Container flow transmission method, container system, computer equipment and storage medium
By introducing a domain name resolution module into the container system, it is determined whether to intercept traffic to the sidecar container for service governance based on the domain name address, which solves the problem of low service governance efficiency in the microservice system, and realizes accurate interception and transmission of traffic, improving system efficiency.
Patent Information
- Application Number
- CN202311870065.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2023-12-30
- Publication Date
- 2025-07-01
AI Technical Summary
In the prior art, the problem of low service governance efficiency in microservice systems, especially when the service governance logic is deployed in the sidecar of the business container, the full traffic entering and leaving the business container is intercepted, resulting in traffic that does not require service governance also participates in the service governance process, affecting efficiency.
By introducing a domain name resolution module in the container system, the current domain name of the traffic is determined first and the domain name address is resolved. If it is equal to the preset target address, it will be intercepted to the sidecar container for verification. Otherwise, it will be directly transmitted to the target container to achieve accurate interception and transmission of traffic.
It improves the efficiency of service governance, avoids traffic that does not require service governance to be intercepted, reduces performance losses, and improves the overall performance of the microservice system.
Smart Images

Figure CN120238515A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the field of microservice technology, and in particular to a container traffic transmission method, a container system, a computer device, and a storage medium. Background Art
[0002] With the development of microservice technology, in order to decouple the service governance logic from the business code logic, when the service governance logic is currently deployed in the sidecar of the business container, all traffic in and out of the business container is intercepted by the sidecar, and then the service governance process can be implemented in the sidecar. This processing method has the problem of low service governance efficiency. Summary of the invention
[0003] Based on this, it is necessary to provide a container traffic transmission method, container system, computer device and computer-readable storage medium that can improve service governance efficiency in response to the above technical problems.
[0004] In a first aspect, the present application provides a container traffic transmission method, which is applied to a container system, wherein the container system includes a first business container, a first sidecar container of the first business container, and a domain name resolution module. The method includes:
[0005] The first business container determines the current domain name of the outgoing traffic; the domain name resolution module resolves the current domain name to obtain a domain name resolution address, and feeds back the domain name resolution address to the first business container; if the domain name resolution address is equal to a preset target address, the first business container sends the outgoing traffic to the first sidecar container according to the preset target address, wherein the first sidecar container is used to verify the outgoing traffic and forward the outgoing traffic to the second business container after the verification is successful; if the domain name resolution address is not equal to the preset target address, the first business container directly transmits the outgoing traffic to the second business container according to the domain name resolution address.
[0006] In one embodiment, the domain name resolution module includes a firewall module and a second sidecar container of the first business container; the domain name resolution module resolves the current domain name to obtain a domain name resolution address, including:
[0007] The firewall module intercepts the domain name resolution request of the first business container and redirects the domain name resolution request to the second sidecar container, wherein the domain name resolution request includes the current domain name of the outgoing traffic; the second sidecar container resolves the current domain name to obtain a domain name resolution address.
[0008] In one embodiment, resolving the current domain name to obtain a domain name resolution address includes:
[0009] Determine the traffic verification attribute of the current domain name; if the traffic verification attribute indicates that the current domain name needs to be traffic verified, resolve the current domain name to a preset target address; if the traffic verification attribute indicates that the current domain name does not need to be traffic verified, resolve the current domain name to a corresponding transmission target address.
[0010] In one embodiment, the first service container sends the outgoing traffic to the first sidecar container according to the preset target address, including:
[0011] The first business container generates a traffic sending request according to the preset target address and the outgoing traffic; the first business container sends the traffic sending request to the firewall module according to the preset target address; the firewall module redirects the traffic sending request to the first side car container, wherein the first side car container is used to parse the traffic sending request into the outgoing traffic.
[0012] In one of the embodiments, after the first service container sends the outgoing traffic to the first sidecar container according to the preset target address, the method further includes:
[0013] If the outgoing flow fails the flow verification, the first sidecar container intercepts the outgoing flow.
[0014] In one embodiment, the domain name resolution module includes a firewall module; the method further includes:
[0015] The firewall module determines a current target port of the incoming traffic; if the current target port is a preset port that requires traffic verification, the firewall module redirects the incoming traffic to the first sidecar container, wherein the first sidecar container is used to verify the incoming traffic and forward the incoming traffic to the first business container after the verification is successful; if the current target port is a preset port that does not require traffic verification, the firewall module transmits the incoming traffic to the first business container.
[0016] In one of the embodiments, after the firewall module redirects the incoming traffic to the first sidecar container, the method further includes:
[0017] If the incoming flow fails the flow verification, the first sidecar container intercepts the incoming flow.
[0018] In a second aspect, the present application further provides a container system. The container system includes a first business container, a first sidecar container of the first business container, and a domain name resolution module;
[0019] The first service container is used to determine the current domain name of the outgoing traffic;
[0020] The domain name resolution module is used to resolve the current domain name, obtain a domain name resolution address, and feed back the domain name resolution address to the first service container;
[0021] The first business container is further configured to, if the domain name resolution address is equal to the preset target address, send the outgoing traffic to the first sidecar container according to the preset target address, wherein the first sidecar container is configured to verify the outgoing traffic and forward the outgoing traffic to the second business container after successful verification; if the domain name resolution address is not equal to the preset target address, directly transmit the outgoing traffic to the second business container according to the domain name resolution address.
