A data forwarding method, device, storage medium and program product
By setting up virtual machine programs before the kernel protocol stack, using the target mapping relationship table to intercept and redirect data forwarding requests, the service exceptions and forwarding efficiency reduction caused by container group scheduling nodes are solved, and efficient data forwarding and low latency are achieved.
Patent Information
- Application Number
- CN202510536688.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-27
- Publication Date
- 2025-07-25
- Estimated Expiration
- 2045-04-27
AI Technical Summary
On the container group scheduling node, as the service scale increases, the number of iptables rules expands, resulting in performance degradation, poor flexibility in managing and updating rules, and service exceptions are caused when the container group is scheduled to the same node.
By setting up virtual machine programs before the kernel protocol stack, using the target mapping relationship table to intercept and redirect data forward requests, the dependence on iptables is avoided and the Internet protocol address and port value of the container is directly mapped.
It improves data forwarding efficiency, reduces network delay, and solves the service abnormality caused by container group scheduling nodes.
Smart Images

Figure CN120090970B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer network communication technologies, and in particular, to a data forwarding method, device, storage medium, and program product. Background Art
[0002] In scenarios such as edge computing or when specific port exposure services are required, containers need to directly use node ports, which is generally achieved through the hostPort (a configuration option for mapping node ports to internal container ports) function provided by the container cluster. The traditional hostPort function is implemented by a specific container network interface and relies on mechanisms such as iptables (a firewall tool for managing packet filtering and forwarding). By configuring iptables rules on the node, packets are redirected to the internal container port. However, as the service scale increases, the number of iptables rules may rapidly expand, leading to performance degradation. At the same time, the flexibility of managing and updating the rules is also poor. And due to the uncertainty of container group scheduling nodes, when containers with the same hostPort are scheduled to the same node, service exceptions will occur. Summary of the Invention
[0003] This application provides a data forwarding method, device, storage medium, and program product to at least solve the problems in the related art that service exceptions are caused by container group scheduling nodes, and as the service scale increases, more port forwarding rules need to be configured on the node, resulting in a decrease in forwarding efficiency.
[0004] This application provides a data forwarding method applied to at least one node in a container cluster. The data forwarding method includes:
[0005] In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node;
[0006] Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node;
[0007] In response to a successful comparison, use a virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack;
[0008] In response to a successful interception, according to the target mapping table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.
[0009] The present application also provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of the following data forwarding method when executing the computer program:
[0010] In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node;
[0011] Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node;
[0012] In response to a successful comparison, use a virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack;
[0013] In response to a successful interception, according to the target mapping table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.
[0014] The present application also provides a computer-readable storage medium, in which a computer program is stored, where the computer program, when executed by a processor, implements the steps of the following data forwarding method:
[0015] In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node;
[0016] Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node;
[0017] In response to a successful comparison, use a virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack;
[0018] In response to a successful interception, according to the target mapping table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.
[0019] The present application also provides a computer program product, including a computer program, which when executed by a processor implements the steps of a data forwarding method including the following:
[0020] In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node;
[0021] Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node;
[0022] In response to a successful comparison, use a virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack;
[0023] In response to a successful interception, according to the target mapping table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.
[0024] The present application intercepts the data forwarding request belonging to the current node through a virtual machine program set before the kernel protocol stack; according to the port value of the target node in the data forwarding request and the target mapping table, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container, solving the technical problems of service anomalies caused by container group scheduling nodes and the decline in forwarding efficiency due to the need to configure more port forwarding rules on nodes as the service scale increases, achieving the technical effects of improving data forwarding efficiency and reducing network latency. BRIEF DESCRIPTION OF THE DRAWINGS
[0025] In order to more clearly illustrate the embodiments of the present application, the following will briefly introduce the drawings required in the embodiments. Obviously, the drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0026] Figure 1 It is a schematic flowchart of a data forwarding method provided by an embodiment of the present application;
[0027] Figure 2 It is an overall flowchart block diagram of a data forwarding method provided by an embodiment of the present application;
[0028] Figure 3 This is the internal structure diagram of an electronic device for implementing a data forwarding method provided by an embodiment of the present application. Specific embodiments
[0029] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.
