Flow path processing method and device, equipment and medium

By obtaining and visualizing the traffic paths of container groups and external service nodes, the fault location difficulties caused by network problems in the microservice architecture are solved and the troubleshooting efficiency is improved.

CN120389941APending Publication Date: 2025-07-29PING AN PAY ELECTRONIC PAYMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510554159.6
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-28
Publication Date
2025-07-29

AI Technical Summary

Technical Problem

In the microservice architecture, calling failures caused by network problems between container groups and external service nodes are difficult to quickly locate, affecting the efficiency of troubleshooting.

Method used

By obtaining traffic data from container groups and external service nodes, the traffic paths, including the network paths of the host node and the traffic transmission node, are determined and visualized, and graphical displays are provided to assist operation and maintenance personnel in quickly locate the cause of failure.

Benefits of technology

It improves the visual display of traffic paths between the container group and external service nodes, helps operation and maintenance personnel to quickly locate the cause of call failures, and improves the fault location efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120389941A_ABST
    Figure CN120389941A_ABST
Patent Text Reader

Abstract

The invention relates to the technical field of micro-services and the field of financial science and technology, and provides a flow path processing method, device, equipment and medium, and the method comprises the steps: determining a target container group and a target external service node which need to be subjected to flow path display; obtaining first flow data of a host node deployed by the target container group; obtaining second traffic data of a traffic transmission node corresponding to a node cluster where the host node is located; and determining a traffic path between the target container group and the target external service node according to the first traffic data and the second traffic data, and visually displaying the traffic path in a graphic form. According to the method and the device, the flow path between the container group and the external service node can be visually displayed, so that operation and maintenance personnel can be assisted to quickly position the fault reason causing the calling fault when the calling of the external service by the service operated by the container group fails, and the fault positioning efficiency is improved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present invention relates to the technical fields of microservices and fintech, and particularly to a traffic path processing method, a traffic path processing device, a computer device, and a computer-readable storage medium. Background Art

[0002] In the digital age, microservice architectures have been widely popularized. More and more business systems, such as insurance systems, banking systems, and e-commerce systems, have adopted microservice architectures. The core of the microservice architecture lies in splitting large business systems into multiple small, autonomous services. For example, an e-commerce system can be split into user services, product services, order services, payment services, logistics services, etc. Each service focuses on a single business function. For example, the product service is responsible for the management and display of product information.

[0003] A pod is the basic deployment unit of Kubernetes. It can contain one or more closely collaborating containers, and services run in containers. It can be understood that although a service can run independently, the realization of its function depends on the invocation of external services. When facing a call failure to an external service due to network problems, it is often necessary for operation and maintenance personnel to check each possible node between the node where the service is located and the node where the external service is located one by one. Summary of the Invention

[0004] Embodiments of the present invention provide a traffic path processing method, a traffic path processing device, a computer device, and a computer-readable storage medium, enabling the traffic path between a pod and an external service node to be visually and intuitively displayed. Thus, when a call from a service running in the pod to an external service fails, it can assist operation and maintenance personnel in quickly locating the cause of the call failure and improving the efficiency of fault location.

[0005] In a first aspect, a traffic path processing method is provided, including: Determine a target pod and a target external service node for which traffic path display is required; Obtain first traffic data of the host node on which the target pod is deployed; Obtain second traffic data of traffic transmission nodes corresponding to the node cluster where the host node is located; Determine the traffic path between the target pod and the target external service node according to the first traffic data and the second traffic data, and visually display the traffic path in the form of a graph.

[0006] In a second aspect, a traffic path processing device is provided, including: A node determination module, configured to determine a target pod and a target external service node for which traffic path display is required; A data acquisition module, configured to acquire first traffic data of a host node on which a target container group is deployed; and acquire second traffic data of a traffic transmission node corresponding to a node cluster where the host node is located; A path display module, configured to determine a traffic path between the target container group and a target external service node according to the first traffic data and the second traffic data, and visually display the traffic path in the form of a graph.

[0007] In a third aspect, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps in the above traffic path processing method are implemented.

[0008] In a fourth aspect, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps in the above traffic path processing method are implemented.

