Outbound flow control method, device and equipment for containerization application and medium
By obtaining and converting dynamic IP addresses into fixed IP address segments in containerized applications, the problem of Pod outbound traffic cannot be forwarded smoothly is solved, the stability and security of firewall rules are achieved, and the smooth forwarding of outbound traffic is ensured.
Patent Information
- Application Number
- CN202510535476.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-25
- Publication Date
- 2025-07-18
AI Technical Summary
In containerized applications, frequent changes in dynamic IP addresses cause Pod outbound traffic to be unable to be smoothly forwarded to external services. The existing technology requires frequent update of firewall policies, which increases the possibility of misconfiguration or misconfiguration and reduces the security of the firewall.
By acquiring and starting the egress gateway on the target gateway node, establishing communication between the preset container and the egress gateway and firewall, obtaining the dynamic IP address of the egress gateway and converting it into a fixed IP address segment, obtaining and forwarding outbound traffic in real time, avoiding frequent updates of firewall rules.
Improves the security of the firewall, ensures smooth forwarding of outbound traffic to external services, reduces the hassle of updating firewall rules, and enhances network stability and security.
Smart Images

Figure CN120342713A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information security technology, and in particular, to a method, device, equipment and medium for outbound traffic control of containerized applications. Background Art
[0002] With the increasingly complex network security threat situation and the increasingly perfect network structure, firewall devices are deployed between various network regions in large medical industry data centers, and access between regions is securely controlled through firewall policies. A firewall is a network device that separates the internal network from the external network, and the data flow transmitted between networks is judged by the firewall whether it is allowed to continue transmission, thereby protecting the internal network from external attacks and intrusions.
[0003] In a network environment where containerized applications are widely deployed, as a basic unit of a container orchestration platform (such as Kubernetes), the IP address of a Pod is usually dynamically allocated. When a Pod is scaled in or out, rebuilt, or migrated, its IP address will change. Due to the protection of the firewall, after the IP address of the Pod changes, the outbound traffic of the Pod cannot be smoothly forwarded to external services. In order to ensure that the outbound traffic of the Pod is smoothly forwarded to external services, in the prior art, it is necessary to frequently update the firewall policy according to the change of the IP address so that the firewall allows the outbound traffic corresponding to the changed IP address to be transferred out. However, the frequent change of dynamic IP addresses increases the possibility of misconfiguration or omission of configuration, resulting in low security of the firewall.
[0004] Therefore, in the case of frequent changes of dynamic IP addresses, how to make the outbound traffic of the Pod be smoothly forwarded to external services has become an urgent problem to be solved. Summary of the Invention
[0005] In view of this, embodiments of the present invention provide a method, device, equipment and medium for outbound traffic control of containerized applications to solve the problem that the outbound traffic of the Pod cannot be smoothly forwarded to external services in the case of frequent changes of dynamic IP addresses.
[0006] In a first aspect, an embodiment of the present invention provides a method for outbound traffic control of containerized applications, and the outbound traffic control method includes: When processing the outbound traffic of a preset container at a target network gateway node, obtain an egress gateway installed and started on the target network gateway node, establish communication between the preset container and the egress gateway, and communication between the egress gateway and the firewall; Obtain the dynamic IP address of the egress gateway and the fixed IP address segment allowed by the firewall to access external services, and convert the dynamic IP address into the fixed IP address segment; Obtain the real-time outbound traffic of the preset container in real time, and use the fixed IP address segment to forward the real-time outbound traffic to an external service.
[0007] In a second aspect, an embodiment of the present invention provides an outbound traffic control device for a containerized application. The outbound traffic control device includes: An obtaining module, configured to, when a target network gateway processes the outbound traffic of a preset container, obtain an egress gateway installed and started on the target network gateway, establish communication between the preset container and the egress gateway, and communication between the egress gateway and a firewall; A conversion module, configured to obtain the dynamic IP address of the egress gateway and the fixed IP address segment allowed by the firewall to access an external service, and convert the dynamic IP address into the fixed IP address segment; A forwarding module, configured to obtain the real-time outbound traffic of the preset container in real time, and use the fixed IP address segment to forward the real-time outbound traffic to an external service.
[0008] In a third aspect, an embodiment of the present invention provides a computer device, which includes a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the outbound traffic control method described in the first aspect is implemented.
[0009] In a fourth aspect, an embodiment of the present invention provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the outbound traffic control method described in the first aspect is implemented.
