Data processing method and system for cluster nodes, and device and storage medium
By obtaining network service data and secure port filing data in the Kubernetes cluster, establishing and updating the associated information tables between nodes and NodePort ports, the problem of NodePort ports being easily invaded is solved, and the effect of improving cluster stability and reliability is achieved.
Patent Information
- Application Number
- PCT/CN2024/135878
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2023-12-08
- Filing Date
- 2024-11-29
- Publication Date
- 2025-06-12
AI Technical Summary
In the service exposure scenario of the Kubernetes microservice NodePort, the ports of some nodes are easily illegally invaded, resulting in the stability and reliability of cluster operation being affected.
By obtaining the network service data of the cluster and the security port filing data of each node, establishing the original association information table between the node and the NodePort port, and updating the association information table based on the security port filing data, automatically blocking the NodePort port that has not been securely registered.
It reduces the risk of illegal port intrusion and improves the stability and reliability of cluster operation.
Smart Images

Figure CN2024135878_12062025_PF_FP_ABST
Abstract
Description
Cluster node data processing method, system, device and storage medium Technical Field
[0001] The present application relates to the field of cluster technology, and in particular to a data processing method, system, device, and storage medium for cluster nodes. Background Art
[0002] With the development of information technology, the containerized deployment of applications has gradually been implemented and popularized. Kubernetes (k8s for short) is a container-centric infrastructure that can schedule and run containers on physical clusters or virtual machine clusters, and provide an open source platform for automatic deployment, scaling and management of containers. k8s meets some common requirements of applications in production environments: application instance replicas, horizontal automatic scaling, naming and discovery, load balancing, rolling upgrades, resource monitoring, etc. NodePort is a way to expose services in Kubernetes. In Kubernetes, you can create a NodePort type service to expose applications inside the cluster to the outside of the cluster. NodePort type services open a fixed port on each node and map this port to the IP of the service. In this way, external users can access application services by accessing the node's IP address and NodePort.
[0003] In related technologies, for the service exposure scenario of k8s microservice NodePort, there are multiple computing nodes in a cluster, and each node may correspond to a different IP address. However, the service exposure of the NodePort port works on all nodes. The ports of some nodes may be easily illegally invaded, which affects the stability and reliability of the cluster operation.
[0004] In summary, the problems existing in related technologies need to be solved urgently. Summary of the Invention
[0005] The purpose of this application is to solve one of the technical problems existing in the related art to at least a certain extent.
[0006] To this end, an object of embodiments of the present application is to provide a data processing method, system, device, and storage medium for cluster nodes.
[0007] In order to achieve the above technical objectives, the technical solutions adopted in the embodiments of the present application include:
[0008] In one aspect, an embodiment of the present application provides a data processing method for a cluster node, the method comprising:
[0009] Obtain the cluster's network service data and each node's security port record data;
[0010] According to the network service data, establish the original association information table of the node and NodePort port;
[0011] According to the security port registration data corresponding to each of the nodes, the original association information table is updated to obtain a target association information table;
[0012] Receive a request data packet, parse the request data packet, and obtain target IP address information and target port information;
[0013] Query the target association information table to see whether there is an association between the target IP address information and the target port information. If there is an association between the target IP address information and the target port information, perform business processing on the request data packet; or, if there is no association between the target IP address information and the target port information, discard the request data packet.
[0014] In addition, the data processing method of the cluster node according to the above embodiment of the present application may also have the following additional technical features:
[0015] Furthermore, in one embodiment of the present application, establishing the original association information table of the node and the NodePort port according to the network service data includes:
[0016] Determine the namespace of each service in the cluster based on the network service data;
[0017] Determine each minimum deployable unit according to the namespace;
[0018] Detect the NodePort port of each of the minimum deployable units and establish an original association information table between the nodes and the NodePort ports.
[0019] Furthermore, in one embodiment of the present application, parsing the request data packet to obtain target IP address information and target port information includes:
[0020] Detecting the protocol type of the request data packet;
[0021] According to the protocol type, the request data packet is parsed to obtain the target IP address information and the target port information.
[0022] Furthermore, in one embodiment of the present application, the security port filing data is obtained by the following steps:
[0023] Performing security checks on each port of the node;
[0024] Based on the results of the security detection, secure port filing data is generated.
[0025] Furthermore, in one embodiment of the present application, the original association information table is updated according to the security port registration data corresponding to each of the nodes to obtain a target association information table, including:
[0026] Detect whether the NodePort port is in the port recorded in the security port filing data corresponding to the node;
[0027] If the NodePort port is not in the port recorded in the security port filing data corresponding to the node, the association relationship between the node and the NodePort port in the original association information table is deleted to obtain a target association information table.
[0028] Furthermore, in one embodiment of the present application, the method further includes:
[0029] Detect resource usage of the NodePort port of the node;
[0030] Based on the resource usage, the minimum deployable unit corresponding to the NodePort port is expanded.
[0031] Furthermore, in one embodiment of the present application, the expanding the minimum deployable unit corresponding to the NodePort port according to the resource usage includes:
[0032] When the number of connections of the NodePort port increases by more than a first threshold, the minimum deployable unit corresponding to the NodePort port is expanded;
[0033] Alternatively, when the hardware resource utilization of the node exceeds a second threshold, the minimum deployable unit corresponding to the NodePort port is expanded.
