Container network configuration method, device, system, equipment and medium
By using the first tag information of the node in the container network configuration to filter the IP segments of the same server room, the problems of high router pressure and limited cluster scalability are solved, and efficient container network communication is achieved.
Patent Information
- Application Number
- CN202510291636.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-12
- Publication Date
- 2025-07-18
AI Technical Summary
In the container network configuration, as nodes increase, router processing pressure increases, affecting cluster scalability, and the routing link is complex and difficult to manage.
By obtaining the first tag information of the node, the target address pool is filtered out from the candidate address pool of the same server room, and the node is allocated unused IP network segments to ensure that the container does not need to jump across subnets when communicating with external devices, and is directly routed to the target subnet.
It reduces the processing pressure of routers, ensures the scalability of the cluster, shortens the routing links, and improves communication efficiency.
Smart Images

Figure CN120342874A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of container networks, and in particular, to a method, device, system, equipment and medium for configuring a container network. Background Art
[0002] In the computer field, a cluster is a group of independent nodes connected through a network to work together to provide more powerful computing power, storage capacity or other services than a single computer. These nodes can be physical servers or virtual machines on physical servers. They provide services as a whole and can flexibly allocate tasks and resources. For example, a Kubernetes cluster, abbreviated as a K8S cluster, is used to automatically deploy, scale, and manage containerized applications.
[0003] In a cluster environment, container network configuration is crucial. Because a cluster usually contains multiple nodes, and multiple containers are running on each node. It is necessary to ensure effective communication between containers, between containers and nodes, and between containers and the external network. Good container network configuration can support the characteristics of high availability, scalability, and high performance of the cluster.
[0004] Currently, for the method of configuring a container network, when a node requests an IP network segment, it is often flexibly allocated according to the availability of the network segment. For example, an unused network segment is selected from all subnets involved in the cluster. As the number of nodes added to the cluster increases, the routing links for communication between containers on the nodes and external devices become more and more complex, resulting in a large routing processing pressure and being inconvenient to manage. In order to reduce the processing pressure of the router, the scalability of the cluster will be restricted to a certain extent.
[0005] Therefore, how to propose a new container network management method to reduce the router processing pressure without affecting the scalability of the cluster has become an urgent problem to be solved. Summary of the Invention
[0006] Based on this, it is necessary to provide a method, device, electronic equipment and storage medium for displaying a protocol to reduce the router processing pressure without affecting the scalability of the cluster for the above technical problems.
[0007] In a first aspect, a method for configuring a container network is provided. The method includes: in response to receiving a node addition request sent by a server, obtaining first label information of a corresponding node in a cluster from the node addition request; the node addition request is used to request adding a new node to the cluster; the node refers to a device on which a container runtime environment is deployed, and the first label information is used to represent the server room to which the node belongs; screening out a target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster, where each of the candidate address pools includes multiple IP network segments, and all the IP network segments in any one of the candidate address pools are divided from a subnet corresponding to the same server room; selecting an unused IP network segment from the target address pool, and allocating the IP network segment to the node, so that a network plugin of the cluster allocates an IP address to a container deployed on the node according to the IP network segment, enabling the container to participate in network communication using the IP address.
[0008] In a second aspect, a device for configuring a container network is provided. The device includes: an obtaining module, configured to obtain first label information of a corresponding node in a cluster from a node addition request in response to receiving the node addition request sent by a server; the node addition request is used to request adding a new node to the cluster; the node refers to a device on which a container runtime environment is deployed, and the first label information is used to represent the server room to which the node belongs; a filtering module, configured to screen out a target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster, where each of the candidate address pools includes multiple IP network segments, and all the IP network segments in a single candidate address pool are divided from a subnet corresponding to the same server room; an address allocation module, configured to select an unused IP network segment from the target address pool, and allocate the IP network segment to the node, so that a network plugin of the cluster allocates an IP address to a container deployed on the node according to the IP network segment, enabling the container to participate in network communication using the IP address.
[0009] In a third aspect, a configuration system for a container network is provided. The system includes a first server and a second server. The first server is configured to respond to a node creation instruction triggered by a user, deploy a container running environment locally, and use the identifier of the server room to which the first server belongs as first label information. The first server is further configured to send a node addition request to the second server, where the node addition request includes the first label information. The second server is configured to respond to a cluster setup instruction triggered by a user and perform cluster initialization locally. After receiving the node addition request, the second server adds the first server as a node of the cluster and obtains the first label information of the node from the node addition request. The second server is configured to filter out a target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster. Each candidate address pool includes multiple IP network segments, and all the IP network segments in a single candidate address pool are divided from the subnet corresponding to the same server room. The second server is configured to select an unused IP network segment from the target address pool and allocate the IP network segment to the node, so that the network plugin of the cluster assigns an IP address to the container deployed on the node, enabling the container to participate in network communication using the IP address.