[0022] In a third aspect, the present application further provides a computer device applied to a container system, the container system comprising a first business container, a first sidecar container of the first business container, and a domain name resolution module. The computer device comprises a memory and a processor, the memory stores a computer program, and the processor implements the following steps when executing the computer program:
[0023] The first business container determines the current domain name of the outgoing traffic; the domain name resolution module resolves the current domain name to obtain a domain name resolution address, and feeds back the domain name resolution address to the first business container; if the domain name resolution address is equal to a preset target address, the first business container sends the outgoing traffic to the first sidecar container according to the preset target address, wherein the first sidecar container is used to verify the outgoing traffic and forward the outgoing traffic to the second business container after the verification is successful; if the domain name resolution address is not equal to the preset target address, the first business container directly transmits the outgoing traffic to the second business container according to the domain name resolution address.
[0024] In a fourth aspect, the present application further provides a computer-readable storage medium, applied to a container system, wherein the container system includes a first business container, a first sidecar container of the first business container, and a domain name resolution module. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the following steps are implemented:
[0025] The first business container determines the current domain name of the outgoing traffic; the domain name resolution module resolves the current domain name to obtain a domain name resolution address, and feeds back the domain name resolution address to the first business container; if the domain name resolution address is equal to a preset target address, the first business container sends the outgoing traffic to the first sidecar container according to the preset target address, wherein the first sidecar container is used to verify the outgoing traffic and forward the outgoing traffic to the second business container after the verification is successful; if the domain name resolution address is not equal to the preset target address, the first business container directly transmits the outgoing traffic to the second business container according to the domain name resolution address.
[0026] In a fifth aspect, the present application further provides a computer program product, which is applied to a container system, wherein the container system includes a first business container, a first sidecar container of the first business container, and a domain name resolution module. The computer program product includes a computer program, which, when executed by a processor, implements the following steps:
[0027] The first business container determines the current domain name of the outgoing traffic; the domain name resolution module resolves the current domain name to obtain a domain name resolution address, and feeds back the domain name resolution address to the first business container; if the domain name resolution address is equal to a preset target address, the first business container sends the outgoing traffic to the first sidecar container according to the preset target address, wherein the first sidecar container is used to verify the outgoing traffic and forward the outgoing traffic to the second business container after the verification is successful; if the domain name resolution address is not equal to the preset target address, the first business container directly transmits the outgoing traffic to the second business container according to the domain name resolution address.
[0028] In the above-mentioned container traffic transmission method, container system, computer device and storage medium, for the outgoing traffic of the first business container, the first business container will first determine the current domain name of the outgoing traffic, and then the domain name resolution module will resolve the current domain name to obtain the domain name resolution address, and feedback the domain name resolution address to the first business container. If the domain name resolution address is equal to the preset target address, it means that the outgoing traffic is the traffic that needs to be intercepted, so that the first business container can intercept the outgoing traffic to the first sidecar container of the first business container according to the preset target address. In this way, the outgoing traffic is verified in the first sidecar container, and after the verification is successful, the first sidecar container forwards the outgoing traffic to the second business container. If the domain name resolution address is not equal to the preset target address, it means that the outgoing traffic is not the outgoing traffic that needs to be intercepted, so that the first business container directly transmits the outgoing traffic to the second business container according to the domain name resolution address. In this way, the present application can accurately intercept the outgoing traffic that needs to be service-governed in the first business container and send it to the sidecar for service management, and directly release the outgoing traffic that does not need to be service-governed in the first business container to the second business container, avoiding the situation where all traffic is intercepted to the sidecar for service management, thereby improving the efficiency of service management. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] Figure 1 A schematic diagram of a flow chart of a container flow transmission method in one embodiment;
[0030] Figure 2 A schematic diagram of a process of performing domain name resolution in one embodiment;
[0031] Figure 3 A schematic diagram of a flow chart of inbound traffic transmission in one embodiment;
[0032] Figure 4 A schematic diagram of a visualization process of inflow transmission in another embodiment;
[0033] Figure 5 A schematic diagram of a visualized flow of outbound traffic transmission in another embodiment;
[0034] Figure 6 is a structural block diagram of a container system in one embodiment;
[0035] Figure 7 FIG. 4 is a diagram showing the internal structure of a computer device in one embodiment. DETAILED DESCRIPTION
[0036] In order to make the purpose, technical solution and advantages of the present application more clearly understood, the present application is further described in detail below in conjunction with the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0037] With the development of microservice technology, in order to decouple the service governance logic from the business code logic, when the service governance logic is currently deployed in the sidecar of the business container, all traffic in and out of the business container is intercepted by the sidecar, and then the service governance process can be implemented in the sidecar. However, not all traffic in and out of the business container needs to go through the service governance process, such as current limiting or fuse breaking, so after intercepting all traffic to the sidecar, some traffic that does not need to go through the service governance process will also enter the sidecar to participate in the service governance process, thereby affecting the efficiency of service governance.