[0034] On the other hand, an embodiment of the present application provides a data processing system for cluster nodes, the system comprising:
[0035] An acquisition unit is used to obtain the network service data of the cluster and the security port registration data of each node;
[0036] An establishing unit, configured to establish an original association information table of the node and the NodePort port according to the network service data;
[0037] An updating unit, configured to update the original association information table according to the security port filing data corresponding to each of the nodes to obtain a target association information table;
[0038] A parsing unit, configured to receive a request data packet, parse the request data packet, and obtain target IP address information and target port information;
[0039] A processing unit is used to query whether there is an association relationship between the target IP address information and the target port information in the target association information table. If there is an association relationship between the target IP address information and the target port information, business processing is performed on the request data packet; or if there is no association relationship between the target IP address information and the target port information, discarding the request data packet.
[0040] In another aspect, an embodiment of the present application provides an electronic device, including:
[0041] at least one processor;
[0042] at least one memory for storing at least one program;
[0043] When the at least one program is executed by the at least one processor, the at least one processor implements the above-mentioned data processing method for the cluster node.
[0044] On the other hand, an embodiment of the present application further provides a computer-readable storage medium, which stores a program executable by a processor. When the program executable by the processor is executed, it is used to implement the data processing method of the cluster node.
[0045] The advantages and benefits of this application will be partially given in the following description, and partially become apparent from the following description, or learned through practice of this application:
[0046] The data processing method, system, device and storage medium of the cluster node disclosed in the embodiment of the present application obtain the network service data of the cluster and the security port filing data of each node; according to the network service data, establish the original association information table of the node and the NodePort port; according to the security port filing data corresponding to each of the nodes, update the original association information table to obtain the target association information table; receive a request data packet, parse the request data packet, and obtain the target IP address information and the target port information; query the target association information table whether there is an association relationship between the target IP address information and the target port information, if there is an association relationship between the target IP address information and the target port information, perform business processing on the request data packet; or, if there is no association relationship between the target IP address information and the target port information, discard the request data packet. This method can verify the request data packet, automatically block the NodePort port that has not been securely filed, reduce the risk of illegal intrusion of the port, and improve the stability and reliability of cluster operation. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the following introduction is made to the drawings of the embodiments of the present application or the related technical solutions in the prior art. It should be understood that the drawings introduced below are only for the convenience of clearly describing some embodiments of the technical solutions of the present invention. For those skilled in the art, other drawings can be obtained based on these drawings without any creative work.
[0048] FIG1 is a schematic diagram of an implementation environment of a cluster node data processing method provided in an embodiment of the present application;
[0049] FIG2 is a schematic diagram of a flow chart of a data processing method for a cluster node provided in an embodiment of the present application;
[0050] FIG3 is a schematic diagram of a target association information table provided in an embodiment of the present application;
[0051] FIG4 is a schematic diagram of a process for parsing a request data packet provided in an embodiment of the present application;
[0052] FIG5 is a schematic diagram of a process for establishing an original association information table provided in an embodiment of the present application;
[0053] FIG6 is a schematic diagram of a process for generating secure port filing data provided in an embodiment of the present application;
[0054] FIG7 is a schematic diagram of a process for obtaining a target association information table provided in an embodiment of the present application;
[0055] FIG8 is a schematic diagram of a specific processing flow of a request data packet provided in an embodiment of the present application;
[0056] FIG9 is a schematic diagram of the structure of a data processing system of a cluster node provided in an embodiment of the present application;
[0057] FIG10 is a schematic structural diagram of an electronic device provided in an embodiment of the present application;
[0058] FIG11 is a schematic structural diagram of another electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0059] The present application is further described below in conjunction with the accompanying drawings and specific embodiments. The described embodiments should not be considered as limiting the present application. All other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0060] In the following description, reference is made to “some embodiments”, which describes a subset of all possible embodiments, but it will be understood that “some embodiments” may be the same subset or different subsets of all possible embodiments and may be combined with each other without conflict.
[0061] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application pertains. The terms used herein are for the purpose of describing the embodiments of this application only and are not intended to limit this application.
[0062] 1) Cluster: A loosely coupled multi-processor system consisting of a group of independent computer nodes or server nodes, where inter-process communication is achieved between nodes through a network.
[0063] 2) Containers, a sandbox technology, isolate applications from the outside world and facilitate portability to various host machines. Essentially, they are specialized processes that use namespaces, control groups, and root-slicing technologies to partition resources, files, devices, state, and configuration into an isolated space.
[0064] 3) Kubernetes, or K8S for short, is a container orchestration engine and a portable, extensible, open-source platform. It provides a method for automating the deployment, scaling, and management of containerized applications, making it easy to run and manage applications in distributed environments. Kubernetes is widely used in cloud computing, big data, artificial intelligence, and other fields, and is one of the standards for container orchestration and management.
[0065] 4) NodePort port, a way to expose Service in Kubernetes. In a Kubernetes cluster, Service is a logical abstraction used to expose a group of Pods to other applications or users. The NodePort port is accessed by selecting a fixed port on the cluster node and mapping the Service to the port. Specifically, when creating a Service, you can choose to expose the Service using NodePort. At this time, Kubernetes will select a port on each cluster node and map the port to the corresponding port on the Pod proxied by the Service (generally the target port of the Service). In this way, by accessing the port of any node, you can access the Pod proxied by the Service.
[0066] 5) Pod, the smallest deployable and manageable computing unit, also known as the minimum deployable unit. A pod is a collection of one or more containers that share the same network namespace, storage volumes, and IP address. A pod is considered a logical machine running in a Kubernetes cluster and is the fundamental unit of Kubernetes scheduling and management.
