Network topological graph construction method and device, electronic equipment and storage medium

By determining workloads in Kubernetes clusters and building a network topology diagram based on load traffic relationships, the topology diagram complexity problem caused by the short POD life cycle is solved, and the construction efficiency and quality is improved, and user analysis decisions and historical topology traceability is supported.

CN120358145APending Publication Date: 2025-07-22TENCENT TECHNOLOGY (SHENZHEN) CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410084367.X
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-19
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

The existing network topology graph construction method in Kubernetes clusters has low construction efficiency, complex images, and inability to trace historical topology, which affects user analysis and decision-making.

Method used

By obtaining the computing unit assets and traffic information of the target cluster, the workload is determined, and the network topology diagram is constructed based on the load traffic relationship. The aggregation of the computing unit is a workload node, simplifying the complexity of the network topology diagram.

Benefits of technology

It improves the efficiency and quality of network topology map construction, reduces user visual congestion, supports effective analytical decisions, and realizes traceability of historical topology.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358145A_ABST
    Figure CN120358145A_ABST
Patent Text Reader

Abstract

The embodiment of the invention discloses a network topological graph construction method and device, electronic equipment and a storage medium. The method comprises the following steps: acquiring asset information and flow information of each computing unit in a target cluster; according to the asset information, at least one workload is determined from the target cluster, and the workload comprises at least one computing unit; for each working load, determining a load flow relationship between the working load and other working loads in the target cluster according to the flow information of each computing unit in the working load, the load flow relationship comprising a load flow path and a load flow direction between the working loads; and constructing a network topological graph of the target cluster based on the load flow relationship. According to the scheme, the construction efficiency of the network topological graph can be improved, and the quality of the constructed network topological graph is ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the field of computer technology, and in particular, to a method, apparatus, electronic device, and storage medium for constructing a network topology diagram. Background Art

[0002] In recent years, with the popularization of cloud technology, more and more organizations and enterprises have begun to adopt this technology to manage and detect their network environments. Among them, the visualization of network asset traffic has become one of the important means of modern network management.

[0003] The visualization of network asset traffic refers to a structure diagram or chart that describes the traffic flow in the network and the relationships between assets. It shows the connection methods, communication paths, and data flow directions between various assets in the network, and can usually be presented in the form of a network topology diagram.

[0004] However, currently, the network topology diagram is generally constructed using the smallest deployable unit in the cluster (such as a POD in a Kubernetes cluster) as a node. Due to the short lifecycle of PODs and the deployment of services in a microservices manner, there are a large number of traffic connections and a large number of POD assets between PODs and between PODs and the Internet (INTERNET). As a result, the displayed network topology diagram will be very complex, resulting in low efficiency in constructing the network topology diagram, and causing a feeling of congestion for users visually, creating a data flood for users and making it impossible to effectively make further analysis and decisions based on the visualized network topology diagram, resulting in low quality of the constructed network topology diagram. Summary of the Invention

[0005] Embodiments of this application provide a method, apparatus, electronic device, and storage medium for constructing a network topology diagram, which can improve the quality and efficiency of constructing the network topology diagram.

[0006] Embodiments of this application provide a method for constructing a network topology diagram, including:

[0007] Obtain the asset information and traffic information of each computing unit in the target cluster;

[0008] Determine at least one workload from the target cluster according to the asset information, where the workload includes at least one computing unit;

[0009] For each workload, determine the load traffic relationship between the workload and other workloads in the target cluster according to the traffic information of each computing unit in the workload, where the load traffic relationship includes the load traffic path and load traffic direction between workloads;

[0010] Construct a network topology diagram of the target cluster based on the load traffic relationship.

[0011] The embodiment of the present application further provides a network topology graph construction device, including:

[0012] An acquisition unit, configured to acquire the asset information and traffic information of each computing unit in the target cluster;

[0013] A first determination unit, configured to determine at least one workload from the target cluster according to the asset information, where the workload includes at least one computing unit;

[0014] A second determination unit, configured to, for each workload, determine the load traffic relationship between the workload and other workloads in the target cluster according to the traffic information of each computing unit in the workload, where the load traffic relationship includes the load traffic path and load traffic direction between the workloads;

[0015] A topology graph construction unit, configured to construct a network topology graph of the target cluster based on the load traffic relationship.

[0016] In some embodiments, the second determination unit includes:

[0017] A unit traffic relationship determination module, configured to, for each computing unit in the workload, determine the unit traffic relationship between the computing unit and other computing units in the target cluster according to the traffic information of the computing unit, where the unit traffic relationship includes the unit traffic path and unit traffic direction between the computing units;

[0018] A load traffic relationship determination module, configured to determine the load traffic relationship of the workload according to the unit traffic relationship.

[0019] In some embodiments, the load traffic relationship determination module is specifically configured to:

[0020] According to the unit traffic relationship, determine an associated computing unit corresponding to the computing unit in the target cluster, where there is a unit traffic path between the associated computing unit and the computing unit;

[0021] Acquire the workload corresponding to the associated computing unit;

[0022] Compare the workload corresponding to the associated computing unit with the workload corresponding to the computing unit;

[0023] If the workload corresponding to the associated computing unit is different from the workload corresponding to the computing unit, then generate a load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit based on the unit traffic path existing between the associated computing unit and the computing unit;

[0024] Determine the load flow relationship according to the load flow path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit.

[0025] In some embodiments, the load flow relationship determination module is further specifically configured to:

[0026] Obtain the number of paths of the unit flow path existing between the associated computing unit and the computing unit;

[0027] If there are multiple unit flow paths, obtain the unit path directions of the multiple unit flow paths;

[0028] If the unit path directions of the multiple unit flow paths are the same, fuse the multiple unit flow paths to obtain a load flow path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit, and the load flow direction of the load flow path is the same as the unit path directions of the multiple unit flow paths.

[0029] In some embodiments, the load flow relationship determination module is further specifically configured to:

[0030] If the unit path directions of the multiple unit flow paths are different, fuse the multiple unit flow paths according to different unit path directions respectively to obtain a first flow path and a second flow path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit, and the path direction of the first flow path is opposite to the path direction of the second flow path;

[0031] Use the first flow path and the second flow path as the load flow paths between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit.

[0032] In some embodiments, the network topology graph construction device further includes:

[0033] A first response unit, configured to display the network topology graph in response to a topology graph display instruction, where the network topology graph includes nodes and connections between the nodes, the nodes represent the workloads, and the connections represent the load flow relationships.

[0034] In some embodiments, the network topology graph construction device further includes:

[0035] A second response unit, configured to obtain the target workload corresponding to the target node in response to a viewing instruction for the target node in the network topology graph;

[0036] An information acquisition unit, configured to acquire asset information and traffic information of each computing unit in the target workload;

[0037] An information display unit, configured to display the asset information and traffic information of each computing unit in the target workload.

[0038] In some embodiments, the network topology graph construction device further includes:

[0039] A time acquisition unit, configured to acquire the annotation time corresponding to the network topology graph, where the annotation time is the acquisition time of the asset information and traffic information used when constructing the network topology graph;

[0040] A storage unit, configured to annotate the network topology graph based on the acquisition time, and store the annotated network topology graph in a topology graph database;

[0041] The first response unit is specifically configured to:

[0042] Determine the target annotation time indicated by the topology graph display instruction;

[0043] Extract the network topology graph matching the target annotation time from the topology graph database, and display the network topology graph matching the target annotation time.

[0044] In some embodiments, the acquisition unit includes:

[0045] An initial information acquisition module, configured to acquire at least one initial asset information and at least one initial traffic information collected by each computing unit in the target cluster within a specified time period;

[0046] A first filtering module, configured to filter the at least one initial asset information according to a preset asset condition to obtain the asset information of the computing unit;

[0047] A second filtering module, configured to filter the at least one initial traffic information according to a preset traffic condition to obtain the traffic information of the computing unit.

[0048] In some embodiments, the first filtering module is specifically configured to:

[0049] Delete the duplicate initial asset information in the at least one initial asset information to obtain the asset information of the computing unit.

[0050] In some embodiments, the second filtering module is specifically configured to:

[0051] Delete the duplicate initial traffic information in the at least one initial traffic information to obtain the traffic information of the computing unit.

[0052] In some embodiments, the target cluster further includes a communication unit, and the topology graph construction unit is specifically configured to:

[0053] Determine the communication traffic relationship between the workload and the communication unit according to the traffic information of each computing unit in the target cluster, where the communication traffic relationship includes the traffic path and traffic direction between the workload and the communication unit;

[0054] Construct a network topology graph of the target cluster according to the communication traffic relationship and the load traffic relationship.

[0055] An embodiment of the present application further provides an electronic device, including a memory storing multiple instructions; the processor loads the instructions from the memory to execute the steps in any one of the network topology graph construction methods provided by the embodiments of the present application.

[0056] An embodiment of the present application further provides a computer-readable storage medium, where the computer-readable storage medium stores multiple instructions, and the instructions are suitable for being loaded by a processor to execute the steps in any one of the network topology graph construction methods provided by the embodiments of the present application.

[0057] An embodiment of the present application further provides a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps in any one of the network topology graph construction methods provided by the embodiments of the present application are implemented.