[0009] In the solution implemented by the above traffic path processing method, device, device, and medium, by determining a target container group and a target external service node for which traffic path display is required; acquiring first traffic data of a host node on which the target container group is deployed; acquiring second traffic data of a traffic transmission node corresponding to a node cluster where the host node is located; determining a traffic path between the target container group and the target external service node according to the first traffic data and the second traffic data, and visually displaying the traffic path in the form of a graph. In this way, the traffic path between the container group and the external service node can be visually and intuitively displayed, so that when a failure occurs in the call of the service running in the container group to the external service, it can assist the operation and maintenance personnel to quickly locate the cause of the call failure and improve the failure location efficiency. Description of the Drawings

[0010] In order to more clearly illustrate the technical solutions of the embodiments of the present invention, the drawings required for the description of the embodiments of the present invention will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, other drawings can be obtained based on these drawings without creative efforts.

[0011] Figure 1 is a schematic diagram of the application environment of the traffic path processing method in an embodiment of the present invention; Figure 2 is a schematic flowchart of the traffic path processing method in an embodiment of the present invention; Figure 3 is an example diagram of visually displaying a traffic path in an embodiment of the present invention; Figure 4It is another example diagram for visually displaying the traffic path in an embodiment of the present invention; Figure 5 It is an example diagram for displaying traffic status information in an embodiment of the present invention; Figure 6 It is a schematic structural diagram of a traffic path processing device in an embodiment of the present invention; Figure 7 It is a schematic structural diagram of a computer device in an embodiment of the present invention; Figure 8 It is another schematic structural diagram of a computer device in an embodiment of the present invention. Detailed implementation manners

[0012] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts shall fall within the protection scope of the present invention.

[0013] The traffic path processing method provided by the embodiments of the present invention can be applied to the application environment as Figure 1 shown, where the client communicates with the server through a network. The server can receive a path display request input by a user (such as an operation and maintenance personnel) through the client, and determine a target container group and a target external service node that need to perform traffic path display according to the path display request; obtain first traffic data of a host node where the target container group is deployed; obtain second traffic data of a traffic transmission node corresponding to the node cluster where the host node is located; determine the traffic path between the target container group and the target external service node according to the first traffic data and the second traffic data, visually display the traffic path in the form of a graph, and return the display data of the visual display to the client, so that the client can also visually display the above traffic path in the form of a graph locally. Among them, the client can include, but is not limited to, various personal computers, laptop computers, smart phones, tablet computers, and portable wearable devices. The server can be implemented by an independent server or a server cluster composed of multiple servers. The present invention will be described in detail through specific embodiments below.

[0014] Please refer to Figure 2 shown Figure 2 It is a flowchart of a traffic path processing method provided by an embodiment of the present invention, including the following steps: S110: Determine a target container group and a target external service node that need to perform traffic path display.

[0015] Kubernetes is an extensible open-source container orchestration platform for automating the deployment, scaling, and operation of containerized applications, providing automated deployment, scaling, and operation and maintenance functions for container clusters.

[0016] Microservices is an architectural pattern that breaks down a business system into independent services, each of which can be developed, deployed, and scaled independently.

[0017] A Pod is the smallest basic unit created or deployed by Kubernetes. A Pod can encapsulate one or more containers, and the container provides the running environment for the service. Containers within a Pod share storage resources, network, and runtime environment configurations, making the Pod a highly integrated service running environment.

[0018] In practical applications, a Kubernetes node cluster can be created first, then the service can be deployed into the containers in the Kubernetes nodes, and finally, the service can be managed through the Pods, including but not limited to operations such as starting, stopping, upgrading, and scaling the service. For each Pod, the Kubernetes node it runs on can be regarded as the host node of this Pod because the Pod actually runs on these nodes, and there is a hosting relationship between them.

[0019] It can be understood that during the business implementation process of a business system, there is a need for internal services of the business system to call external services. For example, the logistics service in an e-commerce system (i.e., an internal service of the e-commerce system) needs to call the logistics tracking service provided by a logistics provider (i.e., an external service of the e-commerce system) to obtain real-time logistics tracking information for display to users. This call to the external service is achieved based on the traffic transmission between the host node where the internal service is deployed (i.e., the host node of the Pod running the internal service) and the host node where the external service is deployed (i.e., the host node where the Pod running the external service is deployed, denoted as the external service node hereafter). The normality of the traffic path between the two determines the normality of the call between them, which makes it crucial to understand the traffic path between the Pod running the internal service and the external service node.

[0020] In an embodiment of the present invention, a path display request can be received, and the container group and the external service node that need to be path-identified indicated by the path display request are respectively determined as the target container group and the target external service node. Exemplarily, a request input interface can be provided, and the request input interface includes a container group configuration interface and an external service node configuration interface, where the container group configuration interface is used to configure the container group that needs to perform traffic path display, and the external service node configuration interface is used to configure the external service node that needs to perform traffic path display. For example, the network address of the container group that needs to perform traffic display can be input through the container group configuration interface to indicate the container group, and the network address that needs to perform traffic path display can be input through the external service node configuration interface to indicate the external service node.