[0010] The beneficial effects of the present invention compared with the prior art are as follows: In this application, when a target network gateway processes the outbound traffic of a preset container, an egress gateway installed and started on the target network gateway is obtained, communication between the preset container and the egress gateway, and communication between the egress gateway and a firewall are established; the dynamic IP address of the egress gateway and the fixed IP address segment allowed by the firewall to access an external service are obtained, and the dynamic IP address is converted into the fixed IP address segment; the real-time outbound traffic of the preset container is obtained in real time, and the fixed IP address segment is used to forward the real-time outbound traffic to an external service. Converting the dynamic IP address into the fixed IP address segment allowed by the firewall to access an external service avoids the trouble of frequently updating firewall rules, improves the security of the firewall, and the fixed IP address segment allowed by the firewall to access an external service can avoid the interception of outbound traffic by the firewall, so that the outbound traffic of the preset container can be smoothly forwarded to an external service. Description of the Drawings
[0011] To more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0012] Figure 1 is a schematic flowchart of a method for controlling outbound traffic of a containerized application provided in Embodiment 1 of the present invention; Figure 2 is a schematic structural diagram of a device for controlling outbound traffic of a containerized application provided in the embodiments of the present invention; Figure 3 is a schematic structural diagram of a computer device provided in the embodiments of the present invention. Detailed implementation manners
[0013] The following will clearly and completely describe the technical solutions in the embodiments of the present invention with reference to the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the scope of protection of the present invention.
[0014] In the following description, specific details such as specific system structures and technologies are presented for the purpose of illustration rather than limitation, so as to thoroughly understand the embodiments of the present invention. However, those skilled in the art should clearly understand that the present invention can also be implemented in other embodiments without these specific details. In other cases, detailed descriptions of well-known systems, systems, circuits, and methods are omitted to avoid unnecessary details from interfering with the description of the present invention.
[0015] It should be understood that when used in the specification of the present invention and the appended claims, the term "comprising" indicates the presence of the described features, wholes, steps, operations, elements, and / or components, but does not exclude the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or their combinations.
[0016] It should also be understood that the term " / and" as used in the specification of the present invention and the appended claims refers to any combination and all possible combinations of one or more of the associated listed items, and includes these combinations.
[0017] As used in the specification of the present invention and the appended claims, the term "if" may be construed, depending on the context, as "when", or "once", or "in response to determining", or "in response to detecting". Similarly, the phrase "if determined" or "if [the described condition or event] is detected" may be construed, depending on the context, as meaning "once determined", or "in response to determining", or "once [the described condition or event] is detected", or "in response to detecting [the described condition or event]".
[0018] In addition, in the description of the specification of the present invention and the appended claims, the terms "first", "second", "third", etc. are only used for differentiating descriptions and should not be construed as indicating or implying relative importance.
[0019] Reference to "one embodiment" or "some embodiments" or the like described in the specification of the present invention means that a specific feature, structure, or characteristic described in connection with that embodiment is included in one or more embodiments of the present invention. Thus, statements such as "in one embodiment", "in some embodiments", "in other some embodiments", "in still other embodiments", etc. that appear in different places in this specification do not necessarily all refer to the same embodiment, but mean "one or more but not all embodiments", unless otherwise specifically emphasized in another way. The terms "comprising", "including", "having", and their variants all mean "including but not limited to", unless otherwise specifically emphasized in another way.
[0020] It should be understood that the magnitudes of the sequence numbers of the steps in the following embodiments do not mean the order of execution is prior or subsequent. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present invention.
[0021] In order to illustrate the technical solution of the present invention, specific embodiments will be used for illustration below.
[0022] See Figure 1 , which is a schematic flowchart of a method for controlling outbound traffic of a containerized application provided in the first embodiment of the present invention. As Figure 1 shown, the method for controlling outbound traffic of the containerized application may include the following steps.
[0023] S101: When processing the outbound traffic of a preset container at a target network gateway node, obtain the egress gateway installed and started on the target network gateway node, establish communication between the preset container and the egress gateway, and communication between the egress gateway and the firewall.
[0024] In step S101, the preset container is the basic unit of the container orchestration platform, the target gateway node is the physical network node in the network architecture that realizes the interconnection and interoperability between different protocols, networks or services, and the egress gateway is the core component deployed at the network boundary, responsible for managing the outbound traffic from the internal network to the external network. Establish the communication between the preset container and the egress gateway, so that the outbound traffic of the preset container flows through the egress gateway, and establish the communication between the egress gateway and the firewall to ensure that the outbound traffic of the egress gateway can be sequentially forwarded to the external service.
[0025] In this embodiment, during the diagnosis and treatment process of the patient during the perioperative period, it is often necessary to collect various imaging information of the same patient. Common examples include ultrasound images, surgical images, etc. Different images are often stored in different network systems. Different network systems are secured through firewall policies and then managed by the security management layer. Among them, the security management layer generally uses distributed containers based on kubernetes.
[0026] When the target gateway node processes the outbound traffic (imaging data) of a preset container, obtain the egress gateway installed and started on the target gateway node. Among them, the target gateway node has sufficient network bandwidth and computing resources to process the outbound traffic of the preset container. The preset container is a resource object that runs containerized applications. The egress gateway is the Egress Gateway. The Egress Gateway is a component in the Istio service mesh. Install and start the Egress Gateway component. The EgressGateway is used to manage outbound traffic and provide security and traffic control. Using the Egress Gateway as the egress gateway can be used to manage the traffic from the internal to the external service.