[0038] In the present application, for the outgoing traffic of the first business container, the first business container will first determine the current domain name of the outgoing traffic, and then the domain name resolution module will resolve the current domain name to obtain the domain name resolution address, and feedback the domain name resolution address to the first business container. If the domain name resolution address is equal to the preset target address, it means that the outgoing traffic is the traffic that needs to be intercepted, so that the first business container can intercept the outgoing traffic to the first sidecar container of the first business container according to the preset target address. In this way, the outgoing traffic is verified in the first sidecar container, and after the verification is successful, the first sidecar container forwards the outgoing traffic to the second business container. If the domain name resolution address is not equal to the preset target address, it means that the outgoing traffic is not the outgoing traffic that needs to be intercepted, so the first business container directly transmits the outgoing traffic to the second business container according to the domain name resolution address. In this way, the outgoing traffic that needs to be service-governed (traffic verification) in the present application is accurately intercepted to the first sidecar container, and the outgoing traffic that does not need to be service-governed is directly directed to the second business container, avoiding the situation where the entire traffic is intercepted to the sidecar for service governance, thereby improving the efficiency of service governance.
[0039] In one embodiment, Figure 1 As shown, a container traffic transmission method is provided. This embodiment takes the method applied to a container system as an example for explanation. The container system includes a first business container, a first sidecar container of the first business container, and a domain name resolution module. In this embodiment, the method includes the following steps:
[0040] Step 202: The first service container determines the current domain name of the traffic.
[0041] The container system may be a microservice system, the first business container is a container in which the business code logic of the microservice is deployed, the current domain name is the domain name corresponding to the transmission target address of the outgoing traffic, and the transmission target address of the outgoing traffic can be obtained by resolving the current domain name normally; the outgoing traffic is the traffic requested to flow out of the first business container, for example, it can be data transmitted from the first business container to other business containers, etc.
[0042] Step 204: The domain name resolution module resolves the current domain name to obtain a domain name resolution address, and feeds back the domain name resolution address to the first service container.
[0043] Among them, the domain name resolution module will pre-save the domain name that needs to be verified for traffic as a preset domain name, so it can directly identify whether the current domain name is the preset domain name that needs to be verified for traffic; the domain name resolution address can be a preset target address or a transmission target address, wherein the preset target address can be the port address of the first sidecar container of the first business container, and the transmission target address can normally resolve the current domain name of the traffic to obtain the target port address.
[0044] As an example, step 204 includes: if the current domain name is a preset domain name that requires traffic verification, the domain name resolution module forcibly resolves the current domain name to a preset target address, and feeds back the preset target address as the domain name resolution address to the first business container; if the current domain name is a preset domain name that does not require traffic verification, the current domain name is resolved normally, and the transmission target address obtained by the normal resolution is fed back to the first business container as the domain name resolution address.
[0045] Step 206: If the domain name resolution address is equal to the preset target, the first business container sends the outgoing traffic to the first sidecar container according to the preset target address, wherein the first sidecar container is used to verify the outgoing traffic and forward the outgoing traffic to the second business container after the verification is successful.
[0046] Among them, the preset target address can be the port address of the first side car container, which is used to direct the outgoing traffic of the first business container to the first side car container; the service governance logic is deployed in the first side car container, which is used to perform traffic verification on the outgoing traffic directed to the first side car container, and forward the outgoing traffic to the second business container after the traffic verification is successful, or intercept the outgoing traffic after the traffic verification fails; the traffic verification can be a current limiting verification or a fuse verification, etc.
[0047] As an example, step 206 includes: if the domain name resolution address is equal to the preset target address, the first business container directly directs the outgoing traffic to the first sidecar container of the first business container according to the preset target address, wherein the first sidecar container is used to verify the outgoing traffic and forward the outgoing traffic to the second business container after the verification is successful, or intercept the outgoing traffic after the verification fails.
[0048] The container system further includes a firewall module, which may be iptables (IP packet filtering system) for setting, maintaining and checking IP packet filtering rules of the container system.
[0049] As an example, step 206 includes: if the domain name resolution address is equal to the preset target address, the first business container sends the outgoing traffic to the firewall module according to the preset target address; the firewall module redirects the outgoing traffic to the first sidecar container of the first business container, wherein the first sidecar container is used to verify the outgoing traffic and forward the outgoing traffic to the second business container after the verification is successful, or intercept the outgoing traffic after the verification fails.
[0050] In one embodiment, after the first service container sends the outgoing traffic to the first sidecar container according to the preset target address, the container traffic transmission method further includes:
[0051] The first sidecar container performs traffic verification on the outgoing traffic; if the outgoing traffic passes the traffic verification, the first sidecar container forwards the outgoing traffic to the second business container; if the outgoing traffic fails the traffic verification, the first sidecar container intercepts the outgoing traffic.
[0052] Among them, the service governance logic is set in the first sidecar container, and the service governance logic can be traffic verification logic or routing logic, etc. The traffic verification can be current limiting verification or fuse verification.