[0021] S120: Obtain first traffic data of the host node where the target container group is deployed.

[0022] As above, after determining the target container group and the target external service node that need to perform traffic path display, on the one hand, obtain the traffic data of the host node where the target container group is deployed, which is recorded as the first traffic data. Exemplarily, the first traffic data of the host node where the target container group is deployed can be collected by a traffic collection tool matching the host node, and the collected first traffic data is stored in a time series database for subsequent processing.

[0023] For example, the first traffic data of the obtained host node may include traffic-related attribute data such as the source network address, destination network address, timestamp, and traffic size of the egress traffic of the host node.

[0024] It should be noted that for a node, the egress traffic refers to the traffic sent from the node to other external nodes, and the ingress traffic refers to the traffic sent from other external nodes to the node.

[0025] S130: Obtain second traffic data of the traffic transmission node corresponding to the node cluster where the host node is located.

[0026] The traffic transmission node refers to a related node that provides traffic transmission capabilities, such as: A router node, which plays the roles of traffic forwarding and path selection, is a bridge for interconnecting different networks, can realize the storage and packet forwarding of traffic between different networks, and forwards traffic from the source network to the target network according to the target network address; An egress gateway node, which controls the traffic flowing out of the internal network to the external network, is the traffic outlet of the internal network and the external network, and can realize functions such as protocol conversion, flow control, and monitoring of external requests. Deploying an egress gateway in a Kubernetes cluster can simplify the management and routing of external service traffic in the cluster; A firewall node is a defense system that isolates the internal network from the external network, allowing authorized traffic to pass through and rejecting unauthorized traffic.

[0027] On the other hand, the traffic data of the traffic transmission nodes corresponding to the node cluster where the host node is located is also obtained, denoted as the second traffic data. Exemplarily, the second traffic data of the traffic transmission nodes corresponding to the node cluster where the host node is located can be collected by a traffic collection tool matching the traffic transmission nodes, and the collected second traffic data is stored in a time series database for subsequent processing.

[0028] For example, the obtained second traffic data of the traffic transmission nodes may include the source network address, destination network address, timestamp, and traffic size of the incoming traffic of the traffic transmission nodes, as well as traffic-related attribute data such as the source network address, destination network address, timestamp, and traffic size of the outgoing traffic of the traffic transmission nodes.

[0029] It should be noted that the execution order of the above S120 and S130 is not affected by the sequence number. It can be that S120 is executed before S130, or S120 is executed after S130, or S120 and S130 are executed simultaneously.

[0030] S140: Determine the traffic path between the target container group and the target external service node according to the first traffic data and the second traffic data, and visually display the traffic path in the form of a graph.

[0031] As above, after obtaining the first traffic data of the host node where the target container group is deployed and the second traffic data of the traffic transmission nodes corresponding to the node cluster where the host node is located, further according to the configured traffic path determination strategy, based on the first traffic data, the second traffic data, as well as the network address of the target container group and the network address of the target external service node, determine the traffic path between the target container group and the target external service node, and according to the configured visualization strategy, visually display the determined traffic path between the target container group and the target external service node in the form of a graph, so that users can clearly understand the traffic trend from the target container group to the target external service.

[0032] Among them, the traffic path between the target container group and the target external service node can be visually displayed in the form of a two-dimensional graph, or the traffic path between the target container group and the target external service node can be visually displayed in the form of a three-dimensional graph. There is no specific limitation in the embodiments of the present invention.

[0033] Optionally, in one embodiment, the first traffic data includes the source network address and the destination network address of the egress traffic of the host node, the second traffic data includes the source network address and the destination network address of the ingress traffic of the traffic transmission node, the source network address and the destination network address of the egress traffic of the traffic transmission node, and the source network address translation record of the traffic transmission node. Determining the traffic path between the target container group and the target external service node according to the first traffic data and the second traffic data includes: Obtain the network address of the target container group and the network address of the target external service node; According to the source network address and the destination network address of the egress traffic of the host node, the source network address and the destination network address of the ingress traffic of the traffic transmission node, the source network address and the destination network address of the egress traffic of the traffic transmission node, the source network address translation record of the traffic transmission node, the network address of the target container group, and the network address of the target external service node, perform traffic association on the egress traffic of the host node, the ingress traffic and the egress traffic of the traffic transmission node, and obtain the traffic path between the target container group and the target external service node.