[0010] In a fourth aspect, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the container network configuration method as described in the first aspect above are implemented.
[0011] In a fifth aspect, a computer-readable storage medium stores a computer program, and when the program is executed by a processor, the steps of the container network configuration method as described in the first aspect above are implemented.
[0012] In summary, the present application proposes a method, apparatus, system, device and medium for configuring a container network. When allocating an IP network segment to a node, the method first obtains the first label information of the nodes in the cluster, then filters out the target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster, and selects an unused IP network segment from the target address pool to allocate to the node. When allocating an IP address to a container on the node, an IP address can be split from the IP network segment allocated to the node. The present application uses the first label information to represent the server room to which the server where the node is located belongs, and classifies the available IP network segments of the cluster according to the server room. In this way, before allocating an IP network segment to a node, the target address pool corresponding to the server room to which the node belongs can be filtered out using the first label information, and the IP network segment selected from this target address pool is a network segment under the subnet corresponding to the server room to which the node belongs. In this way, network segments under the same subnet can be allocated to nodes in the same server room in the cluster. In this way, when a container communicates with an external device, there is no need to jump across subnets anymore. By directly routing to the subnet to which the IP address of the container belongs, the container can be found, shortening the routing link and reducing the routing pressure. Even if the cluster is expanded and nodes in different server rooms are continuously added to the cluster, it can be ensured that the IP network segment allocated to the node is a network segment under the subnet corresponding to the server room to which the node belongs, rather than a network segment under the subnet corresponding to other server rooms, reducing the impact of cluster expansion on the routing pressure. Thus, while reducing the routing pressure, the scalability of the cluster is not overly affected. BRIEF DESCRIPTION OF THE DRAWINGS
[0013] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the following will briefly introduce the drawings required for the description of the embodiments of the present invention. Obviously, the following drawings are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained without creative efforts based on these drawings.
[0014] Figure 1 is a flowchart of a method for configuring a container network according to an exemplary embodiment of the present application; Figure 2 is a flowchart of a method for configuring a container network according to an exemplary embodiment of the present application; Figure 3 is a schematic block diagram of a device for configuring a container network according to another exemplary embodiment of the present application; Figure 4 is a schematic block diagram of a system for configuring a container network according to another exemplary embodiment of the present application; Figure 5It is a schematic block diagram of a computer device shown according to an exemplary embodiment of the present application. Detailed implementation manners
[0015] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, rather than all the embodiments. The embodiments described by referring to the accompanying drawings are exemplary and are intended to explain the present application, and should not be construed as a limitation to the present application. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without making creative efforts belong to the scope of protection of the present application.
[0016] The container network configuration method proposed in the embodiments of the present application is applicable to the Cilium network, allocates IP network segments to nodes in the K8S cluster, and allocates IP addresses to containers on the nodes based on the IP network segments. This method is executed by the container network configuration device proposed in the present application or deployed on a computer device for execution. For example, applying this container network configuration method to the master node of the K8S cluster, such as the server where the cluster control platform is located, to allocate IP network segments to the slave nodes of the cluster, so that when allocating IP addresses to the containers deployed on the slave nodes, an IP address can be split from the IP network segment allocated to the slave node, so that the IP address used by the container is an IP address in the subnet of the server room where the slave node is located. When routing this container, there is no need to jump from other subnets, and it can be directly routed to the subnet of the server room where the slave node is located, shortening the routing pressure. This method is applicable to adding nodes in any server room to the cluster and does not limit the scalability of the cluster.
[0017] Figure 1 It is a flowchart of a container network configuration method shown according to an exemplary embodiment of the present application. As Figure 1 shown, the container network configuration method includes the following steps: S101, in response to receiving a node addition request sent by a server, obtain first label information of a corresponding node in the cluster from the node addition request; the node addition request is used to request adding a new node to the cluster; a node refers to a device on which a container running environment is deployed, and the first label information is used to characterize the server room to which the node belongs.
[0018] Exemplarily, the container network configuration method proposed in the embodiments of the present application can be executed by a container network configuration device, and the container network configuration device can be set on the server where the cluster master node is located, for example, set on the server where the management control platform of the K8S cluster is located.
