Container communication method and device, electronic equipment and storage medium
By deploying virtual network switches in the host and establishing a communication path between container-virtual network switch-host-external network, the problem of container communication capabilities in containerized mixed environments is solved, and efficient network forwarding and isolation monitoring is achieved.
Patent Information
- Application Number
- CN202411954073.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-12-27
- Publication Date
- 2025-06-06
AI Technical Summary
In the environment of container mixing, how to ensure the normal communication capabilities of the container, especially when the network environment is complicated.
Deploy a virtual network switch in the host, and establish a network communication path between container-virtual network switch-host-external network through the virtual network card to realize the network forwarding function of container-to-external network.
The network forwarding and isolation monitoring of multiple containers is realized through the software services of the virtual network switch, which improves the network forwarding performance and ensures the normal communication capabilities of the container.
Smart Images

Figure CN120104245A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of container technology, and in particular to a container communication method, device, electronic device, and storage medium. Background Art
[0002] Container is a lightweight virtualization technology that packages applications and their dependencies into an independent, portable operating environment, allowing resource isolation and restriction at the operating system level, so that multiple containers can share the operating system kernel on the same host, while running independently without interfering with each other; containerized co-location can make better use of idle resources and improve overall resource utilization by co-deploying different types of businesses or services in the same VPC. However, containerized co-location will increase the complexity of the network environment. How to ensure the normal communication capabilities of containers while co-locating containers is an urgent problem to be solved. Summary of the invention
[0003] The present application provides a container communication method, device, electronic device and storage medium. The technical solution is as follows:
[0004] According to one aspect of the present application, a container communication method is provided, the method being applied to a host machine, wherein a virtual network switch and at least one container are deployed in the host machine, the method comprising:
[0005] When the target container has a network forwarding requirement, the target container sends a network forwarding data packet to the virtual network switch through a first virtual network card pair, where the first virtual network card pair is used to connect the target container and the virtual network switch, and different containers and virtual switches are connected through different first virtual network card pairs;
[0006] The virtual network switch receives the network forwarding data packet through the first virtual network card pair, and forwards the network forwarding data packet to the host machine through the second virtual network card pair, wherein the second virtual network card pair is used to connect the virtual network switch and the host machine;
[0007] The host machine receives the network forwarding data packet through the second virtual network card pair, and sends the network forwarding data packet to the external network through the target network interface.
[0008] According to another aspect of the present application, a container communication device is provided, the device is applied to a host machine, a virtual network switch and at least one container are deployed in the host machine, and the device includes:
[0009] A first sending module, configured to, when the target container has a network forwarding requirement, cause the target container to send a network forwarding data packet to the virtual network switch through a first virtual network card pair, wherein the first virtual network card pair is used to connect the target container and the virtual network switch, and different containers and virtual switches are connected through different first virtual network card pairs;
[0010] A second sending module, configured for the virtual network switch to receive the network forwarding data packet through the first virtual network card pair, and to forward the network forwarding data packet to the host machine through the second virtual network card pair, wherein the second virtual network card pair is configured to connect the virtual network switch and the host machine;
[0011] The third sending module is used for the host machine to receive the network forwarding data packet through the second virtual network card pair, and to send the network forwarding data packet to the external network through the target network interface.
[0012] According to another aspect of the present application, an electronic device is provided, including: a processor and a memory storing a program, wherein the program includes instructions, and when the instructions are executed by the processor, the processor executes the container communication method as described above.
[0013] According to another aspect of the present application, a non-transitory computer-readable storage medium storing computer instructions is provided, wherein the computer instructions are used to cause the computer to execute the container communication method as described above.
[0014] According to another aspect of the present application, a computer program product is provided, the computer program product comprising computer instructions, the computer instructions being stored in a computer-readable storage medium. A processor of a computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the above container communication method.
