Data processing method, apparatus and system, and storage medium

By applying encapsulation rules on the computing node, the packets of the target traffic are directly sent to the target server, which solves the problem of excessive load of the load balancer and improves system performance.

WO2025118809A1PCT designated stage expired Publication Date: 2025-06-12HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
View PDF 5 Cites 0 Cited by

Patent Information

Application Number
PCT/CN2024/123482
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2024-03-27
Filing Date
2024-10-08
Publication Date
2025-06-12

AI Technical Summary

Technical Problem

In the network architecture of cloud computing services, the load balancer is too high, resulting in system performance degradation.

Method used

By applying encapsulation rules on the compute node, obtaining packets of the target traffic and sending them directly to the target server, avoiding forwarding through the load balancer, thereby reducing the load balancer load.

Benefits of technology

It effectively reduces the load of the load balancer and improves the processing capacity and performance of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN2024123482_12062025_PF_FP_ABST
    Figure CN2024123482_12062025_PF_FP_ABST
Patent Text Reader

Abstract

The present application belongs to the field of cloud computing. Disclosed are a data processing method, apparatus and system, and a storage medium. The method comprises: on the basis of an encapsulation rule, acquiring a first message to be sent of target traffic, wherein an outer destination address included in the first message is a tunnel endpoint address of a target server, the encapsulation rule is used for indicating that an outer destination address included in a message which belongs to the target traffic and is acquired by a computing node is a tunnel endpoint address of the target server, and the target server is a server which is selected by a load balancer from among a plurality of servers and is configured to process the target traffic; and sending the first message to the target server. The present application can reduce the load of a load balancer.
Need to check novelty before this filing date? Find Prior Art

Description

Data processing method, device, system and storage medium

[0001] This application claims priority to Chinese patent application No. 202311678267.1, filed on December 6, 2023, entitled “A method, device, and other apparatus for data processing,” the entire contents of which are incorporated herein by reference. This application claims priority to Chinese patent application No. 202410361764.7, filed on March 27, 2024, entitled “Data processing method, device, system, and storage medium,” the entire contents of which are incorporated herein by reference. Technical Field

[0002] The present application relates to the field of cloud computing, and in particular to a data processing method, device, system, and storage medium. Background Art

[0003] In the network architecture of cloud computing services, load balancing technology is crucial for improving network service capabilities. This network architecture typically includes compute nodes, a load balancer, and multiple servers, which provide traffic processing services. Compute nodes can send upstream traffic to the load balancer. The load balancer selects a server from among these servers based on a load balancing policy and then sends the upstream traffic to that server, which then processes the traffic.

[0004] The upstream traffic sent by the computing nodes must pass through the load balancer and then be sent to the server, which puts a heavy load on the load balancer.

[0005] Summary of the Invention

[0006] This application provides a data processing method, device, system, and storage medium to reduce the load on a load balancer. The technical solution is as follows:

[0007] In a first aspect, the present application provides a data processing method, applied to a computing node. In the method, based on an encapsulation rule, a first message of target traffic to be sent is obtained, wherein the outer destination address included in the first message is the tunnel endpoint address of a target server. The encapsulation rule instructs the computing node to include an outer destination address in messages belonging to the target traffic as the tunnel endpoint address of a target server, which is a server selected by a load balancer from multiple servers to process the target traffic. The first message is sent to the target server.

[0008] Because the encapsulation rule instructs the computing node to obtain a message belonging to the target traffic, including an outer destination address that is the tunnel endpoint address of the target server, the computing node, based on the encapsulation rule, obtains a first message including an outer destination address that is the tunnel endpoint address of the target server. Because the outer destination address included in the first message is the tunnel endpoint address of the target server, the computing node can send the first message to the target server, thereby offloading the first message from the load balancer and reducing the load on the load balancer.

[0009] In one possible implementation, a second message of target traffic is obtained, wherein the outer destination address included in the second message is the tunnel endpoint address of the load balancer. The second message is sent to the load balancer, which is configured to select a target server from a plurality of servers and send a third message to the target server, wherein the third message is obtained based on the second message. A fourth message is received from the target server based on the third message, wherein the outer source address included in the fourth message is the tunnel endpoint address of the target server. The encapsulation rule is generated based on the tunnel endpoint address of the target server. In this way, the computing node is connected to the target server through the load balancer, and an encapsulation rule is generated based on the fourth message returned by the target server. Based on the encapsulation rule, the first message can be unloaded from the load balancer.

[0010] In another possible implementation, the third message also includes a first tag, which is used to indicate that the target traffic should be offloaded from the load balancer. The fourth message is sent by the target server based on the first tag, and the fourth message also includes a second tag, which is used to indicate that the target server supports offloading the target traffic from the load balancer. An encapsulation rule is generated based on the second tag and the tunnel endpoint address of the target server. This allows the compute node to offload the first message from the load balancer only if both the compute node and the target server support offloading the target traffic from the load balancer. This avoids communication errors.

[0011] In another possible implementation, the encapsulation rule includes first identification information and the tunnel endpoint address of the target server. The first identification information is identification information of the target traffic to be sent by the computing node. The first identification information of the target traffic is obtained; and the encapsulation rule including the first identification information is obtained. This ensures that the encapsulation rule is accurately obtained when the first message is sent, and based on the encapsulation rule, the first message can be successfully offloaded from the load balancer.

[0012] In another possible implementation, the target server includes a target service for processing target traffic, the target traffic is the traffic to be sent by the target virtual instance included in the computing node, and the first identification information includes one or more of the following information: the virtual extended local area network identifier VNI of the target virtual instance, the address of the target virtual instance, the address of the target service, the source port number of the first message, the destination port number of the first message, or the communication protocol used by the first message.

[0013] In another possible implementation, the address of the target service is a virtual private cloud (VPC) address of the target service, or the address of the target service is a virtual address bound to the target server.

[0014] In another possible implementation, the first message includes a virtual extended local area network VxLAN message header, the VxLAN message header includes an outer destination address, and the outer destination address is a tunnel endpoint address of a target server.

[0015] In a second aspect, the present application provides a data processing method, the method being applied to a target server, the target server being a server selected by a load balancer from multiple servers to process target traffic to be sent by a computing node. In the method, a first message of target traffic sent by a computing node is received, the first message including first identification information, which is identification information of the target traffic. Based on the first message, a fifth message is generated, the fifth message including second identification information and a payload portion of the first message, the second identification information being used to identify the target traffic on the target server, and being identification information assigned by the load balancer when requesting the target server to process the target traffic. The fifth message is processed.

[0016] After receiving the first message including the first identification information, the target server generates a fifth message including the second identification information. The second identification information is used to identify the target traffic on the target server, thereby enabling the target server to identify the fifth message based on the second identification information and process the fifth message. In this way, the first message does not need to include the second identification information assigned by the load balancer, but instead includes the first identification information. Therefore, the computing node can directly send the first message to the target server, thereby offloading the first message from the load balancer and reducing the load on the load balancer.

[0017] In one possible implementation, the target server includes a conversion rule indicating a conversion relationship between the first identification information and the second identification information, and generates a fifth message based on the conversion rule and the first message. Thus, the conversion rule can be used to successfully obtain a fifth message that can be processed by the target server.

[0018] In another possible implementation, the first identification information includes the first content and the second content, the second identification information includes the third content and the second content, and the conversion rule includes the first content, the second content, and the third content, thereby reducing the data volume of the conversion rule.

[0019] In another possible implementation, the target traffic is traffic to be sent by a target virtual instance included in the computing node, and the target server further includes a processing module, the processing module being configured to provide a target service for processing the target traffic;

[0020] The first content includes one or more of the following: a virtual extended local area network identifier VNI of a target virtual instance, an address of a target virtual instance, or a virtual private cloud VPC address of a target service;

[0021] The second content includes one or more of the following: a source port number of the first message, a destination port number of the first message, or a communication protocol used by the first message;

[0022] The third content includes one or more of the following: the address of the dedicated network segment of the load balancer or the virtual address bound to the target server.

[0023] In another possible implementation, a conversion rule is obtained based on the first identification information included in the first message. The first content in the first identification information is replaced with the third content included in the conversion rule to obtain second identification information. A fifth message is generated that includes the second identification information and the payload portion of the first message. In this way, the conversion rule can be accurately obtained based on the first identification information, and the conversion rule can be used to successfully obtain a fifth message that can be processed by the target server.

[0024] In another possible implementation, a third message sent by the load balancer is received, the third message including the second identification information and the first content. The third message is obtained by the load balancer based on the second message after receiving the second message of the target traffic, the second message including the first identification information. A conversion rule is generated based on the third message. In this way, the computing node and the target server are connected via the load balancer, and a conversion rule is generated based on the third message sent by the load balancer. Based on the conversion rule, the first message can be offloaded from the load balancer.

[0025] In another possible implementation, the third message also includes a first flag, which indicates that the target traffic should be offloaded from the load balancer. Based on the first flag, a fourth message is sent to the compute node, where the fourth message includes a second flag, which indicates that the target server supports offloading the target traffic from the load balancer. This allows the first message to be offloaded from the load balancer if both the compute node and the target server support offloading the target traffic from the load balancer, thus avoiding communication errors.

[0026] In another possible implementation, the first message includes a virtual extended local area network VxLAN message header, the VxLAN message header includes an outer destination address, and the outer destination address is a tunnel endpoint address of a target server.

[0027] In a third aspect, the present application provides a device for storing data, the device comprising: a processing unit and a sending unit. The processing unit is configured to obtain, based on an encapsulation rule, a first message of target traffic to be sent, wherein the outer destination address included in the first message is the tunnel endpoint address of the target server; wherein the encapsulation rule is configured to indicate that the outer destination address included in the message belonging to the target traffic obtained by the device is the tunnel endpoint address of the target server, and the target server is a server selected by a load balancer from multiple servers to process the target traffic. The sending unit is configured to send the first message to the target server.

[0028] Because the encapsulation rule instructs the device to obtain a message belonging to the target traffic, including an outer destination address that is the tunnel endpoint address of the target server, the processing unit obtains, based on the encapsulation rule, a first message including an outer destination address that is the tunnel endpoint address of the target server. Because the outer destination address included in the first message is the tunnel endpoint address of the target server, the sending unit can send the first message to the target server, thereby offloading the first message from the load balancer and reducing the load on the load balancer.

