Container configuration method and device, electronic equipment and readable storage medium
By automatically modifying the IP address of the container network bridge interface, the problems of manual configuration are easily prone to errors and low efficiency, and normal communication and efficient configuration between the container and the host are achieved.
Patent Information
- Application Number
- CN202510239952.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-28
- Publication Date
- 2025-05-13
AI Technical Summary
When configuring the IP address of the network bridge interface of the container, it is easy to cause IP address configuration errors, and manual configuration is inefficient.
By obtaining the host's IP address list and the target IP address of the network bridge interface, if the first interval of the target IP address is the same as the first interval of the host's first IP address, the first interval of the target IP address is modified to generate the second IP address to ensure that there is no routing conflict in the communication between the container and the host.
The automatic configuration of the IP address of the container network bridge interface is realized, which avoids routing conflicts, improves configuration efficiency, and ensures normal communication between the container and the host.
Smart Images

Figure CN119996376A_ABST
Abstract
Description
Technical Field
[0001] The present invention belongs to the field of computer technology, and specifically relates to a container configuration method, device, electronic device and readable storage medium. Background Art
[0002] Linux Containers (LXC) is a virtualization technology at the operating system level. Based on LXC technology, you can create containers on the host. When creating a container, you need to create a network bridge interface corresponding to the container so that the host and other devices can communicate with the container based on the network bridge interface.
[0003] In the related art, the Internet Protocol (IP) address is often configured for the network bridge interface of the container by manual configuration, but it is easy to cause IP address configuration errors and manual configuration is inefficient. Summary of the invention
[0004] The present invention aims to provide a container configuration method, device, electronic device and readable storage medium, which at least solve the problem that when configuring an IP address for a network bridge interface of a container in the prior art, the IP address is easily misconfigured and the configuration efficiency is low.
[0005] In order to solve the above-mentioned technical problems, the present invention is achieved as follows:
[0006] In a first aspect, an embodiment of the present invention provides a container configuration method, comprising: obtaining an IP address list of a host machine and a target IP address of a network bridge interface; the network bridge interface corresponds to a container to be configured in the host machine, and the IP address list includes a first IP address corresponding to the host machine; if a first interval of the target IP address is the same as a first interval of the first IP address, modifying the first interval of the target IP address to obtain a second IP address; the first interval is used to identify a network address; replacing the target IP address with the second IP address so that the host machine can communicate with the container to be configured based on the second IP address.
[0007] In the second aspect, an embodiment of the present invention also provides a container configuration device, including: a first acquisition module, used to obtain an IP address list of a host machine, and a target IP address of a network bridge interface; the network bridge interface corresponds to the container to be configured in the host machine, and the IP address list includes a first IP address corresponding to the host machine; an update module, used to modify the first interval of the target IP address to obtain a second IP address if the first interval of the target IP address is the same as the first interval of the first IP address; the first interval is used to identify a network address; a replacement module, used to replace the target IP address with the second IP address, so that the host machine can communicate with the container to be configured based on the second IP address.
[0008] In a third aspect, an embodiment of the present invention further provides an electronic device, comprising a processor; and one or more programs, wherein the one or more programs are stored in a memory and are configured to be executed by one or more processors, wherein the one or more programs include instructions for performing the following operations: obtaining an IP address list of a host machine and a target IP address of a network bridge interface; the network bridge interface corresponds to a container to be configured in the host machine, and the IP address list includes a first IP address corresponding to the host machine; if the first interval of the target IP address is the same as the first interval of the first IP address, modifying the first interval of the target IP address to obtain a second IP address; the first interval is used to identify a network address; replacing the target IP address with the second IP address so that the host machine can communicate with the container to be configured based on the second IP address.
[0009] In a fourth aspect, an embodiment of the present invention further provides a readable storage medium, which, when instructions in the readable storage medium are executed by a processor of an electronic device, enables the electronic device to execute the method described in the first aspect.
[0010] In summary, in this embodiment, the target IP address of the network bridge interface of the container to be configured in the host machine and the IP address list of the host machine are obtained. If the two match successfully, it means that the first interval of the network bridge interface of the container to be configured is the same as the first interval of the host machine, and the IP addresses of the network bridge interface of the container to be configured and the host machine are in the same network segment, which often leads to routing conflicts during the communication process. Then, the first interval of the target IP address of the network bridge interface of the container to be configured is updated to obtain the second IP address, so that the network segment of the second IP address is different from the network segment of the first IP address in the IP address list. Thereby, the automatic configuration of the IP address of the network bridge interface of the container to be configured is realized, and the network segment corresponding to the network bridge interface of the container to be configured is different from the network segment corresponding to the host machine, and the container to be configured will not have the problem of routing conflicts, ensuring the normal communication between the container to be configured and the host machine. This embodiment solves the problem of low configuration efficiency and easy errors when configuring the IP address of the network bridge interface corresponding to the container in the related technology. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] Figure 1 is a flowchart of the steps of a container configuration method provided by an embodiment of the present invention;
[0012] Figure 2 is a schematic diagram of a connection relationship between a container and a network bridge interface provided by an embodiment of the present invention;
[0013] Figure 3 is a flowchart of the steps of a container configuration method provided by an embodiment of the present invention;
[0014] Figure 4 is a flowchart of the steps of a container configuration method provided by an embodiment of the present invention;
[0015] Figure 5 is a block diagram of a container configuration device provided by an embodiment of the present invention;
[0016] Figure 6 is a block diagram of an electronic device provided by an embodiment of the present invention;
[0017] Figure 7 is a block diagram of another electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0018] The memory training method provided by the embodiment of the present invention is described in detail below through specific embodiments and application scenarios in conjunction with the accompanying drawings.
[0019] Figure 1 is a flowchart of a container configuration method provided by an embodiment of the present invention, referring to Figure 1 , the method may include the following steps:
[0020] Step 101, obtain the IP address list of the host machine and the target IP address of the network bridge interface.
[0021] Specifically, the network bridge interface corresponds to the container to be configured in the host machine, and the IP address list includes a first IP address corresponding to the host machine.
[0022] The host machine has at least one physical network card, and each physical network card has a corresponding first IP address. Correspondingly, the IP address list may include at least one first IP address of the host machine.
[0023] Furthermore, at least one network bridge interface can be set in a host machine, and a network bridge interface can be connected to at least one container. In order to avoid routing conflicts and ensure normal communication of containers, it is necessary to ensure that the first intervals of IP addresses between different network bridge interfaces are different, and the first interval is used to identify the network address. Furthermore, the first intervals of the IP addresses of the same network bridge interface and each container under the network bridge interface are the same, but the second intervals are different, and the second interval is used to identify the device address. For example, the correspondence between the host machine, the network bridge interface and the container can be referred to as shown in Table 1 below:
[0024] Table 1
[0025]
[0026] Further, the connection diagram of each device shown in Table 1 is as follows Figure 2 In the embodiment shown in Table 1, two types of network bridge interfaces are provided in the host machine, namely, Lxcbr type and Docker type network bridge interfaces.
[0027] Specifically, the network bridge interface includes a network bridge interface Lxcbr0, a network bridge interface Docker0, and a network bridge interface Lxcbr1. Among them, Lxcbr0 connects container 0 and container 1, the network bridge interface Docker0 connects container 2 and container 3, and the network bridge interface Lxcbr1 connects container 4 and container 5.
[0028] For example, if container 5 is the container to be configured, the IP address of the network bridge interface Lxcbr1 is the target IP address in this step. Furthermore, if there are network bridge interfaces corresponding to other containers in the host machine, the IP address list includes multiple first IP addresses, and the multiple first IP addresses include two types: the first IP address of the host machine, and the first IP addresses corresponding to other network bridge interfaces in the host machine.
[0029] For example, in Table 1 and Figure 2In the illustrated embodiment, the IP address list includes the first IP address of the host machine, the first IP address of the network bridge interface Lxcbr0, the network bridge interface Docker0, and the first IP addresses of the network bridge interface Lxcbr1.
[0030] For example, the container to be configured is a container created based on LXC technology. Among them, LXC technology is an operating system virtualization technology used to create and manage lightweight containers on a host. Multiple containers created based on LXC technology can share the kernel in the host machine, and respond to the resource requests of each container respectively through the kernel service. The startup speed of the container created based on this technology is very fast. This method of creating and managing containers is particularly suitable for application scenarios that require rapid deployment and elastic contraction. Correspondingly, the method of this embodiment is particularly suitable for application scenarios that require rapid deployment and elastic contraction. For example, the method of this embodiment is suitable for application scenarios that run database processing programs, real-time detection and processing of application data traffic, or other application scenarios that require rapid deployment and elastic contraction. When creating a container based on LXC technology, it is necessary to create a network bridge interface corresponding to the container, and set an IP address for the network bridge interface so that the container communicates with other containers, the host machine or an external network through the IP address of the network bridge interface. Further, the container to be configured is a newly constructed container in the host machine. For the newly constructed container, the IP address of its corresponding network bridge interface needs to be configured.
[0031] For example, the target IP address of the network bridge interface may be randomly generated, or any first IP address in the IP address list may be directly set as the target IP address of the network bridge interface.
[0032] Step 102: If the first interval of the target IP address is the same as the first interval of the first IP address, modify the first interval of the target IP address to obtain a second IP address.
[0033] If the first interval of the target IP address is different from the first interval of the first IP address, the target IP address is directly configured to the network bridge interface. The first interval is used to identify the network address. Specifically, the first interval of the target IP address is used to identify the network address of the network where the network bridge interface is located, and the first interval of the first IP address is used to identify the network address of the network where the host is located.
