Data forwarding method and device, storage medium and program product

By setting up virtual machine programs to intercept and redirect data forwarding requests in the kernel space, the problems of service exceptions and port forwarding rules bloat caused by container group scheduling nodes are solved, and the effect of improving data forwarding efficiency and reducing network delay is achieved.

CN120090970AActive Publication Date: 2025-06-03JINAN INSPUR DATA TECH CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
CN202510536688.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-27
Publication Date
2025-06-03
Estimated Expiration
2045-04-27

AI Technical Summary

Technical Problem

The container group scheduling nodes lead to service exceptions, and the need to configure more port forwarding rules on the nodes as the service scale increases, resulting in a decrease in forwarding efficiency.

Method used

Data forwarding is completed by setting the virtual machine program to intercept data forwarding requests at preset locations in the kernel space and redirecting according to the target mapping relationship table and the port value of the target node.

Benefits of technology

Improve data forwarding efficiency, reduce network delay, and avoid service abnormalities caused by container group scheduling nodes.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120090970A_ABST
    Figure CN120090970A_ABST
Patent Text Reader

Abstract

The invention discloses a data forwarding method and device, a storage medium and a program product, and relates to the technical field of computer network communication, and the method comprises the steps: intercepting a data forwarding request belonging to a current node through a virtual machine program arranged in front of a kernel protocol stack; according to a port value of a target node in the data forwarding request and a target mapping relation table, the virtual machine program is used for redirecting the data forwarding request to complete data forwarding, and the target mapping relation table is used for describing the corresponding relation between the port value of the node and the position parameter of the container; the position parameters of the container at least comprise an internet protocol address and a port value of the container, the technical problems that service abnormity is caused by scheduling nodes of the container group and the forwarding efficiency is reduced due to the fact that more port forwarding rules need to be configured on the nodes along with the increase of the service scale are solved, and the purposes of improving the data forwarding efficiency and reducing the forwarding cost are achieved. And the network time delay is reduced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer network communication technologies, and particularly to a data forwarding method, device, storage medium, and program product. Background Art

[0002] In scenarios such as edge computing or when specific port exposure services are required, containers need to directly use node ports, which is generally achieved through the hostPort (a configuration option for mapping node ports to internal container ports) function provided by the container cluster. The traditional hostPort function is implemented by a specific container network interface and relies on mechanisms such as iptables (a firewall tool for managing packet filtering and forwarding). By configuring iptables rules on the node, packets are redirected to the internal container port. However, as the service scale increases, the number of iptables rules may rapidly expand, resulting in performance degradation. At the same time, the flexibility of managing and updating the rules is also poor. And due to the uncertainty of container group scheduling nodes, when containers with the same hostPort are scheduled to the same node, service exceptions will occur. Summary of the Invention

[0003] This application provides a data forwarding method, device, storage medium, and program product to at least solve the problems in the related art that service exceptions are caused by container group scheduling nodes, and as the service scale increases, more port forwarding rules need to be configured on the node, resulting in a decrease in forwarding efficiency.

[0004] This application provides a data forwarding method applied to at least one node in a container cluster. The data forwarding method includes: In response to receiving a data forwarding request, parsing the data forwarding request to obtain target node information, where the target node information at least includes the Internet Protocol (IP) address and port value of the target node; Obtaining the IP address of the current node and comparing the IP address of the current node with the IP address of the target node; In response to a successful comparison, intercepting the data forwarding request using a virtual machine program, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack; In response to a successful interception, redirecting the data forwarding request using the virtual machine program according to the target mapping relationship table and the port value of the target node to complete data forwarding, where the target mapping relationship table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the IP address and port value of the container.

[0005] The present application also provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of the following data forwarding method when executing the computer program: In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node; Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node; In response to a successful comparison, use a virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack; In response to a successful interception, according to the target mapping table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.

[0006] The present application also provides a computer-readable storage medium, in which a computer program is stored, where the computer program, when executed by a processor, implements the steps of the following data forwarding method: In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node; Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node; In response to a successful comparison, use a virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack; In response to a successful interception, according to the target mapping table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.