[0019] The server for adding a request in the above step S101 may include the server where the management control platform of the cluster is located, or other servers that actively request to join the cluster as cluster nodes.
[0020] For example, a developer can configure relevant information on the management control platform of the cluster to add a new node to the cluster. Among the configured relevant information, the first label information of the new node may be included. After the user configuration is completed, the server where the management control platform is located triggers a node addition request to other components to request other components to deploy the newly added node. The container network configuration device parses the first label information from the node addition request in response to the node addition request.
[0021] In some embodiments, the container network configuration method proposed in this application is directly executed by the server where the management control platform of the cluster is located. Other servers outside the cluster actively send a node addition request to the server where the management control platform of the cluster is located to request to be added to the cluster as a new node. When deploying the new node, the server where the management control platform of the cluster is located obtains the first label information from the node addition request.
[0022] For example, the server where the node is located can actively add the node to the cluster. The server creates a node addition request, writes the identifier of the server room where the server is located into the node addition request, and then the server sends the request to the server where the control management platform of the cluster is located. After receiving the node addition request, the server where the control management platform is located can add the node to the node resources of the cluster, so that when the management control platform of the cluster needs to deploy a new container, it can find a node that meets the resource requirements from the node resources for container deployment. At the same time, the server where the management control platform is located parses the identifier of the server room from the above node addition request and records the identifier of the server room as the first label information of the node.
[0023] The embodiment of this application provides a method for obtaining the first label information. When the server actively adds a node to the cluster, the server writes the identifier of the server room to which the node belongs into the node addition request. After the management control platform of the cluster receives the node addition request, it can parse the identifier of the server room from the node addition request, and then the management control platform can use the identifier of the server room as the first label information of the node. In this way, when allocating an IP network segment for the node, the first label information can be used for address pool matching. A network segment under the subnet of the server room to which the node belongs is allocated to the node.
[0024] For ease of understanding, the following explanations are provided: A mature cluster may include multiple nodes, such as master nodes and slave nodes. The master node is responsible for managing the slave nodes, and the slave nodes are used to process various computing tasks assigned by the master node.
[0025] In some embodiments, the cluster node in step S101 above may refer to a slave node.
[0026] In a K8S cluster, the master node is the node where the cluster management and control platform is located. Container groups POD can be deployed on the slave nodes, and each container group includes at least one container.
[0027] A node can be understood as a device on which a container runtime environment is deployed, or as a resource group that provides a container runtime environment. This device / resource group can be a physical server or a virtual machine. For example, when deploying a container runtime and the core components of K8S on a physical server in a server room in sequence to build a container runtime environment, and then using this physical server as a node; or when deploying a container runtime and the core components of K8S on a virtual machine of a physical server, and then using this virtual machine as a node.
[0028] Therefore, a node can also be understood as a server or virtual machine in the cluster that actually runs containerized application programs. They receive instructions from the cluster control platform and are then responsible for executing specific computing tasks and running corresponding containers.
[0029] When a slave node needs to be created, a container runtime can be installed on a server, as well as core components of K8S such as Kubelet, Kubeadm, and Kubectl. Among them, Kubelet is used to communicate with the cluster control plane and ensure that relevant tasks run on the node as required. Kubeadm is used for initialization operations such as node joining the cluster, and Kubectl facilitates management operations on the cluster. In this way, a slave node that can communicate with the cluster control platform and run containerized application programs is built on the server.
[0030] In the embodiment of the present application, during the process of creating a slave node, the identifier of the server room to which the node belongs is obtained, and then the identifier of the server room is used as the first label information of the node.
[0031] S102, from multiple candidate address pools corresponding to the cluster, filter out a target address pool that matches the first label information. Each candidate address pool includes multiple IP network segments, and all IP network segments in a single candidate address pool are divided from the subnet corresponding to the same server room.
[0032] After obtaining the first label information of the node, filter out a candidate address pool that matches the first label information from all candidate address pools corresponding to the cluster as the target address pool.
[0033] Among them, each candidate address pool may include multiple IP network segments. An IP network segment is a range of IP addresses.
[0034] All IP network segments in a candidate address pool are divided from the subnet corresponding to the same server room.
[0035] For example, an enterprise sets up two data centers, Data Center A and Data Center B, which are located in different server rooms. The enterprise divides the subnet 10.10.10.0 / 24 for Server Room 1 located in Region 1, and divides the subnet 192.168.20.0 / 24 for the server room in Region 2.