[0034] For example, the target IP address and the first IP address can be Class A, Class B, Class C or other types of IP addresses, and this embodiment does not limit the applicable IP address types. Among them, for the three types of IP addresses, the first interval can include the first three network address segments; for Class A IP addresses, the first interval can also include the first two network address segments; for Class B IP addresses, the first interval can also include the first two network address segments belonging to the private network address range. Furthermore, the target IP address and the first IP address also have a second interval for characterizing the device address, wherein the second interval is the part of the IP address other than the first interval. For example, the first IP address is 192.168.5.25, its first interval is 192.168.5, and its second interval is 25.
[0035] In the case where there are no other network bridge interfaces in the host machine, the IP address list in the host machine includes at least one first IP address of the host machine. In the case where there are other network bridge interfaces in the host machine, the IP address list includes: the first IP address of the host machine, and the first IP addresses of other network bridge interfaces; wherein the other network bridge interfaces are network bridge interfaces corresponding to other containers. In the case where no other network bridge interfaces are installed in the host machine, the IP address list only includes the first IP address of the host machine.
[0036] It should be noted that, in this embodiment, the first IP address is used to represent the IP address recorded in the IP address list, and does not mean that the first IP address in the IP address list is the same IP address. Furthermore, in the IP address list, the first IP address of the host machine is different from the first IP address of the other network bridge interface. Furthermore, the first interval of the first IP address of the host machine and the first IP address of the other network bridge interface is different, and the second interval of the first IP address of the host machine and the first IP address of the other network bridge interface may be the same or different.
[0037] The first interval of the first IP address of the host machine is different from that of the first IP address of other network bridge interfaces, which can avoid routing conflicts when the container communicates with the host machine, or when the container communicates with the container, or when the container communicates with the external network, thereby causing communication anomalies. Since the IP address is composed of the first interval and the second interval, as long as the first intervals of the host machine and the network bridge interface are different, regardless of whether the second intervals between the two are the same, the first IP addresses of the two will not be the same, and the communication failure problem caused by the same first IP address of the host machine and the network bridge interface will not occur.
[0038] For example, refer to Figure 2, the host machine not only has the network bridge interfaces Lxcbr0 and Lxcbr1 created based on LXC technology, but also has the network bridge interface Docker0 created based on docker technology. For example, container 5 is the container to be configured, then the target IP address of the network bridge interface of the container to be configured is the IP address of the network bridge interface Lxcbr1; the first IP address of the host machine is the IP address of the physical network card eth0, and the first IP addresses of other network bridge interfaces are the IP addresses of Docker0 and Lxcbr0. Then the IP address list includes: the first IP address of eth0, the first IP address of Docker0, and the first IP address of Lxcbr0. The IP address of Lxcbr1 is the target IP address.
[0039] Furthermore, if the first interval of the target IP address is the same as the first interval of any first IP address, it means that the target IP address of the network bridge interface is the same as the network segment of the first IP address of the host or other network bridge interfaces, then the first interval of the target IP address is updated to obtain a second IP address with a different network segment from the first IP address; if the first interval of the target IP address is different from the first intervals of all first IP addresses in the IP address list, it means that the network segment of the target IP address of the network bridge interface of the container to be configured is different from the network segment of the first IP address of the host and other network bridge interfaces, and the target IP address can be directly configured to the network bridge interface.
[0040] For example, the first interval of the target IP address and the first interval of the first IP address in the IP address list are obtained respectively, and the first interval of the target IP address of the network bridge interface and the first interval of the first IP address in the IP address list are compared respectively to determine whether the first interval of the target IP address is the same as the first interval of the first IP address. If the first interval of the target IP address is the same as the first interval of the first IP address, the network segment of the target IP address is the same as the network segment of the first IP address. When the network segments are the same, routing conflicts often occur when the container communicates with the host, or when the container communicates with the container, or when the container communicates with the external network, resulting in communication anomalies. Therefore, if the network of the network bridge interface and the first interval of the first IP address in the IP address list are the same, it is necessary to modify the first interval of the target IP address to obtain a second IP address whose first interval is different from the first interval of all first IP addresses.
[0041] The IP address includes a first interval and a second interval, and the first interval may include at least one network address segment. For example, one or more network address segments in the target IP address may be modified to obtain a second IP address that is different from the first interval of all first IP addresses. For example, if the first IP address is 192.168.5.25, then the first interval of the first IP address is 192.168.5. The target IP address is 192.168.5.10, and the first interval of the target IP address is 192.168.5. In this embodiment, the first interval of the target IP address is the same as that of the first IP address, both of which are 192.168.5, then the network segment of the target IP address and the first IP address is also the same. For example, the third segment of the target network address segment of the target IP address may be modified to obtain a modified second IP address.
[0042] For example, the third network address segment of the target IP address can be updated to a value that is different from the third network address segments of all first IP addresses, for example, updated to 9, based on which the second IP address is obtained: 192.168.9.10. After the target IP address is modified, the first interval of the second IP address is 192.168.9, and the first interval of the first IP address is 192.168.5. If the two are different, the second IP address and the first IP address are not in the same network segment. When the container communicates based on the second IP address, the routing conflict problem can be avoided.
[0043] Step 103: Replace the target IP address with the second IP address so that the host machine can communicate with the container to be configured based on the second IP address.
[0044] Further, the second IP address is configured to the network bridge interface of the container to be configured, so that the host machine can obtain other communication devices to communicate with the container to be configured based on the second IP address.
[0045] In the related art, when deploying a container service on a host, it is necessary to set up the container network by manual configuration, and the container network setting includes setting the IP address of the network bridge interface corresponding to the container. This method has the problems of long time consumption and low efficiency. Especially when the container service is deployed on multiple machines, the disadvantages of this method are more obvious. In addition, when configuring the IP address of the container network bridge interface based on the method of the related art, there is also the problem that the manual configuration of the IP address of the network bridge interface is prone to errors. Specifically, when configuring the IP address of the network bridge interface through the manual configuration method of the related art, it is easy for the IP address of the configured network bridge interface to be in the same network segment as the IP address of the host machine, which will cause the container corresponding to the network bridge interface to conflict with the host machine routing, thereby affecting the network communication between the host machine and the container.
[0046] For example, if the first IP address of the host is 192.168.5.25 and the target IP address of the network bridge interface is 192.168.5.10, the two are in the same network segment. In this case, the container corresponding to the network bridge interface will have a routing conflict with the host, resulting in abnormal communication between the host and the container.
[0047] Specifically, when configuring the IP address of the network bridge interface based on the method of related technology, the following situations may occur:
[0048] / home / alpine / alpine / lxc-templates-legacy#route-n
[0049] Kernel IP routing table
[0050]
[0051] Furthermore, in the above-mentioned embodiment of the related technology, the host network bridge interface is eth2, and the container network bridge interface is Lxcbr0. The first interval of both is 10.130.0, and the two are in the same network segment, which will cause routing conflicts during the communication process.
[0052] In this embodiment, the target IP address of the network bridge interface of the container to be configured in the host machine and the IP address list of the host machine are obtained. If the two match successfully, it means that the first interval of the network bridge interface of the container to be configured is the same as the first interval of the host machine, and the network bridge interface of the container to be configured and the host machine are in the same network segment, which often leads to routing conflicts during the communication process. Then, the second IP address is obtained by updating the first interval of the target IP address of the network bridge interface of the container to be configured, so that the first interval of the second IP address is different from the first interval of the first IP address in the IP address list, and the network segment of the second IP address is also different from the network segment of each first IP address in the IP address list. Thereby, the automatic configuration of the IP address of the network bridge interface of the container to be configured is realized, and the network segment corresponding to the network bridge interface of the container to be configured is different from the network segment corresponding to the host machine, and the container to be configured will not have the problem of routing conflicts, ensuring the normal communication between the container to be configured and the host machine, or other devices. This embodiment solves the problem of low configuration efficiency and easy errors when configuring the IP address of the network bridge interface corresponding to the container in the related technology.
[0053] Reference Figure 3 The container configuration method of the present application may further include the following steps:
[0054] Step 201, obtain the IP address list of the host machine.
[0055] The network bridge interface corresponds to the container to be configured in the host machine, and the IP address list includes a first IP address corresponding to the host machine.
[0056] The method of this step has been described in the aforementioned step 101 and will not be repeated here.
[0057] Step 202: Obtain a container configuration file of the container to be configured, and extract the interface name of the network bridge interface from the container configuration file.
[0058] For example, the container configuration file stores the configuration information of the container to be configured, which may include the interface name of the network bridge interface corresponding to the container to be configured, the container's environment variables, the container name, the container startup command, and other information. For example, the interface name of the network bridge interface can be extracted from the container configuration file using grep and awk techniques. For example, if the configuration file is in the following path: / var / lib / lxc / container1 / config, the name of the network bridge interface can be extracted using the following method:
[0059] config_file = " / var / lib / lxc / container1 / config" #Use grep to extract the line containing "lxc.net.0.link = xxx", and use awk to extract the network interface name used by the container
[0060] container_bridge=$(grep"lxc.net.0.link=""$config_file"|awk-F"="'{print$2}')
[0061] Furthermore, the interface name of the network bridge interface created in the host is obtained. For example, on different operating systems, the LXC main package (lxc) and the configuration template package (lxc-templates) may be different. When these two packages are installed in some operating systems, a network bridge interface will be created. When the network bridge interface is created, the name of the created network bridge interface will be stored in the network information of the host operating system.
[0062] Step 203: If the interface name of the network bridge interface is different from the interface names of all the network bridge interfaces created in the host machine, a network bridge interface is created in the host machine, and a target IP address is set for the network bridge interface.
[0063] If the interface name of the network bridge interface of the container to be configured is different from the interface names of all created network bridge interfaces, it means that the network bridge interface of the container to be configured has not been created in the host. Therefore, you need to create a network bridge interface in the host and set the target IP address for the network bridge interface.
[0064] For example, the first IP address of the host machine may be set as the target IP address of the network bridge interface, or the target IP address of the network bridge interface may be randomly generated.