[0007] The present application also provides a computer program product, including a computer program, where the computer program, when executed by a processor, implements the steps of the following data forwarding method: In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node; Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node; In response to a successful comparison, use the virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack; In response to a successful interception, according to the target mapping relationship table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping relationship table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container include at least the Internet protocol address and port value of the container.

[0008] This application intercepts the data forwarding request belonging to the current node through the virtual machine program set before the kernel protocol stack; according to the port value of the target node in the data forwarding request and the target mapping relationship table, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping relationship table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container include at least the Internet protocol address and port value of the container, which solves the technical problems of service anomalies caused by container group scheduling nodes and the decline of forwarding efficiency due to the need to configure more port forwarding rules on nodes as the service scale increases, and achieves the technical effects of improving data forwarding efficiency and reducing network latency. BRIEF DESCRIPTION OF THE DRAWINGS

[0009] To more clearly illustrate the embodiments of the present application, the drawings required for the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0010] Figure 1 It is a schematic flowchart of a data forwarding method provided by an embodiment of the present application; Figure 2 It is an overall flowchart block diagram of a data forwarding method provided by an embodiment of the present application; Figure 3 It is an internal structure diagram of an electronic device for implementing the data forwarding method provided by an embodiment of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0011] The technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present application without creative efforts shall fall within the protection scope of the present application.

[0012] It should be noted that in the description of the present application, the terms "including", "comprising" or any other variation thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device including a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence.

[0013] In order to enable those skilled in the art of the present technology to better understand the solutions of the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.

[0014] Embodiment 1 As Figure 1 shown, an embodiment of the present application provides a data forwarding method, which is applied to at least one node in a container cluster. The data forwarding method includes: In response to receiving a data forwarding request, parsing the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node; Obtaining the Internet protocol address of the current node and comparing the Internet protocol address of the current node with the Internet protocol address of the target node; In response to a successful comparison, intercepting the data forwarding request by using a virtual machine program, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack; In response to a successful interception, redirecting the data forwarding request by using the virtual machine program according to the target mapping table and the port value of the target node to complete the data forwarding, where the target mapping table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.

[0015] Specifically, a virtual machine program set before the kernel protocol stack intercepts data forwarding requests belonging to the current node; according to the port value of the target node in the data forwarding request and the target mapping relation table, the virtual machine program redirects the data forwarding request to complete data forwarding, where the target mapping relation table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container include at least the Internet protocol address and port value of the container, solving the technical problems of service exception caused by container group scheduling nodes and the decline of forwarding efficiency due to the need to configure more port forwarding rules on nodes as the service scale increases, achieving the technical effects of improving data forwarding efficiency and reducing network latency.

[0016] In one embodiment, the container cluster mentioned in this application may be Kubernetes, abbreviated as k8s or kube. There are multiple nodes in the container cluster management platform. A node can be a virtual machine or a physical machine, depending on the cluster configuration. A node may contain multiple services, and the services in each node may change. For example, there is a new service in a node. At this time, it is necessary to determine the target receiver corresponding to this new service. Therefore, it is also necessary to deploy a proxy service on each node of the container cluster management platform and run the proxy service to listen for changes in the services in each node by using the proxy service. Create a container group through Kubernetes for a specific business. A container group is the smallest management unit scheduled by Kubernetes. A container group consists of one or more containers. Containers belonging to the same container group share namespaces such as processes and networks.

[0017] In one embodiment, the virtual machine program mentioned in this application may be an eBPF (extended Berkeley Packet Filter) program. eBPF can refer to a technology that can run a sandbox program in the kernel, providing a mechanism for safely injecting code when kernel events and user program events occur, enabling non-kernel developers to control the kernel. With the development of the kernel, eBPF has gradually expanded from the initial packet filtering to network, kernel, security, tracing, etc., and its functional characteristics are still developing rapidly. An eBPF program can refer to a technology that can run a program written by a user in the operating system kernel without modifying the kernel code or loading a kernel module, that is, the eBPF program makes the operating system kernel programmable.