[0036] If the node that currently needs to perform container network configuration is a virtual machine on a certain server in Server Room 1, among all the candidate address pools corresponding to the cluster, find the candidate address pool divided from the subnet 10.10.10.0 / 24 as the target address pool. Each IP network segment included in this candidate address pool is divided from the subnet 10.10.10.0 / 24. For example, IP network segment 1: 10.10.10.10 - 10.10.10.50; IP network segment 2: 10.10.10.51 - 10.10.10.100.
[0037] It should be noted that the subnets mentioned in this example are for exemplary display only and are not real subnets.
[0038] S103, Select an unused IP network segment from the target address pool, and assign the IP network segment to the node, so that the network plugin of the cluster assigns an IP address to the container deployed on the node, enabling the container to participate in network communication using the IP address.
[0039] Select an unused IP network segment from the target address pool and assign the IP network segment to the node.
[0040] When the network plugin installed in the cluster assigns an IP address to the container deployed on this node, it can divide an IP address from the IP network segment assigned to this node and assign the IP address to the container.
[0041] For example, install the Cilium network plugin in the K8S cluster. In the Kubernetes environment, Cilium, as a CNI plugin, interacts with the Kubernetes API server. When a new Pod is deployed to a node, Kubernetes will call Cilium. Cilium will assign an IP address to the Pod.
[0042] In a Kubernetes environment, a Pod is the smallest deployable and manageable computing unit. Each Pod needs to have a unique IP address so that it can be recognized in the network and communicate with other network entities (such as other Pods, servers in the external network, etc.).
[0043] As a container network solution, Cilium undertakes the task of assigning IP addresses to Pods. This is like in a community (network environment), each household (Pod) needs to have a house number (IP address), and Cilium is the role responsible for assigning these "house numbers" to these "households".
[0044] In summary, the container network configuration method according to the embodiments of the present application responds to receiving a node addition request sent by the server, obtains the first label information of the nodes in the cluster from the node addition request, then filters out the target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster, selects an unused IP network segment from the target address pool and assigns it to the node, and when assigning an IP address to the containers on the node, an IP address can be split from the IP network segment assigned to the node. The present application uses the first label information to represent the server room to which the node belongs, and classifies the available IP network segments of the cluster according to the server room; in this way, before assigning an IP network segment to a node, the address pool can be filtered using the first label information first, and the IP network segment selected from this address pool is a network segment under the subnet corresponding to the server room to which the node belongs; in this way, network segments under the same subnet can be assigned to the nodes in the same server room in the cluster. In this way, when the container communicates with external devices, there is no need to jump across subnets anymore, and directly routing to the subnet to which the IP address of the container belongs can find the container, shortening the routing link and reducing the routing pressure; even if the cluster is expanded and nodes in different server rooms are continuously added to the cluster, it can be ensured that the IP network segment assigned to the node is a network segment under the subnet corresponding to the server room to which the node belongs, rather than a network segment under the subnet corresponding to other server rooms, reducing the impact of cluster expansion on the routing pressure, so that while reducing the routing pressure, the scalability of the cluster is not overly affected. Compared with the method of randomly assigning available IP network segments to different nodes with respect to the availability of the reference IP network segment, resulting in different nodes in the same server room using network segments in different subnets, and thus requiring multiple subnet jumps when routing the containers on the routing node, the embodiments of the present application reduce the routing pressure and ensure the scalability of the cluster.
[0045] Based on the above embodiments, as Figure 2 shown, in the above step S102, "filter out the target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster" includes the following steps: S201. Obtain the second label information of each candidate address pool, where the second label information is used to characterize the server computer room corresponding to the candidate address pool.
[0046] The second label information can be configured when the user adds an address pool to the cluster. For example, the user adds a certain address pool to the IP Pool (address pool) resource of the cluster as a candidate address pool by running a command line, and writes the identifier of the server computer room corresponding to the candidate address pool in the command line; the management control platform of the cluster stores the identifier of the server computer room as the second label information of the candidate address pool.
[0047] S202. Screen the second label information that matches the first label information.
[0048] S203. Use the candidate address pool identified by the screened second label information as the target address pool.
[0049] Further, in some embodiments, after step S202, the container network configuration method may further include the following steps: S204. If no second label information that matches the first label information is screened out, push a reminder message to the user, where the reminder message includes the first label information, to remind the user to add a candidate address pool corresponding to the target server computer room to the cluster, and the target server computer room is the server computer room characterized by the first label information.
[0050] Exemplarily, judge all the candidate address pools in the cluster, that is, judge whether the second label information of the candidate address pool matches the first label information of the node.
[0051] When one piece of second label information is found to match the first label information, use the candidate address pool identified by the second label information as the target address pool.