[0015] The beneficial effects brought by the technical solution provided by the embodiment of the present application include at least:
[0016] The embodiment of the present application constructs a new container network communication system: a virtual network switch and at least one container are deployed in a host machine, the container and the virtual network switch are connected through a first virtual network card pair, and the virtual network switch and the host machine are connected through a second virtual network card pair, thereby constructing a network communication path of container-virtual network switch-host machine-external network, thereby realizing a network forwarding function from container to external network; and because the virtual network switch is essentially a software service, the network forwarding and isolation monitoring of multiple containers are realized by the software service, which can improve the network forwarding performance compared to execution by the host machine. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] Further details, features and advantages of the present application are disclosed in the following description of exemplary embodiments in conjunction with the accompanying drawings, in which:
[0018] Figure 1 A schematic diagram showing an example system in which various methods described herein may be implemented according to an exemplary embodiment of the present application;
[0019] Figure 2 A flow chart of a container communication method according to an exemplary embodiment of the present application is shown;
[0020] Figure 3 A flow chart of a container communication method according to an exemplary embodiment of the present application is shown;
[0021] Figure 4 A flow chart of another container communication method according to an exemplary embodiment of the present application is shown;
[0022] Figure 5 It is a schematic diagram of access control provided by an exemplary embodiment of the present application;
[0023] Figure 6 It is a structural schematic diagram of a container communication device provided in an embodiment of the present application;
[0024] Figure 7 A structural block diagram of an exemplary electronic device that can be used to implement the embodiments of the present application is shown. DETAILED DESCRIPTION
[0025] The embodiments of the present application will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present application are shown in the accompanying drawings, it should be understood that the present application can be implemented in various forms and should not be construed as being limited to the embodiments described herein. Instead, these embodiments are provided to provide a more thorough and complete understanding of the present application. It should be understood that the drawings and embodiments of the present application are only for exemplary purposes and are not intended to limit the scope of protection of the present application.
[0026] It should be understood that the various steps described in the method implementation of the present application can be performed in different orders and / or performed in parallel. In addition, the method implementation may include additional steps and / or omit the steps shown. The scope of the present application is not limited in this respect.
[0027] The term "including" and its variations used herein are open inclusions, i.e., "including but not limited to". The term "based on" means "based at least in part". The term "one embodiment" means "at least one embodiment"; the term "another embodiment" means "at least one other embodiment"; the term "some embodiments" means "at least some embodiments". The relevant definitions of other terms will be given in the following description. It should be noted that the concepts of "first", "second", etc. mentioned in this application are only used to distinguish different devices, modules or units, and are not used to limit the order or interdependence of the functions performed by these devices, modules or units. It should be noted that the modifications of "one" and "multiple" mentioned in this application are illustrative rather than restrictive. Those skilled in the art should understand that unless otherwise clearly indicated in the context, it should be understood as "one or more". The names of the messages or information exchanged between multiple devices in the embodiments of this application are only for illustrative purposes, and are not used to limit the scope of these messages or information.
[0028] The solution of the present invention is described below with reference to the accompanying drawings, and the technical solution provided by the embodiment of the present invention is explained in detail through specific embodiments and their application scenarios.
[0029] In order to ensure the network communication performance of containers while implementing containerized co-location, this application adds a virtual network switch to the container communication scenario, and solves problems such as container network access connectivity, access control, and network monitoring through the virtual network switch. Figure 1 Schematic diagram of the system architecture provided by the exemplary embodiment of the present application. Figure 1 As shown, the entire network communication system includes an external network 110 , a host machine 120 , a virtual network switch 130 and at least one container 140 , and the virtual network switch 130 and the at least one container 140 are deployed in the host machine 120 .
[0030] Among them, the container 140 is connected to the virtual network switch 130 through a virtual network card pair, and the flow table rules are set in the virtual network switch 130 to realize the forwarding of network data packets. The virtual network switch 130 is also connected to the host machine 120 through the virtual network card pair, and routing rules are configured in the host machine 120 to realize the forwarding of network data packets with the external network 110.
[0031] based on Figure 1 Please refer to the system architecture diagram shown in Figure 2 , which shows a flow chart of a container communication method according to an exemplary embodiment of the present application. The method is applied to a host machine as an example for explanation. Figure 2 As shown, the method includes:
[0032] Step 201: When the target container has a network forwarding requirement, the target container sends a network forwarding data packet to the virtual network switch through the first virtual network card pair. The first virtual network card pair is used to connect the target container and the virtual network switch, and different containers and virtual switches are connected through different first virtual network card pairs.
[0033] Among them, a virtual network switch and at least one container are deployed in the host machine. Taking the target container in at least one container as an example, the target container is connected to the virtual network switch through the first virtual network card pair, the virtual network switch is connected to the host machine through the second virtual network card pair, and the host machine is connected to the external network through the target network interface, thereby forming a network data forwarding path from the container to the external network. Different containers are connected to the virtual network switch through different first virtual network card pairs to achieve isolation between different containers.
[0034] Based on the network data forwarding path of target container-virtual network switch-host machine-external network, when the target container has the network forwarding requirement, the target container can send a network forwarding data packet to the virtual network switch through the first virtual network card.
[0035] Step 202: The virtual network switch receives a network forwarding data packet through a first virtual network card pair, and forwards the network forwarding data packet to a host machine through a second virtual network card pair, where the second virtual network card pair is used to connect the virtual network switch and the host machine.
[0036] The corresponding virtual network switch can receive the network forwarding data packets sent by the target container through the first virtual network card, and forward the network forwarding data packets to the host through the second virtual network card, thereby realizing communication between the container and the host, and then using the host to communicate with the external network.