[0067] With the development of information technology, the containerized deployment of applications has gradually been implemented and popularized. Kubernetes (k8s for short) is a container-centric infrastructure that can schedule and run containers on physical clusters or virtual machine clusters, and provide an open source platform for automatic deployment, scaling and management of containers. k8s meets some common requirements of applications in production environments: application instance replicas, horizontal automatic scaling, naming and discovery, load balancing, rolling upgrades, resource monitoring, etc. NodePort is a way to expose services in Kubernetes. In Kubernetes, you can create a NodePort type service to expose applications inside the cluster to the outside of the cluster. NodePort type services open a fixed port on each node and map this port to the IP of the service. In this way, external users can access application services by accessing the node's IP address and NodePort.
[0068] In related technologies, for the service exposure scenario of k8s microservice NodePort, there are multiple computing nodes in a cluster, and each node may correspond to a different IP address. However, the service exposure of the NodePort port works on all nodes. The ports of some nodes may be easily illegally invaded, which affects the stability and reliability of the cluster operation.
[0069] In view of this, an embodiment of the present application provides a data processing method for cluster nodes, which can verify the request data packet, automatically block the NodePort port that has not been security-recorded, reduce the risk of illegal intrusion of the port, and improve the stability and reliability of cluster operation.
[0070] 1 , which shows a schematic diagram of an implementation environment of a cluster node data processing method provided in an embodiment of the present application. In this implementation environment, the main hardware and software entities involved include a terminal device 110 and a server 120 .
[0071] In the embodiment of the present application, the terminal device 110 and the server 120 can communicate with each other. The data processing method of the cluster node provided in the embodiment of the present application can be implemented by the terminal device 110 and the server 120 alone, or based on the interaction between the terminal device 110 and the server 120.
[0072] The terminal device 110 in the above embodiment may include a smart phone, a tablet computer, a laptop computer, a desktop computer, a smart watch, and a vehicle-mounted terminal, but is not limited thereto.
[0073] Server 120 can be an independent physical server, or a server cluster or distributed system composed of multiple physical servers. It can also be a cloud server that provides basic cloud computing services such as cloud services, cloud databases, cloud computing, cloud functions, cloud storage, network services, cloud communications, middleware services, domain name services, security services, CDN (Content Delivery Network), as well as big data and artificial intelligence platforms.
[0074] The terminal device 110 and the server 120 may establish a communication connection via a wireless network or a wired network. The wireless network or wired network uses standard communication technologies and / or protocols. The network may be the Internet or any other network, including but not limited to a local area network (LAN), a metropolitan area network (MAN), a wide area network (WAN), a mobile, wired or wireless network, a private network or a virtual private network. Furthermore, the aforementioned software and hardware entities may use the same communication connection method or different communication connection methods, and this application does not impose any specific restrictions on this.
[0075] Of course, it is understandable that the implementation environment in FIG1 is only some optional application scenarios of the data processing method of the cluster node provided in the embodiment of the present application, and the actual application is not fixed to the software and hardware environment shown in FIG1.
[0076] Below, in combination with the introduction of the aforementioned implementation environment, a data processing method for a cluster node provided in an embodiment of the present application is introduced and explained.
[0077] Please refer to FIG. 2 , which is a schematic diagram of a data processing method for a cluster node provided by an embodiment of the present application. The data processing method for the cluster node includes but is not limited to:
[0078] Step 210: Obtain the network service data of the cluster and the security port record data of each node;
[0079] In this step, when processing the data of the cluster nodes, the network service data of the cluster and the security port filing data of each node can be obtained first. Among them, the network service data of the cluster refers to the information related to the network services provided by the cluster, for example, it can include the service type, service performance and related address and port information provided in the cluster, and this application does not limit this. In the embodiment of the present application, the security port filing data of each node in the cluster is also obtained. Here, the security port filing data refers to the filing information of the security ports used by each node in the cluster. In some cases, specific ports need to be filed to ensure the compliance and security of network services. It can be understood that if certain ports in the node have been securely filed, it can be considered that the port is a secure port and can provide services normally; conversely, if certain ports in the node have not been securely filed, it can be considered that these ports have security risks and there may be certain risks in providing services.
[0080] Step 220: Create an original association information table of the node and NodePort port based on the network service data;
[0081] In this step, after obtaining the network service data, you can create a table of raw node and NodePort association information based on the network service data. A NodePort is a method used in Kubernetes to expose services. When creating a service, you can choose to expose it using a NodePort. Kubernetes then selects a port on each cluster node and maps it to the corresponding port on the Pod that the service proxies. This allows you to access the Pod that the service proxies by accessing that port on any node.
[0082] In this step, the services exposed using NodePorts within the cluster can be determined based on the network service data. The NodePorts corresponding to these services are then determined, thereby creating a table of raw association information between each node and NodePort. For example, if there are currently four services exposed using NodePorts, with corresponding NodePorts of 80, 8181, 8675, and 9099, a table of correspondence between each node and these NodePorts can be created to obtain the raw association information table.
[0083] Step 230: Update the original association information table according to the security port registration data corresponding to each node to obtain a target association information table;
[0084] In this step, after obtaining the original association information table, the original association information table can be updated according to the security port filing data corresponding to each node to obtain the target association information table. Specifically, it can be understood that in the original association information table, there may be some nodes whose ports have not been securely filed, and there is a security risk. Therefore, in an embodiment of the present application, these NodePort ports that have not been securely filed can be banned according to the security port filing data, thereby updating the correspondence between the nodes and the NodePort ports in the original association information table to obtain the target association information table.
