Container communication method, electronic equipment and medium
By converting IP packets to MPLS packets with forwarding tags, the method addresses IP ACL-induced communication issues in container networking, enhancing inter-container communication efficiency and reliability.
Patent Information
- Application Number
- CN202410057526.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-01-15
- Publication Date
- 2025-07-15
AI Technical Summary
In container network communication, IP access control list (ACL) rules cause abnormal communication between containers, especially in the same LAN, where IP packets are intercepted.
Multi-protocol tag switching (MPLS) technology is adopted to encapsulate IP packets into MPLS packets, and transmit them between nodes through forwarding tags, circumventing IP ACL interception and realizing cross-node communication.
It reduces the limitations of IP ACL on container IP packets, improves communication capabilities between containers, and reduces communication abnormalities.
Smart Images

Figure CN120321175A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of container communication technology, and in particular, to a container communication method, an electronic device, and a medium. Background Art
[0002] Currently, the communication of container networks between different nodes all adopts the transmission mode of IP packets. For nodes where containers are located in the same local area network, ipv4 or ipv6 packet routing lookup methods are used to send IP packets. For nodes where containers are located in different local area networks, IP tunneling is used to send IP packets.
[0003] In a real production environment, for network security, even for node communication in the same local area network, IP access control list (ACL) rules are set in routers and switches to filter IP packets, resulting in some IP packets sent by containers being intercepted, thus causing abnormal communication between containers. Summary of the Invention
[0004] This application proposes a container communication method, an electronic device, and a medium, aiming to reduce the restrictions of IP ACL on container IP packets and improve the communication ability between containers.
[0005] To achieve the above object, the first aspect of this application provides a container communication method, which is applied to a first node. The method includes:
[0006] Obtain the destination address information of the IP packet to be forwarded in the source container, where the destination address information is the global address information of the destination container located in the second node, and the source container is configured in the first node;
[0007] Determine a forwarding label according to the destination address information;
[0008] Encapsulate the IP packet according to the forwarding label to obtain an MPLS packet;
[0009] Send the MPLS packet to the next-hop node, so that the next-hop node sends the MPLS packet to the destination container according to the forwarding label.
[0010] To achieve the above object, the second aspect of this application provides a container communication method, which is applied to a second node. The method includes:
[0011] Receive an MPLS packet, where the MPLS packet includes a forwarding label;
[0012] When the label value of the forwarding label is the first label value, perform label pop-up on the MPLS packet to obtain an IP packet, where the IP packet includes destination address information, and the destination address information is the global address information of the destination container, and the destination container is located in the second node;
[0013] Forward the IP packet to the destination container according to the destination address information.
[0014] To achieve the above object, a third aspect of the present application provides a container communication method, which is applied to a third node, and the method includes:
[0015] Receive an MPLS packet, where the MPLS packet includes a forwarding label and an IP packet to be forwarded to a destination container, and the destination container is configured in a second node;
[0016] When the label value of the forwarding label is the second label value, determine a target forwarding label according to the forwarding label;
[0017] Replace the forwarding label in the MPLS packet with the target forwarding label, and send the MPLS packet with the replaced label to the next-hop node according to the target forwarding label.
[0018] To achieve the above object, a fourth aspect of the embodiments of the present application proposes an electronic device, which includes a memory and a processor, the memory stores a computer program, and when the processor executes the computer program, the method described in any one of the first to third aspects above is implemented.
[0019] To achieve the above object, a fifth aspect of the embodiments of the present application proposes a computer-readable storage medium, which stores a computer program, and when the computer program is executed by a processor, the method described in any one of the first to third aspects above is implemented.
[0020] In the embodiments of the present application, the destination address information of the IP packet to be forwarded in the source container is obtained through the first node, and the forwarding label is determined according to the destination address information; the IP packet is encapsulated according to the forwarding label to obtain an MPLS packet; the MPLS packet is sent to the next-hop node, so that the next-hop node sends the MPLS packet to the destination container according to the forwarding label. In this way, by encapsulating the IP packet of the source container into an MPLS packet and sending it to the next-hop node, the restriction of the IP ACL set in the subsequent nodes including the next-hop node on the IP packet of the source container is reduced, and the communication ability between containers is improved, thereby reducing the situation of abnormal communication between containers caused by the node IP ACL. Description of the Drawings
[0021] Figure 1 is a schematic diagram of the steps of a container communication method provided by an embodiment of the present application;
[0022] Figure 2 is Figure 1 a schematic diagram of the steps of a sub-step embodiment of step S102 in
[0023] Figure 3 is a schematic diagram of the steps of a container communication method provided by another embodiment of the present application;
[0024] Figure 4 is a schematic diagram of the structure of a first node provided by an embodiment of the present application;
[0025] Figure 5 is a schematic diagram of the steps of a container communication method provided by another embodiment of the present application;
[0026] Figure 6 is Figure 5 a schematic diagram of the steps of a sub-step embodiment of step S402 in
[0027] Figure 7 is a schematic diagram of the structure of a second node provided by an embodiment of the present application;
[0028] Figure 8 is a schematic diagram of the steps of a container communication method provided by another embodiment of the present application;
[0029] Figure 9 is a schematic diagram of the steps of a container communication method provided by another embodiment of the present application;
[0030] Figure 10 is a schematic diagram of the structure of a third node provided by an embodiment of the present application;
[0031] Figure 11 is a step interaction diagram provided by a general embodiment of the present application;
[0032] Figure 12 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0033] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0034] It should be noted that, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the technical field to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0035] Currently, the communication of container networks between different nodes all adopts the transmission mode of IP packets. For nodes where containers are located in the same local area network, ipv4 or ipv6 packet routing lookup methods are used to send IP packets. For nodes where containers are located in different local area networks, the IP tunneling method is used to send IP packets.
[0036] In a real production environment, for network security, even for node communication in the same local area network, IP access control list (ACL) rules are set in routers and switches to filter IP packets, resulting in some IP packets sent by containers being intercepted, thus causing abnormal communication between containers.
[0037] Based on this, the embodiments of this application propose a container communication method, an electronic device, and a medium, aiming to reduce the restrictions of IP ACL on container IP packets and improve the communication ability between containers.
[0038] First, the nouns appearing in this application are explained:
[0039] Multi-Protocol Label Switching (MPLS): A new technology that uses labels to guide the high-speed and efficient transmission of data on an open communication network. This technology combines the characteristics of layer 2 switching and layer 3 routing, organically combining the layer 2 infrastructure and layer 3 routing. Layer 3 routing is implemented at the edge of the network, while layer 2 switching is used in the MPLS network core. MPLS realizes packet forwarding through label switching at each node. It does not change the existing routing protocols and can be implemented on various layer 2 physical media. Currently, there are media such as ATM, FR (Frame Relay), Ethernet, and PPP. Through MPLS, layer 3 routing can be well complemented by layer 2 technology, giving full play to the good traffic design management of layer 2 and the flexibility of layer 3 "Hop-By-Hop" routing to achieve end-to-end QoS guarantee.
[0040] A container communication method, an electronic device, and a medium provided by the embodiments of this application are specifically described through the following embodiments. First, a container communication method provided in the first aspect of the embodiments of this application is described.
[0041] It should be noted that the first node, the second node, and the third node mentioned in this application are used to refer to node identities. For the same node, when the node needs to send out the IP packets generated by the internal container, at this time, the node is the first node, and it can be artificially determined as the source node in the MPLS technology architecture according to the steps executed by the first node; when the node needs to forward IP packets or MPLS packets outward, at this time, the node is the third node, and it can be artificially determined as the intermediate node in the MPLS technology architecture according to the steps executed by the third node; when the node needs to receive IP packets and forward them to the internal container, or de-encapsulate the MPLS packets and forward them to the internal container, at this time, the node is the second node, and it can be artificially determined as the end node in the MPLS technology architecture according to the steps executed by the second node.
[0042] Please refer to Figure 1 , Figure 1 which is a schematic diagram of the steps of the container communication method provided by an embodiment of this application. In the embodiment of this application, the container communication method is applied to the first node, and the method includes but is not limited to the following steps.
[0043] Step S101, obtain the destination address information of the IP packet to be forwarded in the source container.
[0044] Step S102, determine the forwarding label according to the destination address information.
[0045] Step S103, encapsulate the IP packet according to the forwarding label to obtain an MPLS packet.