[0037] Since the virtual network switch is essentially a software service, the network forwarding function of multiple containers can be implemented through the virtual network switch, replacing the host machine to directly process the network forwarding data packets of multiple containers, which can improve the network forwarding performance.
[0038] Step 203: the host machine forwards the data packet to the receiving network through the second virtual network card, and sends the network forwarding data packet to the external network through the target network interface.
[0039] The corresponding host machine can receive the network forwarding data packet of the target container forwarded by the virtual network switch through the second virtual network card, and the host machine is configured with a hardware target network interface, thereby sending the network forwarding data packet to the external network through the target network interface.
[0040] In summary, the embodiment of the present application constructs a new container network communication system: a virtual network switch and at least one container are deployed in the host machine, the container and the virtual network switch are connected through a first virtual network card pair, and the virtual network switch and the host machine are connected through a second virtual network card pair, thereby constructing a network communication path of container-virtual network switch-host machine-external network, thereby realizing the network forwarding function from container to external network; and because the virtual network switch is essentially a software service, the network forwarding and isolation monitoring of multiple containers are realized by the software service, which can improve the network forwarding performance compared to the execution by the host machine.
[0041] The first virtual network card pair and the second virtual network card pair each include two network interfaces, and each network interface is in a different network namespace to act as a bridge to achieve communication between different network namespaces.
[0042] Please refer to Figure 3 , which shows a flow chart of another container communication method according to an exemplary embodiment of the present application. This method is applied to a host machine as an example for explanation. Figure 3 As shown, the method includes:
[0043] Step 301: When the target container has a network forwarding requirement, the target container sends a network forwarding data packet to the virtual network switch through the first virtual network interface.
[0044] Among them, the first virtual network card pair used to connect the target container and the virtual network switch includes a first virtual network interface and a second virtual network interface, the first virtual network interface is located in the target container, and the second virtual network interface is located in the virtual network switch to achieve the connection between the target container and the virtual network switch.
[0045] After the target container is created, it will be configured with a container routing rule, which indicates that the target container can send network forwarding packets through a specific virtual network interface. Correspondingly, when the target container has network forwarding requirements, the target container can determine the IP address of the first virtual network interface in the first virtual network card pair based on the container routing rule, and then send the network forwarding packet to the virtual network switch through the first virtual network interface based on the IP address.
[0046] It should be noted that no matter the target container communicates with other containers in the host machine, or communicates with the host machine, or communicates with an external network, a network forwarding data packet is sent to the virtual network switch through the first virtual network interface in the first virtual network card pair.
[0047] Step 302: The virtual network switch receives a network forwarding data packet through the second virtual network interface, and forwards the network forwarding data packet to the host machine through the third virtual network interface.
[0048] Similarly, the second virtual network card pair for connecting the virtual network switch and the host machine includes a third virtual network interface and a fourth virtual network interface. The third virtual network interface is located in the virtual network switch and the fourth virtual network interface is located in the host machine to realize the connection between the virtual network switch and the host machine.
[0049] The virtual network switch is configured with a target flow table rule, which is a set of rules used in the virtual network switch to define the packet forwarding mode and path. It implements flexible flow control through matching conditions and actions, and supports dynamic updates and adjustments to meet complex network requirements. The corresponding virtual network switch can receive the network forwarding data packet sent by the target container through the second virtual network interface, and determine the IP address of the third virtual network interface based on the target flow table rule, thereby sending the network forwarding data packet to the host through the third virtual network interface based on the IP address.
[0050] Step 303: The host machine receives the network forwarding data packet through the fourth virtual network interface, and sends the network forwarding data packet to the external network through the target network interface.
[0051] The corresponding host receives the network forwarding data packet through the fourth virtual network interface in the second virtual network card pair, and determines the IP address of the target network interface according to the configured target routing rule, so as to send the network forwarding data packet to the external network through the target network interface.
[0052] Optionally, in other possible implementations, if a first container, a second container and a virtual network switch are deployed in a host machine, the first container is connected to the virtual network switch through a first virtual network card pair 1, the second container is connected to the virtual network switch through a first virtual network card pair 2, and the virtual network switch is connected to the host machine through a second virtual network card pair; if the first container needs to access the second container, the first container sends a data packet to the virtual network switch through the first virtual network card pair 1, and the virtual network switch receives the data packet through the first virtual network card pair 1, and matches the data packet with the target flow table rule. If the matching result indicates that container 2 allows container 1 to access, the virtual network switch forwards the data packet to container 2 through the first virtual network card pair 2 to achieve communication between container 1 and container 2.