[0085] For example, please refer to Figure 3, which shows a target association information table provided in an embodiment of the present application. For the aforementioned NodePort ports being 80, 8181, 8675, and 9099, respectively, assuming that the cluster includes nodes ip1, ip2, and ip3, wherein ports 8675 and 9099 in node ip1 have not been securely filed, while ports 80 and 8181 have been securely filed, then the association between node ip1 and ports 8675 and 9099 can be deleted from the original association information table, while the association between node ip1 and ports 80 and 8181 is retained. Ports 80, 8181, and 8675 in node ip2 have not been securely filed, while port 9099 has been securely filed, then the association between node ip2 and ports 80, 8181, and 8675 can be deleted from the original association information table, while the association between node ip2 and port 9099 is retained. Ports 80, 8181, and 9099 in node ip3 have not been security-recorded, but port 8675 has been security-recorded. Therefore, the association between node ip3 and ports 80, 8181, and 9099 can be deleted from the original association information table, while the association between node ip3 and port 8675 can be retained. In this way, the updated target association information table can be obtained as shown in Figure 3.
[0086] Step 240: Receive a request data packet, parse the request data packet, and obtain target IP address information and target port information;
[0087] In this step, when processing business data, the cluster can receive the request data packet, and then parse the request data packet to obtain the target IP address information and target port information.
[0088] Specifically, referring to FIG. 4 , in some embodiments, parsing the request data packet to obtain target IP address information and target port information includes:
[0089] Step 410: Detect the protocol type of the request data packet;
[0090] Step 420: Parse the request data packet according to the protocol type to obtain target IP address information and target port information.
[0091] In an embodiment of the present application, when parsing a request packet, the specific implementation method varies depending on the programming language and network library used. For example, in an embodiment of the present application, a network socket can be created, and the socket type can be specified as a listening socket to receive the request packet. The socket can then be used to listen for connections and wait for the arrival of a request packet. When the request packet arrives, the socket is used to receive the packet and store it in a buffer. The protocol type of the request packet can then be detected and parsed based on the protocol type.
[0092] Specifically, general request data packets include types such as TCP protocol and UDP protocol. For request data packets of TCP protocol, the target IP address and target port number can be obtained by reading the first few bytes of the data packet; for request data packets of UDP protocol, the data packet already contains the target IP address and target port number, which can be read directly from the data packet. The specific protocol parsing rules can be referred to the corresponding protocol specifications, which will not be elaborated in this application.
[0093] Step 250: Query the target association information table to see whether there is an association between the target IP address information and the target port information. If there is an association between the target IP address information and the target port information, perform business processing on the request data packet; or, if there is no association between the target IP address information and the target port information, discard the request data packet.
[0094] In this step, after receiving the request data packet, the target IP address information and target port information are parsed out, and the target association information table can be used to determine whether the request data packet has requested a port that has been securely filed. Specifically, the target association information table can be queried to determine whether there is a correlation between the target IP address information and the target port information. In conjunction with Figure 3, it can be understood that if the target association information table contains a correlation between the target IP address information and the target port information, it means that the node corresponding to the IP address has been securely filed for the requested NodePort port and can be considered a secure port. At this time, the request data packet can be processed normally. After the business processing is completed, the corresponding business processing results can be generated and the results fed back to the user terminal. Feedback can be achieved in different ways, such as returning specific fields in the data packet, sending notification messages, updating web page content, etc. In contrast, if the target association information table does not contain a correlation between the target IP address information and the target port information, it means that the node corresponding to the IP address has not been securely filed for the requested NodePort port and can be considered an unsafe port. At this time, the request data packet can be discarded.
[0095] It can be understood that in an embodiment of the present application, a data processing method for a cluster node is provided, which can verify the request data packet, automatically block the NodePort port that has not been security-recorded, reduce the risk of illegal intrusion of the port, and improve the stability and reliability of the cluster operation.
[0096] Specifically, in some embodiments, referring to FIG. 5 , establishing the original association information table of the node and the NodePort port according to the network service data includes:
[0097] Step 510: Determine the namespace of each service in the cluster based on the network service data;
[0098] Step 520: Determine each minimum deployable unit according to the namespace;
[0099] Step 530: Detect the NodePort port of each of the minimum deployable units and establish an original association information table between the nodes and the NodePort ports.
[0100] In an embodiment of the present application, when establishing the original association information table, the namespaces of each service in the cluster can be determined based on the network service data, and then the minimum deployable unit (pod) provided in the cluster can be determined through the namespace. Next, the service port of the minimum deployable unit can be filtered to detect whether it contains a NodePort port. If so, an association relationship between the NodePort port and all nodes can be established. In this way, all minimum deployable units can be traversed to obtain the original association information table.
[0101] Specifically, in some embodiments, referring to FIG. 6 , the secure port filing data is obtained by the following steps:
[0102] Step 610: Perform security checks on each port of the node;
[0103] Step 620: Generate security port filing data based on the security detection result.
[0104] In the embodiments of the present application, when determining the security port filing data, a security detection tool or script can be used to scan each port of the node to detect whether there are open risk ports. Commonly used port scanning tools include Nmap, OpenVAS, etc. Alternatively, a vulnerability scanning tool can be used to scan the port. The vulnerability scanning tool can detect whether the port has known vulnerabilities by comparing it with a known vulnerability database. Commonly used vulnerability scanning tools include Nessus, Qualys, etc. In the embodiments of the present application, there is no restriction on the specific means used for security detection.
