Bandwidth limiting system and method, and electronic device, storage medium and program product

By implementing bandwidth acquisition modules and bandwidth limiting modules on cluster nodes, dynamically adjusting the bandwidth of each priority, the performance bottleneck problem of traditional bandwidth control solutions in hybrid deployment scenarios is solved, and efficient bandwidth control and isolation of different priority levels is achieved.

WO2025134024A1PCT designated stage expired Publication Date: 2025-06-26CLOUD INTELLIGENCE ASSETS HOLDING (SINGAPORE) PTE LTD
View PDF 8 Cites 0 Cited by

Patent Information

Application Number
PCT/IB2024/062973
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Priority Date
2023-12-21
Filing Date
2024-12-20
Publication Date
2025-06-26

AI Technical Summary

Technical Problem

Traditional bandwidth control solutions are difficult to effectively isolate the traffic of online and offline tasks in hybrid deployment scenarios, and the performance bottleneck is serious and cannot meet the needs of efficient processing.

Method used

A bandwidth limiting system is provided, including a bandwidth acquisition module and a bandwidth limiting module, for processing multiple priority data packets on a cluster node. The system dynamically adjusts the current limit bandwidth of each priority by collecting the current actual bandwidth of each priority and according to the pre-configured total limit bandwidth and the limit bandwidth range of each priority to achieve bandwidth control of different priority levels.

Benefits of technology

It realizes effective isolation of bandwidths of each priority, supports bandwidth borrowing and return of different priority levels, improves bandwidth control effect in hybrid deployment scenarios, simplifies configuration methods, and improves processing efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure IB2024062973_26062025_PF_FP_ABST
    Figure IB2024062973_26062025_PF_FP_ABST
Patent Text Reader