[0018] In one of the embodiments, the target mapping table mentioned in this application may be an eBPF mapping table. An eBPF mapping table may refer to a storage type that can save status information and pass it from the processing function of one eBPF event to another, or save some statistical information and pass it from the kernel space to the user space program. For example, an eBPF mapping table may refer to an efficient key-value pair storage device resident in the kernel space, including various types of maps, and its functions are implemented by the kernel. The interaction scenarios of the eBPF mapping table are as follows: the interaction between the eBPF program and the user program, that is, after the eBPF program runs, the obtained results are stored in the map for the user program to access through the file descriptor; the interaction between the eBPF program and the kernel program, that is, the interaction with the kernel program other than the eBPF program can also use the map as an intermediary; the interaction between eBPF programs, that is, if global variables are needed for interaction inside the eBPF program, but due to security reasons, the eBPF program is not allowed to access global variables, the map can be used as a global variable. The eBPF mapping table can be shared by the user space and the kernel space.

[0019] In addition, as Figure 2 shown, before receiving the data forwarding request, the data forwarding method further includes: Obtaining the port value of the node and the port value of the container; Corresponding the port value of the node with the port value of the container one by one to construct the first mapping relationship of the container, and determining the container as the first mapping container; Judging whether there is a port conflict between the first mapping containers; If not, obtaining the Internet protocol address of the first mapping container; According to the Internet protocol address of the first mapping container and the first mapping relationship, constructing the second mapping relationship of the first mapping container, and determining the first mapping container as the second mapping container; Generating a target mapping relationship table according to the second mapping relationships corresponding to multiple second mapping containers.

[0020] Specifically, first, the port value of the node is corresponded with the port value of the container one by one to construct the first mapping relationship of the container; then, on the basis of the first mapping relationship, combined with the Internet protocol address of the first mapping container, the second mapping relationship of the first mapping container is constructed; according to the second mapping relationships corresponding to multiple second mapping containers, a target mapping relationship table is generated, avoiding the situation where the container group is scheduled to the current node, resulting in data forwarding failure.

[0021] In addition, before judging whether there is a port conflict between the first mapping containers, the data forwarding method further includes: Generating the first mapping relationship parameter of the first mapping container according to the first mapping relationship of the first mapping container; Obtain the configuration file of the first mapping container, and add a first mapping relationship parameter field to the configuration file of the first mapping container; Write the first mapping relationship parameter of the first mapping container into the first mapping relationship parameter field of the first mapping container.

[0022] Specifically, the first mapping relationship parameter is used to describe the attributes of the first mapping relationship. Through the first mapping relationship parameter in the container, the container port can be directly mapped to the corresponding node port, improving the efficiency of data forwarding.

[0023] In one embodiment, the first mapping relationship parameter mentioned in this application may be hostPort. hostPort is a configuration option for mapping a node port to an internal container port, which is a parameter representing the mapping of the container port to the node port. After specifying the node port through this parameter, the outside of the cluster can access the corresponding container through the Internet protocol address of the node where the container is located and this node port. The first mapping relationship parameter mentioned in this application may also be a uniqueness parameter representing the mapping relationship between the port value of the container and the port value of the node. For example, use 0001 to represent the mapping relationship between the port value 8888 of the container and the port value 18888 of the node; use 0002 to represent the mapping relationship between the port value 9999 of the container and the port value 19999 of the node... Furthermore, determining whether there is a port conflict between the first mapping containers includes: In response to the first mapping relationship parameter in the configuration file of the first mapping container not appearing repeatedly, it is determined that there is no port conflict between the first mapping containers; In response to the first mapping relationship parameter in the configuration file of the first mapping container appearing repeatedly, it is determined that there is a port conflict between the first mapping containers.

[0024] Specifically, based on the first mapping relationship, the port values of the same containers may appear on the same node, resulting in data forwarding failure. Therefore, it is necessary to determine whether there is a port conflict before constructing the second mapping relationship, so as to avoid the situation of data forwarding failure after the second mapping relationship is established.