[0034] In the embodiment of the present invention, for the host node where the target container group is deployed, by matching the traffic collection tool of the host node, collect traffic data of the egress traffic of the host node, and obtain traffic data such as the timestamp, traffic size, source network address, and destination network address of the egress traffic. Among them, the source network address consists of two parts, namely the source IP address and the source port number, such as 192.168.0.1:8080. Similarly, the destination network address also consists of two parts, namely the destination IP address and the destination port number.

[0035] For the traffic transmission node, by matching the traffic collection tool of the traffic transmission node, collect traffic data of the ingress traffic and the egress traffic of the traffic transmission node respectively, obtain traffic data such as the timestamp, traffic size, source network address, and destination network address of the ingress traffic of the traffic transmission node, and obtain traffic data such as the timestamp, traffic size, source network address, and destination network address of the egress traffic of the traffic transmission node. In addition, obtain the source network address translation record corresponding to the egress traffic of the traffic transmission node, and this source network address translation record describes the source network address before and after the network address conversion of the egress traffic.

[0036] When determining the traffic path between the target container group and the target external service node, based on the source network address and destination network address of the egress traffic of the above host node, the source network address and destination network address of the ingress traffic of the traffic transmission node, the source network address, destination network address, and source network address translation record of the egress traffic of the traffic transmission node, the network address of the target container group, and the network address of the target external service node, traffic association is performed on the egress traffic of the host node, the ingress traffic and egress traffic of the traffic transmission node to obtain the traffic path between the target container group and the target external service node.

[0037] Exemplarily, for the egress traffic of the host node, the network address of the target container group can be used as the source network address, and the network address of the target external service node can be used as the destination network address to associate the egress traffic belonging to the target container group from the egress traffic of the host node.

[0038] For the ingress traffic of the traffic transmission node, the network address of the target container group can be used as the source network address, and the network address of the target external service node can be used as the destination network address. Then, based on the timestamp of the ingress traffic of the traffic transmission node and the timestamp of the egress traffic card of the target container group, the ingress traffic matching the egress traffic of the target container group is associated from the ingress traffic of the traffic transmission node.

[0039] For the egress traffic of the traffic transmission node, the source network address before conversion corresponding to the egress traffic is determined according to the source network address translation record. Then, using the network address of the target container group as the source network address before conversion and the network address of the target external service node as the destination network address, combined with the timestamp of the ingress traffic of the traffic transmission node matching the target container group and the timestamp of the egress traffic of the traffic transmission node, the egress traffic matching the ingress traffic of the traffic transmission node matching the target container group is associated from the egress traffic of the traffic transmission node.

[0040] Based on the above traffic association results, the traffic path between the target container group and the target external service node can be obtained. This traffic path describes the traffic flow direction between the target container group and the target external service node, as well as the path nodes through which the traffic passes. The path nodes include at least one of the host node, traffic transmission node, and external service node. For example, the determined traffic path between the target container group and the target external service node describes that the traffic from the target container group to the target external service node starts from the host node of the target container group, flows to the first traffic transmission node - the egress gateway node, after the source network address is converted through the egress gateway node, then flows to the second traffic transmission node - the firewall node, and finally flows to the target external service node after passing through the traffic control of the firewall node.

[0041] Optionally, in one embodiment, the traffic path is visually displayed in the form of a graph, including: Draw node graphics representing path nodes in the traffic path in the graphical interface, and draw connection lines representing the traffic flow directions between path nodes between the node graphics. The path nodes include at least one of a target container group, a traffic transmission node, and a target external service node.

[0042] Among them, the graphical interface can be implemented through browser-based page tools. For example, Hypertext Markup Language can be used to construct the basic structure of the graphical interface (such as titles, paragraphs, links, and pictures), various tags can be used to define different interface elements, and Cascading Style Sheets can be used to beautify the interface elements and control their appearance and layout (such as visual attributes like colors, fonts, margins, backgrounds, etc.). In addition, scripting languages can be used to add dynamic interactivity to the graphical interface, making the interaction between the user and the graphical interface more fluent and intuitive.

[0043] When visualizing the traffic path in graphical form, for a path node in the traffic path, first determine the drawing style of the node graphic representing the path node (including but not limited to at least one of the graphic shape, graphic size, graphic color, and color shade of the node graphic. The drawing style can be default-configured or dynamically configured), and then draw the node graphic representing the path node according to the determined drawing style. Then, according to the traffic flow directions between the path nodes described by the traffic path, draw connection lines representing the traffic flow directions between the path nodes between the node graphics. In addition, for the connection lines between the node graphics, the associated source network address and destination network address can also be added. Thus, the traffic path is visualized in graphical form.