[0053] Specifically, the first sidecar container performs traffic verification on the outbound traffic of the first business container according to the set service governance logic; if the outbound traffic of the first business container passes the traffic verification, the first sidecar container forwards the outbound traffic of the first business container to the second business container; if the outbound traffic of the first business container fails the traffic verification, the first sidecar container intercepts the outbound traffic of the first business container.
[0054] Step 208: If the domain name resolution address is not equal to the preset target address, the first service container directly transmits the outgoing traffic to the second service container according to the domain name resolution address.
[0055] As an example, step 208 includes: if the domain name resolution address is not equal to the preset target address, it means that the domain name resolution address is a transmission target address obtained by normal resolution, and the first business container generates a traffic sending request based on the transmission target address and the outgoing traffic, and transmits the traffic sending request to the second business container, so that the second business container resolves the traffic sending request and obtains the outgoing traffic transmitted by the first business container.
[0056] In the above-mentioned container traffic transmission method, for the outgoing traffic of the first business container, the first business container will first determine the current domain name of the outgoing traffic, and then the domain name resolution module will resolve the current domain name to obtain the domain name resolution address, and feedback the domain name resolution address to the first business container. If the domain name resolution address is equal to the preset target address, it means that the outgoing traffic is the traffic that needs to be intercepted, so that the first business container can intercept the outgoing traffic to the first sidecar container of the first business container according to the preset target address. In this way, the outgoing traffic is verified in the first sidecar container, and after the verification is successful, the first sidecar container forwards the outgoing traffic to the second business container. If the domain name resolution address is not equal to the preset target address, it means that the outgoing traffic is not the outgoing traffic that needs to be intercepted, so the first business container directly transmits the outgoing traffic to the second business container according to the domain name resolution address. In this way, in this embodiment, the outgoing traffic that requires service governance (traffic verification) is accurately intercepted to the first sidecar container, while the outgoing traffic that does not require service governance is directly directed to the second business container. The outgoing traffic that requires service governance in the first business container can be accurately intercepted to the sidecar for service governance, and the outgoing traffic that does not require service governance in the first business container can be directly released to the second business container, avoiding the situation where all traffic is intercepted to the sidecar for service governance, thereby improving the efficiency of service governance and reducing the performance loss of the microservice system.
[0057] In one embodiment, Figure 2 As shown, the domain name resolution module includes a firewall module and a second sidecar container of the first business container; the domain name resolution module resolves the current domain name to obtain a domain name resolution address, including:
[0058] Step 302: The firewall module intercepts the domain name resolution request of the first business container and redirects the domain name resolution request to the second sidecar container, wherein the domain name resolution request includes the current domain name of the outgoing traffic.
[0059] Among them, a firewall module is provided in this embodiment, and a first firewall rule is provided in the firewall module. The first firewall rule is used to redirect the domain name resolution request sent by the hijacked first business container to the second sidecar container of the first business container; the second sidecar container is used to perform domain name resolution on the current domain name in the domain name resolution request.
[0060] As an example, step 302 includes: the firewall module intercepts the domain name resolution request sent by the first business container, and redirects the domain name resolution request to the second sidecar container of the first business container based on the set first firewall rule, wherein the domain name resolution request includes the current domain name of the outgoing traffic.
[0061] As an example, the first firewall rule may be an iptables rule, the domain name resolution request may be a Dns query request, and the second sidecar container acts as a Dns server.
[0062] Step 304: The second sidecar container resolves the current domain name to obtain a domain name resolution address.
[0063] As an example, step 304 includes: the second sidecar container extracts the current domain name of the traffic from the domain name resolution request, and identifies whether the current domain name is a preset domain name that requires traffic verification; if the current domain name is a preset domain name that requires traffic verification, the second sidecar container forces the current domain name to be resolved to a preset target address, and uses the preset target address as the domain name resolution address; if the current domain name is not a preset domain name that requires traffic verification, the second sidecar container resolves the current domain name normally, obtains the transmission target address, and uses the transmission target address as the domain name resolution address.
[0064] In this embodiment, the firewall module intercepts the domain name resolution request sent by the first business container, and redirects the domain name resolution request to the second sidecar container according to the set first firewall rule; the second sidecar container can resolve the current domain name of the outgoing traffic that needs to be verified to the preset target address, so that the outgoing traffic can be directed to the first sidecar container of the first business container based on the preset target address; the second sidecar container can also normally resolve the current domain name of the outgoing traffic that does not need to be verified to the transmission target address, so that the outgoing traffic can be directly transmitted to the second business container according to the transmission target address. Therefore, in this embodiment, by setting the first firewall rule in the firewall module to redirect the intercepted domain name resolution request to the second sidecar container, and setting the second sidecar container to resolve the current domain name in the domain name resolution request according to the situation, it is possible to accurately direct the outgoing traffic that needs to be verified to the first sidecar container, and directly direct the outgoing traffic that does not need to be verified to the second business container, laying the foundation for improving service governance efficiency.
