Service access method and device and related equipment

By receiving the routing information reported by the node and building service routing information, the network congestion and single-node failure caused by the NodePort method are solved, and efficient publication of ClusterIP services is achieved, reducing costs.

CN119995993AActive Publication Date: 2025-05-13NEW H3C TECH CO LTD
View PDF 6 Cites 0 Cited by

Patent Information

Application Number
CN202510147945.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-02-10
Publication Date
2025-05-13
Estimated Expiration
2045-02-10

AI Technical Summary

Technical Problem

When the prior art uses NodePort type Service to disclose services to the outside world, it is easy to cause network congestion and single-node failure. The LoadBalancer method requires an additional cloud platform load balancer, which increases the cost of use and maintenance.

Method used

By receiving the routing information reported by the node, the routing information of the service is constructed and sent to the authentication device, synchronized to the boundary Border device, and a routing table entry with the destination address as the service address is generated to realize load balancing forwarding of user requests.

Benefits of technology

The ClusterIP type service has been released to the public, avoiding network congestion and single-node failure problems in the NodePort method, and at the same time, no additional cloud platform load balancer is required, reducing costs.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119995993A_ABST
    Figure CN119995993A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of containers, in particular to a service access method and device and related equipment. The method comprises the steps that routing information reported by nodes is received, and when one node monitors that a service of a specified type is created, routing information with a destination address being the address of the service and next hop information being the address of the node is constructed; determining an authentication device accessed by the node based on the address of the node; the routing information is sent to the authentication equipment, and the authentication equipment synchronizes the routing information to the Border equipment in the network, so that the Border equipment generates a routing table item of which the destination address is the address of the service and the next hop information is the authentication equipment based on the routing information; and the Border equipment determines a routing table entry used for forwarding the user request based on the address of the service carried by the received user request, and forwards the user request to the corresponding authentication equipment based on the routing table entry.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of container technology, and in particular to a service access method, device and related equipment. Background Art

[0002] Kubernetes Service is an abstraction that defines access policies for a group of Pods (encapsulation of one or more containers). It provides a stable network identity and routes traffic to these Pods through load balancing. For some Pod applications (such as front-ends), users may want to make them public, that is, access the service from outside the cluster.

[0003] Among them, there are three main types of Service in the Kubernetes cluster:

[0004] ClusterIP type, exposes the Service through the cluster's internal virtual IP. The virtual IP of this type of Service can only be accessed within the cluster. NodePort type, exposes the service on the IP of each node through a static port (NodePort). Kubernetes will also set a cluster virtual IP address for this type of Service for internal / external access to the cluster. LoadBalancer type, uses an external load balancer to expose the service to the outside world. Kubernetes does not directly provide a load balancing component, and a third-party load balancing component must be provided, or the Kubernetes cluster must be integrated with a cloud provider. Kubernetes will also set a cluster virtual IP address for this type of Service for internal access to the cluster.

[0005] Currently, NodePort and Loadbalancer services are usually used to expose services to the outside world. If a NodePort service is used to expose services to the outside world, users can access the static port of a node to send messages to the node, and the node will forward the message to the backend real service for response. If a Loadbalancer service is used to expose services to the outside world, users can access the load balancer outside the Kubernetes cluster, and the load balancer will forward the traffic to the node, and the node will forward the traffic to the backend real service for response.

[0006] However, using the NodePort method will cause external requests to access a certain node, which is not only prone to network congestion, but also exposes the node's real IP. If the node fails, the service will be unreachable and high availability will not be met. Using the LoadBalancer method requires the use of the cloud provider's load balancing component. Its load balancing strategy is determined by the cloud platform, and users need to spend more usage and maintenance costs. Summary of the invention

[0007] The present application provides a service access method, apparatus and related equipment.

[0008] In a first aspect, the present application provides a service access method, which is applied to a controller in a network, and the method includes:

[0009] Receive routing information reported by nodes. When a node detects the creation of a service of a specified type, it constructs routing information corresponding to the service. The destination address of the routing information is the address of the service, and the next hop information is the address of the node.