[0029] In one possible implementation, the device further includes a receiving unit; a processing unit for obtaining a second message of target traffic, wherein the outer destination address included in the second message is the tunnel endpoint address of the load balancer. The sending unit is further used to send a second message to the load balancer, and the load balancer is used to select a target server from a plurality of servers and send a third message to the target server, wherein the third message is obtained based on the second message. The receiving unit is used to receive a fourth message sent by the target server based on the third message, wherein the outer source address included in the fourth message is the tunnel endpoint address of the target server. The processing unit is further used to generate an encapsulation rule based on the tunnel endpoint address of the target server. In this way, the device connects to the target server through the load balancer, and generates an encapsulation rule based on the fourth message returned by the target server. Based on the encapsulation rule, the first message can be unloaded from the load balancer.

[0030] In another possible implementation, the third message also includes a first tag, which is used to indicate that the target traffic should be offloaded from the load balancer. The fourth message is sent by the target server based on the first tag, and the fourth message also includes a second tag, which is used to indicate that the target server supports offloading the target traffic from the load balancer. The processing unit is configured to generate an encapsulation rule based on the second tag and the tunnel endpoint address of the target server. This allows the encapsulation rule to be generated only when both the device and the target server support offloading the target traffic from the load balancer. Only then can the processing unit offload the first message from the load balancer based on the encapsulation rule, thus avoiding communication errors.

[0031] In another possible implementation, the encapsulation rule includes first identification information and a tunnel endpoint address of a target server. The first identification information is identification information of the target traffic to be sent by the device. The processing unit is further configured to obtain the first identification information of the target traffic and obtain the encapsulation rule including the first identification information. This ensures that the encapsulation rule is accurately obtained when the first message is sent, and based on the encapsulation rule, the first message can be successfully offloaded from the load balancer.

[0032] In another possible implementation, the target server includes a target service for processing target traffic, the target traffic is the traffic to be sent by the target virtual instance included in the device, and the first identification information includes one or more of the following information: the virtual extended local area network identifier VNI of the target virtual instance, the address of the target virtual instance, the address of the target service, the source port number of the first message, the destination port number of the first message, or the communication protocol used by the first message.

[0033] In another possible implementation, the address of the target service is a virtual private cloud (VPC) address of the target service, or the address of the target service is a virtual address bound to the target server.

[0034] In another possible implementation, the first message includes a virtual extended local area network VxLAN message header, the VxLAN message header includes an outer destination address, and the outer destination address is a tunnel endpoint address of a target server.

[0035] In a fourth aspect, the present application provides a data processing device, which is a server selected by a load balancer from a plurality of servers for processing target traffic to be sent by a computing node, and the device includes: a receiving unit and a message processing unit. The receiving unit is used to receive a first message of target traffic sent by the computing node, the first message including first identification information, and the first identification information is identification information of the target traffic. The message processing unit is used to generate a fifth message based on the first message, the fifth message including second identification information and the payload part of the first message, the second identification information is used to identify the target traffic on the device, and the second identification information is identification information assigned when the load balancer requests the device to process the target traffic. The message processing unit is also used to process the fifth message.

[0036] After the receiving unit receives the first message including the first identification information, the message processing unit generates a fifth message including the second identification information. The second identification information is used to identify the target traffic on the target server, thereby enabling the message processing unit to identify the fifth message based on the second identification information and process the fifth message. In this way, the first message does not need to include the second identification information assigned by the load balancer, but instead includes the first identification information. Therefore, the computing node can directly send the first message to the device, thereby offloading the first message from the load balancer and reducing the load on the load balancer.

[0037] In one possible implementation, the device includes a conversion rule indicating a conversion relationship between first identification information and second identification information, where the second identification information is identification information assigned when a load balancer requests the device to process target traffic. A message processing unit is configured to generate a fifth message based on the conversion rule and the first message. The conversion rule can thus successfully generate a fifth message that can be processed by the message processing unit.

[0038] In another possible implementation, the first identification information includes the first content and the second content, the second identification information includes the third content and the second content, and the conversion rule includes the first content, the second content, and the third content.

[0039] In another possible implementation, the target traffic is the traffic to be sent by the target virtual instance included in the computing node, and the device also includes a processing module, which is used to provide a target service for processing the target traffic. The first content includes one or more of the following: the virtual extended local area network identifier VNI of the target virtual instance, the address of the target virtual instance, or the virtual private cloud VPC address of the target service. The second content includes one or more of the following: the source port number of the first message, the destination port number of the first message, or the communication protocol used by the first message. The third content includes one or more of the following: the address of the dedicated network segment of the load balancer or the virtual address bound to the device.

[0040] In another possible implementation, the message processing unit is configured to obtain a conversion rule based on first identification information included in the first message; replace the first content in the first identification information with the third content included in the conversion rule to obtain second identification information; and generate a fifth message including the second identification information and the payload portion of the first message. In this manner, the conversion rule can be accurately obtained based on the first identification information, and a fifth message that can be processed by the message processing unit can be successfully obtained based on the conversion rule.

[0041] In another possible implementation, the receiving unit is further configured to receive a third message sent by the load balancer, the third message including the second identification information and the first content. The third message is obtained by the load balancer based on the second message after receiving the second message of the target traffic, the second message including the first identification information. The message processing unit is further configured to generate a conversion rule based on the third message. In this way, the computing node and the device are connected via the load balancer, and a conversion rule is generated based on the third message sent by the load balancer. Based on the conversion rule, the first message can be offloaded from the load balancer.

[0042] In another possible implementation, the third message further includes a first tag, the first tag being used to indicate that the target traffic should be offloaded from the load balancer. The message processing unit is further configured to send a fourth message to the computing node based on the first tag, the fourth message including a second tag being used to indicate that the device supports offloading the target traffic from the load balancer. In this way, if both the computing node and the device support offloading the target traffic from the load balancer, the first message can be offloaded from the load balancer, thereby avoiding communication errors.

[0043] In another possible implementation, the first message includes a virtual extended local area network VxLAN message header, the VxLAN message header includes an outer destination address, and the outer destination address is the tunnel endpoint address of the device.

[0044] In a fifth aspect, the present application provides a computing device cluster, wherein the computing device cluster includes at least one computing device, each computing device including a processor and a memory;

[0045] The processor of the at least one computing device is used to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method in the first aspect, the second aspect, any possible implementation of the first aspect, or any possible implementation of the second aspect.

[0046] In a sixth aspect, the present application provides a computer program product comprising instructions, which, when executed by a computing device cluster, causes the computing device cluster to execute the method in the first aspect, the second aspect, any possible implementation of the first aspect, or any possible implementation of the second aspect.

[0047] In the seventh aspect, the present application provides a computer-readable storage medium comprising computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method in the first aspect, the second aspect, any possible implementation of the first aspect, or any possible implementation of the second aspect.

[0048] In an eighth aspect, the present application provides a chip comprising a memory and a processor, the memory being used to store computer instructions, and the processor being used to call and run the computer instructions from the memory to execute the method in the first aspect, the second aspect, any possible implementation of the first aspect, or any possible implementation of the second aspect.

[0049] In a ninth aspect, the present application provides a data processing system, which includes the apparatus described in the third aspect and the apparatus described in the fourth aspect. BRIEF DESCRIPTION OF THE DRAWINGS

[0050] FIG1 is a schematic diagram of a virtual server cluster provided in an embodiment of the present application;

[0051] FIG2 is a schematic diagram of another virtual server cluster provided in an embodiment of the present application;

[0052] FIG3 is a flow chart of a data processing method provided in an embodiment of the present application;

[0053] FIG4 is a flow chart of a method for sending a message provided in an embodiment of the present application;

[0054] FIG5 is a flow chart of another method for sending a message provided in an embodiment of the present application;

[0055] FIG6 is a flow chart of another method for sending a message provided in an embodiment of the present application;

[0056] FIG7 is a flow chart of another data processing method provided in an embodiment of the present application;

[0057] FIG8 is a flow chart of a method for sending a message provided in an embodiment of the present application;

[0058] FIG9 is a flow chart of another method for sending a message provided in an embodiment of the present application;

[0059] FIG10 is a flow chart of another method for sending a message provided in an embodiment of the present application;

[0060] FIG11 is a schematic structural diagram of a data processing device provided in an embodiment of the present application;

[0061] FIG12 is a schematic structural diagram of another data processing device provided in an embodiment of the present application;

[0062] FIG13 is a schematic diagram of the structure of a computing device provided in an embodiment of the present application;

[0063] FIG14 is a schematic diagram of a data processing cluster structure provided in an embodiment of the present application;

[0064] FIG15 is a schematic diagram of another data processing cluster structure provided in an embodiment of the present application;

[0065] FIG16 is a schematic diagram of the structure of another computing device provided in an embodiment of the present application;

[0066] FIG17 is a schematic diagram of another data processing cluster structure provided in an embodiment of the present application;

[0067] FIG18 is a schematic diagram of another data processing cluster structure provided in an embodiment of the present application. DETAILED DESCRIPTION

[0068] The following is an introduction to the relevant concepts of this application:

[0069] The first packet, the second packet, the third packet, the fourth packet, the fifth packet, the sixth packet, the seventh packet, the eighth packet, the ninth packet, and the tenth packet are all packets of target traffic.

[0070] The first identification information and the second identification information are both identification information of the target traffic. The first identification information is used to identify the target traffic in the computing node, and the second identification information is used to identify the target traffic in the processing module of the target server.

[0071] The encapsulation rule is used to instruct the computing node that the outer destination address included in the message belonging to the target traffic obtained is the tunnel endpoint address of the target server.

[0072] The first conversion rule is used to indicate a conversion relationship between the first identification information and the second identification information.

[0073] The second conversion rule is used to indicate a conversion relationship between the first identification information and the second identification information.

[0074] The third conversion rule is used to indicate a conversion relationship from the second identification information to the first identification information.

[0075] Referring to Figure 1, an embodiment of the present application provides a virtual server cluster 100, which includes a computing node 101, a load balancer 102 and multiple servers 103. The computing node 101 can communicate with the load balancer 102, and the load balancer 102 can also communicate with each server 103.

[0076] The multiple servers 103 all include a target service, where the target service is a service for processing target traffic, and the target traffic is traffic to be sent by the computing node 101 or traffic to be read by the computing node 101 .

[0077] In some embodiments, the multiple servers 103 may be bound to the same virtual address, and the virtual private cloud (VPC) address of the target service corresponds to the virtual address.

[0078] In some embodiments, the virtual addresses bound to the multiple servers 103 are virtual internet protocol (VIP), etc., the VPC address of the target service is the VPC IP of the target service, etc., the load balancer is a VPC endpoint, etc., and the virtual server cluster 100 may be a Linux virtual server (LVS), etc.