[0058] In the embodiments of the present application, after obtaining the asset information and traffic information of each computing unit in the target cluster, at least one workload is determined from the target cluster according to the asset information, where the workload includes at least one computing unit; then, for each workload, the load traffic relationship between the workload and other workloads in the target cluster is determined according to the traffic information of each computing unit in the workload, and the load traffic relationship includes the load traffic path and load traffic direction between the workloads; finally, a network topology graph of the target cluster is constructed based on the load traffic relationship. That is to say, by aggregating a large number of computing units in the target cluster into a small number of workloads according to the asset information and traffic information of the computing units, and constructing a network topology graph with the workloads as nodes, the traffic of the computing units can be effectively converged, thereby greatly reducing the complexity of the network topology graph, improving the construction efficiency of the network topology graph, reducing the visual congestion of users, improving the visual experience of users, and enhancing the quality of the network topology graph, so that users can effectively make further analysis and decisions based on the visualized network topology graph. Description of the Drawings

[0059] To more clearly illustrate the technical solutions in the embodiments of the present application, the following will briefly introduce the accompanying drawings required for the description of the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those skilled in the art, without creative efforts, other accompanying drawings can be obtained based on these drawings.

[0060] Figure 1a It is a schematic diagram of the scenario of the network topology construction method provided by the embodiment of the present application;

[0061] Figure 1b It is a schematic flowchart of the network topology construction method provided by the embodiment of the present application;

[0062] Figure 1c It is a schematic diagram of the asset relationship in the target cluster provided by the embodiment of the present application;

[0063] Figure 1d It is a schematic diagram of traffic filtering between POD1 and POD2 provided by the embodiment of the present application;

[0064] Figure 1e It is a schematic diagram of the unit traffic relationship provided by the embodiment of the present application;

[0065] Figure 1f It is a schematic diagram of the load traffic relationship provided by the embodiment of the present application;

[0066] Figure 1g It is a schematic diagram of a kind of traffic path fusion provided by the embodiment of the present application;

[0067] Figure 1h It is a schematic diagram of another kind of traffic path fusion provided by the embodiment of the present application;

[0068] Figure 1i It is the network topology diagram provided by the embodiment of the present application;

[0069] Figure 1j It is the calculation unit relationship diagram provided by the embodiment of the present application;

[0070] Figure 2a It is a schematic diagram of the application of the network topology construction method in the server provided by the embodiment of the present application;

[0071] Figure 2b It is a schematic flowchart of the network asset traffic visualization provided by the embodiment of the present application;

[0072] Figure 3 It is a schematic structural diagram of a kind of network topology construction device provided by the embodiment of the present application;

[0073] Figure 4 It is a schematic structural diagram of the electronic device provided by the embodiment of the present application. Specific embodiments

[0074] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without creative efforts belong to the scope of protection of the present application.

[0075] The embodiments of the present application provide a method, apparatus, electronic device, and storage medium for constructing a network topology diagram.

[0076] Among them, the network topology diagram construction apparatus can be specifically integrated in an electronic device, and the electronic device can be a device such as a terminal or a server. Among them, the terminal can be a device such as a mobile phone, a tablet computer, a smart Bluetooth device, a laptop computer, or a personal computer (PC); the server can be a single server or a server cluster composed of multiple servers.

[0077] In some embodiments, the network topology diagram construction apparatus can also be integrated in multiple electronic devices. For example, the network topology diagram construction apparatus can be integrated in multiple servers, and multiple servers are used to implement the network topology diagram construction method of the present application.

[0078] In some embodiments, the server can also be implemented in the form of a terminal.

[0079] For example, referring to Figure 1a , Figure 1a shows a schematic diagram of a scenario of the network topology diagram construction method provided by the embodiments of the present application. As Figure 1a shown, the scenario can include a server 100 and a user terminal 200. The server 100 can be communicatively connected to the user terminal 200. In actual applications, the server 100 can receive a network topology diagram acquisition request sent by the user terminal 200 and return a corresponding network topology diagram to the user terminal 200 according to the network topology diagram acquisition request. After receiving the network topology diagram, the user terminal 200 can display it through its display device. The user terminal 200 can be a mobile phone, a tablet computer, a smart Bluetooth device, a smart wearable device, a laptop computer, or a personal computer, etc.

[0080] Among them, the server 100 can perform the following steps:

[0081] Obtain the asset information and traffic information of each computing unit in the target cluster;

[0082] Determine at least one workload from the target cluster based on the asset information, the workload including at least one computing unit;

[0083] For each workload, determine a load flow relationship between the workload and other workloads in the target cluster according to flow information of each computing unit in the workload, wherein the load flow relationship includes a load flow path and a load flow direction between the workloads;

[0084] Based on the load flow relationship, a network topology diagram of the target cluster is constructed.

[0085] It can be understood that in the specific implementation of this application, data related to traffic information, asset information, etc. is involved. When the above embodiments of this application are applied to specific products or technologies, user permission or consent is required, and the collection, use and processing of relevant data need to comply with relevant laws, regulations and standards of relevant countries and regions.

[0086] It should be noted that the serial numbers of the following embodiments are not intended to limit the preferred order of the embodiments.

[0087] Embodiment 1

[0088] Cloud native: A software approach to building, deploying, and managing modern applications in a cloud computing environment. It uses an open source stack for containerization, improves flexibility and maintainability based on a microservice architecture, supports continuous iteration and operation and maintenance automation with the help of agile methods and DevOps, and uses cloud platform facilities to achieve elastic scaling, dynamic scheduling, and optimize resource utilization.

[0089] Network asset traffic visualization: Network asset traffic visualization refers to a structural diagram or chart that describes the flow of traffic in the network and the relationship between assets. It shows the connection method, communication path (hereinafter also referred to as traffic path) and data flow direction (hereinafter also referred to as traffic direction) between various assets in the network. Among them, network assets can be various resources deployed and managed on the cloud platform, such as containers, container groups, etc.

[0090] Kubernetes: Also known as k8s, it is an open source platform that automates Linux container operations. It can help users save many manual deployment and expansion operations in the application containerization process. Kubernetes can be used to aggregate multiple groups of hosts running Linux containers, and Kubernetes can help manage these clusters easily and efficiently. Among them, the cluster managed by the Kubernetes platform can be referred to as a Kubernetes cluster.

[0091] CS architecture: That is, the client-server architecture. In this architecture, the functions of a computer system are divided into two parts: the client and the server. The client refers to the terminal device used by the user, such as a personal computer, mobile phone, tablet, etc., which is used to send requests to the server and receive responses. The server refers to the central computer or computer cluster that provides services, responsible for receiving requests from the client, processing them, and returning the results to the client.

[0092] NAMESPACE: It refers to the namespace, which is a mechanism for creating virtual isolation environments in the Kubernetes cluster. It can help divide the cluster into multiple logical parts, each with its own resources and objects. NAMESPACE can be used to isolate different teams, projects, or environments, as well as avoid naming conflicts. By using NAMESPACE, multiple applications can run in the same Kubernetes cluster and remain isolated from each other. Each NAMESPACE has its own resources such as Pods, Services, Deployments, etc.

[0093] WORKLOAD: It refers to the workload, which is the application or service running in the Kubernetes cluster. It can be a collection of one or more Pods and usually includes other resources related to the application, such as storage volumes, configurations, and services.

[0094] POD: It refers to the container group, which is the smallest deployable unit in Kubernetes and can be called a computing unit in the cluster. It is a group composed of one or more containers. It provides an independent running environment, including isolation of network and storage resources. PODs are usually used to run containers that share the same resources and lifecycle. They can run on the same host and communicate through the local network.

[0095] eBPF: The full name is extended Berkeley Packet Filter. It is a kernel technology that allows users to extend kernel functions by inserting custom code at specific hook points without changing the kernel source code. eBPF was originally designed for network packet filtering and analysis, but now it has been extended to other fields, such as security detection, performance analysis, and operating system observation.

[0096] Currently, with the popularization of cloud-native technologies such as containers, microservices, and continuous delivery, a large number of applications are built based on kubernetes container orchestration. Compared with the traditional network mode, in the cloud-native scenario, the network is a key component connecting various containers and services. And the network asset traffic visualization platform has the following four functions:

[0097] 1. Visualize network topology: The network topology in a Kubernetes cluster is usually very complex, involving connections between multiple hosts, containers, and services. The cloud-native network asset traffic topology can provide a visual graphical representation to help administrators and operators better understand and analyze the network structure, thus better managing and maintaining the cluster.

[0098] 2. Troubleshooting and debugging: When network problems or failures occur, the cloud-native network asset traffic topology can help quickly locate the source of the problem. By observing the path and flow of traffic, it is possible to determine whether there are network bottlenecks, packet loss, latency, etc., and troubleshoot and debug accordingly.

[0099] 3. Security auditing and risk assessment: The network topology can help with security auditing and risk assessment. By analyzing the traffic topology, it is possible to determine which assets are communicating with each other and whether there are any anomalies or potential security risks. This helps to detect potential security vulnerabilities early and take corresponding security measures to protect containers and services.

[0100] 4. Performance optimization: The cloud-native network asset traffic topology can provide insights into network performance. By analyzing the path and flow of traffic, it is possible to identify bottlenecks and the reasons for bottlenecks in the network and take corresponding optimization measures to improve the communication efficiency and performance between containers and services.