[0105] Based on the results of the security detection, secure port filing data can be generated. These data should include information such as the open status of each port, the service or application corresponding to the port, vulnerability detection results, and security configuration check results. In addition, abnormal network activities can also be recorded as clues to potential security incidents. It is understandable that in the embodiments of the present application, the generated secure port filing data can be used for security management and monitoring. They can help better understand the security risks in the system, take timely measures to repair vulnerabilities, optimize configurations, and monitor network traffic to detect abnormal activities.
[0106] Specifically, in some embodiments, referring to FIG. 7 , the original association information table is updated according to the security port filing data corresponding to each of the nodes to obtain a target association information table, including:
[0107] Step 710: Detect whether the NodePort port is in the port recorded in the security port filing data corresponding to the node;
[0108] Step 720: If the NodePort port is not in the port recorded in the security port filing data corresponding to the node, delete the association relationship between the node and the NodePort port in the original association information table to obtain the target association information table.
[0109] In an embodiment of the present application, as described above, these NodePort ports that have not been securely registered can be blocked based on the security port registration data, thereby updating the correspondence between the node and the NodePort port in the original association information table to obtain a target association information table. Specifically, here, it is possible to detect whether the NodePort port is in the port recorded in the security port registration data corresponding to the node. If it is in the port recorded in the security port registration data, it can be considered that the NodePort port has been securely registered and can be retained; if it is not in the port recorded in the security port registration data, it can be considered that the NodePort port has not been securely registered and can be deleted, thereby obtaining a target association information table.
[0110] Specifically, in some embodiments, the method further includes:
[0111] Detect resource usage of the NodePort port of the node;
[0112] Based on the resource usage, the minimum deployable unit corresponding to the NodePort port is expanded.
[0113] Referring to Figure 8, Figure 8 shows a specific request data packet processing flow chart provided in an embodiment of the present application. In Figure 8, after the request data packet enters the cluster, it can be processed by XDP. XDP stands for eXpress Data Path, which is the lowest-level integrated data packet processor of the Linux kernel network stack. It only exists on the RX path. When the network packet reaches the kernel, the XDP program will be executed early. XDP can parse the request data packet to obtain the target IP address information and target port information. Assuming that the current request IP address is the address corresponding to the node ip1, it can detect whether the target port information is port 80 or port 8181. If so, the request data packet can be processed. If not, for example, the target port information is port 9099 or port 8675, the request data packet can be discarded.
[0114] When processing request packets, eBPF (extended BPF) can be used. eBPF, which stands for Extended BPF, is an extension of BPF technology that can implement kernel tracing, application performance tuning / monitoring, and flow control. The principle of eBPF implementing kernel tracing is to compile the written eBPF program into BPF bytecode using the clang / llvm compiler and then inject it into the kernel. In an embodiment of the present application, capacity expansion can be achieved based on eBPF. Specifically, the resource usage of the NodePort port of each node can be monitored, and based on the resource usage, the minimum deployable unit corresponding to the NodePort port can be expanded. For example, the growth of the number of connections on the NodePort port can be monitored. If it exceeds a fixed value (first threshold) or ratio, such as exceeding 20% within a certain time period, the minimum deployable unit can be expanded. For another example, the hardware resource utilization of the node, such as memory or CPU, can be detected. If it exceeds a preset ratio (second threshold), the minimum deployable unit can be expanded. In an embodiment of the present application, the specific values of the first and second thresholds are not limited and can be flexibly adjusted as needed.
[0115] 9 , the data processing system of the cluster node proposed in the embodiment of the present application includes:
[0116] An acquisition unit 910 is configured to acquire the network service data of the cluster and the security port registration data of each node;
[0117] An establishing unit 920 is configured to establish an original association information table of the node and the NodePort port according to the network service data;
[0118] An updating unit 930 is configured to update the original association information table according to the security port registration data corresponding to each of the nodes to obtain a target association information table;
[0119] The parsing unit 940 is configured to receive a request data packet, parse the request data packet, and obtain target IP address information and target port information;
[0120] Processing unit 950 is used to query whether there is an association relationship between the target IP address information and the target port information in the target association information table. If there is an association relationship between the target IP address information and the target port information, business processing is performed on the request data packet; or if there is no association relationship between the target IP address information and the target port information, the request data packet is discarded.
[0121] It can be understood that the contents of the above method embodiments are all applicable to the present system embodiments, the functions specifically implemented by the present system embodiments are the same as those of the above method embodiments, and the beneficial effects achieved are also the same as those achieved by the above method embodiments.
[0122] The present application also discloses an electronic device, including:
[0123] at least one processor;
[0124] at least one memory for storing at least one program;
[0125] When at least one program is executed by at least one processor, the at least one processor implements an embodiment of a data processing method for a cluster node.
[0126] It can be understood that the contents of the aforementioned cluster node data processing method embodiment are all applicable to the present electronic device embodiment, the functions specifically implemented by the present electronic device embodiment are the same as those of the aforementioned cluster node data processing method embodiment, and the beneficial effects achieved are also the same as those achieved by the aforementioned cluster node data processing method embodiment.
[0127] The electronic device in the embodiment of the present application may be a terminal device, a computer device or a server device.
