Data access method, micro-service architecture and flow monitoring method

By introducing proxy containers into the microservice architecture and using mapped addresses for data interaction recording, the problem of traffic governance in the Kubernetes host network is solved, and effective traffic monitoring of each container is achieved.

CN120238472APending Publication Date: 2025-07-01HUNAN FUMI INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202311870527.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2023-12-29
Publication Date
2025-07-01

AI Technical Summary

Technical Problem

In Kubernetes' host network, traffic control for each container cannot be performed because the containers in the host network are shared, and the service mesh cannot be used to monitor the traffic usage of each container.

Method used

A proxy container is introduced in the microservice architecture. By setting mapping addresses for access objects, data traffic records are realized during data interaction, data traffic records are generated for each container, and sent to the server for monitoring.

Benefits of technology

The traffic monitoring of each container in the Kubernetes host network is realized, the problem of traffic control cannot be carried out, and the efficiency and accuracy of traffic monitoring are improved.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120238472A_ABST
    Figure CN120238472A_ABST
Patent Text Reader

Abstract

The invention discloses a data access method, a micro-service architecture and a flow monitoring method, the data access method is applied to a proxy container in the micro-service architecture, and because the micro-service architecture comprises the proxy container set for a plurality of containers, each container can access the proxy container in the process of data interaction with other applications. The access object is accessed through the mapping address set by the proxy container for the access object and the proxy container, so that interaction data generated during data interaction is input and output through the proxy container; according to the invention, the server can monitor the flow of each container according to the data flow record of each container generated by the proxy container based on the interaction data generated when each container interacts with other access objects, and the problem that the flow of each container in a k8s host network cannot be controlled is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to the technical field of data processing, and more particularly to a data access method, a microservices architecture, and a traffic monitoring method. Background Art

[0002] A main requirement for traffic governance of each container in a microservices architecture is to be able to observe and monitor the traffic usage of each container. However, for the host network of k8s (Kubernetes, application software), since the containers in the host network share the same network, it is not possible to use a service mesh to monitor the traffic usage of each container, so it is impossible to implement traffic governance for each container in the host network. Summary of the Invention

[0003] In view of the above-mentioned defects or deficiencies in the prior art, it is desirable to provide a method for traffic governance of each container in a host network.

[0004] In a first aspect, a data access method is provided, which is applied to a proxy container of a microservices architecture. The microservices architecture includes a plurality of containers and proxy containers for the plurality of containers. The method includes:

[0005] Receiving a data interaction request related to each of the containers, the data interaction request carrying a mapping address set by the proxy container for the access object;

[0006] Determining the real address of the access object based on the mapping address, accessing the access object according to the real address, and obtaining interaction data corresponding to the data interaction request;

[0007] Generating a data traffic record for each of the containers based on the interaction data related to each of the containers, and sending the data traffic records of each of the containers to a server.

[0008] In a second aspect, a microservices architecture is provided. The architecture includes a plurality of containers and proxy containers.

[0009] The containers are used to send data interaction requests to the proxy container, and the data interaction requests carry a mapping address set by the proxy container for the access object;

[0010] The proxy container is used to determine the real address of the access object based on the mapping address, access the access object according to the real address, obtain interaction data corresponding to the data interaction request; generate a data traffic record for each of the containers based on the interaction data related to each of the containers, and send the data traffic records of each of the containers to a server.

[0011] In a third aspect, a traffic monitoring method is provided, which is applied to a service device. The method includes:

[0012] In response to obtaining the traffic usage of the target container within the target time period, obtain the total traffic data for the target time period from the data traffic records of the proxy container in the microservices architecture, where the data traffic records are generated by the proxy container based on the interaction data obtained when each container passes through the proxy container for data;

[0013] Filter the traffic data corresponding to the target container from the total traffic data according to the unique identifier of the target container.

[0014] A fourth aspect provides a service device, including a memory and a processor, where the memory stores a computer program, and when the processor executes the computer program, the steps of the method in the third aspect are implemented.

[0015] A fifth aspect provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the method in the third aspect are implemented.