[0101] Therefore, visualizing network asset traffic is of great significance for aspects such as management, troubleshooting, security, and performance optimization, and can help improve the reliability, security, and performance of the cluster.

[0102] However, the following are the three most core problems faced by the network visualization platform:

[0103] 1. POD asset traffic data deluge: The Kubernetes network is a complex topic, involving multiple network components and configuration options. Due to the short lifecycle of PODs and the deployment of services in a microservices manner, there are a large number of traffic connections between PODs, between PODs and the Internet (INTERNET), and a large number of POD assets. Therefore, the visualization platform needs to overcome this complexity and present network topology and configuration information in a simple and intuitive way.

[0104] 2. Low efficiency in constructing network topology: The Kubernetes network is a platform built with microservices. Due to the short lifecycle of PODs, the creation, deletion, and migration of containers and Pods may occur at any time. The visualization platform needs to be able to capture and reflect these changes in real time, which includes two aspects, one is assets and the other is network traffic, to maintain the accuracy of the network state.

[0105] 3. Network topology with untraceable historical scope: Since the lifecycle of PODs in Kubernetes is usually short, historical asset traffic fails to be saved in time, resulting in an inability to trace the historical network topology diagram, thus increasing the maintenance cost.

[0106] In view of the above problems, in this embodiment, a method for constructing a network topology diagram related to cloud network technology is provided. As Figure 1b shown, the specific process of this method for constructing a network topology diagram can be as follows:

[0107] 101. Obtain the asset information and traffic information of each computing unit in the target cluster.

[0108] Among them, the target cluster refers to the cluster for which a network topology diagram needs to be constructed. Among them, a cluster refers to connecting multiple computers or servers together to provide higher performance, reliability, and scalability through resource sharing and collaborative work. In this embodiment, the target cluster can be a Kubernetes cluster.

[0109] Among them, the computing unit is the smallest schedulable and manageable unit in the target cluster. Exemplarily, in the following, this embodiment takes the target cluster as a Kubernetes cluster as an example and takes the computing unit as a POD in the Kubernetes cluster as an example for illustration.

[0110] Among them, the asset information may include the label, container, network, storage, lifecycle, status, etc. of the computing unit.

[0111] Exemplarily, in this embodiment, taking the computing unit as a POD (which can also be called a POD asset) as an example, its label is a key-value pair used to identify and classify PODs. Specifically, labels can be used for resource selection and filtering. Among them:

[0112] The container is the main building block of the POD. They share the same network and storage resources and run on the same node. A POD can contain one or more containers.

[0113] The network means that the containers in the POD share the same network namespace and they can communicate using the same IP address and port number. Kubernetes will automatically create a virtual network so that the containers in the POD can communicate with each other.

[0114] The storage refers to the storage volume. In practical applications, the storage volume can be mounted to the containers in the POD so that they can access the same data; the storage volume can be a local disk, network storage, cloud storage, etc.

[0115] The lifecycle refers to that the Kubernetes controller is responsible for managing the lifecycle of PODs, including processes such as creation, scheduling, update, and deletion.

[0116] The status of a POD can include information such as the current running status, the status of containers, and the network status. Specifically, the kubectl command can be used to view the status of a POD.

[0117] Among them, the traffic information is the data volume or related information of the data stream transmitted by the computing unit in the network. Exemplarily, taking the computing unit as a POD, its traffic information can include information such as IP address, container port, service address, network policy, and traffic statistics. In this embodiment, since the IP address usually includes the IP of the source POD and the IP of the target POD, according to the traffic information of the POD, the unit traffic path and unit traffic direction between multiple PODs in the target cluster can be known. Among them, the source POD refers to the POD that sends data or initiates a network request, and it sends the data to the target POD to form traffic.

[0118] In some embodiments, in step 101, the specific implementation of obtaining the asset information and traffic information of each computing unit in the target cluster may include:

[0119] A1. For each computing unit in the target cluster, obtain at least one initial asset information and at least one initial traffic information collected by the computing unit within a specified time period.

[0120] Among them, the initial asset information can be the raw data collected from the target cluster for asset information. It should be noted that the above asset information can be obtained after some asset preprocessing. Optionally, the asset preprocessing can include asset format conversion. Exemplarily, the POD asset conversion mainly associates the POD asset information with K8S assets according to the raw data of the POD and the information of k8s, so as to obtain the relationship between POD assets, WORKLOAD assets, and NAMESPACE assets. This process will perform association conversion on the source node and the target POD assets. Exemplarily, for example, the asset relationship of POD assets, WORKLOAD assets, and NAMESPACE assets can be as Figure 1c shown, where the POD belongs to the WORKLOAD, and the WORKLOAD belongs to the NAMESPACE.

[0121] Among them, the initial traffic information can be the raw data collected from the target cluster for traffic information. It should be noted that the above traffic information can be obtained after some traffic preprocessing. Optionally, the traffic preprocessing can include traffic format conversion, etc. Exemplarily, here mainly the raw traffic data captured by eBPF is converted. The raw traffic data can include: source POD name, source POD label, IP information of the source POD, source POD port information, destination POD name, destination POD label, IP information of the destination POD, destination POD port information, traffic layer-4 protocol, traffic layer-7 protocol, traffic time, raw traffic identifier, traffic action, whether it is a return packet, traffic direction, and other information. The traffic format conversion is mainly to convert the captured raw traffic data so that the traffic information is converted from the original diverse formats into a unified format matching the Kubernetes platform, to facilitate subsequent operations such as traffic aggregation and constructing a network topology map based on the traffic information.

[0122] In some embodiments, the initial traffic information can be collected through technologies such as eBPF technology, Network Sniffing, Port Mirroring, Packet Capture Tools, etc. Exemplarily, when collecting through eBPF technology, it can include the following two parts:

[0123] I. Capturing data packets: The eBPF program for traffic collection can be inserted into different stages in the network protocol stack, such as the network interface, network layer, transport layer, etc., to capture data packets entering and leaving the system.

[0124] II. Filtering and classification: The eBPF program can filter and classify the captured data packets according to specific filtering rules and conditions. This enables Cilium to identify and process specific types of traffic, such as based on application, service, or network policy, etc. Among them, Cilium is an open-source project in the field of container networking, mainly used for containers, and is used to provide and transparently protect the network connections and load balancing between application workloads (such as application containers or processes).

[0125] In some embodiments, the initial asset information can be collected through the Informer mechanism. In Kubernetes, the Informer mechanism is a mechanism for detecting and capturing changes in Kubernetes cluster resource objects. Specifically, the change of the POD label can be detected through the Informer mechanism, so as to perceive asset changes in real time and obtain the initial asset information of the POD in real time.

[0126] Exemplarily, detecting changes in POD resource objects through the Informer mechanism can be carried out according to the following steps:

[0127] 1. Create an Informer object for a POD: Using the Kubernetes client library, an Informer object for a POD can be created. The Informer object is responsible for communicating with the Kubernetes API server and receiving event notifications about the POD resource object.

[0128] 2. Register an event handling function: When creating the Informer object, an event handling function needs to be registered. This function will be called when the POD resource object changes. Among them, this function can be customized to perform corresponding operations on the POD according to requirements.

[0129] 3. Start the Informer: Once the Informer object and the event handling function are both set up, the start method of the Informer object can be called to start the Informer. This will start capturing changes in the POD resource object. Among them, the start method can be the Start() method. Start() is a method or function used to start a certain program, service, or component.

[0130] 4. Process events: When the POD resource object changes, the Informer will receive relevant event notifications and call the registered event handling function. In the event handling function, logic can be written to process newly added, updated, or deleted POD objects.

[0131] 5. Handle errors and reconnect: The Informer will handle connection problems and errors with the API server. When connection problems and errors occur, the Informer can automatically attempt to reconnect and continue to detect changes in the POD resource object.

[0132] In the above way, the Informer mechanism is used to detect changes in the POD resource object and perform custom operations when changes occur. It can capture and respond to changes in the POD status in real time, so as to obtain the initial asset information to adapt to the changing environment in the cluster.

[0133] Among them, the specified time period can be the most recent period (the most recent hour) up to the current moment, or a historical time period (such as the time range from 9:00 to 10:00). The specific specified time period can be customized according to actual needs and is not limited here.

[0134] A2. Filter at least one piece of initial asset information according to preset asset conditions to obtain the asset information of the computing unit.

[0135] Among them, the preset asset condition can be a filtering condition set for the initial asset information. Since there may be multiple pieces of initial asset information collected by the computing unit within the specified time period, and some of the multiple pieces of initial asset information may be unnecessary, these unnecessary initial asset information can be filtered out through the preset asset condition, and only the required part is retained.

[0136] In some embodiments, in step A2, according to the preset asset condition, the specific implementation of filtering at least one piece of initial asset information to obtain the asset information of the computing unit may include:

[0137] Delete the duplicate initial asset information among at least one piece of initial asset information to obtain the asset information of the computing unit.

[0138] Exemplarily, for example, within the specified time period, if two identical pieces of initial asset information of a computing unit (such as POD1) are detected by Informer, that is, the POD A asset is detected twice within the specified time period, then only one piece of initial asset information of the POD A asset can be retained, and other duplicate initial asset information is deleted.

