Traffic label processing method, server and storage medium
By using the coordinated work of the target data surface component and the control surface component in the service mesh to dynamically set traffic labels, the high maintenance costs and risks caused by intrusive settings in the prior art are solved, and non-invasive traffic label settings and flexible routing are achieved.
Patent Information
- Application Number
- CN202410010272.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-03
- Publication Date
- 2025-07-04
AI Technical Summary
The prior art requires intrusion of code when setting traffic tags in applications, resulting in high maintenance costs and risks.
Receive access requests through the target data surface component, determine whether they comply with the dynamic marking rules issued by the control surface component, generate and add traffic tags, and realize non-invasive traffic tag settings.
It reduces the maintenance costs and risks on the application side, provides more flexible and scalable routing capabilities, and covers more communication scenarios.
Smart Images

Figure CN120263723A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and in particular, to a traffic label processing method, a server, and a storage medium. Background Art
[0002] Service mesh is often used to describe the microservice network that constitutes an application and the interactions between applications. As an infrastructure layer for processing inter-service communication, service mesh is responsible for reliably delivering requests by constructing the complex service topologies of modern cloud-native applications. In a service mesh, an ingress gateway or a mesh proxy can receive requests from an application and route the requests to the corresponding application service instance according to the traffic labels carried by the requests. To implement routing operations for different traffic, setting traffic labels for requests sent by an application has become a crucial step. Currently, there are some methods for setting traffic labels in the code of an application. This method requires intrusion into the application, resulting in relatively high maintenance costs and risks. Therefore, there is a need to propose a new solution. Summary of the Invention
[0003] Multiple aspects of this application provide a traffic label processing method, a server, and a storage medium, which are used to dynamically set traffic labels for requests of an application in a non-intrusive manner, thereby reducing the maintenance costs and risks on the application side.
[0004] An embodiment of this application provides a traffic label processing method, including: receiving a first access request through a target data plane component; determining whether the first access request meets the rule activation condition corresponding to a dynamic tagging rule; the dynamic tagging rule is issued by a control plane component; if it meets the condition, generating a target traffic label according to the label generation method in the dynamic tagging rule; adding the target traffic label to the first access request to perform routing and forwarding on the first access request according to the target traffic label.
[0005] Optionally, before determining whether the first access request meets the rule activation condition corresponding to the dynamic tagging rule, it further includes: obtaining label configuration data provided by a user through the control plane component; parsing the label configuration data to obtain the scope of the activation entity defined by the label configuration data and the dynamic tagging rule; and issuing the dynamic tagging rule to the target data plane component according to the scope of the activation entity.
[0006] Optionally, it also includes: obtaining metadata information of at least one application service instance in the data plane through the control plane component; and sending the dynamic labeling rule to the target data plane component according to the effective subject range, including: judging whether the at least one application service instance is within the effective subject range according to the metadata information of the at least one application service instance; if any application service instance of the at least one application service instance is within the effective subject range, sending the dynamic labeling rule to the grid proxy component corresponding to the application service instance.
[0007] Optionally, determining whether the first access request meets the rule effectiveness conditions corresponding to the dynamic labeling rule includes: performing at least one of the following judgment operations on the first access request, and determining that the first access request meets the rule effectiveness conditions corresponding to the dynamic labeling rule when the results of at least one of the judgment operations are all yes: determining whether the destination application service corresponding to the first access request is within the effective callee range corresponding to the rule effectiveness conditions; determining whether the calling protocol adopted by the first access request is within the effective protocol range corresponding to the rule effectiveness conditions.
[0008] Optionally, a target traffic label is generated according to a label generation method in the dynamic labeling rule, including: obtaining a header value with a specified header name from the request header of the first access request as the label value of the target traffic label; or obtaining a label value corresponding to a specified label name from the label of a container group to which the container where the target data plane component is located belongs, as the label value of the target traffic label; or obtaining a specified constant value as the label value of the target traffic label; or obtaining a field value corresponding to a specified field from the request body of the first access request as the label value of the target traffic label; or obtaining a parameter value corresponding to a specified query parameter from the query parameter of the first access request as the label value of the target traffic label.
[0009] Optionally, it also includes: obtaining the context unique identifier of the first access request from the first access request; establishing a mapping relationship between the target traffic label and the context unique identifier; the mapping relationship is used to query the target traffic label according to the context unique identifier in the processing link of the first access request.
[0010] Optionally, after adding the target traffic label to the first access request, it also includes: forwarding the first access request to the target application service instance proxied by the target data plane component; receiving a second access request returned by the target application service instance based on the first access request; the second access request carries the context unique identifier; querying the mapping relationship based on the context unique identifier to obtain the target traffic label corresponding to the context unique identifier; adding the target traffic label to the second access request to route and forward the second access request based on the target traffic label.
[0011] Optionally, the target data plane component includes: an ingress gateway component of the data plane or any grid proxy component in the data plane.
[0012] An embodiment of the present application also provides a server, comprising: a memory and a processor; the memory is used to store one or more computer instructions; the processor is used to execute the one or more computer instructions to: execute the steps in the method provided in the embodiment of the present application.