[0052] If, after comparison, no second label information that matches the first label information exists, it is confirmed that there is no available address pool for the node in the current IPpool resource of the cluster. In this case, a reminder message can be pushed to the user to remind the user to add an available address pool for the node to the IP pool resource of the cluster as a candidate address pool.
[0053] In the embodiment of the present application, when adding a candidate address pool, the identifier of the server computer room corresponding to the candidate address pool is recorded as the second label information of the candidate address pool. When an IP network segment needs to be allocated to a node, the first label information of the node can be compared with the second label information of all candidate address pools, and the second label information that matches the first label information is compared. Then, the candidate address pool identified by the second label information is used as the target address pool. When there is no second label information that matches the first label information, the user is reminded to add a candidate address pool to the cluster. This embodiment provides a method for screening the target address pool, ensuring that the IP addresses allocated to each node come from the subnet corresponding to the server computer room to which the node belongs.
[0054] In some embodiments, before "obtaining the first label information of the corresponding node in the cluster from the node addition request" in the above step S101, the container network configuration method of the embodiment of the present application further includes the following steps: Set the IP address management mode of the network plugin to a mode that matches the type of the cluster, so that the network plugin can allocate IP addresses to the containers deployed on the node according to the IP network segment allocated to the node in the cluster; and set the information addition component in the network plugin to the available state, and the information addition component is used to add annotations to the nodes of the cluster.
[0055] Among them, the type of the cluster is used to characterize the architecture form on which the cluster runs, and the type of the cluster includes but is not limited to the K8S cluster.
[0056] Corresponding to the above step S103 of "allocating the IP network segment to the node", the following steps may be included: Use the information addition component to add the IP network segment to the annotation information of the node, so that the proxy component in the network plugin can obtain the IP network segment from the annotation information of the node before allocating the IP address of the container.
[0057] Exemplarily, in the K8S cluster, perform the following configuration on Cilium IPAM: Set the IPAM mode of Cilium to the Kubernetes mode, and by setting annotateK8sNode=true, make Cilium write the IP network segment allocated to the node as the value of the annotations (comments) field in the node information. Thus, when Cilium allocates IP addresses to the containers of the node, it can obtain the network segment information from the annotations of the node.
[0058] In the embodiments of the present application, by adjusting the configuration of Cilium, Cilium can write the IP network segment allocated to the node by the container network configuration device into the annotations of the node, so that when Cilium allocates an IP address to the container of the node, it can determine the IP address of the container from the IP network segment corresponding to the node. The present application does not change the operation framework of Cilium, but only adjusts the configuration information of Cilium, which has high operability.
[0059] Based on the above embodiments, after "allocating the IP network segment to the node" in step S103 above, the container network configuration method of the embodiments of the present application further includes the following steps: Advertise the IP network segment to the router outside the cluster, so that the router can forward data packets between the node and other devices outside the cluster according to the IP network segment.
[0060] Exemplarily, the Pod CIDR of the node (i.e., the IP network segment allocated to the node above) can be advertised to the router through the BGP protocol using the BGP peering policy of Cilium to achieve routing support outside the cluster.
[0061] In some embodiments, the advertised router can be pre-configured as needed. For example, the identifier of the router to be passed through is provided to the management and control platform of the cluster. After the management and control platform allocates the IP network segment to the node with the help of the Cilium plugin, Cilium can be further called to advertise the IP network segment to one or more pre-configured routers, so that the router can update the routing path of the node to the routing table.
[0062] In the embodiments of the present application, after the IP network segment allocation is completed, the IP network segment of the node is further advertised to the router. In this way, when an external device needs to communicate with a certain container on the node, it can be routed to the node through the routing path corresponding to the IP network segment, and then the node can find the container that needs to participate in the communication from the deployed multiple containers according to the IP address. The communication efficiency between the container and the external device is improved.
[0063] The container network configuration method proposed in the embodiments of the present application provides an improved solution for Cilium IPAM, enabling it to dynamically allocate the IP network segment of PODs according to the first label information of nodes in the Kubernetes cluster, and realizing cross-multi-data center node management and container network allocation.
[0064] It should be understood that the magnitudes of the sequence numbers of the above steps in the embodiments do not mean the order of execution. The order of execution of each process should be determined according to its function and internal logic, and should not constitute any limitation to the implementation process of the embodiments of the present application.
[0065] Figure 3 is a block diagram of a configuration device for a container network shown according to an exemplary embodiment of the present application, as Figure 3 shown, the device 300 includes: an acquisition module 301, a filtering module 302, and an address allocation module 303.