[0065] If the interface name of the network bridge interface of the container to be configured is the same as the interface name of any created network bridge interface, it means that the network bridge interface of the container to be configured has been created in the host. In this case, there is no need to build the network bridge interface again. For example, the interface name of the created network bridge interface is stored in the network information of the host operating system. The network information on the host operating system can be read through the ifconfig command to find out whether there is a network bridge interface corresponding to the container to be configured in the network information, and use the variable has_container_interface flag. Specifically, the following method can be used to find out whether the network bridge interface of the container to be configured has been created in the host:
[0066]
[0067] If the value of has_container_interface is true, it means that the network bridge interface of the container to be configured has been created in the host. If the value of has_container_interface is false, it means that the network bridge interface of the container to be configured has not been created in the current host. In this case, you need to create a network bridge interface for the container to be configured in the current host and assign it a target IP address.
[0068] For example, you can create a network bridge interface by running the following command: brctl addbr lxcbri, where lxcbri indicates the name of the network bridge interface.
[0069] After creating a network bridge interface, you can initialize the created network bridge interface through the following command: ip addr add192.168.1.2.8 / 24dev$container_bridge. Among them, $container_bridge represents the name of the network bridge interface; 192.168.1.2 is the IP address assigned to the network bridge interface.
[0070] After creating the network bridge interface of the container to be configured, in order to prevent the target IP address of the network bridge interface of the container to be configured from being in the same network segment as the first IP address of the host machine, which may cause routing conflicts, the host machine's IP address list may be read first, and an initial IP address may be set for the network bridge interface of the container to be configured, and the set initial IP address is the target IP address in this step. Then, according to the method of steps 204 to 206, it is determined whether the first interval of the target IP address is the same as the first interval of the first IP address in the IP address list, and if they are the same, the target IP address is updated to a second IP address whose first interval is different from the first interval of the first IP address in the IP address list.
[0071] Specifically, the first interval of the target IP address includes at least one target network address segment arranged in sequence, and each target network address segment has its own corresponding arrangement number. For example, the target IP address is 192.168.5.10, and its first interval is 192.168.5. The first interval includes three target network address segments, and the three target network address segments are: the first target network address segment 192, the second target network address segment 168, and the third target network address segment 5.
[0072] For example, the target network address segment corresponding to the preset arrangement number in the target IP address is modified to obtain a second IP address; wherein, when modifying the target network address segment, it is necessary to ensure that the updated target network address segment is within the legal network address segment range, and further, it is necessary to ensure that the updated target network address segment is within the network address segment range corresponding to the IP address type.
[0073] For example, the target IP address range is: 192.168.0.0 ~ 192.168.255.255, and the modified target network address segment is the third segment in the first interval. It is necessary to ensure that the updated target network address segment is in the range of 0 to 255.
[0074] The following is a further exemplary description of a method for modifying the target network address segment corresponding to the preset arrangement sequence number in the target IP address to obtain the second IP address:
[0075] Step 204: If the first interval of the target IP address is the same as the first interval of the first IP address, a target network address segment corresponding to a preset arrangement number is obtained from at least one target network address segment.
[0076] The preset sequence number may be one or more of the sequence numbers of the target network address segment. For example, the target IP address is 192.168.5.10, the first interval of the target IP address is 192.168.5, and the target network address segment includes three segments. For example, the preset sequence number is the third segment. In this embodiment, the target network address segment corresponding to the preset sequence number is 5.
[0077] Step 205, modify the target network address segment corresponding to the preset arrangement sequence number to obtain an updated target network address segment.
[0078] The method for modifying the target network address segment may include: directly modifying the target network address segment corresponding to the preset sequence number. For example, if the first interval of the target IP address is 192.168.5, the preset sequence number is the third segment, and the target network address segment corresponding to the preset sequence number is 5, an addition operation may be performed to obtain an updated target network address segment 6.
[0079] The method for modifying the target network address segment may also include: the first interval of the first IP address includes at least one first network address segment, obtaining the target first network address segment corresponding to the preset arrangement number in the first network address segment and modifying it to obtain a second network address segment that is different from the first network address segment corresponding to the preset arrangement number in each first IP address, and then using the second network address segment to directly replace the target network address segment corresponding to the preset arrangement number in the target IP address. For example, the first interval of the first IP address is 192.168.8, and the preset arrangement number is the third segment, then the target first network address segment corresponding to the preset arrangement number is 8, which can be added by 1 to obtain the second network address segment 9, and the second network address segment 9 is used to replace the target network address segment 5 corresponding to the preset arrangement number to obtain an updated target network address segment 9.
[0080] Furthermore, if the updated target network address segment exceeds the legal network address segment range, the policy for modifying the target network address segment may be changed.
[0081] For example, the strategy for changing the target network address segment may include: the current strategy is to obtain the target first network address segment from the first network address segment in the first interval of the first IP address, perform a sum operation on the target first network address segment and the preset network address segment, and determine the sum result as the updated target network address segment; if the updated target network address segment exceeds the legal network address segment range, the value of the preset network address segment can be reduced, or the sum operation can be changed to a difference operation.
[0082] For example, if the current strategy is to obtain the target first network address segment from the first IP address, a difference operation is performed on the target first network address segment and the preset network address segment, and the difference result is determined as the updated target network address segment; if the target network address segment exceeds the legal network address segment range, the value of the preset network address segment can be reduced, or the difference operation can be changed to a sum operation.
[0083] For example, after adding 2 to the target network address segment, if the updated target network address segment exceeds the maximum value of the legal network address segment range (eg, 255), then adding 1 to the target network address segment is performed to obtain an updated target network address segment.
[0084] Step 206, concatenate the updated target network address segment, other target network address segments except the target network address segment corresponding to the preset arrangement number, and the second interval in the target IP address to obtain a second IP address.
[0085] Specifically, the second interval is used to identify the device address. For example, if the target IP address is 192.168.5.10, the updated target network address segment (the third target network address segment) is 9, and the other target network address segments except the third target network address segment are: the first target network address segment 192 and the second target network address segment 168, and the second interval is 10, then the second IP address obtained after splicing is 192.168.9.10.
[0086] Step 207: Replace the target IP address with the second IP address so that the host machine can communicate with the container to be configured based on the second IP address.
[0087] If the first interval of the network bridge interface is different from the first interval of the first IP address of the host machine, the network segments are also different. Therefore, based on the method of this embodiment, it can be ensured that the second IP address and the first IP address are not in the same network segment. Using the second IP address to replace the target IP address and configuring the second IP address to the network bridge interface of the container to be configured can avoid routing conflicts when the container to be configured communicates.
[0088] For example, the second IP address may be used to replace the target IP address in the following manner, thereby configuring the second IP address to the network bridge interface:
[0089]
[0090] After the network bridge interface is configured, start the network bridge interface. After starting the network bridge interface, the network bridge interface can receive and send data that the host or other communication devices interact with the container to be configured. For example, the network bridge interface can be started by the following command: ifconfig$container_bridge up. Among them, other communication devices include other containers in the host, and other hosts and containers in other hosts.
[0091] For example, the IP address list also includes: the first IP addresses of other network bridge interfaces in the host machine. That is, the IP address list includes multiple first IP addresses, and the multiple first IP addresses include the first IP address of the host machine and the first IP addresses of other network bridge interfaces. The first interval of the first IP address of the host machine and the first IP addresses of other network bridge interfaces is different.
[0092] For example, refer to Figure 2 , the container to be configured is Docker0, and the corresponding network bridge interface is Lxcbr0, then the target IP address of the network bridge interface of the container to be configured is the IP address of Lxcbr0. The IP address list includes the first IP address of the host physical network card eth0, and the first IP address of other network bridge interface Docker0.
[0093] For example, the first interval of the first IP address includes multiple first network address segments arranged in sequence. Each first network address segment has its own corresponding arrangement sequence number. For example, in one embodiment, the first IP address is 192.168.5.25, then the first interval of the first IP address is 192.168.5, and the first network address segment includes three segments. For example, the preset arrangement sequence number is the third segment, then in this embodiment, the target first network address segment corresponding to the preset arrangement sequence number is 5.
[0094] Furthermore, in step 205, modifying the target network address segment to obtain an updated target network address segment may include the following sub-steps:
[0095] Sub-step 2051, obtaining at least one target first interval from the first intervals of multiple first IP addresses.
[0096] Specifically, the first network address segment corresponding to the first permutation number in the target first interval is the same as the target network address segment corresponding to the first permutation number, wherein the first permutation number is a permutation number other than the preset permutation number. The target first interval is used to generate an updated target network address segment.
[0097] For example, the host machine has two first IP addresses, and in addition to the network bridge interface of the container to be configured, the host machine also has another network bridge interface. In this embodiment, the IP list includes: the first IP addresses 192.168.5.25 and 192.168.7.100 of the host machine, and the first IP address 192.168.8.121 of the other network bridge interface. Among them, the target IP address of the network bridge interface of the container to be configured is 192.168.5.10. In the first IP address, the first IP address includes three first network address segments, namely the first segment, the second segment and the third segment. Among them, the preset arrangement sequence number is the third segment, and the first arrangement sequence number other than the preset arrangement sequence number includes the first segment and the second segment.
[0098] In this embodiment, the target network address segments corresponding to the first sequence number (including the first segment and the second segment) of the network bridge interface to be configured are 192 and 168. In this embodiment, the first interval first sequence number (including the first segment and the second segment) corresponding to 192.168.5.1, 192.168.7.1, and 192.168.8.1 in the IP list are the same as the first interval first sequence number corresponding to the target IP address, which is 192.168. Therefore, these first intervals are the target first intervals in this step, and the target first intervals are 192.168.5, 192.168.7, and 192.168.8.
[0099] For example, the first IP address may include: the first IP address of the host machine, and the first IP addresses of other network bridge interfaces in the host machine except the network bridge interface. For each first IP address, the first network address segment corresponding to the first arrangement number in the first interval of the first IP address is obtained.