[0053] In this embodiment, the first virtual network card pair and the second virtual network card pair each include two virtual network interfaces, which are respectively deployed in two different network namespaces to act as a bridge to achieve communication between different network namespaces. For example, by deploying the first virtual network interface in the first virtual network card pair in a container and deploying the second virtual network interface in the first virtual network card pair in a virtual network switch, communication between the container and the virtual network switch can be achieved through the first virtual network card pair.
[0054] use Figure 1 The container network communication system can not only realize the network forwarding function from the container to the external network, but also realize the network access function of the external network to the target container.
[0055] Please refer to Figure 4 , which shows a flow chart of another container communication method according to an exemplary embodiment of the present application. This method is applied to a host machine as an example for explanation. Figure 4 As shown, the method includes:
[0056] Step 401: The host receives a network access data packet through a target network interface.
[0057] If the external network needs to access the target container in the host machine, the host machine will first receive the network access data packet sent by the external network through the target network interface, and then realize the network access function through the communication path of host machine-virtual network switch-target container.
[0058] Step 402: The host machine forwards the network access data packet to the virtual network switch through the second virtual network card.
[0059] Since the host machine is connected to the virtual network switch through the second virtual network card pair, the corresponding host machine can forward the network access data packet to the virtual network switch through the second virtual network card pair. Specifically, the host machine sends the network access data packet to the virtual network switch through the fourth virtual network interface in the second virtual network card pair.
[0060] Similar to the network forwarding function, when implementing the network access function, it is also necessary to implement it through the target routing rules in the host machine. Correspondingly, in an exemplary example, step 402 can also be replaced by step 402A: the host machine determines to forward the network access data packet to the virtual network switch through the second virtual network card based on the target routing rules.
[0061] Optionally, step 402A may also include step 402A1 and step 402A2.
[0062] Step 402A1, the host matches the target routing rule and the network access data packet to obtain a first matching result.
[0063] Step 402A2: If the first matching result indicates that the network access data packet is used to access the target container, the host machine forwards the network access data packet to the virtual network switch through the second virtual network card.
[0064] Specifically, after receiving the network access data packet, the host machine will match the target routing rule and the network access data packet to obtain a first matching result, which is the routing rule that matches the network access data packet. If the routing rule (or the first matching result) indicates that the network access data packet is used to access the target container, the host machine forwards the network access data packet to the virtual network switch through the second virtual network card.
[0065] The target routing rule is determined by conditions and execution actions. It matches the attribute information of the data packet (for example, IP address, protocol, etc.) with the conditions of the target routing rule. If the conditions match, the routing rule that matches the conditions is determined as the first matching result, and based on the execution action in the routing rule, it is determined how to handle the network access data packet.
[0066] Step 403: The virtual network switch receives the network access data packet through the second virtual network card pair, and forwards the network access data packet to the target container through the first virtual network card pair.
[0067] The corresponding virtual network switch receives the network access data packet through the second virtual network card pair. Since the virtual network switch is connected to the target container through the first virtual network card pair, the network access data packet can be forwarded to the target container through the first virtual network card pair. Specifically, the virtual network switch receives the network access data packet through the third virtual network interface in the second virtual network card pair, and forwards the network access data packet to the target container through the second virtual network interface in the first virtual network card pair.
[0068] Optionally, the business personnel implement network access control for each container by configuring the target flow table rules in the virtual switch. For example, if a container is only allowed to be accessed through a specific network protocol, the corresponding rules can be configured in the target flow table rules to implement the access control. Correspondingly, based on the configuration of the target flow table rules, in an exemplary example, step 403 can also include step 403A: the virtual network switch determines to forward the network access data packet to the target container through the first virtual network card based on the target flow table rules.
[0069] Optionally, step 403A may also include step 403A1 and step 403A2.
[0070] Step 403A1, the virtual network switch matches the target flow table rule and the network access data packet to obtain a second matching result.
[0071] Step 403A2: If the second matching result indicates that access to the target container is allowed, the virtual network switch forwards the network access data packet to the target container through the first virtual network card.
[0072] Specifically, after receiving the network access data packet forwarded by the host, the virtual network switch matches the network access data packet and the target flow table rule to obtain a matching target rule, i.e., the second matching result. If the second matching result indicates that the network access data packet is allowed to access the target container, the virtual network switch will forward the network access data packet to the target container through the first virtual network card; if the second matching result indicates that the network access data packet is not allowed to access the target container (i.e., access restriction), the virtual network switch will not forward the network access data packet, but delete or discard the network access data packet. The action (discard or forward) performed by the virtual network switch is determined by the execution action in the matched target rule.
[0073] In order to achieve flexible access control, a controller for users (business personnel) is provided, and users can directly configure access control parameters in the configuration interface corresponding to the controller to achieve personalized and flexible network access control. In a possible implementation, the user enters the access control parameters in the configuration interface corresponding to the target controller, and the corresponding virtual network switch can receive the access control parameters sent by the target controller and generate the target flow table rules based on the access control parameters.