[0016] This application provides a data access method, a microservices architecture, and a traffic monitoring method. The data access method is applied to the proxy container in the microservices architecture. Since the microservices architecture includes proxy containers set for multiple containers, when each container conducts data interaction with other applications, it accesses the access object through the mapped address set by the proxy container for the access object and the proxy container, so that the interaction data generated during data interaction enters and exits through the proxy container, facilitating the server to implement traffic monitoring of each container based on the data traffic records of each container generated by the proxy container based on the interaction data generated when each container interacts with other access objects, and solving the problem of being unable to manage the traffic of each container in the host network of k8s. BRIEF DESCRIPTION OF THE DRAWINGS

[0017] By reading the detailed description of the non-limiting embodiments with reference to the following drawings, other features, objectives, and advantages of this application will become more apparent:

[0018] Figure 1 A schematic structural diagram of a microservices architecture in an embodiment;

[0019] Figure 2 A schematic flowchart of a data interaction method in an embodiment;

[0020] Figure 3 A schematic flowchart of another data interaction method in an embodiment;

[0021] Figure 4 A schematic flowchart of yet another data interaction method in an embodiment;

[0022] Figure 5 Flow schematic diagram of another data interaction method in an embodiment;

[0023] Figure 6 Application scenario diagram of a data interaction method in an embodiment;

[0024] Figure 7 Internal structure diagram of the server in an embodiment. Detailed implementation manners

[0025] The present application will be further described in detail below with reference to the accompanying drawings and embodiments. It can be understood that the specific embodiments described herein are only used to explain the related invention, rather than limiting the invention. In addition, it should be noted that for the sake of description, only the parts related to the invention are shown in the drawings.

[0026] It should be noted that, without conflict, the embodiments in the present application and the features in the embodiments can be combined with each other. The present application will be described in detail below with reference to the drawings and embodiments.

[0027] Please refer to Figure 1 , Figure 1 A microservice architecture provided by the present application, as Figure 1 shown, the microservice architecture includes multiple Nodes (nodes), multiple Pods (containers) corresponding to the multiple Nodes, and one Proxy Pod (proxy container) corresponding to each container.

[0028] Among them, a Node refers to a computer or other device connected to a network with an independent address and having the function of transmitting or receiving data. A Node can be a workstation, a client, a network user, a personal computer, a server, a printer, and other devices with network connections. The role of a Node is to be responsible for sending, receiving, forwarding, store-and-forwarding, path selection, etc. of information in the network.

[0029] A Pod is the smallest unit of k8s, which encapsulates at least one container. Each Pod will be assigned a unique IP address. If multiple containers are encapsulated in a Pod, then the multiple containers share an IP address and network ports. It can be understood that all containers in the Pod can access the shared storage volume, and the containers share data.

[0030] The Proxy Pod is deployed based on the daemon set, and it can pass the interaction data between each container and the middleware in the microservice architecture in and out through the Proxy Pod, so as to perform traffic governance on each container in the microservice architecture.

[0031] The creation process of the microservice architecture will be described below:

[0032] As Figure 2 shown, it includes the following steps:

[0033] Step S201, deploy multiple containers for each node based on the host network of k8s;

[0034] Among them, the microservice architecture is an architecture built based on the k8s host network. The microservice architecture includes multiple Nodes, at least one Pod is deployed corresponding to each Node, and each Pod includes at least containers. Generally, multiple Pods will be deployed for each Node, and this application does not limit this. Each Node is responsible for running and managing multiple Pods set corresponding to it, and it can provide host and network resources for each Pod and the containers in each Pod set corresponding to it, enabling the Pod to run and the Pod to communicate with middleware (such as a data storage system). Each Node is also responsible for monitoring the health status of each Pod set corresponding to it and handling events and failures of each Pod.

[0035] When creating a Pod, the k8s scheduler will select a suitable Node to run the Pod. After the containers in the Pod are scheduled to a specific Node, they are created and run on that Node. If the Node where a Pod is located fails or becomes unavailable, the k8s scheduler will automatically schedule the Pod to another available Node to continue running. When the Pod is no longer needed, the Pod can be destroyed by deleting the Pod object, the resources will be released, and the containers in the Pod will stop running.

[0036] Step S202, deploy a proxy container for the multiple containers corresponding to each node;

[0037] Among them, the Proxy Pod is deployed based on the daemon set. One Proxy Pod can be deployed for the multiple containers in each microservice architecture, so that all the interaction data generated when the multiple containers interact with the middleware can pass through the Proxy Pod, so that the Proxy Pod can monitor the traffic of the containers in each Pod.

[0038] Step S203, perform traffic recording related settings on the proxy container to obtain the target microservice architecture.