[0013] The embodiment of the present application also provides a computer-readable storage medium storing a computer program, which can implement the steps in the method provided in the embodiment of the present application when the computer program is executed by a processor.
[0014] In this embodiment, the first access request is received by the target data plane component, and it is determined whether the first access request meets the rule effectiveness conditions corresponding to the dynamic labeling rules issued by the control plane component; if it meets the conditions, a target traffic label is generated according to the label generation method in the dynamic labeling rule, and the target traffic label is added to the first access request to route and forward the first access request according to the target traffic label. In this embodiment, on the one hand, the dynamic setting function of the traffic label is implemented based on the target data plane component and the control plane component, and the traffic label can be set for the access request of the application without intruding the code of the application that issues the access request, thereby reducing the maintenance cost and risk on the application side. On the other hand, the access request can be flexibly labeled through the dynamic labeling rules to achieve more scalable and flexible routing capabilities, thereby covering more communication scenarios. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] The drawings described herein are used to provide a further understanding of the present application and constitute a part of the present application. The illustrative embodiments of the present application and their descriptions are used to explain the present application and do not constitute an improper limitation on the present application. In the drawings:
[0016] Figure 1 A schematic diagram of the structure of a service grid provided for an exemplary embodiment of the present application;
[0017] Figure 2 Flow chart of the traffic label processing method provided by an exemplary embodiment of the present application;
[0018] Figure 3 Tracking diagram of the processing link of the first access request provided by an exemplary embodiment of the present application;
[0019] Figure 4 Flow chart of the traffic label processing method executed in the service mesh provided by an exemplary embodiment of the present application;
[0020] Figure 5 Structure diagram of the server provided by an exemplary embodiment of the present application. Detailed implementation manners
[0021] To make the objectives, technical solutions and advantages of the present application clearer, the technical solutions of the present application will be clearly and completely described below in conjunction with the specific embodiments of the present application and the corresponding drawings. Apparently, the described embodiments are only a part rather than all of the embodiments of the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts shall fall within the protection scope of the present application.
[0022] The terms used in the embodiments of the present invention are only for the purpose of describing specific embodiments, and are not intended to limit the present invention. The singular forms "a", "the" and "said" used in the embodiments of the present invention and the appended claims are also intended to include the plural forms, unless the context clearly indicates otherwise. "Plural" generally includes at least two, but does not exclude the case of including at least one.
[0023] It should be understood that the term " / and / " used herein is only a description of the association relationship of associated objects, indicating that there can be three relationships. For example, A and / or B can represent: A exists alone, A and B exist simultaneously, and B exists alone. In addition, the character " / " herein generally represents an "or" relationship between the front and rear associated objects.
[0024] It should also be noted that the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a commodity or system including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such commodity or system. Without further limitation, the element defined by the statement "including one..." does not exclude the existence of another identical element in the commodity or system including the said element.
[0025] To more clearly describe the technical solutions provided in the embodiments of the present application, the service mesh architecture and some related concepts involved in the embodiments of the present application will be introduced below.
[0026] Among them, a service mesh is a dedicated infrastructure layer used to achieve reliable, fast, and secure inter-service calls in a microservices architecture. Among them, the service mesh is mainly used to facilitate secure and reliable communication between multiple microservices. A microservice refers to decomposing an application into multiple smaller services or instances and running them on different clusters / machines. Among them, an application service instance can also be called a workload. Each application service instance is bound with a mesh proxy to achieve communication and management between services.
[0027] As Figure 1 shown, the microservices include application service instance A and application service instance B, and application service instance A and application service instance B form the functional application layer of service mesh 100. In one implementation, application service instances A and B run in the form of containers / processes in a machine / workload container group.
[0028] In one implementation, application service instance A can be a commodity query service, and application service instance B can be a commodity order placement service.
[0029] As Figure 1 shown, application service instance A and mesh proxy (sidecar) 103 coexist in machine / workload container group 109, and application service instance B and mesh proxy 105 coexist in machine / workload container group 110. Mesh proxies 103 and 105 form the data plane layer of service mesh 100. Among them, mesh proxies 103 and 105 are running in the form of containers / processes 104 and containers / processes 106 respectively. Among them, application service instance A and application service instance B are running in the form of containers / processes 107 and containers / processes 108 respectively. Bidirectional communication can be carried out between mesh proxy 103 and application service instance A, and bidirectional communication can be carried out between mesh proxy 105 and application service instance B. In addition, bidirectional communication can also be carried out between mesh proxy 103 and mesh proxy 105.
[0030] In one implementation, all traffic of application service instance A is routed to the appropriate destination through mesh proxy 103, and all network traffic of application service instance B is routed to the appropriate destination through mesh proxy 105.
[0031] In one implementation, the function of the extended data plane layer can be implemented by writing a custom filter for the proxy (Envoy) in the service mesh 100. The mesh proxy configuration can be used to correctly proxy service traffic in the service mesh, realizing service interconnection and service governance. The mesh proxy 103 and the mesh proxy 105 can be configured to perform at least one of the following functions: service discovery, health checking, routing, load balancing, authentication and authorization, and observability.