[0079] In some embodiments, when computing node 101 needs to send target traffic, computing node 101 sends a second message belonging to the target traffic to load balancer 102, where the second message includes the address of the target service that computing node 101 requests to process the target traffic.

[0080] The load balancer 102 receives the second message, obtains a virtual address corresponding to the address of the target service, determines multiple servers 103 bound to the virtual address, selects a server from the multiple servers 103 as the target server, and sends a third message to the target server. The third message is obtained based on the second message, and the target server processes the third message.

[0081] Afterwards, for each other message belonging to the target traffic, for the sake of convenience, the other message is called the first message, the computing node 101 sends the first message to the load balancer 102, the load balancer 102 sends the first message to the target server, and the target server processes the first message.

[0082] Therefore, when the computing node 101 sends the target traffic, it needs to send each packet of the target traffic to the load balancer 102, and the load balancer 102 then sends each packet of the target traffic to the target server. In other words, the target traffic is not unloaded from the load balancer 102.

[0083] In some embodiments, the target traffic is the traffic in the multiple servers 103. When the computing node 101 needs to read the target traffic, the computing node 101 sends a second message to the load balancer 102. The second message includes the address of the target service requested by the computing node 101 and the tunnel endpoint address of the computing node 101. The load balancer 102 receives the second message, obtains the virtual address corresponding to the address of the target service, determines the multiple servers 103 bound to the virtual address, selects a server from the multiple servers 103 as the target server, and sends a third message to the target server. The third message includes the virtual address of the target server (which is the virtual address bound to the target server) and the tunnel endpoint address of the computing node 101. The target server receives the third message and, based on the fact that the third message includes the tunnel endpoint address of the computing node 101, sends each message included in the target traffic to the computing node 101. The computing node 101 receives each message included in the target traffic.

[0084] Therefore, when computing node 101 reads the target traffic, the target server sends each message included in the target traffic to computing node 101 based on the tunnel endpoint address of computing node 101 included in the third message, so that the target traffic can be unloaded from load balancer 102.

[0085] In some embodiments, the target service address may be a VPC address of the target service, or a virtual address bound to multiple servers 103 for providing the target service. Server 103 may provide an object storage service (OBS), etc.

[0086] In some embodiments, referring to FIG2 , the computing node 101 includes at least one virtual instance, the target traffic is the traffic that the target virtual instance in the computing node 101 needs to send, or the target traffic is the traffic that the target virtual instance in the computing node 101 needs to read, and the at least one virtual instance includes the target virtual instance.

[0087] In some embodiments, the at least one virtual instance includes one or more of the following: a container or a virtual machine, etc.

[0088] In some embodiments, referring to FIG2 , for each server 103, the server 103 includes an elastic virtual switch (EVS) 1031 and a processing module 1032. For example, assuming that the server 103 is the target server described above, when the target traffic is the traffic to be sent by the computing node 101, for the second message described above, the target server can receive each message of the target traffic through the EVS 1031 in the target server, and process each message of the target traffic through the processing module 1032. When the target traffic is the traffic to be read by the computing node 101, the processing module 1032 includes the target traffic, and the target server sends the message included in the target traffic in the processing module 1032 to the computing node 101 through the EVS 1031 of the target server.

[0089] When the target traffic is traffic to be sent by computing node 101, if the first packet of the target traffic is offloaded from load balancer 102, computing node 101 can directly send the first packet to the target server. This can reduce the load on load balancer 102. To this end, the first packet of the target traffic can be offloaded from load balancer 102 using any of the following embodiments.

[0090] Referring to FIG3 , an embodiment of the present application provides a data processing method 300, which is applied to the virtual server cluster 100 shown in FIG1 or FIG2 . The method 300 operates in the full network address translation (Full NAT) mode of the virtual server cluster 100 and includes the following process.

[0091] Step 301: The computing node obtains a second message and sends the second message to the load balancer. The second message belongs to the target traffic. The second message includes the first identification information of the target traffic. The outer destination address included in the second message is the tunnel endpoint address of the load balancer.

[0092] In some embodiments, the second message may be the first message of the target traffic. The target traffic may be traffic to be sent by a target virtual instance in the computing node, or the target traffic may be traffic to be read by a target virtual instance in the computing node. The computing node includes at least one virtual instance, and the target virtual instance is any instance in the computing node.

[0093] In some embodiments, the target virtual instance may be a virtual machine or a container, etc.

[0094] In some embodiments, the target traffic is traffic to be sent by the target virtual instance, and the second message may be a write request. Alternatively, the target traffic is traffic to be read by the target virtual instance, and the second message may be a read request.

[0095] In some embodiments, referring to FIG. 4 , the second message includes a message header and a payload portion, and the message header includes an outer message header and an inner message header.

[0096] The outer header of the second message includes one or more of the following information: the virtual extensible local area network (VNI) identifier of the target virtual instance, an outer source address, or an outer destination address. The outer source address is the tunnel endpoint address of the compute node (denoted by Vtep1), and the outer destination address is the tunnel endpoint address of the load balancer (denoted by Vtep2).

[0097] The inner header of the second message includes one or more of the following information: inner source address, inner destination address, first port number (the source port number of the second message, represented by port1), second port number (the destination port number of the second message, represented by port2), or communication protocol (represented by protocol). The inner source address is the address of the target virtual instance (represented by cip), and the inner destination address is the VPC address of the target service, which is the service responsible for processing the target traffic.

[0098] In some embodiments, the first identification information includes one or more of the following information: the VNI of the target virtual instance, the address of the target virtual instance, the VPC address of the target service, the first port number, the second port number, or the communication protocol, etc. Optionally, the first identification information may be a sextuple, i.e., including the above six pieces of information.

[0099] In some embodiments, referring to FIG. 4 , the second message further includes a first tag, and the first tag is used to indicate that the target traffic is to be unloaded from the load balancer.

[0100] Optionally, the VNI is used to identify the target virtual instance. The second message is a virtual extensible local area network (VxLAN) message, the outer message header of the second message is a VxLAN message header, and the inner message header of the second message is a virtual local area network (VLAN) message header. The tunnel endpoint address of the computing node can be the VxLAN tunnel endpoint IP (Vtep IP) of the computing node, etc., and the tunnel endpoint address of the load balancer can be the Vtep IP of the load balancer, etc.

[0101] Step 302: The load balancer receives the second message and determines a target server for providing a target service based on the second message and the load balancing policy. The target service is a service for processing target traffic.

[0102] The VPC address of the target service corresponds to a virtual address, and the virtual address is bound to multiple servers, all of which provide the target service.

[0103] In step 302, the load balancer receives the second message, reads the VPC address of the target service from the second message, and obtains the virtual address corresponding to the VPC address of the target service based on the VPC address of the target service. The load balancer then determines multiple servers bound to the virtual address, where the multiple servers provide the target service, and selects a server from the multiple servers as the target server based on the load balancing policy.

[0104] Step 303: The load balancer sends a third message to the target server. The third message is obtained based on the second message. The third message includes the second identification information of the target traffic. The outer destination address included in the third message is the tunnel endpoint address of the target server. The third message also includes the first identification information or part of the first identification information.

[0105] The second identification information is the identification information assigned by the load balancer to the target traffic. Part of the first identification information includes the address of the target virtual instance and the VPC address of the target service, etc.

[0106] 4 , the third message includes a message header and a payload part, and the message header includes an outer message header and an inner message header.

[0107] The outer header of the third message includes one or more of the following information: the VNI of the target virtual instance, an outer source address, or an outer destination address. The outer source address is the tunnel endpoint address Vtep1 of the computing node, and the outer destination address is the tunnel endpoint address of the target server (represented by Vtep3).

[0108] The inner header of the third message includes one or more of the following information: an inner source address, an inner destination address, a first port number (port1) (the source port number of the third message), a second port number (port2) (the destination port number of the third message), or a communication protocol. The inner source address is the address of the load balancer's dedicated network segment (expressed as Snat), and the inner destination address is the virtual address of the target server (expressed as vip), which is the virtual address bound to the target server.

[0109] The inner header of the third message further includes the first identification information or part of the first identification information. Optionally, the inner header of the third message includes a transmission control protocol option (TOA) field, and the TOA field includes the first identification information or part of the first identification information.

[0110] In step 303, the load balancer selects an idle address from the addresses included in the dedicated network segment of the load balancer, and uses the selected idle address as the address of the dedicated network segment of the load balancer. The outer destination address included in the outer message header of the second message is replaced by the tunnel endpoint address of the load balancer with the tunnel endpoint address of the target server. The inner source address included in the inner message header of the second message is replaced by the address of the target virtual instance with the address of the dedicated network segment of the load balancer. The inner destination address included in the inner message header of the second message is replaced by the VPC address of the target service with the virtual address of the target server. The first identification information or part of the first identification information is filled in the TOA field of the inner message header of the second message to obtain a third message.

[0111] In some embodiments, the first identification information includes first content and second content, the second identification information includes third content and the second content, and the second content is common to the first identification information and the second identification information.

[0112] The first content includes one or more of the following: the VNI of the target virtual instance, the address of the target virtual instance, or the VPC address of the target service;

[0113] The second content includes one or more of the following: the first port number, the second port number, or the communication protocol used by the second message;

[0114] The third content includes one or more of the following: the address of the dedicated network segment of the load balancer or the virtual address of the target server.

[0115] That is, the second identification information includes one or more of the following information: the address of the dedicated network segment of the load balancer, the virtual address of the target server, the first port number, the second port number, or the communication protocol, etc. Optionally, the second identification information may be a quintuple included in the inner header of the third message, i.e., including the above five pieces of information.

[0116] In some embodiments, the load balancer further generates a first conversion rule, the first conversion rule being used to indicate a conversion relationship between the first identification information and the second identification information. Optionally, the first conversion rule is used to indicate a conversion relationship from the first identification information to the second identification information. The load balancer stores the first conversion rule.

[0117] In some embodiments, the first conversion rule includes the first identification information and the third content. For example, referring to Table 1 below and FIG4 , the first conversion rule includes the VNI of the target virtual instance, the address of the target virtual instance (expressed using cip), the VPC address of the target service, the first port number port1, the second port number port2, the communication protocol protocol, the address of the private network segment of the load balancer Snat, and the virtual address vip of the target server.

[0118] Table 1

[0119] Step 304: The target server receives the third message and obtains a second conversion rule and a sixth message based on the third message. The second conversion rule is used to indicate the conversion relationship between the first identification information and the second identification information. The sixth message includes the second identification information and the payload portion of the third message.