[0074] Figure 5 Schematic diagram of access control provided by the exemplary embodiment of the present application. Figure 5 As shown in the figure, the user fills in the access control information through the web page corresponding to the controller (the access control information is first stored in the database); then the target controller converts the access control information into the configuration parameters of OVS (virtual network switch) and sends it to OVS; after receiving the configuration information, the OVS control component (Vswitchd) in OVS converts it into target flow table rules and adds it to OVS to implement access control of network traffic. This process allows users to directly define and modify network access control policies through a user-friendly web interface. These policies are then intelligently converted by the controller into configuration parameters that can be recognized by OVS and dynamically pushed to the OVS instances in the network. Once OVS receives this configuration information, it will quickly convert it into specific target flow table rules, which directly act on network traffic and implement fine-grained access control of network traffic. For example, by matching the target flow table rules, access control between two containers can be implemented.
[0075] The significant advantage of this architecture is its strong scalability. First, by managing network policies through a centralized target controller, the network scale can be easily expanded because new OVS instances can be seamlessly added to the network and uniformly managed and configured by the target controller. Secondly, the decoupling design between the target controller and OVS enables the system to flexibly respond to different network devices and protocols, facilitating the introduction of new network functions or optimizing existing functions. In addition, since network policies are defined at the logical level, they can be easily adjusted dynamically according to business needs without changing the physical network layout or reconfiguring equipment.
[0076] In this embodiment, by configuring the target flow table rules in the virtual network switch, network access control for each container can be achieved, and the virtual switch performs the matching of the target flow table rules instead of the host machine to perform access control, which can reduce the processing performance pressure on the host machine and improve the network forwarding performance.
[0077] In other possible scenarios, the virtual network switch also has a network traffic monitoring function. By enabling the sflow collection function of the virtual network switch (OVS) and configuring the collection push address, sampling frequency and other information, fine monitoring of network traffic can be achieved. In a corresponding possible implementation, the virtual network switch collects network traffic data according to a preset period and forwards the network traffic data to the target receiving end, which is used to monitor network traffic based on network traffic data packets.
[0078] Specifically, we first enable the sFlow collection function of OVS and configure its push address (i.e. the location of the target receiver) and key parameters such as sampling frequency in detail to achieve fine monitoring of network traffic. As a lightweight network traffic monitoring protocol, sFlow can efficiently collect detailed information at the packet level, including source address, destination address, port number, protocol type, etc., without significantly affecting network performance.
[0079] Subsequently, at the target receiving end, the system receives sFlow packets from OVS and uses professional parsing tools and techniques to perform in-depth analysis of these packets. During the analysis process, not only the basic information of the flow data is extracted, but further data aggregation, statistical analysis and other processing may also be performed to more intuitively display the characteristics and trends of network traffic.
[0080] Finally, through visualization technology, the parsed and calculated data are presented in the form of charts, reports, etc., helping network administrators to quickly understand the network operation status, identify potential problems and risks, and formulate corresponding network optimization and troubleshooting strategies accordingly.
[0081] In summary, the above steps build an efficient and automated network traffic monitoring and analysis system by utilizing the sFlow function of OVS and the data parsing and display capabilities of the server, providing a strong guarantee for improving network performance and timely detection and resolution of faults.
[0082] If you need to implement the network access function and network forwarding function provided in the above embodiment, you need to perform a series of configuration operations after creating the container. The process of configuring the network for the container can also include the following steps:
[0083] Step 1: After creating the target container in the host machine, assign a container IP address to the target container and configure container routing rules for the target container.
[0084] Step 2: Create a first virtual network card pair, where the first virtual network interface of the first virtual network card pair is located in the target container, and the second virtual network interface of the first virtual network card pair is located in the virtual switch.
[0085] Step 3: Configure the target bridge in the virtual switch.
[0086] Step 4: Create a second virtual network card pair, the third virtual network interface of the second virtual network card pair is located in the virtual network switch, and the fourth virtual network interface of the second virtual network card pair is located in the host machine, and a fixed IP is allocated to the network card at one end of the host machine.
[0087] Step 5: Configure target routing rules for the host.
[0088] Step 6: Enable the IP forwarding function of the host machine.
[0089] By turning on the host's ip_forward parameter, traffic forwarding on the host is allowed.
[0090] Assign an independent IP address to the container, configure its virtual network interface (NIC), and set the default routing rules to ensure that the container can communicate correctly. Next, use Linux's veth pair technology to create a pair of virtual network interfaces, one of which is assigned to the container and the other is connected to the Open vSwitch (OVS) bridge, thus achieving a direct connection between the container and OVS. Subsequently, configure the OVS bridge, including the necessary network policies and forwarding rules, to support complex network topologies and traffic management.