[0032] As Figure 1 shown, the service mesh 100 further includes a control plane layer. Among them, the control plane layer can be a set of services running in a dedicated namespace, and the managed control plane component 101 hosts these services in the machine / workload container group (machine / Pod) 102. As Figure 1 shown, the managed control plane component 101 communicates bidirectionally with the mesh proxy 103 and the mesh proxy 105. The managed control plane component 101 is configured to perform some control and management functions. For example, the managed control plane component 101 receives the telemetry data transmitted by the mesh proxy 103 and the mesh proxy 105, and can further aggregate this telemetry data. For these services, the managed control plane component 101 can also provide a user-facing application programming interface (Application Programming Interface, API) to more easily manipulate network behavior and provide configuration data to the mesh proxy 103 and the mesh proxy 105.
[0033] In the service mesh, the ingress gateway (such as API Gateway) is mainly responsible for handling external traffic entry and providing functions such as API management and access control. The mesh proxy (such as Sidecar Proxy) is responsible for communicating and managing between application service instances. The two together constitute the infrastructure of the service mesh, realizing fine-grained traffic control, policy implementation, and security protection.
[0034] In the service mesh, an endpoint usually refers to the network address of an application service instance, that is, the specific network location of the application service instance in the service mesh, usually including information such as an IP address and a port number. When the mesh proxy receives a request from the outside, it will forward the request to the corresponding application service instance endpoint.
[0035] In a service mesh, traffic labels are a mechanism for marking and managing traffic. Typically, when an application service instance registers with the service mesh, it carries some traffic labels that describe specific attributes or identities of the application service instance. When the mesh proxy of the application service instance receives a request sent by the application service instance, it can determine the target application service instance corresponding to the request based on the traffic labels and predefined routing rules, and route the request to the target application service instance.
[0036] In some typical methods, traffic labels can be set for an application by intruding into the application's code so that the application service instance corresponding to the application carries the traffic labels in the requests it sends. In some solutions, traffic labels can be set manually in the application code. For example, an interface for setting traffic labels can be called in the application code to use the interface to set labels for the egress traffic of the application. In other solutions, a third-party framework or library can be used to set traffic labels for the egress traffic of the application. In still other solutions, AOP (Aspect Oriented Programming) technology can be used to automatically implant the code for setting traffic labels in the application. The above intrusive traffic label setting methods require modifying the application or using a third-party framework or library, increasing the maintenance cost and risk. On the other hand, during the process of setting traffic labels, it is necessary to unify and standardize the naming rules, formats, and details of traffic labels, further increasing the management cost and risk of traffic labels.
[0037] In view of the above technical problems, in some embodiments of the present application, a solution is provided. The technical solutions provided by each embodiment of the present application will be described in detail below with reference to the accompanying drawings.
[0038] Figure 2 is a schematic flowchart of a traffic label processing method provided by an exemplary embodiment of the present application. The method may include the steps as Figure 2 shown:
[0039] Step 201: Receive a first access request through a target data plane component.
[0040] Step 202: Determine whether the first access request meets the rule activation conditions corresponding to the dynamic tagging rule; the dynamic tagging rule is sent by a control plane component.
[0041] Step 203: If it meets the conditions, generate a target traffic label according to the label generation method in the dynamic tagging rule.
[0042] Step 204: Add the target traffic label to the first access request to perform routing and forwarding on the first access request according to the target traffic label.
[0043] In this embodiment, the target data plane component can be the ingress gateway component of the data plane or any mesh proxy component. Among them, the ingress gateway component is the entry of the service mesh, mainly used for labeling the received access requests from inside or outside the service mesh according to the dynamic labeling rules, and forwarding the access requests to different destinations. Among them, the mesh proxy component is the proxy of the workloads in the service mesh, used to proxy the egress traffic and ingress traffic of the application service instances corresponding to the workloads. Among them, any mesh proxy component is mainly used for labeling the ingress traffic from the ingress gateway component or other mesh proxy components according to the dynamic labeling rules, and can label the egress traffic of the application service instances it proxies.
[0044] Among them, when the target data plane component is implemented as the ingress gateway component, the first access request can be an access request sent by an application outside the service mesh to the ingress gateway of the service mesh. The ingress gateway component can label the first access request according to the dynamic labeling rules, and forward the labeled first access request to the mesh proxy component inside the service mesh according to the routing rules.
[0045] Among them, when the target data plane component is implemented as any mesh proxy component, the first access request can be an access request forwarded by the ingress gateway to this mesh proxy component. The mesh proxy component can label the first access request according to the dynamic labeling rules, and forward the labeled first access request to the application service instance proxied by the mesh proxy component.
[0046] Among them, when the target data plane component is implemented as any mesh proxy component, the first access request can also be an egress access request sent by the application service instance proxied by this mesh proxy component. The mesh proxy component can label the egress access request according to the dynamic labeling rules, and forward the labeled first access request to other mesh proxy components or the egress gateway component. Among them, the dynamic labeling rules are generated by the control plane component in the service mesh. Before dynamically labeling the access request, the control plane component can obtain the label configuration data provided by the user and parse the label configuration data to obtain the dynamic labeling rules. Among them, the label configuration data is used to configure the dynamic generation method of the traffic label.