[0120] In some embodiments, the second conversion rule is also used to indicate a conversion relationship from the first identification information to the second identification information. The target server stores the second conversion rule.

[0121] In some embodiments, the second conversion rule includes the first identification information and the third content. For example, referring to FIG4 and referring to Table 2 below, the second conversion rule includes the VNI of the target virtual instance, the address cip of the target virtual instance, the VPC address of the target service, the first port number port1, the second port number port2, the communication protocol protocol, the address Snat of the private network segment of the load balancer, and the virtual address vip of the target server.

[0122] Table 2

[0123] Referring to Figure 4, the target server includes an EVS and a processing module. The EVS of the target server receives the third message, obtains the first identification information and the third content from the third message, generates a second conversion rule including the first identification information and the third content, and removes the outer message header of the third message to obtain the sixth message.

[0124] In some embodiments, the EVS of the target server receives a third message, reads the VNI of the target virtual instance from the outer message header of the third message, and reads the address of the target virtual instance, the VPC address of the target service, the first port number, the second port number and / or the communication protocol from the inner message header of the third message, thereby obtaining the first identification information.

[0125] In some embodiments, the target server further generates a third conversion rule, the third conversion rule being used to indicate a conversion relationship from the second identification information to the first identification information, and the target server further stores the third conversion rule.

[0126] In some embodiments, the third conversion rule includes the second identification information and the first content. For example, referring to FIG4 and referring to Table 3 below, the third conversion rule includes the address Snat of the private network segment of the load balancer, the virtual address vip of the target server, the first port number port1, the second port number port2, the communication protocol protocol, the VNI of the target virtual instance, the address cip of the target virtual instance, and the VPC address of the target service.

[0127] Table 3

[0128] In some embodiments, the sixth message is a VLAN message, etc.

[0129] Step 305: The target server inputs the sixth message to the processing module included in the target server, so that the processing module processes the sixth message.

[0130] In some embodiments, the processing module included in the target server is used to provide a target service, and the processing module included in the target server uses the target service to process the sixth message.

[0131] Optionally, when the target traffic is traffic to be sent by the computing node, the target service may be a storage service, and the processing module included in the target server may store the sixth message. Alternatively, the target service may be a sending service, and the processing module included in the target server may send the sixth message. Of course, the target service may be other services, which are not listed here.

[0132] Optionally, when the target traffic is traffic to be read by the computing node, the processing module may include the target traffic, and the processing module obtains the message included in the target traffic based on the sixth message.

[0133] In some embodiments, since the message header of the sixth message includes the second identification information, the identification information that the processing module included in the target server can recognize for identifying the target traffic is the second identification information, rather than the first identification information, that is, the second identification information is used to identify the target traffic in the processing module included in the target server.

[0134] Step 306: The target server sends a fourth message to the computing node, the fourth message including the first identification information, and the outer source address included in the fourth message is the tunnel endpoint address of the target server and the outer destination address is the tunnel endpoint address of the computing node.

[0135] In some embodiments, the processing module of the target server may input a seventh message to the EVS of the target server, where the message header of the seventh message includes the second identification information.

[0136] Optionally, referring to Figure 4, the message header of the seventh message includes a quintuple, namely, the virtual address vip of the target server (the source address of the seventh message), the address Snat of the private network segment of the load balancer (the destination address of the seventh message), the second port number port2 (the source port number of the seventh message), the first port number port1 (the destination port number of the seventh message) and the communication protocol protocol.

[0137] The EVS of the target server receives the seventh message, obtains a third conversion rule based on the second identification information included in the seventh message, and obtains a fourth message based on the third conversion rule and the seventh message.

[0138] As shown in Table 3 above, the third conversion rule includes first content, which includes the VNI of the target virtual instance, the address cip of the target virtual instance, and the VPC address of the target service. As shown in Figure 4, the fourth message includes a message header, which includes an outer message header and an inner message header. Optionally, if the seventh message includes a payload portion, the fourth message also includes the payload portion of the seventh message.

[0139] The outer header of the fourth message includes one or more of the following information: the VNI of the target virtual instance, an outer source address or an outer destination address, wherein the outer source address is the tunnel endpoint address Vtep3 of the target server, and the outer destination address is the tunnel endpoint address Vtep1 of the computing node.

[0140] The inner header of the fourth message includes one or more of the following information: an inner source address, an inner destination address, a second port number (port2) (the source port number of the fourth message), a first port number (port2) (the destination port number of the fourth message), or a communication protocol (protocol). The inner source address is the VPC address of the target service, and the inner destination address is the address (cip) of the target virtual instance.

[0141] In some embodiments, referring to FIG. 4 , the header of the fourth message may further include a second tag, where the second tag is used to indicate that the target server supports offloading the target traffic from the load balancer.

[0142] In some embodiments, the seventh message is a VLAN message, etc.

[0143] Step 307: The computing node receives the fourth message and generates an encapsulation rule based on the fourth message, where the encapsulation rule is used to instruct to configure the outer destination address included in the message belonging to the target traffic as the tunnel endpoint address of the target server.

[0144] In step 307, the computing node receives the fourth message. When the second mark in the fourth message is used to indicate that the target server supports unloading the target traffic from the load balancer, the computing node obtains the first identification information and the tunnel endpoint address of the target server from the fourth message, and generates an encapsulation rule based on the first identification information and the tunnel endpoint address of the target server.

[0145] In some embodiments, the encapsulation rule includes the first identification information and the tunnel endpoint address of the target server. For example, referring to FIG4 and referring to Table 4 below, the encapsulation rule includes the VNI of the target virtual instance, the address cip of the target virtual instance, the VPC address of the target service, the first port number port1, the second port number port2, the communication protocol protocol, and the tunnel endpoint address of the target server (represented by Vtep3).

[0146] Table 4

[0147] In some embodiments, if the target traffic is traffic to be sent by the computing node, the computing node may send the remaining packets of the target traffic, or the computing node may continue to send at least one packet belonging to the target traffic to the load balancer, using the process of step 308. For example, the eighth packet is a packet in the target traffic that follows the first packet. Referring to FIG. 5 , the computing node sends the eighth packet to the load balancer. The eighth packet includes the first identification information, and the outer destination address included in the eighth packet is the tunnel endpoint address of the load balancer.

[0148] 5 , the eighth message includes a message header and a payload portion, and the structure of the message header of the eighth message is the same as the structure of the message header of the second message. That is, the outer message header of the eighth message includes one or more of the following information: the VNI of the target virtual instance, the outer source address or the outer destination address, etc. Among them, the outer source address is the tunnel endpoint address Vtep1 of the computing node, and the outer destination address is the tunnel endpoint address Vtep2 of the load balancer. The inner message header of the eighth message includes one or more of the following information: the inner source address, the inner destination address, the first port number port1 (the source port number of the eighth message), the second port number port2 (the destination port number of the eighth message), or the communication protocol protocol, etc. Among them, the inner source address is the address cip of the target virtual instance, and the inner destination address is the VPC address of the target service.

[0149] The load balancer receives the eighth message, obtains a first conversion rule based on the first identification information included in the eighth message, and obtains a ninth message based on the first conversion rule and the eighth message. The ninth message includes the second identification information and a payload portion of the eighth message, and the outer destination address of the ninth message is the tunnel endpoint address of the target server. The second identification information is located in an inner message header of the ninth message.

[0150] Referring to the first conversion rule shown in Table 1 above, the ninth message includes a message header and the payload portion of the eighth message, and the message header of the ninth message includes an outer message header and an inner message header. Referring to Figure 5, the outer message header of the ninth message includes one or more of the following information: the VNI of the target virtual instance, the outer source address or the outer destination address, etc. Among them, the outer source address is the tunnel endpoint address Vtep1 of the computing node, and the outer destination address is the tunnel endpoint address Vtep3 of the target server. The inner message header of the ninth message includes one or more of the following information: the inner source address, the inner destination address, the first port number port1 (the source port number of the ninth message), the second port number port2 (the destination port number of the ninth message), or the communication protocol protocol, etc. Among them, the inner source address is the address Snat of the dedicated network segment of the load balancer, and the inner destination address is the virtual address vip of the target server.

[0151] The load balancer sends a ninth message to the target server. The EVS included in the target server receives the ninth message, removes an outer message header of the ninth message, obtains a tenth message, the message header of the tenth message includes the second identification information, inputs the tenth message to the processing module included in the target server, and the processing module included in the target server processes the tenth message.

[0152] When the target flow is short, the target flow includes the second message and the at least one message. It is not necessary to offload the target flow from the load balancer, and the computing node sends the target flow to the target server through the load balancer. When the target flow is long, and after sending the at least one message, other messages remain, the remaining messages in the target flow are offloaded from the load balancer and sent to the target server through the process of step 308.

[0153] In some embodiments, if the target traffic is the traffic to be read by the computing node, the target server may continue to send the remaining messages of the target traffic to the computing node in the manner of step 306, and the computing node receives the remaining messages of the target traffic.

[0154] Step 308: The computing node obtains a first message belonging to the target traffic based on the encapsulation rule. The first message includes first identification information, and the outer destination address included in the first message is the tunnel endpoint address of the target server.

[0155] In step 308, the computing node obtains the first identification information of the target traffic, obtains the encapsulation rule based on the first identification information, and generates the first message of the target traffic that the target virtual instance needs to send based on the encapsulation rule. The outer destination address of the first message is the tunnel endpoint address of the target server, and the first message also includes the first identification information.

[0156] 6 , the computing node obtains the encapsulation rule shown in Table 4 based on the first identification information of the target traffic. The first message generated based on the encapsulation rule includes a message header and a payload portion, where the message header is an outer message header and an inner message header.

[0157] The outer header of the first message includes one or more of the following information: VNI ​​of the target virtual instance, outer source address or outer destination address, etc. The outer source address is the tunnel endpoint address Vtep1 of the computing node, and the outer destination address is the tunnel endpoint address Vtep1 of the target server.

[0158] The inner header of the first message includes one or more of the following information: an inner source address, an inner destination address, a first port number (port1) (the source port number of the first message), a second port number (port2) (the destination port number of the first message), or a communication protocol (protocol). The inner source address is the address cip of the target virtual instance, and the inner destination address is the VPC address of the target service.

[0159] Step 309: The computing node sends a first message to the target server.

[0160] Since the outer destination address of the first message is the tunnel endpoint address of the target server, the computing node can send the first message directly to the target server. That is, the computing node does not need to send the first message to the load balancer and the load balancer sends the first message to the target server, thereby unloading the target traffic from the load balancer and reducing the load on the load balancer.

