Network proxy method and related device
By offloading network proxy components from CPU to DPU on the same node in cloud computing scenarios, the resource competition problem is solved, performance and efficiency are improved, and more efficient resource utilization is achieved.
Patent Information
- Application Number
- CN202311684256.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-07
- Publication Date
- 2025-06-10
AI Technical Summary
In cloud computing scenarios, because the network proxy components need to share CPU resources with the application, the resource competition is caused, reducing the number of instances that the application can deploy, affecting performance.
Run the application on the CPU, and the network proxy component runs on the DPU and is deployed on the same node, forwarding packets to the network proxy component on the DPU through the host network space for processing, thereby reducing the processing pressure on the CPU.
By offloading the network proxy components to the DPU, the processing pressure on the CPU is reduced, the performance of the network proxy service is improved, the CPU can provide more resources to deploy applications, and the DPU's hardware processing capabilities are effectively utilized.
Smart Images

Figure CN120128459A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing technology, and in particular, to a network proxy method and related devices. Background Art
[0002] In the field of cloud computing, cloud native is an application development and deployment technology in cloud computing platforms, mainly characterized by containerized development and deployment, dynamic scheduling, and scaling. In cloud native scenarios, a service mesh is introduced as the basic network infrastructure. The service mesh will mount a network proxy component in the form of a sidecar next to each application, so as to achieve network policy control without the application being aware of it.
[0003] Since the network proxy component is mounted next to the application in the form of a sidecar, the Central Processing Unit (CPU) often needs to run the application and the network proxy component simultaneously. In this way, although the network proxy component mounted in the form of a sidecar provides relatively flexible network processing capabilities, it leads to resource competition between the application and the network proxy component on the CPU, reducing the number of instances of the application that can be deployed and affecting the performance in cloud computing scenarios. Summary of the Invention
[0004] This application provides a network proxy method, which can improve the performance in cloud computing scenarios.
[0005] In a first aspect of this application, a network proxy method is provided. This method is applied to cloud native scenarios. Specifically, the method includes: the network namespace on the host where the first application runs (abbreviated as the host network space) obtains a first data packet from the first application, where the first application runs on the first CPU. That is, the first data packet is sent by the first application running on the first CPU. The host network space is, for example, a network stack created on the host where the first application runs, and is used to perform operations such as filtering and routing on data packets.
[0006] Then, the host network space forwards the first data packet to the first network proxy component. The first network proxy component is used to provide network proxy services for the first data packet, and the first network proxy component runs on the first Data Processing Unit (DPU). The first CPU and the first DPU are deployed on the same node, for example, on the same server. That is, a mapping relationship is established between the first CPU and the first DPU. The first DPU is used to provide network proxy services for the application running on the first CPU, so that there is no need to run the corresponding network proxy component on the first CPU.
[0007] In this solution, the application runs on the CPU, while the network proxy component of the application runs on the DPU, and the DPU and the CPU are deployed on the same node. Moreover, the data packets sent by the application are forwarded to the network proxy component on the DPU for processing, so as to provide network proxy services for the application. Since the DPU has hardware support for accelerating data packet processing (that is, the DPU can provide more efficient network proxy services than the CPU), unloading the network proxy component from the CPU to the DPU on the same node can relieve the processing pressure of the CPU, improve the performance of the network proxy service, ensure that more resources can be provided on the CPU to deploy the application, and effectively utilize the hardware processing capacity of the DPU.
[0008] In a possible implementation, the host network space determines to forward the first data packet using a first routing when the source address of the first data packet is the address where the application running in the first CPU is located and the first data packet is sent by a virtual network card. The first routing is used to forward the data packet to the first network proxy component on the first DPU. In this way, based on the indication of the first routing, the host network space forwards the first data packet to the first network proxy component.
[0009] That is to say, when the source address of the first data packet is the address where the application running in the first CPU is located and the first data packet is sent by a virtual network card, the host network space can determine that the first data packet is sent by the application running in the first CPU, rather than going to the application running in the first CPU. Therefore, the first data packet needs to be forwarded to the first network proxy component on the first DPU for processing.
[0010] In this solution, by identifying the source address of the data packet and the sender of the data packet, it is possible to determine whether the data packet has been processed by the network proxy, and then forward the data packet to the network proxy component on the DPU for processing, ensuring the feasibility of the solution.
[0011] In a possible implementation, in response to the first data packet matching the preset rules in the data packet filtering system, the host network space can mark the first data packet. The preset rules are that the source address of the data packet is the address where the application running in the first CPU is located and the data packet is sent by a virtual network card. Then, based on the mark on the first data packet, the host network space determines to forward the first data packet using the first routing.
[0012] Among them, the preset rules in the data packet filtering system are, for example, the rules in IPTABLES, such as the rules on the PREROUTING chain in IPTABLES. Since IPTABLES is a data packet filtering system in the kernel, after the first data packet is sent by the first application, it will go through the rules in IPTABLES, thereby marking the first data packet.
[0013] In this solution, based on the rules in the data packet filtering system, the data packets that need to be forwarded to the network proxy component on the DPU for processing are identified, and the identified data packets are marked, so that corresponding routing can be performed based on the marks on the data packets during the data packet forwarding stage to achieve forwarding. This can effectively forward the data packets sent by the application on the CPU to the DPU for network proxy processing, and reduce the modification to the existing technology, improving the feasibility of the solution.
[0014] In a possible implementation, the preset rules and the first routing are configured by the container network interface (CNI) plugin running on the first CPU. That is to say, in actual applications, by modifying the implementation logic of the CNI plugin, the rules and routing configurations in this solution can be implemented by the modified CNI plugin, ensuring the normal execution of this solution.
[0015] In this solution, by running the CNI plugin on the first CPU to automatically configure the preset rules and the first routing in the data packet filtering system, it can be achieved that the entire process can be automatically completed by only modifying the CNI plugin, avoiding manual execution of complex logic configurations on each CPU and improving the convenience of solution implementation.
[0016] In a possible implementation, the first network proxy component is used to forward the processed first data packet to the second network proxy component running on the second DPU after performing network proxy processing on the first data packet; among them, the second network proxy component is used to provide network proxy services for the second application, and the destination address of the first data packet is the address where the second application is located, such as the address of the virtual network card on the container where the second application is located.
[0017] That is to say, the second application is provided with network proxy services by the second network proxy component on the second DPU. When the destination address of the first data packet is the address where the second application is located, the first network proxy component sends the processed first data packet to the second network proxy component on the second DPU, and after being processed by the second network proxy component, it is sent to the second application.
[0018] In a possible implementation, the second application runs on the second CPU, and the second CPU and the second DPU are deployed on the same node, while the first DPU and the second DPU are located on different nodes. That is, a DPU can be deployed on each node to provide network proxy services for the applications running on the CPUs of the same node, thereby ensuring that the CPUs on each node can release more resources to deploy applications.
[0019] In this solution, the network proxy component on the DPU can not only provide network proxy services for the data packets flowing out of the application, but also provide network proxy services for the data packets flowing into the application, so as to realize providing all-round network proxy services for the application and ensure that normal network proxy services can still be provided after unloading the network proxy component from the DPU.
[0020] In a possible implementation, the method further includes: the host network space receives a second data packet sent by the first network proxy component, and the destination address of the second data packet is a third application running on the first CPU; then, the host network space forwards the second data packet to the third application.
[0021] Among them, the host network space forwards the second data packet to the third application in response to the second data packet being sent by the physical network card and the destination address of the second data packet being the third application running on the first CPU.
[0022] Specifically, when the second data packet is sent by the physical network card and the destination address of the second data packet is the third application running on the first CPU, the host network space can confirm that the second data packet is a data packet that has undergone network proxy processing, so it can directly forward the second data packet based on the destination address of the second data packet, without the need to route the second data packet to the first network proxy component of the first DPU, avoiding the data packet from falling into a loop forwarding process.
