Virtual instance flow control method based on cloud computing technology and related products
By identifying the attribute information of the destination virtual instance on the switch to determine the speed limit value, the problem of limited DSCP value range is solved, and efficient flow control of the inlet traffic of the virtual instance is realized to ensure normal operation of the service.
Patent Information
- Application Number
- CN202410387051.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-22
- Filing Date
- 2024-03-29
- Publication Date
- 2025-06-24
AI Technical Summary
In the prior art, the value range of the differential service code point (DSCP) is limited and cannot meet the speed limit requirements of more scenarios, resulting in poor flow control effect on virtual machine network inlet traffic in cloud computing scenarios.
By identifying the attribute information related to the destination virtual instance carried in the message on the switch, and determining the corresponding speed limit value based on these attribute information, thereby realizing fine flow control of the inlet traffic of the virtual instance.
The flow control effect of virtual instance inlet traffic is improved, and the normal operation of services on each virtual instance can be better ensured, and bandwidth competition among virtual instances is avoided due to improper speed limit.
Smart Images

Figure CN120200980A_ABST
Abstract
Description
[0001] This application claims the priority of the Chinese patent application with the application number 202311801170.5 and the invention title "Virtual Machine Network Inlet Traffic Control Method, Device and Related Equipment" filed on December 22, 2023, the entire content of which is incorporated herein by reference. Technical Field
[0002] Embodiments of this application relate to the field of cloud technologies, and in particular, to a virtual instance traffic control method and related products based on cloud computing technologies. Background Art
[0003] In public cloud or private cloud scenarios, multiple virtual machines are installed in the same physical machine, and users can implement corresponding services through one or more virtual machines in the physical machine. In this scenario, it is usually necessary to perform flow control on the service traffic on the virtual machines to ensure the normal operation of the services on the virtual machines.
[0004] In related technologies, a switch connected to a physical machine performs flow control on the inlet traffic of the physical machine through the differentiated services code point (DSCP) in a packet, and thus implements flow control on the service traffic on the virtual machines in the physical machine. However, since the value range of DSCP is only 63, this flow control method cannot meet the speed limit requirements of more scenarios. Summary of the Invention
[0005] Embodiments of this application provide a virtual instance traffic control method and related products based on cloud computing technologies, which can realize that in a cloud scenario, a switch controls the traffic in the incoming direction of a destination virtual instance according to the attribute information related to the destination virtual instance carried in a packet, thereby improving the flow control effect. The technical solutions are as follows:
[0006] In a first aspect, a virtual instance traffic control method based on cloud computing technologies is provided. This method is applied to a switch, the switch is disposed in a first data center that provides cloud computing services, the first data center further includes multiple servers, the multiple servers are connected to the switch, and a first virtual instance runs on a first server among the multiple servers.
[0007] In this method, a switch receives a first stacked packet, where the first stacked packet includes a first inner packet and a first outer packet header. The first inner packet is a packet sent from a second virtual instance to a first virtual instance. The first outer packet header carries attribute information related to the first virtual instance. The second virtual instance is set in a second server among multiple servers, or in a third server in a second data center that provides cloud computing services. The attribute information related to the first virtual instance includes a tenant identifier to which the first virtual instance belongs, or an identifier of a virtual port assigned to the first virtual instance. The switch determines a target ingress rate limit value according to the attribute information related to the first virtual instance. The switch performs traffic control on the first stacked packet according to the target ingress rate limit value.
[0008] In the method provided in the embodiments of the present application, for the ingress traffic of virtual instances in a server, a switch can identify the attribute information related to the destination virtual instance of the traffic, and then determine the corresponding rate limit value according to the attribute information related to the destination virtual instance, so as to implement traffic control on the ingress traffic of the virtual instance. That is to say, the embodiments of the present application provide a method for controlling the ingress traffic of a virtual instance with the attribute information related to the destination virtual instance as the granularity on a switch. Compared with traffic control according to DSCP in the traffic, the method provided in the embodiments of the present application can effectively ensure the normal operation of services on each virtual instance, that is, the traffic control effect is better.
[0009] Based on the method provided in the first aspect, in a possible implementation, the switch stores a first mapping relationship, where the first mapping relationship includes multiple reference ingress rate limit values and reference attribute information respectively corresponding to the multiple reference ingress rate limit values. Each piece of reference attribute information is related to at least one virtual instance among multiple virtual instances running on the first server. Correspondingly, the target ingress rate limit value is one of the multiple reference ingress rate limit values, and the attribute information related to the first virtual instance matches the reference attribute information corresponding to the target ingress rate limit value in the first mapping relationship.
[0010] Through the above first mapping relationship, the switch can quickly determine the target ingress rate limit value for the ingress traffic of the virtual instance.
[0011] Based on the method provided in the first aspect, in a possible implementation, the first data center further includes a control node. In this scenario, the switch receives ingress rate limit configuration information sent by the control node, and the ingress rate limit configuration information includes the first mapping relationship.
[0012] In the embodiments of the present application, the control node can configure the ingress rate limit value on the switch, which improves the application flexibility of the embodiments of the present application.
[0013] Based on the method provided in the first aspect, in a possible implementation manner, each reference ingress rate limit value is related to the virtual instance performance information and the network card bandwidth information. The virtual instance performance information is the performance information of the virtual instance related to the reference attribute information corresponding to each reference ingress rate limit value, and the network card bandwidth information is the bandwidth information of the physical network card on the switch connected to the first server.
[0014] In the above manner, the control node can automatically calculate different ingress rate limit values for different virtual instance related information without manual participation, further improving the application flexibility of the embodiments of the present application.
[0015] Based on the method provided in the first aspect, in a possible implementation manner, in this method, the switch receives a second stacked packet, which includes a second inner packet and a second outer packet header. The second inner packet is a packet sent from a first virtual instance to a third virtual instance, and the second outer packet header carries attribute information related to the third virtual instance. The third virtual instance is set in the fourth server of multiple servers or in the fifth server of the third data center providing cloud services. The attribute information related to the third virtual instance includes the tenant identifier to which the third virtual instance belongs or the identifier of the virtual port assigned to the third virtual instance. The switch determines a target egress rate limit value according to the attribute information related to the third virtual instance, and the switch performs traffic control on the second stacked packet according to the target egress rate limit value.
[0016] In the embodiments of the present application, the switch can also perform traffic control on the egress traffic of each virtual instance in the first server to avoid consuming the resources of the virtual switch on the server to implement traffic control on the egress traffic of the virtual instance.
[0017] Based on the method provided in the first aspect, in a possible implementation manner, the switch stores a second mapping relationship, which includes multiple reference egress rate limit values and the reference attribute information respectively corresponding to the multiple reference egress rate limit values. Correspondingly, the target egress rate limit value is one of the multiple reference egress rate limit values, and the attribute information related to the third virtual instance matches the reference attribute information corresponding to the target egress rate limit value in the second mapping relationship.
[0018] Through the above second mapping relationship, the switch can quickly determine the target egress rate limit value for the virtual instance egress traffic.