Abstract

Provided in the present disclosure are a bandwidth limiting system and method, and an electronic device, a storage medium and a program product, which are applied to any node in a cluster, wherein the cluster is configured to process data packets of a plurality of priorities. The system comprises: a bandwidth collection module, which is configured to collect the current actual bandwidth corresponding to each priority among a plurality of priorities, and adjust the current limited bandwidth, which corresponds to each priority, on the basis of the current actual bandwidths corresponding to the plurality of priorities, a total limited bandwidth of pre-configured nodes and a limited bandwidth range corresponding to each priority; and a bandwidth limiting module, which is configured to determine a target priority corresponding to a data packet to be sent, and determine, on the basis of the current actual bandwidth and the current limited bandwidth which correspond to the target priority, whether to release the data packet. The present disclosure can realize effective support for bandwidth control of a co-location scenario, and a bandwidth control process and a configuration mode are simple and efficient and easily maintained, thereby improving an overall processing effect of multiple priority tasks.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Bandwidth Limiting System, Method, Electronic Device, Storage Medium, and Program Product This disclosure claims priority to Chinese patent application No. 202311782000.7, filed with the China Patent Office on December 21, 2023, entitled "Bandwidth Limiting System, Method, Electronic Device, Storage Medium, and Program Product," the entire contents of which are incorporated herein by reference. Technical Field This disclosure relates to the field of computer technology, and more particularly to a bandwidth limiting system, method, electronic device, storage medium, and program product. Background: With the continuous development of cloud computing technology, more and more users are choosing to use cloud computing to process tasks. To achieve higher resource utilization, online and offline tasks can be deployed in a hybrid manner across nodes in a cloud cluster. Hybrid deployment scenarios pose greater challenges to bandwidth control. Effectively isolating the traffic of online and offline tasks and maximizing the processing efficiency of both online and offline tasks have become key issues. Traditional bandwidth control solutions are complex and prone to performance bottlenecks, making them difficult to meet the requirements of hybrid deployment scenarios. SUMMARY OF THE INVENTION The present disclosure provides a bandwidth limiting system, method, electronic device, storage medium, and program product for improving bandwidth control in hybrid deployment scenarios. In a first aspect, embodiments of the present disclosure provide a bandwidth limiting system, applied to any node in a cluster, the cluster being configured to process packets of multiple priorities. The system includes: a bandwidth acquisition module for acquiring the current actual bandwidth corresponding to each of the multiple priorities and adjusting the current limited bandwidth corresponding to each priority based on the current actual bandwidth corresponding to the multiple priorities, the pre-configured total limited bandwidth of the node, and the limited bandwidth range corresponding to each priority; a bandwidth limiting module for determining a target priority for a packet to be sent and determining whether to release the packet based on the current actual bandwidth and current limited bandwidth corresponding to the target priority, where the target priority is one of the multiple priorities. Optionally, the bandwidth limiting system also includes a configuration module for obtaining the total limited bandwidth and the limited bandwidth range corresponding to each priority sent by an application program interface server. Optionally, the node is deployed with at least one container, and the at least one container is used to process data packets; the configuration module is further used to: obtain a priority corresponding to each container; and the bandwidth limiting module, when determining a target priority corresponding to a data packet to be sent, is specifically used to: determine, based on characteristic information of the data packet, a container corresponding to the data packet, wherein the target priority of the data packet is the priority of the corresponding container.Optionally, the node includes at least one network card; the bandwidth collection module and the bandwidth limiting module are configured to be mounted on the at least one network card to perform bandwidth collection and bandwidth limiting on data packets corresponding to the at least one network card. Optionally, each of the at least one network card has an inbound queue and an outbound queue, wherein the inbound queue of any network card includes data packets sent by the network card to the container, and the outbound queue includes data packets sent by the container to the network card. The bandwidth collection module is specifically configured to perform bandwidth collection on the inbound queue and the outbound queue, respectively; and the bandwidth limiting module is specifically configured to perform bandwidth limiting on the inbound queue and the outbound queue, respectively. Optionally, the total limited bandwidth of the node includes the total limited bandwidth of the ingress and the total limited bandwidth of the egress, and the limited bandwidth range corresponding to each priority includes the limited bandwidth range of the ingress and the limited bandwidth range of the egress. Bandwidth collection and bandwidth limiting are performed on the inbound queue based on the total limited bandwidth of the ingress and the limited bandwidth