[0023] In a possible implementation, the first DPU includes a first virtual network device and a second virtual network device. The first virtual network device is used to receive data packets with the source address being the application running on the first CPU, and the second virtual network device is used to receive data packets with the destination address being the application running on the first CPU. Both the first virtual network device and the second virtual network device are used to forward the received data packets to different ports on the first network proxy component. Among them, different ports on the first network proxy component are respectively used to receive data packets from different sources and execute different processing flows for data packets from different sources.
[0024] That is to say, for data packets from different sources, two different virtual network devices can be used on the first DPU for reception, and then the received data packets are forwarded by the virtual network devices to the corresponding ports on the first network proxy component for further network proxy processing. For example, for data packets from the first CPU, the first virtual network device can send the received data packets to the first port on the first network proxy component, so that the first network proxy component can perform processing operations such as encryption on the data packets received on the first port to ensure the security when the data packets are transmitted to other nodes subsequently. Another example is that for data packets sent to the first CPU, the second virtual network device can send the received data packets to the second port on the first network proxy component, so that the first network proxy component can perform processing operations such as decryption on the data packets received on the second port.
[0025] In this solution, by setting different virtual network devices on the DPU to receive data packets from different sources, it is possible to forward data packets from different sources to different ports on the network proxy component to execute corresponding processing procedures, thereby realizing the classification processing of data packets, enabling the network proxy component to determine the processing procedure for data packets based on the port type of the received data packets, without having to identify the source type of the data packets, and improving the processing efficiency of data packets.
[0026] In a possible implementation manner, the first application program runs on the first CPU in a microservices manner.
[0027] The second aspect of this application provides a network proxy device, which is applied to the cloud native scenario, and the device includes: a receiving module, configured to obtain a first data packet from a first application program, where the first application program runs on the first CPU; a sending module, configured to forward the first data packet to the first network proxy component, where the first network proxy component is used to provide network proxy services for the first data packet, and the first network proxy component runs on the DPU, and the first CPU and the first DPU are deployed on the same node.
[0028] In a possible implementation manner, the device further includes: a processing module, configured to determine to forward the first data packet using a first route in response to the source address of the first data packet being the address where the application program running in the first CPU is located and the first data packet being sent by a virtual network card; the sending module is further configured to forward the first data packet to the first network proxy component based on the indication of the first route.
[0029] In a possible implementation, the processing module is further configured to mark the first data packet in response to the first data packet matching a preset rule in the data packet filtering system, where the preset rule is that the source address of the data packet is the address where the application running in the first CPU is located and the data packet is sent by the virtual network card; the sending module is further configured to determine to forward the first data packet using the first route based on the mark on the first data packet.
[0030] In a possible implementation, the preset rule and the first route are configured by a Container Network Interface (CNI) plugin running on the first CPU.
[0031] In a possible implementation, the first network proxy component is configured to forward the processed first data packet to a second network proxy component running on a second DPU after performing network proxy processing on the first data packet; wherein, the second network proxy component is configured to provide network proxy services for a second application, and the destination address of the first data packet is the address where the second application is located.
[0032] In a possible implementation, the second application runs on a second CPU, and the second CPU and the second DPU are deployed on the same node, while the first DPU and the second DPU are located on different nodes.
[0033] In a possible implementation, the receiving module is further configured to receive a second data packet sent by the first network proxy component, where the destination address of the second data packet is a third application running on the first CPU; the sending module is further configured to forward the second data packet to the third application.
[0034] In a possible implementation, the sending module is further configured to forward the second data packet to the third application in response to the second data packet being sent by the physical network card and the destination address of the second data packet being the third application running on the first CPU.
[0035] In a possible implementation, the first DPU includes a first virtual network device and a second virtual network device. The first virtual network device is configured to receive data packets with the source address being the application running on the first CPU, and the second virtual network device is configured to receive data packets with the destination address being the application running on the first CPU. Both the first virtual network device and the second virtual network device are configured to forward the received data packets to different ports on the first network proxy component.
[0036] In a possible implementation, the first application runs on the first CPU in a microservices manner. That is, the first application is divided into multiple small components or services, and each small component or service can be separately deployed in different containers.
[0037] In a third aspect of the present application, a network proxy device is provided, which may include a processor coupled to a memory. The memory stores program instructions, and when the program instructions stored in the memory are executed by the processor, the method of the first aspect or any implementation manner of the first aspect is implemented. For the steps executed by the processor in each possible implementation manner of the first aspect, reference may be specifically made to the first aspect, and details are not repeated here.
[0038] In a fourth aspect of the present application, a data processing system is provided, which is characterized by including a CPU and a DPU deployed on the same node. An application program runs on the CPU, and a network proxy component is deployed on the DPU. The network proxy component is used to provide network proxy services for the application program running on the CPU.
[0039] In a fifth aspect of the present application, a computer-readable storage medium is provided. A computer program is stored in the computer-readable storage medium, and when it runs on a computer, the computer is caused to execute the method of any implementation manner of the first aspect.
[0040] In a sixth aspect of the present application, a circuit system is provided. The circuit system includes a processing circuit configured to execute the method of any implementation manner of the first aspect.
[0041] In a seventh aspect of the present application, a computer program product is provided. When it runs on a computer, the computer is caused to execute the method of any implementation manner of the first aspect.
[0042] In an eighth aspect of the present application, a chip system is provided. The chip system includes a processor for supporting a server or a feature screening device to implement the functions involved in any implementation manner of the first aspect. For example, it processes the data and / or information involved in the above method. In a possible design, the chip system further includes a memory for storing the necessary program instructions and data of the server or the feature screening device. The chip system may be composed of chips or may include chips and other discrete devices.
[0043] The beneficial effects of the second aspect to the eighth aspect above can be referred to the introduction of the first aspect, and details are not repeated here. Description of the Drawings
[0044] Figure 1 A deployment schematic diagram of an application program and a network proxy in the related art;
[0045] Figure 2 A schematic structural diagram of an electronic device 101 provided in an embodiment of the present application;
[0046] Figure 3 A network proxy method provided in an embodiment of the present application;
[0047] Figure 4 Schematic diagram of the application architecture of a network proxy method provided by an embodiment of the present application;
[0048] Figure 5 Another schematic diagram of the application architecture of a network proxy method provided by an embodiment of the present application;
[0049] Figure 6 Schematic diagram of the transmission of a data packet provided by an embodiment of the present application;
[0050] Figure 7 Another schematic diagram of the transmission of a data packet provided by an embodiment of the present application;
[0051] Figure 8 Schematic diagram of the structure of a network proxy device provided by an embodiment of the present application;
[0052] Figure 9 Schematic diagram of the structure of an electronic device provided by an embodiment of the present application;
[0053] Figure 10 Schematic diagram of the structure of a computer-readable storage medium provided by an embodiment of the present application. Detailed implementation manners
[0054] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments.
[0055] The terms "first", "second", "third", "fourth", etc. (if any) in the specification and claims of the present application and the above accompanying drawings are used to distinguish similar objects, and do not necessarily need to be used to describe a specific order or sequence. It should be understood that the data used in this way can be interchanged under appropriate circumstances so that the embodiments described here can be implemented in an order different from that shown or described here.
[0056] In addition, the terms "include" and "have" and any variations thereof are intended to cover non-exclusive inclusion. For example, a process, method, system, product or device that includes a series of steps or units does not necessarily have to be limited to those steps or units clearly listed, but may include other steps or units that are not clearly listed or are inherent to these processes, methods, products or devices.
[0057] For ease of understanding, some technical terms related to the embodiments of the present application are introduced below.
[0058] (1) Container technology
[0059] Container technology is a development and operation and maintenance technology that reuses the kernel functions of the host operating system by using operating system namespaces, reducing the size of images, greatly shortening the cold start time of instances, reducing the computing resource occupancy of instances, and providing a more convenient construction method and greater development flexibility on the premise of achieving the same virtualization abstraction as virtual machines and certain resource isolation.