[0139] It can be understood that when constructing a topology graph with PODs as nodes, each piece of asset information can generate a corresponding node for the POD. If duplicate asset information is retained, multiple nodes will be generated for a POD in the network topology, but these multiple nodes represent the same POD asset, resulting in redundancy and confusion in the topology graph. Therefore, in this embodiment, by deleting the duplicate initial asset information among at least one piece of initial asset information to obtain the asset information of the computing unit, redundant information can be effectively reduced, and the construction efficiency of the network topology can be improved.

[0140] A3. According to the preset traffic condition, filter at least one piece of initial traffic information to obtain the traffic information of the computing unit.

[0141] In some embodiments, in step A3, according to the preset traffic condition, the specific implementation of filtering at least one piece of initial traffic information to obtain the traffic information of the computing unit may include:

[0142] Delete the duplicate initial traffic information among at least one piece of initial traffic information to obtain the traffic information of the computing unit.

[0143] Exemplarily, for example, within the specified time period, it is detected that POD1 sends multiple identical data packets to POD2, and multiple identical pieces of initial traffic information are obtained, that is, multiple identical traffic flows are generated between POD1 and POD2. Then only one traffic flow, that is, one piece of initial traffic information, can be retained. Other duplicate initial traffic information is deleted.

[0144] It is understandable that when constructing a topology graph with PODs as nodes, each traffic information can generate a connection line between the corresponding nodes of two PODs. If duplicate traffic information is retained, multiple connection lines will be generated between the corresponding nodes of two PODs, resulting in redundancy and confusion in the topology graph. Exemplarily, as Figure 1d shown, if three duplicate initial traffic information are detected between the two nodes POD1 and POD2, three connection lines will be generated on the network topology graph. After filtering the duplicate traffic information, only one connection line will be retained on the network topology graph. Therefore, in this embodiment, by deleting the duplicate initial traffic information in at least one initial traffic information to obtain the traffic information of the computing unit, redundant information can be effectively reduced and the construction efficiency of the network topology can be improved.

[0145] 102. Determine at least one workload from the target cluster according to the asset information, where the workload includes at least one computing unit.

[0146] In some embodiments, the asset information contains tags. Since the tags pre-classify the rare computing units in the target cluster, the same type of computing units can be classified into one workload according to the tags, thereby obtaining at least one workload. For example, POD1 and POD2 with tag A are classified into one workload, and POD3 and POD4 with tag B are classified into another workload.

[0147] It is understandable that computing units with the same tag can share the same network namespace. That is to say, all PODs in the same workload will share the same network namespace, which means they can access and communicate with each other.

[0148] Optionally, computing units with the same tag can share the same storage volume. In some cases, PODs in the same workload need to share the same storage volume so that they can access the same data.

[0149] Optionally, computing units with the same tag can have the same life cycle. All PODs in the same workload usually have the same life cycle, that is, they will start, stop or restart simultaneously.

[0150] Optionally, computing units with the same tag can all be different instances of the same application program: all PODs in the same workload are usually different instances of the same application program to provide higher availability and scalability.

[0151] 103. For each workload, determine the load traffic relationship between the workload and other workloads in the target cluster according to the traffic information of each computing unit in the workload. The load traffic relationship includes the load traffic path and load traffic direction between the workloads.

[0152] In some embodiments, in step 103, the specific implementation of determining the load traffic relationship between the workload and other workloads in the target cluster according to the traffic information of each computing unit in the workload may include:

[0153] B1. For each computing unit in the workload, determine the unit traffic relationship between the computing unit and other computing units in the target cluster according to the traffic information of the computing unit. The unit traffic relationship includes the unit traffic path and unit traffic direction between the computing units.

[0154] Among them, since the traffic information may include IP addresses (such as the IP of the source POD and the IP of the target POD), when the IP of the source POD and the IP of the target POD are known, the unit traffic path and unit traffic direction between two PODs can be determined. Therefore, the unit traffic relationship in the target cluster can be determined according to the traffic information of each computing unit in the target cluster.

[0155] Exemplarily, the unit traffic relationship may be as Figure 1e shown. The computing units in the target cluster may include POD1, POD2, POD3, POD4, POD5, POD6, and POD7. According to the asset information of each POD in the target cluster, it can be known that POD1 and POD2 belong to WORKLOAD1, POD3 and POD4 belong to WORKLOAD2, and POD5, POD6, and POD7 belong to WORKLOAD3. According to the traffic information of each POD in the target cluster, it can be obtained that the unit traffic path between POD1 and POD5 is path 1, and the traffic direction of path 1 is from POD1 to POD5. The unit traffic path between POD2 and POD7 is path 2, and the traffic direction of path 2 is from POD7 to POD2. The unit traffic path between POD3 and POD4 is path 3, and the traffic direction of path 3 is from POD3 to POD4. The unit traffic path between POD4 and POD6 is path 4, and the traffic direction of path 4 is from POD6 to POD6.

[0156] B2. Determine the load traffic relationship of the workload according to the unit traffic relationship.

[0157] In some embodiments, in step B2, the specific implementation of determining the load traffic relationship of the workload according to the unit traffic relationship may include:

[0158] B21. Determine the associated computing unit corresponding to the computing unit in the target cluster according to the unit traffic relationship. There is a unit traffic path between the associated computing unit and the computing unit.

[0159] Continuing with the above example, Figure 1e taking POD4 as an example in [reference], the associated computing units of POD4 include POD3 and POD6.

[0160] B22. Obtain the workload corresponding to the associated computing unit.

[0161] Continuing with the above example, it can be known that the workload corresponding to POD3 is WORKLOAD2, and the workload corresponding to POD6 is WORKLOAD3.

[0162] B23. Compare the workload corresponding to the associated computing unit with the workload corresponding to the computing unit.

[0163] Continuing with the above example, the workload corresponding to POD4 is WORKLOAD2. Compare the workload corresponding to POD4 with the workloads corresponding to POD3 and POD6 respectively to determine whether the two compared workloads are the same.

[0164] B24. If the workload corresponding to the associated computing unit is different from the workload corresponding to the computing unit, then generate a load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit based on the unit traffic path existing between the associated computing unit and the computing unit.

[0165] Continuing with the above example, through comparison, it can be found that the workload corresponding to POD4 is the same as the workload corresponding to POD3, both being WORKLOAD2. However, the workload corresponding to POD4 (WORKLOAD2) is different from the workload corresponding to POD6 (WORKLOAD3).

[0166] At this time, according to the unit traffic path (Path 4) between POD4 and POD6, a load traffic path between WORKLOAD2 and WORKLOAD3 can be generated. Specifically, a load traffic path can be generated between WORKLOAD2 and WORKLOAD3, and the traffic direction of this load traffic path is the same as the traffic direction of Path 4.

[0167] B25. Determine the load traffic relationship according to the load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit.

[0168] Among them, by traversing each computing unit in the target cluster through the method of the above steps 21 to 24, the load traffic paths and load traffic directions among the various workloads in the target cluster can be obtained, that is, the load traffic relationship.

[0169] Continuing with the above example, according to Figure 1e the unit traffic relationship in, the load traffic relationship as shown in Figure 1f can be obtained. The load traffic relationship includes a load traffic path between WORKLOAD2 and WORKLOAD3, and the direction of this load traffic path is from WORKLOAD2 to WORKLOAD3; it also includes two load traffic paths between WORKLOAD1 and WORKLOAD3, and the two load traffic paths are opposite.

[0170] In some embodiments, the specific implementation of B24 may include:

[0171] Obtain the number of paths of the unit traffic paths existing between the associated computing unit and the computing unit.

[0172] If there are multiple unit traffic paths, obtain the unit path directions of the multiple unit traffic paths.

[0173] If the unit path directions of the multiple unit traffic paths are the same, fuse the multiple unit traffic paths to obtain a load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit, and the load traffic direction of the load traffic path is the same as the unit path directions of the multiple unit traffic paths.

[0174] Exemplarily, as shown in Figure 1g , for example, there are 3 unit traffic paths between WORKLOAD8 and WORKLOAD9, namely path 5, path 6, and path 7. Since the directions of path 5, path 6, and path 7 are the same, path 5, path 6, and path 7 can be fused to obtain path A as shown in Figure 1g , and path A is used as the load traffic path between WORKLOAD8 and WORKLOAD9.

[0175] Considering that in this embodiment, the network topology graph is constructed with workloads as nodes, that is, the network asset traffic topology is displayed from the WORKLOAD perspective. Therefore, in this embodiment, by fusing multiple unit traffic paths between two workloads, the constructed network topology graph can be made more concise.

[0176] In some embodiments, the specific implementation of B24 may further include:

[0177] If the unit path directions of multiple unit traffic paths are inconsistent, then the multiple unit traffic paths are respectively fused according to different unit path directions, so as to obtain a first traffic path and a second traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit, and the path direction of the first traffic path is opposite to the path direction of the second traffic path;

[0178] The first traffic path and the second traffic path are used as the load traffic paths between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit.

[0179] Exemplarily, as Figure 1h shown, for example, there are 3 unit traffic paths between WORKLOAD8 and WORKLOAD9, namely path 5, path 6, and path 7. Since the path directions of path 5 and path 6 are different from the path direction of path 7, path 5 and path 6 can be fused to obtain a first traffic path (such as path B), and path 7 can be fused to obtain a second traffic path (such as path C), and then both the first traffic path and the second traffic path are used as the load traffic paths between WORKLOAD8 and WORKLOAD9.