range of the ingress for each priority, and bandwidth collection and bandwidth limiting are performed on the outbound queue based on the total limited bandwidth of the egress and the limited bandwidth range of the egress for each priority. Optionally, when the bandwidth acquisition module adjusts the current restricted bandwidth corresponding to each priority level based on the current actual bandwidths corresponding to the multiple priorities, the pre-configured total restricted bandwidth of the node, and the restricted bandwidth range corresponding to each priority level, the module is specifically configured to: if the sum of the current actual bandwidths corresponding to the multiple priorities is less than the total restricted bandwidth of the node, adjust the current restricted bandwidths corresponding to at least some of the priorities upward; and / or, if the sum of the current actual bandwidths corresponding to the multiple priorities is greater than the total restricted bandwidth of the node, adjust the current restricted bandwidths corresponding to at least some of the priorities downward; wherein the current restricted bandwidth of any priority level before and after adjustment is within the corresponding restricted bandwidth range.Optionally, the restricted bandwidth range includes a maximum restricted bandwidth and a minimum restricted bandwidth; when upward adjusting the current restricted bandwidth corresponding to at least some priorities, the bandwidth acquisition module is specifically configured to: subtract the sum of the current actual bandwidths of the multiple priorities from the total restricted bandwidth of the node to obtain the free bandwidth; and sequentially increase the current restricted bandwidth corresponding to each priority in descending order of priority until the total increase reaches the free bandwidth; wherein, for at least some priorities that have been increased, the adjusted current restricted bandwidth of any priority other than the last adjusted priority is the corresponding maximum restricted bandwidth; when downward adjusting the current restricted bandwidth corresponding to at least some priorities, the bandwidth acquisition module is specifically configured to: subtract the total restricted bandwidth of the node from the sum of the current actual bandwidths of the multiple priorities to obtain the contention bandwidth; and sequentially decrease the current restricted bandwidth corresponding to each priority in descending order of priority until the total decrease reaches the contention bandwidth; wherein, for at least some priorities that have been decreased, the adjusted current restricted bandwidth of any priority other than the last adjusted priority is the corresponding maximum restricted bandwidth. Optionally, when determining whether to release the data packet based on the current actual bandwidth and the current limited bandwidth corresponding to the target priority, the bandwidth limiting module is specifically configured to: release the data packet if the current actual bandwidth corresponding to the target priority is less than the current limited bandwidth; and discard the data packet if the current actual bandwidth corresponding to the target priority is not less than the current limited bandwidth. Optionally, when collecting the current actual bandwidth corresponding to each of multiple priority levels, the bandwidth collection module is specifically configured to: determine the priority corresponding to the data packet currently received or sent by the container within a preset period, and add the size of the data packet to the traffic size of the corresponding priority level; and determine the current actual bandwidth of each priority level based on the traffic size of each priority level within the preset period. Optionally, the bandwidth collection module is further configured to: after adding the size of the data packet to the traffic size of the corresponding priority, update the timestamp corresponding to the priority to the timestamp corresponding to the data packet. When determining the current actual bandwidth of each priority level based on the traffic size of each priority level within a preset period, the bandwidth collection module is specifically configured to: for any priority level, calculate the bandwidth of each of a plurality of sampling points within the preset period based on the timestamp and traffic size corresponding to the priority level, and determine the current actual bandwidth of the priority level within the preset period based on the bandwidths of the plurality of sampling points. Optionally, the bandwidth collection module and the bandwidth limiting module are implemented using extended Berkeley Packet Filter (eBPF) technology.Optionally, the total limited bandwidth of the node and the limited bandwidth range corresponding to each priority are recorded in an eBPF data storage structure; the bandwidth collection module is further configured to: read the total limited bandwidth of the node and the limited bandwidth range corresponding to each priority from the eBPF data storage structure, and record the current actual bandwidth and the adjusted current limited bandwidth corresponding to each priority in the eBPF data storage structure; the bandwidth limiting module is further configured to: read the current actual bandwidth and current limited bandwidth corresponding to the target priority from the eBPF data storage structure. In a second aspect, embodiments of the present disclosure provide a bandwidth limiting method, applied to any node in a cluster, the cluster being configured to process packets of multiple priorities. The method comprises: collecting the current actual bandwidth corresponding to each of the multiple priorities, and adjusting the current limited bandwidth corresponding to each priority based on the current actual bandwidth