[0019] Based on the method provided in the first aspect, in a possible implementation, the first overlay packet is a Virtual eXtensible Local Area Network (VXLAN) packet. The VXLAN packet includes a VXLAN header, and the Virtual eXtensible Local Area Network Identifier (VNI) field in the VXLAN header is used to carry the tenant identifier of the first virtual instance; or, the first overlay packet is a VXLAN Generic Protocol Extension (VXLAN-GPE) packet based on VXLAN. The VXLAN-GPE packet includes a GPE header, and the extended field in the GPE header is used to carry the identifier of the virtual port assigned to the first virtual instance.
[0020] By the above method, relevant attribute information of the first virtual instance is carried in certain fields of the first overlay packet to implement the solution provided in the embodiments of the present application.
[0021] Based on the method provided in the first aspect, in a possible implementation, the first virtual instance includes a virtual machine or a container.
[0022] In the embodiments of the present application, the virtual instance can be a virtual machine or a container, which further improves the application flexibility of the embodiments of the present application.
[0023] In a second aspect, a switch is provided. The switch has a function of implementing the behavior of the virtual instance traffic control method based on cloud computing technology provided in the first aspect above. The switch includes at least one module, and the at least one module is used to implement the method provided in the first aspect above.
[0024] In a third aspect, a switch is provided. The switch includes a processor and a memory; the processor of the device is configured to execute instructions stored in the memory of the switch so that the switch executes the method provided in the first aspect above.
[0025] In a fourth aspect, a computer program product containing instructions is provided. When the instructions are run on a computer device, the computer device is caused to execute the method provided in the first aspect above.
[0026] In a fifth aspect, a computer-readable storage medium is provided, including computer program instructions. When the computer program instructions are executed by a switch, the computer device executes the method provided in the first aspect above.
[0027] The technical effects obtained in the second aspect, third aspect, fourth aspect, and fifth aspect above are similar to the technical effects obtained by the corresponding technical means in the first aspect, and will not be elaborated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0028] Figure 1 is a schematic diagram of an implementation environment provided by an embodiment of the present application;
[0029] Figure 2It is another schematic diagram of the implementation environment provided by the embodiments of the present application;
[0030] Figure 3 It is another schematic diagram of the implementation environment provided by the embodiments of the present application;
[0031] Figure 4 It is a flowchart of a virtual instance traffic control method based on cloud computing technology provided by the embodiments of the present application;
[0032] Figure 5 It is a schematic diagram of a scenario where a switch controls the incoming traffic of a virtual instance provided by the embodiments of the present application;
[0033] Figure 6 It is another schematic diagram of a scenario where a switch controls the incoming traffic of a virtual instance provided by the embodiments of the present application;
[0034] Figure 7 It is another flowchart of a virtual instance traffic control method based on cloud computing technology provided by the embodiments of the present application;
[0035] Figure 8 It is a schematic diagram of the structure of a switch provided by the embodiments of the present application;
[0036] Figure 9 It is a schematic diagram of the structure of a switch provided by the embodiments of the present application. Detailed implementation manners
[0037] To make the objectives, technical solutions, and advantages of the embodiments of the present application clearer, the following will further describe the embodiments of the present application in detail with reference to the accompanying drawings.
[0038] Before explaining the embodiments of the present application, the noun concepts involved in the embodiments of the present application will be explained first.
[0039] Physical machine: A physical server used to provide cloud services such as public cloud or private cloud.
[0040] Virtual machine: In a physical machine, in order to save resources, multiple virtual machines can be installed, and these multiple virtual machines are allocated to multiple tenants, and different tenants belong to different virtual local area networks (VLANs).
[0041] Virtual switch: A virtual switch installed on a physical machine, used to forward the incoming traffic of the physical machine to each virtual machine, or forward the outgoing traffic of each virtual machine to other devices outside the physical machine.
[0042] Switch: Used to forward traffic to a physical machine or forward the outgoing traffic of a physical machine to other physical machines.
[0043] With the rapid development and increasing maturity of cloud technologies such as public cloud, private cloud, or hybrid cloud, more and more enterprise users prefer to use cloud computing instead of traditional business deployment methods when deploying their businesses, that is, deploying the business on virtual machines of physical machines that provide cloud services.
[0044] Among them, a virtual switch is also installed in the physical machine. In some scenarios, the virtual machine switch can perform traffic control on the outbound traffic of each virtual machine in the physical machine to ensure that the outbound traffic of the virtual machine can reach the promised capacity. However, before the traffic reaches the virtual switch, it needs to pass through the switch and the physical network card of the physical machine first, which causes the traffic of different virtual machines to compete for bandwidth on the switch and the physical network card. If the traffic of a certain virtual machine occupies too much bandwidth of the switch or the physical network card, it will affect the normal operation of the services of other virtual machines.
[0045] Therefore, in some other scenarios, the switch can perform traffic control on the inbound traffic of the physical machine through the differentiated services code point (DSCP) in the packet. However, since the value range of DSCP is only 63, this traffic control method cannot meet the speed limit requirements of more scenarios.
[0046] Based on this, the embodiments of the present application provide a virtual instance traffic control method based on cloud computing technology. In the method provided by the embodiments of the present application, the switch can identify the attribute information related to the destination virtual instance of the traffic, and then determine the corresponding speed limit value according to the attribute information related to the destination virtual instance, so as to achieve traffic control on the inbound traffic of the virtual instance. That is, the embodiments of the present application provide a virtual instance inbound traffic control method with the attribute information related to the destination virtual instance as the granularity on the switch. Compared with traffic control according to the DSCP in the traffic, the method provided by the embodiments of the present application can effectively ensure the normal operation of the services on each virtual instance, that is, the traffic control effect is better.
[0047] The following explains the implementation environment, the virtual instance traffic control method based on cloud computing technology, and related products involved in the embodiments of the present application.
[0048] Figure 1 It is a schematic diagram of an implementation environment provided by the embodiments of the present application. As Figure 1 shown, the implementation environment includes at least one data center for providing cloud computing services, Figure 1 and three data centers are taken as an example for illustration.
[0049] Among them, each data center includes multiple servers and switches. The servers in the embodiments of the present application are physical machines. A virtual instance runs on any server. In the embodiments of the present application, a virtual instance can be understood as a virtual system that provides computing resources and storage resources in an isolated environment. The virtual instance exemplarily includes virtual machines and containers, which improves the application flexibility of the embodiments of the present application.
[0050] For any data center, each server in the data center is connected to the switch to communicate with other servers in the same data center through the switch, or communicate with servers in other data centers through the switch.
[0051] Figure 2 It is a schematic diagram of another implementation environment provided by the embodiments of the present application. As Figure 2 shown, this implementation environment includes a first data center 1 and a second data center 2, and the first data center 1 and the second data center 2 are any two of multiple data centers that provide cloud computing servers. Among them, the first data center 1 includes multiple servers 10 and a switch 11, and the second data center 2 also includes multiple servers 20 and a switch 21.
[0052] Taking the first data center 1 as an example, multiple virtual instances are running in each server 10 of the first data center 1, and the switch 11 can perform flow control on the ingress traffic of multiple virtual instances on any server 10 through the method provided by the embodiments of the present application.