[0010] Determine, based on the address of the node included in the routing information, the authentication device to which the node is connected;

[0011] The routing information is sent to the authentication device, wherein the authentication device synchronizes the routing information to a border device in the network, so that the Border device generates a routing table entry with the destination address being the address of the service and the next hop information being the authentication device based on the routing information. When the Border device receives a user request for accessing the service, the Border device determines the routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

[0012] Optionally, the service of the specified type is a ClusterIP type service.

[0013] In a second aspect, the present application provides a service access method, which is applied to an authentication device in a network, and the method includes:

[0014] Receiving routing information sent by the controller, wherein, when a node detects the creation of a service of a specified type, constructs routing information in which the destination address corresponding to the service is the address of the service and the next hop information is the address of the node, and determines the authentication device connected to the node based on the address of the node included in the routing information, and sends the routing information to the authentication device;

[0015] The routing information is synchronized to the border device in the network, so that the border device generates a routing table entry with the destination address being the address of the service and the next hop information being the authentication device based on the routing information. When the border device receives a user request to access the service, the border device determines the routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

[0016] Optionally, at least two routing table entries for forwarding the user request are maintained on the Border device. When the Border device receives a user request to access the service, the Border device determines at least two routing table entries for forwarding the user request based on the address of the service carried in the user request, and determines a target routing table entry for forwarding the user request from the at least two routing table entries based on a preset load balancing strategy, and forwards the user request to a corresponding authentication device based on the target routing table entry.

[0017] In a third aspect, the present application provides a service access device, which is applied to a controller in a network, and the device includes:

[0018] A receiving unit, configured to receive routing information reported by a node, wherein when a node detects the creation of a service of a specified type, it constructs routing information corresponding to the service, the destination address of the routing information is the address of the service, and the next hop information is the address of the node;

[0019] A determination unit, configured to determine an authentication device accessed by the node based on an address of the node included in the routing information;

[0020] A sending unit is used to send the routing information to the authentication device, wherein the authentication device synchronizes the routing information to a border device in the network, so that the Border device generates a routing table entry with a destination address being the address of the service and the next hop information being the authentication device based on the routing information. When the Border device receives a user request for accessing the service, the Border device determines a routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

[0021] Optionally, the service of the specified type is a ClusterIP type service.

[0022] In a fourth aspect, the present application provides a service access device, which is applied to an authentication device in a network, and the device includes:

[0023] A receiving unit, configured to receive routing information sent by a controller, wherein when a node detects the creation of a service of a specified type, it constructs routing information in which the destination address corresponding to the service is the address of the service and the next hop information is the address of the node, and determines the authentication device connected to the node based on the address of the node included in the routing information, and sends the routing information to the authentication device;

[0024] A synchronization unit is used to synchronize the routing information to a border device in the network, so that the border device generates a routing table entry whose destination address is the address of the service and the next hop information is the authentication device based on the routing information. When the border device receives a user request for accessing the service, the border device determines the routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

[0025] Optionally, at least two routing table entries for forwarding the user request are maintained on the Border device. When the Border device receives a user request to access the service, the Border device determines at least two routing table entries for forwarding the user request based on the address of the service carried in the user request, and determines a target routing table entry for forwarding the user request from the at least two routing table entries based on a preset load balancing strategy, and forwards the user request to a corresponding authentication device based on the target routing table entry.

[0026] In a fifth aspect, an embodiment of the present application provides a service access device, the service access device comprising:

[0027] A memory for storing program instructions;

[0028] The processor is used to call the program instructions stored in the memory, and execute the steps of the method as described in any one of the first aspects above according to the obtained program instructions.

[0029] In a sixth aspect, an embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of the method described in any one of the above-mentioned first aspects.

[0030] In a seventh aspect, an embodiment of the present application provides a service access device, the service access device comprising:

[0031] A memory for storing program instructions;

[0032] The processor is used to call the program instructions stored in the memory and execute the steps of the method as described in any one of the second aspects according to the obtained program instructions.

[0033] In an eighth aspect, an embodiment of the present application further provides a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of the method described in any one of the second aspects above.