[0047] Optionally, the label configuration data may at least include: effective subject information. The effective subject information is used to describe which subjects (for example, workloads or workload groups) the traffic label is applied to. Among them, the effective subject information may be different in different label configuration data. For example, when certain workloads are added to the service grid, new label configuration data provided by the user may be obtained, and the effective subject information in the label configuration data may include the identification of the newly added workload. For another example, when the traffic label of a specified workload is modified, new label configuration data provided by the user may be obtained, and the effective subject information in the label configuration data may include the identification of these specified workloads. When parsing the label rule configuration data, the control plane component may parse the effective subject information in the label rule configuration data to determine the effective subject range of the traffic label.
[0048] Optionally, the label configuration data may also include: labeling rule description information, which may include: definition information of the rule effectiveness conditions of the traffic label and definition information of the label generation method. The definition information of the rule effectiveness conditions is used to describe the conditions that trigger the labeling operation of the access request when the access request meets them. The definition information of the label generation method may be used to describe the user-defined label name and the method for obtaining the user-defined label value.
[0049] The tag configuration data can be provided to the control plane component of the service grid in the form of a configuration file, so that the control plane component can obtain the dynamic tagging rules of the access request through the configuration file without intruding the application program that issued the access request. The configuration file can be flexibly provided according to the tag configuration requirements. When a new application service instance is added to the service grid, the tag configuration data can be updated by updating the configuration file.
[0050] After the control plane component obtains the tag configuration data provided by the user, it can parse the tag configuration data to obtain the effective subject range and dynamic labeling rules defined by the tag configuration data.
[0051] Among them, the control plane component can parse the labeling rule description information in the label configuration data to obtain dynamic labeling rules. Optionally, the control plane component can parse the rule effectiveness conditions from the definition information of the rule effectiveness conditions of the traffic label to obtain the label generation method. Optionally, the control plane component can parse the definition information of the label generation method of the traffic label to obtain the label generation method. Among them, the rule effectiveness conditions are used to describe the conditions under which the labeling operation is performed on the workload traffic. The label generation method is used to describe the processing method used to generate a traffic label for the workload traffic.
[0052] Optionally, the definition information of the rule activation condition defined by the label configuration data may include at least one of: the activation callee information and the activation protocol information. Among them, the activation callee information is used to limit the scope of the target application service instance for which the traffic label becomes effective. Optionally, the control plane component may parse the activation callee information in the label configuration data to determine the scope of the activation callee for the traffic label. Among them, the activation protocol scope is used to limit the scope of the call protocol for which the traffic label becomes effective. Optionally, the control plane component may parse the protocol call information in the label configuration data to determine the activation protocol scope of the traffic label.
[0053] Optionally, the definition information of the label generation method in the label configuration data can be described by a label rule expression. Among them, the label rule expression is used to describe the specific method of calculating the label value for the label name specified by the user. For example, the label rule expression can describe obtaining the value of a specified field from the specified information as the label value. The control plane component can parse the label rule expression to obtain the label generation method defined by the label configuration data.
[0054] Among them, the control plane component can parse the activation subject information in the label configuration data to obtain the activation subject scope. After obtaining the activation subject scope, the control plane component can, according to the activation subject scope, send the dynamic tagging rule to the target data plane component within the activation subject scope, so that the target data plane component tags the incoming / outgoing traffic according to the dynamic tagging rule.
[0055] In some alternative embodiments, the control plane component can obtain the metadata information of at least one application service instance in the data plane. Among them, the metadata information of any application service instance may include at least one of: the application service name corresponding to the application service instance, the namespace it belongs to, the runtime node environment it is in, the operating system it uses, the supported monitoring services, etc. and other attribute tags.
[0056] Accordingly, when the control plane component sends the dynamic tagging rule to the target data plane component according to the activation subject scope, it can respectively determine whether the at least one application service instance is within the activation subject scope according to the metadata information of the at least one application service instance. If any of the at least one application service instances is within the activation subject scope, the control plane component can send the dynamic tagging rule to the mesh proxy component (i.e., the target data plane component) corresponding to the application service instance.
[0057] Based on the above, after the target data plane component receives the first access request, it can determine whether the first access request meets the rule activation condition corresponding to the dynamic tagging rule. If it meets, it generates a target traffic label according to the label generation method in the dynamic tagging rule.
[0058] Optionally, the rule activation conditions may include: the activation callee scope and / or the activation protocol scope. The following will continue to take the first access request as an example to exemplarily illustrate the above judgment process.
[0059] In some optional embodiments A1, when determining whether the first access request meets the rule activation conditions corresponding to the dynamic tagging rule, the target data plane component may determine whether the destination application service corresponding to the first access request is within the activation callee scope corresponding to the rule activation conditions. If the destination application service corresponding to the first access request is within the activation callee scope corresponding to the rule activation conditions, it may be determined that the first access request meets the rule activation conditions corresponding to the dynamic tagging rule.
[0060] In some other optional embodiments A2, when determining whether the first access request meets the rule activation conditions corresponding to the dynamic tagging rule, the target data plane component may determine whether the call protocol used by the first access request is within the activation protocol scope corresponding to the rule activation conditions. If the call protocol used by the first access request is within the activation protocol scope corresponding to the rule activation conditions, it may be determined that the first access request meets the rule activation conditions corresponding to the dynamic tagging rule.