[0030] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variation thereof are intended to cover a non-exclusive inclusion, such that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0031] In order to enable those skilled in the art of this technology to better understand the solution of the present application, the present application will be further described in detail below in conjunction with the accompanying drawings and specific embodiments.
[0032] Embodiment 1
[0033] As Figure 1 shown, an embodiment of the present application provides a data forwarding method, which is applied to at least one node in a container cluster. The data forwarding method includes:
[0034] In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node;
[0035] Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node;
[0036] In response to a successful comparison, use a virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack;
[0037] In response to successful interception, according to the target mapping relationship table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping relationship table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container include at least the Internet protocol address and port value of the container.
[0038] Specifically, intercept the data forwarding request belonging to the current node through the virtual machine program set in front of the kernel protocol stack; according to the port value of the target node in the data forwarding request and the target mapping relationship table, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping relationship table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container include at least the Internet protocol address and port value of the container, which solves the technical problems of service anomalies caused by container group scheduling nodes and the decrease in forwarding efficiency due to the need to configure more port forwarding rules on nodes as the service scale increases, and achieves the technical effects of improving data forwarding efficiency and reducing network latency.
[0039] In one embodiment, the container cluster mentioned in this application may be Kubernetes, abbreviated as k8s or kube. There are multiple nodes in the container cluster management platform. A node can be a virtual machine or a physical machine, depending on the cluster configuration. A node may contain multiple services, and the services in each node may change. For example, there is a new service in the node. At this time, it is necessary to determine the target receiver corresponding to this new service. Therefore, it is also necessary to deploy a proxy service on each node of the container cluster management platform and run the proxy service to monitor the changes of the services in each node by using the proxy service. Create a container group for a specific business through Kubernetes. A container group is the smallest management unit scheduled by Kubernetes. A container group consists of one or more containers. Containers belonging to the same container group share process, network, and other namespaces.
[0040] In one embodiment, the virtual machine program mentioned in this application may be an eBPF (extended Berkeley Packet Filter) program. eBPF refers to a technology that can run sandbox programs in the kernel, providing a mechanism for securely injecting code when kernel events and user program events occur, enabling non-kernel developers to control the kernel. With the development of the kernel, eBPF has gradually expanded from initial packet filtering to networking, the kernel, security, tracing, etc., and its functional features are still developing rapidly. An eBPF program refers to a technology that allows user-written programs to run in the operating system kernel without modifying the kernel code or loading kernel modules, that is, the eBPF program makes the operating system kernel programmable.
[0041] In one embodiment, the target mapping table mentioned in this application may be an eBPF mapping table. An eBPF mapping table refers to a storage type that can save state information passed from the processing function of one eBPF event to another, or save some statistical information passed from the kernel space to the user space program. For example, an eBPF mapping table refers to an efficient key-value pair storage device resident in the kernel space, containing various types of maps, and its functions are implemented by the kernel. The interaction scenarios of the eBPF mapping table are as follows: the interaction between the eBPF program and the user program, that is, after the eBPF program runs, the obtained results are stored in the map for the user program to access through the file descriptor; the interaction between the eBPF program and the kernel program, that is, when interacting with kernel programs other than the eBPF program, the map can also be used as an intermediary; the interaction between eBPF programs, that is, if global variables are needed for interaction inside the eBPF program, but global variables are not allowed to be accessed by the eBPF program due to security reasons, the map can be used as a global variable. The eBPF mapping table can be shared between the user space and the kernel space.
[0042] In addition, as Figure 2 shown, before receiving the data forwarding request, the data forwarding method further includes:
[0043] Obtain the port value of the node and the port value of the container;
[0044] Correspond the port value of the node with the port value of the container one by one, construct the first mapping relationship of the container, and determine the container as the first mapped container;
[0045] Determine whether there is a port conflict between the first mapped containers;
[0046] If not, obtain the Internet protocol address of the first mapped container;
[0047] Construct the second mapping relationship of the first mapping container according to the Internet protocol address of the first mapping container and the first mapping relationship, and determine the first mapping container as the second mapping container;
[0048] Generate a target mapping relationship table according to the second mapping relationships corresponding to multiple second mapping containers.