corresponding to the multiple priorities, a pre-configured total limited bandwidth of the node, and the limited bandwidth range corresponding to each priority; determining a target priority corresponding to a packet to be sent, and determining whether to release the packet based on the current actual bandwidth and current limited bandwidth corresponding to the target priority, wherein the target priority is one of the multiple priorities. In a third aspect, embodiments of the present disclosure provide an electronic device, comprising: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to cause the electronic device to perform the method described in the second aspect. In a fourth aspect, embodiments of the present disclosure provide a computer-readable storage medium, wherein the computer-readable storage medium stores computer-executable instructions, and when the processor executes the computer-executable instructions, the method described in the second aspect is implemented. In a fifth aspect, embodiments of the present disclosure provide a computer program product, comprising a computer program, which, when executed by the processor, implements the method described in the second aspect.The bandwidth limiting system, method, electronic device, storage medium, and program product provided herein are applied to any node in a cluster, where the cluster is configured to process data packets of multiple priorities. The system includes: a bandwidth acquisition module, configured to acquire the current actual bandwidth corresponding to each of the multiple priorities and adjust the current limited bandwidth corresponding to each priority based on the current actual bandwidth corresponding to the multiple priorities, the pre-configured total limited bandwidth of the node, and the limited bandwidth range corresponding to each priority; a bandwidth limiting module, configured to determine the target priority corresponding to a data packet to be sent and determine whether to release the data packet based on the current actual bandwidth and current limited bandwidth corresponding to the target priority. The target priority is one of the multiple priorities. By configuring the limited bandwidth range for each priority, the current limited bandwidth of each priority can be dynamically adjusted, and data packets of each priority can be controlled to meet the current limited bandwidth of each priority, thereby effectively isolating the bandwidth of each priority. Furthermore, by referring to the current actual bandwidth of each priority and the total limited bandwidth of the node during adjustment, bandwidth can be dynamically allocated from the entire device perspective based on current actual usage, supporting bandwidth borrowing and repayment for different priorities. Effective support for colocation scenarios is achieved, and the bandwidth control process and configuration method are simple, efficient, and easy to maintain, improving the overall processing performance of multi-priority tasks. BRIEF DESCRIPTION OF THE DRAWINGS The accompanying drawings herein are incorporated into and constitute a part of this specification. They illustrate embodiments consistent with the present disclosure and, together with the specification, serve to explain the principles of the present disclosure. Figure 1 is a diagram of an application scenario provided by an embodiment of the present disclosure; Figure 2 is a schematic diagram of a bandwidth limitation system provided by an embodiment of the present disclosure; Figure 3 is a schematic diagram of a user terminal configuration interface provided by an embodiment of the present disclosure; Figure 4 is a schematic diagram of the workflow of a bandwidth acquisition module provided by an embodiment of the present disclosure; Figure 5 is a schematic diagram of the workflow of a bandwidth limitation module provided by an embodiment of the present disclosure; Figure 6 is a schematic diagram of the flow of a bandwidth limitation method provided by an embodiment of the present disclosure; and Figure 7 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present disclosure. The above drawings illustrate specific embodiments of the present disclosure, which will be described in more detail below. These drawings and descriptions are not intended to limit the scope of the present disclosure in any way, but rather to illustrate the concepts of the present disclosure for those skilled in the art by reference to specific embodiments. DETAILED DESCRIPTION OF THE EMBODIMENTS Exemplary embodiments will be described in detail herein, with examples illustrated in the accompanying drawings. When the following description refers to the drawings, unless otherwise indicated, the same numbers in different drawings represent the same or similar elements.The implementations described in the following exemplary embodiments do not represent all implementations consistent with the present disclosure. Instead, they are merely examples of apparatuses and methods consistent with certain aspects of the present disclosure, as detailed in the appended claims. It should be noted that the user information (including but not limited to user device information, user attribute information, etc.) and data (including but not limited to data used for analysis, stored data, and displayed data, etc.) involved in the present disclosure are all authorized by the user or fully authorized by all parties. The collection, use, and processing of relevant data must comply with relevant laws, regulations, and standards, and corresponding operation portals are provided for users to choose to authorize or deny. First, the terms used in the present disclosure are explained: eBPF: Extended Berkeley Packet Filter, a Linux operating system kernel function extension technology that can be embedded in custom programs to execute customized logic in the Linux system.