[0046] Step S104, send the MPLS packet to the next-hop node so that the next-hop node sends the MPLS packet to the destination container according to the forwarding label.
[0047] It should be noted that the destination address information here is the global address information of the destination container located at the second node, and the source container is configured in the first node.
[0048] For the source container, when it needs to perform network communication with the destination container, the source container needs to send an IP packet to the destination container. Since the container encapsulates the network inside the first node, when the destination container is configured in the second node, cross-node communication between the source container and the destination container is required, and at this time, communication at the physical level of the nodes is involved. When communicating between nodes, IP ACL is enabled, and IP ACL will intercept the IP packet according to the specific address information. In order to ensure that the IP packet sent by the source container is not affected by the IP ACL in each subsequent node during the transmission process, it is necessary to use the MPLS protocol for packet transmission to avoid the IP packet interception performed by the IP ACL. Therefore, it is necessary to convert the IP packet to be sent into an MPLS packet before the packet sending and receiving at the node level can be achieved.
[0049] Based on this, when the source container needs to send an IP packet to the destination container, the first node becomes the source node in the MPLS technology architecture, and the second node becomes the end node in the MPLS technology architecture. The first node needs to first obtain the IP packet to be forwarded in the source container. Since the IP packet carries the destination address information indicating the destination container, the first node can extract the address information from the IP packet to obtain the destination address information of the IP packet.
[0050] Since the node networks to which the first node and the second node belong perform packet sending and receiving between nodes through the MPLS technology, when the node network is networked, an MPLS tunnel is established based on any two nodes as the source and end nodes. For each MPLS tunnel, along the direction from the end node to the source node in the tunnel, the end node assigns a forwarding label to the source node and each intermediate node. Therefore, each node will record the one or more label values corresponding to each MPLS tunnel to which it belongs in one or more tables, so as to use the forwarding label to achieve MPLS packet sending and receiving between nodes with other nodes. It should be noted that an MPLS tunnel includes one or more Label Switched Paths (LSPs).
[0051] Based on this, the second node where the corresponding destination container is located can be queried through the destination address information corresponding to the IP packet, and then the MPLS tunnel corresponding to the first node as the source node and the second node as the end node is queried to determine the next-hop node, and the label assigned to the next-hop node in this MPLS tunnel is determined as the forwarding label. The forwarding label is encapsulated into the IP packet to obtain an MPLS packet.
[0052] In the MPLS technology, except for the source node and the end node, other nodes do not extract the data part in the MPLS packet, nor analyze the destination address information in the IP packet. The first node can directly send the MPLS packet formed from the IP packet to the next-hop node without considering the impact of the IP ACL in the next-hop node on the IP packet, thereby avoiding the interception of the IP packet sent by the source container by the IP ACL in the next-hop node, and enabling the next-hop node to continue sending the IP packet in the form of an MPLS packet to the destination container according to the forwarding label, so that after receiving the MPLS packet, the second node sends the complete IP packet sent by the source container to the destination container.
[0053] In the embodiment of the present application, by encapsulating the IP packet of the source container into an MPLS packet and sending it to the next-hop node, the restriction of the IP ACL set in the subsequent nodes including the next-hop node on the IP packet of the source container is reduced, and the communication ability between containers is improved, thereby reducing the abnormal communication between containers caused by the node IP ACL.
[0054] It should be noted that the IP packets here are diverse and can be IP packets of the ipv4 protocol or IP packets of the ipv6 protocol. The embodiments of the present application do not limit this.
[0055] It should be noted that the specific form of the next-hop node here is diverse, so that sending the MPLS packet to the destination container can have but is not limited to the following embodiments.
[0056] In one embodiment, the next-hop node is the second node as the end node, and the MPLS packet is directly sent to the second-hop node.
[0057] In one embodiment, the next-hop node is an intermediate node. The next-hop node performs label replacement or label popping according to the forwarding label corresponding to the next two-hop node relative to the first node, thereby sending the MPLS packet to the second node.
[0058] It should be noted that the specific form of each node recording one or more label values corresponding to each MPLS tunnel it belongs to is diverse and can be the following embodiments or other embodiments. The embodiments of the present application do not limit this.
[0059] In one embodiment, for a certain node in a node network, the node belongs to an edge device (Label Edge Router, LER) in the node network. At this time, the node will not act as an intermediate node in any MPLS tunnels formed by the node network. Therefore, the node can record, in each MPLS tunnel where it is the end node, the label values (i.e., incoming labels) corresponding to one or more upstream nodes, and in each MPLS tunnel where it is the source node, the label values (i.e., outgoing labels) corresponding to one or more downstream nodes.
[0060] In one embodiment, for a certain node in a node network, the node belongs to a switching device (Label Switching Router, LSR) in the node network. At this time, the node can act as an intermediate node in some of the MPLS tunnels formed by the node network. Therefore, the node can record, in each MPLS tunnel where it is the end node, the label values (i.e., incoming labels) corresponding to one or more upstream nodes, and in each MPLS tunnel where it is the source node, the label values (i.e., outgoing labels) corresponding to one or more downstream nodes, and in each MPLS tunnel where it is the intermediate node, the label values corresponding to one or more upstream nodes and one or more downstream nodes in each MPLS tunnel.
[0061] In one embodiment, due to special requirements, some nodes are set to only act as source nodes for sending MPLS packets, and other nodes need to send packets to these nodes through other network protocols. At this time, these nodes act as source nodes in their respective corresponding MPLS tunnels to communicate with other nodes. Therefore, for each of these nodes, the node can record the label values corresponding to one or more downstream nodes in each MPLS tunnel.
[0062] In one embodiment, due to special requirements, some nodes are set to only act as end nodes for receiving MPLS packets, and other nodes need to receive packets sent by these nodes through other network protocols. At this time, these nodes act as end nodes in their respective corresponding MPLS tunnels to communicate with other nodes. Therefore, for each of these nodes, the node can record the label values corresponding to one or more upstream nodes in each MPLS tunnel.
[0063] In one embodiment, due to special requirements, some nodes are set to only forward MPLS packets as intermediate nodes, and the packets generated locally by the nodes need to be sent through other network protocols. At this time, these nodes communicate with other nodes as intermediate nodes in their respective corresponding MPLS tunnels. Therefore, for each of these nodes, the node can record the label values corresponding to one or more upstream nodes and one or more downstream nodes in each MPLS tunnel.
[0064] It should be noted that the specific form of recording the label values in one or more tables is diverse. Exemplarily, such as multi-table recording based on nodes, recording all the incoming label values and outgoing label values corresponding to a hop node in the same table; or, a node only sets one table and records all the incoming label values and outgoing label values learned by itself in the same table, etc. The embodiments of the present application do not limit this.
[0065] It should be noted that the local area networks to which the first node and the second node belong may be the same or different, and there may be but are not limited to the following embodiments according to the local area networks to which they belong.
[0066] In one embodiment, the first node and the second node are located in the same local area network, and the first node and the second node are connected to the same layer-2 switch or the same router. After the layer-2 switch or the router enables the MPLS protocol, it can send the MPLS packets of the first node to the next-hop node and filter the IP packets through the set IP ACL. It should be noted that the layer-2 switch or the router here can act as the third node (i.e., the intermediate node) or the direct connection device of the first node and the second node. The embodiments of the present application do not limit this.
[0067] In one embodiment, the first node and the second node are located in different local area networks. The first node is connected to the first layer-2 switch, and the second node is connected to the second layer-2 switch. The first layer-2 switch and the second layer-2 switch are connected to a layer-3 switch or a layer-3 router. All the switches and routers enable the MPLS protocol, so as to transmit the MPLS packets to the next-hop node located in the same local area network or different local area networks until the last node (i.e., the second node) receives the MPLS packets.
[0068] In one embodiment, the first node and the second node are located in different local area networks, and the first node and the second node are connected to the same router. After the router enables the MPLS protocol, it can directly send the MPLS packets of the first node to the second node in a different local area network and filter the IP packets through the set IP ACL.
[0069] In one embodiment, the first node and the second node are located in different local area networks. The first node and the second node are connected to the same router. After the router enables the MPLS protocol, it can directly send the MPLS packets of the first node to the second node in a different local area network, and filter the IP packets through the set IP ACL.
[0070] In one embodiment, the first node and the second node are located in different local area networks. The first node is connected to the first router, and the second node is connected to the second router. The first router and the second router are connected to each other or connected to an additional router. All routers enable the MPLS protocol, so as to transmit the MPLS packets to the next-hop node located in the same local area network or different local area networks until the last node (i.e., the second node) receives the MPLS packets.