[0091] In order to ensure the correct forwarding of network traffic, further set routing rules and routing tables, especially when it comes to communication between containers and external networks such as virtual private clouds (VPCs), these routing settings are crucial. They ensure that network packets can flow along the predetermined path and realize the function of forwarding traffic from containers to external networks such as VPCs through the host.
[0092] Finally, enable the host's IP forwarding function (by modifying the ip_forward parameter), allowing the host to act as a relay station for network traffic and forward data packets from containers or other network interfaces. This step is a necessary condition for enabling containers to communicate with external networks, ensuring the connectivity and flexibility of the entire network architecture.
[0093] Please refer to Figure 6 , which is a schematic diagram of the structure of a container communication device provided in an embodiment of the present application. For example, Figure 6 As shown, the device 600 includes:
[0094] A first sending module 601 is used for, when the target container has a network forwarding requirement, the target container sending a network forwarding data packet to the virtual network switch through a first virtual network card pair, wherein the first virtual network card pair is used to connect the target container and the virtual network switch, and different containers and virtual switches are connected through different first virtual network card pairs;
[0095] A second sending module 602, configured for the virtual network switch to receive the network forwarding data packet through the first virtual network card pair, and to forward the network forwarding data packet to the host machine through the second virtual network card pair, wherein the second virtual network card pair is configured to connect the virtual network switch and the host machine;
[0096] The third sending module 603 is used for the host machine to receive the network forwarding data packet through the second virtual network card pair, and to send the network forwarding data packet to the external network through the target network interface.
[0097] Optionally, the first virtual network card pair includes a first virtual network interface and a second virtual network interface, and the second virtual network card pair includes a third virtual network interface and a fourth virtual network interface;
[0098] The first sending module 601 is further configured to:
[0099] The target container sends the network forwarding data packet to the virtual network switch through the first virtual network interface;
[0100] The second sending module 602 is further configured to:
[0101] The virtual network switch receives the network forwarding data packet through the second virtual network interface, and forwards the network forwarding data packet to the host machine through the third virtual network interface;
[0102] The third sending module 603 is further used for:
[0103] The host machine receives the network forwarding data packet through the fourth virtual network interface.
[0104] Optionally, the device further comprises:
[0105] A first receiving module, configured for the host machine to receive a network access data packet through the target network interface;
[0106] A fourth sending module, configured for the host machine to forward the network access data packet to the virtual network switch through the second virtual network card;
[0107] A fifth sending module is used for the virtual network switch to receive the network access data packet through the second virtual network card pair, and to forward the network access data packet to the target container through the first virtual network card pair.
[0108] Optionally, the fourth sending module is further used to:
[0109] The host determines, based on the target routing rule, to forward the network access data packet to the virtual network switch through the second virtual network card;
[0110] The fifth sending module is further used for:
[0111] The virtual network switch determines, based on a target flow table rule, to forward the network access data packet to the target container through the first virtual network card.
[0112] Optionally, the fourth sending module is further used to:
[0113] The host machine matches the target routing rule and the network access data packet to obtain a first matching result;
[0114] If the first matching result indicates that the network access data packet is used to access the target container, the host machine forwards the network access data packet to the virtual network switch through the second virtual network card.
[0115] Optionally, the fifth sending module is further used to:
[0116] The virtual network switch matches the target flow table rule and the network access data packet to obtain a second matching result;
[0117] If the second matching result indicates that access to the target container is allowed, the virtual network switch forwards the network access data packet to the target container through the first virtual network card.
[0118] Optionally, the device further comprises:
[0119] A second receiving module, configured for the virtual network switch to receive access control parameters sent by the target controller, wherein the access control parameters are obtained through input operations on a configuration interface corresponding to the target controller;
[0120] A generating module is used for the virtual network switch to generate the target flow table rule based on the access control parameter.
[0121] The exemplary embodiment of the present application also provides an electronic device, comprising: at least one processor; and a memory connected to the at least one processor in communication. The memory stores a computer program that can be executed by the at least one processor, and the computer program is used to cause the electronic device to perform the method according to the embodiment of the present application when executed by the at least one processor.
[0122] The exemplary embodiment of the present application further provides a non-transitory computer-readable storage medium storing a computer program, wherein the computer program, when executed by a processor of a computer, is used to cause the computer to perform a method according to an embodiment of the present application.
[0123] The exemplary embodiments of the present application further provide a computer program product, including a computer program, wherein when the computer program is executed by a processor of a computer, it is used to enable the computer to execute the method according to the embodiment of the present application.