[0025] Furthermore, as Figure 2 shown, constructing the second mapping relationship of the first mapping container according to the Internet protocol address and the first mapping relationship of the first mapping container includes: Obtain the port value of the first mapping container, and obtain the port value of the node corresponding to the port value of the first mapping container according to the first mapping relationship of the first mapping container; Construct the second mapping relationship of the first mapping container according to the Internet protocol address, port value of the first mapping container, and the port value of the node corresponding to the port value of the first mapping container.

[0026] Specifically, first, according to the first mapping relationship of the first mapping container, determine the port value of the node corresponding to the port value of the first mapping container; then, based on the port value of the node corresponding to the port value of the first mapping container, construct the correspondence relationship among the Internet protocol address, port value of the first mapping container, and the port value of this node, avoiding the situation where the same container port appears on the current node due to container group scheduling when only using the first mapping relationship, thus causing data forwarding failure.

[0027] In one embodiment, the present application can also construct the second mapping relationship of the first mapping container with the Internet protocol address of the first mapping container as the key and the first mapping relationship parameter of the first mapping container as the value.

[0028] Further, as Figure 2 shown, constructing the second mapping relationship of the first mapping container according to the Internet protocol address, port value of the first mapping container, and the port value of the node corresponding to the port value of the first mapping container includes: Based on the Internet protocol address and port value of the first mapping container, form a string of the first mapping container, and use the string as a position parameter; Make the port value of the node corresponding to the port value of the first mapping container correspond one-to-one with the string of the first mapping container to construct the second mapping relationship of the first mapping container.

[0029] Specifically, considering the uniqueness of the Internet protocol address of the container, form a string by combining the Internet protocol address and port value of the first mapping container, thereby ensuring the uniqueness of the string; make the port value of the node corresponding to the port value of the first mapping container correspond one-to-one with the string of the first mapping container to construct the second mapping relationship of the first mapping container, avoiding the situation where data forwarding fails when the container group is scheduled to the current node.

[0030] In addition, before the virtual machine program intercepts the data forwarding request, the data forwarding method further includes: Write a virtual machine program using a user program and load the virtual machine program into the kernel space; Use a kernel program to mount the virtual machine program to a preset position.

[0031] In one embodiment, the eBPF program can be written using code tools, and then the written program is loaded into the system kernel through bpf(). The injection program bpf_load_program() incorporates a more complex verifier (a driver verification tool in an operating system for detecting and diagnosing driver problems). Before running the injection program, a series of security checks can be performed to maximize system security. The eBPF bytecode that passes the security checks is compiled using the kernel JIT (Just-In-Time Compilation), generating native assembly instructions and attaching them to the program at specific kernel hooks. Finally, the kernel space and the user space communicate through an efficient map mechanism. The user program can create the above eBPF program according to the access rules created by the user and inject the eBPF program into the kernel space.

[0032] Further, a virtual machine program is written using the user program and loaded into the kernel space, including: Determine a preset location; Based on the preset location, write a virtual machine program using the user program and compile the virtual machine program into virtual machine program bytecode to be loaded into the kernel space.

[0033] Further, mount the virtual machine program to the preset location using the kernel program, including: Perform a security check on the virtual machine program bytecode using the kernel program; In response to passing the security check, recompile the virtual machine program bytecode into a virtual machine program using the kernel program and mount the virtual machine program to the preset location.

[0034] Further, determining the preset location includes: Judge whether the current node supports fast data path mounting and / or traffic controller mounting; In response to the current node supporting fast data path mounting and not supporting traffic controller mounting, mount the virtual machine program on the fast data path hook in the kernel space; In response to the current node supporting traffic controller mounting and not supporting fast data path mounting, mount the virtual machine program on the traffic controller hook in the kernel space; In response to the current node supporting both fast data path mounting and traffic controller mounting, mount the virtual machine program on the fast data path hook in the kernel space.