[0061] In still some other optional embodiments A3, when determining whether the first access request meets the rule activation conditions corresponding to the dynamic tagging rule, the target data plane component may determine whether the destination application service corresponding to the first access request is within the activation callee scope corresponding to the rule activation conditions and determine whether the call protocol used by the first access request is within the activation protocol scope corresponding to the rule activation conditions. If the destination application service corresponding to the first access request is within the activation callee scope corresponding to the rule activation conditions and the call protocol used by the first access request is within the activation protocol scope corresponding to the rule activation conditions, it may be determined that the first access request meets the rule activation conditions corresponding to the dynamic tagging rule.
[0062] If the first access request meets the rule activation conditions corresponding to the dynamic tagging rule, the target data plane component may generate a target traffic tag according to the tag generation method in the dynamic tagging rule. The following will take some tag generation methods as examples for exemplary illustration.
[0063] In some optional embodiments B1, the target data plane component may obtain the header value with a specified header name from the request header of the first access request as the tag value of the target traffic tag.
[0064] For example, when the target data plane component is implemented as an ingress gateway component, the ingress gateway component can obtain the header value with a specified header name from the obtained access request as the label value corresponding to the target traffic label. When the target data plane component is implemented as a mesh proxy component, the mesh proxy component can obtain the header value with a specified header name from the request entering the mesh proxy component as the label value corresponding to the target traffic label. For another example, when the target data plane component is implemented as a mesh proxy component, the mesh proxy component can obtain the header value with a specified header name from the request sent from the application service instance it proxies to the mesh proxy component as the label value corresponding to the target traffic label, which will not be enumerated one by one.
[0065] In some optional embodiments B2, the target data plane component can obtain the label value corresponding to the specified label name from the labels of the container group to which the container where the target data plane component is located belongs as the label value of the target traffic label.
[0066] In some optional embodiments B3, the target data plane component obtains a specified constant value as the label value of the target traffic label.
[0067] In some optional embodiments B4, the target data plane component can obtain the field value corresponding to the specified field from the request body of the first access request as the label value of the target traffic label.
[0068] In some optional embodiments B5, the target data plane component can obtain the parameter value corresponding to the specified query parameter from the query parameters of the first access request as the label value of the target traffic label.
[0069] It should be understood that in addition to the above implementation manners, other label generation methods are also adopted to generate the label value of the target traffic label, which can be dynamically configured through label configuration data. In practice, multiple label generation methods can be obtained according to the label configuration data flexibly defined by the user, and the label value can be obtained according to the obtained dynamic tagging rules, which will not be enumerated one by one.
[0070] After obtaining the target traffic label based on the above implementation manner, the target data plane component can add the target traffic label to the first access request to perform routing and forwarding on the first access request according to the target traffic label. Optionally, the dynamic traffic label can be added to the first access request by adding a header to the message of the first access request. Optionally, the target data plane component can add a new message header to the first access request. Wherein, the message header field of the new message header is the label name of the target traffic label, and the message header value is the label value of the target traffic label.
[0071] It should be noted that the target data plane component can further obtain routing rules and perform routing and forwarding on the first access request based on the routing rules. Among them, the routing rules can be issued by the control plane component. It should be understood that the above dynamic tagging rules are only for illustrative purposes. In practice, multiple dynamic tagging rules can be obtained according to the tag configuration data flexibly defined by users, and tag values can be obtained according to the obtained dynamic tagging rules, which will not be listed one by one.
[0072] In some alternative embodiments, when the tag configuration data defines the tag name of the target traffic tag, the control plane component can establish a mapping relationship between the tag name of the target traffic tag and the routing destination as the routing rule, and issue the routing rule to the target data plane component. Furthermore, when the target data plane component receives an access request, it can query the routing destination matching the tag name in the routing rule according to the tag name of the target traffic tag carried in the access request, and perform routing and forwarding according to the routing destination.
[0073] In some other alternative embodiments, after parsing the dynamic tagging rules, the control plane component can generate dynamic routing rules according to the dynamic tagging rules and issue the dynamic routing rules to the target data plane component. For example, the control plane component can establish a mapping relationship between the tag value field of the target traffic tag, the dynamic tagging rules, and the routing destination as the routing rule. When the target data plane component receives an access request, it can obtain the tag value corresponding to the tag value field from the access request according to the dynamic tagging rules corresponding to the tag value field, so as to complete the routing rule. Furthermore, the target data plane component can perform routing and forwarding according to the tag value of the target traffic tag carried in the access request and the completed routing rule.
[0074] In some alternative embodiments, to retain the target traffic tag in the processing link of the first access request, the target data plane component can obtain the context unique identifier of the first access request from the first access request and establish a mapping relationship between the target traffic tag and the context unique identifier, and the mapping relationship is saved in the form of a key-value pair dictionary. Among them, the context unique identifier is carried throughout the processing link of the first access request. Among them, the mapping relationship is used to query the target traffic tag according to the context unique identifier in the processing link of the first access request.
[0075] The following will take the processing link between any mesh proxy component and the workload it proxies as an example for illustrative description.