[0124] refer to Figure 7 , the structural block diagram of the electronic device 700 that can be used as the server or client of the present application will now be described, which is an example of the hardware device that can be applied to various aspects of the present application. The electronic device is intended to represent various forms of digital electronic computer equipment, such as laptop computers, desktop computers, workbenches, personal digital assistants, servers, blade servers, mainframe computers, and other suitable computers. The electronic device can also represent various forms of mobile devices, such as personal digital processing, cellular phones, smart phones, wearable devices and other similar computing devices. The components shown herein, their connections and relationships, and their functions are only examples, and are not intended to limit the implementation of the present application described and / or required herein.
[0125] like Figure 7As shown, the electronic device 700 includes a computing unit 701, which can perform various appropriate actions and processes according to a computer program stored in a read-only memory (ROM) 702 or a computer program loaded from a storage unit 708 into a random access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the device 700 can also be stored. The computing unit 701, the ROM 702, and the RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0126] A plurality of components in the electronic device 700 are connected to the I / O interface 705, including: an input unit 706, an output unit 707, a storage unit 708, and a communication unit 709. The input unit 706 may be any type of device capable of inputting information to the electronic device 700, and the input unit 706 may receive input digital or character information, and generate key signal inputs related to user settings and / or function control of the electronic device. The output unit 707 may be any type of device capable of presenting information, and may include but is not limited to a display, a speaker, a video / audio output terminal, a vibrator, and / or a printer. The storage unit 708 may include but is not limited to a disk, an optical disk. The communication unit 709 allows the electronic device 700 to exchange information / data with other devices through a computer network such as the Internet and / or various telecommunication networks, and may include but is not limited to a modem, a network card, an infrared communication device, a wireless communication transceiver, and / or a chipset, such as a Bluetooth device, a WiFi device, a WiMax device, a cellular communication device, and / or the like.
[0127] The computing unit 701 may be a variety of general and / or special processing components with processing and computing capabilities. Some examples of the computing unit 701 include, but are not limited to, a central processing unit (CPU), a graphics processing unit (GPU), various special artificial intelligence (AI) computing chips, various computing units running machine learning model algorithms, digital signal processors (DSPs), and any appropriate processors, controllers, microcontrollers, etc. The computing unit 701 performs the various methods and processes described above. For example, in some embodiments, Figure 2 , Figure 3 , Figure 4 The method shown may be implemented as a computer software program, which is tangibly contained in a machine-readable medium, such as storage unit 708. In some embodiments, part or all of the computer program may be loaded and / or installed on electronic device 700 via ROM 702 and / or communication unit 709. In some embodiments, computing unit 701 may be configured to execute the computer program by any other suitable means (e.g., by means of firmware). Figure 2 , Figure 3 , Figure 4The method shown.
[0128] The program code for implementing the method of the present application can be written in any combination of one or more programming languages. These program codes can be provided to a processor or controller of a general-purpose computer, a special-purpose computer, or other programmable data processing device, so that the program code, when executed by the processor or controller, implements the functions / operations specified in the flow chart and / or block diagram. The program code can be executed entirely on the machine, partially on the machine, partially on the machine and partially on a remote machine as a stand-alone software package, or entirely on a remote machine or server.
[0129] In the context of the present application, a machine-readable medium may be a tangible medium that may contain or store a program for use by or in conjunction with an instruction execution system, device, or equipment. A machine-readable medium may be a machine-readable signal medium or a machine-readable storage medium. A machine-readable medium may include, but is not limited to, an electronic, magnetic, optical, electromagnetic, infrared, or semiconductor system, device, or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium may include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.
[0130] As used herein, the terms "machine-readable medium" and "computer-readable medium" refer to any computer program product, apparatus, and / or device (e.g., disk, optical disk, memory, programmable logic device (PLD)) for providing machine instructions and / or data to a programmable processor, including a machine-readable medium that receives machine instructions as a machine-readable signal. The term "machine-readable signal" refers to any signal for providing machine instructions and / or data to a programmable processor.
[0131] To provide interaction with a user, the systems and techniques described herein can be implemented on a computer having: a display device (e.g., a CRT (cathode ray tube) or LCD (liquid crystal display) monitor) for displaying information to the user; and a keyboard and pointing device (e.g., a mouse or trackball) through which the user can provide input to the computer. Other types of devices can also be used to provide interaction with the user; for example, the feedback provided to the user can be any form of sensory feedback (e.g., visual feedback, auditory feedback, or tactile feedback); and input from the user can be received in any form (including acoustic input, voice input, or tactile input).
[0132] The systems and techniques described herein may be implemented in a computing system that includes back-end components (e.g., as a data server), or a computing system that includes middleware components (e.g., an application server), or a computing system that includes front-end components (e.g., a user computer with a graphical user interface or a web browser through which a user can interact with implementations of the systems and techniques described herein), or a computing system that includes any combination of such back-end components, middleware components, or front-end components. The components of the system may be interconnected by any form or medium of digital data communication (e.g., a communication network). Examples of communication networks include: a local area network (LAN), a wide area network (WAN), and the Internet.