[0044] For example, please refer to Figure 3 , for a traffic path from a target container group to a target external service node, this traffic path involves four path nodes, namely the host node where the target container group is deployed, the egress gateway node, the firewall node, and the target external service node. The node graphics of all path nodes are drawn according to the same drawing style, and node description information characterizing the path nodes they represent is also added to the node graphics. And on the connection lines representing the traffic flow directions, the source network address and destination network address related to the traffic from the target container group to the target external service node are added. As Figure 3As shown, it can be intuitively seen that the traffic from the target container group to the target external service node is the traffic with the source network address 10.244.0.1:65501 and the destination network address 8.8.8.8:65506. This traffic is sent from the host node where the target container group is deployed and then enters the egress gateway node. After this traffic enters the egress gateway node, the source network address is converted from 10.244.0.1:65501 to 192.168.0.1:65502 and then sent out to enter the firewall node. After this traffic enters the firewall node, the source network address is further converted from 192.168.0.1:65502 to 172.16.0.1:65503 and then sent to the target external service node.

[0045] For another example, please refer to Figure 4 . For the traffic path from a target container group to a target external service node, this traffic path involves four path nodes, namely the host node where the target container group is deployed, the egress gateway node, the firewall node, and the target external service node. The node graphics of all path nodes are drawn in different drawing styles (specifically presented as different graphic shapes), and on the connection line representing the traffic direction, the source network address and the destination network address related to the traffic from the target container group to the target external service node are added. As Figure 4 shown, it can be intuitively seen that the traffic from the target container group to the target external service node is the traffic with the source network address 10.244.0.2:65501 and the destination network address 6.6.6.6:65506. This traffic is sent from the host node where the target container group is deployed and then enters the egress gateway node. After this traffic enters the egress gateway node, the source network address is converted from 10.244.0.2:65501 to 192.168.0.2:65502 and then sent out to enter the firewall node. After this traffic enters the firewall node, the source network address is further converted from 192.168.0.2:65502 to 172.16.0.2:65503 and then sent to the target external service node.

[0046] Optionally, in an embodiment, after drawing the node graphics representing the path nodes in the traffic path and drawing the connection lines representing the traffic direction between the node graphics in the graphical interface, it further includes: Obtaining the traffic status information of the path nodes and displaying the traffic status information in the graphical interface.

[0047] In the embodiments of the present invention, in order to further enhance the visualization display effect of the traffic path, the display of traffic status information is also performed.

[0048] Among them, for the path nodes in the traffic path, the traffic status information of the path nodes is also obtained, and the traffic status information is used to describe the traffic status of the traffic corresponding to the traffic path, including but not limited to at least one of delay, packet loss rate, and bandwidth utilization rate.

[0049] For a path node, the delay describes the time taken for the above traffic to reach the next path node after leaving the path node, usually in milliseconds; the packet loss rate describes the proportion of data packets lost during the process of the traffic reaching the next path node after leaving the path node; the bandwidth utilization rate describes the ratio of the actually occupied bandwidth of the traffic to the available bandwidth, usually expressed as a percentage.

[0050] It should be noted that in the embodiments of the present invention, there is no specific limitation on the display form of the traffic status information of the path nodes in the graphical interface, which can be in text form or graphical form.

[0051] For example, please refer to Figure 5 , and display the obtained traffic status information of the path nodes in text form in the graphical interface.

[0052] Optionally, in an embodiment, after obtaining the traffic status information of the path nodes, it further includes: According to the traffic status information of the path nodes, update the drawing style of the connection line.

[0053] The embodiments of the present invention further provide a dynamic adjustment mechanism, which uses the traffic status information of the path nodes to update the drawing style of the real-time connection line. This means that if the traffic status of a certain path node changes, users will be able to quickly identify the traffic status through the visual changes of the connection line. Among them, updating the drawing style of the connection line can include changing the color, width, style (such as solid line, dotted line, dot-dash line, etc.) of the connection line, or adding specific marks and legends to represent different traffic statuses, and so on. In addition, the change trend of the traffic status can also be displayed through dynamic graphic effects, such as gradient colors or animations, so as to provide a more intuitive and dynamic visual experience.

[0054] Exemplarily, a user interface can be provided, which allows users to customize the mapping relationship between the traffic status and the drawing style of the connection line, so that users can set different colors, patterns or animation effects to represent different traffic statuses according to personal preferences or specific monitoring requirements.