[0071] It should be noted that the specific method of determining the forwarding label according to the destination address information here is diverse. It can be the following embodiments or other embodiments. The embodiments of the present application do not limit this.
[0072] In one embodiment, the first node establishes a Forwarding Information Base (FIB), a Next Hop Label Forwarding Entry (NHLFE), and an Incoming Label Map (ILM) through the MPLS protocol. For the first node as the source node, the first node queries the FIB entry according to the destination address information to determine the target Tunnel ID corresponding to the destination address information. The source node in the MPLS tunnel corresponding to the target Tunnel ID is the first node, and the last node is the second node. Find the corresponding NHLFE entry according to the target Tunnel ID, and determine the outgoing label in the corresponding NHLFE entry as the forwarding label.
[0073] Please refer to Figure 2 , Figure 2 is Figure 1 a schematic diagram of the steps of a sub-step embodiment of step S102 in. In one embodiment, step S102 includes but is not limited to the following sub-steps.
[0074] Step S201, obtain the label forwarding table corresponding to the destination address information locally.
[0075] Step S202, use the outgoing label corresponding to the next-hop node as the forwarding label.
[0076] It should be noted that the label forwarding table here includes label forwarding path information, and the label forwarding path information includes the outgoing label corresponding to the next-hop node.
[0077] It should be noted that in the MPLS technology, relevant information such as the outgoing interface information and incoming label is required. This information can be stored in the label forwarding path information or can be stored using another table. The embodiments of the present application do not make any limitations in this regard. For the convenience of description, the following embodiments of the present application will all take the case where the relevant information such as the outgoing interface information and incoming label is stored in the label forwarding path information as an example for the subsequent description of the embodiments. For the multi-table storage embodiments, the corresponding additional table lookup operations can be referred to the following embodiments and added.
[0078] Specifically, each node in the node network stores a label forwarding table in the same format, and the label forwarding path information of the label forwarding table stores information related to the tunnel ID. For the first node, first, it is necessary to query the MPLS tunnel according to the destination address to determine the corresponding MPLS tunnel, and retrieve the information related to the tunnel ID from the locally stored label forwarding table according to this MPLS tunnel, so as to determine the label forwarding table corresponding to the MPLS tunnel, and determine the outgoing label included in the label forwarding path information in the table as the forwarding label.
[0079] It should be noted that the specific form of the information related to the MPLS tunnel here is diverse. It can be the following embodiments or other embodiments. The embodiments of the present application do not make any limitations in this regard.
[0080] In one embodiment, the information related to the tunnel ID here is the tunnel ID. The first node queries the FIB table to obtain the target tunnel ID of the MPLS tunnel corresponding to itself as the source node and the second node as the end node and determines the next-hop node used, and retrieves the information from the locally stored label forwarding table according to the target tunnel ID and the next-hop node, so as to determine the label forwarding table corresponding to both the target tunnel ID and the next-hop node, and determine the outgoing label included in the label forwarding path information in the table as the forwarding label.
[0081] Since the number of LSPs under one MPLS tunnel is not limited, for the same tunnel ID, the next-hop node of the first node in one MPLS tunnel may be one or may be multiple, so that the outgoing label corresponding to the same tunnel ID may be one or may be multiple. The first node determines the unique outgoing label pointed to by the target tunnel ID and the next-hop node used in the current MPLS packet transmission as the forwarding label, so that the first node can send the MPLS packet to the specified next-hop node.
[0082] In one embodiment, the information related to the tunnel ID here is network segment information, which is used to indicate the network segment allocated according to a certain node path in the node network. In this embodiment, in order to be able to specify the specific part or all of the transmission path used by the MPLS packet in this packet transmission, a certain node path in the network is configured as the same network segment. The first node queries the MPLS tunnel corresponding to itself as the source node and the second node as the end node through the FIB table, determines the next-hop node used, determines the network segment to which the next-hop node belongs, and retrieves the information of the local storage label forwarding table according to the network segment and the next-hop node, so as to determine the label forwarding table corresponding to both the target network segment and the next-hop node, and determines the output label in the label forwarding path information in the table as the forwarding label.
[0083] Since the node network is divided into network segments for one or more nodes through network segment configuration, the transmission path in the node network is relatively fixed, so that the node paths included in each LSP in each MPLS are unified in the node network. Based on this, when the first node determines the network segment, since a label forwarding path information stores both network segment information and output label at the same time, the next-hop node actually does not need to first query the tunnel according to the forwarding label of the MPLS and then determine the output label. It only needs to directly query the input label and its own network segment to directly determine the next two-hop nodes relative to the first node and the output labels corresponding to the next two-hop nodes. That is to say, in the process of the first node sending an MPLS packet to the second node, only the first node needs to perform a tunnel query once, and no tunnel query is required in the subsequent MPLS packet sending process.
[0084] It should be noted that in each of the above embodiments of the present application that adopt a label forwarding table and the embodiments that will appear below, the label forwarding table is different from the ILM table and the NHLFE table and does not record the operation type corresponding to the label. Therefore, it is impossible to use the operation type information to instruct the node to perform an action. Instead, the corresponding label operation is determined jointly according to the specific label value of the forwarding label and whether the output label is empty. In the MPLS technical architecture, specific label values are set for the nodes corresponding to the penultimate hop and the last hop. The specific label values of the forwarding labels in the present application follow the original MPLS technical architecture. For the source node, since the IP packet generated by the container does not include a forwarding label and the output label is not set to be empty to indicate that a label push operation (Push) is performed on the IP packet. When the node finds that the forwarding label of the IP packet is empty but the output label is not empty, a label push is performed on the IP packet. For the intermediate node, when the input label is 3 and the output label is set to be empty, a label pop operation (Pop) is performed on the IP packet. When the node finds that the forwarding label of the IP packet is 3 and the output label is empty, a label pop is performed on the IP packet. When the input label is not 3 and is not set to be empty to indicate that a label swap operation (Swap) is performed on the IP packet. When the node finds that the forwarding label of the IP packet is 3 but the output label is not empty, a label swap is performed on the IP packet. For the end node, the output label is set to be empty to indicate that a label pop operation (Pop) is performed on the IP packet. When the node finds that the forwarding label of the IP packet is 0 and the label is empty, a label pop is performed on the IP packet.
[0085] In the embodiment of the present application, the LSPs in the network are path-divided by the network segments stored in the label forwarding path information, so that the MPLS packet transmission of the node network is performed by querying the network segments, enabling the first node to complete the tunnel query of the entire MPLS packet transmission through the network segment query, improving the forwarding performance of subsequent MPLS packets, and thus improving the system throughput between the source container and the destination container.
[0086] In one embodiment, the MPLS packet can be sent to the next-hop node in the following manner: determining the target output interface according to the output interface information and sending the MPLS packet to the next-hop node according to the target output interface.
[0087] In the embodiment of the present application, by using the label forwarding table to replace the original ILM label table and NHLFE table, when the first node generates an MPLS packet, it can directly query the label forwarding table to determine the output label without performing multi-table queries. Compared with the query scheduling of multiple tables, the embodiment of the present application can improve the query speed of the output label, thereby improving the generation speed of MPLS packets and thus improving the system throughput per unit time.
[0088] Note that the specific source of the label forwarding table of the first node can be diverse, which can be the following embodiments or other embodiments.
[0089] In one embodiment, the networks to which the first node and the second node belong are small networks, and the MPLS tunnels are constructed by establishing static LSPs. The label forwarding table is constructed according to the defined MPLS tunnels, and this label forwarding table is uploaded to each node in the network.
[0090] Please refer to Figure 3 , Figure 3 which is a schematic diagram of the steps of the container communication method provided in another embodiment of this application. In one embodiment, the first node is configured with a first node network card. Before step S101, the method further includes but is not limited to the following steps.
[0091] Step S301, perform global address configuration on the first node network card to determine the global address information corresponding to the first node network card.
[0092] Step S302, perform global address configuration for each container in the first node according to the global address information corresponding to the first node network card to determine the global address information corresponding to each container in the first node.
[0093] Step S303, perform container route learning with other nodes in the domain through Interior Gateway Protocols (IGP) to obtain the global address information and route information corresponding to the containers in other nodes in the domain.