[0049] Specifically, first, one-to-one correspondence is established between the port values of the nodes and the port values of the containers to construct the first mapping relationship of the containers; then, on the basis of the first mapping relationship, combined with the Internet protocol address of the first mapping container, the second mapping relationship of the first mapping container is constructed; a target mapping relationship table is generated according to the second mapping relationships corresponding to multiple second mapping containers, avoiding the situation where the container group is scheduled to the current node, resulting in data forwarding failure.
[0050] In addition, before determining whether there is a port conflict between the first mapping containers, the data forwarding method further includes:
[0051] Generate the first mapping relationship parameters of the first mapping container according to the first mapping relationship of the first mapping container;
[0052] Obtain the configuration file of the first mapping container, and add a first mapping relationship parameter field to the configuration file of the first mapping container;
[0053] Write the first mapping relationship parameters of the first mapping container into the first mapping relationship parameter field of the first mapping container.
[0054] Specifically, the first mapping relationship parameters are used to describe the attributes of the first mapping relationship. Through the first mapping relationship parameters in the container, the container ports can be directly mapped to the corresponding node ports, improving the efficiency of data forwarding.
[0055] In one embodiment, the first mapping relationship parameters mentioned in this application may be hostPort. hostPort is a configuration option for mapping node ports to internal container ports, and is a parameter representing the mapping of container ports to node ports. After specifying the node port through this parameter, the outside of the cluster can access the corresponding container through the Internet protocol address of the node where the container is located and this node port. The first mapping relationship parameters mentioned in this application may also be uniqueness parameters used to represent the mapping relationship between the port values of the containers and the port values of the nodes. For example, use 0001 to represent the mapping relationship between the port value 8888 of the container and the port value 18888 of the node; use 0002 to represent the mapping relationship between the port value 9999 of the container and the port value 19999 of the node...
[0056] Further, determining whether there is a port conflict between the first mapping containers includes:
[0057] Determine that there is no port conflict between the first mapping containers in response to the non-repetition of the first mapping relationship parameters in the configuration file of the first mapping containers;
[0058] Determine that there is a port conflict between the first mapping containers in response to the repetition of the first mapping relationship parameters in the configuration file of the first mapping containers.
[0059] Specifically, based on the first mapping relationship, the port values of the same containers may appear on the same node, resulting in data forwarding failure. Therefore, it is necessary to determine whether there is a port conflict before constructing the second mapping relationship, so as to avoid the situation of data forwarding failure after the second mapping relationship is established.
[0060] Further, as Figure 2 shown, construct the second mapping relationship of the first mapping containers according to the Internet protocol address and the first mapping relationship of the first mapping containers, including:
[0061] Obtain the port value of the first mapping container, and obtain the port value of the node corresponding to the port value of the first mapping container according to the first mapping relationship of the first mapping container;
[0062] Construct the second mapping relationship of the first mapping container according to the Internet protocol address, port value of the first mapping container, and the port value of the node corresponding to the port value of the first mapping container.
[0063] Specifically, first determine the port value of the node corresponding to the port value of the first mapping container according to the first mapping relationship of the first mapping container; then, based on the port value of the node corresponding to the port value of the first mapping container, construct the corresponding relationship between the Internet protocol address, port value of the first mapping container, and the port value of this node, avoiding the situation that due to container group scheduling, the same container ports appear on the current node when only using the first mapping relationship, resulting in data forwarding failure.
[0064] In one of the embodiments, the present application can also construct the second mapping relationship of the first mapping containers with the Internet protocol address of the first mapping container as the key and the first mapping relationship parameters of the first mapping container as the value.
[0065] Further, as Figure 2 shown, construct the second mapping relationship of the first mapping containers according to the Internet protocol address, port value of the first mapping container, and the port value of the node corresponding to the port value of the first mapping container, including:
[0066] Based on the Internet protocol address and port value of the first mapping container, form a string of the first mapping container, and use the string as the position parameter;
[0067] The port values of the nodes corresponding to the port values of the first mapping container are put into one-to-one correspondence with the strings of the first mapping container to construct the second mapping relationship of the first mapping container.