[0002] TC: Traffic Control, a traffic rate limiting, shaping, and policy control mechanism provided by the Linux kernel. edt: Earliest Departure Time, a timestamp-based bandwidth limiting technology.

[0003] Qdisc: Queue Dispatching is a queuing discipline in the Linux system used for bandwidth control. Hybrid deployment refers to the simultaneous deployment of online and offline tasks on a single node. A node is an individual computer or server in a cluster. Online tasks generally refer to tasks with high real-time requirements, such as online queries and instant messaging. Offline tasks generally refer to tasks with lower real-time requirements that can be processed offline, such as offline training and batch computing. In cloud-native scenarios, containers can run on any node in a cluster, and nodes may be deployed with a mix of online and offline tasks. The disclosed embodiments can be used to control bandwidth for nodes in a cluster. A node, also known as a node device, is a device in a cluster used to process online or offline tasks. Each node can include multiple network interfaces (NICs). One or more containers can be deployed on a node, and applications within these containers can use multiple NICs to process online or offline tasks. Containers can be created and destroyed, the number of containers in a node can vary, and the relationship between containers and network interfaces is unrestricted. Typically, a container can use one network interface card (NIC), though multiple NICs can be used in certain situations. Different containers can be used to process different task types. For example, some containers may process online tasks, while others may process offline tasks. These containers can all use the node's NIC, allowing online and offline tasks to share the node's underlying infrastructure. Furthermore, due to limited node bandwidth resources, online and offline tasks may face resource contention. Therefore, bandwidth restrictions can be applied to packets for different tasks. Effectively isolating online and offline bandwidth in situations where resource contention exists, while ensuring that offline task bandwidth is met as much as possible, poses a challenge. Some technologies employ the Linux kernel's Qdisc mechanism to implement bandwidth control. The Qdisc mechanism configures a Qdisc scheduler for each NIC and implements bandwidth control through methods such as HTB (Hierarchical Token Bucket). For example, a tree structure can be used to classify packets transmitted by network cards, with each category assigned to separate queues. Bandwidth restrictions can be implemented across queues using the same global lock. Applying the Qdisc solution to colocation scenarios presents numerous challenges and makes it difficult to meet the requirements of colocation scenarios. Specifically, in the case of colocation of containers, containers of different task types will use multiple network cards on a node to send and receive packets simultaneously.The Qdisc solution can only limit bandwidth on a single network interface card (NIC). Multiple NICs cannot share the same rate limiting policy. Therefore, dynamic bandwidth allocation cannot be achieved across multiple NICs on a node, nor can it support dynamic bandwidth borrowing and returning across the entire machine (node). This makes it unsuitable for colocation scenarios. Furthermore, bandwidth limiting relies on a global lock mechanism, which can create performance bottlenecks in high-traffic scenarios. Furthermore, bandwidth limiting policies may require dynamic adjustment. For example, users may desire to adjust the bandwidth allocation ratio for different task types based on actual needs. The Qdisc solution requires configuring a tree structure using specific commands, resulting in complex configuration rules that are difficult to maintain. In light of this, embodiments of the present disclosure provide a bandwidth limiting system to address the inability of traditional bandwidth limiting solutions to support bandwidth control in colocation scenarios. Figure 1 illustrates an application scenario provided by embodiments of the present disclosure. As shown in Figure 1, the system may include a configuration module, a bandwidth collection module, and a bandwidth limiting module. Users can interact with the configuration module through the API (Application Programming Interface) server to configure bandwidth limiting policies, thereby controlling the bandwidth collection module and bandwidth limiting module. The bandwidth collection module and bandwidth limiting module are mounted on the network interface card (NIC) to control the NIC's ingress and egress queues, respectively. The ingress and egress queues maintain ingress and egress traffic, respectively. The ingress direction is transmitted from the NIC to the container, while the egress direction is transmitted from the container to the NIC. Packets transmitted between the NIC and the container have multiple priorities, and the bandwidth collection module and bandwidth limiting module can control packets of different priorities separately. Specifically, the configuration module can configure the total bandwidth limit for the entire node. For example, the total bandwidth limit for a node is 100M (MegaBits Per Second, Mbps). At the same time, tasks are classified according to priority, and task containers of different priorities are mixed and deployed on the node. Different bandwidth restrictions can be configured for tasks of different priorities. For example, the bandwidth restriction range for priority L1 is 10M-20M. oIn practical applications, the current bandwidth limit for each priority level can be adjusted in real