[0065] In one embodiment, resolving the current domain name to obtain the domain name resolution address includes:
[0066] Determine the traffic verification attribute of the current domain name; if the traffic verification attribute indicates that the current domain name needs to be traffic verified, resolve the current domain name to the preset target address; if the traffic verification attribute indicates that the current domain name does not need to be traffic verified, resolve the current domain name to the corresponding transmission target address.
[0067] The flow verification attribute may be an identifier of the current domain name, which is used to identify whether the current domain name needs to be flow verified. For example, the flow verification attribute may be an annotation or a character label.
[0068] Specifically, if there is a domain name consistent with the current domain name among the preset domain names, it is determined that the traffic verification attribute of the current domain name indicates that the current domain name needs to be traffic verified, so that the current domain name is forcibly resolved to the preset target address, and the preset target address is used as the domain name resolution address; if there is no domain name consistent with the current domain name among the preset domain names, it is determined that the traffic verification attribute of the current domain name indicates that the current domain name does not need to be traffic verified, so that the current domain name is normally resolved to the transmission target address, and the transmission target address is used as the domain name resolution address.
[0069] In the above embodiment, a specific domain name resolution rule is set in the second side car container, which can forcibly resolve the current domain name that needs to be traffic verified to a preset target address. In this way, the outgoing traffic that needs to be traffic verified will be forcibly directed to the first side car container according to the preset target address. At the same time, the current domain name that does not need to be traffic verified can be normally resolved to the transmission target address. In this way, the outgoing traffic that does not need to be traffic verified will be normally directed to the second business container according to the transmission target address, thereby achieving the goal of accurately directing the outgoing traffic that needs to be traffic verified to the first side car container, and avoiding directing the outgoing traffic that does not need to be traffic verified to the first side car container.
[0070] In one embodiment, the first service container sends outgoing traffic to the first sidecar container according to a preset target address, including:
[0071] The first business container generates a traffic sending request according to the preset target address and outgoing traffic; the first business container sends the traffic sending request to the firewall module according to the preset target address; the firewall module redirects the traffic sending request to the first sidecar container, wherein the first sidecar container is used to parse the traffic sending request into outgoing traffic.
[0072] Among them, the preset target address can be a port address in the firewall module, and the firewall module is also provided with a second firewall rule, and the second firewall rule can redirect the traffic sending request transmitted to the preset target address to the first sidecar container.
[0073] Specifically, the first business container encapsulates the preset target address and outgoing traffic into a traffic sending request, and transmits the traffic sending request to the firewall module according to the preset target address; the firewall module redirects the traffic sending request to the first side car container according to the set second firewall rule; the first side car container parses the traffic sending request to obtain the outgoing traffic of the first business container.
[0074] As an example, the second firewall rule may be an iptables rule, the traffic sending request may be an HTTP request, the HTTP request includes TCP traffic, and the TCP traffic is the outgoing traffic of the first business container.
[0075] In the above embodiments, by setting the preset target address as the port address of the firewall module and setting the second firewall rule in the firewall module, the traffic sending request sent by the first service container can be directly redirected to the first sidecar container. After the first sidecar container parses the traffic sending request, the outgoing traffic that needs to be traffic-checked can be obtained. In this way, the outgoing traffic that needs to be traffic-checked is accurately directed to the first sidecar container of the first service container, laying a foundation for improving the service governance efficiency.
[0076] In one embodiment, referring to Figure 3 , the domain name resolution module includes a firewall module; the container traffic transmission method further includes:
[0077] Step 402, the firewall module determines the current target port of the incoming traffic.
[0078] Among them, the incoming traffic is the traffic that requests to enter the first service container, for example, it can be the traffic transmitted from other service containers to the first service container; the current target port is the service port that the incoming traffic needs to reach.
[0079] As an example, step 402 includes: if the firewall module detects the traffic request of the incoming traffic of the first service container, then parses the traffic request of the incoming traffic to obtain the current target port of the incoming traffic of the first service container.
[0080] Step 404, if the current target port is a preset port that needs to be traffic-checked, the firewall module redirects the incoming traffic to the first sidecar container, where the first sidecar container is used to check the incoming traffic and forward the incoming traffic to the first service container after successful check.
[0081] Step 406, if the current target port is a preset port that does not need to be traffic-checked, the firewall module transmits the incoming traffic to the first service container.
[0082] Among them, in the service container, traffic check is usually required for the incoming traffic related to the service process, while traffic check is usually not required for the incoming traffic unrelated to the service process. For example, for the TCP traffic of the middleware, traffic check does not need to be performed in the sidecar container of the service container.
[0083] As an example, steps 404 to 406 include: if the current target port is a preset port that needs to be traffic-checked, the firewall module redirects the incoming traffic to the first sidecar container of the first service container according to the set third firewall rule. The first sidecar container checks the incoming traffic. If the traffic check fails, the first sidecar container intercepts the incoming traffic; if the traffic check is successful, the first sidecar container transmits the incoming traffic to the firewall module; the firewall module forwards the incoming traffic transmitted by the first sidecar container to the first service container.