[0035] Specifically, both the fast data path and the traffic controller are before the kernel protocol stack. Therefore, by triggering the fast data path hook or the traffic controller hook to intercept packets, it is possible to bypass the lengthy kernel protocol stack, iptables and other unnecessary kernel modules, improving the data forwarding efficiency and reducing the network latency. Moreover, since the position of the fast data path hook in the kernel space is before the traffic controller hook, when the current node supports the fast data path mount and the traffic controller mount, the priority of the fast data path hook is set higher than that of the traffic controller hook, further improving the data forwarding efficiency and reducing the network latency.

[0036] In one embodiment, XDP (eXpress Data Path) is located in the network driver layer, which is the earliest position in the software stack that can process packets. The so-called software stack is a collection of independent components that work together to ensure the normal operation of the software. The fast data path can process packets before they reach the kernel protocol stack and has excellent data plane processing performance, opening up the highway for network processing.

[0037] In one embodiment, TC (Traffic Control) is located in the upper layer of the kernel network stack and is used for traffic classification and traffic control. Network traffic can be classified and processed by configuring filtering rules and actions, such as implementing functions like traffic forwarding, speed limiting, and filtering. Through the traffic controller, network traffic can be flexibly controlled and managed in the system. The eBPF program can be attached to the entry hook point of the traffic controller to process packets before they reach the kernel protocol stack.

[0038] Furthermore, as Figure 2 shown, according to the target mapping relationship table and the port value of the target node, the virtual machine program redirects the data forwarding request to complete data forwarding, including: Matching the port value of the target node with the port values of the nodes in the target mapping relationship table to obtain the corresponding string of the target container, where the string of the target container includes the Internet protocol address and port value of the target container; Determining the target container group according to the Internet protocol address of the target container, where the target container group is used to encapsulate the target container; Determining the target port on the current node according to the port value of the target node; Forwarding the data forwarding request from the target port of the current node to the target container group by using the virtual machine program according to the Internet protocol address of the target container; Determining the target container according to the port value of the target container and forwarding the data forwarding request from the target container group to the target container by using the virtual machine program.

[0039] Specifically, according to the port value of the target node, determine the target port of the current node; according to the port value of the target node and the target mapping table, determine the string of the target container; according to the Internet protocol address in the string of the target container, determine the target container group; use the virtual machine program to forward the data forwarding request from the target port of the current node to the target container group; according to the port value of the target container, determine the target container; use the virtual machine program to forward the data forwarding request from the target container group to the target container, avoiding the situation where the container group is scheduled to the current node, resulting in data forwarding failure, and improving the data forwarding efficiency and reducing the network delay.

[0040] In one embodiment, assume that the Internet protocol address of the current node is 192.168.1.123. When an external access to 192.168.1.123:18888 is initiated from outside the cluster, resolve the Internet protocol address 192.168.1.123 and the port value 18888 of the target node in the data forwarding request; compare the Internet protocol address 192.168.1.123 of the target node with the Internet protocol address 192.168.1.123 of the current node; at this time, the comparison is successful, and use the virtual machine program to intercept the data forwarding request; query the target mapping table with "18888" as the key, and the string of the target container is queried as "100.18.162.123:8888"; call the redirect function in the virtual machine program to redirect the data forwarding request from 192.168.1.123:18888 to 100.18.162.123:8888 to complete the data forwarding.

[0041] In addition, as Figure 2 shown, the data forwarding method further includes: Monitor the configuration file of the second mapped container; In response to monitoring that the configuration file of the second mapped container has been deleted, obtain the port value of the second mapped container, and according to the first mapping relationship of the second mapped container, obtain the port value of the node corresponding to the port value of the second mapped container; Match the port value of the node corresponding to the port value of the second mapped container with the port value of the node in the target mapping table to obtain the target mapping relationship of the second mapped container; Delete the target mapping relationship of the second mapped container from the target mapping table.

[0042] Specifically, by updating the target mapping table in a timely manner, avoid the situation of data conflict caused by creating a new container group or scheduling the container group subsequently.

