing table is as follows: New entry (destination address: 192.168.3.0, next hop address: 10.0.0.3, interface: eth2); first entry (destination address: 192.168.1.0, next hop address: 10.0.0.1, interface: eth0); second entry (destination address: 192.168.2.0, next hop address: 10.0.0.2, interface: eth1);

[0038] If the adjustment entry set is an entry to be deleted, such as the need to delete the second entry from the initial routing table, remove the target entry that matches the adjustment entry set in the initial routing table, and delete the old routing rule corresponding to the target entry. The updated routing table is as follows: The first entry (destination address: 192.168.1.0, next hop address: 10.0.0.1, interface.

[0039] In the above embodiment, by adding new routing table entries, changes in network topology or traffic patterns can be better adapted, thereby improving the adaptability and scalability of the network. Deleting routing table entries and rules that are no longer needed can reduce the size and complexity of the routing table and improve the management efficiency and performance of the routing table.

[0040] In an exemplary embodiment, after the initial routing table synchronously stored in the controller is updated based on the adjustment table entry set to obtain the target routing table, and the target routing table is distributed to the network device associated with the current node, the above method also includes: collecting resource flow information of the network device; determining the target direction of the external traffic change of the container orchestration platform according to the resource flow information; when the target direction is the same as the communication direction corresponding to the target routing table, determining that external calls to the container orchestration platform are allowed through a private address.

[0041] Optionally, a container orchestration platform needs to collect resource flow information of network devices, determine the target direction of external traffic changes of the container orchestration platform, and limit external calls to the container orchestration platform. First, collect resource flow information of network devices through network monitoring tools, including data exchange between devices, traffic size and other information. According to the resource flow information, analyze the target direction of external traffic changes of the container orchestration platform, and determine the network resources and routing settings that need to be adjusted. When the target direction is the same as the communication direction corresponding to the target routing table, determine that external calls to the container orchestration platform are allowed through private addresses. In addition, security devices such as network devices and firewalls can be configured to limit external calls to the container orchestration platform to only qualified private addresses. Regularly monitor and audit network traffic to ensure network security and system stability. Through the above steps, the external traffic of the container orchestration platform can be effectively managed, network security and performance stability can be improved, and the normal operation of the system can be ensured.

[0042] Optionally, Kubernetes or K8s is a container orchestration platform, where K8s is the abbreviation of Kubernetes, which is an abbreviation formed by replacing the eight characters between the first letter "K" and the last letter "s" with 8. It is an open source containerized orchestration tool for managing containerized applications on multiple hosts in a cloud platform, and has the advantages of high availability and elastic scalability.

[0043] In the above embodiments, by collecting resource flow information of network devices, the communication between network devices can be fully understood, including information such as data flow direction and traffic size, which is helpful for analyzing network load and performance bottlenecks. By determining the target direction of external traffic changes of the container orchestration platform based on resource flow information, the adjustment and optimization of network resources can be better planned, and the overall performance and stability of the system can be improved. By determining that external calls to the container orchestration platform are allowed through private addresses, network security can be improved, unauthorized external access can be avoided, and the security of system data and privacy information can be protected.

[0044] In an exemplary embodiment, when the initial routing table corresponding to the container orchestration platform completes the addition of broadcast labels, the IP address information corresponding to the target resource transmitted through the current node is collected through the controller, including: when the controller is at the startup moment, the routing configuration table of the controller is initialized, and the configuration change data of the target resource carrying the broadcast label is listened to, wherein the configuration change data includes at least one of the following: real-time subnet configuration data, real-time service configuration data, real-time container configuration data; determining multiple similarities between the configuration change data and different routing table items in the routing configuration table; determining whether new IP address information appears based on multiple similarities, and determining the IP address information corresponding to the target resource.

[0045] In the above embodiment, by monitoring the configuration change data of the target resource carrying the broadcast tag, the latest IP address information of the target resource can be obtained in time to ensure the accuracy and practicality of the routing table. By collecting the IP address information corresponding to the target resource through the controller, the cumbersome process of manually updating the routing table can be avoided, and the management efficiency can be improved. The controller can automatically process the similarity between the configuration change data and the different routing table items in the routing configuration table, and determine whether new IP address information appears based on the similarity, thereby realizing an automated IP address information update process. By comparing multiple similarities, the IP address information corresponding to the target resource can be determined more accurately to avoid incorrect routing configuration.

[0046] In an exemplary embodiment, determining whether new IP address information appears is based on multiple similarities, including: when at least one target similarity among multiple similarities is less than a preset threshold, determining that new IP address information that has not been added to the initial routing table exists in the target resource; when multiple similarities are all greater than or equal to the preset threshold, determining that new IP address information that has not been added to the initial routing table does not exist in the target resource.

