Firewall configuration method and device for protecting cloud security, and network flow processing method and device

By configuring network traffic filtering policies in the mangle table of each container group under the computing node, the problem of traditional firewalls identifying and filtering network traffic in the service mesh mode is solved, and network isolation and management of all container groups in the computing cluster is realized, which improves cloud security.

CN120433982APending Publication Date: 2025-08-05BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 0 Cites 2 Cited by

Patent Information

Application Number
CN202510560942.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-04-29
Publication Date
2025-08-05

AI Technical Summary

Technical Problem

Traditional firewall services are difficult to identify and filter network traffic through NAT tables in service mesh mode, resulting in poor network isolation and the inability to effectively manage container groups that do not adopt service mesh mode, affecting cloud security.

Method used

By configuring network traffic filtering policies in the mangle table of each container group under the compute node, filtering and managing network traffic is achieved to ensure that the firewall function operates effectively in each container group, regardless of whether it is a service mesh mode.

Benefits of technology

It realizes network traffic management of all container groups in the computing cluster, ensures cloud security, avoids the failure of traditional firewalls in service mesh mode, and maintains the normal functions of communication agents.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120433982A_ABST
    Figure CN120433982A_ABST
Patent Text Reader

Abstract

The invention provides a firewall configuration method for protecting cloud security. The method comprises the following steps: acquiring a firewall policy related to a target computing node in a target computing cluster; wherein the target computing node runs at least one target container group, and the firewall policy comprises a mapping relationship between a network traffic filtering policy and the container group applying the network traffic filtering policy; determining a network flow filtering strategy corresponding to each target container group according to the firewall strategy; and for each target container group in the target computing node, executing the following steps: configuring a network traffic filtering strategy corresponding to the target container group in a table used for modifying the network traffic content in the target container group. In the method, aiming at each container group, no matter whether the container group is in a service grid mode or not, the firewall function can be realized, the network flow management can be completed, and meanwhile, aiming at the container group in the service grid mode, the subsequent communication agent is not influenced.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to a firewall configuration method for protecting cloud security, a network traffic processing method for protecting cloud security, a firewall configuration device for protecting cloud security, a network traffic processing device for protecting cloud security, an electronic device, a computer-readable storage medium, and a computer program product. Background Art

[0002] With the continuous advancement of computer technology, computing clusters have emerged. Computing clusters typically consist of multiple computing nodes that work together to provide high-performance computing capabilities. Business applications based on a microservices architecture can be deployed in computing clusters. Each business service within an application can be packaged into different containers in the computing cluster, forming a business container within each container group.

[0003] In computing clusters, container network isolation is particularly important for cloud security. In business applications within the aforementioned microservices architecture, the service mesh model can be used to manage communication between business containers. However, in a service mesh model, traditional firewall services struggle to process network traffic. Furthermore, the network traffic processing provided by the service mesh model only controls network access for container groups within the service mesh, making it difficult to manage all container groups within the computing cluster, significantly impacting cloud security. Summary of the Invention

[0004] This application provides a firewall configuration method for cloud security. This method implements firewall functionality and manages network traffic for each container group, regardless of whether it is in service grid mode. This application also provides a network traffic processing method for cloud security, a firewall configuration device for cloud security, a network traffic processing device for cloud security, an electronic device, a computer-readable storage medium, and a computer program product.

[0005] In a first aspect, the present application provides a firewall configuration method for protecting cloud security, the method comprising:

[0006] Obtaining a firewall policy associated with a target computing node in a target computing cluster; wherein the target computing node runs at least one target container group, and the firewall policy includes: a mapping relationship between a network traffic filtering policy and a container group to which the network traffic filtering policy is applied;

[0007] Determine, according to the firewall policy, a network traffic filtering policy corresponding to each target container group;

[0008] For each target container group in the target computing node, the following steps are performed: configuring the network traffic filtering policy corresponding to the target container group in a table in the target container group for modifying network traffic content.

[0009] In a second aspect, the present application provides a network traffic processing method for protecting cloud security, which is applied to a first target container group. A network traffic filtering policy is configured in a table for modifying network traffic content in the first target container group. The network traffic filtering policy is determined based on a firewall policy related to a computing node running the first target container group. The first target container group runs a business container. The method includes:

[0010] receiving first network traffic;

[0011] filtering the first network traffic according to a network traffic filtering policy configured in a table for modifying network traffic content in the first target container group;

[0012] The filtered first network traffic is sent to the service container.

[0013] In a third aspect, the present application provides a firewall configuration device for protecting cloud security, the device comprising:

[0014] An acquisition module is configured to acquire a firewall policy associated with a target computing node in a target computing cluster; wherein the target computing node runs at least one target container group, and the firewall policy includes a mapping relationship between a network traffic filtering policy and a container group to which the network traffic filtering policy is applied;

[0015] a determination module, configured to determine, according to the firewall policy, a network traffic filtering policy corresponding to each target container group;

[0016] The configuration module is configured to perform the following steps for each target container group in the target computing node: configuring the network traffic filtering policy corresponding to the target container group in a table in the target container group for modifying network traffic content.

[0017] In a fourth aspect, the present application provides a network traffic processing device for protecting cloud security, which is deployed in a first target container group. A network traffic filtering policy is configured in a table for modifying network traffic content in the first target container group. The network traffic filtering policy is determined based on a firewall policy related to a computing node running the first target container group. The first target container group runs a business container. The device includes:

[0018] A communication module, configured to receive first network traffic;

[0019] a filtering module, configured to filter the first network traffic according to a network traffic filtering policy configured in a table for modifying network traffic content in the first target container group;

[0020] The communication module is further configured to send the filtered first network traffic to the service container.

[0021] In a fifth aspect, the present application provides an electronic device, comprising a processor and a memory. The processor and the memory communicate with each other. The processor is configured to execute instructions stored in the memory to cause the electronic device to perform the firewall configuration method described in the first aspect or any implementation of the first aspect, or to perform the network traffic processing method described in the second aspect or any implementation of the second aspect.