[0128] For example, referring to FIG10 , FIG10 is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. Taking the electronic device as a terminal device as an example, in FIG10 , the terminal device 1000 may include an RF (Radio Frequency) circuit 1010, a memory 1020 including one or more computer-readable storage media, an input unit 1030, a display unit 1040, a sensor 1050, an audio circuit 1060, a short-range wireless transmission module 1070, a processor 1080 including one or more processing cores, and a power supply 1090 and other components. It will be understood by those skilled in the art that the device structure shown in FIG10 does not constitute a limitation on the terminal device, and may include more or fewer components than shown, or combine certain components, or arrange components differently.
[0129] The RF circuit 1010 can be used to receive and transmit signals during information transmission or calls. Specifically, it receives downlink information from the base station and transmits it to one or more processors 1080 for processing. Furthermore, it transmits uplink data to the base station. Typically, the RF circuit 1010 includes, but is not limited to, an antenna, at least one amplifier, a tuner, one or more oscillators, a SIM card, a transceiver, a coupler, an LNA (Low Noise Amplifier), a duplexer, and the like. Furthermore, the RF circuit 1010 can communicate with the network and other devices via wireless communication. Wireless communication can utilize any communication standard or protocol, including but not limited to GSM (Global System of Mobile Communication), GPRS (General Packet Radio Service), CDMA (Code Division Multiple Access), WCDMA (Wideband Code Division Multiple Access), LTE (Long Term Evolution), email, SMS (Short Messaging Service), and the like.
[0130] The memory 1020 can be used to store software programs and modules (or units). The processor 1080 executes various functional applications and data processing by running the software programs and modules (or units) stored in the memory 1020. The memory 1020 may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, at least one application required for a function (such as a sound playback function, an image playback function), etc.; the data storage area may store data created based on the use of the terminal device 1000 (such as audio data, a phone book), etc. In addition, the memory 1020 may include a high-speed random access memory and may also include a non-volatile memory, such as at least one disk storage device, a flash memory device, or other volatile solid-state storage device. Accordingly, the memory 1020 may also include a memory controller to provide the processor 1080 and the input unit 1030 with access to the memory 1020. Although FIG10 shows the RF circuit 1010, it is understood that it is not a necessary component of the terminal device 1000 and can be omitted as needed without changing the essence of the invention.
[0131] The input unit 1030 can be used to receive input digital or character information and generate keyboard, mouse, joystick, optical, or trackball signal input related to object settings and function control. Specifically, the input unit 1030 may include a touch-sensitive surface 1031 and other input devices 1032. The touch-sensitive surface 1031, also known as a touch display or touchpad, can detect touch operations performed by an object on or near it (for example, operations performed by an object using a finger, stylus, or any other suitable object or accessory on or near the touch-sensitive surface 1031) and drive corresponding connected devices according to a pre-set program. Optionally, the touch-sensitive surface 1031 may include a touch detection device and a touch controller. The touch detection device detects the touch position of the object and detects signals generated by the touch operation, transmitting the signals to the touch controller. The touch controller receives the touch information from the touch detection device, converts it into touch point coordinates, and then sends it to the processor 1080. It can also receive and execute instructions from the processor 1080. In addition, the touch-sensitive surface 1031 can be implemented using various types such as resistive, capacitive, infrared, and surface acoustic wave. In addition to the touch-sensitive surface 1031, the input unit 1030 can also include other input devices 1032. Specifically, the other input devices 1032 can include, but are not limited to, one or more of a physical keyboard, function keys (such as volume control keys, power keys, etc.), a trackball, a mouse, a joystick, and the like.
[0132] The display unit 1040 can be used to display information input by or provided to an object and to control various graphical object interfaces of the terminal device 1000. These graphical object interfaces can be composed of graphics, text, icons, videos, or any combination thereof. The display unit 1040 may include a display panel 1041. Optionally, the display panel 1041 may be configured in the form of an LCD (Liquid Crystal Display), an OLED (Organic Light-Emitting Diode), or the like. Furthermore, the touch-sensitive surface 1031 may be overlaid on the display panel 1041. When the touch-sensitive surface 1031 detects a touch operation on or near it, it transmits the information to the processor 1080 to determine the type of touch event. The processor 1080 then provides a corresponding visual output on the display panel 1041 based on the type of touch event. Although in FIG10 , the touch-sensitive surface 1031 and the display panel 1041 are implemented as two separate components to implement input and output functions, in some embodiments, the touch-sensitive surface 1031 and the display panel 1041 may be integrated to implement input and output functions.
[0133] The terminal device 1000 may also include at least one sensor 1050, such as a light sensor, a motion sensor, and other sensors. Specifically, the light sensor may include an ambient light sensor and a proximity sensor, wherein the ambient light sensor may adjust the brightness of the display panel 1041 according to the brightness of the ambient light, and the proximity sensor may turn off the display panel 1041 or the backlight when the terminal device 1000 is moved to the ear. As a type of motion sensor, the gravity acceleration sensor can detect the magnitude of acceleration in all directions (generally three axes), and can detect the magnitude and direction of gravity when stationary. It can be used for applications that recognize the posture of the mobile phone (such as horizontal and vertical screen switching, related games, magnetometer posture calibration), vibration recognition related functions (such as pedometer, tapping), etc.; as for other sensors that can be configured in the terminal device 1000, such as gyroscopes, barometers, hygrometers, thermometers, infrared sensors, etc., they will not be described in detail here.