[0053] Next, taking the first server 10 in the first data center 1 as an example, the implementation environment of the embodiments of the present application will be further described. Figure 3 It is a schematic diagram of another implementation environment provided by the embodiments of the present application. As Figure 3 shown, multiple virtual instances 101 and a virtual switch 102 are running on the first server 10, Figure 3 and three virtual instances 101 are taken as an example.
[0054] When the switch 11 receives a packet destined for the first server 10, it forwards the packet to the virtual switch 102, and the virtual switch 102 forwards the packet to the corresponding virtual instance 101.
[0055] In an embodiment of the present application, when the switch 11 receives a packet destined for the first server 10, it also parses the attribute information related to the destination virtual instance carried in the packet, and then performs traffic control on the packet according to the attribute information related to the destination virtual instance. If the traffic control result indicates that the packet is allowed to be sent, the switch 11 forwards the packet to the virtual instance switch 102. Correspondingly, if the traffic control result indicates that the packet is not allowed to be sent, the switch 11 discards the packet or caches the packet. Thus, a virtual instance ingress traffic control method with the attribute information related to the destination virtual instance as the granularity is implemented on the switch. The detailed implementation manner will be described in the subsequent method embodiments.
[0056] To implement a virtual instance ingress traffic control method with the attribute information related to the destination virtual instance as the granularity on the switch, an ingress rate limit value matching different virtual instance attribute information can be pre-configured on the switch, so that the switch 11 can quickly perform traffic control on the virtual instance ingress traffic according to the configured ingress rate limit value.
[0057] In some embodiments, the implementation manner of configuring the ingress rate limit value matching different virtual instance attribute information on the switch can be: the switch obtains the ingress rate limit configuration information, and the ingress rate limit configuration information includes the ingress rate limit values respectively corresponding to different virtual instance attribute information.
[0058] For example, if the virtual instance attribute information is the VNI of the virtual instance, the ingress rate limit value corresponding to a certain target VNI can be understood as: the ingress rate limit value configured for at least one virtual instance with the VNI being the target VNI. Another example, if the virtual instance attribute information is the identifier of the virtual port allocated to the virtual instance, the ingress rate limit value corresponding to a certain target port identifier can be understood as: the ingress rate limit value configured for the virtual instance with the port being the port indicated by the target port identifier.
[0059] Among them, the ingress rate limit configuration information can be directly set manually by a technician on the switch. Optionally, it can also be automatically configured by the control node based on the performance of the virtual instance, which improves the application flexibility of the embodiments of the present application. As Figure 3 shown, the first data center 1 further includes a control node 12, and the control node 12 is used to configure the ingress rate limit value matching different virtual instance attribute information on the switch 11, so that the switch 11 can perform traffic control on the virtual instance ingress traffic according to the configured ingress rate limit value.
[0060] Exemplarily, the implementation manner for the control node to configure the ingress rate limit value on the switch may be as follows: The control node receives a virtual instance configuration instruction from the cloud management platform, where the cloud management platform is used to manage the infrastructure that provides cloud computing services; in response to the virtual instance configuration instruction, the control node determines the ingress rate limit values corresponding to different virtual instance attribute information according to the performance information of one or more virtual instances running on the first server and the bandwidth information of the physical network card connected to the first server on the switch; the control node sends the ingress rate limit configuration information to the switch, and the ingress rate limit configuration information includes the ingress rate limit values corresponding to different virtual instance attribute information respectively.
[0061] Through the above method, the control node can automatically calculate different ingress rate limit values for different virtual instance-related attribute information, without manual participation in the configuration of the rate limit values, further improving the application flexibility of the embodiments of the present application.
[0062] Among them, the performance information of the virtual instance may exemplarily include the number of processing units on the virtual instance, the type of processing unit, etc. For example, the number of central processing units (CPUs) included in the virtual instance, the number of graphics processing units (GPUs), etc.
[0063] Exemplarily, when a tenant deploys services on one or more virtual instances of the first server through the cloud management platform, the cloud management platform can send the virtual instance configuration instruction to the control node to trigger the control node to configure the ingress rate limit values corresponding to the attribute information related to each virtual instance in the first server on the switch.
[0064] The above control node configures the rate limit values corresponding to each virtual instance in the first server on the switch when the tenant deploys services. Optionally, the control node can also configure the rate limit values for the virtual instance on the switch at other times, which will not be exemplified one by one here.
[0065] It should be noted that since the switch 11 is configured with a network card corresponding to each server 10, the traffic between the switch 11 and different servers 10 is isolated from each other. In other words, the processing methods of the traffic between the switch 11 and each server 10 are independent of each other. Therefore, the subsequent embodiments will be described by taking the communication between the switch 11 and the first server 10 as an example.
[0066] Figure 4 It is a flowchart of a virtual instance traffic control method provided by an embodiment of the present application based on cloud computing technology. This method is applied to Figure 3 the implementation environment shown, as Figure 4 shown, this method includes the following steps.
[0067] Step 401: The switch receives a first stacked packet, which includes a first inner packet and a first outer packet header. The first inner packet is a packet sent by a second virtual instance to a first virtual instance. The first outer packet header carries attribute information related to the first virtual instance. The second virtual instance is set in a second server among multiple servers or in a third server in a second data center providing cloud computing services. The attribute information related to the first virtual instance includes a tenant identifier to which the first virtual instance belongs or an identifier of a virtual port allocated to the first virtual instance.
[0068] Wherein, the second virtual instance is also the source virtual instance of the first stacked packet, and the first virtual instance is also the destination virtual instance of the first stacked packet.
[0069] The attribute information related to the first virtual instance is used to indicate the attribute value of the first virtual instance on each of at least one attribute, so that the switch can classify and control the incoming traffic of the virtual instance based on the attribute values of each attribute of the destination virtual instance in the packet.
[0070] In some embodiments, the attribute information related to the destination virtual instance includes the attribute value of the destination virtual instance on a specified attribute. Wherein, the specified attribute is a pre-specified attribute. In this way, the switch can classify and control the incoming traffic of the virtual instance based on a certain specified attribute of the destination virtual instance.
[0071] Exemplarily, the specified attribute may be a virtual extensible local area network identifier (VNI) of the virtual instance. Wherein, the VNI of the virtual instance is also the identifier of the VXLAN of the tenant to which the virtual instance belongs. In this scenario, the attribute information related to the first virtual instance includes the tenant identifier to which the first virtual instance belongs.
[0072] Wherein, when the packet is a packet encapsulated by the VXLAN protocol, the packet includes a VXLAN header, and the VXLAN header includes a VNI field, and the information carried by the VNI field includes the VNI of the destination virtual instance.
[0073] Based on this, in some embodiments, the first stacked packet is a VXLAN packet, and the VXLAN packet includes a VXLAN header, and the VNI field in the VXLAN header is used to carry the tenant identifier to which the first virtual instance belongs.
[0074] As another example, the specified attribute may be a virtual port identifier assigned to a virtual instance. Herein, the virtual port of the virtual instance is also the port on the virtual instance that is connected to the virtual switch, and this virtual port is also referred to as a virtual network card. In this scenario, the attribute information related to the first virtual instance includes the identifier of the virtual port assigned to the first virtual instance.