[0094] Step S304, obtain one or more label switching paths corresponding to the destination address information according to the Label Distribution Protocol (LDP), and one or more label forwarding path information corresponding to each of the one or more label switching paths.
[0095] Step S305, construct a label forwarding table according to the label forwarding path information.
[0096] For the source container, before sending an IP packet to the destination container, it is necessary to know in advance the destination address information and the MPLS tunnel between the first node and the second node. First, it is necessary to obtain the destination address information through route learning, and during the route learning process, the address information and route information of other containers will also be obtained. According to these route information, an MPLS tunnel is constructed to obtain the MPLS tunnel between the first node and the second node.
[0097] Specifically, perform global address configuration on the loopback network card in the first node to obtain the global address information corresponding to the loopback network card in the first node. According to the global address information corresponding to the loopback network card in the first node, perform global address configuration on the network card of the first node to determine the global address information corresponding to the network card of the first node. According to the global address information corresponding to the network card of the first node, perform global address configuration for each container in the first node to obtain the global address information corresponding to each container in the first node.
[0098] Since each container in the first node configures the global address based on the global address information corresponding to the network card of the first node, there is a binding relationship between the global address information corresponding to each container in the first node and the global address information corresponding to the network card of the first node. Similarly, there is a binding relationship between the global address information corresponding to the network card of the first node and the global address information corresponding to the loopback network card in the first node. Due to the characteristics of the loopback network card, the global address information of the loopback network card can be used as the unique identifier (Router id) of the node, so that the global address information corresponding to the network card of the first node and the global address information corresponding to each container in the first node both carry the unique identifier of the first node.
[0099] Perform container route learning with other nodes in the domain through the Interior Gateway Protocol IGP to obtain the global address information and routing information corresponding to the containers in other nodes in the domain. In this process, the first node obtains the destination address information of the destination container through container route learning.
[0100] After obtaining the routing information, the first node constructs an MPLS tunnel with other nodes in the domain through the Label Distribution Protocol LDP to obtain one or more LSPs, including one or more LSPs corresponding to the destination address information. According to the one or more LSPs corresponding to the destination address information, obtain the one or more label forwarding path information corresponding to each of the one or more LSPs, and thus construct a label forwarding table corresponding to the destination address information based on this label forwarding path information.
[0101] In this process, since LDP distributes labels according to the route, each route will have a label distribution. However, due to the role of the unique identifier, even if there are multiple container routes, in one LSP, the first node will be assigned the same in-label or out-label.
[0102] For example, assume there are a first node, a second node, and a third node in a node network. The third node is an intermediate node. The first node has n source containers, and the second node has only one destination container. In theory, the first node should be assigned n outgoing labels due to the number of containers. However, due to the function of unique identification, the first node is finally assigned only one outgoing label. When any source container in the first node sends an IP packet to the destination container in the second node, this outgoing label is used as the forwarding label.
[0103] In one embodiment, the Interior Gateway Protocol (IGP) used by the first node is the Open Shortest Path First (OSPF) protocol. Through dynamic routing learning and dynamic MPLS tunnel construction, the dynamic topology ability of the node network is improved, making it easier for the node network to perform internal node changes and container changes within nodes.
[0104] In one embodiment, when the label forwarding path information used by the first node includes tunnel IDs, MPLS tunnels are divided according to the source node and the end node of each Label Switched Path (LSP), and corresponding tunnel IDs are assigned to the divided MPLS tunnels.
[0105] In one embodiment, when the label forwarding path information used by the first node includes network segments, the network segments are divided according to the node paths in each LSP to obtain the network segments corresponding to each node path.
[0106] Please refer to Figure 4 , Figure 4 which is a schematic structural diagram of the first node provided in an embodiment of this application. In one embodiment, the source containers in the first node are configured with first container-to-network interface cards (Veth pair), and the first node is configured with a first network plugin and a first node network interface card.
[0107] The first container-to-network interface card (Veth pair) is configured to output the IP packets of the source containers; the first network plugin is configured to encapsulate the IP packets according to the forwarding label to obtain MPLS packets; the first node network interface card is configured to send the MPLS packets to the next-hop node.
[0108] Before setting the first network plugin, the first node network interface card directly encapsulates the IP packets output by the source containers into other types of packets and outputs them externally. For example, the IP packets of the source containers are used as the data part and encapsulated into the IP packets of the first node. In this process, it is difficult to encapsulate the IP packets output by the source containers into MPLS packets. Therefore, it is necessary to set a first network plugin between the first node network interface card and the first container-to-network interface card to implement the above various embodiments.
[0109] Specifically, the first container pair network card includes a first in-container network card and a first out-container network card. The IP packet of the source container is output outside the source container through the first in-container network card and input into the first node through the first out-container network card. The first network plugin creates a container network between the first out-container network card and the first node network card. The first out-container network card inputs the IP packet of the source container into this container network, and encapsulates the IP packet through this network, so as to output the encapsulated MPLS packet to the first node network card.
[0110] Please refer to Figure 5 , Figure 5 which is a schematic diagram of the steps of the container communication method provided by another embodiment of the present application. In this embodiment, the method is applied to the second node, and the method includes but is not limited to the following steps.
[0111] Step S401: Receive the MPLS packet.
[0112] Step S402: When the label value of the forwarding label is the first label value, perform label pop-up on the MPLS packet to obtain the IP packet.
[0113] Step S403: Forward the IP packet to the destination container according to the destination address information.
[0114] It should be noted that the MPLS packet here includes the forwarding label, the IP packet includes the destination address information, the destination address information is the global address information of the destination container, and the destination container is located in the second node.
[0115] In an embodiment, each node in the node network is set to perform label pop-up operation only at the last hop. After the second node receives the MPLS packet from the previous node, the second node will query the forwarding label encapsulated in the MPLS packet to perform the label pop-up action according to the label value of the forwarding label.
[0116] Specifically, when the forwarding label is the first label value, it means that the second node is the last node in the MPLS technology architecture, and the second node needs to perform the label pop-up action on the MPLS packet to obtain the IP packet sent by the source container. Then, according to the destination address information carried in the IP packet, the IP packet is forwarded to the destination container in the second node.
[0117] Since the IP packet of the source container enters the second node in the form of an MPLS packet, the IP ACL set in the second node does not act on the MPLS packet, so that the IP packet of the source container can enter the second node completely without being affected by the IP ACL set in the second node, so that the destination container can obtain the complete IP packet of the source container.
[0118] In the embodiment of the present application, by receiving the MPLS packet encapsulated by the IP packet of the source container and decompressing it to obtain the IP packet of the source container, the restriction of the IP ACL including the node local on the IP packet of the source container is reduced, the communication ability between containers is improved, and thus the situation of abnormal communication between the source container and the destination container caused by the node IP ACL is reduced.
[0119] It should be noted that the specific form of the first tag value here is diverse and is determined according to the IP protocol. When the IP packet sent by the source container is ipv6, the first tag value is "2", and when the IP packet sent by the source container is ipv4, the first tag value is "0".
[0120] It should be noted that the specific form of popping the tag from the MPLS packet here is diverse. Corresponding to the table building method of the first node, it can be the following embodiments or other embodiments, and the embodiments of the present application do not limit this.
[0121] In an embodiment, the second node establishes a FIB table, an NHLFE table, and an ILM table through the MPLS protocol. For the second node as the end node, the second node queries the corresponding ILM table according to the tag value of the forwarding tag. The ILM table records the tag operation type for the MPLS packet. Since the tag operation type corresponding to the first tag value is popping, after the second node pops the forwarding tag, it directly forwards the IP packet to the destination container.
[0122] In an embodiment, when the label forwarding path information used in the first node includes a tunnel ID, the label forwarding path information used in the second node also correspondingly includes a tunnel ID. The second node is provided with an information table for recording the tunnel ID for tunnel query. For the second node, first, it is necessary to perform an MPLS tunnel query according to the destination address to determine the corresponding MPLS tunnel, and retrieve the tunnel ID from the locally stored label forwarding table according to the MPLS tunnel, so as to determine the label forwarding table corresponding to the MPLS tunnel.
[0123] For the second node as the end node, the forwarding tag in the received MPLS packet is the first tag value, and the corresponding output tag is set to be empty. Therefore, when the second node finds that the forwarding tag is the first tag value and the corresponding output tag is empty, it pops the tag from the MPLS packet to obtain the IP packet.