[0180] 104. Based on the load traffic relationship, construct a network topology diagram of the target cluster.

[0181] In some embodiments, since the load traffic relationship includes the load traffic paths and load traffic directions between various workloads in the target cluster, each workload can be represented as a node, the load traffic paths between workloads can be represented as connections between nodes, and the load traffic directions can be represented as arrows on the connections, so as to construct a network topology diagram of the target cluster. Exemplarily, the constructed network topology diagram is as Figure 1i shown. In Figure 1i the network topology diagram, the workloads are used as nodes for display. Therefore, compared with using the computing units in the workloads as nodes for display, a large number of nodes and a large number of connections will be reduced, making the network topology diagram more concise. Optionally, as Figure 1i shown, the namespace to which each workload belongs can also be displayed in the network topology diagram, so that users can view the target cluster more intuitively and effectively.

[0182] In some embodiments, in the network topology diagram, the thickness of the connection between workloads can be positively correlated with the number of unit traffic paths fused by the connection.

[0183] In some embodiments, in step 104, the specific implementation of constructing a network topology diagram of the target cluster based on the load traffic relationship may include:

[0184] Determine the communication traffic relationship between the workload and the communication unit according to the traffic information of each computing unit in the target cluster, where the communication traffic relationship includes the traffic path and traffic direction between the workload and the communication unit;

[0185] Among them, the communication unit can communicate with the Internet as a gateway. Exemplarily, the communication unit can be an IP-based asset point, and the IP-based asset point can refer to an entity or organization that owns and manages IP addresses.

[0186] Construct a network topology diagram of the target cluster according to the communication traffic relationship and the load traffic relationship.

[0187] Among them, the communication traffic relationship includes the traffic path and traffic direction between the communication unit and the workload.

[0188] Optionally, there can be multiple communication units, and multiple communication units can be uniformly represented by an Internet node in the network topology diagram. Exemplarily, as Figure 1i shown, in the network topology diagram, there is a connection line between the node corresponding to the workload and the Internet node, indicating that there is a traffic path between the workload and at least one communication unit included in the Internet node. Thus, the display of the nodes corresponding to the communication units in the network topology diagram can be avoided, and the display of the connection lines between the communication units and the workload can be significantly reduced, making the network topology diagram more concise.

[0189] In some embodiments, after step 104, the method may further include:

[0190] In response to the topology diagram display instruction, display the network topology diagram, where the network topology diagram includes nodes and the connection lines between the nodes, the nodes represent the workload, and the connection lines represent the load traffic relationship.

[0191] Among them, the topology diagram display instruction can be an instruction sent by the user to the server for requesting to display the network topology diagram. The topology diagram display instruction can be sent by the user to the server through the input device of the server (such as a touch screen, keyboard, mouse, etc.), or can be sent by the user to the server through a mobile terminal communicatively connected to the server.

[0192] After receiving the topology diagram display instruction, the server can display the network topology diagram corresponding to the topology diagram display instruction through its display device. It can also send the network topology diagram corresponding to the topology diagram display instruction to the user's mobile terminal for display on the mobile terminal. How to display it specifically is not limited here.

[0193] In some embodiments, after step 104, the method may further include:

[0194] Obtain the annotation time corresponding to the network topology diagram, where the annotation time is the collection time of the asset information and traffic information used to construct the network topology.

[0195] Annotate the network topology diagram based on the construction time, and store the annotated network topology diagram in the topology diagram database.

[0196] Exemplarily, for example, when a user uses the Kubernetes platform on a server, a network topology diagram corresponding to a time period can be generated at regular intervals through the above network topology diagram construction method and stored in the topology diagram database. For example, the topology diagram database can include network topology diagram 1 corresponding to time T1 to time T2, network topology diagram 2 corresponding to time T2 to time T3, and network topology Figure 3 , where time T1, time T2, and time T3 are all historical times.

[0197] Correspondingly, the specific implementation manner of displaying the network topology diagram in response to the topology diagram display instruction may include:

[0198] Determine the target annotation time indicated by the topology diagram display instruction.

[0199] Among them, the target annotation time may be carried in the topology diagram display instruction, so the server can extract the target annotation time from the topology diagram display instruction.

[0200] Extract the network topology diagram that matches the target annotation time from the topology diagram database, and display the network topology diagram that matches the target annotation time.

[0201] Continuing with the above example, if the target annotation time is from time T2 to time T3, then the server can display network topology diagram 2.

[0202] In this embodiment, by time annotating the network topology diagrams generated at historical times and storing them in the topology diagram database, it is convenient for users to recall the network topology diagrams of historical events.

[0203] In some embodiments, after the step of displaying the network topology diagram in response to the topology diagram display instruction, the method may further include:

[0204] In response to a viewing instruction for a node in the network topology diagram, obtain the asset information and traffic information of each computing unit included in the workload corresponding to the node.

[0205] Display the asset information and traffic information of each computing unit included in the workload corresponding to the node.

[0206] Exemplarily, for example, the user pairs with Figure 1iAfter a viewing instruction is sent from a node corresponding to a workload in the shown network topology diagram, the server can display the asset information and traffic information of each computing unit included in the workload corresponding to the node. Optionally, the asset information and traffic information can be displayed through a list or through a computing unit relationship diagram, which is not limited herein.

[0207] Exemplarily, for the computing unit relationship diagram, the computing unit relationship diagram can be as Figure 1j shown. The computing unit relationship diagram can include multiple traffic flows, such as the traffic relationship between POD A and POD B, and the traffic from POD C to the INTERNET. Specifically, in Figure 1j , it can be known that a traffic flow corresponds to source POD information (such as Figure 1j the IP, LABEL, SERVICE of POD A), destination POD information (such as Figure 1j the IP, LABEL, SERVICE of POD B), protocol type (such as Figure 1j protocols such as SYN, TCP, PORT, PROTOCL), occurrence time (such as Figure 1j TIME), flag bit (such as Figure 1j ACTION) etc., see Figure 4 . In addition to the traffic between PODs, it also includes the traffic from POD to the INTERNET (such as Figure 1j the traffic from POD C to the INTERNET).

[0208] It can be seen that in this embodiment, after obtaining the asset information and traffic information of each computing unit in the target cluster, at least one workload is determined from the target cluster according to the asset information, where the workload includes at least one computing unit; then, for each workload, the load traffic relationship between the workload and other workloads in the target cluster is determined according to the traffic information of each computing unit in the workload, and the load traffic relationship includes the load traffic path and load traffic direction between the workloads; finally, based on the load traffic relationship, the network topology diagram of the target cluster is constructed. That is to say, by aggregating a large number of computing units in the target cluster into a small number of workloads according to the asset information and traffic information of the computing units, and constructing a network topology diagram with the workloads as nodes, the traffic of the computing units can be effectively converged, thus greatly reducing the complexity of the network topology diagram and also reducing the visual congestion of the user, so that the user can effectively make further analysis and decisions based on the visualized network topology diagram.

[0209] Embodiment 2

[0210] The method described in the above embodiment will be further described in detail below.

[0211] In this embodiment, taking the construction of a network topology diagram as an example, the method of the embodiment of the present application will be described in detail.

[0212] As Figure 2a shown, the specific process of a network topology diagram construction method is as follows:

[0213] 201. The server obtains the asset information and traffic information of each computing unit in the target cluster.

[0214] In some embodiments, in step 201, the specific implementation of obtaining the asset information and traffic information of each computing unit in the target cluster may include:

[0215] For each computing unit in the target cluster, obtain at least one initial asset information and at least one initial traffic information collected by the computing unit within a specified time period;

[0216] According to the preset asset conditions, filter at least one initial asset information to obtain the asset information of the computing unit;

[0217] According to the preset traffic conditions, filter at least one initial traffic information to obtain the traffic information of the computing unit.

[0218] Among them, the step "According to the preset asset conditions, filter at least one initial asset information to obtain the asset information of the computing unit" may include:

[0219] Delete the repeated initial asset information in at least one initial asset information to obtain the asset information of the computing unit.

[0220] Among them, the step "According to the preset traffic conditions, filter at least one initial traffic information to obtain the traffic information of the computing unit" may include:

[0221] Delete the repeated initial traffic information in at least one initial traffic information to obtain the traffic information of the computing unit.

[0222] 202. The server determines at least one workload from the target cluster according to the asset information, and the workload includes at least one computing unit.

[0223] 203. For each workload, the server determines the load traffic relationship between the workload and other workloads in the target cluster according to the traffic information of each computing unit in the workload. Among them, the load traffic relationship includes the load traffic path and load traffic direction between the workloads.

[0224] Among them, in step 203, determining the load traffic relationship between the workload and other workloads in the target cluster according to the traffic information of each computing unit in the workload may include:

[0225] For each computing unit in the workload, according to the traffic information of the computing unit, determine the unit traffic relationship between the computing unit and other computing units in the target cluster. The unit traffic relationship includes the unit traffic path and the unit traffic direction between the computing units;

[0226] According to the unit traffic relationship, determine the load traffic relationship of the workload.