[0027] Among them, the Egress Gateway is the bridge between the services in the service mesh and the external services, and processes all requests from the internal services of the gateway node to the external services. It can act as a load balancer and distribute requests to multiple external service instances. The Egress Gateway records all requests passing through it for monitoring, logging, and tracing.
[0028] In this embodiment, by configuring the network policy of the preset container, establish the communication between the preset container and the egress gateway to ensure that the outbound traffic of the preset container flows through the egress gateway. By configuring the communication tunnel between the egress gateway and the firewall, establish the communication between the egress gateway and the firewall to ensure that the outbound traffic can be forwarded to the external service.
[0029] It should be noted that when establishing communication between the egress gateway and the firewall, a communication tunnel between the egress gateway and the firewall is configured, that is, the basic network parameters of the firewall device are configured to ensure communication with the Egress Gateway. When configuring the basic network parameters of the firewall device, first determine the network location of the egress gateway, that is, the network location of the Egress Gateway, then configure the interfaces and routes, and then set the security policies and NAT.
[0030] For example, divide the exclusive area of the egress gateway according to the network location of the egress gateway, that is, divide the exclusive area of the Egress Gateway. Create an independent security area (such as egress-zone) in the firewall, and include the physical interface connecting to the egress gateway, that is, the physical interface connecting to the Egress Gateway (such as GigabitEthernet1 / 0 / 0) into this area, and configure the IP address of the same network segment as the egress gateway, that is, the IP address of the same network segment as the Egress Gateway. Open the ICMP protocol and HTTP / HTTPS ports (such as 80, 443) of the interface to ensure basic communication reachability. Configure a static default route to direct the outbound traffic with the destination address of the external service to the IP address of the egress gateway node (such as 192.168.1.254). Create a security policy to allow the outbound traffic to be forwarded to the external service.
[0031] Optionally, before obtaining the egress gateway installed and started on the target gateway node, it further includes: Configure the routing rules of the preset container to make the outbound traffic of the preset container pass through the egress gateway.
[0032] In this embodiment, configure the routing rules of the preset container to make the outbound traffic of the preset container pass through the egress gateway. First, enable egress isolation, create a network policy object to restrict the outbound traffic of the preset container to only allow traffic to flow to the Service or Pod of the egress gateway, and prohibit direct access to the external network. It should be noted that if it is necessary to allow the outbound traffic of some preset containers to bypass the egress gateway (such as internal service communication), it can be finely controlled through podSelector or namespaceSelector. Then include the external domain name (such as *.example.com) into the service mesh management through ServiceEntry and bind it to the egress gateway, and configure the VirtualService routing rules to force the outbound traffic to pass through the egress gateway node.
[0033] It should be noted that if the preset container is a Pod container in the Kubernetes cluster, in the Kubernetes cluster, the K8S CNI model defines a series of interface specifications related to container network configuration. Based on these specifications, container network function developers can develop CNI network plugins by themselves to implement the standard functions and custom extension functions required by K8S. Based on the custom extension ability provided by the CNI specification, we can develop a plugin specifically for configuring custom routes for containers. The plugin name is IRoute-CNI, and the specified route information is configured into the container. In the process of container creation, the core management component - Kubelet component in K8S can read the CNI plugin list from a specific configuration file and execute each CNI plugin in sequence. These plugins are used to set network-related information for the container. The CNI plugin related to multiple network cards of the container creates multiple network cards for the container based on this mechanism. Therefore, we can write the relevant information of IRoute-CNI into this configuration file (at the end), and Kubelet calls IRoute-CNI to set the routing rules at the last stage of setting the container network. In this technical solution, the whole process is realized by Kubelet scheduling, and there is no need to open the permission to operate the routing rules for the container itself, thus avoiding security problems.
[0034] In specific implementation, the IRoute-CNI plugin consists of two parts: iroute-config configuration and iroute-cni binary. iroute-config is used to configure routing rules. It is stored in the specified directory of each node of the K8S container cloud platform in the form of yaml, and the name is iroute-config.yaml. The iroute-cni binary file is used to set custom routes for the container. It is stored in the fixed directory of each node of the K8S container cloud platform and is called by kubelet to execute the routing setting during the container creation process. It will dynamically load the configuration information in iroute-config, query the corresponding routing information according to the namespace where the container is located, and set it into the container.
[0035] The container custom routing configuration method provided in this embodiment is applied to a preset plugin, that is, the IRoute-CNI plugin, which receives the request information sent by the Kubelet component. In specific implementation, the request information is container creation-related information, and the configuration file includes multiple routing rules and corresponding namespaces.
[0036] The iroute-cni binary of the IRoute-CNI plugin obtains the configuration file by loading the iroute-config configuration. The configuration file stores specific custom routing information, which includes namespaces and routing rules.
[0037] In this embodiment, routing rules of a preset container are configured so that the outbound traffic of the preset container passes through the egress gateway, facilitating the management of the outbound traffic of the preset container by the egress gateway.