[0055] Optionally, in an embodiment, after obtaining the traffic status information of the path nodes, it further includes: According to the traffic status information of the path nodes, determine the abnormal path nodes, and output the abnormal alarm information corresponding to the abnormal path nodes.

[0056] In an embodiment of the present invention, after obtaining the traffic status information of a path node, an abnormal path node is further determined according to the configured anomaly detection policy and the traffic status information of the path node.

[0057] Exemplarily, for latency, a latency threshold can be set. If it is recognized that the latency of a path node exceeds this latency threshold, it can be determined that the path node has an anomaly of excessive latency. For the packet loss rate, a packet loss rate threshold can be set. If it is recognized that the packet loss rate of a path node exceeds this packet loss rate threshold, it can be determined that the path node has an anomaly of excessive packet loss rate. For the bandwidth utilization rate, a bandwidth utilization rate threshold can be set. If it is recognized that the bandwidth utilization rate of a path node exceeds the bandwidth utilization rate threshold, it can be determined that the path node has an anomaly of excessive bandwidth utilization rate.

[0058] As above, after determining the abnormal path node, abnormal alarm information corresponding to the abnormal path node is output, and this abnormal alarm information is used to describe the anomaly that occurs in the abnormal path node.

[0059] Among them, the abnormal alarm information can also be displayed in the above graphical interface. Here, the display form of the abnormal alarm information is not specifically limited. The abnormal alarm information can be displayed in the graphical interface in the form of a graph, or the abnormal alarm information can be displayed in the graphical interface in the form of text.

[0060] Optionally, in an embodiment, after determining the abnormal path node according to the traffic status information of the path node, it further includes: Obtain the anomaly exclusion policy corresponding to the abnormal path node and output this anomaly exclusion policy.

[0061] In an embodiment of the present invention, corresponding to different types of anomalies, corresponding anomaly exclusion policies are pre-configured. These anomaly exclusion policies are designed to guide users to solve or alleviate specific anomalies, so that users can quickly take actions to process the abnormal path node, thereby restoring the normal operation state of the traffic path between the target container group and the target external service node. For example, these anomaly exclusion policies can be re-routing traffic, adjusting bandwidth allocation, updating firewall rules, and so on.

[0062] Optionally, in an embodiment, after determining the abnormal path node according to the traffic status information of the path node, it further includes: Highlight the node graph representing the abnormal path node.

[0063] In the embodiments of this aspect, in order to enable users to quickly notice the abnormal path nodes in the traffic path, after determining the abnormal path nodes, the node graphics representing the abnormal path nodes are prominently displayed according to the configured prominent display strategy. There are no specific restrictions on the configuration of the prominent display strategy here. Exemplarily, the prominent display strategy can be configured as: changing the color of the node graphics representing the abnormal path nodes to be different from the node graphics representing other path nodes, and animation effects such as adding a flashing effect to the node graphics representing the abnormal path nodes can also be added.

[0064] The following takes the traffic transmission nodes including the egress gateway node and the firewall node as an example for illustration. Among them, the target container group and the target external service node that need to perform traffic path display are determined, the network address of the target container group and the network address of the target external service node are obtained; the source network address and the target network address of the egress traffic of the host node where the target container group is deployed are obtained; the source network address and the target network address of the ingress traffic and the source network address and the target network address of the egress traffic of the egress gateway node corresponding to the node cluster where the host node is located are obtained, and the source network address and the target network address of the ingress traffic and the source network address and the target network address of the egress traffic of the firewall node corresponding to the node cluster where the host node is located are obtained; according to the network address of the target container group and the network address of the target external service node, the source network address and the target network address of the egress traffic of the host node where the target container group is deployed, the source network address and the target network address of the ingress traffic and the source network address and the target network address of the egress traffic of the egress gateway node corresponding to the node cluster where the host node is located, and the source network address and the target network address of the ingress traffic and the source network address and the target network address of the egress traffic of the firewall node corresponding to the node cluster where the host node is located, traffic association is performed to obtain the traffic path between the target container group and the target external service node; the obtained traffic path between the target container group and the target external service node is visually displayed in the form of a graph.

[0065] As can be seen from the above, the traffic path processing solution provided by the present invention determines the target container group and the target external service node that need to perform traffic path display; obtains the first traffic data of the host node where the target container group is deployed; obtains the second traffic data of the traffic transmission nodes corresponding to the node cluster where the host node is located; determines the traffic path between the target container group and the target external service node according to the first traffic data and the second traffic data, and visually displays the traffic path in the form of a graph. In this way, the traffic path between the container group and the external service node can be visually and intuitively displayed, so that when a failure occurs in the call of the service running in the container group to the external service, it can assist the operation and maintenance personnel to quickly locate the cause of the call failure and improve the failure location efficiency.