[0047] Optionally, multiple similarities are used to determine whether new IP address information needs to be added to the initial routing table. The system compares the IP address information of the target resource with the information in the initial routing table, calculates the similarity, and sets the preset threshold to 0.8. Specifically, there are two situations:

[0048] Case 1: Similarity 1 is 0.75, and similarity 2 is 0.82. At least one similarity is less than the preset threshold of 0.8, and the system determines that there is new IP address information in the target resource and needs to be added to the initial routing table.

[0049] Case 2: Similarity 1 is 0.85, and similarity 2 is 0.88. All similarities are greater than or equal to the preset threshold of 0.8. The system determines that there is no new IP address information in the target resource and does not need to be added to the initial routing table.

[0050] In the above embodiment, by using multiple similarities to determine whether new IP address information appears, accuracy can be improved. Through the comprehensive judgment of multiple similarities, various situations can be considered more comprehensively, thereby reducing the possibility of misjudgment. When multiple similarities are greater than or equal to the preset threshold, it can be more certain that there is no new IP address information in the target resource, avoiding false alarms; and when at least one similarity is less than the preset threshold, it can be determined that there is new IP address information in the target resource, avoiding missed reports.

[0051] In an exemplary embodiment, determining a set of adjustment table items based on the IP address information and an initial routing table synchronously stored in the controller includes: parsing the IP address information to obtain a network segment used by the current container orchestration platform and a list of IP addresses corresponding to different containers in the current container orchestration platform; determining a target IP address to be added and deleted based on the network segment and the IP address list; and determining a set of adjustment table items based on the target IP address and the initial routing table.

[0052] Optionally, in the above embodiment, if the network segment used by the current container orchestration platform is 192.168.1.0 / 24, there are three containers corresponding to the IP address lists of 192.168.1.1, 192.168.1.2, and 192.168.1.3 respectively. The initial routing table contains the following entries:

[0053] Destination address: 192.168.1.1, next hop: 10.0.0.1;

[0054] Destination address: 192.168.1.2, next hop: 10.0.0.2;

[0055] Based on the above information, it can be determined that the set of entries that need to be adjusted is the newly added target IP address 192.168.1.3 and the deleted target IP address 192.168.1.1. The final adjusted routing table is as follows:

[0056] Destination address: 192.168.1.2, next hop: 10.0.0.2;

[0057] Destination address: 192.168.1.3, next hop: 10.0.0.3.

[0058] In the above embodiment, by parsing the IP address information and the corresponding network segment and IP address list, the target IP address to be added and deleted can be accurately determined, unnecessary adjustment operations are avoided, and the accuracy of the adjustment table item set is improved. By comparing with the initial routing table synchronously stored in the controller, the accuracy and consistency of the adjustment table item set can be ensured, erroneous operations caused by inconsistent data are avoided, and the reliability of the adjustment is improved.

[0059] In an exemplary embodiment, after the initial routing table synchronously stored in the controller is updated based on the adjustment table entry set to obtain the target routing table, and the target routing table is distributed to the network device associated with the current node, the above method also includes: obtaining the basic IP address information of the container corresponding to the network device; when the broadcast label corresponding to the target routing table is the first label, merging the basic IP address information with the target IP address information corresponding to multiple items in the target routing table to obtain a first merged result; and updating the routing address of the network device according to the first merged result.

[0060] In the above embodiment, by updating the adjustment entry set, the accuracy and completeness of the target routing table can be ensured to avoid errors or omissions. By merging the basic IP address information with the target IP address information in the target routing table, the steps of updating the routing address can be reduced and the updating efficiency can be improved.

[0061] In an exemplary embodiment, updating the router address of a network device according to a first merging result includes: when the first merging result indicates that the basic IP address information and the target IP address information cannot be merged, using the basic IP address information to update the router address of the network device; when the first merging result indicates that the merging of the basic IP address information and the target IP address information is complete, setting the basic IP address information in front of the subnet configuration data and / or service configuration data in the router address of the network device, and setting the next hop of the router address to the host router address.

[0062] Optionally, assume that the basic IP address information is 192.168.1.1, the target IP address information is 10.0.0.1, and the host router address is 192.168.1.2. When the first merge result indicates that the basic IP address information and the target IP address information cannot be merged: use the basic IP address information 192.168.1.1 to update the router address to ensure that the router can continue to work normally even if the information cannot be merged. When the first merge result indicates that the merge of the basic IP address information and the target IP address information is completed: set the basic IP address information 192.168.1.1 in front of the subnet configuration data and service configuration data in the router address, and set the next hop of the router address to the host router address 192.168.1.2. This can achieve more efficient data transmission and improve the performance and stability of network equipment.