[0161] Step 310: The target server receives the first message, obtains a second conversion rule based on the first identification information included in the first message, and obtains a fifth message based on the second conversion rule and the first message, where the fifth message includes the second identification information and the payload portion of the first message.

[0162] Referring to Figure 6, the EVS of the target server obtains first identification information from the outer message header and inner message header of the first message, obtains the second conversion rule based on the first identification information, removes the outer message header of the first message, replaces the inner source address included in the inner message header of the first message from the address cip of the target virtual instance to the address Snat of the private network segment of the load balancer included in the second conversion rule, and replaces the inner target address included in the inner message header of the first message from the VPC address of the target service to the virtual address vip of the target server included in the second conversion rule, to obtain the fifth message.

[0163] Referring to the second conversion rule shown in Table 2 above and FIG6 , the fifth message includes a message header and the payload portion of the first message. The message header of the fifth message includes one or more of the following information: source address, destination address, first port number port1 (the source port number of the fifth message), second port number port2 (the destination port number of the fifth message), or communication protocol protocol. The source address is the address Snat of the load balancer's private network segment, and the destination address is the virtual address vip of the target server.

[0164] Step 311: The target server inputs the fifth message to the processing module of the target server, and the processing module is used to process the fifth message.

[0165] The EVS included in the target server inputs the fifth message to the processing module included in the target server, and the processing module included in the target server processes the fifth message.

[0166] In an embodiment of the present application, a computing node sends a second message of target traffic to a load balancer. The outer destination address of the second message is the tunnel endpoint address of the load balancer. The load balancer selects a target server from multiple servers and sends a third message to the target server. The outer destination address of the third message is the tunnel endpoint address of the target server. The target server generates a second translation rule. The second translation rule includes first identification information, the address of the load balancer's dedicated network segment, and the virtual address of the target server. That is, the second translation rule indicates the translation relationship between the first identification information and the second identification information. The target server sends a fourth message to the computing node. The outer source address of the fourth message is the tunnel endpoint address of the target server. The computing node generates an encapsulation rule based on the tunnel endpoint address of the target server. The encapsulation rule includes the first identification information and the tunnel endpoint address of the target server. Based on the encapsulation rule, the computing node obtains a first message of target traffic. The first message includes the first identification information. The outer destination address of the first message is the tunnel endpoint address of the target server. This allows the computing node to send the first message to the target server. This eliminates the need for the first message to pass through the load balancer, thereby offloading the target traffic from the load balancer. After receiving the first message, the target server can remove the outer message header of the first message and, based on the second conversion rule, replace the address of the target virtual instance and the VPC address of the target service in the inner message header of the first message with the address of the load balancer's private network segment and the virtual address of the target server, respectively, as included in the second conversion rule, to obtain a fifth message. This ensures that the fifth message includes the second identification information, ensuring successful processing of the fifth message and avoiding errors.

[0167] 7 , an embodiment of the present application provides a data processing method 700, which is applied to the virtual server cluster 100 shown in FIG1 or FIG2 . The method 700 operates in the direct routing (DR) mode of the virtual server cluster 100 and includes the following process.

[0168] Step 701: The computing node obtains a second message and sends the second message to the load balancer. The second message is a message belonging to the target traffic. The second message includes the first identification information of the target traffic. The outer destination address included in the second message is the tunnel endpoint address of the load balancer, and the inner destination address included in the second message is a virtual address.

[0169] The virtual address is bound to multiple servers for providing target services, and the target services are used to process target traffic.

[0170] In some embodiments, the second message may be the first message of the target traffic. The target traffic may be traffic to be sent by a target virtual instance in the computing node, or the first traffic may be traffic to be read by a target virtual instance in the computing node. The computing node includes at least one virtual instance, and the target virtual instance is any instance in the computing node.

[0171] In some embodiments, the target traffic is traffic to be sent by the target virtual instance, and the second message may be a write request. Alternatively, the target traffic is traffic to be read by the target virtual instance, and the second message may be a read request.

[0172] In some embodiments, referring to FIG8 , the second message includes a message header and a payload portion, and the message header includes an outer message header and an inner message header.

[0173] The outer header of the second message includes one or more of the following information: the VNI of the target virtual instance, an outer source address, or an outer destination address. The outer source address is the tunnel endpoint address of the compute node (denoted by Vtep1), and the outer destination address is the tunnel endpoint address of the load balancer (denoted by Vtep2).

[0174] The inner header of the second message includes one or more of the following information: an inner source address, an inner destination address, a first port number (the source port number of the second message, represented by port1), a second port number (the destination port number of the second message, represented by port2), or a communication protocol (represented by protocol), etc. The inner source address is the address of the target virtual instance, and the inner destination address is a virtual address (represented by vip) bound to multiple servers used to provide the target service.

[0175] The embodiment shown in Figure 3 uses a VPC address to access the Hypertext Transfer Protocol (HTTP) service on the real server, using Full NAT for forwarding. However, the embodiment of this application uses the HTTP service of the real server within the OBS VIP range on the real server, which is an optimization based on DR mode. Therefore, the implementation of Figures 4 to 6 above uses the Full NAT mode of the virtual server cluster 100 for forwarding, while the implementation of Figures 8 to 10 in the embodiment of this application uses the DR mode of the virtual server cluster 100 for forwarding.

[0176] In some embodiments, the first identification information includes one or more of the following information: VNI ​​of the target virtual instance, address of the target virtual instance, virtual address of the target service, first port number, second port number or communication protocol, etc.

[0177] In some embodiments, referring to FIG. 8 , the second message further includes a first tag, and the first tag is used to indicate that the target traffic is to be unloaded from the load balancer.

[0178] Step 702: The load balancer receives the second message and determines a target server for providing a target service based on the second message and the load balancing policy. The target service is a service for processing target traffic.

[0179] In step 702, the load balancer receives the second message, reads from the second message the virtual addresses bound to multiple servers providing the target service, determines the multiple servers bound to the virtual addresses, and selects a server from the multiple servers as the target server based on the load balancing policy.

[0180] Step 703: The load balancer sends a third message to the target server. The third message is obtained based on the second message. The outer destination address included in the third message is the tunnel endpoint address of the target server.

[0181] 8 , the third message includes a message header and a payload portion, and the message header includes an outer message header and an inner message header.

[0182] The outer header of the third message includes one or more of the following information: the VNI of the target virtual instance, an outer source address, or an outer destination address. The outer source address is the tunnel endpoint address Vtep1 of the computing node, and the outer destination address is the tunnel endpoint address of the target server (represented by Vtep3).

[0183] The inner header of the third message is the same as the inner header of the second message. Specifically, the inner header of the third message includes one or more of the following information: an inner source address, an inner destination address, a first port number (port1) (the source port number of the third message), a second port number (port2) (the destination port number of the third message), or a communication protocol. The inner source address is the address cip of the target virtual instance, and the inner destination address is the virtual address vip of the target server.

[0184] Step 704: The target server receives the third message, and obtains a sixth message based on the third message, where the sixth message includes the inner message header of the third message and the payload portion of the third message.

[0185] 8 , the target server includes an EVS and a processing module. The EVS of the target server receives the third message and removes the outer message header of the third message to obtain a sixth message.

[0186] Step 705: The target server inputs the sixth message to the processing module included in the target server, so that the processing module processes the sixth message.

[0187] In some embodiments, the processing module included in the target server is used to provide a target service, and the processing module included in the target server uses the target service to process the sixth message.

[0188] Optionally, when the target traffic is traffic to be sent by the computing node, the target service may be a storage service, and the processing module included in the target server may store the sixth message. Alternatively, the target service may be a sending service, and the processing module included in the target server may send the sixth message. Of course, the target service may be other services, which are not listed here.

[0189] Optionally, when the target traffic is traffic to be read by the computing node, the processing module may include the target traffic, and the processing module obtains the message included in the target traffic based on the sixth message.

[0190] Step 706: The target server sends a fourth message to the computing node, the fourth message including the first identification information, and the outer source address included in the first message is the tunnel endpoint address of the target server and the outer destination address is the tunnel endpoint address of the computing node.

[0191] In some embodiments, the processing module of the target server may input the seventh message to the EVS of the target server.

[0192] Optionally, referring to Figure 8, the message header of the seventh message includes a quintuple, namely, the virtual address vip of the target server (the source address of the seventh message), the address cip of the target virtual instance (the destination address of the seventh message), the second port number port2 (the source port number of the seventh message), the first port number port1 (the destination port number of the seventh message) and the communication protocol protocol.

[0193] The target server's EVS receives the seventh message and adds an outer header to it to generate a fourth message. Referring to Figure 8 , the added outer header includes one or more of the following information: the VNI of the target virtual instance, an outer source address, or an outer destination address. The outer source address is the tunnel endpoint address Vtep3 of the target server, and the outer destination address is the tunnel endpoint address Vtep1 of the compute node.

[0194] In some embodiments, referring to FIG. 8 , the header of the fourth message may further include a second tag, where the second tag is used to indicate that the target server supports offloading the target traffic from the load balancer.

[0195] Step 707: The computing node receives the fourth message and generates an encapsulation rule based on the fourth message, where the encapsulation rule is used to instruct to configure the outer destination address included in the message belonging to the target traffic as the tunnel endpoint address of the target server.

[0196] In step 707, the computing node receives the fourth message. When the second tag in the fourth message is used to indicate that the target server supports unloading the target traffic from the load balancer, the computing node obtains the first identification information and the tunnel endpoint address of the target server from the fourth message, and generates an encapsulation rule based on the first identification information and the tunnel endpoint address of the target server.

[0197] In some embodiments, the encapsulation rule includes the first identification information and the tunnel endpoint address of the target server. For example, referring to FIG8 and referring to Table 5 below, the encapsulation rule includes the VNI of the target virtual instance, the address cip of the target virtual instance, the virtual address vip of the target service, the first port number port1, the second port number port2, the communication protocol protocol, and the tunnel endpoint address Vtep3 of the target server.

[0198] Table 5

[0199] In some embodiments, if the target traffic is traffic to be sent by the computing node, the computing node may send the remaining packets of the target traffic, or the computing node may continue to send at least one packet belonging to the target traffic to the load balancer, using the process of step 708. For example, the eighth packet is a packet located after the first packet in the target traffic. Referring to FIG. 9 , the computing node sends the eighth packet to the load balancer. The eighth packet includes the first identification information, and the outer destination address included in the eighth packet is the tunnel endpoint address of the load balancer.