[0227] Among them, the specific implementation of the step "According to the unit traffic relationship, determine the load traffic relationship of the workload" may include:

[0228] According to the unit traffic relationship, determine the associated computing unit corresponding to the computing unit in the target cluster. There is a unit traffic path between the associated computing unit and the computing unit;

[0229] Obtain the workload corresponding to the associated computing unit;

[0230] Compare the workload corresponding to the associated computing unit with the workload corresponding to the computing unit;

[0231] If the workload corresponding to the associated computing unit is different from the workload corresponding to the computing unit, then based on the unit traffic path existing between the associated computing unit and the computing unit, generate a load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit;

[0232] According to the load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit, determine the load traffic relationship.

[0233] Among them, the specific implementation of the step "Based on the unit traffic path existing between the associated computing unit and the computing unit, generate a load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit" may include:

[0234] Obtain the number of paths of the unit traffic path existing between the associated computing unit and the computing unit;

[0235] If there are multiple unit traffic paths, obtain the unit path directions of the multiple unit traffic paths;

[0236] If the unit path directions of multiple unit traffic paths are the same, then fuse the multiple unit traffic paths to obtain a load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit, and the load traffic direction of the load traffic path is the same as the unit path directions of the multiple unit traffic paths.

[0237] Wherein, the method may further include:

[0238] If the unit path directions of multiple unit traffic paths are not the same, then fuse the multiple unit traffic paths separately according to different unit path directions to obtain a first traffic path and a second traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit, and the path direction of the first traffic path is opposite to the path direction of the second traffic path;

[0239] Use the first traffic path and the second traffic path as the load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit.

[0240] 204. The server constructs a network topology diagram of the target cluster based on the load traffic relationship.

[0241] In some embodiments, the specific implementation of step 204 may include:

[0242] Determine the communication traffic relationship between the workload and the communication unit according to the traffic information of each computing unit in the target cluster, and the communication traffic relationship includes the traffic path and traffic direction between the workload and the communication unit;

[0243] Construct a network topology diagram of the target cluster according to the communication traffic relationship and the load traffic relationship.

[0244] In some embodiments, after step 204, the method may further include:

[0245] Obtain the annotation time corresponding to the network topology diagram, and the annotation time is the acquisition time of the asset information and traffic information used when constructing the network topology diagram;

[0246] Annotate the network topology diagram based on the acquisition time and store the annotated network topology diagram in the topology diagram database.

[0247] 205. The server displays the network topology diagram in response to the topology diagram display instruction, and the network topology diagram includes nodes and connections between the nodes. Wherein, the nodes represent workloads, and the connections represent the load traffic relationship.

[0248] In some embodiments, in step 205, in response to the topology diagram display instruction, the specific implementation of displaying the network topology diagram may include:

[0249] Determine the target annotation time indicated by the topology graph display instruction;

[0250] Extract the network topology graph that matches the target annotation time from the topology graph database, and display the network topology graph that matches the target annotation time.

[0251] 206. In response to a viewing instruction for a target node in the network topology graph, the server obtains the target workload corresponding to the target node.

[0252] 207. The server obtains the asset information and traffic information of each computing unit in the target workload.

[0253] 208. The server displays the asset information and traffic information of each computing unit in the target workload.

[0254] Exemplarily, in practical applications, taking the POD asset as the computing unit as an example, steps 201 to 208 can be implemented through the network asset traffic visualization process as shown in Figure 2b the following.

[0255] First, the host can collect POD traffic through the eBPF technology to obtain POD traffic (i.e., the above-mentioned traffic information), and collect POD assets through the Informer mechanism to obtain POD assets (i.e., the above-mentioned asset information). Among them, the host can be equivalent to the above-mentioned server, and a visualization platform can be installed in the server, and the visualization platform can be built based on Kubernetes.

[0256] Then, aggregate the POD traffic and aggregate the POD assets.

[0257] Among them, when aggregating the POD traffic, it can include two parts: one is to convert the raw traffic data captured by eBPF to convert POD traffic with different protocols and different formats into a unified format matching the visualization platform. The second is to remove duplicate traffic collected during the eBPF collection period. Among them, after aggregating the POD traffic, the eBPF program can also filter and classify the captured data packets according to specific filtering rules and conditions to obtain the filtered POD traffic.

[0258] When aggregating POD assets, it can also include two parts. One is the POD asset conversion, which mainly associates the POD asset information with K8S assets according to the POD original information and in combination with the information of k8s, so as to obtain the relationships among POD assets, WORKLOAD assets, and NAMESPACE assets. This process will perform an association conversion on the source node and the target POD assets. The other is to deduplicate the same POD assets and the same IP-class asset points during the period collected by the Informer.

[0259] Then, for the filtered POD traffic and the aggregated POD assets, WORKLOAD traffic asset aggregation can be carried out. Specifically, WORKLOAD traffic asset aggregation can have the following two functions: One is to construct points for assets with assets but no traffic, construct points and edges for source assets and destination assets with traffic, and aggregate the POD source points and POD target points in the above asset points and traffic. The traffic itself serves as the edge and is saved into the self-built graph model. The other is to construct the points (equivalent to the nodes in the network topology graph constructed in the above embodiments) and edges (equivalent to the connections between the nodes in the network topology graph constructed in the above embodiments) of the network topology graph with WORKLOAD or INTERNET as the basic unit according to the POD traffic and asset information. The role of this is to converge the multiple POD traffic of the same WORKLOAD, and the IP-class asset points are uniformly attributed to the INTERNET node, so that the network asset traffic topology can be displayed from the WORKLOAD perspective. After WORKLOAD traffic asset aggregation, the data required to construct the network topology graph (which can be abbreviated as the real-time graph) at the current moment can be obtained. This data can reflect the load traffic relationship among WORKLOADs. Then, the data required for the real-time graph can be saved into the real-time graph model. Among them, the real-time graph model is a graph model topology constructed according to the real-time traffic and historical time assets. The edge represents the relationship between nodes and usually represents the transmission path of network traffic. Each edge has some properties (EdgeProperties), which are key-value pairs used to describe the characteristics and metadata of the edge. Among them, the graph is the container of the entire topology graph model, containing the hash value, traits, vertex set, out-edge set, and in-edge set. The graph can also store and manage nodes and the relationships between them.

[0260] Among them, the topology graph model also provides some methods to operate on the graph. For example, the New function is used to create a new graph instance. Another example is that the AddVertex method can be used to add nodes to the graph. Before adding nodes, some type filtering is performed to ensure that only compliant nodes are added. Another example is that the Vertex method can be used to obtain a node with a specified hash value. Another example is that some graph models also provide an AddEdge method to add edges. Before adding an edge, it is checked whether the source node and the target node already exist. If not, these two nodes are added first. Another example is that the Edge method can be used to obtain the edge between a specified source node and target node, so as to perform graph search on real-time data in the visualization platform.

[0261] In addition, the filtered POD traffic and the aggregated POD assets obtained above can be managed by the historical traffic manager and the historical asset manager respectively. Among them, the historical traffic manager can manage the POD traffic required to generate the network topology graph (which can be abbreviated as the historical graph) at a historical moment, and the historical asset manager can manage the POD assets required to generate the network topology graph at a historical moment. Among them, the historical traffic manager and the historical asset manager can respectively send the data they manage to the historical graph model so that the historical graph model constructs the historical graph. The historical graph model is a graph model topology constructed based on the POD traffic and POD assets within a historical time range. Similar to the real-time graph model, except that the data is historical data, so as to perform graph search on historical data in the visualization platform.

[0262] In practical applications, when the visualization platform receives a graph search instruction, it can determine whether the requirement of the graph search instruction is a historical graph search. If so, graph traversal operations are performed in the real-time graph model. If not, graph traversal operations are performed in the historical graph model.

[0263] Among them, graph traversal means that the visualization platform finds adjacent points and edges for specific points or specific edges. In this embodiment, it supports finding all adjacent points and edges for a certain asset point. The graph traversal algorithm used can be the breadth-first search algorithm. Breadth-first search is performed based on a specific search starting point, and it can be used to search for adjacent point edges based on NAMESPACE, WORKLOAD, and POD.

[0264] It can be seen that in this embodiment, through the above network topology graph construction method, deploying the client and the server using the CS architecture, an efficient and rich commercializable visualization platform can be built. This visualization platform can achieve the following technical effects:

[0265] 1. Support multiple network topologies: Based on the CS architecture, by installing the client for each user in each cluster and connecting the client to the background, the visualization problem of multiple users, multiple clusters, and multiple networks is solved.

[0266] 2. Rich visualization types: The client-side collects asset information in real time, combines eBPF to capture real-time traffic information, and aggregates through traffic and assets to form a traffic and asset topology, solving the problem of a single visualization platform type.

[0267] 3. Efficient construction of traffic topology: Through an asynchronous update mechanism, combined with eBPF traffic capture technology and background caching technology, the problem of low efficiency in constructing the traffic topology of the visualization platform can be solved.

[0268] 4. Rich network traffic types: Based on eBPF technology, various types of data are collected, such as TCP, UDP and other types of traffic information, solving the problem of a single traffic type in the visualization platform.