[0060] Generally speaking, the container cluster management system kubernetes platform can build container deployment services. Usually, a container is an operating system-level virtualization technology that isolates different processes through operating system isolation technology. Container technology is different from hardware virtualization technology. There is no virtual hardware, and there is no operating system inside the container, only processes.
[0061] (2) pod
[0062] A pod is the basic deployment unit of the kubernetes platform. A pod consists of a group of containers working on the same node. Among them, a pod is a container group that encapsulates storage resources (volume), independent network addresses, and container management policies.
[0063] A pod can include multiple containers, logically identifying an instance of a certain application. For example, a web application consists of three components: front-end, back-end, and database. These three components run in their respective containers, and for this instance, a pod containing three containers can be corresponding.
[0064] Exemplarily, in a possible example, a pod may include: network namespace, mounted volume, CPU declaration, memory declaration, temporary files, data in memory, and connections to system services, etc. Among them, the network namespace is an important function for implementing network virtualization. It can create multiple isolated network spaces, and they have their own network stack information. In addition, other information may also be included in the pod, and this embodiment does not make specific limitations on this.
[0065] (3) Cloud Native
[0066] Cloud Native is an application development and deployment technology in cloud computing platforms characterized by containerized development and deployment, dynamic scheduling, and scaling. Specifically, Cloud Native technology is based on container technology and provides a series of basic functions for containerized deployment of application programs, such as placement scheduling, resource allocation, status monitoring, dynamic scaling, load balancing, fault tolerance, and restart, etc., which are container operation and maintenance technologies.
[0067] (4) Service Mesh
[0068] A service mesh refers to a configurable infrastructure layer for microservices applications. It enables smoother, more reliable, and faster communication between each microservice instance. The service mesh provides functions such as service discovery, load balancing, encryption, authentication, authorization, support for the circuit breaker pattern, and a series of other functions.
[0069] Generally speaking, the service mesh is mainly used to manage the communication between various microservices in a distributed application. By abstracting the complexity of network communication, the service mesh enables developers to focus on the application logic without having to deal with the complexity of network code. It provides a consistent and flexible way to handle cross-service communication and allows the implementation of advanced traffic management policies, security policies, and observability mechanisms.
[0070] (5) Microservice
[0071] Microservices, also known as microservice architectures, are a cloud-native architecture approach that includes numerous loosely coupled and independently deployable small components or services in a single application. That is to say, microservices refer to breaking down a large monolithic software into small independent services that communicate through well-defined application programming interfaces (APIs). Different microservices are responsible for each small independent team and can be reused and independently updated and scaled during operation and maintenance.
[0072] Generally, a microservice is to develop an application as a group of small services, each service running in its own process, and lightweight communication mechanisms are used for communication between services.
[0073] (6) Sidecar
[0074] In the cloud-native scenario, a sidecar (also called a side vehicle) is an architectural pattern that injects a specific container into a unit composed of a group of business containers to complete specific functions.
[0075] (7) Network proxy
[0076] A network proxy, also known as a proxy, is a special network service that allows a terminal (usually a client) to communicate with another terminal through this service in a non-direct connection. Among them, the services provided by the network proxy can include the following services.
[0077] 1. Network traffic encryption: The network proxy at the data sending end encrypts the traffic, and the network proxy at the data receiving end decrypts the traffic to avoid attacks and leaks during the transmission process.
[0078] 2. Identity authentication and authorization: The network proxy at the data sending end adds identity information to the data packet, and the network proxy at the data receiving end determines whether the permission allows the connection based on the identity information.
[0079] 3. Load balancing: The network proxy at the data sending end distributes the data packets to multiple data receiving ends according to rules.
[0080] 4. Monitoring and logging: The network proxies at both the data sending end and the data receiving end can monitor the network usage of the microservices and record it.
[0081] 5. Rate limiting and quotas: The network proxies at both the data sending end and the data receiving end can limit the sending / receiving frequency of data packets or allocate quotas for the data packets of the peer end.
[0082] 6. Service discovery: Detect all available upstream or downstream service instances.
[0083] 7. Health check: Detect whether the upstream or downstream service instances are healthy and ready to receive network traffic.
[0084] (8) IPTABLES
[0085] IPTABLES is a packet filtering system integrated into the Linux kernel. If the Linux system is connected to the Internet or a local area network (LAN), a server, or a proxy server connecting the LAN and the Internet, then this IPTABLES is beneficial for better controlling packet filtering and firewall configuration on the Linux system.
[0086] When the firewall makes packet filtering decisions, there is a set of rules to follow. These rules are stored in a dedicated packet filtering table, and these packet filtering tables are integrated into the Linux kernel. In the packet filtering table, the rules are grouped in so-called chains. And IPTABLES is actually a powerful tool that can be used to add, edit, and remove rules in the packet filtering table.
[0087] (9) Data Processing Unit (DPU)
[0088] DPU is a programmable electronic circuit with data processing and hardware acceleration functions. Currently, DPU is mainly used for data computing and processing within data centers. Generally speaking, a DPU usually contains a processor, a network card, and a programmable data hardware acceleration engine. Therefore, DPU can process data like a CPU while also processing network packets.
[0089] (10) Generic Network Virtualization Encapsulation (GENEVE)
[0090] GENEVE is a virtualized tunnel communication technology. Compared with previous similar technologies, a significant difference of GENEVE is that the protocol metadata itself is extensible. That is, GENEVE provides an extensible GENEVE header, making the service more flexible. Geneve encapsulates the relevant information of network virtualization in an optional variable-length header, which can support more features and options, such as traffic marking, quality control, and security, etc.
[0091] (11) Container Network Interface (CNI):
[0092] CNI provides network general plugin interface services. CNI defines the basis of Kubernetes network plugins, and the network is configured through CNI plugins when containers are created.
[0093] (12) Network Namespace
[0094] Network Namespace is a virtualization technology that can create multiple independent network stacks on the same host, and each network stack has its own independent network interfaces, routing tables, firewalls, and other network configurations. Generally, the network stacks created on the host are also called host network spaces. By using network namespaces, different application programs or containers can be isolated from each other to avoid conflicts between them.
[0095] Please refer to Figure 1 , Figure 1 for a deployment schematic diagram of an application program and a network proxy in related technologies. As Figure 1 shown, in the cloud native scenario, a pod can include multiple containers. The multiple containers include N containers for running application programs, such as application container 1, application container 2... application container N, etc. Outside these containers for running application programs, a network proxy container is mounted in the form of a sidecar, and a network proxy component runs in the network proxy container, which is used to provide network proxy services for the application programs running in each application container.
[0096] In addition, containers within the same pod all run on the same CPU, and each container needs to occupy a certain amount of CPU processing resources. Therefore, the network proxy container running on the CPU will compete with other application containers for CPU processing resources, resulting in a reduction in the number of application containers that can be deployed on the CPU.
[0097] Based on this, the present application provides a network proxy method. The application runs on the CPU, while the network proxy component of the application runs on the DPU, and the DPU and the CPU are deployed on the same node. Moreover, the data packets sent by the application are forwarded to the network proxy component on the DPU for processing, thereby providing network proxy services for the application. Since the DPU has hardware support for accelerating data packet processing, unloading the network proxy component from the CPU to the DPU on the same node can relieve the processing pressure on the CPU, improve the performance of the network proxy service, ensure that more resources can be provided on the CPU for deploying applications, and effectively utilize the hardware processing capabilities of the DPU.
[0098] For ease of understanding, the device to which the network proxy method provided in the embodiments of the present application is applied will be introduced below.