[0038] S102: Obtain the dynamic IP address of the egress gateway and the fixed IP address segment allowed by the firewall to access external services, and convert the dynamic IP address into the fixed IP address segment.
[0039] In step S102, the dynamic IP address of the egress gateway is the dynamic IP address after the IP address changes due to scaling, reconstruction, or migration of the preset container, and the fixed IP address segment is the address segment allowed by the firewall to access external services.
[0040] In this embodiment, the preset container is a basic unit in a Kubernetes cluster. Among them, Kubernetes (also known as k8s), as a portable and scalable open-source platform, provides a framework for running distributed systems elastically, promotes declarative configuration and automation, and its services, support, and tools are widely used. In the Kubernetes platform, the smallest resource management component is the pod (container group). A pod can run one or more containers. Containers under the same pod must run on the same node. Each pod will be assigned a unique IP address. All containers under it share the network space, including the IP address and ports. Moreover, containers inside the pod can communicate with each other using localhost.
[0041] Before obtaining the dynamic IP address after the IP address changes due to scaling, reconstruction, or migration of the preset container, it is necessary to deploy the Kubernetes cluster. Calico can be deployed as a Kubernetes cluster network plugin. Among them, Calico is a pure three-layer data center network solution that supports using the BGP (Border Gateway Protocol) dynamic protocol for route exchange. In the BGP mode, Calico uses each computing node of the Kubernetes cluster as a virtual router to maintain the container route information table on the host, and then spreads it to the entire Calico network through the BGP protocol to realize the mutual exchange of container route information in the cluster. When a route reflector is configured and a BGP neighbor is established with the physical network core switch (or router) enabled with the BGP protocol, the IP address of the preset container can be announced to the entire physical network and route exchange can be performed, thereby realizing the exposure of containers in the cluster to the outside of the cluster, that is, the route from outside the cluster to containers in the cluster is reachable.
[0042] Allocate a dynamic IP resource pool for the Kubernetes cluster. This dynamic IP resource pool is used by Calico IPAM to automatically assign IP addresses to containers in the normal release (non-fixed IP release) mode. After the preset container is automatically assigned an IP address, the outbound traffic of the corresponding preset container flows through the egress gateway to determine the dynamic IP address of the corresponding egress gateway, that is, the IP address automatically assigned to the preset container.
[0043] When obtaining the fixed IP address segment allowed by the firewall to access external services, the fixed IP address segment needs to ensure that it does not conflict with the existing network. It is recommended to use private network addresses (such as 192.168.1.0 / 24 or 10.0.0.0 / 8) etc., to avoid overlapping with the Dynamic Host Configuration Protocol (DHCP) address pool. For example, if the DHCP allocation range is 192.168.1.100 - 200, the fixed IP address segment can be set to 192.168.1.50 - 99.
[0044] Before obtaining the fixed IP address segment allowed by the firewall to access external services, define an Access Control List (ACL), create a rule in the firewall to allow the fixed IP segment to access external services. For example, to allow the 192.168.1.0 / 24 network segment to access all external services, it needs to be bound to the external network interface and the Network Address Translation (NAT) function needs to be enabled.
[0045] Restrict access to external services to only the fixed IP address segment through AuthorizationPolicy: When converting the dynamic IP address to the fixed IP address segment, Source Network Address Translation (SNAT) can be performed. SNAT is used to convert the private IP address (dynamic IP address) of the internal network host to the public IP address (fixed IP address segment), enabling internal network devices to access the external network through a unified egress.
[0046] In this embodiment, obtain the dynamic IP address of the egress gateway and the fixed IP address segment allowed by the firewall to access external services, and convert the dynamic IP address to the fixed IP address segment. This makes it possible to only configure the fixed IP address segment in the firewall device, without having to pay attention to the changes in the container IP addresses and without having to frequently update the policies in the firewall device, thus avoiding the trouble of frequently updating the firewall rules.
[0047] Optionally, before converting the dynamic IP address to the fixed IP address segment, it further includes: Write an eBPF program, which is used to convert the dynamic IP address to the fixed IP address segment; Load the eBPF program at the egress gateway.
[0048] In this embodiment, an eBPF (extended Berkeley Packet Filter) program is written. Here, eBPF (Extended BPF) is a kernel technology in Linux 4.x+ and is equivalent to a lightweight sandbox virtual machine. The eBPF program runs inside the Linux kernel and can provide verified access to kernel memory. eBPF allows the kernel to run BPF bytecode. Although the front-end language used can be different, it is usually a restricted subset of the C language. Usually, Clang is first used to compile the C code into BPF bytecode, and then the bytecode is verified to ensure its safe execution. These strict verifications ensure that the machine code will not deliberately or accidentally endanger the Linux kernel, and ensure that the BPF probe can be executed in a certain number of instructions each time it is triggered. These guarantees enable eBPF programs to be used in performance-critical workloads such as packet filtering and network monitoring.