[0076] Optionally, after adding the target traffic label in the first access request, the grid proxy component may forward the first access request to the target application service instance represented by the grid proxy component. After the target application service instance processes the first access request, it may issue a second access request, and the second access request may be used to call other application service instances. Among them, the second access request carries the context unique identifier. After the grid proxy component receives the second access request returned by the target application service instance based on the first access request, it may query the mapping relationship based on the context unique identifier to obtain the target traffic label corresponding to the context unique identifier. The grid proxy component may add the target traffic label in the second access request to route and forward the second access request based on the target traffic label.
[0077] like Figure 3 As shown, the first access request received by the grid proxy component carries the context unique identifier and the target traffic label, and locally saves the mapping relationship between the context unique identifier and the target traffic label (i.e., the key-value pair dictionary). When the grid proxy component forwards the first access request to the workload, the first access request carries the context unique identifier. The second request returned by the workload to the grid proxy component also carries the context unique identifier. Furthermore, the grid proxy component can query the mapping relationship based on the context unique identifier and add the target traffic label in the second request.
[0078] Based on this implementation, when the application service instance cannot identify the target traffic label and cannot add the target traffic label in the second access request, the grid proxy component can track the target traffic label based on the established mapping relationship, so that the target traffic label can be applied in the entire processing link of the first access request, reducing the risk of unsuccessful routing and forwarding due to the lack of a traffic label.
[0079] In this embodiment, the first access request is received by the target data plane component, and it is determined whether the first access request meets the rule effectiveness conditions corresponding to the dynamic labeling rules issued by the control plane component; if it meets the conditions, a target traffic label is generated according to the label generation method in the dynamic labeling rule, and the target traffic label is added to the first access request to route and forward the first access request according to the target traffic label. In this embodiment, on the one hand, the dynamic setting function of the traffic label is implemented based on the target data plane component and the control plane component, and the traffic label can be set for the access request of the application without intruding the code of the application that issues the access request, thereby reducing the maintenance cost and risk on the application side. On the other hand, the access request can be flexibly labeled through the dynamic labeling rules to achieve more scalable and flexible routing capabilities, thereby covering more communication scenarios.
[0080] The following will be combined Figure 4The structures of the data plane and the control plane shown are used to further exemplarily illustrate the embodiments of the present application.
[0081] As Figure 4 shown, the service mesh controller 401 in the control plane can obtain the metadata information of the application service instance C and the gateway 405b. The user can provide label configuration data through the declarative API, and the traffic label configuration controller 402 in the control plane can obtain the label configuration data. The traffic label configuration generator 403 can parse the label configuration data to obtain the dynamic tagging rules. The traffic label configuration generator 403 includes: a scope definition plugin, a label rule definition plugin, and an attribute definition plugin. Among them, the scope definition plugin is used to parse the effective subject scope, the effective callee scope, and the effective protocol scope from the label configuration data. Among them, the label rule definition plugin is used to parse the dynamic tagging rules from the label configuration data. Among them, the attribute definition plugin is used to parse the attribute information corresponding to the label generation method from the label configuration data.
[0082] The traffic label configuration generator 403 can send the dynamic tagging rules to the mesh proxy 404b and the gateway 405b in the data plane according to the effective subject scope. Furthermore, the mesh proxy 404b can use the first traffic label processor 404a to generate the dynamic traffic label C1 for the application service instance C. The gateway 405b can use the second traffic label processor 405a to generate the dynamic traffic label B1 for the application service instance B.
[0083] It should be noted that the execution subject of each step of the method provided in the above embodiments can be the same device, or the method can also be executed by different devices as the execution subject. For example, the execution subject of steps 201 to 204 can be device A; for another example, the execution subject of steps 201 and 202 can be device A, and the execution subject of step 203 can be device B; and so on.
[0084] In addition, in some processes described in the above embodiments and the accompanying drawings, a plurality of operations appear in a specific order, but it should be clearly understood that these operations can be executed not in the order in which they appear in this article or in parallel. The operation numbers such as 201 and 202 are only used to distinguish different operations, and the numbers themselves do not represent any execution order. In addition, these processes can include more or fewer operations, and these operations can be executed in sequence or in parallel. It should be noted that the descriptions such as "first" and "second" in this article are used to distinguish different messages, devices, modules, etc., do not represent the sequence, and do not limit that "first" and "second" are different types.
[0085] It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data for analysis, stored data, displayed data, etc.) involved in this application are all information and data that have been authorized by the user or fully authorized by all parties. And the collection, use, and processing of relevant data need to comply with the relevant laws, regulations, and standards of relevant countries and regions, and corresponding operation entrances are provided for users to choose to authorize or refuse.
[0086] Figure 5 The schematic structural diagram of the server provided by an exemplary embodiment of the present application is shown as Figure 5 shown. The server includes: a memory 501, a processor 502, and a communication component 503.
[0087] The memory 501 is used to store computer programs and can be configured to store various other data to support operations on the server. Examples of such data include instructions for any application or method operating on the server.
[0088] In some optional embodiments, Figure 5 the server shown is used to execute a traffic label processing method. Among them, the processor 502, coupled to the memory 501, is used to execute the computer program in the memory 501 for: receiving a first access request through a target data plane component; determining whether the first access request meets the rule activation condition corresponding to the dynamic tagging rule; the dynamic tagging rule is sent by the control plane component; if it meets the condition, generating a target traffic label according to the label generation method in the dynamic tagging rule; adding the target traffic label to the first access request to perform routing and forwarding on the first access request according to the target traffic label.