[0063] Optionally, each route entry in the routing table specifies a next-hop address. The next-hop address in the above embodiment refers to the IP address of the host where the node controller is located. The node controller (such as kube-controller-manager in Kubernetes) runs on the cluster management plane and is responsible for monitoring changes in various resources in the cluster, including network-related resources such as Service and Pod networks (subnet).

[0064] In the above embodiment, by directly using the basic IP address information to update the router address, the complexity of the merging process can be reduced, thereby improving operational efficiency. Errors or conflicts that may occur when merging the basic IP address information and the target IP address information are avoided, and the stability and reliability of the overall system are improved. By setting the basic IP address information in front of the router address, network traffic can be more effectively managed and the data transmission path can be optimized, thereby improving network performance. By setting the next hop of the router address to the host router address, more flexible network management and configuration can be achieved, which facilitates the adjustment of the network structure and traffic routing at any time. By merging the basic IP address information and the target IP address information, network access rights and data transmission security can be better controlled, thereby improving the security level of the network.

[0065] In an exemplary embodiment, when the broadcast tag corresponding to the target routing table is the second tag, it is determined whether the container is scheduled to the current node; and the routing address of the network device is dynamically updated according to the call result of the container.

[0066] In an exemplary embodiment, dynamically updating the routing address of a network device according to a call result of a container includes: when the call result indicates that the container has been scheduled to the current node, merging the basic IP address information and the target IP address information to obtain a second merged result; updating the routing address of the network device according to the second merged result. When the call result indicates that the container has not been scheduled to the current node, instructing the network device to use the most recently used routing address.

[0067] Optionally, in the above embodiment, if the container has been scheduled to the current node, the basic IP address information is 192.168.1.1, and the target IP address information is 10.0.0.1. According to the call result, the basic IP address information and the target IP address information are merged to obtain a second merged result of 192.168.1.1 / 10.0.0.1. Then, the routing address of the network device is updated according to the second merged result, and the target IP address 10.0.0.1 in the routing table is pointed to 192.168.1.1. If the call result indicates that the container is not scheduled to the current node, the network device will use the most recently used routing address for routing forwarding to ensure the stability and continuity of network communication.

[0068] In the above embodiment, by updating the routing address of the network device in real time when the call result indicates that the container has been scheduled to the current node, it can be ensured that the routing address of the network device is always consistent with the location of the container, reducing the workload and error rate of manual updates.

[0069] In an exemplary embodiment, after the initial routing table synchronously stored in the controller is updated based on the adjustment table entry set to obtain the target routing table, and the target routing table is distributed to the network device associated with the current node, the method further includes: recording the access record of the network device accessing the container orchestration platform through the private address; and periodically sending the access record to the management object of the container orchestration platform.

[0070] As an optional implementation, after the initial routing table synchronously stored in the controller is updated based on the adjustment table entry set to obtain the target routing table, and the target routing table is distributed to the network device associated with the current node, the method further includes:

[0071] When the container orchestration platform includes two or more nodes, the load information of all nodes is periodically obtained from the container orchestration platform through the controller;

[0072] Analyze the load information and identify abnormal nodes with network bottlenecks or overload among two or more nodes based on the analysis results;

[0073] Dynamically adjust the broadcast label corresponding to the abnormal node, wherein the dynamic adjustment at least includes: limiting the external broadcast on the current abnormal node and increasing the traffic support of the current abnormal node.

[0074] Optionally, when the container orchestration platform contains two or more nodes, the controller periodically (for example, every 5 minutes, every 10 minutes or a custom frequency) obtains load information of all nodes from the platform, including but not limited to CPU usage, memory usage, network bandwidth utilization, and the number of currently active connections; parses the load information and identifies network bottlenecks or overloaded nodes through data analysis algorithms. These algorithms may include but are not limited to statistical analysis, machine learning models, or custom evaluation functions to determine whether the load of the node exceeds the normal threshold or whether there are signs of network congestion; based on the analysis results, dynamically adjust the broadcast label strategy corresponding to the abnormal node. Specific adjustment strategies include but are not limited to: a) Limit broadcasts: Reduce or suspend external broadcasts on the current abnormal node to prevent more external traffic from pouring into the node, thereby alleviating network bottlenecks or CPU / memory pressure; b) Increase traffic support: In some cases, if the network bottleneck of the abnormal node is due to insufficient resources rather than excessive traffic, the traffic processing capacity of the abnormal node can be increased by increasing resource allocation, optimizing network configuration, or introducing traffic control mechanisms; c) Load balancing: The controller can adjust the broadcast label configuration to distribute external traffic more evenly to nodes with lighter network loads, thereby achieving load balancing of the entire container orchestration platform; d) Priority adjustment: Adjust the priority of the broadcast label to ensure that key services or resources are accessed externally first, so as to maintain the availability of key services even when network resources are tight.