[0022] In a sixth aspect, the present application provides a computer-readable storage medium, which stores instructions, and the instructions instruct the electronic device to execute the firewall configuration method in the above-mentioned first aspect or any implementation of the first aspect, or to execute the network traffic processing method in the second aspect or any implementation of the second aspect.

[0023] In the seventh aspect, the present application provides a computer program product comprising instructions, which, when run on an electronic device, enables the electronic device to execute the firewall configuration method in the above-mentioned first aspect or any implementation of the first aspect, or to execute the network traffic processing method in the second aspect or any implementation of the second aspect.

[0024] Based on the implementation methods provided in the above aspects, this application can also be further combined to provide more implementation methods.

[0025] It can be seen from the above technical solutions that this application has the following advantages:

[0026] The present application provides a firewall configuration method for protecting cloud security. The method first obtains a firewall policy related to a target computing node in a target computing cluster, wherein the target computing node runs at least one target container group, and the firewall policy includes: a mapping relationship between a network traffic filtering policy and a container group to which the network traffic filtering policy is applied. Then, based on the firewall policy, a network traffic filtering policy corresponding to each target container group is determined. For each target container group in the target computing node, the following steps are performed: the network traffic filtering policy corresponding to the target container group is configured in a table in the target container group for modifying network traffic content.

[0027] In this method, firewall configuration is performed for each container group under a compute node, using the compute node as the dimension. Unlike traditional firewalls, which configure network traffic filtering policies within a filter rule table (i.e., a filter table), this method configures the network traffic filtering policies corresponding to each container group under a compute node within the container group's table (i.e., a mangle table) used to modify network traffic content. This allows network traffic to be filtered first by the network traffic filtering policies in the mangle table. This allows firewall functionality to be implemented for each container group, regardless of whether it is in service grid mode, effectively managing network traffic. Furthermore, for container groups in service grid mode, this does not affect subsequent communication proxies. BRIEF DESCRIPTION OF THE DRAWINGS

[0028] In order to more clearly illustrate the technical methods of the embodiments of the present application, the following briefly introduces the drawings required for use in the embodiments.

[0029] Figure 1 A schematic diagram of communication between business containers in a service grid mode provided in an embodiment of the present application;

[0030] Figure 2 A schematic diagram of the architecture of a network isolation system provided in an embodiment of the present application;

[0031] Figure 3 A flowchart of a firewall configuration method for protecting cloud security provided in an embodiment of the present application;

[0032] Figure 4 A schematic diagram of a process for determining a firewall policy provided in an embodiment of the present application;

[0033] Figure 5 A flowchart of a network traffic processing method for protecting cloud security provided in an embodiment of the present application;

[0034] Figure 6 A schematic diagram of the structure of a firewall configuration device for protecting cloud security provided in an embodiment of the present application;

[0035] Figure 7 A schematic diagram of the structure of a network traffic processing device for protecting cloud security provided in an embodiment of the present application;

[0036] Figure 8 A schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION

[0037] The terms "first" and "second" in the embodiments of this application are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of technical features indicated. Therefore, features specified as "first" or "second" may explicitly or implicitly include one or more of the features.

[0038] First, some technical terms and application scenarios involved in the embodiments of this application are introduced.

[0039] Computing clusters typically consist of multiple compute nodes that work together to provide high-performance computing capabilities. Computing nodes can be either physical or virtual machines. Computing clusters are typically used to perform complex computing tasks that require extensive computing and storage resources, such as data analysis, machine learning, and graphics rendering.

[0040] In a computing cluster, a container group (POD) is the smallest unit that can be created and managed. In other words, a container group can be understood as the basic deployment unit in a computing cluster. A container group typically encapsulates one or more containers. Containers running in the same container group share network and storage resources.

[0041] With the continuous development of cloud computing technology, more and more users (such as organizations and enterprises) are adopting the microservices architecture to deploy business applications. In a microservices architecture, business applications are broken down into multiple small, independent services, each of which implements a specific business function.

[0042] Business applications using a microservices architecture can be deployed in a computing cluster. Specifically, each service within a business application can be packaged into separate containers within the computing cluster, forming a business container within each container group. A container contains the dependencies and configuration required to run the service. Containerization provides isolation, ensuring environmental consistency across services, and ultimately improving the maintainability, scalability, and reliability of business applications.

[0043] The process of deploying microservices-based business applications in a computing cluster can be implemented using a container orchestration system. A container orchestration system, also known as a container orchestration platform or container orchestration engine, is a software system used to automatically deploy, scale, and manage business applications in a computing cluster. For example, the container orchestration system can be a Kubernetes (K8s) system.

[0044] In the business applications of the aforementioned microservices architecture, the service mesh model can be used to manage communication between various business containers. Specifically, the service mesh can be understood as the communication layer in the microservices architecture, which is used to manage network communication, flow control, and security authentication between various business container services. In the service mesh model, a communication proxy container (such as an Envoy proxy) is deployed in the container group where the business container is located through a sidecar proxy. The communication proxy container is used to proxy the communication between the various business containers in the business application without modifying the business code.

[0045] In computing clusters, container network isolation is crucial for ensuring the security and stability of containerized environments (i.e., cloud security). Typically, computing clusters are equipped with firewalls. Related technologies utilize Internet Protocol (IP) packet filtering systems to implement firewall functionality.

[0046] Specifically, the IP packet filtering system consists of the netfilter component and the iptables component, with the netfilter component deployed in kernel space and the iptables component deployed in user space. The IP packet filtering system maintains four tables: the raw table, used for preliminary processing of network traffic (e.g., network packets) based on detection data table rules; the mangle table, used for modifying network traffic content based on data flag bit modification rules; the NAT table, used for converting network addresses based on translation rules; and the filter table, used for managing network traffic based on filtering rules. In traditional firewall services, network traffic filtering policies are configured in the filter table.