[0034] In summary, the service access method provided in the embodiment of the present application receives routing information reported by a node, wherein, when a node detects the creation of a service of a specified type, it constructs routing information corresponding to the service, the destination address of the routing information is the address of the service, and the next hop information is the address of the node; based on the address of the node included in the routing information, the authentication device connected to the node is determined; the routing information is sent to the authentication device, wherein the authentication device synchronizes the routing information to a border device in the network, so that the Border device generates a routing table entry with the destination address being the address of the service and the next hop information being the authentication device based on the routing information; when the Border device receives a user request to access the service, based on the address of the service carried in the user request, it determines the routing table entry for forwarding the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

[0035] By adopting the service access method provided in the embodiment of the present application, the services deployed by the user in the Kubernetes cluster can be published externally through ClusterIp, and the outside world can access the services in the cluster through the ip, and the leaf devices share the load through equal-cost routing. This avoids the network congestion and single-node failure problems caused by the NodePort method, and at the same time, there is no need to spend extra costs like the Loadbalancer method to match the cloud platform load balancer. BRIEF DESCRIPTION OF THE DRAWINGS

[0036] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments of the present application or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this application. For ordinary technicians in this field, other drawings can also be obtained based on these drawings of the embodiments of the present application.

[0037] Figure 1 A detailed flow chart of a service access method provided in an embodiment of the present application;

[0038] Figure 2 A detailed flow chart of another service access method provided in an embodiment of the present application;

[0039] Figure 3A service IP external publishing architecture diagram provided in an embodiment of the present application;

[0040] Figure 4 A schematic diagram of the structure of a service access device provided in an embodiment of the present application;

[0041] Figure 5 A schematic diagram of the structure of another service access device provided in an embodiment of the present application;

[0042] Figure 6 A schematic diagram of the hardware architecture of a service access device provided in an embodiment of the present application;

[0043] Figure 7 A schematic diagram of the hardware architecture of another service access device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0044] The terms used in the embodiments of the present application are only for the purpose of describing specific embodiments, rather than limiting the present application. The singular forms of "a", "said" and "the" used in the present application and claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used herein refers to any or all possible combinations of one or more associated listed items.

[0045] It should be understood that, although the terms first, second, third, etc. may be used to describe various information in the embodiments of the present application, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of the present application, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, in addition, the word "if" used may be interpreted as "at..." or "when..." or "in response to determination".

[0046] For example, see Figure 1 , which is a detailed flow chart of a service access method provided in an embodiment of the present application, the method is applied to a controller in a network, and the method includes the following steps:

[0047] Step 100: Receive routing information reported by a node, wherein when a node detects the creation of a service of a specified type, it constructs routing information corresponding to the service, the destination address of the routing information is the address of the service, and the next hop information is the address of the node.

[0048] In the embodiment of the present application, when a service of a specified type is created on a node of the cluster, the node detects the creation of the service and builds corresponding routing information based on the IP address of the node and the IP address of the service. It should be noted that the destination address of the routing information is the IP address of the service, and the next hop information is the IP address of the node. After the node builds the routing table entry corresponding to the service, it reports the routing table entry to the controller.

[0049] In the embodiment of the present application, the specified type of service is a ClusterIP type service.

[0050] Specifically, the node can access the API interface of the controller, and send the routing table items to be reported to the controller through the API interface.

[0051] Step 110: Based on the address of the node included in the routing information, determine the authentication device to which the node is connected.

[0052] In actual applications, the controller maintains topology information of each device included in the managed network. Then, after receiving routing information corresponding to a specified type of service reported by a node, the authentication device connected to the node is determined based on the next-hop address information included in the routing information (such as the IP address of the node). The authentication device refers to the device that performs online authentication on the node when the node goes online (such as the Leaf device in the Spine-Leaf network).

[0053] Step 120: Send the routing information to the authentication device.

[0054] In an embodiment of the present application, the authentication device synchronizes the routing information to a border device in the network, so that the Border device generates a routing table entry with the destination address being the address of the service and the next hop information being the authentication device based on the routing information. When the Border device receives a user request to access the service, the Border device determines the routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

[0055] In an embodiment of the present application, after receiving the routing information corresponding to each specified type of service reported by the node, the controller sends the routing information to the authentication device corresponding to the node. After receiving the routing information sent by the controller, the authentication device synchronizes the routing information to the boundary device (such as Border device) in the network. In actual applications, after receiving the routing information synchronized by the authentication device, the Border device generates a routing table entry with the destination address being the IP address of the service and the next hop information being the IP address of the authentication device based on the address (IP address) of the service included in the routing information.