[0075] In summary, a closed-loop network resource management and optimization mechanism is implemented through the controller, which can automatically adjust the broadcast label strategy according to the real-time load situation, avoiding the degradation of system performance due to node overload or network bottleneck, while improving resource utilization and overall system stability. In the scenario of a large-scale, multi-node container orchestration platform, it can effectively cope with various network challenges caused by dynamic changes in nodes.

[0076] Obviously, the embodiments described above are only some embodiments of the present application, not all embodiments. In order to better understand the above method, the above process is described below in conjunction with the embodiments, but it is not intended to limit the technical solutions of the embodiments of the present application, specifically:

[0077] The optional embodiment of the present application provides a method for exposing the private IP of a container based on a label mechanism and dynamic routing configuration. By adding external broadcast labels to the container's subnet, service, and pod, and starting the controller at the required node, the IP address with the broadcast label is dynamically collected and configured. Each started controller parses and collects Pod resource, subnet, and service resource information, dynamically configures the routing table for all IPs of the resource, and directs the traffic of these IP addresses to the correct destination. Figure 3 As shown, Figure 3 It is a structural diagram of a system for exposing private IP of containers to the outside world based on a label mechanism and dynamic routing configuration according to an embodiment of the application.

[0078] Optional, Figure 4 4 is a schematic diagram of the structure of a container network management system according to an embodiment of the present application. The system at least includes: a label configuration module 42, a controller module 44, and a routing configuration module 46.

[0079] Optionally, the label configuration module 42 is used to add broadcast labels to the configurations of Subnet, Service and Pod.

[0080] Optionally, the controller module 44 is used to start and monitor resource configuration changes with broadcast tags on required nodes.

[0081] Optionally, the routing configuration module 46 is used to dynamically calculate and update the routing table according to the collected IP address information and the network load conditions to optimize network traffic and resource utilization.

[0082] As an optional embodiment, Figure 5 The following is a flow chart of routing configuration for a container network management system according to an embodiment of the present application. The container network management system may perform the following steps:

[0083] Step 502: Add cluster mode and local mode configuration.

[0084] Step 504: add an external broadcast tag to the subnet; add an external broadcast tag to the Service; add an external broadcast tag to the Pod, and set the broadcast mode to cluster mode or local mode as required.

[0085] Step 506: All IP addresses of Pods and Services with broadcast labels are transmitted in the network.

[0086] Step 508: Start the controller at the designated node. After the controller monitors the subnet and service with the broadcast tag, it broadcasts the subnet / service / pod to the router and sets the corresponding route on the router.

[0087] Optional, Figure 6 The flowchart of a method for exposing a container private IP to the outside based on a label mechanism and dynamic routing configuration according to an embodiment of the present application is as follows: Figure 6 As shown, the specific steps include:

[0088] Step 1: System initialization and mode configuration. When the system is initialized, select cluster mode or local mode for configuration according to needs.

[0089] Step 2: Add labels. In the configuration of Subnet, Service, and Pod, add external broadcast labels and mode labels to indicate that these resources are allowed to broadcast their IP / network segments externally. The specific configuration information is as follows:

[0090] (1) The code example corresponding to the Pod configuration information is as follows: {apiVersion: v1; kind: Pod; metadata: name: pod1; namespace: wyd-test; labels: broadcast: "true"; mode: "cluster" # or 'mode: local'}.

[0091] (2) The code example corresponding to the Subnet configuration information is as follows: {apiVersion: v1; kind: Subnet; metadata: name: subnet1; labels: broadcast: "true";}.

[0092] (3) The code example corresponding to the Service configuration information is as follows: {apiVersion: v1; kind:Service; metadata: name: service1; labels: broadcast: "true"}.

[0093] Step 3: Start the controller. Start the controller on the required node. After the controller starts, it will listen to and collect the IP addresses of all Pod and Service resources with broadcast labels on the node.

[0094] Optionally, start the controller on the required node. You can start the controller on one node or on multiple nodes separately, and improve the reliability and scalability of the current container orchestration platform through distributed management. At the same time, each controller will listen to and collect Pod resources with the node broadcast label or Pod resources with global broadcast labels, as well as global Subnet and Service resource information.