[0075] Wherein, when the packet is a packet encapsulated using the VXLAN protocol, the packet may further include a VXLAN Generic Protocol Extension (GPE) header, and the GPE header includes an extended field that can carry the virtual port identifier of the destination virtual instance.
[0076] Based on this, in some embodiments, the first overlay packet is a VXLAN-GPE packet, and the VXLAN-GPE packet includes a GPE header, and the extended field in the GPE header is used to carry the identifier of the virtual port assigned to the first virtual instance.
[0077] Optionally, the first overlay packet may also be other packets such as a Generic Routing Encapsulation (GRE) packet, etc., to carry the attribute information related to the first virtual instance through other packets, and no further examples will be given here.
[0078] The VNI of the above virtual instance and the virtual port of the virtual instance are used to exemplify the attribute information related to the virtual instance. In the embodiments of the present application, flow control may also be performed according to other attributes of the destination virtual instance, so as to implement a virtual instance ingress traffic control method on the switch with the attribute information related to the destination virtual instance as the granularity.
[0079] Step 402: The switch determines a target ingress rate limit value according to the attribute information related to the first virtual instance.
[0080] In some embodiments, there is a mapping relationship between the virtual instance attribute information and the ingress rate limit value stored in the switch. In this scenario, the implementation manner of step 402 may be: the switch inputs the attribute information related to the first virtual instance into this mapping relationship, and uses the output rate limit value as the target ingress rate limit value.
[0081] This mapping relationship may be a list, and different ingress rate limit values corresponding to the virtual instance attribute information are listed in this list. Optionally, this mapping relationship may also be an algorithm model, and the internal calculation logic of this algorithm model can indicate the conversion relationship between the virtual instance attribute information and the ingress rate limit value. This algorithm model may be pre-configured by technicians, and the embodiments of the present application do not make limitations thereto.
[0082] Exemplarily, the switch stores a first mapping relationship, which includes multiple reference ingress rate limit values and reference attribute information respectively corresponding to the multiple reference ingress rate limit values. Each piece of reference attribute information is related to at least one virtual instance among the multiple virtual instances running on the first server.
[0083] Through the above first mapping relationship, the switch can quickly determine the target ingress rate limit value for the ingress traffic of each virtual instance on the first server.
[0084] In this scenario, the target ingress rate limit value is one of the multiple reference ingress rate limit values in the first mapping relationship, and the attribute information related to the first virtual instance matches the reference attribute information corresponding to the target ingress rate limit value in the first mapping relationship.
[0085] In the embodiments of the present application, the first mapping relationship can be configured by a technician on the switch. Optionally, the first mapping relationship can also be configured through a control node. Based on this, in some embodiments, the switch receives the ingress rate limit configuration information sent by the control node, and the ingress rate limit configuration information includes the first mapping relationship.
[0086] Based on the introduction of the control node in the foregoing implementation environment, the control node can configure the ingress rate limit value according to the performance information of each virtual instance on the first server and the bandwidth information of the network card connected to the first server. In this scenario, each reference ingress rate limit value in the first mapping relationship is related to the virtual instance performance information and the network card bandwidth information, where the virtual instance performance information is the performance information of the virtual instance related to the reference attribute information corresponding to each reference ingress rate limit value, and the network card bandwidth information is the bandwidth information of the physical network card connected to the first server on the switch.
[0087] Exemplarily, the control node can first count the performance information of the virtual instances related to each piece of reference attribute information among the multiple pieces of reference attribute information to obtain the virtual instance performance information corresponding to each piece of reference attribute information. Among them, when the virtual instances related to a certain piece of reference attribute information are multiple virtual instances, the virtual instance performance information corresponding to this piece of reference attribute information is: the set of the performance information of the multiple virtual instances related to this piece of reference attribute information. Then the control node determines the computing power indicated by the virtual instance performance information corresponding to each piece of reference attribute information based on the virtual instance performance information corresponding to each piece of reference attribute information to obtain the computing power corresponding to each piece of reference attribute information. Finally, according to the ratio between the computing powers corresponding to each piece of reference attribute information, the bandwidth of the physical network card connected to the first server on the switch is allocated to obtain the ingress rate limit value corresponding to each piece of reference attribute information.
[0088] The above is used to illustrate how to configure the ingress rate limit value according to the performance information of each virtual instance and the bandwidth information of the network card connected to the first server. The embodiments of the present application do not limit the specific configuration process.
[0089] In addition, in a scenario where the attribute information related to the first virtual instance includes the attribute value of the first virtual instance on a specified attribute, the implementation manner of step 402 may be: The switch determines the target ingress rate limit value according to the attribute value of the first virtual instance on the specified attribute.
[0090] Exemplarily, the above first mapping relationship includes multiple ingress rate limit values and the attribute values of the specified attributes respectively corresponding to the multiple ingress rate limit values. That is, each reference attribute information in the first mapping relationship is an attribute value of the specified attribute. Correspondingly, the implementation manner of the switch determining the target ingress rate limit value according to the attribute value of the first virtual instance on the specified attribute may be: The switch determines, from the multiple ingress rate limit values, the ingress rate limit value that matches the attribute value of the first virtual instance on the specified attribute as the target ingress rate limit value.
[0091] In the above manner, the switch can classify and control the virtual instance ingress traffic using different ingress rate limit values according to the different attribute values of the destination virtual instance of the traffic on the specified attribute. For example, the switch receives a first overlay packet, and the outer packet header of the first overlay packet carries the attribute value of the destination virtual instance on the specified attribute; the switch determines the first target ingress rate limit value according to the attribute value of the destination virtual instance carried by the first overlay packet; the switch performs traffic control on the first overlay packet according to the first ingress target rate limit value. The switch receives a third overlay packet, and the third overlay packet carries the attribute value of the destination virtual instance on the specified attribute; the switch determines the third target ingress rate limit value according to the attribute value of the destination virtual instance carried by the third overlay packet; the switch performs traffic control on the third overlay packet according to the third target ingress rate limit value. In this scenario, when the destination virtual instance of the first overlay packet and the destination virtual instance of the third overlay packet have different attribute values on the specified attribute, the first target ingress rate limit value used by the switch during traffic control is different from the third target ingress rate limit value.
[0092] Exemplarily, the specified attribute is the VNI of the virtual instance, that is, the tenant identifier to which the virtual instance belongs. In this scenario, the first mapping relationship includes multiple VNIs and multiple ingress rate limit values respectively corresponding to the multiple VNIs. The switch can select an ingress rate limit value from these multiple ingress rate limit values according to the VNI of the destination virtual instance carried by the received overlay packet as the target ingress rate limit value used for current traffic control.
[0093] In this scenario, the switch can distinguish different tenants by identifying the VNI of the destination virtual instance in the outer packet header, so as to achieve traffic isolation at the tenant granularity in the virtual instance ingress direction.
[0094] Figure 5 It is a schematic diagram of a scenario for a switch to control the ingress traffic of a virtual instance provided by an embodiment of the present application. As Figure 5 shown, virtual instance 1 and virtual instance 2 belong to the same tenant A, and the VNI corresponding to tenant A is 10,000, that is, virtual instance 1 and virtual instance 2 use the same VNI = 10,000. Virtual instance 3 belongs to another tenant B, and the VNI corresponding to tenant B is 5000, that is, the VNI used by virtual instance 3 is 5000.