[0043] In addition, after determining whether there is a port conflict between the first mapped containers, the data forwarding method further includes: In response to a port conflict existing between first mapping containers, determining the corresponding first mapping containers as conflict containers; According to the first mapping relationship parameters of the conflict containers, dividing the conflict containers with the same first mapping relationship parameters into the same category to obtain a conflict container classification result; Determining a target first mapping container from the conflict container classification result according to a load balancing policy; Constructing a second mapping relationship of the target first mapping container according to the Internet protocol address and the first mapping relationship of the target first mapping container.

[0044] Further, determining a target first mapping container from the conflict container classification result according to a load balancing policy includes: Listening to the number of network request receptions of the conflict containers in the conflict container classification result; Sorting the conflict containers in ascending order of the number of network request receptions to generate a sorting result; Taking the conflict container ranked first according to the sorting result as the target first mapping container.

[0045] Specifically, when containers on the same node are set with the same first mapping relationship parameters, selecting the target first mapping container with the least number of network request receptions according to the load balancing policy, avoiding the situation that the container group is scheduled to the current node, resulting in data forwarding failure, and improving the data forwarding efficiency and reducing the network delay.

[0046] It should be understood that although Figure 1 、 Figure 2 the steps in the flowchart of Figure 1 、 Figure 2 are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order limit, and these steps can be executed in other orders. Moreover,

[0047] Embodiment 2 An embodiment of the present application further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above data forwarding method embodiments, including: In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node; Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node; In response to successful comparison, use a virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack; In response to successful interception, according to the target mapping table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.

[0048] When the program instructions are read and executed by one or more processors, the operations corresponding to the steps in the above method embodiments can also be performed. Reference can be made to the descriptions in the above text, and details are not repeated here. Reference Figure 3 , which exemplarily shows the architecture of an electronic device. Specifically, it may include a processor 310, a video display adapter 311, a disk drive 312, an input / output interface 313, a network interface 314, and a memory 320. The above processor 310, video display adapter 311, disk drive 312, input / output interface 313, network interface 314, and memory 320 can be communicatively connected through a communication bus 330.

[0049] Among them, the processor 310 can be implemented in ways such as a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in this application.

[0050] The memory 320 may be implemented in the form of a Read Only Memory (ROM), a Random Access Memory (RAM), a static storage device, a dynamic storage device, etc. The memory 320 may store an operating system 321 for controlling the operation of the electronic device 300, and a Basic Input / Output System (BIOS) 322 for controlling the low-level operations of the electronic device 300. Additionally, a web browser 323, a data storage management 324, an icon font processing system 325, etc. may also be stored. The above-mentioned icon font processing system 325 may be the application program that specifically implements the operations of the foregoing steps in the embodiments of the present application. In summary, when implementing the technical solution provided by the present application through software or firmware, the relevant program codes are stored in the memory 320 and are called and executed by the processor 310.

[0051] The input / output interface 313 is used to connect to the input / output module to achieve information input and output. The input / output module may be configured as a component in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Among them, the input device may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output device may include a display, a speaker, a vibrator, an indicator light, etc.

[0052] The network interface 314 is used to connect to a communication module (not shown in the figure) to achieve communication interaction between this device and other devices. Among them, the communication module may achieve communication through a wired method (such as USB, network cable, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.).

[0053] The bus 330 includes a path for transmitting information between various components of the device (such as the processor 310, the video display adapter 311, the disk drive 312, the input / output interface 313, the network interface 314, and the memory 320).

[0054] In addition, the electronic device 300 may also obtain information on specific redemption conditions from the virtual resource object redemption condition information database 341 for conditional judgment, etc.

[0055] It should be noted that although the above-mentioned electronic device 300 only shows the processor 310, the video display adapter 311, the disk drive 312, the input / output interface 313, the network interface 314, the memory 320, the bus 330, etc., in the specific implementation process, the electronic device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary for implementing the solution of the present application and does not necessarily include all the components shown in the figure.

[0056] As can be seen from the description of the above embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of this application, in essence, or the part that makes a contribution to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disk, etc., and includes several instructions for causing an electronic device (which can be a personal computer, a cloud server, or a network device, etc.) to execute the methods of each embodiment or some parts of the embodiments of this application.