[0066] In one embodiment, a traffic path processing device is provided, which corresponds one-to-one to the traffic path processing method in the above embodiment. As Figure 6 shown, the traffic path processing device includes a node determination module 210, a data acquisition module 220, and a path display module 230. The detailed description of each functional module is as follows: The node determination module 210 is configured to determine a target container group and a target external service node for which traffic path display is required; The data acquisition module 220 is configured to acquire first traffic data of a host node on which the target container group is deployed; and acquire second traffic data of a traffic transmission node corresponding to the node cluster where the host node is located; The path display module 230 is configured to determine a traffic path between the target container group and the target external service node according to the first traffic data and the second traffic data, and visually display the traffic path in the form of a graph.

[0067] Optionally, in one embodiment, the first traffic data includes the source network address and the destination network address of the egress traffic of the host node, the second traffic data includes the source network address and the destination network address of the ingress traffic of the traffic transmission node, the source network address, the destination network address, and the source network address translation record of the egress traffic of the traffic transmission node. The path display module 230 is configured to acquire the network address of the target container group and the network address of the target external service node; according to the source network address and the destination network address of the egress traffic of the host node, the source network address and the destination network address of the ingress traffic of the traffic transmission node, the source network address, the destination network address, and the source network address translation record of the egress traffic of the traffic transmission node, the network address of the target container group, and the network address of the target external service node, perform traffic association on the egress traffic of the host node, the ingress traffic and the egress traffic of the traffic transmission node, and obtain the traffic path between the target container group and the target external service node.

[0068] Optionally, in one embodiment, the path display module 230 is configured to draw node graphics representing path nodes in the traffic path in the graphical interface, and draw connection lines representing the traffic directions between the path nodes between the node graphics. The path nodes include at least one of the target container group, the traffic transmission node, and the target external service node.

[0069] Optionally, in one embodiment, the path display module 230 is further configured to acquire the traffic status information of the path nodes, and display the traffic status information in the graphical interface.

[0070] Optionally, in one embodiment, the path display module 230 is further configured to update the drawing style of the connection lines according to the traffic status information of the path nodes.

[0071] Optionally, in one embodiment, the traffic path processing device provided by the present invention further includes an exception warning module, which is configured to determine an abnormal path node according to the traffic status information of the path node, and output exception warning information corresponding to the abnormal path node.

[0072] Optionally, in one embodiment, the path display module 230 is further configured to prominently display the node graph representing the abnormal path node.

[0073] For the specific limitations of the traffic path processing device, reference may be made to the limitations of the traffic path processing method in the foregoing text, which will not be elaborated herein. Each module in the above traffic path processing device can be implemented in whole or in part by software, hardware, and their combination. The above modules can be embedded in or independent of the processor in the computer device in the form of hardware, or stored in the memory of the computer device in the form of software, so as to facilitate the processor to call and execute the operations corresponding to the above modules.

[0074] In one embodiment, a computer device is provided. The computer device may be a server, and its internal structure diagram may be as Figure 7 shown. The computer device includes a processor, a memory, a network interface, and a database connected by a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile and / or volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with an external client through a network connection. When the computer program is executed by the processor, it implements the steps of the traffic path processing method in the above embodiments.

[0075] In one embodiment, a computer device is provided. The computer device may be a client, and its internal structure diagram may be as Figure 8 shown. The computer device includes a processor, a memory, a network interface, a display screen, and an input device connected by a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system and a computer program. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The network interface of the computer device is used to communicate with a target external server through a network connection. When the computer program is executed by the processor, it implements the steps of the traffic path processing method in the above embodiments.

[0076] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored in the memory and executable on the processor. When the processor executes the computer program, the steps of the traffic path processing method in the above embodiment are implemented, such as: Determine a target container group and a target external service node for which traffic path display is required; Obtain first traffic data of the host node on which the target container group is deployed; Obtain second traffic data of the traffic transmission node corresponding to the node cluster where the host node is located; According to the first traffic data and the second traffic data, determine the traffic path between the target container group and the target external service node, and visually display the traffic path in the form of a graph.