[0095] Step 4: Dynamic routing configuration. After the node controller listens to the subnet and service with a broadcast label, it broadcasts all the network segments of the subnet / service to the router. The router receives the broadcast message sent by the node controller, parses the network segment information, and sets up a new subnet on the router. The destination address of the subnet is the subnet / service network segment. Each route entry in the routing table specifies the next hop address, which is the IP address of the host where the node controller is located. When the router receives traffic sent to the subnet / service network segment, it forwards the traffic to the specified next hop, so that the IP of the Pod and Service with the broadcast label can be accessed externally. Figure 7 As shown, Figure 7 This is a flow chart of a method for dynamic routing configuration according to an embodiment of the present application; specifically comprising steps 4.1 to 4.4:

[0096] Step 4.1: When the node controller detects a Pod with a broadcast label, it determines whether the broadcast mode is local mode or cluster mode.

[0097] Step 4.2: When the Pod broadcast is in cluster mode, the multiple IPs (IPv4, IPv6) of the current Pod's multiple network cards are differentiated and merged with the router's target IP and subnet and service segments. If the merger is not possible, the Pod IP is broadcast to the router, and a route with the Pod IP and the next hop as the host is set before the subnet and service settings on the router. Otherwise, the merged result is updated on the router.

[0098] Step 4.3: When the Pod broadcast is in local mode, determine whether the Pod is scheduled to the current node. If not, the process ends; if scheduled to the current node, execute step 4.4.

[0099] Optionally, routes to local mode Pod IPs are only advertised from the node where the Pod is located. This means that external traffic goes directly to the node where the Pod is located, with fewer hops than in the cluster strategy.

[0100] Step 4.4: Differentiate and merge the multiple IPs (IPv4, IPv6) of the current Pod's multiple network cards with the existing IPs of the router target and the subnet and service network segments. If the merger is not possible, broadcast the Pod IP to the router, and set a route with the Pod IP and the next hop as the host before the subnet and service settings on the router. Otherwise, update the merged result to the router.

[0101] Step 5: Distribute routing information. The controller distributes the updated routing information to the corresponding network devices (such as routers) to ensure that external traffic can be correctly directed to resources with broadcast labels.

[0102] Step 6: Continuous monitoring. The controller continuously monitors resource configuration changes and dynamically adjusts the routing table to ensure real-time updates.

[0103] Optionally, a dynamic routing configuration method based on a label mechanism is used. Specifically, each started controller parses and collects Pod resource, Subnet and Service resource information, dynamically configures the routing table for all IP addresses of the resource, and directs the traffic of these IP addresses to the correct destination. Specifically, the following steps are included:

[0104] Step 1: Initialization. When the controller starts, it initializes the routing configuration table and starts listening for resource configuration changes with broadcast tags.

[0105] Step 2: Collect IP addresses. When the controller listens to the broadcast labels of new Subnets, Services, and Pods, it collects their IP addresses into temporary storage.

[0106] Step 3: Differential calculation. The controller calculates the newly added and deleted IP addresses based on the current routing table and the collected Subnet, Service network segment, and Pod IP address list.

[0107] Step 4: Update the routing table. For newly added IP addresses, the controller adds them to the front of the Subnet and Service segments of the routing table to improve routing efficiency, and configures the corresponding routing rules. For deleted IP addresses, the controller removes them from the routing table and deletes the corresponding routing rules.

[0108] It should be noted that in the Kubernetes environment, to realize the external exposure of the private IP of the container, it is necessary to clarify which services need to be exposed and determine the IP address allocation strategy for the exposed services; create an independent subnet for the container to isolate the internal network and the external network, and ensure that the IP address range of the subnet does not conflict with the physical network; start one or more controllers on the nodes of the cluster, such as Kube-proxy, which is responsible for maintaining the status of Service resources. Ensure that the controller can access the metadata of the Service and Pod.

[0109] In summary, by utilizing the label mechanism to realize the external broadcast of the container's private IP, the routing can be dynamically managed through simple configuration, which innovatively simplifies network management. In addition, this application supports the deployment of controllers on multiple nodes, and improves the reliability and scalability of the current container orchestration platform through distributed management to avoid single point failures. At the same time, the controller monitors resource configuration changes in real time and dynamically adjusts the routing table, achieving rapid response and flexible adjustment, and enhancing the system's adaptability. In addition, through the optimized routing algorithm, efficient routing configuration and management are achieved, which improves the system's network communication performance and resource utilization. The controller automatically monitors and configures routing, realizing automation and intelligence of network management. In addition, the above method can be seamlessly integrated into the existing Kubernetes cluster without the need for large-scale modifications to the existing architecture.

[0110] Through the description of the above implementation methods, those skilled in the art can clearly understand that the method according to the above embodiment can be implemented by means of software plus a necessary general hardware platform, and of course by hardware, but in many cases the former is a better implementation method.