[0269] 5. Intuitive display from the perspective of WORKLOAD assets: Based on the traffic information between PODs, the traffic information is aggregated in an asset aggregation manner, which can effectively converge POD traffic, display WORKLOAD association information, and can also effectively converge IP traffic and display INTERNET association information, thus greatly reducing the data volume and allowing users to focus on business WORKLOAD information, solving the problem of the data flood of POD and INTERNET asset traffic.

[0270] 6. Support for displaying asset subordination relationships: Using a self-developed graph model, aggregate the subordination relationships of NAMESPACE, WORKLOAD, and POD, and construct a graph model from these relationships, making it convenient for users to view the subordination relationships between assets.

[0271] 7. Efficient construction of asset topology: Through an asynchronous update mechanism, combined with the informer mechanism of the client, it can perceive k8s asset changes in real time, and combined with background caching technology, the problem of low efficiency in constructing the asset topology of the visualization platform can be solved.

[0272] 8. Support for graph search: Using the above graph model, aggregate asset and traffic information to construct a graph network model that can be searched deeply and widely, and use the breadth-first search algorithm for graph search.

[0273] 9. Support for searching historical asset traffic within a time range: Store the historical traffic and assets collected in real time, construct historical assets and historical traffic, so as to support the search of historical asset traffic topologies.

[0274] Example 3

[0275] To better implement the above method, an embodiment of the present application further provides a network topology diagram construction device, which can be specifically integrated in an electronic device. The electronic device can be a terminal, a server, or other devices. Among them, the terminal can be a mobile phone, a tablet computer, a smart Bluetooth device, a notebook computer, a personal computer, or other devices; the server can be a single server or a server cluster composed of multiple servers.

[0276] For example, in this embodiment, taking the network topology diagram construction device specifically integrated in the network topology diagram construction as an example, the method of the embodiment of the present application will be described in detail.

[0277] For example, as Figure 3 shown, the network topology diagram construction device may include an acquisition unit 301, a first determination unit 302, a second determination unit 303, and a topology diagram construction unit 304, as follows:

[0278] The acquisition unit 301 is configured to acquire the asset information and traffic information of each computing unit in the target cluster;

[0279] The first determination unit 302 is configured to determine at least one workload from the target cluster according to the asset information, where the workload includes at least one computing unit;

[0280] The second determination unit 303 is configured to, for each workload, determine the load traffic relationship between the workload and other workloads in the target cluster according to the traffic information of each computing unit in the workload, where the load traffic relationship includes the load traffic path and load traffic direction between the workloads;

[0281] The topology diagram construction unit 304 is configured to construct a network topology diagram of the target cluster based on the load traffic relationship.

[0282] In some embodiments, the second determination unit 303 includes:

[0283] The unit traffic relationship determination module is configured to, for each computing unit in the workload, determine the unit traffic relationship between the computing unit and other computing units in the target cluster according to the traffic information of the computing unit, where the unit traffic relationship includes the unit traffic path and unit traffic direction between the computing units;

[0284] The load traffic relationship determination module is configured to determine the load traffic relationship of the workload according to the unit traffic relationship.

[0285] In some embodiments, the load traffic relationship determination module is specifically configured to:

[0286] Determine the associated computing unit corresponding to the computing unit in the target cluster according to the unit traffic relationship, and there is a unit traffic path between the associated computing unit and the computing unit;

[0287] Obtain the workload corresponding to the associated computing unit;

[0288] Compare the workload corresponding to the associated computing unit with the workload corresponding to the computing unit;

[0289] If the workload corresponding to the associated computing unit is different from the workload corresponding to the computing unit, then generate a load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit based on the unit traffic path existing between the associated computing unit and the computing unit;

[0290] Determine the load traffic relationship according to the load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit.

[0291] In some embodiments, the load traffic relationship determination module is further specifically configured to:

[0292] Obtain the number of paths of the unit traffic path existing between the associated computing unit and the computing unit;

[0293] If there are multiple unit traffic paths, obtain the unit path directions of the multiple unit traffic paths;

[0294] If the unit path directions of the multiple unit traffic paths are the same, then fuse the multiple unit traffic paths to obtain a load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit, and the load traffic direction of the load traffic path is the same as the unit path direction of the multiple unit traffic paths.

[0295] In some embodiments, the load traffic relationship determination module is further specifically configured to:

[0296] If the unit path directions of the multiple unit traffic paths are not the same, then fuse the multiple unit traffic paths separately according to different unit path directions to obtain a first traffic path and a second traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit, and the path direction of the first traffic path is opposite to the path direction of the second traffic path;

[0297] Use the first traffic path and the second traffic path as the load traffic paths between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit.

[0298] In some embodiments, the network topology graph construction device further includes:

[0299] A first response unit, configured to display a network topology diagram in response to a topology diagram display instruction. The network topology diagram includes nodes and connections between the nodes. The nodes represent workloads, and the connections represent load traffic relationships.

[0300] In some embodiments, the network topology diagram construction device further includes:

[0301] A second response unit, configured to obtain a target workload corresponding to a target node in the network topology diagram in response to a viewing instruction for the target node in the network topology diagram;

[0302] An information acquisition unit 301, configured to acquire asset information and traffic information of each computing unit in the target workload;

[0303] An information display unit, configured to display the asset information and traffic information of each computing unit in the target workload.

[0304] In some embodiments, the network topology diagram construction device further includes:

[0305] A time acquisition unit 301, configured to acquire an annotation time corresponding to the network topology diagram. The annotation time is the acquisition time of the asset information and traffic information used when constructing the network topology diagram;

[0306] A storage unit, configured to annotate the network topology diagram based on the acquisition time and store the annotated network topology diagram in a topology diagram database;

[0307] The first response unit is specifically configured to:

[0308] Determine a target annotation time indicated by the topology diagram display instruction;

[0309] Extract a network topology diagram matching the target annotation time from the topology diagram database and display the network topology diagram matching the target annotation time.

[0310] In some embodiments, the acquisition unit 301 includes:

[0311] An initial information acquisition module, configured to acquire at least one initial asset information and at least one initial traffic information collected by each computing unit in the target cluster within a specified time period;

[0312] A first filtering module, configured to perform a filtering process on at least one initial asset information according to a preset asset condition to obtain the asset information of the computing unit;

[0313] A second filtering module, configured to perform a filtering process on at least one initial traffic information according to a preset traffic condition to obtain the traffic information of the computing unit.

[0314] In some embodiments, the first filtering module is specifically configured to:

[0315] Delete the duplicate initial asset information in at least one initial asset information to obtain the asset information of the computing unit.

[0316] In some embodiments, the second filtering module is specifically configured to:

[0317] Delete the duplicate initial traffic information in at least one initial traffic information to obtain the traffic information of the computing unit.

[0318] In some embodiments, the target cluster further includes a communication unit, and the topology graph construction unit 304 is specifically configured to:

[0319] Determine the communication traffic relationship between the workload and the communication unit according to the traffic information of each computing unit in the target cluster, where the communication traffic relationship includes the traffic path and traffic direction between the workload and the communication unit;

[0320] Construct the network topology graph of the target cluster according to the communication traffic relationship and the load traffic relationship.

[0321] In specific implementation, each of the above units can be implemented as an independent entity, or can be arbitrarily combined and implemented as the same or several entities. For the specific implementation of each of the above units, reference can be made to the foregoing method embodiments, which will not be elaborated herein.

[0322] Embodiment 4

[0323] The embodiment of the present application further provides an electronic device, which can be a device such as a terminal or a server. Among them, the terminal can be a mobile phone, a tablet computer, a smart Bluetooth device, a notebook computer, a personal computer, etc.; the server can be a single server or a server cluster composed of multiple servers, etc.

[0324] In some embodiments, the network topology graph construction device can also be integrated in multiple electronic devices. For example, the network topology graph construction device can be integrated in multiple servers, and the network topology graph construction method of the present application is implemented by multiple servers.

[0325] In this embodiment, the electronic device of this embodiment will be described in detail as an example. For example, as Figure 4 shown, it shows a schematic structural diagram of the electronic device involved in the embodiment of the present application. Specifically:

[0326] The electronic device may include a processor 401 with one or more processing cores, a memory 402 with one or more computer-readable storage media, a power supply 403, an input module 404, and a communication module 405 and other components. Those skilled in the art can understand, Figure 4The structure of the electronic device shown does not constitute a limitation on the electronic device, and it may include more or fewer components than shown, or combine certain components, or have different component arrangements. Among them:

[0327] The processor 401 is the control center of the electronic device. It connects various parts of the entire electronic device using various interfaces and circuits. By running or executing software programs and / or modules stored in the memory 402, and by calling the data stored in the memory 402, it executes various functions of the electronic device and processes data, thereby performing an overall detection of the electronic device. In some embodiments, the processor 401 may include one or more processing cores; in some embodiments, the processor 401 may integrate an application processor and a modem processor. Among them, the application processor mainly processes the operating system, user interface, application programs, etc., and the modem processor mainly processes wireless communication. It can be understood that the above-mentioned modem processor may not be integrated into the processor 401 either.

[0328] The memory 402 can be used to store software programs and modules. The processor 401 executes various functional applications and data processing by running the software programs and modules stored in the memory 402. The memory 402 mainly includes a program storage area and a data storage area. Among them, the program storage area can store the operating system, application programs required for at least one function (such as the sound playback function, image playback function, etc.), etc.; the data storage area can store data created according to the use of the electronic device, etc. In addition, the memory 402 can include high-speed random access memory, and can also include non-volatile memory, such as at least one magnetic disk storage device, flash memory device, or other volatile solid-state storage devices. Correspondingly, the memory 402 can also include a memory controller to provide the processor 401 with access to the memory 402.