[0099] Reference can be made to Figure 2 , Figure 2 which is a schematic structural diagram of an electronic device 101 provided in an embodiment of the present application. As Figure 2 shown, the electronic device 101 to which the network proxy method provided in the embodiments of the present application is applied includes a processor 103, and the processor 103 is coupled to a system bus 105. The processor 103 can be one or more processors, and each processor can include one or more processor cores. A display adapter 107, which can drive a display 109, and the display 109 is coupled to the system bus 105. The system bus 105 is coupled to an input / output (I / O) bus through a bus bridge 111. An I / O interface 115 is coupled to the I / O bus. The I / O interface 115 communicates with a variety of I / O devices, such as an input device 117 (e.g., a touch screen, etc.), an external memory 121 (e.g., a hard disk, a floppy disk, an optical disc, or a USB flash drive), a multimedia interface, etc.). A transceiver 123 (which can send and / or receive radio communication signals), a camera 155 (which can capture static and dynamic digital video images), and an external USB port 125. Optionally, the interface connected to the I / O interface 115 can be a USB interface.
[0100] Among them, the processor 103 can be any conventional processor, including a reduced instruction set computing (RISC) processor, a complex instruction set computing (CISC) processor, or a combination of the above. Optionally, the processor can be a dedicated device such as an ASIC.
[0101] The electronic device 101 can communicate with the software deployment server 149 through the network interface 129. Exemplarily, the network interface 129 is a hardware network interface, such as a network card. The network 127 can be an external network, such as the Internet, or an internal network, such as Ethernet or a virtual private network (VPN). Optionally, the network 127 can also be a wireless network, such as a WiFi network, a cellular network, etc.
[0102] The hard disk drive interface 131 is coupled to the system bus 105. The hardware drive interface is connected to the hard disk drive 133. The internal memory 135 is coupled to the system bus 105. The data running in the internal memory 135 can include the operating system (OS) 137, application programs 143, and a schedule of the electronic device 101.
[0103] The operating system includes a Shell 139 and a kernel 141. The Shell 139 is an interface between the user and the kernel of the operating system. The shell is the outermost layer of the operating system. The shell manages the interaction between the user and the operating system: waits for the user's input, interprets the user's input to the operating system, and processes various output results of the operating system.
[0104] The kernel 141 consists of those parts of the operating system that are used to manage memory, files, peripherals, and system resources. The kernel 141 directly interacts with the hardware. The operating system kernel usually runs processes and provides inter-process communication, provides CPU time slice management, interrupts, memory management, and IO management, etc.
[0105] Exemplarily, please refer to Figure 3 , Figure 3 a network proxy method provided by an embodiment of the present application. As Figure 3 shown, the network proxy method provided in this embodiment includes the following steps 301-302. The network proxy method provided in this embodiment can be applied to a cloud-native scenario, and the network stack in the cloud-native scenario forwards the data packets sent by the application programs running on the CPU, so that the data packets of the application programs running on the CPU will be forwarded to the network proxy component on the DPU for processing.
[0106] Step 301: Obtain a first data packet from a first application, where the first application runs on a first CPU.
[0107] In this embodiment, the first application may run on the first CPU in the form of a container. When the first application needs to send data to other applications outside the container, it can issue the first data packet. After the first data packet is issued by the container where the first application is located, the network namespace on the host where the first application runs (hereinafter referred to as the host network space) can obtain the first data packet. Among them, the host network space where the first application runs is responsible for forwarding the first data packet.
[0108] Optionally, the first application runs on the first CPU in the form of a microservice. That is, the first application is divided into multiple small components or services, and each small component or service can be deployed in different containers respectively. Of course, the first application can also run on the first CPU in the form of an independent process, and this embodiment does not make specific limitations on this.
[0109] Step 302: Forward the first data packet to a first network proxy component, where the first network proxy component is used to provide a network proxy service for the first data packet, and the first network proxy component runs on a first data processor DPU, and the first CPU and the first DPU are deployed on the same node.
[0110] In this embodiment, the first CPU for running the first application and the first DPU for running the first network proxy component are deployed on the same node. For example, the first CPU and the first DPU are deployed on the same server. Moreover, a mapping relationship is established between the first CPU and the first DPU, and the first DPU is used to provide a network proxy service for the application running on the first CPU, so that there is no need to run the corresponding network proxy component on the first CPU.
[0111] Since the network proxy component is no longer run on the first CPU, but the first network proxy component running on the first DPU provides the network proxy service for the application running on the first CPU, the host network space can forward the obtained first data packet to the first network proxy component on the first DPU, and the first network proxy component provides the network proxy service.
[0112] Among them, the network proxy services provided by the first network proxy component for the data packet may include, for example, network traffic encryption, identity authentication and authorization, load balancing, monitoring and logging, rate limiting and quotas, service discovery, and health detection services. This embodiment does not make specific limitations on this.
[0113] Optionally, to ensure that the host network space can correctly forward data packets, the host network space may determine to use a first route to forward the first data packet in response to the source address of the first data packet being the address where the application running in the first CPU is located and the first data packet being sent by the virtual network card. Then, based on the indication of the first route, forward the first data packet to the first network proxy component.
[0114] When the source address of the first data packet is the address where the application running in the first CPU is located and the first data packet is sent by the virtual network card, the host network space can determine that the first data packet is sent by the application running in the first CPU rather than going to the application running in the first CPU. Therefore, the first data packet needs to be forwarded to the first network proxy component on the first DPU for processing.
[0115] Among them, the host network space includes a first route and a second route. The first route is used to forward data packets to the first network proxy component on the first DPU; while the second route is a conventional route used to forward data packets based on the destination address of the data packet. When it is determined that the first data packet needs to be forwarded to the first DPU for processing, the forwarding of the first data packet can be performed based on the indication of the first route, so as to ensure that the application does not need to modify the address of the sent data packet and ensure that the network proxy component is offloaded to the DPU without affecting the existing application running logic, improving the applicability of the solution.
[0116] Optionally, in order to effectively identify the data packets that need to be forwarded to the first DPU for processing using the first route, in this embodiment, the rules in the data packet filtering system can be increased to identify data packets.
[0117] Exemplarily, in response to the first data packet matching the preset rules in the data packet filtering system, mark the first data packet. For example, mark the first data packet as Tag_outboundPocket. Wherein, the preset rule is that the source address of the data packet is the address where the application running in the first CPU is located and the data packet is sent by the virtual network card. Then, during the process of forwarding the first data packet, the host network space can determine to use the first route to forward the first data packet based on the mark on the first data packet.
[0118] That is to say, for the marked data packets, the host network space can use the pre-configured first route to forward the data packets to the first network proxy component on the first DPU for processing; for the unmarked data packets, the host network space can use the conventional route to perform the forwarding of the data packets.
[0119] Among them, the preset rules in the packet filtering system are, for example, the rules in IPTABLES, such as the rules on the PREROUTING chain in IPTABLES. Since IPTABLES is a packet filtering system in the kernel, after the first packet is sent by the first application, it will pass through the rules in IPTABLES, thereby marking the first packet.
[0120] In this solution, based on the rules in the packet filtering system, the packets that need to be forwarded to the network proxy component on the DPU for processing are identified, and the identified packets are marked, so that corresponding routing can be performed based on the marks on the packets during the packet forwarding stage to implement forwarding. It can effectively forward the packets sent by the application on the CPU to the DPU for network proxy processing, and reduce the modification to the existing technology, improving the feasibility of the solution.
[0121] Optionally, the preset rules and the first routing in the packet filtering system are configured by the CNI plugin running on the first CPU. That is to say, in actual applications, by modifying the implementation logic of the CNI plugin, the rules and routing configurations in this solution can be implemented by the modified CNI plugin, ensuring that this solution can be executed normally.
[0122] In this solution, by running the CNI plugin on the first CPU to automatically configure the preset rules and the first routing in the packet filtering system, it can be achieved that the entire process can be automatically completed by only modifying the CNI plugin, avoiding manual execution of complex logic configurations on each CPU and improving the convenience of solution implementation.