[0111] The embodiment of the present application also provides a device for updating routing configuration. Figure 8 A structural block diagram of a device for updating routing configuration according to an embodiment of the present application, such as Figure 8 As shown, the device comprises:

[0112] The collection module 72 is used to collect IP address information corresponding to the target resource transmitted through the current node through the controller when the initial routing table corresponding to the container orchestration platform completes the addition of the broadcast label; wherein the controller is associated with the current node, the broadcast label includes at least one of the following: a first label corresponding to the cluster broadcast mode, a second label corresponding to the local broadcast mode, and the initial routing table includes multiple routing table items, each of which includes at least: subnet configuration data, service configuration data, and container configuration data;

[0113] A first determination module 74, configured to determine a set of adjustment table entries according to the IP address information and the initial routing table synchronously stored in the controller;

[0114] The update module 76 is used to update the initial routing table synchronously stored in the controller based on the adjustment table entry set, obtain the target routing table, and distribute the target routing table to the network device associated with the current node; wherein the target routing table is used to support the network device to initiate external access to the container orchestration platform through a private address.

[0115] In an embodiment of the present application, when the initial routing table corresponding to the container orchestration platform completes the addition of broadcast labels, the IP address information corresponding to the target resource transmitted through the current node is collected by the controller; wherein the controller is associated with the current node, the broadcast label includes at least one of the following: a first label corresponding to the cluster broadcast mode, a second label corresponding to the local broadcast mode, and the initial routing table includes multiple routing table items, each of which includes at least: subnet configuration data, service configuration data, and container configuration data; the adjustment table item set is determined according to the IP address information and the initial routing table synchronously stored in the controller; based on the adjustment table item set, the initial routing table synchronously stored in the controller is updated to obtain the target routing table, and the target routing table is distributed to the network device associated with the current node; wherein the target routing table is used to support the network device to initiate external access to the container orchestration platform through a private address. The above technical solution is adopted to solve the problem of complex configuration and low flexibility in the external exposure of the container private IP. Furthermore, the IP address information is collected by the controller, and the target routing table is updated to support the external access of the network device to the container orchestration platform. Thereby realizing the external exposure of the container private IP, simplifying the network configuration, and improving the maintainability and scalability of the current container orchestration platform.

[0116] In an exemplary embodiment, the above-mentioned update module is also used to add the adjustment item set to the initial routing table before the associated existing routing table items when the adjustment item set are all newly added items, and configure new routing rules for the adjustment item set; when the adjustment item set is an item to be deleted, remove the target item in the initial routing table that matches the adjustment item set, and delete the old routing rules corresponding to the target item.

[0117] In an exemplary embodiment, the above-mentioned device also includes: a second determination module, which is used to update the initial routing table synchronously stored in the controller based on the adjustment table entry set to obtain a target routing table, and after distributing the target routing table to the network device associated with the current node, collect resource flow information of the network device; determine the target direction of the external traffic change of the container orchestration platform according to the resource flow information; when the target direction is the same as the communication direction corresponding to the target routing table, determine to allow external calls to the container orchestration platform through a private address.

[0118] In an exemplary embodiment, the above-mentioned collection module is also used to initialize the routing configuration table of the controller when the controller is at the startup moment, and listen to the configuration change data of the target resource carrying the broadcast tag, wherein the configuration change data includes at least one of the following: real-time subnet configuration data, real-time service configuration data, and real-time container configuration data; determine multiple similarities between the configuration change data and different routing table items in the routing configuration table; determine whether new IP address information appears based on multiple similarities, and determine the IP address information corresponding to the target resource.

[0119] In an exemplary embodiment, the above-mentioned collection module is also used to determine that there is new IP address information in the target resource that has not been added to the initial routing table when at least one target similarity among multiple similarities is less than a preset threshold; and to determine that there is no new IP address information in the target resource that has not been added to the initial routing table when multiple similarities are greater than or equal to the preset threshold.

[0120] In an exemplary embodiment, the above-mentioned first determination module is also used to parse the IP address information, obtain the network segment used by the current container orchestration platform and the IP address list corresponding to different containers in the current container orchestration platform; determine the target IP address to be added and deleted based on the network segment and the IP address list; determine the adjustment table entry set through the target IP address and the initial routing table.

[0121] In an exemplary embodiment, the above-mentioned device also includes: an acquisition module, which is used to update the initial routing table synchronously stored in the controller based on the adjustment table entry set to obtain the target routing table, and after distributing the target routing table to the network device associated with the current node, obtain the basic IP address information of the container corresponding to the network device; when the broadcast label corresponding to the target routing table is the first label, merge the basic IP address information with the target IP address information corresponding to multiple items in the target routing table to obtain a first merged result; update the routing address of the network device according to the first merged result.