[0047] See also Figure 1The diagram shows a communication diagram between business containers in a service grid mode. In the service grid mode, the first container group and the second container group can be container groups running on any computing node in the computing cluster. The first container group runs a business container and an envoy container, and the second container group runs a business container and an envoy container. The communication process between the business container in the first container group and the business container in the second container group is as follows: for the network traffic generated by the business container in the second container group, the network traffic passes through the mangle table in the second container group, specifically the postrouting chain of the mangle table, and is sent to the first container group. After passing through the mangle table in the first container group, specifically the prerouting chain of the mangle table, the network traffic content is modified. Then, after passing through the NAT table, the five-tuple information of the network traffic is modified so that the network traffic is imported into the envoy container in the first container group, so that the envoy container in the first container group acts as the agent for the communication of the business container in the first container group. The network traffic generated by the business container in the first container group also follows a similar process and will not be described in detail here.

[0048] However, in traditional firewalls, network traffic filtering policies are configured in the filter table, and these policies typically filter network traffic based on static information such as IP addresses or ports. In service mesh mode, after network traffic passes through the NAT table, the five-tuple information of the network traffic has been modified. Furthermore, service mesh mode typically performs communication proxying based on dynamic policy configurations (such as the container name and labels of the communication proxy container). Therefore, the network traffic filtering policies configured in the filter table have difficulty identifying and filtering network traffic passing through the NAT table, rendering traditional firewall services ineffective in service mesh mode. In other words, because service mesh mode takes over network traffic through the communication proxy container, changing the original transmission path of network traffic, it is difficult to use traditional firewall services to perform network isolation in container groups in service mesh mode.

[0049] The service mesh model also provides a network traffic management method. However, this method can only be used to isolate the network of container groups that do not use the service mesh model. It cannot be used to isolate the network of container groups in the computing cluster that do not use the service mesh model. Therefore, it is difficult to achieve network isolation of all container groups in the computing cluster, and its applicability is not strong.

[0050] In view of this, the present application provides a firewall configuration method for protecting cloud security. The method first obtains a firewall policy related to a target computing node in a target computing cluster, wherein the target computing node runs at least one target container group, and the firewall policy includes: a mapping relationship between a network traffic filtering policy and a container group to which the network traffic filtering policy is applied. Then, based on the firewall policy, the network traffic filtering policy corresponding to each target container group is determined. For each target container group in the target computing node, the following steps are performed: the network traffic filtering policy corresponding to the target container group is configured in a table in the target container group for modifying network traffic content.

[0051] In this method, firewall configuration is performed for each container group under a compute node, using the compute node as the dimension. Unlike traditional firewalls, which configure network traffic filtering policies within a filter rule table (i.e., a filter table), this method configures the network traffic filtering policies corresponding to each container group under a compute node within the container group's table (i.e., a mangle table) used to modify network traffic content. This allows network traffic to be filtered first by the network traffic filtering policies in the mangle table. This allows firewall functionality to be implemented for each container group, regardless of whether it is in service grid mode, effectively managing network traffic. Furthermore, for container groups in service grid mode, this does not affect subsequent communication proxies.

[0052] To facilitate understanding of the technical solutions provided in the embodiments of the present application, the following description will be made with reference to the accompanying drawings. Figure 2 The diagram shows an architecture diagram of a network isolation system. The network isolation system can be divided into a resource controller and a policy executor, which are described below respectively.

[0053] The resource controller can be used to obtain computing cluster resources and issue firewall policies corresponding to container groups within the computing cluster. Computing cluster resources can include container group information, service information, and security policy information. When a new persistent connection between a policy executor and a computing node is established in the network isolation system, the resource controller can issue the firewall policy associated with that computing node to the policy executor. Furthermore, when computing cluster resources change, the resource controller can also issue incremental firewall policies to the policy executor.

[0054] A policy executor corresponds to a compute node and is used to configure network traffic filtering policies for each container group running on a compute node. After receiving the firewall policy from the resource controller, the policy executor can configure the network traffic filtering policy in the mangle table of the corresponding target container group based on the mapping relationship between the network traffic filtering policy in the firewall policy and the container group to which the network traffic filtering policy is applied. In this way, regardless of whether the target container group runs Envoy containers in addition to business containers, the network traffic filtering policy configured in the mangle table can identify and filter network traffic related to business containers, thus implementing the network isolation function of the cloud firewall service for all container groups in the compute cluster.

[0055] Based on the network isolation system provided above, this application provides a firewall configuration method for protecting cloud security, see Figure 3 The flowchart of a firewall configuration method for protecting cloud security is shown in FIG. , and the method specifically includes the following steps:

[0056] S301: Obtain a firewall policy related to a target computing node in a target computing cluster.

[0057] The target computing cluster can be understood as any computing cluster with network isolation requirements, and the target computing cluster runs at least one target container group. In an embodiment of the present application, the target container group can be a container group that collaboratively provides business functions in a microservice architecture, that is, a business container runs in the target container group.

[0058] The embodiments of the present application do not restrict the communication method of the business containers in the target container group. For example, the target container group can adopt the service grid mode for proxy communication. In this case, the target container group also runs a communication proxy container. For another example, the target container group may not adopt the service grid mode. In this case, the target container group does not run a communication proxy container. In other words, the target computing cluster can include both container groups that adopt the service grid mode and container groups that do not adopt the service grid mode.

[0059] In the embodiment of the present application, firewall configuration is performed based on the compute node dimension. That is, for each compute node in the target compute cluster, the firewall service of the container group running in each compute node is configured. The target compute node can be understood as any compute node in the target compute cluster. The target compute node runs at least one target container group. As mentioned above, the target container group may or may not adopt the service grid mode.

[0060] A firewall policy can be understood as a policy used to provide firewall services. A firewall policy may include: a mapping relationship between a network traffic filtering policy and a container group to which the network traffic filtering policy is applied. In other words, a firewall policy indicates two pieces of information: a specific network isolation rule and the object to which the network isolation rule is applied.

[0061] Therefore, the firewall policy associated with the target computing node can be understood as the firewall policy applied to the target container group running on the target computing node, that is, the firewall policy associated with the target computing node includes the network traffic filtering policy corresponding to each container group.

[0062] S302: Determine a network traffic filtering policy corresponding to each target container group according to the firewall policy.