[0123] In addition, on the first DPU, since the first network proxy component on the first DPU is responsible for providing network proxy services for the applications on the first CPU, and the applications on the first CPU may either send packets outward or receive packets sent by other applications, the first network proxy component on the first DPU actually needs to process the packets sent by the applications on the first CPU and the data packets sent to the applications on the first CPU.
[0124] Based on this, in order to effectively process data packets from different sources, the first DPU includes a first virtual network device and a second virtual network device. The first virtual network device is used to receive data packets with the source address being the application running on the first CPU, and the second virtual network device is used to receive data packets with the destination address being the application running on the first CPU. Both the first virtual network device and the second virtual network device are used to forward the received data packets to different ports on the first network proxy component. Among them, different ports on the first network proxy component are respectively used to receive data packets from different sources and execute different processing procedures on the data packets from different sources. In addition, the first virtual network device and the second virtual network device are, for example, virtual network cards that adopt the GENEVE protocol.
[0125] That is to say, for data packets from different sources, two different virtual network devices can be used on the first DPU to receive them, and then the virtual network devices forward the received data packets to the corresponding ports on the first network proxy component to perform further network proxy processing. For example, for data packets from the first CPU, the first virtual network device can send the received data packets to the first port on the first network proxy component, so that the first network proxy component can perform processing operations such as encryption on the data packets received on the first port to ensure the security when the data packets are subsequently transmitted to other nodes. Another example is that for data packets sent to the first CPU, the second virtual network device can send the received data packets to the second port on the first network proxy component, so that the first network proxy component can perform processing operations such as decryption on the data packets received on the second port.
[0126] In this solution, by setting different virtual network devices on the DPU to receive data packets from different sources, it can make data packets from different sources be forwarded to different ports on the network proxy component to execute corresponding processing procedures, thereby realizing the classification processing of data packets, enabling the network proxy component to determine the processing procedure for data packets based on the port type of the received data packets, without the need to identify the source type of the data packets, and improving the processing efficiency of data packets.
[0127] Optionally, since the first network proxy component not only proxies data packets from the application on the first CPU but also proxies data packets going to the application on the first CPU, it is possible that the host network space on the first CPU may also obtain data packets from the first network proxy component and needs to forward the data packets to the corresponding application.
[0128] Exemplarily, the host network space on the first CPU receives the second data packet sent by the first network proxy component, and the destination address of the second data packet is the third application running on the first CPU; then, the host network space forwards the second data packet to the third application.
[0129] Specifically, the host network space forwards the second data packet to the third application in response to the second data packet being sent by the physical network card and the destination address of the second data packet being the third application running on the first CPU. Because, in the case where the second data packet is sent by the physical network card and the destination address of the second data packet is the third application running on the first CPU, the host network space can confirm that the second data packet is a data packet that has undergone network proxy processing, so it can directly forward the second data packet based on the destination address of the second data packet, without the need to route the second data packet to the first network proxy component of the first DPU, thus avoiding the data packet from getting into a loop forwarding process.
[0130] The above introduced the process of forwarding the data packet sent by the application running on the CPU to the network proxy component running on the DPU for processing. The following will introduce how to forward the data packet after the network proxy component finishes processing the data packet.
[0131] In some embodiments, after performing network proxy processing on the first data packet, the above-mentioned first network proxy component forwards the processed first data packet to the second network proxy component running on the second DPU. Among them, the second network proxy component is used to provide network proxy services for the second application, and the destination address of the first data packet is the address where the second application is located, for example, the address of the virtual network card on the container where the second application is located.
[0132] That is to say, the second application is provided with network proxy services by the second network proxy component on the second DPU. When the destination address of the first data packet is the address where the second application is located, the first network proxy component sends the processed first data packet to the second network proxy component on the second DPU, and then the second network proxy component processes it and sends it to the second application.
[0133] Among them, the second application runs on the second CPU, and the second CPU and the second DPU are deployed on the same node, and the first DPU and the second DPU are located on different nodes. That is, a DPU can be deployed on each node to provide network proxy services for the applications running on the CPUs on the same node, thereby ensuring that the CPUs on each node can release more resources to deploy applications.
[0134] In this solution, the network proxy component on the DPU can not only provide network proxy services for the data packets flowing out of the application program, but also provide network proxy services for the data packets flowing into the application program, so as to realize providing all-round network proxy services for the application program, and ensure that normal network proxy services can still be provided after uninstalling the network proxy component from the DPU.
[0135] Exemplarily, please refer to Figure 4 , Figure 4 which is a schematic diagram of the application architecture of a network proxy method provided by an embodiment of this application. As Figure 4 shown, in the application architecture in the cloud native scenario, it includes a first node and a second node. The first node includes a first CPU and a first DPU, and the second node includes a second CPU and a second DPU. Multiple pods can run on the first CPU and the second CPU, and each pod can be used to run an application program. At least one pod can run on the first DPU and the second DPU, and this pod is used to run a network proxy component to provide network proxy services for the application programs running on the CPUs on the same node.
[0136] In addition, a virtual network card can be set on each pod, which is responsible for receiving and sending data packets. The data packets sent and received by the pod through the virtual network card will pass through the host network space before entering the pod. Therefore, the data packets can be processed based on the rules and routing of IPTABLES in the host network space.
[0137] There are corresponding physical network cards on the first CPU, the first DPU, the second CPU, and the second DPU, and the physical network cards are connected through physical links (such as network cables or switches). Therefore, the host network space can send data packets to other hardware through the physical network card, or receive data packets sent by other hardware from the physical network card.
[0138] Please refer to Figure 5 , Figure 5 which is another schematic diagram of the application architecture of a network proxy method provided by an embodiment of this application. As Figure 5 shown, for any CPU in the application architecture in the cloud native scenario, one or more pods can run in this CPU to realize the operation of the application program, and a CNI plugin also runs in the CPU. The CNI plugin running in the CPU is used to add rules of the data packet filtering system (such as adding rules in IPTABLES) in the host network space corresponding to the CPU, and add a route (i.e., the above-mentioned first route) to forward the data packet to the DPU corresponding to the current CPU on the same node, so that the data packets sent by the application programs running in the CPU can be forwarded to the DPU.
[0139] For any DPU in the application architecture in the cloud-native scenario, a CNI plugin can also run in the DPU. The CNI plugin running in the DPU is used to add rules for the packet filtering system in the host network space corresponding to the DPU (such as adding rules in IPTABLES) so that the packets obtained from the physical network card can be forwarded to the correct virtual network card for processing.
[0140] Exemplarily, please refer to Figure 6 , Figure 6 which is a schematic diagram of the transmission of a data packet provided by an embodiment of the present application. As Figure 6 shown, the transmission process of the data packet includes the following steps 1-step 9.
[0141] Step 1, the first application program running in the source pod on the first CPU sends out a data packet.
[0142] Among them, the first CPU runs the source pod (i.e., the pod where the data packet comes from), and the first application program runs in the source pod. When the first application program sends out a data packet, the data packet will be sent out from the virtual network card of the source pod, and the source address of the data packet is the address of the virtual network card on the source pod. Moreover, the data packet sent by the first application program is sent to the second application program running on the second CPU, and the second application program runs on the destination pod running on the second CPU. Therefore, the destination address of the data packet is the address of the virtual network card on the destination pod of the second CPU.
[0143] Step 2, the host network space on the first CPU forwards the data packet to the first DPU through the physical network card.
[0144] After the first application program sends out a data packet, the data packet will pass through the host network space on the first CPU and enter the rule chain on IPTABLES. Among them, the CNI plugin on the first CPU adds new rules on the rule chain of IPTABLES and adds new routes in the host network space. On the rule chain of IPTABLES, the new rule is specifically: determine whether the source address of the data packet is the address of the virtual network card of this CPU and whether the data packet is sent out by the virtual network card. When the data packet meets the rules recorded in the rule chain on IPTABLES, it means that the data packet has not been processed by the network proxy on the DPU. Therefore, the data packet can be marked. In this way, the data packet sent by the first application program meets the above rules, so it will be a data packet with a mark added, and thus can be forwarded according to the newly added route, that is, the data packet is forwarded to the first DPU through the physical network card.