[0100] Specifically, the first network address segment corresponding to the first arrangement number is compared with the target network address segment corresponding to the first arrangement number. If the two are the same, the first interval of the first IP address to which the first network address segment belongs is determined as the target first interval.
[0101] Furthermore, there may be multiple first permutation numbers, and for each first permutation number, the first network address segment and the target network address segment corresponding thereto are compared to obtain a comparison result corresponding to the first permutation number, and the comparison result includes: the first network address segment and the target network address segment corresponding to the first permutation number are the same or different. Furthermore, in the first interval of the same first IP address, if the comparison results corresponding to the first permutation numbers are the same, the first interval of the first IP address is determined to be the target first interval.
[0102] Furthermore, in each target first interval, the first network address segments corresponding to the preset sequence number are obtained respectively. For example, 192.168.5, 192.168.7 and 192.168.8 are selected target first intervals, and the preset sequence number is the third segment. In this embodiment, the first network address segments corresponding to the preset sequence number are 5, 7 and 8 respectively.
[0103] The first permutation sequence number is a permutation sequence number other than the preset permutation sequence number, and the target first interval selected based on the first permutation sequence number is the first interval that is identical to all other target network address segments in the first interval of the target IP address except for the preset network address corresponding to the preset permutation sequence number. In other words, according to sub-step 2051, a target first interval that is at least partially identical to the first interval of the target IP address is screened from the first interval of the first IP address. After the target first interval is screened out, the portion of the target first interval other than the first preset permutation sequence number is continued to be processed according to the method of the subsequent sub-step 2053 to obtain a second network address segment that is different from the portion of the target first interval other than the first preset permutation sequence number.
[0104] Sub-step 2052, obtaining the target first network address segment from the first network address segment corresponding to the target first interval and the preset arrangement sequence number and modifying it to obtain the second network address segment.
[0105] Specifically, the second network address segment is different from the first network address segment corresponding to the preset arrangement sequence number.
[0106] For example, the first interval of the first IP address includes three segments, and the first interval of the target IP address also includes three segments. The preset arrangement sequence number is the third segment, and the first arrangement sequence number is the first segment and the second segment. Based on sub-step 2051, at least one target first interval whose first two segments are the same as the first interval of the target IP address is obtained. Then, from the third segment first network address segment of each target first interval, a target first network address segment is selected and modified to obtain a second network address segment.
[0107] Furthermore, the preset sequence number can be any segment in the sequence number. For example, the preset sequence number is the third segment, and the first sequence number is the other sequence number except the preset sequence number. Therefore, the first sequence number includes the first segment and the second segment. For example, the first IP address in the IP list includes 192.168.5.25, 192.168.7.100, and 192.168.8.121, and the target IP address of the container network bridge interface to be configured is 192.168.5.10.
[0108] Then, the network address segment corresponding to the first arrangement number (the first segment and the second segment) in the target IP address is 192.168. In this embodiment, the network address segment corresponding to the first arrangement number and the target first interval that is the same as the target IP address are determined to be 192.168.5, 192.168.7 and 192.168.8 respectively.
[0109] Further, according to sub-step 2052, one of the network address segments corresponding to the preset arrangement numbers (third segments) of the two target first intervals is selected as the target first network address segment, and it is modified to obtain the second network address segment. For example, the third network address segment in 192.168.8 is selected, and the third network address segment is obtained as 8, which is added by 1 to obtain the second network address segment 9.
[0110] For example, sub-step 2051 may include the following sub-steps:
[0111] Sub-step A1, obtain the target first network address segment with the largest value from the first network address segments corresponding to the target first interval and the preset arrangement number, and perform a sum operation based on the target first network address segment to obtain the second network address segment; or, obtain the target first network address segment with the smallest value from the first network address segments corresponding to the target first interval and the preset arrangement number, and perform a difference operation based on the target first network address segment to obtain the second network address segment.
[0112] Among them, the first preset network address segment can be an arbitrarily set value, for example, it can be 1, 2 or other values. In order to ensure that the second network address segment obtained after the summation operation does not exceed the legal address segment range, the first preset network address segment is preferably set to a smaller value, for example, it is preferably set to 1.
[0113] Further, traverse each target first interval to obtain the first network address segment corresponding to the preset arrangement number among the multiple first network address segments included in the target first interval; then compare all the obtained first network address segments, and determine the maximum value among them as the target first network address segment, or determine the minimum value among them as the target first network address segment.
[0114] If the target first network address segment to be modified is not limited to the maximum or minimum value in the target first network address segment, but a target first network address is randomly selected for modification, the modified second network address segment may be repeated with the target first network address segment in a certain target first interval, which will cause the first interval of the second IP address spliced based on the second network address segment to be repeated with the target first interval. If this happens, it needs to be modified again, which will affect the processing efficiency. For example, the target first interval is 192.168.5, 192.168.7 and 192.168.8, the preset network address segment value is 1, and the preset arrangement sequence number is the third segment, then the first network address segment of the third segment is the target first network address segment. In this example, a third segment first network address segment is randomly selected for the add 1 operation. For example, add 1 to the third segment of the first network address segment 1 in 192.168.7 to obtain the second network address segment 8, which is the same as the third segment of the first network address 8 of 192.168.8. Based on the second network address segment 8, the first interval of the second IP address of the container network bridge interface to be configured is equal to 192.168.8, which is equal to the first interval 192.168.8 of the host machine. This will cause the container network bridge interface to be configured and the host machine to be in the same network segment.
[0115] Based on the method of this embodiment, the minimum value 5 in the third segment of the first network address segment can be used as the target first network address segment, and the difference operation can be performed with the value 1 of the preset network address segment to obtain the second network address segment 4. Based on the second network address segment, the first interval of the container network bridge interface to be configured is 192.168.4. Although the first interval is the same as the first two segments of the first intervals 192.168.5, 192.168.7 and 192.168.8 of the three first IP addresses in the IP address list, the third segment is different, so the network segments represented by each first interval are different. The maximum value 8 in the third segment of the first network address segment can also be used as the target first network address segment, and the sum operation can be performed with the value 1 of the preset network address segment to obtain the second network address segment 9. Based on the second network address segment, the first interval of the container network bridge interface to be configured is 192.168.9.
[0116] According to the above analysis, based on the method of this embodiment, the second network address segment can be quickly acquired, and it can be ensured that the second network address segment and the first network address segments corresponding to the preset arrangement sequence numbers in all target first intervals are different.
[0117] Sub-step 2053: determine the second network address segment as the updated target network address segment.
[0118] At least one target first interval is obtained from the first intervals of the plurality of first IP addresses, because the first network address segment corresponding to the first arrangement number in the target first interval is the same as the target network address segment corresponding to the first arrangement number. Therefore, the target first interval selected based on the method of this embodiment is the first interval that is the same as at least part of the target network address segments in the first interval of the target IP address.
[0119] After selecting the target first interval, continue to process the first network address segments in the target first interval except the first network address segment corresponding to the first arrangement number. Specifically, respectively obtain at least one first network address segment corresponding to the preset arrangement number in each target first interval, obtain the target first network address segment from at least one first network address segment corresponding to the preset arrangement number in the target first interval, modify the target first network address segment to obtain a second network address segment, and the second network address segment and the first network address segment corresponding to the preset arrangement number in the target first interval are different network address segments.
[0120] The second network address segment is determined as the updated target network address segment, and the updated target network address segment, other target network address segments in the target IP address except the target network address segment corresponding to the preset arrangement sequence number, and the second interval in the target IP address are concatenated to obtain the second IP address.
[0121] For example, the preset arrangement number is the third segment, and the first arrangement number is the other arrangement number except the preset arrangement number. Therefore, the first arrangement number includes the first segment and the second segment. The first IP addresses in the IP list include 192.168.5.25, 192.168.7.100, and 192.168.8.121, and the target IP address of the container network bridge interface to be configured is 192.168.5.10. In this embodiment, the network address segment corresponding to the first arrangement number (first segment and second segment) determined from the first IP address is the same as the target first interval of the target IP address, which is 192.168.5, 192.168.7, and 192.168.8, respectively.
[0122] Further, the first network address segments corresponding to the preset arrangement sequence number (third segment) of the target first intervals 192.168.5, 192.168.7 and 192.168.8 are 5, 7 and 8 respectively. The maximum value 8 among the first network address segments (5, 7 and 8) corresponding to the third segments of these three target first intervals is determined as the target first network address segment. A sum operation is performed based on the target first network address segment 8, for example, an addition operation is performed on it to obtain a second network address segment 9, and the second network address segment 9 is determined as the updated target network address segment.
[0123] In the target IP address 192.168.5.10, the target network address segments other than the third target network address segment 5 are 192.168, and the second interval is 10. Therefore, the updated target network address segment 9, the target network address segments other than the third target network address segment, and the second interval in the target IP address are concatenated to obtain the second IP address 192.168.9.10.
[0124] Even if part of the target network address segment (the part corresponding to the first arrangement number) of the first interval of the second IP address thus obtained is the same as part of the first network address segment (the part corresponding to the first arrangement number) of the first interval of the first IP address, the remaining target network address segment (the part corresponding to the preset arrangement number, i.e., the second network address segment) is different from the first network address segment (the part corresponding to the preset arrangement number) of the remaining part of the first interval of the first IP address. That is, based on the method of this embodiment, it can be ensured that the first interval of the container network bridge interface to be configured is different from the first interval of each first IP address in the IP address list.
[0125] In summary, based on the method of this embodiment, a second IP address whose first interval is different from the first interval of each first IP address in the IP address list can be quickly obtained. If the second IP address is different from the first interval of each first IP address in the IP address list, its network segment is also different from the network segment of each first IP address in the IP address list. By configuring the second IP address to the network bridge interface, it is possible to avoid the network segment of the network bridge interface of the container to be configured being different from that of the host machine, as well as from that of other network bridge interfaces in the host machine, thereby avoiding routing conflicts related to each container in the host machine.