[0200] 9 , the eighth message includes a message header and a payload portion, and the structure of the message header of the eighth message is the same as the structure of the message header of the second message. That is, the outer message header of the eighth message includes one or more of the following information: the VNI of the target virtual instance, the outer source address or the outer destination address, etc. Among them, the outer source address is the tunnel endpoint address Vtep1 of the computing node, and the outer destination address is the tunnel endpoint address Vtep2 of the load balancer. The inner message header of the eighth message includes one or more of the following information: the inner source address, the inner destination address, the first port number port1 (the source port number of the eighth message), the second port number port2 (the destination port number of the eighth message), or the communication protocol protocol, etc. Among them, the inner source address is the address cip of the target virtual instance, and the inner destination address is the virtual address vip of the target server.

[0201] Referring to Figure 9, the load balancer receives the eighth message and replaces the outer destination address of the eighth message with the tunnel endpoint address of the target server from the load balancer's tunnel endpoint address, thereby obtaining a ninth message. The load balancer sends the ninth message to the target server. The EVS included in the target server receives the ninth message, removes the outer message header of the ninth message, and obtains a tenth message. The EVS inputs the tenth message to the processing module included in the target server, which then processes the tenth message.

[0202] When the target flow is short, the target flow includes the second message and the at least one message. It is not necessary to offload the target flow from the load balancer, and the computing node sends the target flow to the target server through the load balancer. When the target flow is long, and after sending the at least one message, other messages remain, the remaining messages in the target flow are offloaded from the load balancer and sent to the target server through the process of step 708.

[0203] In some embodiments, if the target traffic is the traffic to be read by the computing node, the target server may continue to send the remaining messages of the target traffic to the computing node in the manner of step 706, and the computing node receives the remaining messages of the target traffic.

[0204] Step 708: The computing node obtains a first message belonging to the target traffic based on the encapsulation rule. The first message includes first identification information, and the outer destination address included in the first message is the tunnel endpoint address of the target server.

[0205] In step 708, the computing node obtains the first identification information of the target traffic, obtains the encapsulation rule based on the first identification information, and generates the first message of the target traffic that the target virtual instance needs to send based on the encapsulation rule. The outer destination address of the first message is the tunnel endpoint address of the target server, and the first message also includes the first identification information.

[0206] In some embodiments, referring to Figure 10, the computing node obtains the encapsulation rule shown in Table 5 based on the first identification information of the target traffic. The first message generated based on the encapsulation rule includes a message header and a payload part, where the message header is an outer message header and an inner message header.

[0207] The outer header of the first message includes one or more of the following information: VNI ​​of the target virtual instance, outer source address or outer destination address, etc. The outer source address is the tunnel endpoint address Vtep1 of the computing node, and the outer destination address is the tunnel endpoint address Vtep1 of the target server.

[0208] The inner header of the first message includes one or more of the following information: an inner source address, an inner destination address, a first port number (port1) (the source port number of the first message), a second port number (port2) (the destination port number of the first message), or a communication protocol (protocol). The inner source address is the address cip of the target virtual instance, and the inner destination address is the virtual address vip of the target server.

[0209] Step 709: The computing node sends a first message to the target server.

[0210] Since the outer destination address of the first message is the tunnel endpoint address of the target server, the computing node can send the first message directly to the target server. That is, the computing node does not need to send the first message to the load balancer and the load balancer sends the first message to the target server, thereby unloading the target traffic from the load balancer and reducing the load on the load balancer.

[0211] Step 710: The target server receives the first message and removes the outer message header of the first message to obtain a fifth message.

[0212] 10 , the EVS of the target server removes the outer message header of the first message to obtain the fifth message.

[0213] Step 711: The target server inputs the fifth message to the processing module of the target server, and the processing module is used to process the fifth message.

[0214] The EVS included in the target server inputs the fifth message to the processing module included in the target server, and the processing module included in the target server processes the fifth message.

[0215] In an embodiment of the present application, the computing node sends a second message of the target traffic to the load balancer, and the outer destination address included in the second message is the tunnel endpoint address of the load balancer. The load balancer selects a target server from multiple servers and sends a third message to the target server, and the outer destination address of the third message is the tunnel endpoint address of the target server. The target server sends a fourth message to the computing node, and the outer source address of the fourth message is the tunnel endpoint address of the target server. The computing node generates an encapsulation rule based on the tunnel endpoint address of the target server, and the encapsulation rule includes the first identification information and the tunnel endpoint address of the target server. In this way, the computing node can obtain the first message of the target traffic based on the encapsulation rule, and the first message includes the first identification information, and the outer destination address of the first message is the tunnel endpoint address of the target server, so that the computing node can send the first message to the target server. This makes it possible for the first message to not pass through the load balancer, thereby unloading the target traffic from the load balancer.

[0216] Referring to FIG11 , an embodiment of the present application provides a data processing apparatus 1100. The apparatus 1100 may be deployed on a computing node in the virtual server cluster 100 shown in FIG1 , or the apparatus 1100 may be deployed on a computing node in the method 300 shown in FIG3 or the method 700 shown in FIG7 . The apparatus 1100 includes:

[0217] The processing unit 1101 is configured to obtain, based on an encapsulation rule, a first message of target traffic to be sent, wherein the outer destination address included in the first message is a tunnel endpoint address of a target server; wherein the encapsulation rule is configured to instruct the apparatus 1100 to obtain a message belonging to the target traffic and including an outer destination address as the tunnel endpoint address of the target server, the target server being a server selected by the load balancer from a plurality of servers to process the target traffic;

[0218] The sending unit 1102 is configured to send a first message to a target server.

[0219] Optionally, the detailed implementation process of the processing unit 1101 obtaining the first message of the target traffic to be sent based on the encapsulation rule can be found in step 308 of method 300 shown in Figure 3 or step 708 of method 700 shown in Figure 7, which will not be described in detail here.

[0220] Optionally, the detailed implementation process of the sending unit 1102 sending the first message to the target server can be found in step 309 of the method 300 shown in FIG3 or the relevant content of step 709 of the method 700 shown in FIG7 , and will not be described in detail here.

[0221] Optionally, the apparatus 1100 further includes a receiving unit 1103;

[0222] The processing unit 1101 is configured to obtain a second message of target traffic, where the outer destination address included in the second message is a tunnel endpoint address of the load balancer;

[0223] The sending unit 1102 is further configured to send a second message to the load balancer, and the load balancer is configured to select a target server from the plurality of servers and send a third message to the target server, where the third message is obtained based on the second message;

[0224] The receiving unit 1103 is configured to receive a fourth message sent by the target server based on the third message, where the outer source address included in the fourth message is the tunnel endpoint address of the target server;

[0225] The processing unit 1101 is further configured to generate an encapsulation rule based on the tunnel endpoint address of the target server.

[0226] Optionally, for the detailed implementation process of the processing unit 1101 obtaining the second message of the target flow, please refer to the relevant content of step 301 of the method 300 shown in Figure 3 or step 701 of the method 700 shown in Figure 7, which will not be described in detail here.

[0227] Optionally, the detailed implementation process of the sending unit 1102 sending the second message to the load balancer refers to the relevant content of step 301 of the method 300 shown in Figure 3 or step 701 of the method 700 shown in Figure 7, which is not described in detail here.

[0228] Optionally, the detailed implementation process of the receiving unit 1103 receiving the fourth message sent by the target server based on the third message can be found in step 307 of method 300 shown in Figure 3 or step 707 of method 700 shown in Figure 7, which will not be described in detail here.

[0229] Optionally, the detailed implementation process of the processing unit 1101 generating the encapsulation rule based on the tunnel endpoint address of the target server can be found in step 307 of the method 300 shown in FIG3 or the relevant content of step 707 of the method 700 shown in FIG7 , which will not be described in detail here.

[0230] Optionally, the third message further includes a first tag, where the first tag is used to indicate that the target traffic is to be unloaded from the load balancer. The fourth message is sent by the target server based on the first tag, and the fourth message further includes a second tag, where the second tag is used to indicate that the target server supports unloading the target traffic from the load balancer.

[0231] The processing unit 1101 is configured to generate an encapsulation rule based on the second tag and the tunnel endpoint address of the target server.

[0232] Optionally, the detailed implementation process of the processing unit 1101 generating the encapsulation rule based on the second tag and the tunnel endpoint address of the target server can be found in step 307 of method 300 shown in Figure 3 or step 707 of method 700 shown in Figure 7, which will not be described in detail here.

[0233] Optionally, the encapsulation rule includes first identification information and a tunnel endpoint address of a target server, where the first identification information is identification information of target traffic to be sent by the apparatus 1100;

[0234] The processing unit 1101 is further configured to:

[0235] Obtaining first identification information of target traffic;

[0236] Obtain an encapsulation rule including the first identification information.

[0237] Optionally, for the detailed implementation process of the processing unit 1101 obtaining the first identification information of the target traffic, please refer to the relevant content of step 308 of the method 300 shown in Figure 3 or step 708 of the method 700 shown in Figure 7, which will not be described in detail here.

[0238] Optionally, the detailed implementation process of the processing unit 1101 obtaining the encapsulation rule including the first identification information can be found in step 308 of the method 300 shown in FIG3 or the relevant content of step 708 of the method 700 shown in FIG7 , which will not be described in detail here.

[0239] Optionally, the target server includes a target service for processing target traffic, the target traffic is the traffic to be sent by the target virtual instance included in the device 1100, and the first identification information includes one or more of the following information: the virtual extended local area network identifier VNI of the target virtual instance, the address of the target virtual instance, the address of the target service, the source port number of the first message, the destination port number of the first message, or the communication protocol used by the first message.

[0240] Optionally, the address of the target service is a virtual private cloud (VPC) address of the target service, or the address of the target service is a virtual address bound to the target server.

[0241] Optionally, the first message includes a virtual extended local area network VxLAN message header, the VxLAN message header includes an outer destination address, and the outer destination address is the tunnel endpoint address of the target server.

[0242] In an embodiment of the present application, a processing unit obtains a first message of target traffic to be sent based on an encapsulation rule, and a sending unit sends the first message to a target server. Because the encapsulation rule is used to instruct the computing node that the outer destination address included in the message belonging to the target traffic is the tunnel endpoint address of the target server, the processing unit obtains a first message including an outer destination address as the tunnel endpoint address of the target server based on the encapsulation rule. Because the outer destination address included in the first message is the tunnel endpoint address of the target server, the sending unit can send the first message to the target server, thereby unloading the first message from the load balancer and reducing the load on the load balancer.