[0124] In an embodiment, when the label forwarding path information used in the first node includes network segment information, the label forwarding path information used in the second node also includes network segment information. Please refer to Figure 6 , Figure 6 For Figure 5Schematic diagram of the steps of a sub-step embodiment of step S402. Step S402 includes but is not limited to the following sub-steps.
[0125] Step S501, obtain local network segment information.
[0126] Step S502, determine the corresponding label forwarding table locally according to the local network segment information and the first label value. Step S503, when the output label is empty, pop the label of the MPLS packet to obtain an IP packet
[0127] It should be noted that the corresponding label forwarding table here includes label forwarding path information, and the label forwarding path information includes an output label corresponding to the next-hop node, network segment information corresponding to the local network segment information, and an input label corresponding to the first label value.
[0128] For the second node, perform network segment retrieval according to the label forwarding table stored locally based on the local network segment information, so as to determine one or more label forwarding tables.
[0129] When there is only one label forwarding table, the label forwarding table is the required label forwarding table. At this time, the second node will still perform input label retrieval according to the forwarding label. Since there is only one label forwarding table, the input label in the label forwarding path information must match the forwarding label. Then, the second node will query the label forwarding path information included in the label forwarding table to determine the output label stored in the label forwarding path information. When the second node finds that the corresponding output label is empty, pop the label of the MPLS packet to obtain an IP packet.
[0130] When there are multiple label forwarding tables, it is necessary to screen the multiple label forwarding tables again through the input label to determine the required label forwarding table. At this time, the second node will perform input label retrieval on these label forwarding tables according to the forwarding label to obtain the label forwarding table with the input label corresponding to the forwarding label. Then, the second node will query the label forwarding path information included in the label forwarding table to determine the output label stored in the label forwarding path information. When the second node finds that the corresponding output label is empty, pop the label of the MPLS packet to obtain an IP packet.
[0131] In the embodiment of the present application, the network segments stored in the label forwarding path information are used to divide the paths of the LSPs in the network, so that the transmission of MPLS packets in the node network is carried out by querying the network segments, enabling the second node to determine the operation of the second node on the forwarding label without performing tunnel query after receiving the MPLS packet, improving the performance of forwarding IP packets to the destination container, and thus improving the system throughput between the source container and the destination container.
[0132] It should be noted that the specific source of the label forwarding table of the second node here can be diverse, which can be the following embodiments or other embodiments.
[0133] In one embodiment, corresponding to the first node, the network to which the first node and the second node belong is a small network. Similarly to the first node, the MPLS tunnel is constructed by establishing a static LSP. According to the defined MPLS tunnel construction label forwarding table, this label forwarding table is uploaded to each node in the network.
[0134] In one embodiment, corresponding to the first node, the second node is configured with a second node network card. Before step S401, the global address of the second node network card is configured to determine the global address information corresponding to the second node network card; according to the global address information corresponding to the second node network card, the global addresses of the respective containers in the second node are configured to determine the global address information corresponding to the respective containers in the second node; the container routing is learned from other nodes in the domain through the Interior Gateway Protocol (IGP) to obtain the global address information and routing information corresponding to the containers in other nodes in the domain; one or more label switching paths corresponding to the destination address information are obtained according to the Label Distribution Protocol (LDP), and one or more label forwarding path information corresponding to the one or more label switching paths are obtained; one or more label forwarding tables are constructed according to the one or more label forwarding path information.
[0135] Specifically, the global address of the loopback network card in the second node is configured to obtain the global address information corresponding to the loopback network card in the second node. According to the global address information corresponding to the loopback network card in the second node, the global address of the second node network card is configured to determine the global address information corresponding to the second node network card. According to the global address information corresponding to the second node network card, the global addresses of the respective containers in the second node are configured to obtain the global address information corresponding to the respective containers in the second node.
[0136] Similar to the first node, since the global addresses of the respective internal containers are configured based on the global address information corresponding to the second node network card, there is a binding relationship between the global address information corresponding to the respective containers in the second node and the global address information corresponding to the first node network card. Similarly, there is a binding relationship between the global address information corresponding to the second node network card and the global address information corresponding to the loopback network card in the first node. Due to the characteristics of the loopback network card, the global address information of the loopback network card can be used as the unique identifier (Router id) of the node. This makes the global address information corresponding to the second node network card and the global address information corresponding to the respective containers in the second node both carry the unique identifier of the second node.
[0137] Perform container routing learning with other nodes in the domain through the Interior Gateway Protocol (IGP) to obtain the global address information and routing information corresponding to the containers in other nodes in the domain. In this process, the first node as the peer obtains the destination address information of the destination container through container routing learning.
[0138] After the second node obtains the routing information, it constructs MPLS tunnels with other nodes in the domain through the Label Distribution Protocol (LDP), obtains one or more Label Switched Paths (LSPs), and obtains the corresponding label forwarding path information according to one or more LSPs corresponding to the destination address information, so as to construct one or more label forwarding tables corresponding to the destination address information according to this label forwarding path information.
[0139] Similarly, in this process, since LDP distributes labels based on routes, each route will have a label distribution. However, due to the role of unique identification, the second node assigns the same label in one LSP according to the container route.
[0140] In one embodiment, corresponding to the first node, when the IGP of the first node is the OSDF protocol and the IGP of the second node also corresponds to the OSDF protocol, through dynamic routing learning and dynamic MPLS tunnel construction, the dynamic topology ability of the node network is improved, making it easier for the node network to perform internal node changes and container changes within the node.
[0141] In one embodiment, when the label forwarding path information used by the second node includes a tunnel ID, the MPLS tunnels are divided according to the source node and the end node of each LSP, and corresponding tunnel IDs are assigned to the divided MPLS tunnels.
[0142] In one embodiment, when the label forwarding path information used by the second node includes network segments, the network segments are divided according to the node paths in each LSP to obtain the network segments corresponding to each node path.
[0143] Please refer to Figure 7 , Figure 7 which is a schematic structural diagram of the second node provided by an embodiment of the present application. In one embodiment, the destination container is configured with a second container pair network card, and the second node is configured with a second network plugin and a second node network card.
[0144] The second container pair network card is configured to receive MPLS packets; the second network plugin is configured to perform label pop-up on the MPLS packets when the label value of the forwarding label is the first label value to obtain IP packets; the second node network card is configured to forward the IP packets to the destination container according to the destination address information.
[0145] Specifically, the second container pair network card includes an in - container network card and an out - of - container network card of the second container. The second node network card receives the MPLS packet sent by the previous hop node to input it into the second node. The second network plugin creates a container network between the out - of - container network card of the second container and the second node network card, and de - encapsulates the MPLS packet through this network, so as to output the IP packet of the source container to the out - of - container network card of the second container. The out - of - container network card of the second container forwards the IP packet of the source container to the in - container network card of the second container, and the in - container network card of the second container inputs the IP packet of the source container into the destination container.
[0146] Please refer to Figure 8 , Figure 8 which is a schematic diagram of the steps of the container communication method provided by another embodiment of this application. In this embodiment, the method is applied to the third node, and the method includes but is not limited to the following steps.
[0147] Step S601: Receive the MPLS packet.
[0148] Step S602: When the label value of the forwarding label is the second label value, determine the target forwarding label according to the forwarding label.
[0149] Step S603: Replace the forwarding label in the MPLS packet with the target forwarding label, and send the MPLS packet after replacing the label to the next hop node according to the target forwarding label.
[0150] It should be noted that in the third node, the MPLS packet includes a forwarding label and an IP packet to be forwarded to the destination container, and the destination container is configured in the second node.
[0151] In one embodiment, corresponding to the embodiment of the second node, each node in the node network is set to perform label pop - up operation only at the last hop. After the third node receives the MPLS packet from the previous node, the third node will query the forwarding label encapsulated in the MPLS packet to perform label replacement action according to the label value of the forwarding label.
[0152] Specifically, when the forwarding label is the second label value, it means that the third node is an intermediate node, and the third node needs to perform label replacement action on the MPLS packet and forward the MPLS packet after replacing the label to the next hop node.
[0153] Since the IP packet of the source container enters the third node in the form of an MPLS packet, similar to the second node, the IP ACL set in the third node cannot intercept the MPLS packet, so that the IP packet of the source container can enter the third node completely without being affected by the IP ACL set in the third node, thus enabling the IP packet of the source container to be forwarded to the next hop node completely.