[0049] The eBPF program can be written using code tools, and then the written program is loaded into the Linux system kernel through bpf(). The injection program bpf_load_program() incorporates a more complex verifier mechanism. Before running the injection program, a series of security checks can be performed to maximize the security of the system. The bpf bytecode that passes the security checks is compiled using the kernel JIT to generate native assembly instructions, which are attached to the program at specific kernel hooks, and finally communicate through an efficient map mechanism. The above eBPF program is written according to the processing requirements for outbound traffic, and the eBPF program is injected into the Linux system kernel.
[0050] It should be noted that the eBPF program runs when a specific event is triggered (such as the arrival of a network packet or the execution of a system call), and directly processes data in the kernel state, improving the processing efficiency of converting a dynamic IP address to a fixed IP address segment. It should be noted that the process of the eBPF program converting a dynamic IP address to a fixed IP address segment is as follows: The eBPF program intercepts network packets and modifies their dynamic IP address header information by attaching to the XDP or TC hook points of the network protocol stack, thereby achieving the conversion of the dynamic IP address to the fixed IP address segment. The specific process is as follows: Dynamic IP address recognition: Obtain the network context of the process through Helper functions such as bpf_get_current_pid_tgid, and match the dynamic IP address assigned by DHCP. Intercept the packet at the XDP layer (data link layer) or TC layer (network layer); Use bpf_skb_store_bytes to modify the source / destination IP fields in the dynamic IP address header and replace them with a predefined fixed IP address segment. And store the mapping relationship between the dynamic IP address and the fixed IP address segment through the eBPF hash table (Hash Map) to support real-time update and query.
[0051] It should be noted that when writing an eBPF program, write the corresponding eBPF program according to the processing requirements of the egress gateway for outbound traffic. For example, when the processing requirement is to convert a dynamic IP address to a fixed IP address segment, use the BCC toolkit to write an eBPF program according to the processing requirements to achieve the conversion of the dynamic IP address to the fixed IP address segment.
[0052] If the processing requirement is to monitor outbound traffic, write an ebpf program for monitoring outbound traffic and load the corresponding eBPF program at the egress gateway. When monitoring outbound traffic, malicious activities can be detected and blocked, intrusion detection and prevention strategies can be implemented, and network security can be improved. In practical applications, in order to distinguish the inbound traffic flowing into the container and the outbound traffic flowing out of the container, the ebpf program includes an inbound traffic monitoring program and an outbound traffic monitoring program. In a specific application scenario, the outbound traffic monitoring program can be implemented through the egressfilter (outbound filtering) of tc (Traffic Control) in Linux. If the processing requirements are to monitor outbound traffic and convert the dynamic IP address to a fixed IP address segment, write an eBPF program for monitoring outbound traffic and converting the dynamic IP address to a fixed IP address segment, and load the eBPF program at the egress gateway to facilitate using the eBPF program to monitor outbound traffic and convert the dynamic IP address to a fixed IP address segment to enhance network security and processing efficiency.
[0053] Optionally, after converting the dynamic IP address to a fixed IP address segment, it further includes: Verify the stability of the conversion of the dynamic IP address to the fixed IP address segment to obtain a verification result; If the verification result is unstable, optimize the eBPF program to obtain the optimized eBPF program, and load the optimized eBPF program at the egress gateway.
[0054] In this embodiment, verify the stability of the dynamic IP address conversion to the fixed IP address segment. Among them, the stability includes the efficiency and accuracy of the dynamic IP address conversion to the fixed IP address segment, ensure the efficiency of the dynamic IP address conversion to the fixed IP address segment, so as to avoid that when the outbound traffic is high-frequency traffic, the dynamic IP address cannot be converted to the fixed IP address segment in time, and ensure that the outbound traffic can access external services in time and safely. Ensure the accuracy of the dynamic IP address conversion to the fixed IP address segment, so as to ensure that the dynamic IP address is converted to the above fixed IP address segment according to the preset rules, so as to ensure that the outbound traffic can access external services through the firewall.
[0055] It should be noted that when verifying the stability of the dynamic IP address conversion to the fixed IP address segment, that is, verifying whether the efficiency and accuracy of the dynamic IP address conversion to the fixed IP address segment meet the corresponding requirements. When both the efficiency and accuracy of the dynamic IP address conversion to the fixed IP address segment meet the corresponding requirements, it is considered that the dynamic IP address conversion to the fixed IP address segment is relatively stable, otherwise, it is considered that the dynamic IP address conversion to the fixed IP address segment is unstable.