[0126] The updated target network address segment can be obtained according to the method of sub-steps 2051 to 2053, and the target network address segment corresponding to the preset arrangement number in the first interval of the target IP address can also be directly modified to obtain the updated target network address segment. For example, the first interval includes three network address segments, and the first arrangement number is the first segment and the second segment. Then traverse the IP address list, compare whether the target IP address of the network bridge interface is in the same network segment as the first IP address in the IP address list, specifically, compare whether the first interval of the target IP address of the network bridge interface is the same as the first interval of the first IP address in the IP address list, and if they are the same, add 1 to the third network address segment of the target IP address of the network bridge interface to ensure that the target IP address of the network bridge interface and the first IP address of the host machine are not in the same network segment.
[0127] Furthermore, first determine whether a network bridge interface for the container to be configured has been created on the host machine. If the network bridge interface for the container to be configured has not been created on the host machine, first create the network bridge interface, then set the target IP address for it, and determine whether the first interval of the target IP address is the same as the first interval of the first IP address in the IP list. If they are the same, update the first interval of the target IP address to obtain the second IP address, otherwise directly configure the target IP address as the IP address of the network bridge interface. If the network bridge interface for the container to be configured has been created on the host machine, then directly determine whether the first interval of the target IP address of the network bridge interface is the same as the first interval of the first IP address in the IP list. If they are the same, update the first interval of the target IP address to obtain the second IP address, otherwise directly configure the target IP address as the IP address of the network bridge interface.
[0128] Specifically, if the network bridge interface of the container to be configured is not created on the host, obtain the second IP address of the network bridge interface according to the following method:
[0129] if["$has_container_interface"=="false"];then / / No container network bridge interface is created on the host
[0130] #Get the host's IP address list
[0131] host_IPs = $(hostname - I)
[0132] #Split the host IP address list into an array
[0133] IFS="read-ra host_IP_array<<<"$host_IPs"
[0134] For example, if the network bridge interface of the container to be configured is not created in the host machine, the network bridge interface is created first, and then the first two network segments in the IP address list (the first network address segment corresponding to the first arrangement number) and the first intervals that are the same as the first two network segments of the target IP address of the network bridge interface are obtained by the following method, and these first intervals are determined as the target first intervals. The third first network address segment in these target first intervals is compared to obtain the largest one, which is determined as the target first network address segment and modified to obtain the second network address segment and replace the third target network address segment to obtain the second IP address; wherein, if the target IP address is different from the first two network segments of other IP addresses in the IP address list, it indicates that the network segment corresponding to the network bridge interface of the container to be configured is different from the network segment corresponding to the host machine, and no additional configuration is required, and the target IP address is directly saved, and it is subsequently directly configured to the network bridge interface of the container to be configured.
[0135]
[0136]
[0137]
[0138] For example, if a network bridge interface has been created on the host, the target IP address of the network bridge interface is read, and it is determined whether the target IP address is in the same network segment as the first IP address of the host. If they are in the same network segment, the network segment of the network bridge interface of the container to be configured is modified. Specifically, the first interval of the network bridge interface can be modified by the following method to achieve the purpose of modifying the network segment of the network bridge interface of the container to be configured.
[0139] if["$has_container_interface"=="true"];then / / The container network bridge interface has been created on the host
[0140] container_bridge_IP = `ifconfig$container_bridge|grep'inet'|awk'{print$2}'` / / Read the IP address of the network bridge interface
[0141] host_IPs = $(hostname-I) # Get the host's IP address list
[0142] IFS="read-ra host_IP_array<<<"$host_IPs"
[0143] For example, when a network bridge interface for the container to be configured has been created in the host machine, the following method is used to directly obtain the first intervals in which the first two network segments in the IP address list (the first network address segment corresponding to the first arrangement number) and the first two network segments of the target IP address of the network bridge interface are the same, and these first intervals are determined as the target first intervals. Compare the third first network address segments in these target first intervals, obtain the largest one, determine it as the target first network address segment and modify it to obtain the second network address segment, determine the second network address segment as the updated target network address segment, and use it to replace the third target network address segment to obtain the second IP address; wherein, if the target IP address is different from the first two network segments of other IP addresses in the IP address list, it indicates that the network segment corresponding to the network bridge interface of the container to be configured is different from the network segment corresponding to the host machine, and no additional configuration is required. The target IP address is directly saved and subsequently directly configured to the network bridge interface of the container to be configured:
[0144]
[0145]
[0146]
[0147] By traversing the first IP address of the host network, the comparison result of the first interval between each first IP address and the target IP address of the network bridge interface corresponding to the container to be configured is obtained, and the IP address of the network bridge interface of the container to be configured is dynamically modified according to the comparison result to avoid the network bridge interface of the container to be configured being in the same network segment as the host network and affecting the host network.
[0148] Furthermore, after configuring the second IP address for the network bridge interface of the container to be configured according to the method of the above embodiment, the container to be configured needs to be further configured to ensure normal communication of the container to be configured. The following is an exemplary description of the method for configuring the IP address for the container to be configured.
[0149] For example, when the container connected to the network bridge interface is only the container to be configured, after step 207, the following steps may also be included:
[0150] Step 208, modify the second interval of the second IP address to obtain a third IP address.
[0151] To ensure normal communication between containers, the container needs to be in the same network segment as its corresponding network bridge interface. Modify the second interval of the second IP address to obtain a third IP address. The third IP address has the same first interval as the second IP address, but a different second interval. That is, the network segment of the third IP address is in the same network segment as the second IP address, but the IP addresses are different.
[0152] Step 209: configure the third IP address to the container to be configured.
[0153] An IP address is assigned to the container to be configured. The IP address of the container to be configured needs to be on the same network segment as the corresponding network bridge interface to ensure normal communication between the container to be configured and the host. The third IP address obtained according to the method of this embodiment is in the same network segment as the second IP address of the network bridge interface, thereby ensuring normal communication of the container to be configured.
[0154] For example, the third IP address can be set for the container to be configured according to the following method:
[0155] IFS = '.' read -ra container_parts <<< "$container_bridge_IP" / / Separate the container network bridge interface IP into an array
[0156] four_octet = "${container_parts[3]}" / / Read the fourth network segment of the container's network bridge interface IP
[0157] ((four_octet++)) / / Add 1 to the 4th network segment number
[0158] container_IP="${container_parts[0]}.${container_parts[1]}.${container_parts[2]}.$four_octet"
[0159] lxc-attach-n container1 / / Enter the container
[0160] IP addr add$container_IP / 24dev eth0 / / Assign the third IP address to the container
[0161] route add-net$host_nat / 24gw$container_IP dev eth0
[0162] exit / / Exit the container
[0163] In one embodiment, the first interval of the fourth IP address corresponding to other containers of the container connected to the network bridge interface is the same as the first interval of the second IP address.
[0164] In this case, after step 207, the following steps may also be included:
[0165] Step 210, compare the second interval of the second IP address with the second interval of the fourth IP address to obtain the maximum second interval, and perform a sum operation on the maximum second interval and the preset second interval to obtain a target second interval, or compare the second interval of the second IP address with the second interval of the fourth IP address to obtain the minimum second interval, and perform a difference operation on the minimum second interval and the preset second interval to obtain the target second interval.
[0166] The first interval of the containers corresponding to the same network bridge interface is the same. Other containers are containers corresponding to the network bridge interface. Therefore, their fourth IP addresses are the same as the first interval of the second IP address of the network bridge interface.
[0167] The IP addresses of the containers corresponding to the same network bridge interface are different, and the IP address of each container is different from the IP address of the corresponding network interface address. Therefore, the second interval of the second IP address of the network bridge interface and the second interval of the fourth IP address of other containers are obtained. The IP address of the container to be configured can be obtained by modifying the second interval.
[0168] Before this step, it also includes: obtaining the second interval of the second IP address and the second interval of the fourth IP address. For example, if the second IP address of the network bridge interface is 192.168.9.10, its second interval is 10; the network bridge interface is connected to three other containers, and the fourth IP addresses of these three other containers are 192.168.9.20, 192.168.9.100 and 192.168.9.101, and the second intervals of these three fourth IP addresses are 20, 100 and 101 respectively.
[0169] In this embodiment, the maximum value in the second interval of the second IP address and the three fourth IP addresses is 101, and the minimum value is 10. The maximum value 101 and the preset address segment can be summed to obtain the target second interval; for example, the maximum value 101 and the preset address segment 1 are summed to obtain the target second interval 102. The minimum value 20 and the preset address segment can also be subtracted to obtain the target second interval, for example, the minimum value 10 and the preset address segment 1 are subtracted to obtain the target second interval 9.
[0170] Step 211, concatenate the first interval of the second IP address and the target second interval to obtain a third IP address.
[0171] For example, in the embodiment shown in step 210, the second IP address is 192.168.9.10, and the obtained target second interval is 9 or 102. The first interval of the second IP address is 192.168.9, and the first interval of the second IP address and the target second interval are concatenated to obtain the third IP address of the container to be configured as 192.168.9.9 or 192.168.9.102.
[0172] The target second interval is different from the second interval of the second IP address and the second interval of the fourth IP address. Therefore, by concatenating the first interval of the second IP address and the target second interval, a third IP address can be obtained that is in the same network segment as the network bridge interface but is different from the second IP address and the fourth IP address.
[0173] Step 212: configure the third IP address to the container to be configured.
[0174] If only the network bridge interface of the container is set on the host, and the IP address of the container is not set, multiple containers and the container and the external network still cannot communicate. In the related art, when the lxc and lxc-templates packages are installed on some operating systems, the network bridge interface of the container and the IP address information of the network interface will be set on the host, but there is no method to automatically set the IP address of the container. In the related art, it is necessary to manually set the IP address for the container to be configured.