[0057] Embodiment 3 The embodiment of this application also provides a computer-readable storage medium, in which a computer program is stored. Among them, the computer program is set to execute the steps in any of the above data forwarding method embodiments when running, including: In response to receiving a data forwarding request, parsing the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node; Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node; In response to a successful comparison, use a virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack; In response to a successful interception, according to the target mapping table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete the data forwarding, where the target mapping table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.

[0058] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0059] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0060] The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.

[0061] Embodiment 4 The embodiments of the present application also provide a computer program product. The above computer program product includes a computer program. When the computer program is executed by a processor, it implements the steps in any one of the above embodiments of the data forwarding method, including: In response to receiving a data forwarding request, parsing the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node; Obtaining the Internet protocol address of the current node and comparing the Internet protocol address of the current node with the Internet protocol address of the target node; In response to successful comparison, use the virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack; In response to successful interception, according to the target mapping relationship table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping relationship table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.

[0062] An embodiment of the present application also provides another computer program product, including a non-volatile computer-readable storage medium, the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above-mentioned data forwarding method embodiments, including: In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node; Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node; In response to successful comparison, use the virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack; In response to successful interception, according to the target mapping relationship table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping relationship table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.

[0063] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.

[0064] The above embodiments only represent several implementation manners of the present application, and their descriptions are relatively specific and detailed, but they should not be construed as limiting the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.

[0065] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered as exceeding the scope of this application.

[0066] The above has introduced in detail a data forwarding method, device, storage medium, and program product provided by this application. Specific examples have been used herein to elaborate on the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art, without departing from the principles of this application, several improvements and modifications can be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.

Claims

1. A data forwarding method, applied to at least one node in a container cluster, characterized in that: The method comprises: In response to receiving the data forwarding request, parsing the data forwarding request to obtain target node information, wherein the target node information at least includes an Internet Protocol address and a port value of the target node; Obtaining an Internet Protocol address of a current node, and comparing the Internet Protocol address of the current node with the Internet Protocol address of the target node; In response to the comparison being successful, intercepting the data forwarding request using a virtual machine program, wherein the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack; In response to successful interception, the data forwarding request is redirected using the virtual machine program to complete data forwarding according to a target mapping relationship table and a port value of the target node, wherein the target mapping relationship table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container include at least the Internet Protocol address and port value of the container.

2. The method according to claim 1, characterized in that: Before receiving the data forwarding request, the method further includes: Obtaining a port value of the node and a port value of the container; Matching the port value of the node with the port value of the container one by one, constructing a first mapping relationship of the container, and determining the container as a first mapping container; Determine whether there is a port conflict between the first mapping containers; If not, obtaining the Internet Protocol address of the first mapping container; constructing a second mapping relationship of the first mapping container according to the Internet Protocol address of the first mapping container and the first mapping relationship, and determining the first mapping container as a second mapping container; The target mapping relationship table is generated according to the second mapping relationships corresponding to the plurality of second mapping containers.

3. The method according to claim 2, characterized in that: Before determining whether there is a port conflict between the first mapping containers, the method further includes: generating a first mapping relationship parameter of the first mapping container according to the first mapping relationship of the first mapping container; Acquire a configuration file of the first mapping container, and add a first mapping relationship parameter field in the configuration file of the first mapping container; The first mapping relationship parameter of the first mapping container is written into the first mapping relationship parameter field of the first mapping container.

4. The method according to claim 3, characterized in that: The determining whether there is a port conflict between the first mapping containers includes: In response to the first mapping relationship parameter in the configuration file of the first mapping container not appearing repeatedly, determining that there is no port conflict between the first mapping containers; In response to repeated appearance of the first mapping relationship parameter in the configuration file of the first mapping container, it is determined that there is a port conflict between the first mapping containers.

5. The method according to claim 2, characterized in that: The constructing the second mapping relationship of the first mapping container according to the Internet Protocol address of the first mapping container and the first mapping relationship includes: Acquire the port value of the first mapping container, and obtain the port value of the node corresponding to the port value of the first mapping container according to the first mapping relationship of the first mapping container; A second mapping relationship of the first mapping container is constructed according to the Internet Protocol address and port value of the first mapping container and the port value of the node corresponding to the port value of the first mapping container.