[0063] Since a firewall policy includes a mapping relationship between a network traffic filtering policy and a container group to which the network traffic filtering policy is applied, by parsing the firewall policy associated with the target computing node, the network traffic filtering policy corresponding to each target container group in the target computing node can be decomposed from the firewall policy associated with the target computing node.

[0064] S303: For each target container group in the target computing node, perform the following steps: configure the network traffic filtering policy corresponding to the target container group in a table in the target container group for modifying network traffic content.

[0065] In an embodiment of the present application, a network traffic filtering policy is configured for each target container group in the target computing node, so that a firewall service is implemented in each target container group in the target computing node.

[0066] Unlike the traditional method of configuring network traffic filtering policies in the filter table, in the embodiment of the present application, the network traffic filtering policies are configured in the mangle table. Since network traffic first passes through the mangle table, then the NAT table, and then the filter table during transmission of the target container group, by configuring the network traffic filtering policies in the mangle table, the network traffic sent to the service container in the target container group is first filtered by the network traffic filtering policies configured in the mangle table, and then subsequent network address translation and other processing are performed, thereby realizing the firewall function without affecting the normal transmission of network traffic.

[0067] In specific implementation, the process identifier (PID) of the main process of each target container group is used to configure the network traffic filtering policy in the mangle table. For example, the PID of the main process can be obtained by running the following command:

[0068] cli,err=client.NewClient("unix: / / / var / run / docker.sock","v1.24",nil,defaultHeaders)

[0069] info,err:=cli.ContainerInspect(context.Background(),containerID)

[0070] In some embodiments, a network traffic filtering policy may include network traffic filtering rules and network traffic objects. Network traffic filtering rules, also known as iptables rules, can be understood as rules for network isolation described using iptables commands. Network traffic objects, also known as ipset information, can be understood as traffic objects that identify, in the form of IP addresses, traffic objects communicating with a target container group. Because there are two types of network traffic objects: traffic objects that send network traffic to a target container group and traffic objects to which a target container group sends network traffic, network traffic objects can include ingress objects and egress objects. Ingress objects send network traffic to a target container group, while a target container group sends network traffic to egress objects.

[0071] When the network traffic object in the network traffic filtering policy corresponding to the target container group is the ingress object of the target container group, the network traffic filtering policy corresponding to the target container group is configured in the forward routing chain of the table for modifying network traffic content in the target container group. When the network traffic object in the network traffic filtering policy corresponding to the target container group is the egress object of the target container group, the network traffic filtering policy corresponding to the target container group is configured in the backward routing chain of the table for modifying network traffic content in the target container group.

[0072] For example, a security policy message is: set in PODA to prohibit external access to IP address B. In this case, the network traffic filtering policy is "Prohibit external access to IP address B", and the container group to which this network traffic filtering policy is applied is PODA. The network traffic filtering policy specifically includes the network traffic filtering rule "Prohibit access" and the network traffic object "IP address B" of the egress object type. This network traffic filtering policy should be configured in the routing post-chain of the target container group.

[0073] That is, the mangle table of the target container group includes a prerouting chain and a postrouting chain. These two chains are used to configure network traffic filtering policies to filter both the network traffic sent to the target container group and the network traffic originating from the target container group. For example, the network traffic sent to the target container group is filtered based on the network traffic filtering policy configured for the prerouting chain in the mangle table. The network traffic originating from the target container group and to be sent to other container groups is filtered based on the network traffic filtering policy configured for the postrouting chain in the mangle table. This implements targeted filtering of network traffic related to the target container group.

[0074] In addition, if the network traffic filtering strategy includes actively monitoring network traffic for alarming, this can be achieved through nflog technology.

[0075] In this method, firewall configuration is performed for each container group under a compute node, using the compute node as the dimension. Unlike traditional firewalls, which configure network traffic filtering policies within a filter rule table (i.e., a filter table), this method configures the network traffic filtering policies corresponding to each container group under a compute node within the container group's table (i.e., a mangle table) used to modify network traffic content. This allows network traffic to be filtered first by the network traffic filtering policies in the mangle table. This allows firewall functionality to be implemented for each container group, regardless of whether it is in service grid mode, effectively managing network traffic. Furthermore, for container groups in service grid mode, this does not affect subsequent communication proxies.

[0076] The previous article describes the firewall configuration process provided in the embodiment of this application. Based on the previous content, it can be seen that in the embodiment of this application, it is necessary to obtain the firewall policy related to the target computing node. The specific generation process of the firewall policy is described below.

[0077] In specific implementation, the firewall policy of each container group in the target computing cluster is obtained, and the firewall policy related to the target computing node is determined based on the computing node where each container group is located.

[0078] That is, in the embodiments of this application, firewall policies are generated based on container groups, and then configured based on compute nodes. This ensures the accuracy of firewall policies by generating separate firewall policies for each container group, as each container group corresponds to a different firewall policy. Furthermore, firewall configuration efficiency is improved by configuring all container groups running on compute nodes together.

[0079] Next, combine Figure 4The flowchart of a process for determining a firewall policy is shown, which illustrates the specific generation process of the firewall policy corresponding to each container group.

[0080] In specific implementation, first, the container group information, service information, and security policy information in the target computing cluster are obtained. The container group information can be understood as the attribute information used to describe each container group in the target computing cluster. For example, the container group information can include the container group name, the container group namespace (namespace), the container group identity (ID), the container group IP address, the container group label (label), and the computing node where the container group is located. The service information can define a logical set of container groups and the policy for accessing the container group. For example, the service information can include the service name, the service namespace, and the service IP address. The security policy information can be understood as the natural language content used to describe the network traffic filtering policy. For example, the "setting in PODA to prohibit external access to IP address B" mentioned above is a security policy information.

[0081] The embodiments of the present application do not limit the method for obtaining container group information, service information, and security policy information in the target computing cluster. For example, when the container orchestration system is a K8s system, the container group information, service information, and security policy information in the target computing cluster are obtained through the ApiServer component provided by the K8s system.