[0133] A computer system may include clients and servers. Clients and servers are generally remote from each other and usually interact through a communication network. The relationship of client and server is generated by computer programs running on respective computers and having a client-server relationship to each other.
Claims
1. A container communication method, characterized in that: The method is applied to a host machine, in which a virtual network switch and at least one container are deployed, and the method includes: When the target container has a network forwarding requirement, the target container sends a network forwarding data packet to the virtual network switch through a first virtual network card pair, where the first virtual network card pair is used to connect the target container and the virtual network switch, and different containers and virtual switches are connected through different first virtual network card pairs; The virtual network switch receives the network forwarding data packet through the first virtual network card pair, and forwards the network forwarding data packet to the host machine through the second virtual network card pair, wherein the second virtual network card pair is used to connect the virtual network switch and the host machine; The host machine receives the network forwarding data packet through the second virtual network card pair, and sends the network forwarding data packet to the external network through the target network interface.
2. The method according to claim 1, characterized in that The first virtual network card pair includes a first virtual network interface and a second virtual network interface, and the second virtual network card pair includes a third virtual network interface and a fourth virtual network interface; The target container sends a network forwarding data packet to the virtual network switch through the first virtual network card pair, including: The target container sends the network forwarding data packet to the virtual network switch through the first virtual network interface; The virtual network switch receives the network forwarding data packet through the first virtual network card pair, and forwards the network forwarding data packet to the host machine through the second virtual network card pair, including: The virtual network switch receives the network forwarding data packet through the second virtual network interface, and forwards the network forwarding data packet to the host machine through the third virtual network interface; The host machine receives the network forwarding data packet through the second virtual network card pair, including: The host machine receives the network forwarding data packet through the fourth virtual network interface.
3. The method according to claim 1 or 2, characterized in that: The method further comprises: The host machine receives a network access data packet through the target network interface; The host machine forwards the network access data packet to the virtual network switch through the second virtual network card; The virtual network switch receives the network access data packet through the second virtual network card pair, and forwards the network access data packet to the target container through the first virtual network card pair.
4. The method according to claim 3, characterized in that The host machine forwards the network access data packet to the virtual network switch through the second virtual network card, including: The host determines, based on the target routing rule, to forward the network access data packet to the virtual network switch through the second virtual network card; The forwarding of the network access data packet to the target container through the first virtual network card includes: The virtual network switch determines, based on a target flow table rule, to forward the network access data packet to the target container through the first virtual network card.
5. The method according to claim 4, characterized in that The host determines, based on the target routing rule, to forward the network access data packet to the virtual network switch through the second virtual network card, including: The host machine matches the target routing rule and the network access data packet to obtain a first matching result; If the first matching result indicates that the network access data packet is used to access the target container, the host machine forwards the network access data packet to the virtual network switch through the second virtual network card.
6. The method according to claim 5, characterized in that The virtual network switch determines, based on the target flow table rule, to forward the network access data packet to the target container through the first virtual network card, including: The virtual network switch matches the target flow table rule and the network access data packet to obtain a second matching result; If the second matching result indicates that access to the target container is allowed, the virtual network switch forwards the network access data packet to the target container through the first virtual network card.
7. The method according to claim 4, characterized in that The method further comprises: The virtual network switch receives the access control parameters sent by the target controller, wherein the access control parameters are obtained through input operations on the corresponding configuration interface of the target controller; The virtual network switch generates the target flow table rule based on the access control parameter.
8. A container communication device, characterized in that: The device is applied to a host machine, in which a virtual network switch and at least one container are deployed, and the device includes: A first sending module, configured to, when the target container has a network forwarding requirement, cause the target container to send a network forwarding data packet to the virtual network switch through a first virtual network card pair, wherein the first virtual network card pair is used to connect the target container and the virtual network switch, and different containers and virtual switches are connected through different first virtual network card pairs; A second sending module, configured for the virtual network switch to receive the network forwarding data packet through the first virtual network card pair, and to forward the network forwarding data packet to the host machine through the second virtual network card pair, wherein the second virtual network card pair is configured to connect the virtual network switch and the host machine; The third sending module is used for the host machine to receive the network forwarding data packet through the second virtual network card pair, and to send the network forwarding data packet to the external network through the target network interface.
9. An electronic device, comprising: processor; as well as Memory for storing programs, The program includes instructions, which, when executed by the processor, cause the processor to perform the method according to any one of claims 1 to 7.
10. A non-transitory computer-readable storage medium storing computer instructions, wherein: The computer instructions are used to cause the computer to execute the method according to any one of claims 1-7.