[0095] The control node pre-configures two ingress rate limit values corresponding to these two VNIs on the switch, which are respectively called ingress rate limit value 1 and ingress rate limit value 2. Exemplarily, the control node determines the total performance information of the two virtual instances corresponding to VNI = 10,000 and the performance information of one virtual instance corresponding to VNI = 5000, statistics the ratio between the computing powers indicated by these two types of performance information, and allocates the bandwidth of the physical network card connected to the server on the switch according to the ratio between the computing powers indicated by these two types of performance information, so as to obtain two ingress rate limit values respectively for VNI = 10,000 and VNI = 5000.
[0096] When the switch receives a packet to be sent to the server, it distinguishes which ingress rate limit value to use for traffic control according to the VNI of the destination virtual instance in the packet. Among them, the two virtual instances of tenant A use the same ingress rate limit value, that is, ingress rate limit value 1 for unified rate limiting, and tenant B uses another ingress rate limit value, that is, ingress rate limit value 2 for rate limiting. That is, when the VNI of the destination virtual instance of the packet is 10,000, at this time the destination virtual instance of the packet is virtual instance 1 or virtual instance 2, and the switch uses ingress rate limit value 1 to perform traffic control on the packet. When the VNI of the destination virtual instance of the packet is 5000, at this time the destination virtual instance of the packet is virtual instance 3, and the switch uses ingress rate limit value 2 to perform traffic control on the packet, so as to achieve traffic isolation control between tenant A and tenant B.
[0097] Moreover, performing rate limiting on the switch does not consume the resources of the virtual switch on the server. At the same time, since traffic control is performed at the tenant granularity, there will also be no packet loss of virtual instances that do not reach the rate limit value due to multiple virtual instances competing for bandwidth on the network card of the switch.
[0098] As another example, the specified attribute is the identifier of the virtual port assigned to the virtual instance. In this scenario, the first mapping relationship includes multiple port identifiers and multiple ingress rate limiting values respectively corresponding to the multiple port identifiers. The switch can select one ingress rate limiting value from the multiple ingress rate limiting values as the target ingress rate limiting value according to the port identifier of the destination virtual instance carried in the packet.
[0099] When the source virtual instance or the gateway sends a packet to the switch, it can identify which port of which virtual instance the destination is sent to. Therefore, the source virtual instance or the gateway can carry the port identifier of the destination virtual instance in the packet header. In this way, when the switch receives the packet, it can distinguish different virtual instance ports by identifying the port identifier of the destination virtual instance carried in the packet header, and achieve traffic isolation at the port granularity.
[0100] Similarly, since rate limiting is performed on the switch, it does not consume the resources of the virtual switch on the server. At the same time, since flow control is performed at the port granularity of the destination virtual instance of the packet, there will also be no packet loss of virtual instances that do not reach the rate limiting value due to multiple virtual instances competing for bandwidth on the network card of the switch.
[0101] Figure 6 It is a schematic diagram of another scenario of the switch performing ingress flow control on virtual instances provided by the embodiments of the present application. As Figure 6 shown, the virtual ports assigned to virtual instances 1 / 2 / 3 are ports 1 / 2 / 3 respectively.
[0102] The control node pre-configures the ingress rate limiting values corresponding to the 3 ports on the switch respectively, which are called ingress rate limiting value 3, ingress rate limiting value 4, and ingress rate limiting value 5. As an example, the control node determines the computing power indicated by the performance information of the three virtual instances corresponding to the three ports respectively, calculates the ratio of the three computing powers, and distributes the bandwidth of the physical network card connected to the server on the switch according to the ratio of the three computing powers to obtain three ingress rate limiting values respectively for the three ports.
[0103] When the switch receives a packet that needs to be sent to the server, when the port identifier of the destination virtual instance of the packet is port 1, at this time the destination virtual instance of the packet is virtual instance 1, and the switch uses ingress rate limiting value 3 for flow control. When the port identifier of the destination virtual instance of the packet is port 2, at this time the destination virtual instance of the packet is virtual instance 2, and the switch uses ingress rate limiting value 4 for flow control. When the port identifier of the destination virtual instance of the packet is port 3, at this time the destination virtual instance of the packet is virtual instance 3, and the switch uses ingress rate limiting value 5 for flow control.
[0104] In Figure 6In the shown scenario, the switch can control the traffic rate limit of each virtual instance through traffic rate limiting at the virtual instance port granularity, achieving traffic isolation between virtual instances. In other words, the switch can limit the traffic volume of each virtual instance to achieve traffic isolation between virtual instances and prevent interference between virtual instances.
[0105] The above takes the example that the attribute value of each specified attribute corresponds to an ingress rate limit value to illustrate the first mapping relationship. Optionally, in some other embodiments, the first mapping relationship has multiple ingress rate limit values, and each rate limit value in the multiple rate limit values corresponds to a range of attribute values of the specified attribute, that is, each reference attribute information in the first mapping relationship is a range of attribute values of the specified attribute. In this scenario, the implementation manner for the switch to determine the target rate limit value according to the attribute value of the destination virtual instance on the specified attribute can be: the switch selects the rate limit value that matches the attribute value of the destination virtual instance on the specified attribute from the multiple rate limit values as the target rate limit value.
[0106] For example, the switch stores multiple ingress rate limit values, and each ingress rate limit value corresponds to a range of VNIs or corresponds to multiple virtual instance port identifiers, so as to achieve traffic control of the virtual instance ingress traffic at a coarser granularity.
[0107] The above takes the example that the switch stores the first mapping relationship including multiple ingress rate limit values to illustrate. Optionally, in the embodiments of the present application, when the switch receives a packet, it can also directly calculate the attribute information of the destination virtual instance through a preset algorithm (that is, the mapping relationship is an algorithm model) to obtain the target ingress rate limit value that matches the attribute information of the destination virtual instance, which will not be elaborated here.
[0108] In addition, the above takes traffic control with one specified attribute as the granularity as an example to illustrate. Optionally, the switch can also combine multiple attributes of the destination virtual instance to comprehensively determine a target ingress rate limit value used for the current traffic control, which will not be elaborated here.
[0109] Step 403: The switch performs traffic control on the first stacked packet according to the target ingress rate limit value.
[0110] In some embodiments, the switch can implement traffic control on the first superimposed packet according to the target ingress rate limit value through a token bucket. For example, for the first mapping relationship in step 402, the switch can configure corresponding token buckets for different reference attribute information, and periodically add tokens to the corresponding token buckets according to the ingress rate limit value corresponding to each reference attribute information. When the switch receives the first superimposed packet, it applies for a token from the token bucket corresponding to the reference attribute information related to the destination virtual instance of the first superimposed packet. If a token can be obtained, that is, the traffic control result is to allow the transmission of the first superimposed packet, the switch then forwards the first superimposed packet to the virtual switch of the first server, and the virtual switch forwards the packet to the destination virtual instance.