[0082] Next, based on the container group information, service information, and security policy information, a network traffic filtering policy is determined. Furthermore, based on the container group information and security policy information, the container groups to which the network traffic filtering policy applies are determined. A mapping relationship is then established between the network traffic filtering policy and the container groups to which it applies, forming a firewall policy for each container group in the target computing cluster.

[0083] That is to say, if Figure 4 As shown, the container group information, service information, and security policy information are processed and cached. The container group cache may include container group information for each container group and a security policy cache corresponding to each container group. The service cache may include service information for each service. The security policy cache may include a piece of security policy information and a network traffic filtering policy (e.g., including network traffic filtering rules and network traffic objects).

[0084] In this way, by associating the container group information of a container group with the security policy cache corresponding to the container group and storing it in the container group cache, a mapping relationship between the network traffic filtering policy and the container group to which the network traffic filtering policy is applied is established, and a firewall policy corresponding to the container group is formed. Then, each security policy information is processed to form a firewall policy corresponding to each container group in the computing cluster.

[0085] For the container group to which the network traffic filtering policy is applied, the container group information of the container group to which the network traffic filtering policy is applied, such as the container group identifier, is determined by parsing the field representing the application object in the security policy information. Then, the container group to which the network traffic filtering policy is applied is determined by combining the container group identifiers of each container group in the container group information.

[0086] For a network traffic filtering policy including network traffic filtering rules and network traffic objects, security policy information is parsed to determine the network traffic filtering rules and filtering object names, and the filtering object names are matched with container group information and service information to determine the network traffic objects associated with the network traffic filtering rules.

[0087] That is to say, on the one hand, network traffic filtering rules are obtained by parsing the security policy information. On the other hand, considering that the security policy information usually does not directly indicate the network traffic object in the form of an IP address, the filtering object name is first obtained by parsing the security policy information, such as a container group name or a service name, and then the network traffic object in the form of an IP address is determined by combining the container group information and the service information.

[0088] In this way, the full amount of container group information, service information, and security policy information in the target computing cluster are integrated into the firewall policy corresponding to each container group, so that the firewall policy of each container group can be configured later.

[0089] Further, continue as Figure 4 As shown, in response to at least one of the container group information, service information and security policy information in the target computing cluster changing or reaching the set update time, at least one of the network traffic filtering policy and the container group applying the network traffic filtering policy is modified.

[0090] In other words, the present embodiment supports two methods for updating the cache. When computing cluster resources change, the changed computing cluster resources can affect the firewall policy. Therefore, by updating the cache, the corresponding firewall policy is modified. When the set update time arrives, such as the time of a scheduled update task, the cache is actively updated to ensure the real-time performance of the firewall policy and, therefore, the effectiveness of the cloud firewall service.

[0091] For example, when a new container group is added to the target compute cluster, the firewall generates a firewall policy for the newly added container group by traversing the security policy information and parsing the security policy information that matches the newly added container group. When a container group is deleted from the target compute cluster, the information related to the container group in the container group cache is deleted. Furthermore, if the firewall policy corresponding to other container groups is related to the newly added or deleted container group, for example, if the newly added or deleted container group is a network traffic object, the corresponding network traffic filtering policy is modified.

[0092] Similarly, when a service is added or deleted in the target computing cluster, if the firewall policy corresponding to other container groups is related to the added or deleted service, for example, if the added or deleted service is a network traffic object, the corresponding network traffic filtering policy is modified.

[0093] When a new security policy is added to the target computing cluster, the new security policy is parsed to obtain a new network traffic filtering policy and the container group to which it applies. A mapping relationship between the new network traffic filtering policy and the container group to which it applies is established in the container group cache. When a security policy is deleted from the target computing cluster, the corresponding network traffic filtering policy is deleted.

[0094] Furthermore, in response to a change in at least one of the container group information, service information, and security policy information in the target computing cluster or the arrival of a set update time, the content of a table for modifying network traffic content in at least one container group in the target computing cluster can also be updated based on the modified network traffic filtering policy and at least one of the container groups to which the network traffic filtering policy is applied.

[0095] In other words, updating the cache and firewall policy occurs simultaneously. For example, when a new container group is added to the target compute cluster, the firewall policy corresponding to the newly added container group is configured in the mangle table of the newly added container group. When a service is added or deleted from the target compute cluster, the modified network traffic filtering policy is reconfigured in the corresponding container group's mangle table, for example, by modifying the network traffic object in the mangle table. When a new security policy is added to the target compute cluster, the new network traffic filtering policy is configured in the container group to which the newly added security policy applies.

[0096] For example, when adding a new network traffic object (ipset information) to the network traffic filtering policy, execute the following command: "nsenter -t <pid>-n ipset add <ipset-name> <ip>When deleting a network traffic object (ipset information) in a network traffic filtering policy, execute the following command: "nsenter -t <pid>-nipset delete <ipset-name> <ip>When modifying the network traffic filtering rules (iptables rules) in the network traffic filtering policy, execute the following command: "nsenter -t <pid>- iptables - restore - T mabgle - w <iptables rules>

[0097] In this way, the firewall policies corresponding to each container group in the target computing cluster are updated in a timely manner to ensure the effectiveness of the firewall policies corresponding to each container group, and the efficiency and accuracy of network isolation are improved.

[0098] Based on the firewall configuration method provided above, the present application also provides a method for processing network traffic to protect cloud security. This method can be applied to the first target container group. In the table for modifying network traffic content in the first target container group, a network traffic filtering policy is configured. The network traffic filtering policy is determined based on the firewall policy related to the computing node running the first target container group. The first target container group runs business containers. Refer to Figure 5 , and the method specifically includes the following steps:

[0099] S501: Receive the first network traffic.

[0100] S502: Filter the first network traffic according to the network traffic filtering policy configured in the table for modifying network traffic content in the first target container group.

[0101] S503: Send the filtered first network traffic to the business container.