[0122] In an exemplary embodiment, the above-mentioned acquisition module is also used to use the basic IP address information to update the router address of the network device when the first merging result indicates that the basic IP address information and the target IP address information cannot be merged; when the first merging result indicates that the merging of the basic IP address information and the target IP address information is completed, the basic IP address information is set in front of the subnet configuration data and / or service configuration data in the router address of the network device, and the next hop of the router address is set to the host router address.

[0123] In an exemplary embodiment, the apparatus further includes: a third determination module, configured to determine whether the container is scheduled to the current node when the broadcast tag corresponding to the target routing table is the second tag; and dynamically update the routing address of the network device according to the call result of the container.

[0124] In an exemplary embodiment, the third determination module is further used to merge the basic IP address information and the target IP address information to obtain a second merged result when the call result indicates that the container has been scheduled to the current node; and update the routing address of the network device according to the second merged result. When the call result indicates that the container has not been scheduled to the current node, instruct the network device to use the most recently used routing address.

[0125] In an exemplary embodiment, the above-mentioned device also includes: a recording module, which is used to update the initial routing table synchronously stored in the controller based on the adjustment table entry set to obtain a target routing table, and after distributing the target routing table to the network device associated with the current node, record the access record of the network device accessing the container orchestration platform through the private address; and periodically send the access record to the management object of the container orchestration platform.

[0126] It should be noted that the above modules can be implemented by software or hardware. For the latter, it can be implemented in the following ways, but not limited to this: the above modules are all located in the same processor; or the above modules are located in different processors in any combination. The description of the features in the embodiment corresponding to the updating device of the routing configuration can refer to the relevant description of the embodiment corresponding to the updating method of the routing configuration, which will not be repeated here.

[0127] An embodiment of the present application further provides an electronic device, including a memory and a processor, wherein a computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any of the above-mentioned routing configuration update method embodiments.

[0128] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored, wherein the computer program is configured to execute the steps of any of the above-mentioned routing configuration updating method embodiments when running.

[0129] In an exemplary embodiment, the computer-readable storage medium may include, but is not limited to, various media that can store computer programs, such as a USB flash drive, a read-only memory (ROM), a random access memory (RAM), a mobile hard disk, a magnetic disk or an optical disk.

[0130] An embodiment of the present application further provides a computer program product, which includes a computer program. When the computer program is executed by a processor, the steps in any of the above-mentioned routing configuration update method embodiments are implemented.

[0131] An embodiment of the present application further provides another computer program product, including a non-volatile computer-readable storage medium, wherein the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in any of the above-mentioned routing configuration update method embodiments are implemented.

[0132] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.

[0133] The above is a detailed introduction to the one provided by the present application. Specific examples are used herein to illustrate the principle and implementation method of the present application, and the description of the above embodiments is only used to help understand the method and its core idea of ​​the present application. It should be pointed out that for ordinary technicians in this technical field, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the scope of protection of the claims of the present application.

Claims

1. A method for updating routing configuration, characterized in that: include: When the initial routing table corresponding to the container orchestration platform completes the addition of the broadcast label, the IP address information corresponding to the target resource transmitted through the current node is collected through the controller; wherein the controller is associated with the current node, the broadcast label includes at least one of the following: a first label corresponding to the cluster broadcast mode, a second label corresponding to the local broadcast mode, and the initial routing table includes a plurality of routing table items, each of which includes at least: subnet configuration data, service configuration data, and container configuration data; Determining an adjustment table entry set according to the IP address information and an initial routing table synchronously stored in the controller; Based on the set of adjustment table entries, the initial routing table synchronously stored in the controller is updated to obtain a target routing table, and the target routing table is distributed to the network device associated with the current node; wherein the target routing table is used to support the network device to initiate external access to the container orchestration platform through a private address; Among them, after updating the initial routing table synchronously stored in the controller based on the adjustment table item set to obtain the target routing table, and distributing the target routing table to the network device associated with the current node, the method also includes: collecting resource flow information of the network device; determining the target direction of the external traffic change of the container orchestration platform according to the resource flow information; and determining that external calls to the container orchestration platform are allowed through a private address when the target direction is the same as the communication direction corresponding to the target routing table.

2. The method according to claim 1, characterized in that Updating the initial routing table synchronously stored in the controller based on the adjustment table entry set includes: In the case where the set of adjustment entries are all newly added entries, the set of adjustment entries is added before the associated existing routing entries in the initial routing table, and a new routing rule for the set of adjustment entries is configured; In the case that the set of adjustment entries is a set of entries to be deleted, the target entry in the initial routing table that matches the set of adjustment entries is removed, and the old routing rule corresponding to the target entry is deleted.