[0243] Referring to FIG. 12 , an embodiment of the present application provides a data processing device 1200 . The device 1200 is a server selected by a load balancer from a plurality of servers to process target traffic to be sent by a computing node. For example, the device 1200 may be deployed on a target server in the virtual server cluster 100 shown in FIG. 1 , or the device 1200 may be deployed on a target server in the method 300 shown in FIG. 3 or the method 700 shown in FIG. 7 . The device 1200 includes:

[0244] The receiving unit 1201 is configured to receive a first message of target traffic sent by a computing node, the first message including first identification information, where the first identification information is identification information of the target traffic;

[0245] The message processing unit 1202 is configured to generate a fifth message based on the first message, where the fifth message includes second identification information and a payload portion of the first message, where the second identification information is used to identify target traffic on the device 1200, and the second identification information is identification information assigned when the load balancer requests the device 1200 to process the target traffic;

[0246] The message processing unit 1202 is further configured to process a fifth message.

[0247] Optionally, for the detailed implementation process of the receiving unit 1201 receiving the first message of the target traffic sent by the computing node, please refer to the relevant content of step 310 of method 300 shown in Figure 3 or step 710 of method 700 shown in Figure 7, which will not be described in detail here.

[0248] Optionally, for the detailed implementation process of the message processing unit 1202 generating the fifth message based on the first message, please refer to the relevant content of step 310 of the method 300 shown in Figure 3 or step 710 of the method 700 shown in Figure 7, which will not be described in detail here.

[0249] Optionally, for the detailed implementation process of the message processing unit 1202 processing the fifth message, please refer to the relevant content of step 311 of the method 300 shown in Figure 3 or step 711 of the method 700 shown in Figure 7, which will not be described in detail here.

[0250] Optionally, the apparatus 1200 includes a conversion rule, the conversion rule being used to indicate a conversion relationship between the first identification information and the second identification information, the second identification information being identification information assigned when the load balancer requests the apparatus 1200 to process target traffic;

[0251] The message processing unit 1202 is configured to generate a fifth message based on the conversion rule and the first message.

[0252] Optionally, the detailed implementation process of the message processing unit 1202 generating the fifth message based on the conversion rule and the first message can be found in step 310 of the method 300 shown in FIG3 or step 710 of the method 700 shown in FIG7 , which will not be described in detail here.

[0253] Optionally, the first identification information includes the first content and the second content, the second identification information includes the third content and the second content, and the conversion rule includes the first content, the second content, and the third content.

[0254] Optionally, the target traffic is traffic to be sent by a target virtual instance included in the computing node, and the apparatus 1200 further includes a processing module configured to provide a target service for processing the target traffic;

[0255] The first content includes one or more of the following: a virtual extended local area network identifier VNI of a target virtual instance, an address of a target virtual instance, or a virtual private cloud VPC address of a target service;

[0256] The second content includes one or more of the following: a source port number of the first message, a destination port number of the first message, or a communication protocol used by the first message;

[0257] The third content includes one or more of the following: the address of the dedicated network segment of the load balancer or the virtual address bound to the device 1200 .

[0258] Optionally, the message processing unit 1202 is configured to:

[0259] Acquire a conversion rule based on the first identification information included in the first message;

[0260] Replacing the first content in the first identification information with the third content included in the conversion rule to obtain second identification information;

[0261] A fifth message including the second identification information and the payload portion of the first message is generated.

[0262] Optionally, the detailed implementation process of the message processing unit 1202 obtaining the conversion rule based on the first identification information included in the first message can be found in step 310 of the method 300 shown in FIG3 or step 710 of the method 700 shown in FIG7 , which will not be described in detail here.

[0263] Optionally, the message processing unit 1202 replaces the first content in the first identification information with the third content included in the conversion rule. The detailed implementation process of obtaining the second identification information refers to step 310 of method 300 shown in Figure 3 or the relevant content of step 710 of method 700 shown in Figure 7, which will not be described in detail here.

[0264] Optionally, the detailed implementation process of the message processing unit 1202 generating the fifth message including the second identification information and the payload part of the first message can be found in step 310 of method 300 shown in Figure 3 or step 710 of method 700 shown in Figure 7, which will not be described in detail here.

[0265] Optionally, the receiving unit 1201 is further configured to receive a third message sent by the load balancer, where the third message includes the second identification information and the first content, and the third message is obtained by the load balancer based on the second message after receiving the second message of the target traffic, where the second message includes the first identification information;

[0266] The message processing unit 1202 is further configured to generate a conversion rule based on the third message.

[0267] Optionally, the detailed implementation process of the receiving unit 1201 receiving the third message sent by the load balancer can be found in step 304 of the method 300 shown in FIG3 or the relevant content of step 704 of the method 700 shown in FIG7 , which will not be described in detail here.

[0268] Optionally, for a detailed implementation process of the message processing unit 1202 generating a conversion rule based on the third message, refer to step 304 of the method 300 shown in FIG3 or step 704 of the method 700 shown in FIG7 , which will not be described in detail here.

[0269] Optionally, the third message further includes a first tag, where the first tag is used to indicate that the target traffic is to be unloaded from the load balancer. The apparatus 1200 further includes a sending unit 1203;

[0270] The sending unit 1203 is configured to send a fourth message to the computing node based on the first tag, where the fourth message includes a second tag, and the second tag is configured to indicate that the apparatus 1200 supports unloading the target traffic from the load balancer.

[0271] Optionally, for the detailed implementation process of the sending unit 1203 sending the fourth message to the computing node based on the first tag, please refer to the relevant content of step 306 of the method 300 shown in Figure 3 or step 706 of the method 700 shown in Figure 7, which will not be described in detail here.

[0272] Optionally, the first message includes a virtual extended local area network VxLAN message header, the VxLAN message header includes an outer destination address, and the outer destination address is the tunnel endpoint address of the device 1200.

[0273] In the embodiment of the present application, after the receiving unit receives the first message including the first identification information, the processing unit generates a fifth message including the second identification information, and the second identification information is used to identify the target traffic on the device, thereby enabling the processing unit to identify the fifth message based on the second identification information and process the fifth message. In this way, the first message does not need to include the second identification information assigned by the load balancer, but instead includes the first identification information. Therefore, the computing node can directly send the first message to the device, thereby offloading the first message from the load balancer and reducing the load on the load balancer.

[0274] 13 , an embodiment of the present application provides a computing device 1300. For example, the computing device 1300 may be a computing node in the virtual server cluster 100 shown in FIG1 , or the computing device 1300 may deploy the computing node in the method 300 shown in FIG3 or the method 700 shown in FIG7 .

[0275] As shown in Figure 13 , computing device 1300 includes a bus 1302, a processor 1304, a memory 1306, and a communication interface 1308. Processor 1304, memory 1306, and communication interface 1308 communicate with each other via bus 1302. Computing device 1300 may be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in computing device 1300.

[0276] Bus 1302 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, among others. Buses may be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG13 illustrates a single bus line, but this does not imply a single bus or type of bus. Bus 1302 may include a path for transmitting information between various components of computing device 1300 (e.g., processor 1304, memory 1306, and communication interface 1308).

[0277] The processor 1304 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0278] The memory 1306 may include volatile memory, such as random access memory (RAM). The memory 1306 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0279] Referring to FIG13 , the memory 1306 stores executable program code, and the processor 1304 executes the executable program code to respectively implement the functions of the processing unit 1101, the sending unit 1102, and the receiving unit 1103 in the apparatus 1100 shown in FIG11 , thereby implementing the method provided by any of the above embodiments. In other words, the memory 1306 stores instructions for executing the method provided by any of the above embodiments. Alternatively,

[0280] The communication interface 1308 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1300 and other devices or a communication network.

[0281] Embodiments of the present application also provide a data processing cluster. The data processing cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.

[0282] As shown in Figure 14, the data processing cluster includes at least one computing device 1300. The memory 1306 of one or more computing devices 1300 in the data processing cluster may store the same instructions for executing the method provided in any of the above embodiments.

[0283] In some possible implementations, the memory 1306 of one or more computing devices 1300 in the data processing cluster may also store some instructions for executing the above-mentioned data processing method. In other words, the combination of one or more computing devices 1300 can jointly execute instructions for executing the method provided in any of the above-mentioned embodiments.

[0284] In some possible implementations, one or more computing devices in the data processing cluster can be connected via a network. The network can be a wide area network (WAN) or a local area network (LAN), among others. FIG. 14 illustrates one possible implementation. As shown in FIG. 14 , two computing devices 1300A and 1300B are connected via a network. Specifically, each computing device is connected to the network via a communication interface within the computing device.

[0285] In this type of possible implementation, the memory 1306 in the computing device 1300A stores instructions for executing the functions of the processing unit 1101 in the embodiment shown in FIG11 . Simultaneously, the memory 1306 in the computing device 1300B stores instructions for executing the functions of the sending unit 1102 and the receiving unit 1103 in the embodiment shown in FIG11 .

[0286] It should be understood that the functionality of the computing device 1300A shown in FIG15 may also be implemented by multiple computing devices 1300. Similarly, the functionality of the computing device 1300B may also be implemented by multiple computing devices 1300.

[0287] The present application also provides another data processing cluster. The connection relationship between the computing devices in this data processing cluster can be similar to the connection method of the data processing cluster described in FIG15 . However, the memory 1306 in one or more computing devices 1300 in this data processing cluster can store the same instructions for executing the methods provided in any of the above embodiments.

[0288] In some possible implementations, the memory 1306 of one or more computing devices 1300 in the data processing cluster may also store partial instructions for executing the method provided in any of the above embodiments. In other words, the combination of one or more computing devices 1300 can jointly execute instructions for executing the method provided in any of the above embodiments.

[0289] 16 , an embodiment of the present application provides a computing device 1600. For example, the computing device 1600 may be a computing node in the virtual server cluster 100 shown in FIG1 , or the computing device 1600 may deploy a computing node in the method 300 shown in FIG3 or the method 700 shown in FIG7 .

[0290] As shown in Figure 16 , computing device 1600 includes a bus 1602, a processor 1604, a memory 1606, and a communication interface 1608. Processor 1604, memory 1606, and communication interface 1608 communicate with each other via bus 1602. Computing device 1600 may be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in computing device 1600.

[0291] Bus 1602 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, among others. Buses may be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG16 shows only one line, but this does not imply a single bus or type of bus. Bus 1602 may include a path for transmitting information between various components of computing device 1600 (e.g., processor 1604, memory 1606, and communication interface 1608).

[0292] The processor 1604 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0293] Memory 1606 may include volatile memory, such as random access memory (RAM). Memory 1606 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).