[0066] The acquisition module 301 is configured to, in response to receiving a node addition request sent by a server, acquire first label information of a corresponding node in the cluster from the node addition request; the node addition request is used to request adding a new node to the cluster; the node refers to a device on which a container running environment is deployed, and the first label information is used to characterize the server computer room to which the node belongs; The filtering module 302 is configured to screen out a target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster. Each candidate address pool includes multiple IP network segments, and all IP network segments in a single candidate address pool are divided from a subnet corresponding to the same server computer room; The address allocation module 303 is configured to select an unused IP network segment from the target address pool and allocate the IP network segment to the node, so that the network plugin of the cluster allocates an IP address to the container deployed on the node according to the IP network segment, enabling the container to participate in network communication using the IP address.
[0067] In an embodiment of the present application, the filtering module is configured to: acquire second label information of each candidate address pool, where the second label information is used to characterize the server computer room corresponding to the candidate address pool; screen the second label information that matches the first label information; and use the candidate address pool identified by the screened second label information as the target address pool.
[0068] Further, the device is further configured to: if no second label information that matches the first label information is screened out, push a reminder message to the user, where the reminder message includes the first label information, to remind the user to add a candidate address pool corresponding to the target server computer room in the cluster, and the target server computer room is the server computer room characterized by the first label information.
[0069] In an embodiment of the present application, the acquisition module is further configured to: set the IP address management mode of the network plugin to a mode that matches the type of the cluster, so that the network plugin can allocate an IP address to the container deployed on the node according to the IP network segment allocated to the node in the cluster; where the type of the cluster is used to characterize the architecture form on which the cluster runs, and the type of the cluster includes a K8S cluster; set the information addition component in the network plugin to an available state, and the information addition component is used to add annotations to the nodes of the cluster; The address allocation module is configured to: use the information addition component to add the IP network segment to the annotation information of the node, so that the proxy component in the network plugin can acquire the IP network segment from the annotation information of the node before allocating the IP address of the container.
[0070] In an embodiment of the present application, the address allocation module is further configured to: notify the IP network segment to a router outside the cluster, so that the router forwards data packets between the node and other devices outside the cluster according to the IP network segment.
[0071] In summary, when the device allocates an IP network segment to a node, it obtains the first label information of the corresponding node in the cluster from the node addition request, then screens out the target address pool that matches the first label information from all candidate address pools corresponding to the cluster, selects an unused IP network segment from the target address pool and allocates it to the node. When allocating an IP address to a container on the node, an IP address can be split from the IP network segment allocated to the node. The present application uses the first label information to represent the server room to which the server where the node is located belongs, and classifies the available IP network segments of the cluster according to the server room; in this way, before allocating an IP network segment to a node, the target address pool can be screened using the first label information, and the IP network segment selected from the target address pool is a network segment under the subnet corresponding to the server room to which the node belongs; in this way, network segments under the same subnet can be allocated to nodes in the same server room in the cluster. In this way, when the container communicates with external devices, there is no need to jump across subnets anymore, and the container can be found directly by routing to the subnet to which the IP address of the container belongs, shortening the routing link and reducing the routing pressure; even if the cluster is expanded and nodes in different server rooms are continuously added to the cluster, it can be ensured that the IP network segment allocated to the node is a network segment under the subnet corresponding to the server room to which the node belongs, rather than a network segment under the subnet corresponding to other server rooms, reducing the impact of cluster expansion on the routing pressure, so that while reducing the routing pressure, the scalability of the cluster is not affected too much.
[0072] To implement the above embodiment, the present application also proposes a configuration system for a container network, as Figure 4 shown, the system 400 includes a first server 401 and a second server 402.
[0073] It should be noted that in the embodiment of the present application, the numbers of the first server 401 and the second server 402 are not limited and can be set as needed. The first server 401 and the second server 402 can be physical machines or virtual machines.
[0074] The first server 401 is configured to respond to a node creation instruction triggered by a user, deploy a container running environment locally, and use the identifier of the server room to which the first server 401 belongs as the first label information; The first server 401 is configured to send a node addition request to the second server 402, and the node addition request includes the first label information; The second server 402 is used to respond to a cluster setup instruction triggered by a user and perform cluster initialization locally; The second server 402 is used to add the first server 401 as a node of the cluster after receiving a node addition request, and obtain the first label information of the node from the node addition request; The second server 402 is used to screen out a target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster. Each candidate address pool includes multiple IP network segments, and all IP network segments in a single candidate address pool are divided from the subnet corresponding to the same server computer room; The second server 402 is used to select an unused IP network segment from the target address pool, and allocate the IP network segment to the node, so that the network plugin of the cluster can allocate IP addresses to the containers deployed on the node according to the IP network segment, enabling network communication between different containers through the allocated IP addresses.