[0084] In one embodiment, after the firewall module redirects the incoming traffic to the first sidecar container, the container traffic transmission method further includes:
[0085] The first sidecar container performs traffic verification on the incoming traffic of the first business container; if the incoming traffic passes the traffic verification, the first sidecar container forwards the incoming traffic to the first business container; if the incoming traffic fails the traffic verification, the first sidecar container intercepts the incoming traffic.
[0086] Wherein, the current target port is the target port for the incoming traffic request to be transmitted, and the incoming traffic will ultimately be transmitted to the target port.
[0087] Specifically, the first sidecar container performs traffic verification on the incoming traffic of the first business container according to the set service governance logic; if the incoming traffic of the first business container passes the traffic verification, the first sidecar container transmits the incoming traffic to the firewall module, and the firewall module forwards the incoming traffic transmitted by the first sidecar container to the second business container; if the incoming traffic of the first business container fails the traffic verification, the first sidecar container intercepts the incoming traffic of the first business container.
[0088] Refer to Figure 4 , Figure 4 FIG. is a visual flowchart of the incoming traffic transmission of a container in one embodiment, where iptables is the firewall module, and the firewall module includes a PREROUTING unit, an INPUT unit, a POLARIS_REDIRECT unit, an OUTPUT unit, and a POSTROUTING unit. Among them, the PREROUTING unit is used to detect whether the current target port of the incoming traffic is a preset port (9080). If the current target port of the incoming traffic is 9080, the PREROUTING unit passes the incoming traffic to the POLARIS_REDIRECT unit, and the POLARIS_REDIRECT unit redirects the incoming traffic to the first sidecar container. After the first sidecar container verifies (verification passed) the incoming traffic, it passes the incoming traffic to the OUTPUT unit, and the incoming traffic can be forwarded to the first business container through the OUTPUT unit and the POSTROUTING unit; if the current target port of the incoming traffic is not 9080, the PREROUTING unit passes the incoming traffic to the INPUT unit, and the INPUT unit directly forwards the incoming traffic to the first business container. Among them, the target port 9080 is the preset port that requires traffic verification, otherports are other ports that do not require traffic verification, port: 15006 is the container port of the first sidecar container, and 127.0.0.1:9080 is the port address of the target port 9080.
[0089] In this embodiment, after the firewall module detects the incoming traffic entering the first service container, it first determines the current target port of the incoming traffic. If the current target port is a preset port that requires traffic verification, the firewall module redirects the incoming traffic to the first sidecar container for traffic verification. After the incoming traffic passes the traffic verification in the first sidecar container, the first sidecar container sends the incoming traffic that has passed the traffic verification to the firewall module. As a result, the firewall module forwards the incoming traffic that has passed the traffic verification to the first service container. If the current target port is a preset port that does not require traffic verification, the firewall module directly transmits the incoming traffic to the first service container. In this way, the incoming traffic that needs to be subject to service governance (traffic verification) can be accurately intercepted into the first sidecar container, while the incoming traffic that does not need to be subject to service governance is directly directed to the first service container, realizing the accurate interception of the incoming traffic that needs to be subject to service governance into the sidecar of the first service container for service governance, and directly releasing the outgoing traffic that does not need to be subject to service governance to the first service container, thereby improving the efficiency of service governance and reducing the performance loss of the microservice system.
[0090] Refer to Figure 5 , Figure 5 FIG. is a visual flowchart of the transmission of outgoing traffic of containers in an embodiment. Among them, service container A is the first service container, service container B is the second service container, sidecar is the first sidecar container, dns-sidecar is the second sidecar container, iptables is the firewall module, test.sf-express.com / hello is the current domain name of the outgoing traffic, Dns query request is the domain name resolution request, 10.4.4.4 is the preset target address obtained by forced resolution, the original DNS resolution result is the transmission target address obtained by normal resolution, HTTP request is the traffic sending request, "needs to be intercepted" means that the outgoing traffic needs to be intercepted into the first sidecar container for traffic verification, and "does not need to be intercepted" means that the outgoing traffic does not need to be intercepted into the first sidecar container for traffic verification.
[0091] Specifically, first, the first service container will determine the current domain name of the traffic, generate and send a domain name resolution request corresponding to the current domain name; the firewall module will hijack the domain name resolution request sent by the first service container and redirect the domain name resolution request to the second sidecar container of the first service container based on the set first firewall rule; the second sidecar container will first determine whether the current domain name is a preset domain name that requires traffic verification. If the current domain name is a preset domain name that requires traffic verification, it will forcibly resolve the current domain name to the preset target address and use the preset target address as the domain name resolution address; if the current domain name is a preset domain name that does not require traffic verification, it will normally resolve the current domain name to the transmission target address and use the transmission target address as the domain name resolution address. Then, the second sidecar container will return the domain name resolution address to the first service container; further, the first service container will encapsulate the domain name resolution address and the outgoing traffic into a traffic sending request. If the domain name resolution address is the transmission target address, it will directly transmit the traffic sending request to the second service container; if the domain name resolution address is the preset target address, it will transmit the traffic sending request to the firewall module according to the preset target address; the firewall module will redirect the traffic sending request to the first sidecar container according to the set second firewall rule; the first sidecar container will parse the traffic sending request to obtain the outgoing traffic and perform traffic verification on the outgoing traffic of the first service container according to the set service governance logic; if the outgoing traffic of the first service container passes the traffic verification, the first sidecar container will forward the outgoing traffic of the first service container to the second service container; if the outgoing traffic of the first service container fails to pass the traffic verification, the first sidecar container will intercept the outgoing traffic of the first service container.