[0089] Optionally, before determining whether the first access request meets the rule activation condition corresponding to the dynamic tagging rule, the processor 502 is further used for: obtaining label configuration data provided by the user through the control plane component; parsing the label configuration data to obtain the activation subject range and the dynamic tagging rule defined by the label configuration data; and sending the dynamic tagging rule to the target data plane component according to the activation subject range.
[0090] Optionally, the processor 502 is also used to: obtain metadata information of at least one application service instance in the data plane through the control plane component; when the processor 502 sends the dynamic labeling rule to the target data plane component according to the effective subject range, it is specifically used to: determine whether the at least one application service instance is within the effective subject range according to the metadata information of the at least one application service instance; if any application service instance of the at least one application service instance is within the effective subject range, send the dynamic labeling rule to the grid proxy component corresponding to the application service instance.
[0091] Optionally, when determining whether the first access request satisfies the rule effectiveness conditions corresponding to the dynamic labeling rule, the processor 502 is specifically used to: perform at least one of the following judgment operations on the first access request, and when the results of at least one of the judgment operations are all yes, determine that the first access request satisfies the rule effectiveness conditions corresponding to the dynamic labeling rule: determine whether the destination application service corresponding to the first access request is within the effective callee range corresponding to the rule effectiveness conditions; determine whether the calling protocol adopted by the first access request is within the effective protocol range corresponding to the rule effectiveness conditions.
[0092] Optionally, when the processor 502 generates a target traffic label according to the label generation method in the dynamic labeling rule, it is specifically used to: obtain a header value with a specified header name from the request header of the first access request as the label value of the target traffic label; or, obtain a label value corresponding to the specified label name from the label of the container group to which the container where the target data plane component is located belongs, as the label value of the target traffic label; or, obtain a specified constant value as the label value of the target traffic label; or, obtain a field value corresponding to a specified field from the request body of the first access request as the label value of the target traffic label; or, obtain a parameter value corresponding to a specified query parameter from the query parameter of the first access request as the label value of the target traffic label.
[0093] Optionally, the processor 502 is also used to: obtain the context unique identifier of the first access request from the first access request; establish a mapping relationship between the target traffic label and the context unique identifier; and the mapping relationship is used to query the target traffic label according to the context unique identifier in the processing link of the first access request.
[0094] Optionally, after adding the target traffic label to the first access request, the processor 502 is further configured to: forward the first access request to the target application service instance proxied by the target data plane component; receive a second access request returned by the target application service instance according to the first access request; the second access request carries the context unique identifier; query the mapping relationship according to the context unique identifier to obtain the target traffic label corresponding to the context unique identifier; add the target traffic label to the second access request, so as to perform routing and forwarding on the second access request according to the target traffic label.
[0095] Optionally, the target data plane component includes: an ingress gateway component of the data plane or any grid proxy component in the data plane.
[0096] Further, as Figure 5 shown, the server further includes: other components such as a power supply component 504. Figure 5 Only some components are schematically shown in Figure 5 the figure, which does not mean that the server only includes
[0097] Among them, the memory 501 can be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic memory, flash memory, a magnetic disk or an optical disc.
[0098] The communication component 503 is configured to facilitate wired or wireless communication between the device where the communication component is located and other devices. The device where the communication component is located can access a wireless network based on a communication standard, such as Wi-Fi (wireless network communication technology), 2G (such as Global System for Mobile Communications (GSM)), 3G (such as Wideband Code Division Multiple Access (WCDMA), 4G (such as Long Term Evolution (LTE)), 4G+ (such as upgraded Long Term Evolution (LTE-Advanced, LTE-A)) or 5G (Fifth Generation Mobile Communication Technology), or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component can be implemented based on Near Field Communication (NFC) technology, Radio Frequency Identification (RFID) technology, Infrared Data Association (IrDA) technology, Ultra Wide Band (UWB) technology, Bluetooth (BT) technology and other technologies.
[0099] The power supply component 504 is used to provide power to various components of the device where the power supply component is located. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing and distributing power to the device where the power supply component is located.
[0100] In this embodiment, the first access request is received by the target data plane component, and it is determined whether the first access request meets the rule effectiveness conditions corresponding to the dynamic labeling rules issued by the control plane component; if it meets the conditions, a target traffic label is generated according to the label generation method in the dynamic labeling rule, and the target traffic label is added to the first access request to route and forward the first access request according to the target traffic label. In this embodiment, on the one hand, the dynamic setting function of the traffic label is implemented based on the target data plane component and the control plane component, and the traffic label can be set for the access request of the application without intruding the code of the application that issues the access request, thereby reducing the maintenance cost and risk on the application side. On the other hand, the access request can be flexibly labeled through the dynamic labeling rules to achieve more scalable and flexible routing capabilities, thereby covering more communication scenarios.
[0101] Accordingly, an embodiment of the present application further provides a computer-readable storage medium storing a computer program, and when the computer program is executed, it can implement each step executable by the server in the above method embodiment.