[0039] Among them, after deploying the Proxy Pod for the multiple containers, in order to make all the interaction data generated when the multiple containers interact with other middleware pass through the Proxy Pod, traffic recording related settings need to be performed on the Proxy Pod to change the existing interaction method between the containers and the middleware, and realize the monitoring of the container traffic usage by the Proxy Pod.

[0040] In an optional embodiment, the traffic-related settings for the proxy container include the following setting process:

[0041] Set the query permissions for the proxy container based on the first parameter and the second parameter. The first parameter is used to define the use of the host's PID namespace by the proxy container; the second parameter is used to define the set of operations and permissions allowed for the proxy container;

[0042] Among them, when the Proxy Pod performs traffic recording-related settings, it needs to query Pods or other applications, such as address queries, process queries, property data queries, etc., and needs to apply to the infrastructure for corresponding query permissions in order to perform relevant settings and subsequent traffic monitoring-related operations.

[0043] Exemplarily, after the Proxy Pod obtains the query permission, when a Pod accesses the Proxy Pod, the Pod acts as a client and will establish a connection with the Proxy Pod using a random port. The Proxy Pod can query the process pid corresponding to the random port based on the information of all processes on the Node, and further obtain the environment variables of the Pod based on the pid. When the Pod is deployed, the basic information of the Pod is set through specific environment variables. For example, spring.appplication.name is a standard environment variable in the Java microservice framework used to set the Pod service name. Therefore, on the same Node, when each application Pod accesses the Proxy Pod, the Proxy Pod can identify the identity of the downstream. For performance considerations, the relationship between the random port and the downstream identity must be maintained through in-memory caching.

[0044] Obtain the access addresses of the access objects having an interaction relationship with each container and the access addresses of each container, perform address conversion on the access addresses of each access object and each container, obtain the mapped addresses of each access object and each container on the proxy container, and store them.

[0045] Among them, in order to enable the containers in the Pod to exchange data with the middleware through the Proxy Pod, it is necessary to perform address conversion on the access addresses of the access objects (i.e., middleware) having an interaction relationship with each container and the access addresses of each container, and obtain the mapped addresses of each access object and each container on the proxy container.

[0046] In another embodiment, after the Proxy Pod performs address translation on the access addresses of each container and the access objects that have an interaction relationship with each container, a correspondence between the mapped address and the access address can be generated and stored in the corresponding memory address, so that subsequently, after receiving an access request sent by each container or an access object that has an interaction relationship with each container, the real address of each container or an access object that has an interaction relationship with each container can be determined based on the correspondence, and the access object can be accessed through the real address.

[0047] In yet another alternative embodiment, in order to enable the containers within the Pod and the access objects that have an interaction relationship with the containers within the Pod to perform data interaction through the Proxy Pod, after the Proxy Pod performs address translation, it is necessary to expose the mapped addresses of the containers within each Pod and the access objects that have an interaction relationship with the containers within the Pod on the Proxy Pod to each container and the access objects that have an interaction relationship with the containers, so that all data in and out of each container and the access objects that have an interaction relationship with each container pass through the Proxy Pod.

[0048] Exemplarily, the address for a container to access the Redis cluster is redis-cluster-a:6379. The Proxy Pod converts the Redis cluster address redis-cluster-a:6379 to 0.0.0.0:16379. Then the container can send an access request carrying 0.0.0.0:16379 to the ProxyPod. The Proxy Pod, through the configuration data, proxies the downstream request for 0.0.0.0:16379 to redis-cluster-a:6379, so as to access the Redis cluster with the real address of redis-cluster-a:6379 through the Proxy Pod.

[0049] Set the access protocols of the proxy container with each access object and each container according to the preset master-slave node information and the topological relationship of the k8s cluster.

[0050] Among them, when the Proxy Pod accesses the backend middleware, it internally parses the access protocol of the middleware. For example, the master-slave node information and the topological relationship of the cluster defined in the protocol can ensure that the Proxy Pod correctly conducts business requests with the Pod or the middleware. Based on the parsed protocol and combined with the perception of the downstream identity, the Proxy Pod realizes the monitoring of the traffic usage of each container within the Pod. For example, the Proxy Pod can monitor the read-write request ratio, access traffic size, instructions, and the size relationship of the corresponding packet bodies of each container. All the observed data can be written into Prometheus, so as to conditionally develop richer monitoring functions.