[0092] In this way, in this embodiment, the outgoing traffic that needs to be subject to service governance (traffic verification) can be accurately intercepted into the first sidecar container, while the outgoing traffic that does not need to be subject to service governance is directly directed to the second service container. In this way, it can be realized that the outgoing traffic that needs to be subject to service governance in the first service container is accurately intercepted into the sidecar for service governance, and the outgoing traffic that does not need to be subject to service governance in the first service container is directly released to the second service container. Therefore, the efficiency of service governance can be improved.
[0093] It should be understood that although the steps in the flowcharts involved in the above-described embodiments are sequentially shown according to the indications of the arrows, these steps are not necessarily executed in the order indicated by the arrows. Unless there is a clear indication in this document, the execution of these steps has no strict order limitation, and these steps can be executed in other orders. Moreover, at least a part of the steps in the flowcharts involved in the above-described embodiments may include multiple steps or multiple stages. These steps or stages are not necessarily executed at the same moment, but can be executed at different moments. The execution order of these steps or stages is not necessarily sequential, but can be executed alternately or in turn with at least a part of other steps or steps or stages in other steps.
[0094] Based on the same inventive concept, an embodiment of the present application also provides a container system for implementing the container traffic transmission method described above. The solution provided by this system to solve the problem is similar to the solution described in the above method. Therefore, the specific limitations in one or more of the following container system embodiments can refer to the limitations on the container traffic transmission method in the above text, and will not be repeated here.
[0095] In one embodiment, as Figure 6 shown, a container system is provided, including: a first service container 502, a first sidecar container 504 of the first service container 502, and a domain name resolution module 506, where:
[0096] The first service container is used to determine the current domain name of the traffic;
[0097] The domain name resolution module is used to resolve the current domain name to obtain a domain name resolution address, and feedback the domain name resolution address to the first service container;
[0098] The first service container is further used to, if the domain name resolution address is equal to a preset target address, send the outgoing traffic to the first sidecar container according to the preset target address, where the first sidecar container is used to verify the outgoing traffic and forward the outgoing traffic to a second service container after successful verification; if the domain name resolution address is not equal to the preset target address, directly transmit the outgoing traffic to the second service container according to the domain name resolution address.
[0099] In one embodiment, the domain name resolution module includes a firewall module and a second sidecar container of the first service container;
[0100] The firewall module is used to intercept the domain name resolution request of the first service container and redirect the domain name resolution request to the second sidecar container, where the domain name resolution request includes the current domain name of the outgoing traffic;
[0101] The second sidecar container is used to resolve the current domain name to obtain a domain name resolution address.
[0102] In one embodiment, the domain name resolution module is further configured to:
[0103] Determine the traffic verification attribute of the current domain name; if the traffic verification attribute indicates that the current domain name needs to be traffic-verified, then resolve the current domain name to a preset target address; if the traffic verification attribute indicates that the current domain name does not need to be traffic-verified, then resolve the current domain name to a corresponding transmission target address.
[0104] In one embodiment, the first service container is configured to generate a traffic sending request according to the preset target address and the outgoing traffic, and send the traffic sending request to the firewall module according to the preset target address; the firewall module redirects the traffic sending request to the first sidecar container; the first sidecar container is configured to resolve the traffic sending request into the outgoing traffic.
[0105] In one embodiment, the first sidecar container is further configured to:
[0106] If the outgoing traffic fails the traffic verification, then intercept the outgoing traffic.
[0107] In one embodiment, the domain name resolution module includes a firewall module; the firewall module is further configured to:
[0108] Determine the current target port of the incoming traffic; if the current target port is a preset port that needs to be traffic-verified, then redirect the incoming traffic to the first sidecar container, where the first sidecar container is configured to verify the incoming traffic and forward the incoming traffic to the first service container after successful verification; if the current target port is a preset port that does not need to be traffic-verified, then transmit the incoming traffic to the first service container.
[0109] In one embodiment, the first sidecar container is further configured to:
[0110] If the incoming traffic fails the traffic verification, then intercept the incoming traffic.
[0111] Each module in the above container system can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to the above respective modules.
[0112] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as shown in Figure 7 . The computer device includes a processor, a memory, and a network interface connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store container traffic transmission flow data. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a container traffic transmission method.
[0113] Those skilled in the art can understand that Figure 7 the structure shown in is only a block diagram of some structures related to the solution of this application, and does not constitute a limitation on the computer device to which the solution of this application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have different component arrangements.
[0114] In one embodiment, a computer device is further provided, including a memory and a processor. A computer program is stored in the memory. When the processor executes the computer program, the steps in the above method embodiments are implemented.