[0102] Among them, the first network traffic can be understood as the network traffic sent to the business container running in the first target container group. Since the network traffic filtering policy is configured in the mangle table of the first target container group, the first network traffic is filtered using the network traffic filtering policy to ensure the security of the first network traffic and implement the network isolation function provided by the firewall service. Furthermore, after the identification and filtering of the first network traffic are completed, the filtered first network traffic is sent to the business container to ensure the security of the containerized environment and the secure communication in the target computing cluster.

[0103] In some embodiments, according to the conversion rule configured in the table for converting network addresses in the first target container group, the destination network address of the filtered first network traffic is modified to the network address of the business container so that the filtered first network traffic is sent to the business container.

[0104] That is to say, the first target container group can be a container group in the conventional network mode. After filtering the first network traffic using the network traffic filtering policy configured in the mangle table, the filtered first network traffic is imported into the business container using the conversion rule configured in the NAT table to complete the transmission of network traffic.

[0105] In other embodiments, according to the conversion rules configured in the table for converting network addresses in the first target container group, the destination network address of the filtered first network traffic is modified to the network address of the communication proxy container, so that the communication proxy container forwards the filtered first network traffic to the business container.

[0106] That is to say, the first target container group can also be a container group in the service grid mode. After filtering the first network traffic using the network traffic filtering policy configured in the mangle table, the filtered first network traffic is imported into the communication proxy container using the conversion rule configured in the NAT table. The communication proxy container sends the filtered first network traffic to the business container to complete the transmission of the network traffic.

[0107] In this way, for the container group in the target computing cluster, regardless of whether the service grid mode is used for network communication, the network isolation function provided by the firewall policy can be realized, which makes up for the limitation that the network traffic management method provided by the service grid mode can only perform network isolation for the container group using the service grid mode, and improves the applicability of the network traffic management method.

[0108] Combined with the above Figures 1 to 5 The firewall configuration method and network traffic processing method provided in the embodiments of the present application are introduced in detail. The devices and equipment provided in the embodiments of the present application will be introduced in conjunction with the accompanying drawings.

[0109] See also Figure 6 The schematic diagram of the structure of the firewall configuration device for protecting cloud security is shown, and the device 60 includes:

[0110] An acquisition module 601 is configured to acquire a firewall policy associated with a target computing node in a target computing cluster; wherein the target computing node runs at least one target container group, and the firewall policy includes a mapping relationship between a network traffic filtering policy and a container group to which the network traffic filtering policy is applied;

[0111] A determination module 602 is configured to determine a network traffic filtering policy corresponding to each target container group according to the firewall policy;

[0112] The configuration module 603 is configured to perform the following steps for each target container group in the target computing node: configuring the network traffic filtering policy corresponding to the target container group in a table in the target container group for modifying network traffic content.

[0113] In some possible implementations, the network traffic filtering policy includes network traffic filtering rules and network traffic objects; and the configuration module 603 is specifically configured to:

[0114] When the network traffic object in the network traffic filtering policy corresponding to the target container group is the ingress object of the target container group, the network traffic filtering policy corresponding to the target container group is configured in the pre-routing chain of the table for modifying network traffic content in the target container group;

[0115] When the network traffic object in the network traffic filtering policy corresponding to the target container group is the egress object of the target container group, the network traffic filtering policy corresponding to the target container group is configured in the post-routing chain of the table for modifying network traffic content in the target container group.

[0116] In some possible implementations, the obtaining module 601 is specifically configured to:

[0117] Obtain the firewall policy for each container group in the target computing cluster;

[0118] According to the computing nodes where the container groups are located, a firewall policy related to the target computing node is determined.

[0119] In some possible implementations, the obtaining module 601 is specifically configured to:

[0120] Obtain container group information, service information, and security policy information in the target computing cluster;

[0121] Determining a network traffic filtering policy based on the container group information, the service information, and the security policy information, and determining a container group to which the network traffic filtering policy is applied based on the container group information and the security policy information;

[0122] A mapping relationship between the network traffic filtering policy and the container group to which the network traffic filtering policy is applied is established to form a firewall policy for each container group in the target computing cluster.

[0123] In some possible implementations, the network traffic filtering policy includes network traffic filtering rules and network traffic objects; and the acquisition module 601 is specifically configured to:

[0124] Parsing the security policy information to determine network traffic filtering rules and filtering object names; and,

[0125] The filtering object name is matched with the container group information and the service information to determine a network traffic object associated with the network traffic filtering rule.

[0126] In some possible implementations, the apparatus 60 further includes an updating module, wherein the updating module is configured to:

[0127] In response to at least one of the container group information, the service information, and the security policy information in the target computing cluster changing or reaching a set update time, modifying at least one of the network traffic filtering policy and the container group to which the network traffic filtering policy is applied.

[0128] In some possible implementations, the update module is further configured to:

[0129] In response to a change in at least one of the container group information, the service information, and the security policy information in the target computing cluster or the arrival of a set update time, content of a table for modifying network traffic content in at least one container group in the target computing cluster is updated according to the modified network traffic filtering policy and at least one of the container groups to which the network traffic filtering policy is applied.

[0130] The configuration device 60 of the firewall service according to the embodiment of the present application may correspond to the method described in the embodiment of the present application, and the above and other operations and / or functions of each module / unit of the configuration device 60 of the firewall service are respectively to realize Figure 3 For the sake of brevity, the corresponding processes of the various methods in the illustrated embodiments are not described again here.

[0131] See also Figure 7 The schematic diagram of the structure of the network traffic processing device for protecting cloud security is shown, which is deployed in a first target container group. A network traffic filtering policy is configured in a table for modifying network traffic content in the first target container group. The network traffic filtering policy is determined based on a firewall policy related to a computing node running the first target container group. The device 70 includes:

[0132] Communication module 701, configured to receive first network traffic;

[0133] A filtering module 702, configured to filter the first network traffic according to a network traffic filtering policy configured in a table for modifying network traffic content in the first target container group;

[0134] The communication module 701 is further configured to send the filtered first network traffic to the service container.

[0135] In some possible implementations, the communication module 701 is specifically configured to:

[0136] According to the conversion rule configured in the table for converting network addresses in the first target container group, the destination network address of the filtered first network traffic is modified to the network address of the business container, so that the filtered first network traffic is sent to the business container.