[0051] After constructing the microservice architecture based on the above method, as Figure 3 shown, Figure 3 A data access method provided by an exemplary embodiment of the present application. Taking the application of this data access method to the proxy container in the above microservice architecture as an example, the steps of this method are described as follows:

[0052] Step S301: Receive data interaction requests related to each container. The data interaction request carries the mapping address set by the proxy container for the access object.

[0053] Among them, the data interaction request includes the first request sent by the container to the middleware and / or the second request sent by the middleware to the container. That is, the proxy container can receive the first request from the container to access the middleware. Exemplarily, container A sends a request to access middleware B to the proxy container. It can be understood that the proxy container can receive the second request from the middleware to access the container. Exemplarily, middleware A sends a request to access container B to the proxy container. Therefore, the containers in the microservice architecture can be the initiators of the access or the objects of the access. The present application does not limit this. However, it should be noted here that whether the container is the initiator or the object of the access, data related to the container will be generated and the traffic of the container will be used, so traffic monitoring is required.

[0054] According to the above description of setting the address for the Proxy Pod, if container A wants to access middleware B, it needs to send an access request to the corresponding interface of the Proxy Pod and carry the mapping address set by the proxy container for middleware B in the access request. In this way, when the Proxy Pod receives the access request sent by container A, it can determine the object that container A needs to access according to the address carried in the access request.

[0055] In an optional embodiment, the container may store the mapping address of the access object with which it has an interaction relationship. Before the container performs data access, it may query the mapping address of the access object to be accessed from the corresponding memory address and encapsulate it in the access request, and send it to the Proxy Pod through the network.

[0056] Step S302: Determine the real address of the access object based on the mapping address, access the access object according to the real address, and obtain the interaction data corresponding to the data interaction request.

[0057] Among them, the real address is the address through which a connection can be established with the access object, the access request can be conveyed to the access object, and the required data can be obtained from the access object. After receiving the data interaction request, the Proxy Pod can perform operations such as decompressing and decrypting the data interaction request to obtain the mapped address of the access object carried in the data interaction request, and then can convert the mapped address according to the preset conversion rules to obtain the real address of the access object; it can also perform address restoration processing on the mapped address based on the mapping rules to obtain the real address of the access object, etc. This application does not limit this.

[0058] In an optional embodiment, as Figure 4 shown, Figure 4 This is an optional embodiment for the proxy container provided by an exemplary embodiment of this application to determine the real address of the access object. This embodiment includes the following steps:

[0059] Step S401: Match the mapped address with the corresponding relationship information to obtain the initial address. The corresponding relationship information includes the access addresses of multiple access objects and the mapped addresses corresponding to the access addresses of each access object;

[0060] Among them, the corresponding relationship information is the information stored in the corresponding memory when the Proxy Pod performs traffic record-related settings, specifically after the address conversion operation. The corresponding relationship information includes the access addresses of multiple containers and the access objects having an interaction relationship with the multiple containers, as well as the mapped addresses corresponding to each access address.

[0061] Exemplarily, the corresponding relationship information is:

[0062]

[0063] It can be understood that after the Proxy Pod obtains the mapped address, it can read the corresponding relationship information from the corresponding memory address, match the mapped address with the corresponding relationship information, so as to obtain the access address of the access object, that is, the initial address.

[0064] Here, it should be noted the difference between the access address and the real address. The access address can be the real address of the access object, or it can be the abstracted address after abstracting the real address of the access object. The abstracted address is equivalent to a large-range address for accessing the access object and is not an accurate address. Therefore, the abstracted address cannot directly access the access object and other methods of parsing are required to obtain the real address of the access object. If the access address is not the abstracted address, it can be used as the real address of the access object to access the access object.

[0065] This application matches the mapped address by setting correspondence information, can quickly obtain the address of the access object before conversion, does not require other operations such as calculation and processing of the address, and can improve the efficiency of data interaction.

[0066] Step S402, determine whether the initial address is an abstract address; if so, execute step S403; if not, execute step S404;

[0067] Among them, based on the above explanation of the abstract address, it can be to perform processing such as parsing, decrypting, disassembling, decompressing, etc. on the initial address after obtaining the initial address, to determine whether there is a hidden address below the initial address. If there is, determine that the initial address is an abstract address. If not, determine that the initial address is not an abstract address.