[0145] In addition, if the data packet does not meet the above rules, it means that the data packet has been processed by the network proxy on the DPU. Therefore, the data packet can be forwarded according to the conventional routing based on the destination address of the data packet.
[0146] Step 3, the host network space on the first DPU forwards the data packet to the virtual network card 1 on the pod running the first network proxy component.
[0147] After the data packet is forwarded to the physical network card of the first DPU, the data packet enters the host network space on the first DPU from the physical network card. The CNI plugin on the first DPU also adds new rules to the rule chain of IPTABLES.
[0148] On the rule chain of IPTABLES of the first DPU, the new rule is specifically: determine whether the source address of the data packet is the virtual network card address of the local CPU and whether the data packet enters from the physical network card. When the data packet meets the above rules recorded in the rule chain of IPTABLES, it means that the data packet is sent by the application program on the local CPU and has not been processed by the network proxy component. Therefore, the data packet can be sent to the virtual network card 1 of the pod. Among them, the virtual network card 1 is used to receive the data packets flowing out of the local CPU (i.e., outbound data packets) and send the received data packets to the first port on the first network proxy component, so that the first network proxy component can perform network proxy operations such as encrypting the data packets.
[0149] In addition, the pod running on the first DPU also includes a virtual network card 2 and a virtual network card 3. Among them, the virtual network card 2 is used to receive the data packets that need to flow into the local CPU (i.e., inbound data packets) and send the received data packets to the second port on the first network proxy component, so that the first network proxy component can perform network proxy operations such as decrypting the data packets.
[0150] Step 4, the virtual network card 3 on the pod running the first network proxy component sends out the data packet.
[0151] After the first network proxy component finishes processing the received data packet, it will send out the processed data packet through the virtual network card 3. That is, the virtual network card 3 is actually the egress virtual network card on the first network proxy component.
[0152] Step 5, the host network space on the first DPU forwards the data packet to the second DPU.
[0153] After the virtual network card 3 in the pod running the first network proxy component sends out a data packet, the destination address of the data packet remains unchanged and is still the address of the virtual network card on the destination pod of the second CPU. In this way, the host network space on the first DPU can determine that the data packet has been processed by the first network proxy component and needs to be sent to other nodes by identifying the destination address of the data packet. Therefore, the data packet can be forwarded to the second DPU corresponding to the second CPU through the physical network card.
[0154] It should be noted that the mapping relationship between the CPUs and DPUs on remote nodes can be stored on the first DPU. For example, the mapping relationship between the virtual network card address of the second CPU and the virtual network card address of the second DPU is stored. In this way, when the first DPU obtains a data packet with the destination address being the virtual network card address of the second CPU on the remote node, the data packet can be forwarded to the DPU corresponding to the second CPU for network proxy processing.
[0155] Step 6, the host network space on the second DPU forwards the data packet to the virtual network card 2 on the pod running the second network proxy component.
[0156] After the data packet is forwarded to the physical network card of the second DPU, the data packet will enter the host network space on the second DPU from the physical network card. The CNI plugin on the second DPU also adds new rules to the rule chain of IPTABLES.
[0157] On the rule chain of IPTABLES of the second DPU, the new rule is specifically: determine whether the destination address of the data packet is the virtual network card address of the local CPU and whether the data packet enters from the physical network card. When the data packet meets the above rules recorded in the rule chain of IPTABLES, it means that the data packet is sent to the application on the local CPU and has not been processed by the network proxy component. Therefore, the data packet can be sent to the virtual network card 2 of the pod. The virtual network card 2 is used to receive the data packets flowing into the local CPU (i.e., inbound data packets) and send the received data packets to the second port on the second network proxy component, so that the second network proxy component can perform network proxy operations such as decrypting the data packets.
[0158] Step 7, the virtual network card 3 on the pod running the second network proxy component sends out a data packet.
[0159] After the second network proxy component finishes processing the received data packet, it will send out the processed data packet through the virtual network card 3. That is, the virtual network card 3 is actually the egress virtual network card on the second network proxy component.
[0160] Step 8, the host network space on the second DPU forwards the data packet to the second CPU.
[0161] After the virtual network card 3 in the pod running the second network proxy component sends out a data packet, the destination address of the data packet does not change and remains the address of the virtual network card on the destination pod of the second CPU. In this way, the host network space on the second DPU can forward the data packet to the physical network card of the second CPU by identifying the destination address of the data packet through the physical network card.
[0162] Step 9, the host network space on the second CPU forwards the data packet to the destination pod running the second application.
[0163] After the data packet is forwarded to the physical network card of the second CPU, the data packet enters the host network space on the second CPU from the physical network card. Based on the fact that the obtained data packet enters from the physical network card, the host network space on the second CPU can determine that the current data packet has been processed by the network proxy, so the data packet is forwarded to the virtual network card of the destination pod according to the destination address of the data packet, so that the data packet can finally reach the second application in the destination pod.
[0164] Figure 6 The illustrated embodiment introduces the process of a data packet being sent from an application running on a local CPU to an application running on a remote node CPU. The following will introduce the process of a data packet being sent from an application running on a local CPU to another application running on the same local CPU.
[0165] Exemplarily, please refer to Figure 7 , Figure 7 which is another schematic diagram of data packet transmission provided by the embodiment of the present application. As Figure 7 shown, the data packet transmission process includes the following steps 1-step 6.
[0166] Step 1, the first application running in the source pod in the first CPU sends out a data packet.
[0167] Among them, the first CPU runs the source pod (i.e., the source pod of the data packet), and the first application runs in the source pod. When the first application sends out a data packet, the data packet is sent out from the virtual network card of the source pod, and the source address of the data packet is the address of the virtual network card on the source pod. Moreover, the data packet sent out by the first application is sent to the third application running on the first CPU, and the third application runs on the destination pod run by the first CPU. Therefore, the destination address of the data packet is the address of the virtual network card on the destination pod of the first CPU. That is, the source pod and the destination pod run on the same CPU, and the data packet is actually transmitted between different pods running on the same CPU.
[0168] Step 2, the host network space on the first CPU forwards the data packet to the first DPU through the physical network card.
[0169] Among them, step 2 in this embodiment is similar to step 2 in the above Figure 6 illustrated embodiment. For details, please refer to the above text and will not be elaborated here.
[0170] Step 3, the host network space on the first DPU forwards the data packet to virtual network card 1 on the pod running the first network proxy component.
[0171] The CNI plugin on the first DPU also adds other new rules to the rule chain of IPTABLES. The new rules are specifically: determine whether the destination address of the data packet is the virtual network card address of the local CPU and whether the data packet enters through the physical network card. When the data packet meets the above rules recorded in the rule chain of IPTABLES, it means that the data packet is sent to the application program on the local CPU and has not been processed by the network proxy component. Therefore, the data packet can be sent to virtual network card 2 of the pod. Among them, virtual network card 2 is used to receive the data packets flowing into the local CPU (i.e., inbound data packets) and send the received data packets to the second port on the second network proxy component, so that the second network proxy component can perform network proxy operations such as decrypting the data packets.
[0172] Step 4, virtual network card 3 on the pod running the first network proxy component sends out the data packet.
[0173] After the first network proxy component finishes processing the received data packet, it will send out the processed data packet through virtual network card 3. That is, virtual network card 3 is actually the egress virtual network card on the first network proxy component.
[0174] Step 5, the host network space on the first DPU forwards the data packet to the first DPU.
[0175] After virtual network card 3 on the pod running the first network proxy component sends out the data packet, the destination address of the data packet does not change and is still the address of the virtual network card on the destination pod of the first CPU. In this way, the host network space on the first DPU can forward the data packet to the first CPU through the physical network card by identifying the destination address of the data packet.