[0137] In some possible implementations, the communication module 701 is specifically configured to:

[0138] According to the conversion rule configured in the table for converting network addresses in the first target container group, the destination network address of the filtered first network traffic is modified to the network address of the communication proxy container, so that the communication proxy container forwards the filtered first network traffic to the business container.

[0139] The network traffic processing device 70 according to the embodiment of the present application may correspond to executing the method described in the embodiment of the present application, and the above and other operations and / or functions of each module / unit of the network traffic processing device 70 are respectively to achieve Figure 5 For the sake of brevity, the corresponding processes of the various methods in the illustrated embodiments are not described again here.

[0140] The embodiment of the present application also provides an electronic device. The electronic device is specifically used to implement Figure 6 In the embodiment shown, the firewall configuration device 60 or Figure 7 The functions of the network traffic processing device 70 in the illustrated embodiment.

[0141] Figure 8 A schematic diagram of the structure of an electronic device 800 is provided. Figure 8 As shown, electronic device 800 includes bus 801, processor 802, communication interface 803 and memory 804. Processor 802, memory 804 and communication interface 803 communicate with each other via bus 801.

[0142] The bus 801 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 8 Only one thick line is used in the diagram, but this does not mean that there is only one bus or one type of bus.

[0143] The processor 802 may be any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0144] The communication interface 803 is used for external communication. For example, the communication interface 803 can be used for communication with a terminal.

[0145] The memory 804 may include volatile memory, such as random access memory (RAM), or non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0146] The memory 804 stores executable codes, and the processor 802 executes the executable codes to perform the aforementioned firewall configuration method or the aforementioned network traffic processing method.

[0147] Specifically, in the implementation Figure 6 or Figure 7 In the case of the embodiment shown, and Figure 6 Each module or unit of the firewall configuration device 60 described in the embodiment, or, Figure 7 When each module or unit of the network traffic processing device 70 described in the embodiment is implemented by software, Figure 6 or Figure 7 The software or program code required for the functions of each module / unit in the system may be partially or completely stored in the memory 804. The processor 802 executes the program code corresponding to each unit stored in the memory 804 to execute the aforementioned firewall configuration method or the aforementioned network traffic processing method.

[0148] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (such as a floppy disk, a hard disk, a magnetic tape), an optical medium (such as a DVD), or a semiconductor medium (such as a solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute the firewall configuration method applied to the firewall configuration device 60, or to execute the network traffic processing method applied to the network traffic processing device 70.

[0149] The present application also provides a computer program product comprising one or more computer instructions that, when loaded and executed on a computing device, fully or partially generate the process or function described in the present application.

[0150] The computer instructions may be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium. For example, the computer instructions may be transmitted from one website, computer, or data center to another website, computer, or data center via wired (e.g., coaxial cable, optical fiber, digital subscriber line (DSL)) or wireless (e.g., infrared, wireless, microwave, etc.) means.

[0151] When the computer program product is executed by a computer, the computer executes any of the aforementioned methods for configuring a firewall, or any of the aforementioned methods for processing network traffic. The computer program product may be a software installation package, and when any of the aforementioned methods for configuring a cloud firewall service or any of the aforementioned methods for managing network traffic is required, the computer program product may be downloaded and executed on a computer.

[0152] The flow charts and block diagrams in the accompanying drawings illustrate the possible architecture, functions and operations of the systems, methods and computer program products according to the various embodiments of the present application. In this regard, each box in the flow chart or block diagram can represent a module, program segment or a part of code, and the module, program segment or a part of code contains one or more executable instructions for realizing the prescribed logical functions. It should also be noted that in some alternative implementations, the functions marked in the box can also occur in a sequence different from that marked in the accompanying drawings. For example, two boxes represented in succession can actually be executed substantially in parallel, and they can sometimes be executed in the opposite order, depending on the functions involved. It should also be noted that each box in the block diagram and / or flow chart, and the combination of the boxes in the block diagram and / or flow chart can be implemented by a dedicated hardware-based system that performs the prescribed function or operation, or can be implemented by a combination of dedicated hardware and computer instructions.

[0153] The units involved in the embodiments described in this application may be implemented in software or hardware, wherein the name of a unit / module does not, in some cases, constitute a limitation on the unit itself.

[0154] The functions described above herein may be performed, at least in part, by one or more hardware logic components. For example, and without limitation, exemplary types of hardware logic components that may be used include: field programmable gate arrays (FPGAs), application specific integrated circuits (ASICs), application specific standard products (ASSPs), systems on chip (SOCs), complex programmable logic devices (CPLDs), and the like.

[0155] In the context of the present application embodiment, machine-readable medium can be a tangible medium that can contain or store a program for use by an instruction execution system, device or equipment or used in combination with an instruction execution system, device or equipment. Machine-readable medium can be a machine-readable signal medium or a machine-readable storage medium. Machine-readable medium can include but is not limited to electronic, magnetic, optical, electromagnetic, infrared or semiconductor systems, devices or equipment, or any suitable combination of the foregoing. A more specific example of a machine-readable storage medium can include an electrical connection based on one or more lines, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination of the foregoing.

[0156] It should be noted that the various embodiments in this specification are described in a progressive manner, with each embodiment focusing on the differences from other embodiments. Reference can be made to the common and similar parts between the various embodiments. For the systems or devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and the relevant parts can be referred to the description of the methods.

[0157] It should be understood that in this application, "at least one (item)" means one or more, and "more" means two or more. "And / or" is used to describe the association relationship of associated objects, indicating that three relationships may exist. For example, "A and / or B" can mean: only A exists, only B exists, and A and B exist at the same time, where A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following items" or similar expressions refers to any combination of these items, including any combination of single or plural items. For example, at least one of a, b or c can mean: a, b, c, "a and b", "a and c", "b and c", or "a and b and c", where a, b, c can be single or plural.

[0158] It should also be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprise," "include," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or apparatus comprising a set of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus comprising the element.