[0068] Step S403, perform concretization processing on the abstract address based on the access protocol between the proxy container and the access object to obtain the real address of the access object;

[0069] Among them, when the proxy container performs traffic record-related settings, based on the setting of query permissions, it can obtain information such as the address and access protocol of the access object. Since the access protocol can record the method of how to access the access object, and this method can also record information such as the real address, access address, and abstract address of the access object, the proxy container can, in the case of determining that the initial address is an abstract address, perform concretization processing on the abstract address according to the access protocol to obtain the real address of the access object.

[0070] Step S404, determine the initial address as the real address of the access object.

[0071] It can be understood that if the initial address is not an abstract address, then the initial address is the real address of the access object and no other processing is required.

[0072] This application processes the mapped address to obtain the initial address, and further determines whether the initial address is an abstract address, so as to more accurately obtain the real address of the access object, improve the accuracy and efficiency of access, and avoid the situation where the access object cannot be accessed directly according to the initial address, resulting in the inability to obtain the required data and causing the interaction to fail.

[0073] Step S303, generate data traffic records for each container based on the interaction data related to each container, and send the data traffic records of each container to the server.

[0074] Among them, the purpose of this application is to be able to monitor the traffic of Pods in a microservices architecture based on the host network. The traffic monitoring is achieved through Proxy Pods. Specifically, the Proxy Pods generate data traffic records for each container based on the interaction data related to each container to record the traffic usage of each Pod. With these records, it is convenient for other devices that need to monitor the Pods to view.

[0075] The data traffic records can record data such as the read / write request ratio, access traffic size, instructions, and the size relationship of the corresponding packet bodies of each container. The monitoring device can accurately obtain the traffic usage of each container based on the data recorded in the data traffic records to achieve traffic monitoring of each container.

[0076] In an optional embodiment, when generating data traffic records, the Proxy Pods can record data traffic according to each container, that is, set corresponding data traffic records for each container. This recording method can facilitate more targeted queries by the monitoring device.

[0077] In another embodiment, when generating data traffic records, the Proxy Pods can record the total traffic within each preset time period according to time, not limited to each container, but the traffic records of all containers within that time period. This recording method is more convenient and can improve the efficiency of generating data traffic records.

[0078] After generating the data traffic records, the Proxy Pods can be stored separately according to each container, or can be stored separately according to different time periods. This application does not limit this.

[0079] After generating the data traffic records, the Proxy Pods can send the data traffic records to the server in real time; after generating the data traffic records, the Proxy Pods can also send the data traffic records to the server when reaching the preset sending time point according to the sending rules; after generating the data traffic records, the Proxy Pods can also send the data traffic records to the server in a targeted manner according to the request requirements when the server sends a fetch request. This application does not limit this.

[0080] The proxy containers in this application generate data traffic records for each container based on the interaction data related to each container, so that the server can monitor the traffic of each container, thereby realizing traffic monitoring of each container in the host network mode, and solving the problem of being unable to manage the traffic of each container in the host network of k8s.

[0081] After constructing the microservices architecture based on the above method, as Figure 5 shown, Figure 5Another data access method provided for an exemplary embodiment of the present application. Taking the application of this data access method to a server as an example, the steps of this method are described as follows:

[0082] Step S501: In response to obtaining the traffic usage of the target container within the target time period, obtain the total traffic data for the target time period from the data traffic records of the proxy container in the microservice architecture. The data traffic records are generated by the proxy container based on the interaction data obtained when each container passes through the proxy container for data;

[0083] Among them, the target container can be any container in the microservice architecture, and the target time period can be several hours, one week, one month, one year, etc. Since the proxy container in the microservice architecture generates corresponding data traffic records according to the interaction data generated during the data interaction of each container, when the server needs to monitor the traffic of the containers in the microservice architecture, it can directly request the proxy container to obtain the corresponding data traffic records.

[0084] Step S502: Screen the traffic data corresponding to the target container from the total traffic data according to the unique identifier of the target container.

[0085] Based on the above description, the proxy container can generate the total traffic data of all containers within the corresponding time period according to time. Therefore, after receiving the acquisition request sent by the server, the proxy container sends the data traffic record corresponding to the total traffic data of the target time period requested by the server to the server through the network. Then, if the server wants the traffic data of the target container, it can, after receiving the data traffic record sent by the proxy container, screen the data traffic record through the unique identifier of the target container to obtain the traffic data corresponding to the target container.