time based on the total bandwidth limit and the bandwidth limit range for each priority level, ensuring that the actual bandwidth for each priority level is below the current bandwidth limit. The bandwidth collection module focuses on collecting the current actual bandwidth for each priority level and dynamically adjusting the current bandwidth limit. Specifically, the bandwidth collection module collects the current actual bandwidth corresponding to each priority level in real time and dynamically adjusts the current bandwidth limit for each priority level based on the preset total bandwidth limit, the bandwidth limit range for each priority level, and the real-time collected current actual bandwidth. This ensures that the current bandwidth limit for each priority level meets its respective bandwidth limit range and that the overall current actual bandwidth meets the node's total bandwidth limit. The bandwidth limiting module can perform actual bandwidth control based on the dynamically adjusted current bandwidth limit for each priority level. For example, for any priority level, it can allow or drop packets of that priority level based on its current bandwidth limit. The disclosed embodiments configure the bandwidth limit range for each priority level and support dynamic adjustment of the current bandwidth limit for each priority level, effectively isolating online and offline bandwidth. Furthermore, adjustments refer to the current actual bandwidth of each priority level and the node's total bandwidth limit. Dynamic bandwidth allocation can be performed across the entire machine based on current usage, supporting bandwidth borrowing and repayment for different priorities. This effectively supports colocation scenarios, thereby improving the overall processing efficiency of online and offline tasks. While better meeting actual task requirements, the solution provided by the disclosed embodiments also offers at least the following advantages over the Qdisc solution: The disclosed embodiments dynamically adjust bandwidth usage for different priorities on a node basis, supporting shared bandwidth limit policies for multiple network interfaces. The bandwidth acquisition module focuses on dynamically adjusting the current bandwidth limit, while the bandwidth limit module releases or drops packets based on the current bandwidth limit. This eliminates the need to classify packets using a tree structure and control different packet categories using global locks, effectively improving processing efficiency and reducing performance bottlenecks. Furthermore, the embodiments of the present disclosure configure the total bandwidth limit for a node and the bandwidth limit range for each priority level, eliminating the need for a complex tree structure. This configuration method is simple, efficient, and easy to maintain. The following detailed description of some embodiments of the present disclosure is provided in conjunction with the accompanying drawings. Unless there is a conflict between the embodiments, the following embodiments and their features may be combined. Furthermore, the sequence of steps in the following method embodiments is provided for illustrative purposes only and is not intended to be a strict limitation. Figure 2 is a schematic diagram of a bandwidth limiting system provided by an embodiment of the present disclosure. The system may be implemented as software, hardware, or a combination of software and hardware, and this embodiment does not limit this.The system can be applied to any node in a cluster that processes packets of multiple priorities. The cluster can be a computing cluster in a cloud-native scenario or other scenarios. As shown in FIG2 , the system can include a bandwidth acquisition module 201 and a bandwidth limiting module 202. oThe bandwidth collection module 201 is configured to collect the current actual bandwidth corresponding to each of multiple priority levels and adjust the current limited bandwidth corresponding to each priority level based on the current actual bandwidth corresponding to the multiple priority levels, the pre-configured total limited bandwidth of the node, and the limited bandwidth range corresponding to each priority level. The multiple priority levels can be set based on actual needs to distinguish different types of traffic. Optionally, multiple priorities can be set based on real-time requirements. For example, two priorities, online and offline, can be set, or three priorities, L0, L1, and L2, can be set, with L0 being the highest priority, indicating the highest real-time requirements, L1 being the second highest, and L2 being the lowest. Alternatively, priorities can be set in other ways, which are not limited here. Each priority level corresponds to a current actual bandwidth, a limited bandwidth range, and a current limited bandwidth. The current actual bandwidth represents the actual bandwidth of the current priority level, i.e., the actual traffic volume generated by the data packets corresponding to the priority level. The restricted bandwidth range may include a minimum restricted bandwidth and / or a maximum restricted bandwidth. The current restricted bandwidth is used to limit the actual traffic flow of a priority level and can be considered a threshold. The current restricted bandwidth is adjusted in real time, but remains within the restricted bandwidth range before and after adjustment. In other words, the current restricted bandwidth cannot be less than the minimum restricted bandwidth and / or greater than the maximum restricted bandwidth. Furthermore, a node has a total restricted bandwidth, which is used to limit the total bandwidth of multiple priorities