[0068] Specifically, considering the uniqueness of the Internet protocol address of the container, the Internet protocol address and the port value of the first mapping container are combined into a string to ensure the uniqueness of the string; the port values of the nodes corresponding to the port values of the first mapping container are put into one-to-one correspondence with the strings of the first mapping container to construct the second mapping relationship of the first mapping container, avoiding the situation where the container group is scheduled to the current node and causes data forwarding failure.
[0069] In addition, before the virtual machine program intercepts the data forwarding request, the data forwarding method further includes:
[0070] Use the user program to write the virtual machine program and load the virtual machine program into the kernel space;
[0071] Use the kernel program to mount the virtual machine program to a preset position.
[0072] In one embodiment, the eBPF program can be written using code tools, and then the written program is loaded into the system kernel through bpf(). The injection program bpf_load_program() incorporates a more complex verifier (a driver verification tool in an operating system for detecting and diagnosing driver problems) mechanism. Before running the injection program, a series of security checks can be performed to maximize the security of the system. The eBPF bytecode that passes the security checks is compiled using kernel JIT (Just-In-Time Compilation, which means that bytecode is dynamically compiled into native machine code during program execution) to generate native assembly instructions and attached to the program at specific kernel hooks. Finally, the kernel space and the user space communicate through an efficient map mechanism. The user program can create the above eBPF program according to the access rules created by the user and inject the eBPF program into the kernel space.
[0073] Further, using the user program to write the virtual machine program and load the virtual machine program into the kernel space includes:
[0074] Determine the preset position;
[0075] Based on the preset position, use the user program to write the virtual machine program and compile the virtual machine program into virtual machine program bytecode to load it into the kernel space.
[0076] Further, using the kernel program to mount the virtual machine program to the preset position includes:
[0077] Use the kernel program to perform security verification on the bytecode of the virtual machine program;
[0078] In response to the successful security verification, use the kernel program to recompile the bytecode of the virtual machine program into a virtual machine program, and mount the virtual machine program to a preset location.
[0079] Further, determining the preset location includes:
[0080] Determine whether the current node supports fast data path mounting and / or traffic controller mounting;
[0081] In response to the current node supporting fast data path mounting and not supporting traffic controller mounting, mount the virtual machine program on the fast data path hook in the kernel space;
[0082] In response to the current node supporting traffic controller mounting and not supporting fast data path mounting, mount the virtual machine program on the traffic controller hook in the kernel space;
[0083] In response to the current node supporting both fast data path mounting and traffic controller mounting, mount the virtual machine program on the fast data path hook in the kernel space.
[0084] Specifically, both the fast data path and the traffic controller are before the kernel protocol stack. Therefore, by triggering the fast data path hook or the traffic controller hook to intercept data packets, it is possible to bypass non-essential kernel modules such as the long kernel protocol stack and iptables, improving the data forwarding efficiency and reducing the network latency. And since the position of the fast data path hook in the kernel space is before the traffic controller hook, when the current node supports both fast data path mounting and traffic controller mounting, the priority of setting the fast data path hook is higher than that of the traffic controller hook, further improving the data forwarding efficiency and reducing the network latency.
[0085] In one embodiment, XDP (eXpress Data Path) is located in the network driver layer, which is the earliest position in the software stack that can process data packets. The so-called software stack is a collection of independent components that work together to ensure the normal operation of the software. The fast data path can process data packets before they reach the kernel protocol stack, and has excellent data plane processing performance, opening up the highway for network processing.
[0086] In one embodiment, the TC (Traffic Control) is located above the kernel network stack and is used for traffic classification and traffic control. Network traffic can be classified and processed by configuring filtering rules and actions. For example, functions such as traffic forwarding, speed limiting, and filtering can be implemented. Through the traffic controller, network traffic can be flexibly controlled and managed in the system. The eBPF program can be attached to the entry hook point of the traffic controller to process the data packet before it reaches the kernel protocol stack.