[0086] Next, based on the steps performed by the above server and proxy container for the data access method, combined with Figure 6 , an exemplary embodiment of the overall interaction is provided. This exemplary embodiment includes the following steps:

[0087] Step S601: In the first time period, container A sent 20 access requests to the proxy container, container B sent 30 access requests to the proxy container, container C sent 40 access requests to the proxy container, and container D sent 50 access requests to the proxy container;

[0088] Step S602: The proxy container receives the access requests sent by container A, container B, container C, and container D in the first time period, and parses them in sequence according to the time sequence of each access request to obtain the mapping addresses carried by each access request;

[0089] Step S603: The proxy container obtains the correspondence information from the memory address, and sequentially matches each mapped address with the correspondence information to obtain a corresponding plurality of initial addresses;

[0090] Step S604: Assume that the plurality of initial addresses are all real addresses, and then use the plurality of initial addresses as real addresses to access the corresponding access objects;

[0091] Step S605: Each access object returns the data corresponding to each access request to the proxy container based on each access request;

[0092] Step S606: The proxy container generates a data traffic record for the first time period according to the data corresponding to each access request;

[0093] Step S607: The proxy container sends the data traffic record for the first time period to the server;

[0094] Step S608: The server determines the traffic usage of Container A in the first time period according to the data traffic record for the first time period and the unique identifier of Container A.

[0095] It can be understood that the server may include a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the following operations are implemented:

[0096] In response to obtaining the traffic usage of the target container in the target time period, obtain the total traffic data for the target time period from the data traffic record of the proxy container in the microservice architecture. The data traffic record is generated by the proxy container based on the interaction data obtained when each container passes through the proxy container for data;

[0097] Screen the traffic data corresponding to the target container from the total traffic data according to the unique identifier of the target container.

[0098] It should be noted that although the operations of the method of the present invention are described in a specific order in the drawings, this does not require or imply that these operations must be performed in this specific order, or that all the operations shown must be performed to achieve the desired result. On the contrary, the steps depicted in the flowchart may be changed in the order of execution.

[0099] The following refers to Figure 7 which shows a schematic structural diagram of a computer system 700 of a server suitable for implementing the embodiments of the present application.

[0100] As Figure 7As shown, computer system 700 includes a central processing unit (CPU) 701, which can perform various appropriate actions and processes according to a program stored in a read-only memory (ROM) 702 or a program loaded from a storage section 708 into a random access memory (RAM) 703. In the RAM 703, various programs and data required for the operation of the system 700 are also stored. The CPU 701, ROM 702, and RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.

[0101] The following components are connected to the I / O interface 705: an input section 706 including a keyboard, a mouse, etc.; an output section 707 including, for example, a cathode ray tube (CRT), a liquid crystal display (LCD), etc., and a speaker, etc.; a storage section 708 including a hard disk, etc.; and a communication section 709 including a network interface card such as a LAN card, a modem, etc. The communication section 709 performs communication processing via a network such as the Internet. A drive 710 is also connected to the I / O interface 705 as needed. A removable medium 711, such as a magnetic disk, an optical disk, a magneto-optical disk, a semiconductor memory, etc., is installed on the drive 710 as needed so that a computer program read from it can be installed into the storage section 708 as needed.

[0102] In particular, according to an embodiment of the present disclosure, the process described above with reference to Figure 5 can be implemented as a computer software program. For example, an embodiment of the present disclosure includes a computer program product, which includes a computer program tangibly embodied on a machine-readable medium, the computer program including program code for performing Figure 5 the method. In such an embodiment, the computer program can be downloaded and installed from a network via the communication section 709, and / or installed from the removable medium 711.

[0103] The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each box in the flowchart or block diagram may represent a module, a segment of a program, or a portion of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions marked in the boxes may occur in a different order than that marked in the accompanying drawings. For example, two consecutive boxes shown may actually be executed substantially in parallel, and they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flowchart, as well as combinations of boxes in the block diagram and / or flowchart, can be implemented by a dedicated hardware-based system that performs the specified functions or operations, or can be implemented by a combination of dedicated hardware and computer instructions.

[0104] The units or modules described in the embodiments of the present application can be implemented in software or in hardware. The described units or modules can also be provided in a processor. For example, it can be described as: a processor includes XX unit, YY unit, and ZZ unit. Among them, the names of these units or modules do not constitute a limitation to the unit or module itself in some cases. For example, the XX unit can also be described as "the unit for XX".