[0159] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.

[0160] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present application. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present application. Therefore, the present application is not limited to the embodiments shown herein, but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.< / pid> < / ip> < / ipset-name> < / pid> < / ip> < / ipset-name> < / pid>

Claims

1. A firewall configuration method for protecting cloud security, characterized in that: The method comprises: Obtaining a firewall policy associated with a target computing node in a target computing cluster; wherein the target computing node runs at least one target container group, and the firewall policy includes: a mapping relationship between a network traffic filtering policy and a container group to which the network traffic filtering policy is applied; Determine, according to the firewall policy, a network traffic filtering policy corresponding to each target container group; For each target container group in the target computing node, the following steps are performed: configuring the network traffic filtering policy corresponding to the target container group in a table in the target container group for modifying network traffic content.

2. The method according to claim 1, characterized in that The network traffic filtering policy includes network traffic filtering rules and network traffic objects; configuring the network traffic filtering policy corresponding to the target container group in a table in the target container group for modifying network traffic content includes: When the network traffic object in the network traffic filtering policy corresponding to the target container group is the ingress object of the target container group, the network traffic filtering policy corresponding to the target container group is configured in the pre-routing chain of the table for modifying network traffic content in the target container group; When the network traffic object in the network traffic filtering policy corresponding to the target container group is the egress object of the target container group, the network traffic filtering policy corresponding to the target container group is configured in the post-routing chain of the table for modifying network traffic content in the target container group.

3. The method according to claim 1, characterized in that The obtaining of the firewall policy related to the target computing node in the target computing cluster includes: Obtain the firewall policy for each container group in the target computing cluster; According to the computing nodes where the container groups are located, a firewall policy related to the target computing node is determined.

4. The method according to claim 3, characterized in that Obtaining the firewall policy for each container group in the target computing cluster includes: Obtain container group information, service information, and security policy information in the target computing cluster; Determining a network traffic filtering policy based on the container group information, the service information, and the security policy information, and determining a container group to which the network traffic filtering policy is applied based on the container group information and the security policy information; A mapping relationship between the network traffic filtering policy and the container group to which the network traffic filtering policy is applied is established to form a firewall policy for each container group in the target computing cluster.

5. The method according to claim 4, characterized in that The network traffic filtering policy includes network traffic filtering rules and network traffic objects; and determining the network traffic filtering policy based on the container group information, the service information, and the security policy information includes: Parsing the security policy information to determine network traffic filtering rules and filtering object names; and, The filtering object name is matched with the container group information and the service information to determine a network traffic object associated with the network traffic filtering rule.

6. The method according to claim 4, characterized in that The method further comprises: In response to at least one of the container group information, the service information, and the security policy information in the target computing cluster changing or reaching a set update time, modifying at least one of the network traffic filtering policy and the container group to which the network traffic filtering policy is applied.

7. The method according to claim 6, characterized in that In response to at least one of the container group information, the service information, and the security policy information in the target computing cluster changing or reaching a set update time, the method further includes: According to at least one of the modified network traffic filtering policy and the container group to which the network traffic filtering policy is applied, content of a table for modifying network traffic content in at least one container group in the target computing cluster is updated.

8. A network traffic processing method for protecting cloud security, characterized in that: Applied to a first target container group, a table for modifying network traffic content in the first target container group is configured with a network traffic filtering policy, the network traffic filtering policy is determined based on a firewall policy related to a computing node running the first target container group, and the first target container group runs a business container, the method comprising: receiving first network traffic; filtering the first network traffic according to a network traffic filtering policy configured in a table for modifying network traffic content in the first target container group; The filtered first network traffic is sent to the service container.

9. The method according to claim 8, characterized in that The sending the filtered first network traffic to the business container includes: According to the conversion rule configured in the table for converting network addresses in the first target container group, the destination network address of the filtered first network traffic is modified to the network address of the business container, so that the filtered first network traffic is sent to the business container.

10. The method according to claim 8, characterized in that The first target container group further runs a communication proxy container, and sending the filtered first network traffic to the business container includes: According to the conversion rule configured in the table for converting network addresses in the first target container group, the destination network address of the filtered first network traffic is modified to the network address of the communication proxy container, so that the communication proxy container forwards the filtered first network traffic to the business container.

11. A firewall configuration device for protecting cloud security, characterized in that: The device comprises: An acquisition module is configured to acquire a firewall policy associated with a target computing node in a target computing cluster; wherein the target computing node runs at least one target container group, and the firewall policy includes a mapping relationship between a network traffic filtering policy and a container group to which the network traffic filtering policy is applied; a determination module, configured to determine, based on the firewall policy, a network traffic filtering policy corresponding to each target container group; The configuration module is configured to perform the following steps for each target container group in the target computing node: configuring the network traffic filtering policy corresponding to the target container group in a table in the target container group for modifying network traffic content.

12. A network traffic processing device for protecting cloud security, characterized in that: Deployed in a first target container group, a table in the first target container group for modifying network traffic content is configured with a network traffic filtering policy, the network traffic filtering policy is determined based on a firewall policy related to a computing node running the first target container group, the first target container group runs a business container, and the device includes: A communication module, configured to receive first network traffic; a filtering module, configured to filter the first network traffic according to a network traffic filtering policy configured in a table for modifying network traffic content in the first target container group; The communication module is further configured to send the filtered first network traffic to the service container.

13. An electronic device, characterized in that: The electronic device includes a processor and a memory; The processor is configured to execute instructions stored in the memory, so that the electronic device performs the method according to any one of claims 1 to 7 or any one of claims 8 to 10.

14. A computer-readable storage medium, characterized in that The method comprises instructions for instructing an electronic device to execute the method according to any one of claims 1 to 7 or any one of claims 8 to 10.

15. A computer program product, characterized in that The computer program product comprises computer-readable instructions for implementing the method of any one of claims 1 to 7 or any one of claims 8 to 10.

Citation Information

Cited By

  • Container network access control method and device, equipment and medium

    CN121333664A

  • Access control method and device for container network, equipment and medium

    CN121333664B