[0176] Step 6, the host network space on the first CPU forwards the data packet to the destination pod running the third application program.
[0177] After the data packet is forwarded to the physical network card of the first CPU, the data packet enters the host network space on the first CPU from the physical network card. Based on the fact that the obtained data packet enters from the physical network card, the host network space on the first CPU can determine that the current data packet has been processed by the network proxy. Therefore, the data packet is forwarded to the virtual network card of the destination pod according to the destination address of the data packet, so that the data packet can finally reach the third application in the destination pod.
[0178] The method provided by the embodiments of the present application is introduced in detail above. Next, the device for executing the above method provided by the embodiments of the present application will be introduced.
[0179] Please refer to Figure 8 , Figure 8 which is a schematic structural diagram of a network proxy device provided by an embodiment of the present application. As Figure 8 shown, the device is applied to a cloud-native scenario, and the device includes: a receiving module 801, configured to obtain a first data packet from a first application program, where the first application program runs on a first CPU; a sending module 802, configured to forward the first data packet to a first network proxy component, where the first network proxy component is configured to provide network proxy services for the first data packet, and the first network proxy component runs on a DPU, and the first CPU and the first DPU are deployed on the same node.
[0180] In a possible implementation manner, the device further includes: a processing module 803, configured to determine to forward the first data packet using a first route in response to the source address of the first data packet being the address where the application program running in the first CPU is located and the first data packet being sent by a virtual network card; the sending module 802 is further configured to forward the first data packet to the first network proxy component based on the indication of the first route.
[0181] In a possible implementation manner, the processing module 803 is further configured to mark the first data packet in response to the first data packet matching a preset rule in the data packet filtering system, where the preset rule is that the source address of the data packet is the address where the application program running in the first CPU is located and the data packet is sent by a virtual network card; the sending module 802 is further configured to determine to forward the first data packet using a first route based on the mark on the first data packet.
[0182] In a possible implementation manner, the preset rule and the first route are configured by a container network interface CNI plugin running on the first CPU.
[0183] In a possible implementation, the first network proxy component is used to forward the processed first data packet to the second network proxy component running on the second DPU after performing network proxy processing on the first data packet; wherein, the second network proxy component is used to provide network proxy services for the second application, and the destination address of the first data packet is the address where the second application is located.
[0184] In a possible implementation, the second application runs on the second CPU, and the second CPU and the second DPU are deployed on the same node, while the first DPU and the second DPU are located on different nodes.
[0185] In a possible implementation, the receiving module 801 is further configured to receive the second data packet sent by the first network proxy component, and the destination address of the second data packet is the third application running on the first CPU; the sending module 802 is further configured to forward the second data packet to the third application.
[0186] In a possible implementation, the sending module 802 is further configured to forward the second data packet to the third application in response to the second data packet being sent by the physical network card and the destination address of the second data packet being the third application running on the first CPU.
[0187] In a possible implementation, the first DPU includes a first virtual network device and a second virtual network device. The first virtual network device is used to receive data packets with the source address being the application running on the first CPU, and the second virtual network device is used to receive data packets with the destination address being the application running on the first CPU. Both the first virtual network device and the second virtual network device are used to forward the received data packets to different ports on the first network proxy component.
[0188] In a possible implementation, the first application runs on the first CPU in the form of a microservice.
[0189] Please refer to Figure 9 , Figure 9 which is a schematic structural diagram of an electronic device provided by an embodiment of the present application. As Figure 9 shown, the electronic device 900 may specifically be a server, which is not limited herein. Specifically, the electronic device 900 includes: a receiver 901, a transmitter 902, a processor 903, and a memory 904 (wherein the number of processors 903 in the electronic device 900 may be one or more, Figure 9 and one processor is taken as an example herein), wherein the processor 903 may include an application processor 9031 and a communication processor 9032. In some embodiments of the present application, the receiver 901, the transmitter 902, the processor 903, and the memory 904 may be connected through a bus or other means.
[0190] The memory 904 may include a read-only memory and a random access memory, and provide instructions and data to the processor 903. A part of the memory 904 may also include a non-volatile random access memory (NVRAM). The memory 904 stores processor and operation instructions, executable modules, or data structures, or subsets thereof, or extended sets thereof, wherein the operation instructions may include various operation instructions for implementing various operations.
[0191] The processor 903 controls the operation of the electronic device. In a specific application, each component of the electronic device is coupled together through a bus system, which may include a power bus, a control bus, a status signal bus, etc. in addition to a data bus. However, for the sake of clear illustration, all kinds of buses are referred to as a bus system in the figure.
[0192] The method disclosed in the embodiments of the present application described above can be applied to or implemented by the processor 903. The processor 903 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the integrated logic circuit in the hardware of the processor 903 or by instructions in software form. The above-mentioned processor 903 may be a general-purpose processor, a digital signal processor (DSP), a microprocessor or a microcontroller, and may further include an application specific integrated circuit (ASIC), a field-programmable gate array (FPGA), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components.
[0193] The processor 903 can implement or execute the various methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present application can be directly embodied as being executed and completed by a hardware decoding processor, or executed and completed by a combination of hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 904, and the processor 903 reads the information in the memory 904 and combines its hardware to complete the steps of the above method.
[0194] The receiver 901 can be used to receive input digital or character information and generate signal inputs related to the relevant settings and function controls of the electronic device. The transmitter 902 can be used to output digital or character information through the first interface; the transmitter 902 can also be used to send instructions to the disk group through the first interface to modify the data in the disk group; the transmitter 902 can also include display devices such as a display screen.
[0195] The electronic device provided by the embodiment of the present application can specifically be a chip, and the chip includes: a processing unit and a communication unit. The processing unit can be, for example, a processor, and the communication unit can be, for example, an input / output interface, a pin, or a circuit, etc. The processing unit can execute the computer execution instructions stored in the storage unit to enable the chip in the execution device to execute the method described in the above embodiment. Optionally, the storage unit is a storage unit within the chip, such as a register, a cache, etc. The storage unit can also be a storage unit located outside the chip within the wireless access device, such as a read-only memory (ROM) or other types of static storage devices that can store static information and instructions, a random access memory (RAM), etc.
[0196] Reference can be made to Figure 10 , Figure 10 which is a schematic structural diagram of a computer-readable storage medium provided by the embodiment of the present application. The present application also provides a computer-readable storage medium. In some embodiments, the above Figure 3 disclosed method can be implemented as computer program instructions encoded in a machine-readable format on a computer-readable storage medium or encoded on other non-transitory media or articles.
[0197] Figure 10 Schematically shown is a conceptual partial view of an example computer-readable storage medium arranged according to at least some of the embodiments shown here. The example computer-readable storage medium includes a computer program for executing a computer process on a computing device.
[0198] In one embodiment, the computer-readable storage medium 1000 is provided using the signal-bearing medium 1001. The signal-bearing medium 1001 can include one or more program instructions 1002, which when run by one or more processors can provide the functions or partial functions described above for Figure 3 description.
[0199] In some examples, the signal-bearing medium 1001 can include a computer-readable medium 1003, such as but not limited to, a hard disk drive, a compact disc (CD), a digital video disc (DVD), a digital tape, a memory, a ROM, or a RAM, etc.
[0200] In some embodiments, the signal-bearing medium 1001 may include a computer-readable medium 1004, such as but not limited to, a memory, a read / write (R / W) CD, an R / W DVD, and the like. In some embodiments, the signal-bearing medium 1001 may include a communication medium 1005, such as but not limited to, digital and / or analog communication media (e.g., fiber optic cables, waveguides, wired communication links, wireless communication links, etc.). Thus, for example, the signal-bearing medium 1001 may be conveyed by a wireless form of the communication medium 1005 (e.g., a wireless communication medium compliant with the IEEE 802.X standard or other transmission protocols).