[0075] It should be noted that the implementation manner of the embodiments of the present application may refer to the description of the implementation manner of the above embodiments, and will not be elaborated here.
[0076] In some embodiments, the second server 402 screening out a target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster may include the following steps: obtaining the second label information of each candidate address pool, where the second label information is used to characterize the server computer room corresponding to the candidate address pool; Screening out the second label information that matches the first label information; using the candidate address pool identified by the screened-out second label information as the target address pool; The second server 402 is further used to: if no second label information that matches the first label information is screened out, push a reminder message to the user, where the reminder message includes the first label information, to remind the user to add a candidate address pool corresponding to the target server computer room in the cluster, and the target server computer room is the server computer room characterized by the first label information.
[0077] In some embodiments, before the second server 402 obtains the first label information of the node from the node addition request, it is further used to: set the IP address management mode of the network plugin to a mode that matches the type of the cluster, so that the network plugin can allocate IP addresses to the containers deployed on the node according to the IP network segments allocated to the nodes in the cluster; where the type of the cluster is used to characterize the architecture form on which the cluster runs, and the type of the cluster includes a K8S cluster; set the information addition component in the network plugin to an available state, and the information addition component is used to add annotations to the nodes of the cluster; The second server 402 allocates an IP network segment to a node, which may include the following steps: using an information addition component to add the IP network segment to the annotation information of the node, so that the proxy component in the network plugin can obtain the IP network segment from the annotation information of the node before allocating the IP address of the container.
[0078] In some embodiments, after the second server 402 allocates the IP network segment to the node, it is further used to announce the IP network segment to a router outside the cluster, so that the router can forward data packets between the node and other devices outside the cluster according to the IP network segment.
[0079] In summary, before allocating an IP network segment to a node, the system can first filter the address pool using the first label information, and the selected IP network segment from the address pool is a network segment under the subnet corresponding to the server room to which the node belongs; in this way, network segments under the same subnet can be allocated to nodes belonging to the same server room in the cluster. Thus, when a container communicates with an external device, there is no need to jump across subnets anymore. By directly routing to the subnet to which the IP address of the container belongs, the container can be found, shortening the routing link and reducing the routing pressure; even when the cluster is expanded and nodes in different server rooms are continuously added to the cluster, it can be ensured that the IP network segment allocated to the node is a network segment under the subnet corresponding to the server room to which the node belongs, rather than a network segment under the subnet corresponding to other server rooms, reducing the impact of cluster expansion on the routing pressure. Therefore, while reducing the routing pressure, the scalability of the cluster is not overly affected.
[0080] To implement the above embodiments, an embodiment of the present application also proposes a computer device 500, including a memory 501, a processor 502, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the steps of the container network configuration method in the above embodiments are implemented.
[0081] To implement the above embodiments, the present application also proposes a computer-readable storage medium, on which a computer program is stored. When the program is executed by a processor, the steps of the container network configuration method in any of the above embodiments are implemented.
[0082] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memories can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memories can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0083] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above-mentioned division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules as needed, that is, the internal structure of the device can be divided into different functional units or modules to complete all or part of the functions described above.
[0084] The above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them; although the present application has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present application, and should all be included in the protection scope of the present application.
Claims
1. A method for configuring a container network, characterized in that The method includes: In response to receiving a node addition request sent by a server, obtaining first label information of a corresponding node in the cluster from the node addition request; the node addition request is used to request adding a new node to the cluster; the node refers to a device deployed with a container running environment, and the first label information is used to characterize the server room to which the node belongs; Filtering out a target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster, where each candidate address pool includes multiple IP network segments, and all the IP network segments in a single candidate address pool are divided from a subnet corresponding to the same server room; Selecting an unused IP network segment from the target address pool and allocating the IP network segment to the node, so that the network plugin of the cluster allocates an IP address to the containers deployed on the node according to the IP network segment, enabling the containers to participate in network communication using the IP address.
2. The method according to claim 1, wherein The filtering out a target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster includes: Obtaining second label information of each candidate address pool, where the second label information is used to characterize the server room corresponding to the candidate address pool; Filtering out the second label information that matches the first label information; Using the candidate address pool identified by the filtered-out second label information as the target address pool; The method further includes: If no second label information that matches the first label information is filtered out, pushing a reminder message to the user, where the reminder message includes the first label information, to remind the user to add a candidate address pool corresponding to the target server room to the cluster, and the target server room is the server room characterized by the first label information.