[0056] Verify whether the efficiency of the dynamic IP address conversion to the fixed IP address segment meets the preset efficiency requirements. After frequently triggering the reallocation of the dynamic IP address, check the update delay of the mapping table, and judge whether the update delay is less than the preset time threshold. If the update delay is less than the preset time threshold, it is considered that the efficiency of the dynamic IP address conversion to the fixed IP address segment meets the preset efficiency requirements. Verify whether the accuracy of the dynamic IP address conversion to the fixed IP address segment meets the preset accuracy requirements. It can be verified whether the dynamic IP addresses assigned after the preset container scaling and migration are converted to the fixed IP address segment according to the preset rules. If the dynamic IP addresses assigned after the container scaling and migration are all converted to the fixed IP address segment according to the preset rules, it is determined that the accuracy of the dynamic IP address conversion to the fixed IP address segment meets the preset accuracy requirements.
[0057] If the verification result is unstable, optimize the eBPF program to obtain the optimized eBPF program, and load the optimized eBPF program at the egress gateway. Among them, when optimizing the eBPF program, XDP_TX batch packet sending can be enabled at the XDP layer to reduce the overhead of per-packet processing and improve the throughput. IP format verification logic can also be added, and illegal dynamic IPs can directly return XDP_DROP to avoid invalid queries, etc. Other methods can also be used for optimization, which is not limited in this embodiment.
[0058] In this example, when the conversion of a dynamic IP address to a fixed IP address segment is unstable, the eBPF program is optimized to improve the efficiency and stability of the conversion of a dynamic IP address to a fixed IP address segment.
[0059] S103: Obtain the real-time outbound traffic of a preset container in real time, and use a fixed IP address segment to forward the real-time outbound traffic to an external service.
[0060] In step S103, the fixed IP address segment is the address segment allowed by the firewall to access the external service.
[0061] In this embodiment, the real-time outbound traffic of a preset container is obtained in real time. When the real-time outbound traffic flows through the egress gateway, the real-time dynamic IP address corresponding to the egress gateway is determined, and the real-time dynamic IP address is converted into a fixed IP address segment. According to the fixed IP address segment, the outbound traffic corresponding to the fixed IP address segment is allowed to access the external service in the firewall policy. Therefore, the real-time outbound traffic can be forwarded to the external service.
[0062] In this embodiment, the real-time outbound traffic of a preset container is obtained in real time, and a fixed IP address segment is used to forward the real-time outbound traffic to an external service, which can easily cope with the dynamic change of the IP address of the preset container.
[0063] Optionally, before forwarding the real-time outbound traffic to an external service, it further includes: Configure the security group rules for the firewall according to the fixed IP address segment and the IP address of the external service, and determine the firewall policy, so as to forward the real-time outbound traffic to the external service according to the firewall policy.
[0064] In this embodiment, the security group rules are configured for the firewall according to the fixed IP address segment and the IP address of the external service to determine the firewall policy. The security group rules include the matching rules between the fixed IP address segment and the IP address of the external service, as well as the protocol and port rules. The default deny rule is added to block the outbound traffic that does not conform to the above matching rules and prevent unauthorized IP addresses from accessing the external service. The protocol and port rules include the protocol types (TCP / UDP / ICMP) and port ranges allowed by the firewall to access.
[0065] After determining the firewall policy, when it is necessary to forward the real-time outbound traffic to an external service, it is judged whether the IP address corresponding to the real-time outbound traffic meets the matching rules between the fixed IP address segment and the IP address of the external service, and whether the protocol type and port range corresponding to the real-time outbound traffic meet the protocol and port rules. If the rules are met, the real-time outbound traffic is allowed to be forwarded to the external service.
[0066] Optionally, after configuring the security group rules for the firewall based on the fixed IP address segment and the IP address of the external service and determining the firewall policy, the following steps are further included: Test the effectiveness of the firewall policy to verify whether the firewall policy is effective; If the firewall policy is ineffective, adjust the security group rules to ensure the effectiveness of the firewall policy.
[0067] In this embodiment, after determining the firewall policy, test the firewall policy to verify its effectiveness, that is, verify whether the outbound traffic of the fixed IP address segment can access the external service. When testing the firewall policy, a rejection rule can be temporarily added to the firewall policy to verify whether the outbound traffic is blocked. If the outbound traffic is blocked, use nmap to initiate a scan from a preset container. If the port status is filtered, it indicates that the firewall policy is effective. Otherwise, it is determined that the firewall policy is ineffective. If the firewall policy is ineffective, adjust the security group rules, that is, adjust the matching rules for the fixed IP address segment and the IP address of the external service, as well as the protocol and port rules, to ensure the effectiveness of the firewall policy.
[0068] In this application, when the target gateway node processes the outbound traffic of a preset container, obtain the egress gateway installed and started on the target gateway node, establish communication between the preset container and the egress gateway, and communication between the egress gateway and the firewall; obtain the dynamic IP address of the egress gateway and the fixed IP address segment allowed by the firewall to access the external service, and convert the dynamic IP address to the fixed IP address segment; obtain the real-time outbound traffic of the preset container in real time, and use the fixed IP address segment to forward the real-time outbound traffic to the external service. Converting the dynamic IP address to the fixed IP address segment allowed by the firewall to access the external service avoids the trouble of frequently updating the firewall rules, improves the security of the firewall, and the fixed IP address segment allowed by the firewall to access the external service can avoid the interception of the firewall for outbound traffic, enabling the outbound traffic of the preset container to be smoothly forwarded to the external service.