[0175] By using the method of this embodiment, an IP address can be automatically set for the container to be configured, and it can be ensured that the IP address configured for the container to be configured and the IP address of the corresponding network bridge interface are located in the same network segment and are different from each other. Thus, normal communication of the container to be configured can be ensured.
[0176] Furthermore, after configuring the IP address for the container to be configured, the following steps may also be included:
[0177] On the host, set the policy of the INPUT and OUTPUT chains of the network bridge interface firewall (iptables) to ACCEP. Set the policy of the INPUT and OUTPUT chains of iptables to ACCEP on the network bridge interface on the host to ensure that data packets between the host and the container are allowed to pass.
[0178] For example, you can set the policy of the INPUT and OUTPUT chains of the network bridge interface iptables to ACCEP in the following way. ACCEP means that data packets between the host and the container are allowed to pass:
[0179] iptables -wI INPUT -i lxcbr0 -j ACCEPT / / Allow all traffic entering the host through the lxcbr0 interface and ping the host in the container
[0180] iptables -w -IOUTPUT -o lxcbr0 -j ACCEPT / / Allow all traffic sent out through the lxcbr0 interface on the host, and ping the container on the host
[0181] When the host and the container communicate, if the destination IP address of the data packet received by the host is not the IP address of the host, the data packet is forwarded through the FORWARD chain of iptables. For example, when accessing Baidu from within the container, or communicating between containers, or when the container accesses other IP addresses in the same network segment as the host, it is necessary to forward through the FORWARD chain.
[0182] When a container in bridge mode created based on LXC technology communicates with other IP addresses, it needs to be forwarded through the network bridge interface, so all traffic passing through the network bridge interface in the FORWARD chain needs to be allowed. For example, the FORWARD chain is set up as follows:
[0183] iptables -wI FORWARD -i "$container_bridge" -j ACCEPT / / Allow packets to be sent from the container
[0184] iptables-wI FORWARD-o"$container_bridge"-j ACCEPT / / Allow sending to the container from the outside
[0185] After setting the second IP address of the network bridge interface of the container to be configured, setting the IP address of the container to be configured, setting the ACCEP policy of the INPUT and OUTPUT chains of the network bridge interface iptables, and setting the FORWARD chain, the container to be configured can communicate normally. However, the source address of the data packet sent at this time is still the internal address of the container to be configured, rather than the public address of the container to be configured on the external network. In order to ensure that other devices on the external network can correctly respond to the data packets sent by the container and realize two-way communication between the container and the external network, it is also necessary to perform network address translation on the source address of the data packet, and perform address translation on the internal address of the container to be configured and replace it with the public address.
[0186] For example, the source address can be converted by the following method:
[0187] IFS = '.' read -ra container_parts <<< "$container_bridge_IP" / / Separate the container network bridge interface IP into an array
[0188] container_nat="${container_parts[0]}.${container_parts[1]}.${container_parts[2]}.0"
[0189] iptables-wt nat-A POSTROUTING-s"$container_nat / 24"! -d"$container_nat / 24"-j MASQUERADE
[0190] The above method replaces the source address of the container with the public address of the host on the external network. As a result, when the data packet sent by the container reaches the external network, the device on the external network can respond correctly, thereby realizing two-way communication between the container and the external network.
[0191] For example, before step 201, the method further includes:
[0192] Step 213, obtaining the first file.
[0193] Specifically, the first file is used to store initialization information of the container to be configured.
[0194] For example, the initialization information may include resource allocation information for the container to be configured, for example, the memory size, disk space size, etc. occupied by the container to be configured.
[0195] For example, by reading the content of the / proc / 1 / cgroup file and using the cat command to determine whether the content of the file is empty, it is determined whether the control group (Cgroup) function has been enabled in the operating system of the host machine according to the determination result.
[0196] For example, if the first file is empty, it is determined that the host operating system has not started the control group function, and the control group function is turned on to write initialization information in the first file; if the content of the / proc / 1 / cgroup file is empty, it means that the host operating system has not turned on the Cgroup function, and the cgroup file system needs to be mounted. After mounting, the system automatically starts the cgroup function.
[0197] The Cgroup file system is a file provided by the operating system kernel, which is used to control the CPU, memory and other resources occupied by the container, and can also be used to control the priority order of process execution. Some operating systems (for example, the alpine system) do not mount the Cgroup file system by default. Correspondingly, the content of the / proc / 1 / cgroup file is empty, and the host operating system does not enable the Cgroup function. In this case, the user needs to mount the Cgroup file system.
[0198] Compared with other virtualization technologies, LXC technology has low overhead in creating and managing containers, and can also limit and control the resources of containers. For example, you can limit and control the CPU, memory, disk and other resources used by containers. In other words, based on LXC technology, you can effectively manage resources when running multiple containers on a shared host.
[0199] Furthermore, the methods of step 212 and step 213 can be implemented by the following method:
[0200] file = " / proc / 1 / cgroup" / / Set the file to be read
[0201] if["$(cat file|wc -c)" -eq 0]; then / / compare the file content to see if it is 0
[0202] mount-t cgroup2 cgroup2 / sys / fs / cgroup / / Mount the cgroup file system (the system has started the cgroup function after mounting)
[0203] else
[0204] echo "cgroup function is enabled"
[0205] When cgroup is not enabled on the system, the cgroup function of the system is automatically enabled to avoid initialization failure when the container is started.
[0206] Step 214, obtaining a container configuration file template of the container to be configured; the container configuration file template is used to store configuration information of the container to be configured.
[0207] Install the command (lxc) and container configuration file template (lxc-templates) on the current system, and select the corresponding template file according to the type of the current operating system.
[0208] For example, step 214 may include the following sub-steps:
[0209] Sub-step 2141, obtaining the target operating system type of the container to be configured.
[0210] The target operating system type can be set according to user needs, for example, it can be alpine, centos, or other operating systems.
[0211] Sub-step 2142, according to the correspondence between the preset operating system type and the preset container configuration file template, obtain the container configuration file template corresponding to the target operating system type.
[0212] For example, if the preset target operating system is the debian operating system, then according to the correspondence between the preset operating system type and the preset container configuration file template, the container configuration file template corresponding to the operating system is the lxc-debian template file. For example, the full path corresponding to the template file can be / usr / local / share / lxc / templates / lxc-debian. For another example, if the preset target operating system is the alpine operating system, then according to the correspondence between the preset operating system type and the preset container configuration file template, the container configuration file template corresponding to the operating system is the lxc-alpine template file.
[0213] For example, a container configuration file template of a container to be configured may be created according to the container configuration file template in the following manner:
[0214] lxc-create-n container1-t lxc-debian / / -n: the name of the created container, -t: container template file
[0215] Step 215: Create a container to be configured according to the initialization information and the container configuration file template.
[0216] For example, the container is initialized according to the initialization information in the first file, and the parameters of the container to be configured are configured according to the configuration information in the container configuration file template to obtain a created container to be configured.
[0217] Step 216, enable the IP forwarding function of the host machine and the IP forwarding function of the container to be configured. When configuring the container network, the IP forwarding function needs to be enabled to ensure normal communication of the container network.
[0218] The container to be configured runs in the host machine, and the IP forwarding function is the master switch for the communication of the container to be configured. If the IP forwarding function is not enabled, even if the IP address and other information of the container to be configured and the network bridge interface are correctly configured, the container to be configured cannot communicate normally with the host machine or other containers.
[0219] If the IP forwarding function is not enabled, even if the steps of the aforementioned embodiment are executed to configure the network bridge interface of the container to be configured and the container network, the configured container cannot communicate normally with the external network and the host machine. In the related art, developers or users usually miss the activation of the IP forwarding function, especially for those who are not familiar with the network. If the IP forwarding function is not enabled, it usually takes a lot of time to identify the error caused by not enabling the IP forwarding function.
[0220] For example, you can enable IP forwarding by:
[0221] sudo sysctl-w net.ipv4.ip_forward=1
[0222] Creating a container based on LXC technology has the advantage of simple commands, but the related technology lacks a method for configuring the network of the container after creating the container based on LXC technology. Therefore, when developers use lxc to create containers, they usually need to invest a lot of time to learn about container network configuration and how to apply the container network configuration to lxc.
[0223] In addition, in the related art, when deploying container services on multiple machines, it is necessary to manually and repeatedly set up the container network for each machine. This method will result in repeated waste of time, resulting in low configuration efficiency, and manually setting the IP address of the container network is prone to the problem of incorrect IP address setting. In the related art, after some operating systems reinstall LXC or LXC-templates packages, the network bridge interface of the container and the IP address of the network bridge interface will be set on the host machine. However, this method can only set the network bridge interface of the container on the host, and cannot automatically set the IP address of the container. For the started container, the IP address of the container still needs to be set manually.
[0224] An embodiment of the present application provides a container configuration method, which can automatically and accurately perform network configuration on the container to be configured, including: performing IP address configuration on the network bridge interface of the container to be configured, performing IP address configuration on the container to be configured, enabling the Cgroup function of the container to be configured, enabling the IP forwarding function, setting policies for the INPUT and OUTPUT chains of the network bridge interface iptables, and setting the FORWARD chain of the network bridge interface iptables.
[0225] Based on the method of this application, people who are not familiar with lxc technology and container network can quickly and accurately configure container network. Figure 4 , the container configuration method of the embodiment of the present application is further illustrated. Figure 4 , the method may include the following steps:
[0226] Step S1, determine whether the host system has started the Cgroup function. If not, go to step S2, otherwise directly go to step S3.
[0227] Read the contents of the / proc / 1 / cgroup file and use the cat command to determine whether the contents of the file are empty. If so, the Cgroup function is not enabled. Otherwise, the Cgroup function is enabled.
[0228] Step S2, start the Cgroup function.
[0229] Start the Cgroup function by mounting the cgroup file system.