6. The method according to claim 5, characterized in that: The constructing a second mapping relationship of the first mapping container according to the Internet Protocol address and the port value of the first mapping container and the port value of the node corresponding to the port value of the first mapping container includes: Based on the Internet Protocol address and port value of the first mapping container, compose a string of the first mapping container, and use the string as the position parameter; The port value of the node corresponding to the port value of the first mapping container is matched with the character string of the first mapping container one by one to construct a second mapping relationship of the first mapping container.

7. The method according to claim 1, characterized in that: Before intercepting the data forwarding request by the virtual machine program, the method further includes: Using a user program to write the virtual machine program, and loading the virtual machine program into the kernel space; The virtual machine program is mounted to the preset location using the kernel program.

8. The method according to claim 7, characterized in that: The step of using a user program to write the virtual machine program and loading the virtual machine program into the kernel space includes: determining the preset position; Based on the preset position, the virtual machine program is written using the user program, and the virtual machine program is compiled into a virtual machine program bytecode to be loaded into the kernel space.

9. The method according to claim 8, characterized in that: The step of mounting the virtual machine program to the preset location by using the kernel program includes: Using the kernel program to perform security verification on the virtual machine program bytecode; In response to the security check passing, the virtual machine program bytecode is recompiled into the virtual machine program by using the kernel program, and the virtual machine program is mounted to the preset location.

10. The method according to claim 8, characterized in that: The determining the preset position includes: Determining whether the current node supports fast data path mounting and / or flow controller mounting; In response to the current node supporting the fast data path mounting and not supporting the traffic controller mounting, mounting the virtual machine program on the fast data path hook of the kernel space; In response to the current node supporting the traffic controller mounting and not supporting the fast data path mounting, mounting the virtual machine program on the traffic controller hook of the kernel space; In response to the current node supporting the fast data path mounting and the traffic controller mounting, the virtual machine program is mounted on the fast data path hook of the kernel space.

11. The method according to claim 6, characterized in that: The redirecting the data forwarding request by using the virtual machine program according to the target mapping relationship table and the port value of the target node to complete the data forwarding includes: Matching the port value of the target node with the port value of the node in the target mapping relationship table to obtain a corresponding character string of the target container, wherein the character string of the target container includes an Internet Protocol address and a port value of the target container; Determine a target container group according to the Internet Protocol address of the target container, wherein the target container group is used to encapsulate the target container; Determining a target port on the current node according to the port value of the target node; forwarding the data forwarding request from the target port of the current node to the target container group using the virtual machine program according to the Internet Protocol address of the target container; The target container is determined according to the port value of the target container, and the data forwarding request is forwarded from the target container group to the target container by using the virtual machine program.

12. The method according to claim 2, characterized in that: The method further comprises: Listening to the configuration file of the second mapping container; In response to monitoring that the configuration file of the second mapping container has been deleted, obtaining the port value of the second mapping container, and obtaining the port value of the node corresponding to the port value of the second mapping container according to the first mapping relationship of the second mapping container; Matching the port value of the node corresponding to the port value of the second mapping container with the port value of the node in the target mapping relationship table to obtain the target mapping relationship of the second mapping container; The target mapping relationship of the second mapping container is deleted from the target mapping relationship table.

13. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the data forwarding method according to any one of claims 1 to 12 when executing the computer program.

14. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the data forwarding method according to any one of claims 1 to 12.

15. A computer program product comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the data forwarding method according to any one of claims 1 to 12 are implemented.

Citation Information

Patent Citations

  • Node cluster communication method, system and device and electronic device

    CN112511611A

  • Container service network configuration method and related product

    CN114363170A

  • TCP relay acceleration system based on eBPF

    CN117834513A

  • Session keeping method and device in k8s cluster, computer equipment and medium

    CN119316428A

  • Encrypted data packet forwarding

    US20230198964A1