[0329] The electronic device also includes a power source 403 that supplies power to each component. In some embodiments, the power source 403 can be logically connected to the processor 401 through a power management system, so as to implement functions such as management of charging, discharging, and power consumption management through the power management system. The power source 403 can also include any components such as one or more DC or AC power sources, a recharge system, a power failure detection circuit, a power converter or inverter, and a power status indicator.

[0330] The electronic device may also include an input module 404, which can be used to receive input digital or character information, and generate keyboard, mouse, joystick, optical or trackball signal inputs related to user settings and function controls.

[0331] The electronic device may further include a communication module 405. In some embodiments, the communication module 405 may include a wireless module. The electronic device may perform short-range wireless transmission through the wireless module of the communication module 405, thereby providing users with wireless broadband Internet access. For example, the communication module 405 may be used to help users send and receive emails, browse web pages, and access streaming media, etc.

[0332] Although not shown, the electronic device may further include a display unit and the like, which will not be elaborated here. Specifically, in this embodiment, the processor 401 in the electronic device will load the executable files corresponding to the processes of one or more application programs into the memory 402 according to the following instructions, and the processor 401 will run the application programs stored in the memory 402 to implement various functions.

[0333] For the specific implementation of each of the above operations, reference may be made to the previous embodiments, which will not be elaborated here.

[0334] Those of ordinary skill in the art can understand that all or part of the steps in the various methods of the above embodiments can be completed by instructions, or by instructions controlling relevant hardware. The instructions can be stored in a computer-readable storage medium and loaded and executed by a processor.

[0335] Therefore, an embodiment of the present application provides a computer-readable storage medium, in which multiple instructions are stored. The instructions can be loaded by a processor to execute the steps in any network topology diagram construction method provided by the embodiments of the present application.

[0336] Among them, the storage medium may include: read-only memory (ROM, Read Only Memory), random access memory (RAM, Random Access Memory), magnetic disk or optical disc, etc.

[0337] According to one aspect of the present application, there is provided a computer program product or computer program. The computer program product or computer program includes computer instructions, and the computer instructions are stored in a computer-readable storage medium. The processor of the computer device reads the computer instructions from the computer-readable storage medium, and the processor executes the computer instructions, so that the computer device executes the method provided in the above embodiments.

[0338] Since the instructions stored in the storage medium can execute the steps in any network topology diagram construction method provided by the embodiments of the present application, the beneficial effects that can be achieved by any network topology diagram construction method provided by the embodiments of the present application can be realized. For details, please refer to the previous embodiments, which will not be elaborated here.

[0339] The above has introduced in detail a method, apparatus, electronic device, and computer-readable storage medium for constructing a network topology diagram. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application; at the same time, for those skilled in the art, according to the idea of the present application, there will be changes in the specific implementation manner and application scope. In summary, the content of this specification should not be construed as a limitation to the present application.

Claims

1. A method for constructing a network topology diagram, characterized in that Including: Obtain the asset information and traffic information of each computing unit in the target cluster; Determine at least one workload from the target cluster according to the asset information, where the workload includes at least one computing unit; For each workload, determine the load traffic relationship between the workload and other workloads in the target cluster according to the traffic information of each computing unit in the workload, where the load traffic relationship includes the load traffic path and load traffic direction between workloads; Construct a network topology map of the target cluster based on the load traffic relationship.

2. The method according to claim 1, characterized in that The determining the load traffic relationship between the workload and other workloads in the target cluster according to the traffic information of each computing unit in the workload includes: For each computing unit in the workload, determine the unit traffic relationship between the computing unit and other computing units in the target cluster according to the traffic information of the computing unit, where the unit traffic relationship includes the unit traffic path and unit traffic direction between computing units; Determine the load traffic relationship of the workload according to the unit traffic relationship.

3. The method according to claim 2, wherein The determining the load traffic relationship of the workload according to the unit traffic relationship includes: Determine the associated computing unit corresponding to the computing unit in the target cluster according to the unit traffic relationship, where there is a unit traffic path between the associated computing unit and the computing unit; Obtain the workload corresponding to the associated computing unit; Compare the workload corresponding to the associated computing unit with the workload corresponding to the computing unit; If the workload corresponding to the associated computing unit is different from the workload corresponding to the computing unit, generate a load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit based on the unit traffic path existing between the associated computing unit and the computing unit; Determine the load traffic relationship according to the load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit.

4. The method according to claim 3, characterized in that, The generating a load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit based on the unit traffic path existing between the associated computing unit and the computing unit includes: Obtain the number of paths of the unit traffic path existing between the associated computing unit and the computing unit; If there are multiple unit traffic paths, obtain the unit path directions of the multiple unit traffic paths; If the unit path directions of the multiple unit traffic paths are the same, fuse the multiple unit traffic paths to obtain a load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit, and the load traffic direction of the load traffic path is the same as the unit path directions of the multiple unit traffic paths.

5. The method according to claim 4, wherein The method further includes: If the unit path directions of multiple said unit traffic paths are inconsistent, then fuse the multiple said unit traffic paths separately according to different unit path directions, so as to obtain a first traffic path and a second traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit, and the path direction of the first traffic path is opposite to the path direction of the second traffic path; Use the first traffic path and the second traffic path as the load traffic path between the workload corresponding to the associated computing unit and the workload corresponding to the computing unit.

6. The method according to claim 1, wherein After constructing the network topology diagram of the target cluster based on the load traffic relationship, the method further includes: In response to a topology diagram display instruction, display the network topology diagram, where the network topology diagram includes nodes and connections between nodes, the nodes represent the workloads, and the connections represent the load traffic relationship.

7. The method according to claim 6, characterized in that, After displaying the network topology diagram in response to the topology diagram display instruction, the method further includes: In response to a viewing instruction for a target node in the network topology diagram, obtain the target workload corresponding to the target node; Obtain the asset information and traffic information of each computing unit in the target workload; Display the asset information and traffic information of each computing unit in the target workload.

8. The method according to claim 6, characterized in that After constructing the network topology diagram of the target cluster based on the load traffic relationship, the method further includes: Obtain the annotation time corresponding to the network topology diagram, where the annotation time is the collection time of the asset information and traffic information used when constructing the network topology diagram; Annotate the network topology diagram based on the collection time, and store the annotated network topology diagram in the topology diagram database; The step of displaying the network topology diagram in response to the topology diagram display instruction includes: Determine the target annotation time indicated by the topology diagram display instruction; Extract the network topology diagram that matches the target annotation time from the topology diagram database, and display the network topology diagram that matches the target annotation time.

9. The method according to any one of claims 1 to 8, characterized in that The step of obtaining the asset information and traffic information of each computing unit in the target cluster includes: For each computing unit in the target cluster, obtain at least one initial asset information and at least one initial traffic information collected within a specified time period; Filter the at least one initial asset information according to a preset asset condition to obtain the asset information of the computing unit; Filter the at least one initial traffic information according to a preset traffic condition to obtain the traffic information of the computing unit.

10. The method according to claim 9, wherein The step of filtering the at least one initial asset information according to a preset asset condition to obtain the asset information of the computing unit includes: Delete the duplicate initial asset information in the at least one initial asset information to obtain the asset information of the computing unit.

11. The method according to claim 9, wherein The step of filtering the at least one initial traffic information according to a preset traffic condition to obtain the traffic information of the computing unit includes: Delete the duplicate initial traffic information in the at least one initial traffic information to obtain the traffic information of the computing unit.

12. The method according to any one of claims 1 to 8, characterized in that, The target cluster further includes a communication unit. Building the network topology diagram of the target cluster based on the load traffic relationship includes: Determine the communication traffic relationship between the workload and the communication unit according to the traffic information of each computing unit in the target cluster. The communication traffic relationship includes the traffic path and traffic direction between the workload and the communication unit. Build the network topology diagram of the target cluster according to the communication traffic relationship and the load traffic relationship.

13. A network topology diagram construction device, characterized in that, Includes: An acquisition unit for acquiring the asset information and traffic information of each computing unit in the target cluster. A first determination unit for determining at least one workload from the target cluster according to the asset information. The workload includes at least one computing unit. A second determination unit for, for each workload, determining the load traffic relationship between the workload and other workloads in the target cluster according to the traffic information of each computing unit in the workload. The load traffic relationship includes the load traffic path and load traffic direction between the workloads. A topology diagram building unit for building the network topology diagram of the target cluster based on the load traffic relationship.

14. An electronic device, characterized in that, Includes a processor and a memory. The memory stores multiple instructions. The processor loads the instructions from the memory to execute the steps in the network topology diagram building method according to any one of claims 1 to 12.

15. A computer-readable storage medium, characterized in that, The computer-readable storage medium stores multiple instructions. The instructions are suitable for being loaded by a processor to execute the steps in the network topology diagram building method according to any one of claims 1 to 12.

16. A computer program product, characterized in that, Includes a computer program / instructions. When the computer program / instructions are executed by a processor, the steps in the network topology diagram building method according to any one of claims 1 to 12 are implemented.