[0069] Please refer to Figure 2 , Figure 2 which is a schematic structural diagram of an outbound traffic control device for a containerized application provided by an embodiment of the present invention. The outbound traffic control device for a containerized application corresponds one-to-one with the outbound traffic control method for a containerized application in the above embodiment. Specifically, please refer to Figure 1 the relevant descriptions in the corresponding embodiments. For the sake of convenience of description, only the parts related to this embodiment are shown. Refer to Figure 2 , the outbound traffic control device 20 includes: an acquisition module 21, a conversion module 22, and a forwarding module 23.
[0070] An acquisition module 21, configured to acquire an egress gateway installed and started on a target gateway node when processing the outbound traffic of a preset container, establish communication between the preset container and the egress gateway, and communication between the egress gateway and a firewall.
[0071] A conversion module 22, configured to acquire the dynamic IP address of the egress gateway and the fixed IP address segment allowed by the firewall to access external services, and convert the dynamic IP address into the fixed IP address segment.
[0072] A forwarding module 23, configured to acquire the real-time outbound traffic of the preset container in real time, and forward the real-time outbound traffic to external services using the fixed IP address segment. Optionally, the above outbound traffic control device 20 further includes: A configuration module, configured to configure the routing rules of the preset container, so that the outbound traffic of the preset container passes through the egress gateway.
[0073] Optionally, the above outbound traffic control device 20 further includes: A writing module, configured to write an eBPF program, and the eBPF program is used to convert the dynamic IP address into the fixed IP address segment.
[0074] A loading module, configured to load the eBPF program on the egress gateway.
[0075] Optionally, the above outbound traffic control device 20 further includes: A verification module, configured to verify the stability of converting the dynamic IP address into the fixed IP address segment to obtain a verification result; An optimization module, configured to optimize the eBPF program if the verification result is unstable to obtain an optimized eBPF program, and load the optimized eBPF program on the egress gateway.
[0076] Optionally, the above outbound traffic control device 20 further includes: A determination module, configured to configure security group rules for the firewall according to the fixed IP address segment and the IP address of the external service, and determine a firewall policy, so as to forward the real-time outbound traffic to the external service according to the firewall policy.
[0077] Optionally, the above outbound traffic control device 20 further includes: A testing module, configured to test the effectiveness of the firewall policy to verify whether the firewall policy is effective.
[0078] An adjustment module, configured to adjust the security group rules if the firewall policy is ineffective to ensure the effectiveness of the firewall policy.
[0079] It should be noted that for the content such as information interaction and execution process among the above units, since it is based on the same concept as the method embodiment of the present invention, for its specific functions and the technical effects brought, reference can be specifically made to the method embodiment part, and details will not be repeated here.
[0080] Figure 3 It is a schematic structural diagram of a computer device provided by an embodiment of the present invention. As Figure 3 shown, the computer device of this embodiment includes: at least one processor ( Figure 3 only one is shown in the figure), a memory, and a computer program stored in the memory and executable on at least one processor. When the processor executes the computer program, it implements the steps in any of the above-mentioned method embodiments for outbound traffic control of containerized applications.
[0081] The computer device may include, but is not limited to, a processor and a memory. Those skilled in the art can understand that Figure 3 this is only an example of a computer device and does not constitute a limitation on the computer device. The computer device may include more or fewer components than shown in the figure, or combine certain components, or different components. For example, it may also include a network interface, a display screen, and an input device, etc.
[0082] The so-called processor may be a CPU, and this processor may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field-programmable gate arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or this processor may also be any conventional processor, etc.
[0083] The memory includes a readable storage medium, an internal memory, etc. Among them, the internal memory can be the memory of a computer device, and the internal memory provides an environment for the operation of the operating system and computer-readable instructions in the readable storage medium. The readable storage medium can be the hard disk of a computer device, and in some other embodiments, it can also be an external storage device of a computer device. For example, a plug-in hard disk, a Smart Media Card (SMC), a Secure Digital (SD) card, a Flash Card, etc. equipped on the computer device. Further, the memory can also include both the internal storage unit of the computer device and the external storage device. The memory is used to store the operating system, application programs, a boot loader (BootLoader), data, and other programs, such as the program code of a computer program. The memory can also be used to temporarily store data that has been output or will be output.