[0111] If a token cannot be obtained, that is, the traffic control result is to prohibit the transmission of the first superimposed packet, the switch then discards the first superimposed packet or caches the first superimposed packet until a token can be obtained.
[0112] For example, when the switch performs traffic control at the tenant granularity, the switch configures a token bucket for each tenant (that is, each VNI), and performs traffic control on the first superimposed packet through the token bucket corresponding to the VNI of the first virtual instance.
[0113] Another example is that when the switch performs traffic control at the virtual instance granularity, the switch configures a token bucket for the virtual port of each virtual instance, and performs traffic control on the first superimposed packet through the token bucket corresponding to the virtual port of the first virtual instance.
[0114] Optionally, traffic control on the first superimposed packet according to the target ingress rate limit value can also be implemented by other means, such as through a leaky bucket algorithm, which will not be exemplified one by one here.
[0115] In summary, in the embodiments of the present application, the switch can identify the attribute information related to the destination virtual instance of the traffic, and then determine the corresponding target ingress rate limit value according to the attribute information related to the destination virtual instance, so as to implement traffic control on the ingress traffic of the virtual instance. That is, the embodiments of the present application provide a method for controlling the ingress traffic of a virtual instance with the attribute information related to the destination virtual instance as the granularity on a switch. Compared with traffic control according to DSCP in the traffic, the method provided in the embodiments of the present application will not cause packet loss of virtual instances that do not reach the rate limit value due to multiple virtual instances competing for bandwidth on the network card of the switch. That is, the method provided in the embodiments of the present application can effectively ensure the normal operation of services on each virtual instance, so the traffic control effect is better. And because the rate limit is executed on the switch, it will not consume the resources of the virtual switch on the server.
[0116] In addition, in the embodiments of the present application, the switch can also perform flow control on the egress traffic of each virtual instance in the first server, so as to avoid consuming the resources of the virtual switch on the server to implement flow control on the egress traffic of the virtual instance. The following uses Figure 7 as an example to explain this solution.
[0117] Figure 7 is a flowchart of another virtual instance traffic control method based on cloud computing technology provided by the embodiments of the present application. This method is applied to the Figure 3 shown implementation environment. As shown in Figure 7 shown, this method includes the following steps.
[0118] Step 701: The switch receives a second stacked packet, which includes a second inner packet and a second outer packet header. The second inner packet is a packet sent from the first virtual instance to the third virtual instance. The second outer packet header carries attribute information related to the third virtual instance. The third virtual instance is set in the fourth server of multiple servers, or in the fifth server of the third data center that provides cloud services. The attribute information related to the third virtual instance includes the tenant identifier to which the third virtual instance belongs, or the identifier of the virtual port allocated to the third virtual instance.
[0119] Among them, the first virtual instance is also the source virtual instance of the second stacked packet, and the third virtual instance is also the destination virtual instance of the second stacked packet. The attribute information related to the third virtual instance is used to indicate the attribute value of the third virtual instance on each attribute in at least one attribute, so that the switch can classify and control the egress traffic of the virtual instance based on the attribute values of each attribute of the destination virtual instance in the packet.
[0120] Among them, the explanation of the attribute information related to the third virtual instance can refer to the description of the attribute information related to the first virtual instance in step 401, which will not be elaborated here.
[0121] The format of the second stacked packet can also refer to the format of the first stacked packet in step 401, which will not be elaborated here.
[0122] Step 702: The switch determines a target egress rate limit value according to the attribute information related to the third virtual instance.
[0123] In some embodiments, the switch stores a second mapping relationship, which includes multiple reference egress rate limit values and reference attribute information respectively corresponding to the multiple reference egress rate limit values; the target egress rate limit value is one of the multiple reference egress rate limit values, and the attribute information related to the third virtual instance matches the reference attribute information corresponding to the target egress rate limit value in the second mapping relationship.
[0124] Through the above second mapping relationship, the switch can quickly determine the target egress rate limit value for the virtual instance egress traffic.
[0125] Exemplarily, the second mapping relationship includes a plurality of VNIs and a plurality of egress rate limit values respectively corresponding to the plurality of VNIs. In this scenario, the target egress rate limit value is the egress rate limit value corresponding to the VNI of the third virtual instance in the second mapping relationship.
[0126] Another exemplarily, the second mapping relationship includes a plurality of port identifiers and a plurality of egress rate limit values respectively corresponding to the plurality of port identifiers. In this scenario, the target egress rate limit value is the egress rate limit value corresponding to the port identifier of the third virtual instance in the second mapping relationship.
[0127] Among them, the explanation of the second mapping relationship can refer to the description of the first mapping relationship in step 402, which will not be elaborated here.
[0128] It should be noted that the multiple reference attribute information in the first mapping relationship is not the same as the reference attribute information in the second mapping relationship. Among them, the multiple reference attribute information in the first mapping relationship is obtained according to the attribute information related to each virtual instance running on the first server, but the multiple reference attribute information in the second mapping relationship is obtained according to the attribute information related to all destination virtual instances of the egress traffic of the first server, and these destination virtual instances are not in the first server.
[0129] In addition, the second mapping relationship can also be configured by technicians or the control node. Based on this, in some embodiments, the switch receives the egress rate limit configuration information sent by the control node, and the egress rate limit configuration information includes the second mapping relationship.
[0130] It should be noted that since the egress traffic of each virtual instance in the first server may be sent to virtual instances on other servers in the same data center, or may also be sent to virtual instances on servers in other data centers. Therefore, the control node needs to consider the virtual instances on the servers in all data centers providing cloud computing services when determining the second mapping relationship.
[0131] In the embodiments of the present application, there is no limitation on how the control node sets the egress rate limit value in the second mapping relationship. The way for the control node to configure the egress rate limit value can be exemplarily the same as the way to configure the egress rate limit value when performing egress traffic rate limiting on the virtual switch of the first server. Exemplarily, for any reference attribute information, the control node can determine the network communication capability of the virtual instance related to the reference attribute information, and then configure the corresponding egress rate limit value for the reference attribute information according to the network communication capability.
[0132] Step 703: The switch performs traffic control on the second superimposed packet according to the target egress rate limit value.
[0133] Among them, the implementation manner of step 703 can refer to step 403 and will not be elaborated here.
[0134] In summary, in the embodiment of the present application, the switch can identify the attribute information related to the destination virtual instance of the egress traffic of a certain virtual instance, and then determine the corresponding target egress rate limit value according to the attribute information related to the destination virtual instance, so as to implement traffic control on the egress traffic of the virtual instance. That is, the embodiment of the present application provides a method for controlling the egress traffic of a virtual instance with the attribute information related to the destination virtual instance as the granularity. Since rate limiting is performed on the switch, the resources of the virtual switch on the server will not be consumed.
[0135] Figure 8 It is a schematic structural diagram of a switch provided by an embodiment of the present application. The switch is disposed in the first data center that provides cloud computing services. The first data center further includes multiple servers. The multiple servers are connected to the switch, and a first virtual instance runs on a first server among the multiple servers. As Figure 8 shown, the switch 800 includes the following modules.