[0201] One or more program instructions 1002 may be, for example, computer-executable instructions or logic-implemented instructions. In some examples, a computing device of a computing device may be configured to provide various operations, functions, or actions in response to the program instructions 1002 communicated to the computing device via one or more of the computer-readable medium 1003, the computer-readable medium 1004, and / or the communication medium 1005.
[0202] It should be further noted that the device embodiments described above are merely illustrative. The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, i.e., they may be located in one place or distributed to multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the solution of this embodiment. In addition, in the drawings of the device embodiments provided in this application, the connection relationships between the modules indicate that they have communication connections, which can be specifically implemented as one or more communication buses or signal lines.
[0203] Through the description of the above embodiments, those skilled in the art can clearly understand that this application can be implemented by means of software plus necessary general hardware, and of course, it can also be implemented by dedicated hardware including application-specific integrated circuits, dedicated CPUs, dedicated memories, dedicated components, etc. Generally, functions completed by computer programs can be easily implemented by corresponding hardware, and the specific hardware structures for implementing the same function can also be diverse, such as analog circuits, digital circuits, or dedicated circuits. However, in more cases, software program implementation is a better embodiment for this application. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a readable storage medium, such as a floppy disk, a USB flash drive, a mobile hard disk, a ROM, a RAM, a magnetic disk, or an optical disc of a computer, and includes several instructions to enable a computer device (which may be a personal computer, a training device, or a network device, etc.) to execute the methods of various embodiments of this application.
[0204] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product.
[0205] The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the embodiments of the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium, or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions can be transmitted from one website, computer, training device, or data center to another website, computer, training device, or data center by wire (such as coaxial cable, optical fiber, digital subscriber line) or wirelessly (such as infrared, wireless, microwave, etc.). The computer-readable storage medium can be any available medium that a computer can store, or a data storage device such as a training device or data center that includes one or more integrated available media. The available medium can be a magnetic medium (such as a floppy disk, hard disk, magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid state disk (SSD)), etc.
Claims
1. A network proxy method, characterized in that, the method is applied to a cloud native scenario and includes: obtaining a first data packet from a first application, where the first application runs on a first central processing unit (CPU); forwarding the first data packet to a first network proxy component, where the first network proxy component is used to provide network proxy services for the first data packet, and the first network proxy component runs on a first data processing unit (DPU), and the first CPU and the first DPU are deployed on the same node.
2. The method according to claim 1, characterized in that, the forwarding the first data packet to the first network proxy component includes: responding to the source address of the first data packet being the address where the application running in the first CPU is located and the first data packet being sent by a virtual network card, and determining to forward the first data packet using a first route; based on the indication of the first route, forwarding the first data packet to the first network proxy component.
3. The method according to claim 2, characterized in that, the responding to the source address of the first data packet being the address where the application running in the first CPU is located and the first data packet being sent by a virtual network card, and determining to forward the first data packet using a first route includes: responding to the first data packet matching a preset rule in a data packet filtering system, where the preset rule is that the source address of the data packet is the address where the application running in the first CPU is located and the data packet is sent by a virtual network card, and marking the first data packet; based on the mark on the first data packet, determining to forward the first data packet using a first route.
4. The method according to claim 3, characterized in that, the preset rule and the first route are configured by a container network interface (CNI) plugin running on the first CPU.
5. The method according to any one of claims 1-4, characterized in that, the first network proxy component is used to forward the processed first data packet to a second network proxy component running on a second DPU after performing network proxy processing on the first data packet; wherein, the second network proxy component is used to provide network proxy services for a second application, and the destination address of the first data packet is the address where the second application is located.
6. The method according to claim 5, characterized in that, the second application runs on a second CPU, and the second CPU and the second DPU are deployed on the same node, and the first DPU and the second DPU are located on different nodes.
7. The method according to any one of claims 1-6, characterized in that, the method further includes: receiving a second data packet sent by the first network proxy component, where the destination address of the second data packet is a third application running on the first CPU; forwarding the second data packet to the third application.
8. The method according to claim 7, characterized in that, the forwarding the second data packet to the third application includes: In response to the second data packet being sent by the physical network card and the destination address of the second data packet being the third application running on the first CPU, forward the second data packet to the third application.
9. The method according to any one of claims 1-8, wherein, the first DPU includes a first virtual network device and a second virtual network device. The first virtual network device is used to receive data packets with the source address being the application running on the first CPU, and the second virtual network device is used to receive data packets with the destination address being the application running on the first CPU. Both the first virtual network device and the second virtual network device are used to forward the received data packets to different ports on the first network proxy component.
10. The method according to any one of claims 1-9, wherein, the first application runs on the first CPU in a microservices manner.
11. A network proxy device, wherein, the device is applied to a cloud-native scenario and includes: a receiving module, configured to obtain a first data packet from a first application, where the first application runs on a first CPU; a sending module, configured to forward the first data packet to a first network proxy component, where the first network proxy component is used to provide network proxy services for the first data packet, and the first network proxy component runs on a first DPU, and the first CPU and the first DPU are deployed on the same node.
12. The device according to claim 11, wherein, the device further includes: a processing module, configured to determine to forward the first data packet using a first route in response to the source address of the first data packet being the address of the application running in the first CPU and the first data packet being sent by a virtual network card; the sending module is further configured to forward the first data packet to the first network proxy component based on the indication of the first route.
13. The device according to claim 12, wherein, the processing module is further configured to mark the first data packet in response to the first data packet matching a preset rule in a data packet filtering system, where the preset rule is that the source address of the data packet is the address of the application running in the first CPU and the data packet is sent by a virtual network card; the sending module is further configured to determine to forward the first data packet using a first route based on the mark on the first data packet.
14. The device according to claim 13, wherein, the preset rule and the first route are configured by a container network interface (CNI) plugin running on the first CPU.
15. The device according to any one of claims 11-14, wherein, the first network proxy component is configured to forward the processed first data packet to a second network proxy component running on a second DPU after performing network proxy processing on the first data packet; Wherein, the second network proxy component is used to provide network proxy services for the second application, and the destination address of the first data packet is the address where the second application is located.
16. The apparatus according to claim 15, wherein, the second application runs on a second CPU, and the second CPU and the second DPU are deployed on the same node, and the first DPU and the second DPU are located on different nodes.
17. The apparatus according to any one of claims 11-16, wherein, the receiving module is further configured to receive a second data packet sent by the first network proxy component, and the destination address of the second data packet is a third application running on the first CPU; the sending module is further configured to forward the second data packet to the third application.
18. The apparatus according to claim 17, wherein, the sending module is further configured to, in response to the second data packet being sent by a physical network card and the destination address of the second data packet being a third application running on the first CPU, forward the second data packet to the third application.
19. The apparatus according to any one of claims 11-18, wherein, the first DPU includes a first virtual network device and a second virtual network device. The first virtual network device is used to receive data packets with a source address of an application running on the first CPU, and the second virtual network device is used to receive data packets with a destination address of an application running on the first CPU. Both the first virtual network device and the second virtual network device are used to forward the received data packets to different ports on the first network proxy component.
20. The apparatus according to any one of claims 11-19, wherein, the first application runs on the first CPU in a microservices manner.
21. A network proxy apparatus, wherein, it includes a memory and a processor; the memory stores code, and the processor is configured to execute the code. When the code is executed, the apparatus executes the method according to any one of claims 1 to 10.
22. A data processing system, wherein, it includes a CPU and a DPU deployed on the same node. An application runs on the CPU, and a network proxy component is deployed on the DPU. The network proxy component is used to provide network proxy services for the application running on the CPU.
23. A computer storage medium, wherein, the computer storage medium stores instructions, and when the instructions are executed by a computer, the computer implements the method according to any one of claims 1 to 10.
24. A computer program product, wherein, the computer program product stores instructions, and when the instructions are executed by a computer, the computer implements the method according to any one of claims 1 to 10.