[0087] Further, as Figure 2 shown, according to the target mapping relationship table and the port value of the target node, the virtual machine program redirects the data forwarding request to complete data forwarding, including:
[0088] Match the port value of the target node with the port values of the nodes in the target mapping relationship table to obtain the corresponding string of the target container. The string of the target container includes the Internet protocol address and port value of the target container;
[0089] Determine the target container group according to the Internet protocol address of the target container. The target container group is used to encapsulate the target container;
[0090] Determine the target port on the current node according to the port value of the target node;
[0091] According to the Internet protocol address of the target container, use the virtual machine program to forward the data forwarding request from the target port of the current node to the target container group;
[0092] Determine the target container according to the port value of the target container, and use the virtual machine program to forward the data forwarding request from the target container group to the target container.
[0093] Specifically, determine the target port on the current node according to the port value of the target node; determine the string of the target container according to the port value of the target node and the target mapping relationship table; determine the target container group according to the Internet protocol address in the string of the target container; use the virtual machine program to forward the data forwarding request from the target port of the current node to the target container group; determine the target container according to the port value of the target container; use the virtual machine program to forward the data forwarding request from the target container group to the target container, avoiding the situation where the container group is scheduled to the current node, resulting in data forwarding failure, and improving the data forwarding efficiency and reducing the network latency.
[0094] In one embodiment, assume that the Internet Protocol (IP) address of the current node is 192.168.1.123. When an external access to 192.168.1.123:18888 is initiated from outside the cluster, the IP address 192.168.1.123 and port value 18888 of the target node in the data forwarding request are resolved; the IP address 192.168.1.123 of the target node is compared with the IP address 192.168.1.123 of the current node; at this time, the comparison is successful, and the virtual machine program is used to intercept the data forwarding request; the target mapping table is queried with "18888" as the key, and the string of the target container is found to be "100.18.162.123:8888"; the redirect function in the virtual machine program is called to redirect the data forwarding request from 192.168.1.123:18888 to 100.18.162.123:8888 to complete the data forwarding.
[0095] In addition, as Figure 2 shown, the data forwarding method further includes:
[0096] Listening to the configuration file of the second mapping container;
[0097] In response to monitoring that the configuration file of the second mapping container has been deleted, obtaining the port value of the second mapping container, and obtaining the port value of the node corresponding to the port value of the second mapping container according to the first mapping relationship of the second mapping container;
[0098] Matching the port value of the node corresponding to the port value of the second mapping container with the port value of the node in the target mapping relationship table to obtain the target mapping relationship of the second mapping container;
[0099] Deleting the target mapping relationship of the second mapping container from the target mapping relationship table.
[0100] Specifically, by updating the target mapping table in a timely manner, it is possible to avoid data conflicts caused by creating new container groups or performing container group scheduling in the future.
[0101] In addition, after determining whether there is a port conflict between the first mapping containers, the data forwarding method further includes:
[0102] In response to there being a port conflict between the first mapping containers, determining the corresponding first mapping containers as conflict containers;
[0103] Dividing the conflict containers with the same first mapping relationship parameters into the same category according to the first mapping relationship parameters of the conflict containers to obtain the conflict container classification result;
[0104] Determining the target first mapping container from the conflict container classification result according to the load balancing strategy;
[0105] Construct the second mapping relationship of the target first mapping container according to the Internet protocol address of the target first mapping container and the first mapping relationship.
[0106] Further, determine the target first mapping container from the conflict container classification result according to the load balancing policy, including:
[0107] Monitor the number of network request receptions of the conflict containers in the conflict container classification result;
[0108] Sort the conflict containers in ascending order of the number of network request receptions to generate a sorting result;
[0109] Use the conflict container ranked first in the sorting result as the target first mapping container.
[0110] Specifically, when containers on the same node are set with the same first mapping relationship parameters, select the target first mapping container with the least number of network request receptions according to the load balancing policy, avoiding the situation where the container group is scheduled to the current node, resulting in data forwarding failure, and improving the data forwarding efficiency and reducing the network delay.