[0056] In this way, when the user accesses the service through the Border or authentication device, when the Border device receives the user's request to access the service, it can determine the routing table entry for forwarding the request based on the destination IP address carried by the request (the IP address of the access service) and route the request to the corresponding authentication device.

[0057] For example, see Figure 2 As shown, it is a detailed flow chart of a service access method provided in an embodiment of the present application. The method is applied to an authentication device in a network. The method includes the following steps:

[0058] Step 200: Receive routing information sent by the controller.

[0059] When a node detects the creation of a service of a specified type, it constructs routing information in which the destination address corresponding to the service is the address of the service and the next hop information is the address of the node. Based on the address of the node included in the routing information, it determines the authentication device to which the node is connected and sends the routing information to the authentication device.

[0060] Step 210: Synchronize the routing information to the border device in the network.

[0061] In an embodiment of the present application, the Border device generates a routing table entry with the destination address being the address of the service and the next hop information being the authentication device based on the routing information. When the Border device receives a user request to access the service, the Border device determines the routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

[0062] In an embodiment of the present application, at least two routing table entries for forwarding the user request are maintained on the Border device. When the Border device receives a user request for accessing the service, the Border device determines at least two routing table entries for forwarding the user request based on the address of the service carried in the user request, and determines a target routing table entry for forwarding the user request from the at least two routing table entries based on a preset load balancing strategy, and forwards the user request to the corresponding authentication device based on the target routing table entry.

[0063] The following describes in detail the process of publishing the service IP provided by the embodiment of the present application in combination with specific application scenarios. Figure 3 As shown, it is an architecture diagram of a service IP external release provided in an embodiment of the present application.

[0064] 1) cni-agent (the agent on the node) constructs the routing table entry of this node according to the forwarding strategy of service (the destination address is ClusterIp (service IP), and the next hop address of this node) and notifies the controller.

[0065] Specifically, add routing table entries to the routing table associated with the Vrouter where the cluster controller is located. The node (cni-agent) is an API interface that can access the DC controller and inform the controller of the routing table entry information to be added (local routing table entries constructed based on forwarding policies, for each service).

[0066] 2) The controller determines the Leaf device (the authentication device online at the node) based on the next-hop node address of the route, and sends a specific Clusterip routing table entry to the Leaf device (the destination address is the service IP, and the next-hop information is the node IP).

[0067] 3) The Leaf device synchronizes the Clusterip routing table entries (destination address (e.g., service IP1), next hop (node ​​IP1))-Leaf1; destination address (service IP1), next hop (node ​​IP2))-Leaf2 to the Border device.

[0068] Generate routing forwarding entries to Leaf1 (there may be multiple entries); destination address (service IP), next hop (LeafIP).

[0069] Thus, after receiving a request to access service 1, the Border device randomly selects one from Leaf 1 or Leaf 2.

[0070] 4) The user accesses clusterip through Border or Leaf. Border and Leaf use equal-cost routing to perform random load and forward the message to the next-hop node (real node). The node forwards the request to the backend real service for response (forwarded to Pod).

[0071] For example, see Figure 4 FIG. 1 is a schematic diagram of a structure of a service access device provided in an embodiment of the present application. The device is applied to a controller in a network. The device includes:

[0072] The receiving unit 40 is used to receive routing information reported by the node, wherein when a node detects the creation of a service of a specified type, it constructs routing information corresponding to the service, the destination address of the routing information is the address of the service, and the next hop information is the address of the node;

[0073] A determination unit 41, configured to determine an authentication device accessed by the node based on an address of the node included in the routing information;

[0074] The sending unit 42 is used to send the routing information to the authentication device, wherein the authentication device synchronizes the routing information to the border device in the network, so that the Border device generates a routing table entry with the destination address being the address of the service and the next hop information being the authentication device based on the routing information. When the Border device receives a user request to access the service, the Border device determines the routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

[0075] Optionally, the service of the specified type is a ClusterIP type service.