[0154] In the embodiment of the present application, by receiving an MPLS packet encapsulated by an IP packet of a source container, replacing the forwarding label, obtaining the MPLS packet after replacing the label, and sending it to the next-hop node, the restriction of the IP ACL including the node local on the IP packet of the source container is reduced, the communication ability between containers is improved, and thus the situation of abnormal communication between the source container and the destination container caused by the node IP ACL is reduced.
[0155] It should be noted that the second label value here is a value greater than 3.
[0156] It should be noted that the specific form of label replacement for the MPLS packet here is diverse. Corresponding to the table building methods of the first node and the second node, it can be the following embodiments or other embodiments, and the embodiments of the present application do not limit this.
[0157] In an embodiment, the third node establishes a FIB table, an NHLFE table, and an ILM table through the MPLS protocol. For the third node as an intermediate node, the third node performs tunnel query according to the label value of the forwarding label to obtain the corresponding ILM table. The ILM table records the tunnel ID of the corresponding MPLS tunnel. Query the corresponding NHLFE table according to the tunnel ID. The NHLFE table records the outgoing interface, the next-hop node, the outgoing label, and the label operation type. Determine the outgoing label as the target forwarding label. Thus, perform label replacement on the forwarding label according to the label operation type and the target forwarding label to obtain the MPLS packet after replacing the label.
[0158] In an embodiment, when the label forwarding path information used by the first and second nodes both includes the tunnel ID, and the label forwarding path information used by the third node also includes the tunnel ID. Similarly, the third node is provided with an information table for recording the tunnel ID for tunnel query. For the third node, first, it is necessary to query the target tunnel ID corresponding to the MPLS tunnel according to the forwarding label, and perform information retrieval on the locally stored label forwarding table according to the queried target tunnel ID and the forwarding label, so as to determine the label forwarding table corresponding to both the target tunnel ID and the forwarding label.
[0159] For the third node as an intermediate node, the forwarding label in the received MPLS packet is the second label value, and the corresponding outgoing label is not set to be empty. Therefore, when the third node finds that the forwarding label is the second label value and the corresponding outgoing label is not empty, perform label replacement on the MPLS packet to obtain the MPLS packet after replacing the label.
[0160] In one embodiment, when the label forwarding path information used in the first and second nodes both includes network segment information, the label forwarding path information used in the third node also includes network segment information. In step S402, obtain the local network segment information; determine the corresponding label forwarding table locally according to the local network segment information and the second label value; and determine the outgoing label as the target forwarding label. It should be noted that the corresponding label forwarding table here includes label forwarding path information, and the label forwarding path information includes the outgoing label corresponding to the next-hop node, the network segment information corresponding to the local network segment information, and the incoming label corresponding to the second label value.
[0161] When the forwarding label of the MPLS packet is the second label value, it indicates that the third node is an intermediate node defined in the MPLS technical architecture, and the label of the MPLS packet needs to be replaced. For the third node, perform network segment retrieval according to the local network segment information in the locally stored label forwarding table to determine one or more label forwarding tables.
[0162] When there is only one label forwarding table, the label forwarding table is the required label forwarding table. At this time, the second node will still perform incoming label retrieval according to the forwarding label. Since there is only one label forwarding table, the incoming label in the label forwarding path information must match the forwarding label. Then, the third node will query the label forwarding path information included in the label forwarding table. When the third node finds that the corresponding outgoing label is not empty, determine the outgoing label as the corresponding target forwarding label.
[0163] When there are multiple label forwarding tables, it is necessary to screen the multiple label forwarding tables again through the incoming label to determine the required label forwarding table. At this time, the third node will perform incoming label retrieval on these label forwarding tables according to the forwarding label to obtain the label forwarding table with the incoming label matching the forwarding label. Then, the third node will query the label forwarding path information included in the label forwarding table. When the third node finds that the corresponding outgoing label is not empty, determine the outgoing label as the corresponding target forwarding label.
[0164] The embodiment of the present application divides the LSP in the network through the network segment stored in the label forwarding path information, so that the transmission of the MPLS packet in the node network is carried out by querying the network segment, enabling the third node to determine the operation of the third node on the forwarding label without performing tunnel query after receiving the MPLS packet, improving the performance of forwarding the IP packet to the destination container, and thus improving the system throughput between the source container and the destination container.
[0165] In an embodiment where the label forwarding path information further includes egress interface information, the specific manner of sending the MPLS packet after replacing the label to the next-hop node can be implemented as follows: Determine the target egress interface according to the egress interface information, and send the MPLS packet after replacing the label to the next-hop node through the target egress interface. Specifically, determine the target egress interface according to the egress interface information located in the same label forwarding table as the target forwarding label, and the third node uses the target egress interface to send the MPLS packet after replacing the label to the next-hop node.
[0166] It should be noted that the specific source of the label forwarding table of the third node here can be diverse, and it can be the following embodiments or other embodiments.
[0167] In one embodiment, corresponding to the first and second nodes, the network to which the first node, the second node, and the third node belong is a small network, and the MPLS tunnel is constructed by establishing a static LSP. The label forwarding table is constructed according to the defined MPLS tunnel and uploaded to each node in the network.
[0168] In one embodiment, corresponding to the first and second nodes, the third node is configured with a third node network card. Before step S601, perform global address configuration on the third node network card to determine the global address information corresponding to the third node network card; perform global address configuration on each container in the third node according to the global address information corresponding to the third node network card to determine the global address information corresponding to each container in the third node; perform container route learning with other nodes in the domain through the Interior Gateway Protocol (IGP) to obtain the global address information and routing information corresponding to the containers in other nodes in the domain; obtain one or more label switching paths corresponding to the destination address information and one or more label forwarding path information corresponding to the one or more label switching paths according to the Label Distribution Protocol (LDP); construct one or more label forwarding tables according to the one or more label forwarding path information.
[0169] Specifically, perform global address configuration on the loopback network card in the third node to obtain the global address information corresponding to the loopback network card in the third node, perform global address configuration on the third node network card according to the global address information corresponding to the loopback network card in the third node to determine the global address information corresponding to the third node network card, and perform global address configuration on each container in the third node according to the global address information corresponding to the third node network card to obtain the global address information corresponding to each container in the third node.
[0170] Since the global addresses of each container inside are configured based on the global address information corresponding to the network card of the third node, there is a binding relationship between the global address information corresponding to each container in the third node and the global address information corresponding to the network card of the third node. Similarly, there is a binding relationship between the global address information corresponding to the network card of the third node and the global address information corresponding to the loopback network card in the third node. Due to the characteristics of the loopback network card, the global address information of the loopback network card can be used as the unique identifier (Router id) of the node, which makes the global address information corresponding to the network card of the third node and the global address information corresponding to each container in the third node both carry the unique identifier of the third node.
[0171] Through the Interior Gateway Protocol (IGP), container routing learning is carried out with other nodes within the domain to obtain the global address information and routing information corresponding to the containers in other nodes within the domain. In this process, the third node obtains the destination address information of the destination container through container routing learning.
[0172] After obtaining the routing information, the third node constructs MPLS tunnels with other nodes within the domain through the Label Distribution Protocol (LDP), obtains one or more Label Switched Paths (LSPs), and obtains the corresponding label forwarding path information according to one or more LSPs corresponding to the destination address information, so as to construct one or more label forwarding tables corresponding to the destination address information according to this label forwarding path information.
[0173] Similarly, in this process, since LDP distributes labels based on routes and each route will have a label distribution, but due to the role of the unique identifier, the third node is assigned the same label in one LSP according to container routing.
[0174] In one embodiment, corresponding to the first and second nodes, when the IGP of the first and second nodes is the OSPF protocol and the IGP of the third node is also the OSPF protocol, through dynamic routing learning and dynamic MPLS tunnel construction, the dynamic topology ability of the node network is improved, making it easier for the node network to perform internal node changes and container changes within the node.
[0175] In one embodiment, when the label forwarding path information used by the third node includes a tunnel ID, the MPLS tunnels are divided according to the source node and the end node of each LSP, and corresponding tunnel IDs are assigned to the divided MPLS tunnels.
[0176] In one embodiment, when the label forwarding path information used by the third node includes network segments, the network segments are divided according to the node paths in each LSP to obtain the network segments corresponding to each node path.
[0177] Please refer to Figure 9 , Figure 9Schematic diagram of the steps of the container communication method provided by another embodiment of this application. After step S601, the method further includes but is not limited to the following steps.