[0077] In one embodiment, a computer-readable storage medium is provided. The computer-readable storage medium stores a computer program. When the computer program is executed by a processor, the steps of the traffic path processing method in the above embodiment are implemented, such as: Determine a target container group and a target external service node for which traffic path display is required; Obtain first traffic data of the host node on which the target container group is deployed; Obtain second traffic data of the traffic transmission node corresponding to the node cluster where the host node is located; According to the first traffic data and the second traffic data, determine the traffic path between the target container group and the target external service node, and visually display the traffic path in the form of a graph.

[0078] It should be noted that for the functions or steps that the above computer-readable storage medium or computer device can implement, reference can be made to the relevant descriptions on the server side and the client side in the foregoing method embodiments. To avoid repetition, they will not be described in detail here.

[0079] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided by the present invention can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in various forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.

[0080] Those skilled in the art can clearly understand that, for the convenience and brevity of description, only the above division of each functional unit and module is used as an example. In actual applications, the above functions can be allocated to different functional units and modules according to needs, that is, the internal structure of the device is divided into different functional units or modules to complete all or part of the functions described above.

[0081] The above embodiments are only used to illustrate the technical solutions of the present invention, not to limit them; although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that they can still modify the technical solutions recorded in the foregoing embodiments, or perform equivalent replacements for some of the technical features; and these modifications or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be included in the protection scope of the present invention.

[0082] It should be noted that the non-company software tools or components appearing in the embodiments of the present invention are only introduced by way of example and do not represent actual use.

Claims

1. A flow path processing method, characterized in that, Including: Determine a target container group and a target external service node for which traffic path display is required; Obtain first traffic data of a host node on which the target container group is deployed; Obtain second traffic data of a traffic transmission node corresponding to a node cluster where the host node is located; Determine a traffic path between the target container group and the target external service node according to the first traffic data and the second traffic data, and visually display the traffic path in a graphical form.

2. The flow path processing method according to claim 2, wherein The first traffic data includes a source network address and a destination network address of the egress traffic of the host node, the second traffic data includes a source network address and a destination network address of the ingress traffic of the traffic transmission node, a source network address, a destination network address and a source network address translation record of the egress traffic of the traffic transmission node, and determining the traffic path between the target container group and the target external service node according to the first traffic data and the second traffic data includes: Obtain the network address of the target container group and the network address of the target external service node; Perform traffic association on the egress traffic of the host node, the ingress traffic and egress traffic of the traffic transmission node according to the source network address and destination network address of the egress traffic of the host node, the source network address and destination network address of the ingress traffic of the traffic transmission node, the source network address, destination network address and source network address translation record of the egress traffic of the traffic transmission node, the network address of the target container group and the network address of the target external service node, to obtain the traffic path between the target container group and the target external service node.

3. The flow path processing method according to claim 1, wherein The visually displaying the traffic path in a graphical form includes: Draw node graphics representing path nodes in the traffic path in the graphical interface, and draw connection lines representing the traffic directions between path nodes between the node graphics, where the path nodes include at least one of the target container group, the traffic transmission node and the target external service node.

4. The flow path processing method according to claim 3, wherein After drawing the node graphics representing path nodes in the traffic path in the graphical interface and drawing the connection lines representing the traffic directions between path nodes between the node graphics, it further includes: Obtain traffic status information of the path nodes, and display the traffic status information in the graphical interface.

5. The flow path processing method according to claim 4, wherein After obtaining the traffic status information of the path nodes, it further includes: Update the drawing style of the connection lines according to the traffic status information of the path nodes.

6. The flow path processing method according to claim 5, characterized in that, After obtaining the traffic status information of the path nodes, it further includes: Determine abnormal path nodes according to the traffic status information of the path nodes, and output abnormal alarm information corresponding to the abnormal path nodes.

7. The flow path processing method according to any one of claims 6, characterized in that After determining the abnormal path nodes according to the traffic status information of the path nodes, it further includes: Highlight the node graphics representing the abnormal path nodes.

8. A flow path processing device, characterized in that, Including: A node determination module, configured to determine a target container group and a target external service node for which traffic path display is required; A data acquisition module, configured to acquire first traffic data of a host node where the target container group is deployed; and acquire second traffic data of a traffic transmission node corresponding to a node cluster where the host node is located; A path display module, configured to determine a traffic path between the target container group and the target external service node according to the first traffic data and the second traffic data, and visually display the traffic path in a graphical form.

9. A computer device, comprising a memory, a processor, and a computer program stored in the memory and executable on the processor, characterized in that, When the processor executes the computer program, it implements the traffic path processing method according to any one of claims 1 to 7.

10. A computer-readable storage medium storing a computer program, characterized in that, When the computer program is executed by a processor, it implements the traffic path processing method according to any one of claims 1 to 7.