[0230] Step S3: obtaining a container configuration file template of the container to be configured, and creating the container to be configured by using the container configuration file template of the container to be configured.
[0231] Install lxc and lxc-templates packages on the current host operating system, and select the corresponding container configuration file template for the container to be configured according to the type of the current operating system. Then create the container to be configured according to the following method: lxc-create-n container1-t lxc-debian.
[0232] Step S4, enable the IP forwarding function to enable normal communication in the container network.
[0233] For example, enable the IP forwarding function by the following method: sudo sysctl -w net.IPv4.IP_forward=1.
[0234] Step S5, determining whether there is a network bridge interface corresponding to the container to be configured on the host system, if so, proceeding to step S7, otherwise directly proceeding to step S6.
[0235] Use grep and awk techniques to extract the name of the network bridge interface in the container configuration file / var / lib / lxc / container1 / config.
[0236] Furthermore, we can determine whether there is a network bridge interface corresponding to the container by using the variable has_container_interface:
[0237]
[0238] Step S6: create a container to be configured on the host system, obtain its corresponding network bridge interface, and assign a target IP address to it.
[0239] The method of this step has been described in the aforementioned step 204 and will not be repeated here.
[0240] Step S7, obtaining an IP address list in the host machine.
[0241] The IP address list includes at least one first IP address.
[0242] Step S8, traverse the first IP address in the IP address list, and determine whether the first interval of the target IP address is the same as the first interval of the first IP address in the IP address list. If they are the same, proceed to step S9, otherwise proceed to step S10.
[0243] The first interval of the target IP address is the same as the first interval of any first IP address in the IP address list, indicating that the network bridge interface and the host or other network bridge interfaces are in the same network segment, and routing conflicts are likely to occur during the communication process of the container to be configured. Otherwise, it means that the network bridge interface and the host and other network bridge interfaces are not in the same network segment, and routing conflicts will not occur during the communication process of the container to be configured.
[0244] Step S9, update the first interval of the target IP address to obtain the second IP address. Then proceed to step S11.
[0245] For example, the first interval of each first IP address in the IP address list is obtained, and the first and second first network address segments are obtained from the first interval of the first IP address, which correspond to the same target first interval as the first and second target network address segments of the target IP address.
[0246] If there is only one target first interval, the third network address segment of the target IP address is directly increased by 1 to obtain the second IP address.
[0247] If there are multiple target first intervals, the third target network address segment of the target IP address can be updated according to the method of sub-steps 2051 to sub-steps 2053 to obtain the second IP address.
[0248] Step S10: directly determine the target IP address as the second IP address.
[0249] If the first interval of the target IP address and the first interval in the IP address list are different, it means that the first interval of the network bridge interface and the first IP address in the IP address list are not in the same network segment. There is no need to modify the first interval of the target IP address, and the target IP address can be directly determined as the second IP address.
[0250] Step S11: configure the second IP address to the network bridge interface of the container to be configured.
[0251] The method of this step can refer to the description of the aforementioned step 208 and will not be repeated here.
[0252] Step S12, starting the network bridge interface.
[0253] Start the network bridge interface by: ifconfig$container_bridge up.
[0254] Step S13: According to the second IP address configured to the network bridge interface, a third IP address whose first interval is the same as the second IP address and whose second interval is different from the second IP address is obtained, and the third IP address is allocated to the container to be configured.
[0255] The method of this step has been described in the aforementioned steps 209 to 210, and the aforementioned steps 211 to 215, and will not be repeated here.
[0256] Step S14, on the host machine, set the policies of the INPUT and OUTPUT chains of the network bridge interface iptables to ACCEP to ensure communication between the container and the host.
[0257] For example, you can set the strategies for the INPUT and OUTPUT chains as follows:
[0258] iptables -wI INPUT -i lxcbr0 -j ACCEPT / / Allow all traffic entering the host through the lxcbr0 interface and ping the host in the container
[0259] iptables -w -IOUTPUT -o lxcbr0 -j ACCEPT / / Allow all traffic sent out through the lxcbr0 interface on the host, and ping the container on the host
[0260] Step S15, setting the FORWARD chain of the network bridge interface iptables to allow the network bridge interface to pass all traffic data to ensure communication between containers in the host machine and between the container and the external network.
[0261] Furthermore, the source address of the container will be replaced with the public address of the host on the external network. Therefore, when the data packet sent by the container reaches the external network, the device on the external network can respond correctly, thereby realizing communication between the container and the external network.
[0262] For example, set the iptables FORWARD chain as follows:
[0263] iptables -wI FORWARD -i "$container_bridge" -j ACCEPT / / Allow packets to be sent out from the container
[0264] iptables-wI FORWARD-o"$container_bridge"-j ACCEPT / / Allow sending to the container from the outside
[0265] The method of this embodiment can realize automatic configuration of container network according to the differences between lxc and lxc-templates of different systems, avoid the time-consuming and error-prone problems of developers or users repeatedly manually configuring the network and locating network problems, and provide a method for users who are not familiar with lxc and network content to quickly configure containers.
[0266] Figure 5 is a block diagram of a container configuration device provided by an embodiment of the present invention, such as Figure 5 As shown, the device 30 includes: a first acquisition module 301, used to obtain the IP address list of the host machine and the target IP address of the network bridge interface; the network bridge interface corresponds to the container to be configured in the host machine, and the IP address list includes the first IP address corresponding to the host machine; an update module 302, used to modify the first interval of the target IP address to obtain a second IP address if the first interval of the target IP address is the same as the first interval of the first IP address; the first interval is used to identify the network address; a replacement module 303, used to replace the target IP address with the second IP address, so that the host machine can communicate with the container to be configured based on the second IP address.
[0267] Optionally, the first interval of the target IP address includes at least one target network address segment arranged in sequence, and each target network address segment has its own corresponding arrangement number; the update module 302 may include: a first acquisition submodule, used to acquire the target network address segment corresponding to the preset arrangement number from at least one target network address segment; the preset arrangement number is one or more of the arrangement numbers; a first update submodule, used to modify the target network address segment corresponding to the preset arrangement number to obtain an updated target network address segment; a second acquisition submodule, used to splice the updated target network address segment, other target network address segments except the target network address segment corresponding to the preset arrangement number, and the second interval in the target IP address to obtain a second IP address; the second interval is used to identify the device address.
[0268] Optionally, the IP address list also includes: the first IP address of other network bridge interfaces in the host machine; the first interval of the first IP address includes multiple first network address segments arranged in sequence; the first update submodule may include: a first acquisition unit, used to acquire at least one target first interval from the first intervals of multiple first IP addresses; the first network address segment corresponding to the first arrangement number in the target first interval is the same as the target network address segment corresponding to the first arrangement number; the first arrangement number is an arrangement number other than the preset arrangement number; the target first interval is used to generate an updated target network address segment; a second acquisition unit, used to acquire the target first network address segment from the first network address segment corresponding to the preset arrangement number in the target first interval and modify it to obtain a second network address segment; a third acquisition unit, used to determine the second network address segment as the updated target network address segment.
[0269] Optionally, the second acquisition unit may include: a first acquisition sub-unit, used to obtain the target first network address segment with the largest value from the first network address segments corresponding to the target first interval and the preset arrangement number, and perform a sum operation based on the target first network address segment to obtain the second network address segment; or, a second acquisition sub-unit, used to obtain the target first network address segment with the smallest value from the first network address segments corresponding to the target first interval and the preset arrangement number, and perform a difference operation based on the target first network address segment to obtain the second network address segment.
[0270] Optionally, the first acquisition module 301 may include: a third acquisition sub-module, used to obtain a container configuration file of the container to be configured, and extract the interface name of the network bridge interface from the container configuration file; a fourth acquisition sub-module, used to create a network bridge interface in the host machine if the interface name of the network bridge interface is different from the interface names of all created network bridge interfaces in the host machine, and set a target IP address for the network bridge interface.
[0271] Optionally, the device 30 further includes: a modification module, used to modify the second interval corresponding to the second IP address to obtain a third IP address; and a first configuration module, used to configure the third IP address to the container to be configured.
[0272] Optionally, the first interval of the fourth IP address corresponding to other containers connected to the network bridge interface is the same as the first interval of the second IP address; then, the device 30 also includes: a second acquisition module, used to compare the second interval of the second IP address and the second interval of the fourth IP address to obtain the maximum second interval, and sum the maximum second interval and the preset second interval to obtain the target second interval; or, a fourth acquisition module, used to compare the second interval of the second IP address and the second interval of the fourth IP address to obtain the minimum second interval, and subtract the minimum second interval from the preset second interval to obtain the target second interval; a fifth acquisition module, used to concatenate the first interval of the second IP address and the target second interval to obtain a third IP address, and configure the third IP address to the container to be configured.
[0273] Optionally, the device 30 also includes: a sixth acquisition module, used to acquire the first file; the first file is used to store initialization information of the container to be configured; a seventh acquisition module, used to acquire a container configuration file template of the container to be configured; the container configuration file template is used to store configuration information of the container to be configured; and a determination module, used to create the container to be configured according to the initialization information and the configuration information in the container configuration file template.
[0274] Optionally, the device 30 further includes: an enabling module, configured to enable the IP forwarding function of the host machine and the IP forwarding function of the container to be configured after the container to be configured is created.
[0275] This embodiment realizes automatic configuration of the IP address of the network bridge interface, and can ensure that the network segment of the second IP address of the network bridge interface is different from the network segment of the first IP address of the host machine, and is also different from the network segment of the first IP address of other network bridge interfaces. The container to be configured communicates based on the second IP address, and there will be no routing conflict problem, which can ensure the normal communication of the container to be configured. The problem of low efficiency and easy error when configuring the IP address of the network bridge interface corresponding to the container in the related art is solved.