[0115] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0116] In one embodiment, a computer program product is provided, including a computer program. When the computer program is executed by the processor, the steps in the above method embodiments are implemented.
[0117] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, database, or other medium used in the embodiments provided in the present application can include at least one of non-volatile and volatile memories. Non-volatile memories can include read-only memory (ROM), magnetic tapes, floppy disks, flash memories, optical memories, high-density embedded non-volatile memories, resistive random access memories (ReRAM), magnetoresistive random access memories (MRAM), ferroelectric random access memories (FRAM), phase change memories (PCM), graphene memories, etc. Volatile memories can include random access memory (RAM) or external cache memories, etc. By way of illustration and not limitation, RAM can be in various forms, such as static random access memory (SRAM) or dynamic random access memory (DRAM), etc. The databases involved in the embodiments provided in the present application can include at least one of relational databases and non-relational databases. Non-relational databases can include distributed databases based on blockchain, etc., without limitation. The processors involved in the embodiments provided in the present application can be general-purpose processors, central processors, graphics processors, digital signal processors, programmable logics, data processing logics based on quantum computing, etc., without limitation.
[0118] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0119] The above-described embodiments only represent several implementation manners of the present application. The description is relatively specific and detailed, but it should not be construed as a limitation on the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the appended claims.
Claims
1. A method for container flow transmission, characterized in that, Applied to a container system, the container system includes a first service container, a first sidecar container of the first service container, and a domain name resolution module; the method includes: The first service container determines the current domain name of the outgoing traffic; The domain name resolution module resolves the current domain name to obtain a domain name resolution address and feeds back the domain name resolution address to the first service container; If the domain name resolution address is equal to a preset target address, the first service container sends the outgoing traffic to the first sidecar container according to the preset target address, where the first sidecar container is used to verify the outgoing traffic and forward the outgoing traffic to a second service container after successful verification; If the domain name resolution address is not equal to the preset target address, the first service container directly transmits the outgoing traffic to the second service container according to the domain name resolution address.
2. The method according to claim 1, wherein The domain name resolution module includes a firewall module and a second sidecar container of the first service container; The domain name resolution module resolves the current domain name to obtain a domain name resolution address, including: The firewall module intercepts the domain name resolution request of the first service container and redirects the domain name resolution request to the second sidecar container, where the domain name resolution request includes the current domain name of the outgoing traffic; The second sidecar container resolves the current domain name to obtain a domain name resolution address.
3. The method according to claim 1 or 2, characterized in that, Resolving the current domain name to obtain a domain name resolution address includes: Determining the traffic verification attribute of the current domain name; If the traffic verification attribute indicates that the current domain name needs to be traffic-verified, resolve the current domain name to a preset target address; If the traffic verification attribute indicates that the current domain name does not need to be traffic-verified, resolve the current domain name to a corresponding transmission target address.
4. The method according to claim 1, characterized in that, The first service container sending the outgoing traffic to the first sidecar container according to the preset target address includes: The first service container generates a traffic sending request according to the preset target address and the outgoing traffic; The first service container sends the traffic sending request to the firewall module according to the preset target address; The firewall module redirects the traffic sending request to the first sidecar container, where the first sidecar container is used to resolve the traffic sending request into the outgoing traffic.
5. The method according to claim 1, characterized in that, After the first service container sends the outgoing traffic to the first sidecar container according to the preset target address, the method further includes: If the outgoing traffic fails the traffic verification, the first sidecar container intercepts the outgoing traffic.
6. The method according to claim 1, wherein The domain name resolution module includes a firewall module; the method further includes: The firewall module determines the current target port of the incoming traffic; If the current target port is a preset port that needs to be traffic-verified, the firewall module redirects the incoming traffic to the first sidecar container, where the first sidecar container is used to verify the incoming traffic and forward the incoming traffic to the first service container after successful verification; If the current target port is a preset port that does not require traffic verification, the firewall module transmits the incoming traffic to the first service container.
7. The method according to claim 6, characterized in that, After the firewall module redirects the incoming traffic to the first sidecar container, the method further includes: If the incoming traffic fails the traffic verification, the first sidecar container intercepts the incoming traffic.
8. A container system, characterized in that, The container system includes a first service container, a first sidecar container of the first service container, and a domain name resolution module; The first service container is configured to determine the current domain name of the outgoing traffic; The domain name resolution module is configured to resolve the current domain name to obtain a domain name resolution address and feedback the domain name resolution address to the first service container; The first service container is further configured to, if the domain name resolution address is equal to a preset target address, send the outgoing traffic to the first sidecar container according to the preset target address, where the first sidecar container is configured to verify the outgoing traffic and forward the outgoing traffic to a second service container after successful verification; If the domain name resolution address is not equal to the preset target address, the outgoing traffic is directly transmitted to the second service container according to the domain name resolution address.
9. A computer device, comprising a memory and a processor, the memory storing a computer program, characterized in that, When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the computer program is executed by the processor, the steps of the method according to any one of claims 1 to 7 are implemented.