[0134] The audio circuit 1060, speaker 1061, and microphone 1062 provide an audio interface between the target device and the terminal device 1000. The audio circuit 1060 converts received audio data into electrical signals and transmits them to the speaker 1061, which then converts them into sound signals for output. Meanwhile, the microphone 1062 converts collected sound signals into electrical signals, which are then received by the audio circuit 1060 and converted into audio data. The audio data is then processed by the output processor 1080 and transmitted to another electronic device via the RF circuit 1010. Alternatively, the audio data is output to the memory 1020 for further processing. The audio circuit 1060 may also include an earphone jack to allow communication between an external headset and the terminal device 1000.
[0135] The short-range wireless transmission module 1070 may be a WIFI (wireless fidelity) module, a Bluetooth module, an infrared module, etc. The terminal device 1000 may transmit information with wireless transmission modules provided on other devices via the short-range wireless transmission module 1070 .
[0136] Processor 1080 is the control center of terminal device 1000. It connects all parts of the device using various interfaces and circuits. By running or executing software programs or modules stored in memory 1020 and accessing data stored in memory 1020, it executes various functions of terminal device 1000 and processes data, thereby providing overall control over the device. Optionally, processor 1080 may include one or more processing cores. Alternatively, processor 1080 may integrate an application processor and a modem processor. The application processor primarily handles the operating system, object interfaces, and application programs, while the modem processor primarily handles wireless communications. It is understood that the modem processor may not be integrated into processor 1080.
[0137] The terminal device 1000 also includes a power supply 1090 (e.g., a battery) for supplying power to various components. Optionally, the power supply 1090 can be logically connected to the processor 1080 via a power management system, thereby enabling the power management system to manage charging, discharging, and power consumption. The power supply 1090 can also include one or more DC or AC power supplies, a recharging system, a power failure detection circuit, a power converter or inverter, a power status indicator, and other arbitrary components.
[0138] Although not shown, the terminal device 1000 may also include a camera, a Bluetooth module, etc., which will not be described in detail here.
[0139] Exemplarily, taking the electronic device as a server device as an example, referring to FIG11 , the server device 1100 may have relatively large differences due to different configurations or performances, and may include one or more central processing units 1110 (abbreviated as CPU, Central Processing Units) and a memory 1160, and one or more storage media 1130 (for example, one or more mass storage devices) storing application programs 1133 or data 1132. Among them, the memory 1160 and the storage medium 1130 can be temporary storage or permanent storage. The program stored in the storage medium 1130 may include one or more units or modules, and each unit or module may include a series of operating instructions for the server device 1100. Furthermore, the central processing unit 1110 may be configured to communicate with the storage medium 1130 and execute a series of operating instructions in the storage medium 1130 on the server device 1100.
[0140] The server device 1100 may further include one or more power supplies 1120 , one or more wired or wireless network interfaces 1140 , one or more input and output interfaces 1150 , and one or more operating systems 1131 .
[0141] The central processing unit 1110 in the server device 1100 may be configured to execute an embodiment of a data processing method for a cluster node.
[0142] The embodiment of the present application further discloses a computer-readable storage medium, which stores a program executable by a processor. When the program executable by the processor is executed by the processor, it is used to implement an embodiment of the data processing method of the cluster node.
[0143] It can be understood that the contents of the data processing method embodiment of the cluster node are applicable to the embodiment of this computer-readable storage medium. The functions specifically implemented by this computer-readable storage medium embodiment are the same as those of the data processing method embodiment of the cluster node, and the beneficial effects achieved are also the same as those achieved by the data processing method embodiment of the cluster node.
[0144] In some optional embodiments, the functions / operations mentioned in the block diagram may not occur in the order mentioned in the operation diagram. For example, depending on the functions / operations involved, the two boxes shown in succession may actually be executed substantially simultaneously or the boxes can sometimes be executed in reverse order. In addition, the embodiments presented and described in the flow chart of the present application are provided in an exemplary manner for the purpose of providing a more comprehensive understanding of the technology. The disclosed method is not limited to the operations and logic flows presented herein. Optional embodiments are contemplated in which the order of the various operations is changed and the sub-operations described as a part of a larger operation are performed independently.
[0145] In addition, although the present application is described in the context of functional modules, it should be understood that, unless otherwise stated, one or more of the functions and / or features may be integrated into a single physical device and / or software module, or one or more functions and / or features may be implemented in separate physical devices or software modules. It is also understood that a detailed discussion of the actual implementation of each module is not necessary for understanding the present application. More specifically, given the properties, functions, and internal relationships of the various functional modules in the devices disclosed herein, the actual implementation of the module will be understood within the routine skills of an engineer. Therefore, a person skilled in the art can implement the present application as set forth in the claims using ordinary techniques without undue experimentation. It is also understood that the specific concepts disclosed are merely illustrative and are not intended to limit the scope of the present application, which is determined by the full scope of the appended claims and their equivalents.
[0146] If the function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, or the part that contributes to the prior art, or the part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for enabling a computer device (which can be a personal computer, server, or network device, etc.) to execute all or part of the steps of the various embodiments of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
[0147] The logic and / or steps represented in the flowcharts or otherwise described herein, for example, can be considered as an ordered list of executable instructions for implementing the logical functions, and can be embodied in any computer-readable storage medium for use by, or in conjunction with, an instruction execution system, apparatus, or device (e.g., a computer-based system, a system including a processor, or other system that can fetch and execute instructions from an instruction execution system, apparatus, or device). For purposes of this specification, a "computer-readable storage medium" can be any device that can contain, store, communicate, propagate, or transport a program for use by, or in conjunction with, an instruction execution system, apparatus, or device.