[0076] For example, see Figure 5 FIG. 1 is a schematic diagram of a structure of a service access device provided in an embodiment of the present application, wherein the device is applied to an authentication device in a network, and the device includes:

[0077] The receiving unit 50 is used to receive the routing information sent by the controller, wherein when a node detects the creation of a service of a specified type, it constructs routing information in which the destination address corresponding to the service is the address of the service and the next hop information is the address of the node, and determines the authentication device connected to the node based on the address of the node included in the routing information, and sends the routing information to the authentication device;

[0078] The synchronization unit 51 is used to synchronize the routing information to the border device in the network, so that the border device generates a routing table entry with the destination address being the address of the service and the next hop information being the authentication device based on the routing information. When the border device receives a user request to access the service, the border device determines the routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

[0079] Optionally, at least two routing table entries for forwarding the user request are maintained on the Border device. When the Border device receives a user request to access the service, the Border device determines at least two routing table entries for forwarding the user request based on the address of the service carried in the user request, and determines a target routing table entry for forwarding the user request from the at least two routing table entries based on a preset load balancing strategy, and forwards the user request to a corresponding authentication device based on the target routing table entry.

[0080] The above units may be one or more integrated circuits configured to implement the above methods, such as one or more application specific integrated circuits (ASIC), or one or more digital signal processors (DSP), or one or more field programmable gate arrays (FPGA). For another example, when a certain unit is implemented in the form of a processing element scheduling program code, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call program code. For another example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).

[0081] Furthermore, the service access device provided in the embodiment of the present application, from the hardware level, the hardware architecture diagram of the service access device can be seen in Figure 6 As shown, the service access device may include: a memory 60 and a processor 61,

[0082] The memory 60 is used to store program instructions; the processor 61 calls the program instructions stored in the memory 60 and executes the above method embodiment applied to the controller according to the obtained program instructions. The specific implementation method and technical effect are similar and will not be repeated here.

[0083] Optionally, the present application also provides a controller, comprising at least one processing element (or chip) for executing the above method embodiment applied to the controller.

[0084] Optionally, the present application also provides a program product, such as a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the above-mentioned method embodiment applied to the controller.

[0085] Furthermore, the service access device provided in the embodiment of the present application, from the hardware level, the hardware architecture diagram of the service access device can be seen in Figure 7 As shown, the service access device may include: a memory 70 and a processor 71,

[0086] The memory 70 is used to store program instructions; the processor 71 calls the program instructions stored in the memory 70 and executes the above method embodiment applied to the authentication device according to the obtained program instructions. The specific implementation method and technical effect are similar and will not be repeated here.

[0087] Optionally, the present application also provides an authentication device, comprising at least one processing element (or chip) for executing the above-mentioned method embodiment applied to the authentication device.

[0088] Optionally, the present application also provides a program product, such as a computer-readable storage medium, which stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the above-mentioned method embodiment applied to the authentication device.

[0089] Here, the machine-readable storage medium may be any electronic, magnetic, optical or other physical storage device that may contain or store information, such as executable instructions, data, etc. For example, the machine-readable storage medium may be: RAM (RadomAccess Memory), volatile memory, non-volatile memory, flash memory, storage drive (such as hard disk drive), solid state drive, any type of storage disk (such as CD, DVD, etc.), or similar storage medium, or a combination thereof.

[0090] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver, a game console, a tablet computer, a wearable device or a combination of any of these devices.

[0091] For the convenience of description, the above device is described in various units according to their functions. Of course, when implementing the present application, the functions of each unit can be implemented in the same or multiple software and / or hardware.

[0092] Those skilled in the art will appreciate that the embodiments of the present application may be provided as methods, systems, or computer program products. Therefore, the present application may adopt the form of a complete hardware embodiment, a complete software embodiment, or an embodiment in combination with software and hardware. Moreover, the embodiments of the present application may adopt the form of a computer program product implemented in one or more computer-usable storage media (including but not limited to disk storage, CD-ROM, optical storage, etc.) that contain computer-usable program code.

[0093] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the processes in the flowchart and / or block diagram. Figure 1 A process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.

[0094] Moreover, these computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory produce a product including an instruction device, which implements the process Figure 1 A process or multiple processes and / or boxes Figure 1 The function specified in one or more boxes.

[0095] These computer program instructions can also be loaded onto a computer or other programmable data processing device so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, thereby providing instructions for executing on the computer or other programmable device to implement the process. Figure 1 A process or multiple processes and / or boxes Figure 1 The steps for the functions specified in one or more boxes.