[0084] Those skilled in the art can clearly understand that, for the convenience and conciseness of description, only the above-mentioned division of each functional unit and module is used as an example. In actual applications, the above-mentioned functions can be allocated to different functional units and modules as needed, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above. Each functional unit and module in the embodiment can be integrated into a processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-mentioned integrated unit can be implemented in the form of hardware or in the form of a software functional unit. In addition, the specific names of each functional unit and module are only for the convenience of mutual distinction and do not limit the protection scope of the present invention. The specific working process of the units and modules in the above-mentioned device can refer to the corresponding process in the foregoing method embodiment and will not be repeated here. If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, to implement all or part of the processes in the above-mentioned embodiment methods of the present invention, a computer program can be used to instruct the relevant hardware to complete. The computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above-mentioned method embodiment can be implemented. Among them, the computer program includes computer program code, and the computer program code can be in the form of source code, object code, executable file or some intermediate form, etc. The computer-readable medium can at least include: any entity or device capable of carrying the computer program code, recording medium, computer memory, read-only memory (ROM), random access memory (RAM), electrical carrier signal, telecommunication signal, and software distribution medium. For example, a USB flash drive, a mobile hard disk, a magnetic disk or an optical disc, etc. In some jurisdictions, according to legislation and patent practice, the computer-readable medium cannot be an electrical carrier signal and a telecommunication signal.
[0085] All or part of the processes in the above-mentioned embodiment methods of the present invention can also be completed by a computer program product. When the computer program product runs on a computer device, it enables the computer device to execute and implement the steps in the above-mentioned method embodiment.
[0086] In the above-mentioned embodiments, the descriptions of each embodiment have their own emphases. For the parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0087] Those of ordinary skill in the art will recognize that the units and algorithm steps of each example described in connection with the embodiments disclosed herein can be implemented in electronic hardware, or in a combination of computer software and electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. A professional technician can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of the present invention.
[0088] In the embodiments provided by the present invention, it should be understood that the disclosed apparatus / computer device and method can be implemented in other ways. For example, the apparatus / computer device embodiments described above are merely illustrative. For example, the division of modules or units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be through some interfaces. The indirect couplings or communication connections of the apparatus or unit can be in electrical, mechanical or other forms.
[0089] The units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they can be located in one place, or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0090] The above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.
Claims
1. A method for outbound traffic control of containerized applications, characterized in that, The outbound traffic control method includes: When the target gateway node processes the outbound traffic of a preset container, obtain the egress gateway installed and started on the target gateway node, establish communication between the preset container and the egress gateway, and communication between the egress gateway and the firewall; Obtain the dynamic IP address of the egress gateway and the fixed IP address segment allowed by the firewall to access external services, and convert the dynamic IP address to the fixed IP address segment; Obtain the real-time outbound traffic of the preset container in real time, and use the fixed IP address segment to forward the real-time outbound traffic to external services.
2. The outbound traffic control method according to claim 1, wherein Before obtaining the egress gateway installed and started on the target gateway node, it further includes: Configure the routing rules of the preset container so that the outbound traffic of the preset container passes through the egress gateway.
3. The outbound traffic control method according to claim 1, wherein Before converting the dynamic IP address to the fixed IP address segment, it further includes: Write an eBPF program, which is used to convert the dynamic IP address to the fixed IP address segment; Load the eBPF program on the egress gateway.
4. The outbound traffic control method according to claim 3, wherein After converting the dynamic IP address to the fixed IP address segment, it further includes: Verify the stability of the conversion of the dynamic IP address to the fixed IP address segment to obtain a verification result; If the verification result is unstable, optimize the eBPF program to obtain an optimized eBPF program, and load the optimized eBPF program on the egress gateway.
5. The outbound traffic control method according to claim 1, wherein Before forwarding the real-time outbound traffic to the external service, it further includes: Configure security group rules for the firewall according to the fixed IP address segment and the IP address of the external service, and determine the firewall policy, so as to forward the real-time outbound traffic to the external service according to the firewall policy.
6. The outbound traffic control method according to claim 1, wherein After configuring the security group rules for the firewall according to the fixed IP address segment and the IP address of the external service and determining the firewall policy, it further includes: Test the effectiveness of the firewall policy to verify whether the firewall policy is effective; If the firewall policy is ineffective, adjust the security group rules to ensure the effectiveness of the firewall policy.
7. An outbound traffic control device for containerized applications, characterized in that, The outbound traffic control device includes: An acquisition module, which is used to obtain the egress gateway installed and started on the target gateway node when the target gateway node processes the outbound traffic of a preset container, establish communication between the preset container and the egress gateway, and communication between the egress gateway and the firewall; A conversion module, which is used to obtain the dynamic IP address of the egress gateway and the fixed IP address segment allowed by the firewall to access external services, and convert the dynamic IP address to the fixed IP address segment; A forwarding module, which is used to obtain the real-time outbound traffic of the preset container in real time, and use the fixed IP address segment to forward the real-time outbound traffic to external services.
8. The outgoing traffic control device according to claim 7, characterized in that, The outbound traffic control device further includes: A configuration module, which is used to configure the routing rules of the preset container so that the outbound traffic of the preset container passes through the egress gateway.
9. A computer device, characterized in that, The computer device includes a processor, a memory, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, it implements the outbound traffic control method according to any one of claims 1 to 6.
10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by the processor, it implements the outbound traffic control method according to any one of claims 1 to 6.