[0111] It should be understood that although Figure 1 、 Figure 2 the steps in the flowchart of Figure 1 、 Figure 2 are shown in sequence according to the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless otherwise clearly stated in this article, the execution of these steps has no strict order restriction, and these steps can be executed in other orders. Moreover,
[0112] Embodiment 2
[0113] An embodiment of the present application further provides an electronic device, including a memory and a processor. A computer program is stored in the memory, and the processor is configured to run the computer program to execute the steps in any one of the above data forwarding method embodiments, including:
[0114] In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node;
[0115] Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node;
[0116] In response to a successful comparison, use the virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack;
[0117] In response to a successful interception, according to the target mapping table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.
[0118] When the program instructions are read and executed by one or more processors, operations corresponding to the steps in the above method embodiments can also be performed. Reference can be made to the description above, and details are not repeated here. Reference Figure 3 , which exemplarily shows the architecture of the electronic device. Specifically, it may include a processor 310, a video display adapter 311, a disk drive 312, an input / output interface 313, a network interface 314, and a memory 320. The above-mentioned processor 310, video display adapter 311, disk drive 312, input / output interface 313, network interface 314, and the memory 320 can be communicatively connected through a communication bus 330.
[0119] Among them, the processor 310 can be implemented in a general-purpose central processing unit (CPU), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, etc., and is used to execute relevant programs to implement the technical solutions provided in this application.
[0120] The memory 320 may be implemented in the form of a Read Only Memory (ROM), a Random Access Memory (RAM), a static storage device, a dynamic storage device, etc. The memory 320 may store an operating system 321 for controlling the operation of the electronic device 300, and a Basic Input / Output System (BIOS) 322 for controlling the low-level operations of the electronic device 300. Additionally, a web browser 323, data storage management 324, an icon font processing system 325, etc. may also be stored. The above-mentioned icon font processing system 325 may be the application program that specifically implements the operations of the foregoing steps in the embodiments of the present application. In summary, when implementing the technical solution provided by the present application through software or firmware, the relevant program code is stored in the memory 320 and is called and executed by the processor 310.
[0121] The input / output interface 313 is used to connect to an input / output module to implement information input and output. The input / output module may be configured as a component in the device (not shown in the figure) or externally connected to the device to provide corresponding functions. Among them, the input devices may include a keyboard, a mouse, a touch screen, a microphone, various sensors, etc., and the output devices may include a display, a speaker, a vibrator, an indicator light, etc.
[0122] The network interface 314 is used to connect to a communication module (not shown in the figure) to implement communication interaction between this device and other devices. Among them, the communication module may implement communication through a wired method (such as USB, network cable, etc.) or through a wireless method (such as a mobile network, WIFI, Bluetooth, etc.).
[0123] The bus 330 includes a path for transmitting information between various components of the device (such as the processor 310, the video display adapter 311, the disk drive 312, the input / output interface 313, the network interface 314, and the memory 320).
[0124] In addition, the electronic device 300 may also obtain information on specific collection conditions from the virtual resource object collection condition information database 341 for use in condition judgment, etc.
[0125] It should be noted that although the above-mentioned electronic device 300 only shows the processor 310, the video display adapter 311, the disk drive 312, the input / output interface 313, the network interface 314, the memory 320, the bus 330, etc., in the specific implementation process, the electronic device may also include other components necessary for normal operation. In addition, those skilled in the art can understand that the above device may also only include the components necessary to implement the solution of the present application and does not necessarily include all the components shown in the figure.
[0126] As can be seen from the description of the above embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus a necessary general hardware platform. Based on such an understanding, the technical solution of this application, in essence or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product can be stored in a storage medium, such as ROM / RAM, magnetic disk, optical disc, etc., and includes several instructions for causing an electronic device (which can be a personal computer, a cloud server, or a network device, etc.) to execute the methods of each embodiment or some parts of the embodiments of this application.
[0127] Embodiment Three
[0128] The embodiment of this application also provides a computer-readable storage medium, in which a computer program is stored. Among them, the computer program is set to execute the steps in any one of the above data forwarding method embodiments when running, including:
[0129] In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node;
[0130] Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node;
[0131] In response to a successful comparison, use the virtual machine program to intercept the data forwarding request, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack;
[0132] In response to a successful interception, according to the target mapping table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping table is used to describe the corresponding relationship between the port value of the node and the location parameters of the container, and the location parameters of the container at least include the Internet protocol address and port value of the container.