[0178] Step S701, when the label value of the forwarding label is the third label value, perform label pop-up on the MPLS packet to obtain an IP packet.
[0179] Step S702, generate a first configuration packet and a second configuration packet.
[0180] Step S703, according to the destination address information, send the first configuration packet, the IP packet, and the second configuration packet to the second node one by one.
[0181] It should be noted that the obtained IP packet includes destination address information, and the destination address information is the address information of the destination container, and the destination container is configured in the second node.
[0182] It should be noted that the first configuration packet is used to add configuration information to the access control list ACL in the second node so that the second node can receive the IP packet, and the second configuration packet is used to delete the configuration information.
[0183] It should be noted that the third label value here is 3.
[0184] In one embodiment, when the label value of the forwarding label is the third label value, it means that the third node is an intermediate node that is the previous hop of the second node. Due to the description meaning of the third label value, the third node needs to perform a label pop-up action locally to forward to the second node by sending an IP packet.
[0185] At this time, there will be a situation where the MPLS packet is forwarded to the third node, and the ACL of the second node rejects the IP packet of the third node, which makes the IP packet of the source container unable to be directly sent to the second node.
[0186] Therefore, a first configuration packet and a second configuration packet different from the form of the IP packet are generated so that the IP packet of the source container can be sent to the second node.
[0187] Specifically, when the label value of the forwarding label is the third label value, perform label pop-up on the MPLS packet to obtain an IP packet, generate a first configuration packet and a second configuration packet different from the form of the IP packet according to the ACL of the second node, and then send the first configuration packet to the second node first, so that the second node adds an ACL to allow the IP packet to enter the second node. At this time, send the IP packet of the source container to the second node, and then send the second configuration packet to the second node to delete the previously added ACL, so as to maintain the original ACL function of the second node.
[0188] In the embodiment of the present application, the ACL in the second node is modified through the first configuration message and the second configuration message, so as to create a receiving window in the second node to receive the IP messages of the source container sent by the third node, and maintain the function of the original ACL.
[0189] Please refer to Figure 10 , Figure 10 which is a schematic structural diagram of the third node provided by an embodiment of the present application. In one embodiment, the third node is configured with a third network plug-in and a third node network card.
[0190] In one embodiment, the third node network card is configured to receive MPLS messages and send the MPLS messages after replacing the labels according to the target forwarding label to the next-hop node; the third network plug-in is configured to determine the target forwarding label according to the forwarding label when the label value of the forwarding label is the second label value, and replace the forwarding label in the MPLS message with the target forwarding label.
[0191] Specifically, the third node network card receives the MPLS message sent by the previous-hop node and inputs it into the third node. The third network plug-in creates a container network in the third node, and replaces the labels of the MPLS message through this network, so as to replace the labels of the received MPLS message, and then outputs the MPLS message after replacing the labels to the third node network card. The third node network card sends the MPLS message after replacing the labels according to the next set of information and the outgoing interface information corresponding to the target forwarding label.
[0192] In one embodiment, the third node network card is configured to receive MPLS messages and send the MPLS messages after replacing the labels according to the target forwarding label to the next-hop node; the third network plug-in is configured to determine the target forwarding label according to the forwarding label when the label value of the forwarding label is the second label value, and replace the forwarding label in the MPLS message with the target forwarding label.
[0193] Specifically, the third node network card receives the MPLS message sent by the previous-hop node and inputs it into the third node. The second network plug-in creates a container network in the third node, and replaces the labels of the MPLS message through this network, so as to replace the labels of the received MPLS message, and then outputs the MPLS message after replacing the labels to the third node network card. The third node network card sends the MPLS message after replacing the labels according to the next set of information and the outgoing interface information corresponding to the target forwarding label. It should be noted that if no container is set in the third node, no third container pair network card is set. If a container is set in the third node, a third container pair network card is configured. When the third node can be configured with a third container pair network card, the received MPLS message is not affected by the third container pair network card.
[0194] Please refer toFigure 11 , Figure 11 It is a step interaction diagram provided for a general embodiment of this application. Specifically, the first node obtains the destination address information of the IP packet to be forwarded in the source container; determines the forwarding label according to the destination address information; encapsulates the IP packet according to the forwarding label to obtain an MPLS packet; and sends the MPLS packet to the third node, so that the third-hop node sends the MPLS packet to the destination container according to the forwarding label.
[0195] The third node receives the MPLS packet; when the label value of the forwarding label is the second label value, determines the target forwarding label according to the forwarding label; replaces the forwarding label in the MPLS packet with the target forwarding label, and sends the MPLS packet after replacing the label to the second-hop node according to the target forwarding label.
[0196] The second node receives the MPLS packet; when the label value of the forwarding label is the first label value, performs label popping on the MPLS packet to obtain an IP packet; and forwards the IP packet to the destination container according to the destination address information.
[0197] An embodiment of this application also provides an electronic device, which includes a memory and a processor. The memory stores a computer program, and when the processor executes the computer program, the above container communication method is implemented. The electronic device can be any intelligent terminal including a tablet computer, an in-vehicle computer, etc.
[0198] Please refer to Figure 12 , Figure 12 which shows the hardware structure of an electronic device in another embodiment. The electronic device includes:
[0199] A processor 1201, which can be implemented in ways such as a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided by the embodiments of this application;
[0200] A memory 1202, which can be implemented in forms such as a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1202 can store an operating system and other application programs. When implementing the technical solutions provided by the embodiments of this specification through software or firmware, the relevant program codes are stored in the memory 1202, and are called by the processor 1201 to execute the container communication method of the embodiments of this application;
[0201] The input / output interface 1203 is used to implement information input and output;
[0202] The communication interface 1204 is used to implement communication interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.);
[0203] The bus 1205 transmits information between various components of the device (such as the processor 1201, the memory 1202, the input / output interface 1203, and the communication interface 1204);
[0204] Among them, the processor 1201, the memory 1202, the input / output interface 1203, and the communication interface 1204 achieve communication connections with each other inside the device through the bus 1205.
[0205] The embodiment of the present application also provides a computer-readable storage medium. This computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the above-mentioned container communication method.
[0206] As a non-transitory computer-readable storage medium, the memory can be used to store non-transitory software programs and non-transitory computer-executable programs. In addition, the memory can include high-speed random access memory, and can also include non-transitory memory, such as at least one magnetic disk storage device, a flash memory device, or other non-transitory solid-state storage devices. In some embodiments, the memory optionally includes a memory remotely set relative to the processor, and these remote memories can be connected to the processor through a network. Examples of the above-mentioned network include but are not limited to the Internet, an enterprise intranet, a local area network, a mobile communication network, and combinations thereof.
[0207] The embodiments described in the embodiments of the present application are for more clearly explaining the technical solutions of the embodiments of the present application, and do not constitute a limitation on the technical solutions provided by the embodiments of the present application. Those skilled in the art know that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided by the embodiments of the present application are equally applicable to similar technical problems.
[0208] Those skilled in the art can understand that the technical solutions shown in the figure do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than those shown in the figure, or combine some steps, or different steps.
[0209] The technical features of the above embodiments can be combined arbitrarily. For the sake of concise description, not all possible combinations of the technical features in the above embodiments are described. However, as long as the combinations of these technical features do not conflict, they should be considered as the scope recorded in this specification.
[0210] In the embodiments of the present application, "at least one" means one or more, and "a plurality" means two or more. "And / or" describes the association relationship of associated objects and indicates that there can be three relationships. For example, A and / or B can represent the situations of existing A alone, existing A and B simultaneously, and existing B alone. Where A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one of the following" and its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, and c can represent: existing a alone, existing b alone, existing c alone, existing a and b simultaneously, existing a and c simultaneously, existing b and c simultaneously, or existing a, b, and c simultaneously, where a, b, and c can be single or multiple.
[0211] In the embodiments of the present application, "indicating" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. If the information indicated by a certain piece of information is called the information to be indicated, then in the specific implementation process, there are many ways to indicate the information to be indicated. For example, but not limited to, the information to be indicated can be directly indicated, such as indicating the information to be indicated itself or the index of the information to be indicated, etc. It is also possible to indirectly indicate the information to be indicated by indicating other information, where there is an association relationship between the other information and the information to be indicated. It is also possible to only indicate a part of the information to be indicated, while the other parts of the information to be indicated are known or pre-agreed. For example, it is also possible to implement the indication of specific information by relying on the arrangement order of each piece of information pre-agreed (such as stipulated in the protocol), thereby reducing the indication overhead to a certain extent.