[0136] A first receiving module 801, configured to receive a first superimposed packet. The first superimposed packet includes a first inner layer packet and a first outer layer packet header. The first inner layer packet is a packet sent by a second virtual instance to the first virtual instance. The first outer layer packet header carries attribute information related to the first virtual instance. The second virtual instance is disposed in a second server among the multiple servers, or disposed in a third server in a second data center that provides cloud computing services. The attribute information related to the first virtual instance includes a tenant identifier to which the first virtual instance belongs, or an identifier of a virtual port allocated to the first virtual instance. The specific implementation manner can refer to Figure 4 step 401 in
[0137] A first determining module 802, configured to determine a target ingress rate limit value according to the attribute information related to the first virtual instance. The specific implementation manner can refer to Figure 4 step 402 in
[0138] A first traffic control module 803, configured to perform traffic control on the first superimposed packet according to the target ingress rate limit value. The specific implementation manner can refer to Figure 4 step 403 in
[0139] Optionally, the switch stores a first mapping relationship, which includes multiple reference ingress rate limit values and corresponding reference attribute information respectively associated with the multiple reference ingress rate limit values. Each piece of reference attribute information is associated with at least one of the multiple virtual instances running on the first server. In this scenario, the target ingress rate limit value is one of the multiple reference ingress rate limit values, and the attribute information associated with the first virtual instance matches the reference attribute information corresponding to the target ingress rate limit value in the first mapping relationship.
[0140] Optionally, the first data center further includes a control node; the switch further includes: a second receiving module, configured to receive ingress rate limit configuration information sent by the control node, where the ingress rate limit configuration information includes the first mapping relationship.
[0141] Optionally, each reference ingress rate limit value is related to virtual instance performance information and network card bandwidth information. The virtual instance performance information is the performance information of the virtual instance associated with the reference attribute information corresponding to each reference ingress rate limit value, and the network card bandwidth information is the bandwidth information of the physical network card connected to the first server on the switch.
[0142] Optionally, the switch further includes: a third receiving module, configured to receive a second stacked packet, where the second stacked packet includes a second inner packet and a second outer packet header. The second inner packet is a packet sent from the first virtual instance to the third virtual instance, and the second outer packet header carries attribute information associated with the third virtual instance. The third virtual instance is set in the fourth server of the multiple servers, or set in the fifth server of the third data center providing cloud services. The attribute information associated with the third virtual instance includes the tenant identifier to which the third virtual instance belongs, or the identifier of the virtual port assigned to the third virtual instance; a second determination module, configured to determine a target egress rate limit value according to the attribute information associated with the third virtual instance; a second flow control module, configured to perform traffic control on the second stacked packet according to the target egress rate limit value.
[0143] Optionally, the switch stores a second mapping relationship, which includes multiple reference egress rate limit values and corresponding reference attribute information respectively associated with the multiple reference egress rate limit values. In this scenario, the target egress rate limit value is one of the multiple reference egress rate limit values, and the attribute information associated with the third virtual instance matches the reference attribute information corresponding to the target egress rate limit value in the second mapping relationship.
[0144] Optionally, the first overlay packet is a VXLAN packet, and the VXLAN packet includes a VXLAN header. The virtual extended local area network identifier (VNI) field in the VXLAN header is used to carry the tenant identifier to which the first virtual instance belongs; alternatively, the first overlay packet is a VXLAN-GPE packet, and the VXLAN-GPE packet includes a GPE header. The extended field in the GPE header is used to carry the identifier of the virtual port allocated to the first virtual instance.
[0145] Optionally, the first virtual instance includes a virtual machine or a container.
[0146] Among them, the first receiving module 801, the first determining module 802, and the first flow control module 803 can all be implemented by software. It should be noted that in other embodiments, the first receiving module 801 can be used to execute any step in the virtual instance network traffic control method based on cloud computing technology, the first determining module 802 can be used to execute any step in the virtual instance traffic control method based on cloud computing technology, and the first flow control module 803 can be used to execute any step in the virtual instance traffic control method based on cloud computing technology. The steps to be implemented by the first receiving module 801, the first determining module 802, and the first flow control module 803 can be specified as needed. By implementing different steps in the virtual instance traffic control method based on cloud computing technology through the first receiving module 801, the first determining module 802, and the first flow control module 803 respectively, all functions of the switch can be realized.
[0147] An embodiment of the present application further provides a switch 900. As Figure 9 shown, the switch 900 includes: a bus 902, a processor 904, a memory 906, and a communication interface 908. The processor 904, the memory 906, and the communication interface 908 communicate with each other through the bus 902. The switch 900 can be any device capable of forwarding packets. It should be understood that the present application does not limit the number of processors and memories in the switch 900.
[0148] The bus 902 can be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 9 only one line is shown here, but it does not mean that there is only one bus or one type of bus. The bus 902 can include a path for transmitting information between various components (such as the memory 906, the processor 904, and the communication interface 908) in the switch 900.
[0149] The processor 904 may include any one or more of processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0150] The memory 906 may include volatile memory, such as random access memory (RAM). The processor 904 may also include non-volatile memory, such as read-only memory (ROM), flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0151] The memory 906 stores executable program code, and the processor 904 executes the executable program code to implement the functions of the foregoing first receiving module 801, first determining module 802, and first flow control module 803 respectively, thereby implementing the virtual instance traffic control method based on cloud computing technology. That is, the memory 906 stores instructions for executing the virtual instance traffic control method based on cloud computing technology.
[0152] Alternatively, the memory 906 stores executable code, and the processor 904 executes the executable code to implement the functions of the foregoing virtual instance traffic control device based on cloud computing technology respectively, thereby implementing the virtual instance traffic control method based on cloud computing technology. That is, the memory 906 stores instructions for executing the virtual instance traffic control method based on cloud computing technology.
[0153] The communication interface 908 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the switch 900 and other devices or communication networks.
[0154] The embodiment of the present application also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions that can run on a computer device or be stored in any available medium. When the computer program product runs on at least one computer device, at least one computer device is caused to execute the virtual instance traffic control method based on cloud computing technology.
[0155] An embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium may be any available medium that can be stored by a computer device or a data storage device such as a data center including one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid state drive), etc. The computer-readable storage medium includes instructions that direct the computer device to execute a virtual instance traffic control method based on cloud computing technology.
[0156] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application and are not intended to limit them. Although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions described in the foregoing embodiments, or perform equivalent replacements for some of the technical features. These modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present application.
Claims
1. A virtual instance traffic control method based on cloud computing technology, characterized in that: The method is applied to a switch, the switch is arranged in a first data center providing cloud computing services, the first data center further comprises a plurality of servers, the plurality of servers are connected to the switch, and a first virtual instance is running on a first server among the plurality of servers; the method comprises: The switch receives a first superposition message, the first superposition message including a first inner message and a first outer message header, the first inner message is a message sent from the second virtual instance to the first virtual instance, the first outer message header carries attribute information related to the first virtual instance, the second virtual instance is set in a second server of the multiple servers, or is set in a third server in a second data center that provides the cloud computing service, wherein the attribute information related to the first virtual instance includes a tenant identifier to which the first virtual instance belongs, or an identifier of a virtual port assigned to the first virtual instance; The switch determines a target ingress rate limit value according to attribute information related to the first virtual instance; The switch performs flow control on the first superposition message according to the target ingress rate limit value.