[0102] Those skilled in the art should understand that the embodiments of the present invention can be provided as a method, a system, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM (Compact Disc Read-Only Memory), optical storage, etc.) containing computer-usable program code.
[0103] The present invention is described with reference to the flowcharts and / or block diagrams of methods, apparatuses (systems), and computer program products according to embodiments of the present invention. It should be understood that each flow and / or block in the flowchart and / or block diagram can be implemented by computer program instructions, and the combination of flows and / or blocks in the flowchart and / or block diagram can also be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the specified functions in one Figure 1 flow or multiple flows and / or blocks Figure 1 block or multiple blocks.
[0104] These computer program instructions can also be stored in a computer-readable memory that can direct a computer or other programmable data processing device to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured article including instruction means, and the instruction means implements the specified functions in one Figure 1 flow or multiple flows and / or blocks Figure 1 block or multiple blocks.
[0105] These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operation steps are executed on the computer or other programmable device to generate a computer-implemented process, and thus the instructions executed on the computer or other programmable device provide steps for implementing the specified functions in one Figure 1 flow or multiple flows and / or blocks Figure 1 block or multiple blocks.
[0106] In a typical configuration, a computing device includes one or more processors (Central Processing Unit, CPU), input / output interface, network interface and memory.
[0107] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.
[0108] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. Information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, Parallel Random Access Machine (PRAM), Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, CD-ROM, Digital Video Disc (DVD) or other optical storage, magnetic cassettes, disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include temporary computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0109] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.
[0110] The above is only an embodiment of the present application and is not intended to limit the present application. For those skilled in the art, the present application may have various changes and variations. Any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of the claims of the present application.
Claims
1. A method for processing traffic labels, characterized in that, including: receiving a first access request through a target data plane component; judging whether the first access request meets the rule activation condition corresponding to a dynamic tagging rule; the dynamic tagging rule is sent down by a control plane component; if it meets the condition, generating a target traffic tag according to the tag generation method in the dynamic tagging rule; adding the target traffic tag to the first access request to perform routing and forwarding on the first access request according to the target traffic tag.
2. The method according to claim 1, characterized in that, Before judging whether the first access request meets the rule activation condition corresponding to the dynamic tagging rule, it further includes: obtaining tag configuration data provided by a user through the control plane component; analyzing the tag configuration data to obtain the activation subject range and the dynamic tagging rule defined by the tag configuration data; sending down the dynamic tagging rule to the target data plane component according to the activation subject range.
3. The method according to claim 2, wherein It further includes: obtaining metadata information of at least one application service instance in the data plane through the control plane component; Sending down the dynamic tagging rule to the target data plane component according to the activation subject range includes: respectively judging whether the at least one application service instance is within the activation subject range according to the metadata information of the at least one application service instance; if any one of the at least one application service instance is within the activation subject range, sending down the dynamic tagging rule to the mesh proxy component corresponding to the application service instance.
4. The method according to claim 1, characterized in that Judging whether the first access request meets the rule activation condition corresponding to the dynamic tagging rule includes: performing the following at least one judgment operation on the first access request, and when the results of the at least one judgment operation are all yes, determining that the first access request meets the rule activation condition corresponding to the dynamic tagging rule: judging whether the destination application service corresponding to the first access request is within the activation callee range corresponding to the rule activation condition; judging whether the call protocol adopted by the first access request is within the activation protocol range corresponding to the rule activation condition.
5. The method according to claim 1, wherein Generating a target traffic tag according to the tag generation method in the dynamic tagging rule includes: obtaining a header value with a specified header name from the request header of the first access request as the tag value of the target traffic tag; or, obtaining a tag value corresponding to a specified tag name from the tags of the container group to which the container where the target data plane component is located belongs as the tag value of the target traffic tag; or, obtaining a specified constant value as the tag value of the target traffic tag; or, obtaining a field value corresponding to a specified field from the request body of the first access request as the tag value of the target traffic tag; or, obtaining a parameter value corresponding to a specified query parameter from the query parameters of the first access request as the tag value of the target traffic tag.
6. The method according to any one of claims 1-5, characterized in that, It further includes: obtaining the context unique identifier of the first access request from the first access request; establishing a mapping relationship between the target traffic tag and the context unique identifier; The mapping relationship is used to query the target traffic label according to the context unique identifier in the processing link of the first access request.
7. The method according to claim 6, characterized in that, After adding the target traffic label to the first access request, it further includes: Forwarding the first access request to the target application service instance proxied by the target data plane component; Receiving a second access request returned by the target application service instance according to the first access request; the second access request carries the context unique identifier; Querying the mapping relationship according to the context unique identifier to obtain the target traffic label corresponding to the context unique identifier; Adding the target traffic label to the second access request to perform routing and forwarding on the second access request according to the target traffic label.
8. The method according to any one of claims 1-5, characterized in that, The target data plane component includes: an ingress gateway component of the data plane or any grid proxy component in the data plane.
9. A server, characterized in that, It includes: A memory and a processor; The memory is used to store one or more computer instructions; The processor is used to execute the one or more computer instructions for: executing the steps in the method according to any one of claims 1-8.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it can implement the steps in the method according to any one of claims 1-8.