[0133] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0134] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0135] The above embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application should be subject to the appended claims.
[0136] Embodiment 4
[0137] The embodiments of the present application also provide a computer program product. The above computer program product includes a computer program. When the computer program is executed by a processor, it implements the steps in any one of the above embodiments of the data forwarding method, including:
[0138] In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information at least includes the Internet protocol address and port value of the target node;
[0139] Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node;
[0140] In response to successful comparison, intercept the data forwarding request by using a virtual machine program, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack;
[0141] In response to successful interception, according to the target mapping relationship table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping relationship table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container include at least the Internet protocol address and port value of the container.
[0142] An embodiment of the present application further provides another computer program product, including a non-volatile computer-readable storage medium, the non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any one of the above-mentioned data forwarding method embodiments, including:
[0143] In response to receiving a data forwarding request, parse the data forwarding request to obtain target node information, where the target node information includes at least the Internet protocol address and port value of the target node;
[0144] Obtain the Internet protocol address of the current node, and compare the Internet protocol address of the current node with the Internet protocol address of the target node;
[0145] In response to successful comparison, intercept the data forwarding request by using a virtual machine program, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack;
[0146] In response to successful interception, according to the target mapping relationship table and the port value of the target node, use the virtual machine program to redirect the data forwarding request to complete data forwarding, where the target mapping relationship table is used to describe the correspondence between the port value of the node and the location parameters of the container, and the location parameters of the container include at least the Internet protocol address and port value of the container.
[0147] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope recorded in this specification.
[0148] The above embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
[0149] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0150] The above has introduced in detail a data forwarding method, device, storage medium, and program product provided by the present application. Specific examples are used herein to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be noted that for those of ordinary skill in the technical field, without departing from the principle of the present application, several improvements and modifications can still be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.
Claims
1. A data forwarding method, applied to at least one node in a container cluster, characterized in that The method includes: In response to receiving a data forwarding request, parsing the data forwarding request to obtain target node information, where the target node information at least includes the Internet Protocol (IP) address and port value of the target node; Obtaining the IP address of the current node, and comparing the IP address of the current node with the IP address of the target node; In response to a successful comparison, intercepting the data forwarding request by using a virtual machine program, where the virtual machine program is set at a preset position in the kernel space, and the preset position is before the kernel protocol stack; In response to a successful interception, redirecting the data forwarding request by using the virtual machine program according to a target mapping relationship table and the port value of the target node to complete data forwarding, where the target mapping relationship table is used to describe the correspondence between the port value of a node and the location parameters of a container, and the location parameters of the container at least include the IP address and port value of the container; Wherein, before receiving the data forwarding request, the method further includes: Obtaining the port value of the node and the port value of the container; Corresponding the port value of the node with the port value of the container one by one to construct a first mapping relationship of the container, and determining the container as a first mapping container; Judging whether there is a port conflict among multiple first mapping containers; If not, obtaining the IP address of the first mapping container; Constructing a second mapping relationship of the first mapping container according to the IP address and the first mapping relationship of the first mapping container, and determining the first mapping container as a second mapping container; Generating the target mapping relationship table according to the second mapping relationships corresponding to multiple second mapping containers.
2. The method according to claim 1, wherein Before judging whether there is a port conflict among multiple first mapping containers, the method further includes: Generating first mapping relationship parameters of the first mapping container according to the first mapping relationship of the first mapping container; Obtaining the configuration file of the first mapping container, and adding a first mapping relationship parameter field to the configuration file of the first mapping container; Writing the first mapping relationship parameters of the first mapping container into the first mapping relationship parameter field of the first mapping container.
3. The method according to claim 2, wherein The judging whether there is a port conflict among multiple first mapping containers includes: In response to the first mapping relationship parameters in the configuration files of multiple first mapping containers not appearing repeatedly, determining that there is no port conflict among multiple first mapping containers; In response to the first mapping relationship parameters in the configuration files of multiple first mapping containers appearing repeatedly, determining that there is a port conflict among multiple first mapping containers.