3. The method according to claim 1, characterized in that, Before obtaining the first label information of the corresponding node in the cluster from the node addition request, the method further includes: Setting the IP address management mode of the network plugin to a mode that matches the type of the cluster, so that the network plugin can allocate an IP address to the containers deployed on the node according to the IP network segment allocated to the node in the cluster; where the type of the cluster is used to characterize the architecture form on which the cluster runs, and the type of the cluster includes a K8S cluster; Setting the information addition component in the network plugin to an available state, where the information addition component is used to add annotations to the nodes of the cluster; The allocating the IP network segment to the node includes: Using the information addition component to add the IP network segment to the annotation information of the node, so that the proxy component in the network plugin can obtain the IP network segment from the annotation information of the node before allocating the IP address of the container.
4. The method according to claim 1, characterized in that After allocating the IP network segment to the node, it further includes: Advertising the IP network segment to a router outside the cluster, so that the router forwards data packets between the node and other devices outside the cluster according to the IP network segment.
5. A configuration device for a container network, characterized in that, The device includes: An acquisition module, configured to obtain first label information of a corresponding node in the cluster from the node addition request in response to receiving the node addition request sent by the server; the node addition request is used to request adding a new node to the cluster; the node refers to a device on which a container running environment is deployed, and the first label information is used to characterize the server computer room to which the node belongs; A filtering module, configured to filter out a target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster, where each candidate address pool includes multiple IP network segments, and all the IP network segments in a single candidate address pool are divided from the subnet corresponding to the same server computer room; An address allocation module, configured to select an unused IP network segment from the target address pool and allocate the IP network segment to the node, so that the network plugin of the cluster allocates an IP address to the container deployed on the node, enabling the container to participate in network communication using the IP address.
6. A configuration system for a container network, characterized in that, The system includes a first server and a second server; The first server is configured to respond to a node creation instruction triggered by a user, deploy a container running environment locally, and use the identifier of the server computer room to which the first server belongs as the first label information; The first server is configured to send a node addition request to the second server, and the node addition request includes the first label information; The second server is configured to respond to a cluster construction instruction triggered by a user and perform cluster initialization locally; The second server is configured to, after receiving the node addition request, add the first server as a node of the cluster and obtain the first label information of the node from the node addition request; The second server is configured to filter out a target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster, where each candidate address pool includes multiple IP network segments, and all the IP network segments in a single candidate address pool are divided from the subnet corresponding to the same server computer room; The second server is configured to select an unused IP network segment from the target address pool and allocate the IP network segment to the node, so that the network plugin of the cluster allocates an IP address to the container deployed on the node, enabling the container to participate in network communication using the IP address.
7. The system according to claim 6, characterized in that, The second server filtering out a target address pool that matches the first label information from multiple candidate address pools corresponding to the cluster includes: Obtaining second label information of each candidate address pool, where the second label information is used to characterize the server computer room corresponding to the candidate address pool; Filtering out the second label information that matches the first label information; Using the candidate address pool identified by the filtered second label information as the target address pool; The second server is further configured to: If no second tag information matching the first tag information is screened out, a reminder message is pushed to the user, and the reminder message includes the first tag information to remind the user to add a candidate address pool corresponding to the target server room in the cluster, where the target server room is the server room characterized by the first tag information.
8. The system according to claim 6, wherein Before the second server obtains the first tag information of the node from the node addition request, it is further configured to: Set the IP address management mode of the network plugin to a mode matching the type of the cluster, so that the network plugin can allocate IP addresses for the containers deployed on the node according to the IP network segment allocated to the node in the cluster; where the type of the cluster is used to characterize the architecture form on which the cluster runs, and the type of the cluster includes a K8S cluster; Set the information addition component in the network plugin to an available state, and the information addition component is used to add annotations to the nodes of the cluster; The second server allocates the IP network segment to the node, including: Using the information addition component to add the IP network segment to the annotation information of the node, so that the proxy component in the network plugin can obtain the IP network segment from the annotation information of the node before allocating the IP address of the container.
9. A computer device, comprising a memory, a processor, and a computer program stored on the memory and executable on the processor, characterized in that, When the processor executes the computer program, the steps of the container network configuration method according to any one of claims 1-4 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that, When the program is executed by the processor, the steps of the container network configuration method according to any one of claims 1-4 are implemented.