3. The method according to claim 1, characterized in that When the initial routing table corresponding to the container orchestration platform completes the addition of broadcast labels, the controller collects the IP address information corresponding to the target resource transmitted through the current node, including: When the controller is at the startup moment, initialize the routing configuration table of the controller, and listen to the configuration change data of the target resource carrying the broadcast tag, wherein the configuration change data includes at least one of the following: real-time subnet configuration data. Real-time service configuration data. Real-time container configuration data; Determining a plurality of similarities between the configuration change data and different routing table entries in the routing configuration table; Determine whether new IP address information appears according to the multiple similarities, and determine the IP address information corresponding to the target resource.

4. The method according to claim 3, characterized in that Determining whether new IP address information appears according to the multiple similarities includes: In the case that at least one target similarity among the multiple similarities is less than a preset threshold, determining that new IP address information that has not been added to the initial routing table exists in the target resource; When the multiple similarities are all greater than or equal to a preset threshold, it is determined that there is no new IP address information in the target resource that has not been added to the initial routing table.

5. The method according to claim 1, characterized in that Determining an adjustment table entry set according to the IP address information and the initial routing table synchronously stored in the controller includes: Parse the IP address information to obtain the network segment used by the current container orchestration platform and a list of IP addresses corresponding to different containers in the current container orchestration platform; Determine the target IP address to be added and deleted based on the network segment and the IP address list; An adjustment table entry set is determined according to the target IP address and the initial routing table.

6. The method according to claim 1, characterized in that After updating the initial routing table synchronously stored in the controller based on the adjustment table entry set to obtain a target routing table, and distributing the target routing table to a network device associated with the current node, the method further includes: Obtain basic IP address information of the container corresponding to the network device; In a case where the broadcast label corresponding to the target routing table is the first label, merging the basic IP address information with the target IP address information corresponding to the multiple entries in the target routing table to obtain a first merging result; The routing address of the network device is updated according to the first merging result.

7. The method according to claim 6, characterized in that Updating the router address of the network device according to the first merging result includes: When the first merging result indicates that the basic IP address information and the target IP address information cannot be merged, updating the router address of the network device using the basic IP address information; When the first merging result indicates that the merging of the basic IP address information and the target IP address information is completed, the basic IP address information is set in front of the subnet configuration data and / or service configuration data in the router address of the network device, and the next hop of the router address is set to the host router address.

8. The method according to claim 6, characterized in that The method further comprises: When the broadcast label corresponding to the target routing table is the second label, determining whether the container is scheduled to the current node; The routing address of the network device is dynamically updated according to the call result of the container.

9. The method according to claim 8, characterized in that Dynamically updating the routing address of the network device according to the call result of the container, including: When the call result indicates that the container has been scheduled to the current node, merging the basic IP address information and the target IP address information to obtain a second merging result; updating the routing address of the network device according to the second merging result; When the calling result indicates that the container is not scheduled to the current node, the network device is instructed to use the routing address that was used most recently.

10. The method according to claim 1, characterized in that After updating the initial routing table synchronously stored in the controller based on the adjustment table entry set to obtain a target routing table, and distributing the target routing table to a network device associated with the current node, the method further includes: Recording the access record of the network device accessing the container orchestration platform through the private address; The access record is periodically sent to a management object of the container orchestration platform.

11. A routing configuration updating device, characterized in that: include: A collection module, used to collect IP address information corresponding to target resources transmitted through the current node through a controller when the initial routing table corresponding to the container orchestration platform completes the addition of broadcast labels; wherein the controller is associated with the current node, and the broadcast label includes at least one of the following: a first label corresponding to a cluster broadcast mode. A second label corresponding to a local broadcast mode, and the initial routing table includes a plurality of routing table items, each of which includes at least: subnet configuration data. Service configuration data. Container configuration data; A first determination module, configured to determine a set of adjustment table entries according to the IP address information and an initial routing table synchronously stored in the controller; An update module, configured to update the initial routing table synchronously stored in the controller based on the set of adjustment table entries, obtain a target routing table, and distribute the target routing table to a network device associated with the current node; wherein the target routing table is used to support the network device to initiate external access to the container orchestration platform through a private address; The device also includes: a second determination module, which is used to update the initial routing table synchronously stored in the controller based on the adjustment table entry set to obtain a target routing table, and after distributing the target routing table to the network device associated with the current node, collect resource flow information of the network device; determine the target direction of the external traffic change of the container orchestration platform according to the resource flow information; when the target direction is the same as the communication direction corresponding to the target routing table, determine to allow external calls to the container orchestration platform through a private address.

12. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the method for updating the routing configuration as claimed in any one of claims 1 to 10 when executing the computer program.

13. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the method for updating the routing configuration according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Electronic device and method for exposure of services in multi-cluster

    CN118827756A