[0096] The above description is only a preferred embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A service access method, characterized in that: Applied to a controller in a network, the method comprises: Receive routing information reported by nodes. When a node detects the creation of a service of a specified type, it constructs routing information corresponding to the service. The destination address of the routing information is the address of the service, and the next hop information is the address of the node. Determine, based on the address of the node included in the routing information, the authentication device to which the node is connected; The routing information is sent to the authentication device, wherein the authentication device synchronizes the routing information to a border device in the network, so that the Border device generates a routing table entry with the destination address being the address of the service and the next hop information being the authentication device based on the routing information. When the Border device receives a user request for accessing the service, the Border device determines the routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

2. The method according to claim 1, characterized in that The specified type of service is a ClusterIP type service.

3. A service access method, characterized in that: Applied to an authentication device in a network, the method comprises: Receiving routing information sent by the controller, wherein, when a node detects the creation of a service of a specified type, constructs routing information in which the destination address corresponding to the service is the address of the service and the next hop information is the address of the node, and determines the authentication device connected to the node based on the address of the node included in the routing information, and sends the routing information to the authentication device; The routing information is synchronized to the border device in the network, so that the border device generates a routing table entry with the destination address being the address of the service and the next hop information being the authentication device based on the routing information. When the border device receives a user request to access the service, the border device determines the routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

4. The method according to claim 3, characterized in that At least two routing table entries for forwarding the user request are maintained on the Border device. When the Border device receives a user request for accessing the service, the Border device determines at least two routing table entries for forwarding the user request based on the address of the service carried in the user request, and determines a target routing table entry for forwarding the user request from the at least two routing table entries based on a preset load balancing strategy, and forwards the user request to the corresponding authentication device based on the target routing table entry.

5. A service access device, characterized in that: A controller used in a network, the device comprising: A receiving unit, configured to receive routing information reported by a node, wherein when a node detects the creation of a service of a specified type, it constructs routing information corresponding to the service, the destination address of the routing information is the address of the service, and the next hop information is the address of the node; A determination unit, configured to determine an authentication device accessed by the node based on an address of the node included in the routing information; A sending unit is used to send the routing information to the authentication device, wherein the authentication device synchronizes the routing information to a border device in the network, so that the Border device generates a routing table entry with a destination address being the address of the service and the next hop information being the authentication device based on the routing information. When the Border device receives a user request for accessing the service, the Border device determines a routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

6. The device according to claim 5, characterized in that The specified type of service is a ClusterIP type service.

7. A service access device, characterized in that: An authentication device used in a network, the device comprising: A receiving unit, configured to receive routing information sent by a controller, wherein when a node detects the creation of a service of a specified type, it constructs routing information in which the destination address corresponding to the service is the address of the service and the next hop information is the address of the node, and determines the authentication device connected to the node based on the address of the node included in the routing information, and sends the routing information to the authentication device; A synchronization unit is used to synchronize the routing information to a border device in the network, so that the border device generates a routing table entry whose destination address is the address of the service and the next hop information is the authentication device based on the routing information. When the border device receives a user request for accessing the service, the border device determines the routing table entry for forwarding the user request based on the address of the service carried in the user request, and forwards the user request to the corresponding authentication device based on the routing table entry.

8. The device according to claim 7, characterized in that At least two routing table entries for forwarding the user request are maintained on the Border device. When the Border device receives a user request for accessing the service, the Border device determines at least two routing table entries for forwarding the user request based on the address of the service carried in the user request, and determines a target routing table entry for forwarding the user request from the at least two routing table entries based on a preset load balancing strategy, and forwards the user request to the corresponding authentication device based on the target routing table entry.

9. A service access device, characterized in that: The service access device comprises: A memory for storing program instructions; The processor is used to call the program instructions stored in the memory, and execute the steps of the method as described in any one of claims 1-2, or 3-4 according to the obtained program instructions.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores computer-executable instructions, and the computer-executable instructions are used to enable the computer to execute the steps of the method as described in any one of claims 1-2, or 3-4.

Citation Information

Patent Citations

  • Route updating method and user cluster

    CN110912827A

  • Service access method and device and load balancing system

    CN116418724A

  • Traffic scheduling method and system, electronic equipment and storage medium

    CN119135636A

  • Technique for addressing a cluster of network servers

    US20040133690A1

  • Automated service-oriented performance management

    US20170111241A1