2. The method according to claim 1, characterized in that The switch stores a first mapping relationship, the first mapping relationship including a plurality of reference inlet rate limit values and reference attribute information respectively corresponding to the plurality of reference inlet rate limit values, each reference attribute information being related to at least one virtual instance among the plurality of virtual instances running on the first server; The target inlet speed limit value is one of the multiple reference inlet speed limit values, and the attribute information related to the first virtual instance matches the reference attribute information corresponding to the target inlet speed limit value in the first mapping relationship.
3. The method according to claim 2, characterized in that The first data center further includes a control node; and the method further includes: The switch receives ingress rate limit configuration information sent by the control node, where the ingress rate limit configuration information includes the first mapping relationship.
4. The method according to claim 2 or 3, characterized in that Each reference inlet speed limit value is related to virtual instance performance information and network card bandwidth information, the virtual instance performance information is performance information of the virtual instance related to the reference attribute information corresponding to each reference inlet speed limit value, and the network card bandwidth information is bandwidth information of the physical network card on the switch connected to the first server.
5. The method according to any one of claims 1 to 4, characterized in that: The method further comprises: The switch receives a second overlay message, the second overlay message includes a second inner message and a second outer message header, the second inner message is a message sent by the first virtual instance to a third virtual instance, the second outer message header carries attribute information related to the third virtual instance, the third virtual instance is set in a fourth server of the multiple servers, or is set in a fifth server of a third data center providing cloud services, wherein the attribute information related to the third virtual instance includes a tenant identifier to which the third virtual instance belongs, or an identifier of a virtual port assigned to the third virtual instance; The switch determines a target egress rate limit value according to attribute information related to the third virtual instance; The switch performs flow control on the second superimposed message according to the target egress rate limit value.
6. The method according to claim 5, characterized in that The switch stores a second mapping relationship, wherein the second mapping relationship includes a plurality of reference export rate limit values and reference attribute information respectively corresponding to the plurality of reference export rate limit values; The target exit speed limit value is one of the multiple reference exit speed limit values, and the attribute information related to the third virtual instance matches the reference attribute information corresponding to the target exit speed limit value in the second mapping relationship.
7. The method according to any one of claims 1 to 6, characterized in that: The first overlay message is a virtual extended local area network VXLAN message, the VXLAN message includes a VXLAN header, and the virtual extended local area network identifier VNI field in the VXLAN header is used to carry the tenant identifier to which the first virtual instance belongs; or, The first overlay message is a VXLAN-GPE message based on a general protocol extension of VXLAN, and the VXLAN-GPE message includes a GPE header, and the extension field in the GPE header is used to carry the identifier of the virtual port assigned to the first virtual instance.
8. The method according to any one of claims 1 to 7, characterized in that: The first virtual instance includes a virtual machine or a container.
9. A switch, characterized in that: The switch is arranged in a first data center providing cloud computing services, the first data center further comprising a plurality of servers, the plurality of servers being connected to the switch, and a first virtual instance running on a first server among the plurality of servers; the switch comprises: A first receiving module, configured to receive a first superposition message, wherein the first superposition message includes a first inner message and a first outer message header, wherein the first inner message is a message sent from the second virtual instance to the first virtual instance, and the first outer message header carries attribute information related to the first virtual instance, wherein the second virtual instance is set in a second server of the plurality of servers, or in a third server of a second data center providing the cloud computing service, wherein the attribute information related to the first virtual instance includes a tenant identifier to which the first virtual instance belongs, or an identifier of a virtual port assigned to the first virtual instance; A first determining module, configured to determine a target inlet speed limit value according to attribute information related to the first virtual instance; The first flow control module is used to perform flow control on the first superposition message according to the target inlet rate limit value.
10. The switch according to claim 9, characterized in that: The switch stores a first mapping relationship, the first mapping relationship including a plurality of reference inlet rate limit values and reference attribute information respectively corresponding to the plurality of reference inlet rate limit values, each reference attribute information being related to at least one virtual instance among the plurality of virtual instances running on the first server; The target inlet speed limit value is one of the multiple reference inlet speed limit values, and the attribute information related to the first virtual instance matches the reference attribute information corresponding to the target inlet speed limit value in the first mapping relationship.
11. The switch according to claim 10, characterized in that: The first data center further includes a control node; the switch further includes: The second receiving module is configured to receive ingress rate limit configuration information sent by the control node, where the ingress rate limit configuration information includes the first mapping relationship.
12. The switch according to claim 10 or 11, characterized in that: Each reference inlet speed limit value is related to virtual instance performance information and network card bandwidth information, the virtual instance performance information is performance information of the virtual instance related to the reference attribute information corresponding to each reference inlet speed limit value, and the network card bandwidth information is bandwidth information of the physical network card on the switch connected to the first server.
13. The switch according to any one of claims 9 to 12, characterized in that: The switch also includes: a third receiving module, configured to receive a second superposition message, wherein the second superposition message includes a second inner message and a second outer message header, wherein the second inner message is a message sent by the first virtual instance to a third virtual instance, and the second outer message header carries attribute information related to the third virtual instance, wherein the third virtual instance is set in a fourth server of the plurality of servers, or in a fifth server of a third data center providing cloud services, wherein the attribute information related to the third virtual instance includes a tenant identifier to which the third virtual instance belongs, or an identifier of a virtual port assigned to the third virtual instance; A second determination module, configured to determine a target exit speed limit value according to attribute information related to the third virtual instance; The second flow control module is used to perform flow control on the second superposition message according to the target egress rate limit value.
14. The switch according to claim 13, characterized in that: The switch stores a second mapping relationship, wherein the second mapping relationship includes a plurality of reference export rate limit values and reference attribute information respectively corresponding to the plurality of reference export rate limit values; The target exit speed limit value is one of the multiple reference exit speed limit values, and the attribute information related to the third virtual instance matches the reference attribute information corresponding to the target exit speed limit value in the second mapping relationship.
15. The switch according to any one of claims 9 to 14, characterized in that: The first overlay message is a virtual extended local area network VXLAN message, the VXLAN message includes a VXLAN header, and the virtual extended local area network identifier VNI field in the VXLAN header is used to carry the tenant identifier to which the first virtual instance belongs; or, The first overlay message is a VXLAN-GPE message based on a general protocol extension of VXLAN, and the VXLAN-GPE message includes a GPE header, and the extension field in the GPE header is used to carry the identifier of the virtual port assigned to the first virtual instance.
16. The switch according to any one of claims 9 to 15, characterized in that: The first virtual instance includes a virtual machine or a container.
17. A switch, characterized in that: The switch includes a processor and a memory; The processor of the switch is used to execute instructions stored in the memory of the switch, so that the switch executes the method according to any one of claims 1-8.
18. A computer program product comprising instructions, characterized in that When the instruction is executed by the switch, the switch executes the method according to any one of claims 1 to 8.
19. A computer-readable storage medium, characterized in that: The method comprises computer program instructions. When the computer program instructions are executed by a switch, the switch executes the method according to any one of claims 1 to 8.