corresponding to the node. The bandwidth acquisition module 201 can determine the current actual bandwidth corresponding to each of the multiple priorities based on the priority and size of each of the multiple data packets transmitted by the network card. Optionally, when adjusting the current restricted bandwidths corresponding to the multiple priorities based on the current actual bandwidths corresponding to the multiple priorities, the pre-configured total restricted bandwidth of the node, and the restricted bandwidth ranges corresponding to the respective priorities, the bandwidth collection module 201 is configured to: if the sum of the current actual bandwidths corresponding to the multiple priorities is less than the total restricted bandwidth of the node, adjust the current restricted bandwidths corresponding to at least some of the priorities upward; and / or if the sum of the current actual bandwidths corresponding to the multiple priorities is greater than the total restricted bandwidth of the node, adjust the current restricted bandwidths corresponding to at least some of the priorities downward; wherein the current restricted bandwidth of any priority before and after adjustment is within the corresponding restricted bandwidth range. Specifically, the bandwidth collection module 201 first sums the current actual bandwidths corresponding to the multiple priorities.If the sum of the current actual bandwidths corresponding to multiple priorities is less than the node's total bandwidth limit, it indicates that resource contention is not occurring and some resources are idle. The current bandwidth limits for some or all priorities can be adjusted upward. For example, there are three priorities: L0, L1, and L2. The current actual bandwidths corresponding to L0, L1, and L2 are calculated to be 10M, 20M, and 30M, respectively. The node's total bandwidth limit is 70M. Since 10M + 20M + 30M < 70M, the current bandwidth limits for some or all of the three priorities can be adjusted upward. For example, if the current bandwidth limit for L0 is also 10M before adjustment, and the bandwidth limit range for L0 is 10-30M, the current bandwidth limit for L0 can be adjusted upward to 20M. o If the sum of the current actual bandwidths corresponding to multiple priorities is greater than the node's total bandwidth limit, it indicates resource contention and some resources are in contention. The current bandwidth limits for some or all priorities can be adjusted downward. For example, there are three priorities: L0, L1, and L2. The current actual bandwidths corresponding to L0, L1, and L2 are calculated to be 30M, 20M, and 30M, respectively. The node's total bandwidth limit is 70M. Since 30M + 20M + 30M > 70M, the current bandwidth limits for some or all of the three priorities can be adjusted downward. For example, if the current bandwidth limit for L2 is 35M before adjustment, and the bandwidth limit range for L2 is 10-50M, the current bandwidth limit for L2 can be adjusted downward to 15M. OYou can set the current bandwidth limits for some or all priorities to increase only when the sum of the current actual bandwidths corresponding to multiple priorities is less than the node's total bandwidth limit. You can also set the current bandwidth limits for some or all priorities to decrease only when the sum of the current actual bandwidths corresponding to multiple priorities is greater than the node's total bandwidth limit. You can also set the current bandwidth limits for some or all priorities to increase when the sum of the current actual bandwidths corresponding to multiple priorities is less than the node's total bandwidth limit, and to decrease when the sum of the current actual bandwidths corresponding to multiple priorities is greater than the node's total bandwidth limit. However, for any priority, both the current bandwidth limit before and after adjustment must be within the corresponding bandwidth limit range. In this way, based on the sum of the current actual bandwidth and the total bandwidth limit, it is possible to determine whether multiple priorities of a node are currently in a contention state. Based on this, the current bandwidth limit can be adjusted accordingly. When resource contention occurs, the current bandwidth limits corresponding to some or all priorities can be adjusted downward to reduce contention and improve overall performance. When resources are idle, the current bandwidth limits corresponding to some or all priorities can be adjusted upward to maximize resource utilization, thereby achieving rational resource allocation and improving node resource utilization and processing efficiency. Optionally, adjustments can be made to different priorities sequentially. For example, when increasing the current bandwidth limits of one or more priorities, the current bandwidth limits of online tasks can be prioritized to ensure that online task data packets are transmitted first. When online tasks are experiencing low performance, the current bandwidth limits of offline tasks can be increased to ensure that offline tasks occupy the remaining bandwidth as much as possible. When decreasing the current bandwidth limits of one or more priorities, the current bandwidth limits of offline tasks can be prioritized to minimize impact on online tasks. This effectively isolates online and offline bandwidth in situations where there is resource contention, and maximizes offline task bandwidth when there is no resource contention. Optionally, the restricted bandwidth range includes a maximum restricted bandwidth and a minimum restricted bandwidth. When upwardly adjusting the current restricted bandwidth corresponding to at least