[0294] Referring to FIG16 , the memory 1606 stores executable program code, and the processor 1604 executes the executable program code to respectively implement the functions of the message processing unit 1202, the receiving unit 1201, and the sending unit 1203 in the apparatus 1200 shown in FIG12 , thereby implementing the method provided by any of the above embodiments. In other words, the memory 1606 stores instructions for executing the method provided by any of the above embodiments. Alternatively,

[0295] The communication interface 1608 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 1600 and other devices or a communication network.

[0296] Embodiments of the present application also provide a data processing cluster. The data processing cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.

[0297] As shown in Figure 17, the data processing cluster includes at least one computing device 1600. The memory 1606 of one or more computing devices 1600 in the data processing cluster may store the same instructions for executing the method provided in any of the above embodiments.

[0298] In some possible implementations, the memory 1606 of one or more computing devices 1600 in the data processing cluster may also store some instructions for executing the above-mentioned data processing method. In other words, the combination of one or more computing devices 1600 can jointly execute instructions for executing the method provided in any of the above-mentioned embodiments.

[0299] In some possible implementations, one or more computing devices in the data processing cluster can be connected via a network. The network can be a wide area network (WAN) or a local area network (LAN), among others. FIG. 17 illustrates one possible implementation. As shown in FIG. 17 , two computing devices 1600A and 1600B are connected via a network. Specifically, each computing device is connected to the network via a communication interface within the computing device.

[0300] In this type of possible implementation, the memory 1606 in the computing device 1600A stores instructions for executing the functions of the message processing unit 1202 in the embodiment shown in FIG12 . Simultaneously, the memory 1606 in the computing device 1600B stores instructions for executing the functions of the receiving unit 1201 and the sending unit 1203 in the embodiment shown in FIG12 .

[0301] It should be understood that the functionality of the computing device 1600A shown in FIG18 may also be implemented by multiple computing devices 1600. Similarly, the functionality of the computing device 1600B may also be implemented by multiple computing devices 1600.

[0302] The present application also provides another data processing cluster. The connection relationship between the computing devices in this data processing cluster can be similar to the connection method of the data processing cluster described in FIG18 . However, the memory 1606 in one or more computing devices 1600 in this data processing cluster can store the same instructions for executing the methods provided in any of the above embodiments.

[0303] In some possible implementations, the memory 1606 of one or more computing devices 1600 in the data processing cluster may also store partial instructions for executing the method provided in any of the above embodiments. In other words, the combination of one or more computing devices 1600 can jointly execute instructions for executing the method provided in any of the above embodiments.

[0304] The present application also provides a computer program product comprising instructions. The computer program product may be software or a program product comprising instructions that can be run on a computing device or stored on any available medium. When the computer program product is run on at least one computing device, the at least one computing device executes the method provided in any of the above embodiments.

[0305] The present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device or a data storage device such as a data center that contains one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute the method provided in any of the above embodiments.

[0306] Those skilled in the art will understand that all or part of the steps to implement the above embodiments may be accomplished by hardware, or by a program to instruct the relevant hardware, and the program may be stored in a computer-readable storage medium, which may be a read-only memory, a disk, or an optical disk, etc.

[0307] The above description is merely an optional embodiment of the present application and is not intended to limit the present application. Any modifications, equivalent replacements, improvements, etc. made within the principles of the present application shall be included in the scope of protection of the present application.

Claims

1. A data processing method, characterized in that: The method is applied to a computing node, and the method comprises: Based on the encapsulation rule, a first message of the target traffic to be sent is obtained, wherein the outer destination address included in the first message is the tunnel endpoint address of the target server; wherein the encapsulation rule is used to indicate that the outer destination address included in the message belonging to the target traffic obtained by the computing node is the tunnel endpoint address of the target server, and the target server is a server selected by the load balancer from multiple servers for processing the target traffic; Send the first message to the target server.

2. The method according to claim 1, characterized in that Before obtaining the first message of the target traffic to be sent based on the encapsulation rule, the method includes: Obtaining a second message of the target traffic, wherein the outer destination address included in the second message is the tunnel endpoint address of the load balancer; Sending the second message to the load balancer, the load balancer is used to select the target server from the multiple servers and send a third message to the target server, the third message is obtained based on the second message; receiving a fourth message sent by the target server based on the third message, wherein the outer source address included in the fourth message is the tunnel endpoint address of the target server; The encapsulation rule is generated based on a tunnel endpoint address of the target server.

3. The method according to claim 2, characterized in that The third message further includes a first tag, where the first tag is used to indicate that the target traffic is to be unloaded from the load balancer, and the fourth message is sent by the target server based on the first tag, and the fourth message further includes a second tag, where the second tag is used to indicate that the target server supports unloading the target traffic from the load balancer; The generating the encapsulation rule based on the tunnel endpoint address of the target server comprises: The encapsulation rule is generated based on the second tag and the tunnel endpoint address of the target server.

4. The method according to any one of claims 1 to 3, characterized in that: The encapsulation rule includes first identification information and a tunnel endpoint address of the target server, wherein the first identification information is identification information of the target traffic to be sent by the computing node; Before obtaining the first message of the target flow to be sent based on the encapsulation rule, the method further includes: Acquire the first identification information of the target flow; Acquire the encapsulation rule including the first identification information.

5. The method according to claim 4, characterized in that The target server includes a target service for processing the target traffic, the target traffic is the traffic to be sent by the target virtual instance included in the computing node, and the first identification information includes one or more of the following information: the virtual extended local area network identifier VNI of the target virtual instance, the address of the target virtual instance, the address of the target service, the source port number of the first message, the destination port number of the first message, or the communication protocol adopted by the first message.

6. The method according to claim 5, characterized in that The address of the target service is a virtual private cloud (VPC) address of the target service, or the address of the target service is a virtual address bound to the target server.

7. The method according to any one of claims 1 to 6, characterized in that: The first message includes a virtual extended local area network VxLAN message header, and the VxLAN message header includes the outer destination address, and the outer destination address is the tunnel endpoint address of the target server.

8. A data processing method, characterized in that: The method is applied to a target server, where the target server is a server selected by a load balancer from a plurality of servers for processing target traffic to be sent by a computing node, and the method comprises: receiving a first message of the target traffic sent by the computing node, wherein the first message includes first identification information, and the first identification information is identification information of the target traffic; Based on the first message, a fifth message is generated, wherein the fifth message includes the second identification information and the payload part of the first message. The second identification information is used to identify the target traffic on the target server, and the second identification information is identification information assigned when the load balancer requests the target server to process the target traffic; Process the fifth message.

9. The method according to claim 8, characterized in that The target server includes a conversion rule, and the conversion rule is used to indicate a conversion relationship between the first identification information and the second identification information; The generating a fifth message based on the first message includes: The fifth message is generated based on the conversion rule and the first message.

10. The method according to claim 9, characterized in that The first identification information includes a first content and a second content, the second identification information includes a third content and the second content, and the conversion rule includes the first content, the second content, and the third content.

11. The method according to claim 10, characterized in that The target traffic is the traffic to be sent by the target virtual instance included in the computing node, and the target server further includes a processing module, and the processing module is used to provide a target service for processing the target traffic; The first content includes one or more of the following: a virtual extended local area network identifier VNI of the target virtual instance, an address of the target virtual instance, or a virtual private cloud VPC address of the target service; The second content includes one or more of the following: a source port number of the first message, a destination port number of the first message, or a communication protocol used by the first message; The third content includes one or more of the following: the address of the dedicated network segment of the load balancer or the virtual address bound to the target server.

12. The method according to any one of claims 9 to 11, characterized in that: The generating the fifth message based on the conversion rule and the first message includes: Acquire the conversion rule based on the first identification information included in the first message; Replacing the first content in the first identification information with the third content included in the conversion rule to obtain the second identification information; The fifth message including the second identification information and the payload portion of the first message is generated.

13. The method according to any one of claims 10 to 12, characterized in that: Before the receiving the first message of the target traffic sent by the computing node, the method further includes: receiving a third message sent by the load balancer, wherein the third message includes the second identification information and the first content, and the third message is obtained by the load balancer based on the second message after receiving the second message of the target traffic, and the second message includes the first identification information; The conversion rule is generated based on the third message.

14. The method according to claim 13, characterized in that The third message also includes a first tag, where the first tag is used to indicate that the target traffic is to be unloaded from the load balancer. The method also includes: A fourth message is sent to the computing node based on the first mark, where the fourth message includes a second mark, and the second mark is used to indicate that the target server supports unloading the target traffic from the load balancer.

15. The method according to any one of claims 8 to 14, characterized in that: The first message includes a virtual extended local area network VxLAN message header, and the VxLAN message header includes an outer destination address, and the outer destination address is the tunnel endpoint address of the target server.

16. A data processing device, characterized in that: The device comprises: A processing unit, configured to obtain, based on an encapsulation rule, a first message of a target flow to be sent, wherein an outer destination address included in the first message is a tunnel endpoint address of a target server; wherein the encapsulation rule is configured to indicate that an outer destination address included in a message belonging to the target flow obtained by the device is a tunnel endpoint address of the target server, and the target server is selected by the load balancer from a plurality of servers. A server selected for processing the target traffic; A sending unit, configured to send the first message to the target server.

17. A data processing device, characterized in that: The device is a server selected by a load balancer from a plurality of servers for processing target traffic to be sent by a computing node, and the device includes: A receiving unit, configured to receive a first message of the target flow sent by the computing node, wherein the first message includes first identification information, and the first identification information is identification information of the target flow; a message processing unit, configured to generate a fifth message based on the first message, wherein the fifth message includes second identification information and a payload portion of the first message, wherein the second identification information is used to identify the target traffic on the device, and the second identification information is identification information assigned when the load balancer requests the device to process the target traffic; The message processing unit is further used to process the fifth message.

18. A data processing system, characterized in that: The system comprises the apparatus of claim 16 and the apparatus of claim 17.

19. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1-7 or claims 8-15.

20. A computer-readable storage medium, characterized in that: The method comprises computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method according to any one of claims 1 to 7 or claims 8 to 15.

21. A computer program product comprising instructions, characterized in that When the instruction is executed by the computing device cluster, the computing device cluster executes the method according to any one of claims 1-7 or claims 8-15.

Citation Information

Patent Citations

  • Message transmission method and device based on iSCSI, equipment and storage medium

    CN111131439A

  • Tunnel traffic load balancing method, device, equipment and medium

    CN113055268A

  • Method and system for realizing transparent proxy based on eBPF technology

    CN115941605A

  • Method and device for realizing cloud service of hardware load balancing equipment

    CN116302557A

  • Policy-based forwarding to a load balancer of a load balancing cluster

    US20220030060A1