4. The method according to claim 1, wherein The constructing the second mapping relationship of the first mapping container according to the IP address and the first mapping relationship of the first mapping container includes: Obtaining the port value of the first mapping container, and obtaining the port value of the node corresponding to the port value of the first mapping container according to the first mapping relationship of the first mapping container; Construct a second mapping relationship of the first mapping container according to the Internet protocol address, port value of the first mapping container, and the port value of the node corresponding to the port value of the first mapping container.
5. The method according to claim 4, characterized in that, The constructing of the second mapping relationship of the first mapping container according to the Internet protocol address, port value of the first mapping container, and the port value of the node corresponding to the port value of the first mapping container includes: Based on the Internet protocol address and port value of the first mapping container, form a string of the first mapping container, and use the string as the position parameter; Establish a one-to-one correspondence between the port value of the node corresponding to the port value of the first mapping container and the string of the first mapping container to construct the second mapping relationship of the first mapping container.
6. The method according to claim 1, wherein Before intercepting the data forwarding request by using the virtual machine program, the method further includes: Write the virtual machine program by using a user program and load the virtual machine program into the kernel space; Use the kernel program to mount the virtual machine program to the preset position.
7. The method according to claim 6, wherein The writing of the virtual machine program by using the user program and loading the virtual machine program into the kernel space includes: Determine the preset position; Based on the preset position, write the virtual machine program by using the user program, and compile the virtual machine program into virtual machine program bytecode to load it into the kernel space.
8. The method according to claim 7, wherein The using of the kernel program to mount the virtual machine program to the preset position includes: Use the kernel program to perform a security check on the virtual machine program bytecode; In response to passing the security check, use the kernel program to recompile the virtual machine program bytecode into the virtual machine program, and mount the virtual machine program to the preset position.
9. The method according to claim 7, wherein The determining of the preset position includes: Judge whether the current node supports fast data path mounting and / or traffic controller mounting; In response to the current node supporting the fast data path mounting and not supporting the traffic controller mounting, mount the virtual machine program on the fast data path hook in the kernel space; In response to the current node supporting the traffic controller mounting and not supporting the fast data path mounting, mount the virtual machine program on the traffic controller hook in the kernel space; In response to the current node supporting the fast data path mounting and the traffic controller mounting, mount the virtual machine program on the fast data path hook in the kernel space.
10. The method according to claim 5, characterized in that The using of the virtual machine program to redirect the data forwarding request according to the target mapping relationship table and the port value of the target node to complete data forwarding includes: Match the port value of the target node with the port value of the node in the target mapping relationship table to obtain the corresponding string of the target container, where the string of the target container includes the Internet protocol address and port value of the target container; Determine a target container group according to the Internet protocol address of the target container, where the target container group is used to encapsulate the target container. Determine a target port on the current node according to the port value of the target node; According to the Internet protocol address of the target container, use the virtual machine program to forward the data forwarding request from the target port of the current node to the target container group; Determine the target container according to the port value of the target container, and use the virtual machine program to forward the data forwarding request from the target container group to the target container.
11. According to the method described in claim 1, wherein, The method further includes: Monitor the configuration file of the second mapped container; In response to monitoring that the configuration file of the second mapped container has been deleted, obtain the port value of the second mapped container, and according to the first mapping relationship of the second mapped container, obtain the port value of the node corresponding to the port value of the second mapped container; Match the port value of the node corresponding to the port value of the second mapped container with the port value of the node in the target mapping relationship table to obtain the target mapping relationship of the second mapped container; Delete the target mapping relationship of the second mapped container from the target mapping relationship table.
12. An electronic device, characterized in that, It includes: A memory for storing a computer program; A processor for implementing the steps of the data forwarding method according to any one of claims 1 to 11 when executing the computer program.
13. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, wherein the computer program implements the steps of the data forwarding method according to any one of claims 1 to 11 when executed by a processor.
14. A computer program product, comprising a computer program, characterized in that, The computer program implements the steps of the data forwarding method according to any one of claims 1 to 11 when executed by a processor.
Citation Information
Patent Citations
Session keeping method and device in k8s cluster, computer equipment and medium
CN119316428A