[0212] In the embodiments of the present application, each term and English abbreviation are exemplary examples given for the convenience of description and should not constitute any limitation to the present application. The present application does not exclude the possibility of defining other terms that can achieve the same or similar functions in existing or future protocols.
[0213] In the embodiments of the present application, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first", "second", and "third" may explicitly or implicitly include one or more of such features.
[0214] The above-described embodiments only represent several implementation manners of the present application, and their descriptions are relatively specific and detailed, but should not be construed as a limitation to the patent scope of the present application. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several deformations and improvements can still be made, and these all belong to the protection scope of the present application.
Claims
1. A container communication method, characterized in that, Applied to the first node, the method includes: Obtain the destination address information of the IP packet to be forwarded in the source container, where the destination address information is the global address information of the destination container located in the second node, and the source container is configured in the first node; Determine a forwarding label according to the destination address information; Encapsulate the IP packet according to the forwarding label to obtain an MPLS packet; Send the MPLS packet to the next-hop node, so that the next-hop node sends the MPLS packet to the destination container according to the forwarding label.
2. The method according to claim 1, wherein The determining a forwarding label according to the destination address information includes: Obtain a label forwarding table corresponding to the destination address information locally. The label forwarding table includes label forwarding path information, and the label forwarding path information includes an output label corresponding to the next-hop node; Use the output label corresponding to the next-hop node as the forwarding label.
3. The method according to claim 2, wherein The first node is configured with a first node network card; Before obtaining the destination address information of the IP packet to be forwarded in the source container, the method further includes: Perform global address configuration on the first node network card to determine the global address information corresponding to the first node network card; Perform global address configuration on each container in the first node according to the global address information corresponding to the first node network card to determine the global address information corresponding to each container in the first node; Perform container route learning with other nodes in the domain through the Interior Gateway Protocol (IGP) to obtain the global address information and routing information of the containers in other nodes in the domain; Obtain one or more label switching paths corresponding to the destination address information according to the Label Distribution Protocol (LDP), and one or more label forwarding path information corresponding to each of the one or more label switching paths; Construct the label forwarding table according to the label forwarding path information.
4. The method according to claim 3, wherein The label forwarding path information further includes: input label, network segment information, and output interface information; The sending the MPLS packet to the next-hop node includes: Determine a target output interface according to the output interface information, and send the MPLS packet to the next-hop node through the target output interface.
5. The method according to any one of claims 1 to 4, characterized in that, The source container is configured with a first container pair network card, the first node is configured with a first network plugin and a first node network card; The first container pair network card is configured to output the IP packet of the source container; The first network plugin is configured to encapsulate the IP packet according to the forwarding label to obtain the MPLS packet; The first node network card is configured to send the MPLS packet to the next-hop node.
6. A container communication method, characterized in that, Applied to the second node, the method includes: Receive an MPLS packet, where the MPLS packet includes a forwarding label; When the label value of the forwarding label is a first label value, perform label popping on the MPLS packet to obtain an IP packet, where the IP packet includes destination address information, and the destination address information is the global address information of the destination container, and the destination container is located in the second node; Forward the IP packet to the destination container according to the destination address information.
7. The method according to claim 6, wherein When the label value of the forwarding label is the first label value, perform label pop-up on the MPLS packet to obtain an IP packet, including: Obtain local network segment information; Determine a corresponding label forwarding table locally according to the local network segment information and the first label value, where the label forwarding table includes label forwarding path information, and the label forwarding path information includes an output label corresponding to the next-hop node, network segment information corresponding to the local network segment information, and an input label corresponding to the first label value; When the output label is empty, perform label pop-up on the MPLS packet to obtain an IP packet.
8. The method according to claim 7, wherein The second node is configured with a second node network card; Before receiving the MPLS packet, the method further includes: Perform global address configuration on the second node network card to determine the global address information corresponding to the second node network card; Perform global address configuration for each container in the second node according to the global address information corresponding to the second node network card to determine the global address information corresponding to each container in the second node; Perform container routing learning with other nodes in the domain through the Interior Gateway Protocol (IGP) to obtain the global address information and routing information corresponding to the containers in other nodes in the domain; Obtain one or more label switching paths corresponding to the destination address information according to the Label Distribution Protocol (LDP), and one or more label forwarding path information corresponding to one or more of the label switching paths; Construct one or more of the label forwarding tables according to one or more of the label forwarding path information.
9. The method according to any one of claims 6 to 8, characterized in that, The destination container is configured with a second container pair network card, the second node is configured with a second network plugin and a second node network card; The second node network card is configured to receive the MPLS packet; The second network plugin is configured to perform label pop-up on the MPLS packet when the label value of the forwarding label is the first label value to obtain the IP packet; The second container pair network card is configured to forward the IP packet to the destination container according to the destination address information.
10. A container communication method, characterized in that, Applied to a third node, the method includes: Receive an MPLS packet, where the MPLS packet includes a forwarding label and an IP packet to be forwarded to a destination container, and the destination container is configured in a second node; When the label value of the forwarding label is the second label value, determine a target forwarding label according to the forwarding label; Replace the forwarding label in the MPLS packet with the target forwarding label, and send the MPLS packet after replacing the label to the next-hop node according to the target forwarding label.
11. The method according to claim 10, wherein When the label value of the forwarding label is the second label value, determining a target forwarding label according to the forwarding label includes: Obtain local network segment information; Determine a corresponding label forwarding table locally according to the local network segment information and the second label value, where the label forwarding table includes label forwarding path information, and the label forwarding path information includes an output label corresponding to the next-hop node, network segment information corresponding to the local network segment information, and an input label corresponding to the second label value; Determine the output label as the target forwarding label.
12. The method according to claim 11, wherein The third node is configured with a third node network card, and the IP packet includes destination address information; Before receiving the MPLS packet, the method further includes: Perform global address configuration on the third node network card to determine the global address information corresponding to the third node network card; Perform global address configuration for each container in the third node according to the global address information corresponding to the third node network card to determine the global address information corresponding to each container in the third node; Perform container route learning with other nodes in the domain through the Interior Gateway Protocol (IGP) to obtain the global address information and routing information corresponding to the containers in other nodes in the domain; Obtain one or more label switching paths corresponding to the destination address information according to the Label Distribution Protocol (LDP), and one or more label forwarding path information corresponding to one or more of the label switching paths; Construct one or more of the label forwarding tables according to one or more of the label forwarding path information.
13. The method according to claim 11, wherein The label forwarding path information further includes: output interface information; Sending the MPLS packet after replacing the label to the next-hop node according to the target forwarding label includes: Determine the target output interface according to the output interface information, and send the MPLS packet after replacing the label to the next-hop node through the target output interface.
14. The method according to claim 10, wherein After receiving the MPLS packet, the method further includes: When the label value of the forwarding label is the third label value, perform label popping on the MPLS packet to obtain an IP packet, where the IP packet includes destination address information, and the destination address information is the address information of the destination container, and the destination container is configured in the second node; Generate a first configuration packet and a second configuration packet, where the first configuration packet is used to add configuration information to the IP access control list in the second node so that the second node receives the IP packet, and the second configuration packet is used to delete the configuration information; Send the first configuration packet, the IP packet, and the second configuration packet to the second node one by one according to the destination address information.
15. The method according to any one of claims 10 to 14, characterized in that The third node is further configured with a third network plugin and a third node network card; The third node network card is configured to receive the MPLS packet, and the third network plugin is configured to perform one of the following: When the label value of the forwarding label is the second label value, determine the target forwarding label according to the forwarding label, and replace the forwarding label in the MPLS packet with the target forwarding label; Or, When the label value of the forwarding label is the third label value, pop the label of the MPLS packet to obtain the IP packet, and generate the first configuration packet and the second configuration packet; The network card of the third node is further configured to perform one of the following: Send the MPLS packet after replacing the label to the next-hop node according to the target forwarding label; Or, According to the destination address information, send the first configuration packet, the IP packet, and the second configuration packet to the second node one by one.
16. An electronic device, characterized in that, The electronic device includes a memory and a processor, the memory stores a computer program, and the processor implements the methods described in claims 1 to 15 when executing the computer program.
17. A computer-readable storage medium storing a computer program, characterized in that, The computer program, when executed by the processor, implements the method described in any one of claims 1 to 15.