[0276] Reference Figure 6, the electronic device 400 may include one or more of the following components: a processing component 402, a memory 404, a power component 406, a multimedia component 408, an audio component 410, an input / output (I / O) interface 412, a sensor component 414, and a communication component 416. The processing component 402 generally controls the overall operation of the electronic device 400, such as operations associated with display, phone calls, data communications, camera operations, and recording operations. The processing component 402 may include one or more processors 420 to execute instructions to complete all or part of the steps of the above-mentioned method. In addition, the processing component 402 may include one or more modules to facilitate the interaction between the processing component 402 and other components. For example, the processing component 402 may include a multimedia module to facilitate the interaction between the multimedia component 408 and the processing component 402.
[0277] The memory 404 is used to store various types of data to support the operation of the electronic device 400. Examples of such data include instructions for any application or method operating on the electronic device 400, contact data, phone book data, messages, pictures, multimedia, etc. The memory 404 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, magnetic disk or optical disk. The power supply component 406 provides power to various components of the electronic device 400. The power supply component 406 may include a power management system, one or more power supplies, and other components associated with generating, managing and distributing power for the electronic device 400. The multimedia component 408 includes an interface that provides an output interface between the electronic device 400 and the user. In some embodiments, the interface may include a liquid crystal display (LCD) and a touch panel (TP). If the interface includes a touch panel, the interface may be implemented as a touch screen to receive input signals from the user. The touch panel includes one or more touch sensors to sense touch, slide and gestures on the touch panel. The touch sensor can not only sense the boundary of the touch or slide action, but also detect the duration and pressure associated with the touch or slide operation. In some embodiments, the multimedia component 408 includes a front camera and / or a rear camera.
[0278] The input / output I / O interface 412 provides an interface between the processing component 402 and the peripheral interface module, which may be a keyboard, a click wheel, a button, etc. These buttons may include, but are not limited to, a home button, a volume button, a start button, and a lock button. The sensor component 414 includes one or more sensors for providing various aspects of status assessment for the electronic device 400. For example, the sensor component 414 can detect the open / closed state of the electronic device 400, the relative positioning of components, such as the display and keypad of the electronic device 400, and the sensor component 414 can also detect the position change of the electronic device 400 or a component of the electronic device 400, the presence or absence of contact between the user and the electronic device 400, the orientation or acceleration / deceleration of the electronic device 400, and the temperature change of the electronic device 400.
[0279] The communication component 416 is used to facilitate wired or wireless communication between the electronic device 400 and other devices. The electronic device 400 can access a wireless network based on a communication standard, such as WiFi, an operator network (such as 2G, 3G, 4G or 5G), or a combination thereof.
[0280] In an exemplary embodiment, the electronic device 400 may be implemented by one or more application-specific integrated circuits (ASICs), digital signal processors (DSPs), digital signal processing devices (DSPDs), programmable logic devices (PLDs), field programmable gate arrays (FPGAs), controllers, microcontrollers, microprocessors, or other electronic components to implement a container configuration method provided in an embodiment of the present application.
[0281] Figure 7 is a block diagram of an electronic device 500 according to another embodiment of the present invention. For example, the electronic device 500 may be provided as a server. Figure 7 , the electronic device 500 includes a processing component 522, which further includes one or more processors, and a memory resource represented by a memory 532 for storing instructions that can be executed by the processing component 522, such as an application. The application stored in the memory 532 may include one or more modules, each corresponding to a set of instructions. In addition, the processing component 522 is configured to execute instructions to execute a container configuration method provided in an embodiment of the present application. The electronic device 500 may also include a power supply component 526 configured to perform power management of the electronic device 500, a wired or wireless network interface 550 configured to connect the electronic device 500 to a network, and an input / output (I / O) interface 558. The electronic device 500 can operate based on an operating system stored in the memory 532, such as Windows ServerTM, MacOS XTM, UnixTM, LinuxTM, FreeBSDTM or the like.
[0282] An embodiment of the present invention further provides a computer program product, including a computer program, and a container configuration method implemented when the computer program is executed by a processor.
[0283] Those skilled in the art will readily appreciate other embodiments of the present invention after considering the specification and practicing the invention disclosed herein. The present invention is intended to cover any variations, uses or adaptations of the present invention, which follow the general principles of the present invention and include common knowledge or customary techniques in the art that are not disclosed in the present disclosure. The specification and examples are intended to be exemplary only, and the true scope and spirit of the present invention are indicated by the following claims. It should be understood that the present invention is not limited to the precise structure described above and shown in the accompanying drawings, and various modifications and changes can be made without departing from the scope thereof. The scope of the present invention is limited only by the appended claims.
Claims
1. A container configuration method, characterized in that: include: Get the host's IP address list and the target IP address of the network bridge interface; The network bridge interface corresponds to the container to be configured in the host machine, and the IP address list includes a first IP address corresponding to the host machine; If the first interval of the target IP address is the same as the first interval of the first IP address, modify the first interval of the target IP address to obtain a second IP address; the first interval is used to identify a network address; The target IP address is replaced with the second IP address, so that the host machine can communicate with the container to be configured based on the second IP address.
2. The method according to claim 1, characterized in that The first interval of the target IP address includes at least one target network address segment arranged in sequence, and each of the target network address segments has a corresponding arrangement sequence number; Then, modifying the first interval of the target IP address to obtain the second IP address includes: From at least one target network address segment, obtain a target network address segment corresponding to a preset arrangement sequence number; the preset arrangement sequence number is one or more of the arrangement sequence numbers; Modifying the target network address segment corresponding to the preset arrangement sequence number to obtain an updated target network address segment; The updated target network address segment, other target network address segments except the target network address segment corresponding to the preset arrangement number, and the second interval in the target IP address are concatenated to obtain the second IP address; the second interval is used to identify the device address.
3. The method according to claim 1 or 2, characterized in that: The IP address list also includes: first IP addresses of other network bridge interfaces in the host machine; the first interval of the first IP address includes a plurality of first network address segments arranged in sequence; Then, the modifying the target network address segment corresponding to the preset arrangement sequence number to obtain an updated target network address segment includes: At least one target first interval is obtained from the first intervals of the plurality of first IP addresses; the first network address segment corresponding to the first permutation sequence number in the target first interval is the same as the target network address segment corresponding to the first permutation sequence number; the first permutation sequence number is a permutation sequence number other than the preset permutation sequence number; the target first interval is used to generate an updated target network address segment; From the first network address segments corresponding to the target first interval and the preset arrangement sequence number, obtain the target first network address segment and modify it to obtain the second network address segment; The second network address segment is determined as the updated target network address segment.
4. The method according to claim 3, characterized in that The step of obtaining and modifying the target first network address segment includes: From the first network address segments corresponding to the target first interval and the preset arrangement sequence number, obtain the target first network address segment with the largest value, and perform a sum operation based on the target first network address segments to obtain the second network address segment; or, From the first network address segments corresponding to the target first interval and the preset arrangement number, the target first network address segment with the smallest value is obtained, and a difference operation is performed based on the target first network address segment to obtain the second network address segment.
5. The method according to claim 1, characterized in that The method further comprises: Modify the second interval corresponding to the second IP address to obtain a third IP address; The third IP address is configured to the container to be configured.
6. The method according to claim 1, characterized in that The first interval of the fourth IP address corresponding to other containers connected to the network bridge interface is the same as the first interval of the second IP address; then, the method further includes: Compare the second interval of the second IP address with the second interval of the fourth IP address to obtain a maximum second interval, and perform a sum operation on the maximum second interval and a preset second interval to obtain a target second interval; or, Compare the second interval of the second IP address with the second interval of the fourth IP address to obtain a minimum second interval, and perform a difference operation on the minimum second interval and a preset second interval to obtain a target second interval; The first interval of the second IP address and the target second interval are concatenated to obtain a third IP address, and the third IP address is configured to the container to be configured.
7. The method according to claim 1, characterized in that Get the target IP address of the network bridge interface, including: Obtaining a container configuration file of the container to be configured, and extracting an interface name of the network bridge interface from the container configuration file; If the interface name of the network bridge interface is different from the interface names of all the network bridge interfaces created in the host machine, the network bridge interface is created in the host machine, and a target IP address is set for the network bridge interface.
8. The method according to claim 1, characterized in that The method further comprises: Obtain a first file; the first file is used to store initialization information of the container to be configured; Acquire a container configuration file template of the container to be configured; the container configuration file template is used to store configuration information of the container to be configured; The container to be configured is created according to the initialization information and the configuration information in the container configuration file template.
9. A container configuration device, characterized in that: include: A first acquisition module is used to obtain a list of IP addresses of the host machine and a target IP address of the network bridge interface; The network bridge interface corresponds to the container to be configured in the host machine, and the IP address list includes a first IP address corresponding to the host machine; An update module, configured to modify the first interval of the target IP address to obtain a second IP address if the first interval of the target IP address is the same as the first interval of the first IP address; the first interval is used to identify a network address; A replacement module is used to replace the target IP address with the second IP address, so that the host machine can communicate with the container to be configured based on the second IP address.
10. An electronic device, characterized in that: The invention comprises a processor; and one or more programs, wherein the one or more programs are stored in a memory and are configured to be executed by the one or more processors, wherein the one or more programs include instructions for performing the following operations: Obtain an IP address list of the host machine and a target IP address of a network bridge interface; the network bridge interface corresponds to a container to be configured in the host machine, and the IP address list includes a first IP address corresponding to the host machine; If the first interval of the target IP address is the same as the first interval of the first IP address, modify the first interval of the target IP address to obtain a second IP address; The target IP address is replaced with the second IP address, so that the host machine can communicate with the container to be configured based on the second IP address.
11. A readable storage medium, characterized in that: When the instructions in the readable storage medium are executed by a processor of an electronic device, the electronic device is enabled to execute the method as claimed in any one of claims 1 to 8.
Citation Information
Cited By
Power concentrator application system for container partitioning based on business function
CN121807617A
Power concentrator application system based on service function for container partitioning
CN121807617B