[0148] It should be understood that various parts of the present application can be implemented using hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented using software or firmware stored in a memory and executed by a suitable instruction execution system. For example, if implemented using hardware, as in another embodiment, any one of the following technologies known in the art or a combination thereof can be used to implement: a discrete logic circuit having a logic gate circuit for implementing a logic function on a data signal, an application-specific integrated circuit having a suitable combination of logic gate circuits, a programmable gate array (PGA), a field programmable gate array (FPGA), etc.
[0149] In the above description of this specification, reference to the terms "one embodiment / example," "another embodiment / example," or "certain embodiments / examples" means that the specific features, structures, materials, or characteristics described in conjunction with the embodiment or example are included in at least one embodiment or example of the present application. In this specification, the schematic representation of the above terms does not necessarily refer to the same embodiment or example. Moreover, the specific features, structures, materials, or characteristics described can be combined in any appropriate manner in any one or more embodiments or examples.
[0150] Although the embodiments of the present application have been shown and described, those skilled in the art will appreciate that various changes, modifications, substitutions, and variations may be made to the embodiments without departing from the principles and intent of the present application, and that the scope of the present application is defined by the claims and their equivalents.
[0151] The above is a specific description of the preferred implementation of the present application, but the present application is not limited to the embodiments. Those skilled in the art may make various equivalent modifications or substitutions without violating the spirit of the present application, and these equivalent modifications or substitutions are all included in the scope defined by the claims of the present application.
Claims
1. A data processing method for a cluster node, characterized in that: The method comprises: Obtain the network service data of the cluster and the security port record data of each node; According to the network service data, an original association information table of the node and the NodePort port is established; According to the security port registration data corresponding to each of the nodes, the original association information table is updated to obtain a target association information table; Receiving a request data packet, parsing the request data packet, and obtaining target IP address information and target port information; Query the target association information table to see whether there is an association between the target IP address information and the target port information. If there is an association between the target IP address information and the target port information, perform business processing on the request data packet; or, if there is no association between the target IP address information and the target port information, discard the request data packet.
2. A cluster node data processing method according to claim 1, characterized in that: The establishing of the original association information table of the node and the NodePort port according to the network service data includes: Determine the namespace of each service in the cluster according to the network service data; Determine each minimum deployable unit according to the namespace; Detect the NodePort port of each of the minimum deployable units, and establish an original association information table of the nodes and the NodePort ports.
3. A cluster node data processing method according to claim 1, characterized in that: The request data packet is parsed to obtain target IP address information and target port information, including: Detecting the protocol type of the request data packet; According to the protocol type, the request data packet is parsed to obtain the target IP address information and the target port information.
4. A cluster node data processing method according to claim 1, characterized in that: The security port filing data is obtained through the following steps: Performing security detection on each port of the node; According to the result of the security detection, secure port filing data is generated.
5. A cluster node data processing method according to any one of claims 1 to 4, characterized in that: The updating of the original association information table according to the security port filing data corresponding to each of the nodes to obtain the target association information table includes: Detect whether the NodePort port is in the port recorded in the security port filing data corresponding to the node; If the NodePort port is not in the port recorded in the security port filing data corresponding to the node, delete the association relationship between the node and the NodePort port in the original association information table to obtain the target association information table.
6. A cluster node data processing method according to claim 1, characterized in that: The method further comprises: Detect resource usage of the NodePort port of the node; According to the resource usage, the minimum deployable unit corresponding to the NodePort port is expanded.
7. A cluster node data processing method according to claim 6, characterized in that: The expanding the minimum deployable unit corresponding to the NodePort port according to the resource usage includes: When the number of connections of the NodePort port increases beyond a first threshold, the minimum deployable unit corresponding to the NodePort port is expanded; Alternatively, when the hardware resource utilization of the node exceeds a second threshold, the minimum deployable unit corresponding to the NodePort port is expanded.
8. A data processing system for cluster nodes, characterized in that: The system comprises: An acquisition unit, used to acquire the network service data of the cluster and the security port record data of each node; An establishing unit, used to establish an original association information table of the node and the NodePort port according to the network service data; An updating unit, configured to update the original association information table according to the security port registration data corresponding to each of the nodes to obtain a target association information table; A parsing unit, used for receiving a request data packet, parsing the request data packet, and obtaining target IP address information and target port information; A processing unit is used to query whether there is an association relationship between the target IP address information and the target port information in the target association information table. If there is an association relationship between the target IP address information and the target port information, business processing is performed on the request data packet; or if there is no association relationship between the target IP address information and the target port information, the request data packet is discarded.
9. An electronic device, characterized in that: include: at least one processor; at least one memory for storing at least one program; When the at least one program is executed by the at least one processor, the at least one processor implements a data processing method for a cluster node as described in any one of claims 1 to 7.
10. A computer-readable storage medium storing a program executable by a processor, characterized in that: The processor-executable program is used to implement a data processing method for a cluster node as described in any one of claims 1 to 7 when executed by the processor.
Citation Information
Patent Citations
Network access method and device based on Kubernetes, equipment and medium
CN113572838A
Access control method and device, equipment and storage medium
CN113596033A
Port allocation method and device, electronic equipment and storage medium
CN113946404A
Data processing method, system and equipment for cluster nodes and storage medium
CN117459317A
Method, System, and Computer Program Product for Maintaining Data Centers
US20210157689A1
Cited By
Multi-tenant data processing method and system for Internet of Things
CN122420303A