[0105] As another aspect, the present application also provides a computer-readable storage medium. The computer-readable storage medium can be the computer-readable storage medium included in the device described in the above embodiments; or it can exist separately and be a computer-readable storage medium not assembled into the device. The computer-readable storage medium stores one or more programs, and the one or more programs are used by one or more processors to execute the formula input method described in the present application.

[0106] The above description is only a preferred embodiment of the present application and an explanation of the applied technical principles. Those skilled in the art should understand that the scope of the invention involved in the present application is not limited to the technical solution formed by the specific combination of the above technical features, and should also cover other technical solutions formed by any combination of the above technical features or their equivalent features without departing from the inventive concept. For example, the technical solutions formed by mutually replacing the above features with the (but not limited to) technical features with similar functions disclosed in the present application.

Claims

1. A data access method, characterized in that, A proxy container applied to a microservices architecture, where the microservices architecture includes multiple containers and proxy containers for the multiple containers, the method comprising: Receiving a data interaction request related to each of the containers, the data interaction request carrying a mapping address set by the proxy container for an access object; Determining a real address of the access object based on the mapping address, accessing the access object according to the real address, and obtaining interaction data corresponding to the data interaction request; Generating a data traffic record for each of the containers based on the interaction data related to each of the containers, and sending the data traffic records of each of the containers to a server.

2. The access method according to claim 1, characterized in that, The determining the real address of the access object based on the mapping address includes: Matching the mapping address with corresponding relationship information to obtain an initial address, the corresponding relationship information including access addresses of multiple access objects and mapping addresses corresponding to the access addresses of each of the access objects; Determining whether the initial address is an abstract address; If so, performing a concretization process on the abstract address based on an access protocol between the proxy container and the access object to obtain the real address of the access object; If not, determining the initial address as the real address of the access object.

3. The access method according to claim 1, characterized in that, The data interaction request includes a first request sent by the container to a middleware and / or a second request sent by the middleware to the container.

4. A microservices architecture, characterized in that, The architecture includes multiple containers and proxy containers, The container is configured to send a data interaction request to the proxy container, the data interaction request carrying a mapping address set by the proxy container for an access object; The proxy container is configured to determine a real address of the access object based on the mapping address, access the access object according to the real address, obtain interaction data corresponding to the data interaction request; generate a data traffic record for each of the containers based on the interaction data related to each of the containers, and send the data traffic records of each of the containers to a server.

5. The architecture according to claim 4, wherein The proxy container is specifically configured to match the mapping address with corresponding relationship information to obtain an initial address, the corresponding relationship information including access addresses of multiple access objects and mapping addresses corresponding to the access addresses of each of the access objects; Determining whether the initial address is an abstract address; If so, performing a concretization process on the abstract address based on an access protocol between the proxy container and the access object to obtain the real address of the access object; If not, determining the initial address as the real address of the access object.

6. The architecture according to claim 4, characterized in that, The creation process of the microservices architecture includes: Deploying multiple containers for each node based on the host network of k8s; Deploying a proxy container for the multiple containers corresponding to each of the nodes; Performing traffic record related settings on the proxy container to obtain a target microservices architecture.

7. The architecture according to claim 6, characterized in that, The traffic record related settings include: Set query permissions for the proxy container based on a first parameter and a second parameter, where the first parameter is used to define the use of the host's PID namespace by the proxy container; the second parameter is used to define a set of operations and permissions allowed for the proxy container. Obtain the access addresses of access objects that have an interaction relationship with each of the containers and the access addresses of each of the containers, perform address conversion on the access addresses of each of the access objects and each of the containers, obtain the mapped addresses of each of the access objects and each of the containers on the proxy container, and store them. Set the access protocols between the proxy container and each of the access objects and each of the containers according to the preset master-slave node information and the topological relationship of the k8s cluster.

8. A data access method, characterized in that, Applied to a server, the method includes: In response to obtaining the traffic usage of a target container within a target time period, obtain the total traffic data for the target time period from the data traffic records of the proxy container in the microservice architecture, where the data traffic records are generated from interaction data obtained by the proxy container based on data passing through the proxy container by each of the containers. Filter the traffic data corresponding to the target container from the total traffic data according to the unique identifier of the target container.

9. A server, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, it implements the steps of the method recited in claim 8.

10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, it implements the steps of the method recited in the claim.