some priorities, the bandwidth acquisition module 201 is specifically configured to: subtract the sum of the current actual bandwidths of the multiple priorities from the node's total restricted bandwidth to obtain the available bandwidth; and sequentially increase the current restricted bandwidth corresponding to each priority in descending order of priority until the total increase reaches the available bandwidth. Among at least some of the priorities that have been upwardly adjusted, for any priority other than the last adjusted priority, the adjusted current restricted bandwidth is the corresponding maximum restricted bandwidth.When downwardly adjusting the current restricted bandwidth corresponding to at least some priorities, the bandwidth collection module 201 is specifically configured to: subtract the total restricted bandwidth of the node from the sum of the current actual bandwidths of multiple priorities to obtain the contention bandwidth; and sequentially reduce the current restricted bandwidth corresponding to each priority in ascending order of priority until the total reduction reaches the contention bandwidth. Among at least some of the priorities that have been downwardly adjusted, the adjusted current restricted bandwidth of any priority other than the last adjusted priority is the corresponding lowest restricted bandwidth. Specifically, the restricted bandwidth range includes a maximum restricted bandwidth and a minimum restricted bandwidth, where the minimum restricted bandwidth is the minimum value of the restricted bandwidth range, and the maximum restricted bandwidth is the maximum value of the restricted bandwidth range. When upwardly adjusting the currently restricted bandwidths corresponding to some or all priorities, the bandwidth collection module 201 subtracts the sum of the current actual bandwidths of multiple priorities from the node's total restricted bandwidth. The resulting difference is the available bandwidth. The currently restricted bandwidths corresponding to the priorities are then increased in descending order of priority until the increase in magnitude equals the available bandwidth. For all priorities except the last adjusted priority among the previously adjusted priorities, the adjusted currently restricted bandwidth becomes the corresponding highest restricted bandwidth. Exemplarily, the priorities are sorted from high to low, and the priority ranked first is adjusted first. The current limited bandwidth corresponding to the priority is subtracted from the highest limited bandwidth corresponding to the priority, and the resulting difference b is compared with the size of the idle bandwidth a. If the resulting difference b is greater than the size of the idle bandwidth a, the magnitude of the increase in the priority ranked first is equal to the size of the idle bandwidth a, and the priority ranked second is no longer adjusted; if the resulting difference b is less than the size of the idle bandwidth a, the current limited bandwidth of the priority ranked first after adjustment is equal to the highest limited bandwidth corresponding to the priority, and the remaining idle bandwidth size is ab. Then, the current limited bandwidth of the priority ranked second is adjusted continuously. The current limited bandwidth corresponding to the priority ranked second is subtracted from the highest limited bandwidth corresponding to the priority, and the resulting difference c is compared with ab. If it is greater than the difference c, the magnitude of the increase in the priority ranked second is equal to the size of the idle bandwidth ab, and the priority ranked third is no longer adjusted; if the resulting difference c is less than the size of the idle bandwidth ab, The current bandwidth limit of the second priority after adjustment is the highest bandwidth limit corresponding to the priority. At this time, the remaining idle bandwidth size is abc. Then the current bandwidth limit of the third, fourth, etc. priorities will be increased. The principle is the same and will not be repeated here.For example, there are three priorities: LO, L1, and L2, arranged from high to low. Their corresponding current actual bandwidths are 10M, 20M, and 30M, respectively. The node's total bandwidth limit is 70M. 10M + 20M + 30M < 70M, and the available bandwidth is 70M - (10M + 20M + 30M) = 10M. Therefore, the bandwidth limits of some or all priorities need to be increased. The specific method is as follows: The current bandwidth limits of LO, L1, and L2 are 10M, 25M, and 35M, respectively, and their maximum bandwidth limits are 30M, 30M, and 45M, respectively. First, adjust the current bandwidth limit of L0. Since 30M - 10M = 20M, which is greater than the available bandwidth of 10M, the increase in L0's bandwidth limit is equal to the available bandwidth of 10M. oIf the idle bandwidth is 30M, since 20M is less than 30M, the current limited bandwidth of L0 is adjusted by 20M. After adjustment, the current limited bandwidth of L0 is 30M, which is equal to the maximum limited bandwidth corresponding to L0. At this time, the idle bandwidth becomes 30M-20M=10M. Therefore, the current limited bandwidth of L1 is adjusted. Since 30M-25M=5M, which is less than the current idle bandwidth of 10M, the current limited bandwidth of L1 is adjusted by 5M. After adjustment, the current limited bandwidth of L1 is 30M, which is equal to the maximum limited bandwidth corresponding to L1. At this time, the idle bandwidth becomes 10M-5M=5M. Then the current limited bandwidth of L2 is adjusted. Since 45M-35M=10M, which is greater than the current idle bandwidth of 5M, the current limited bandwidth of L2 is adjusted by 5M of the idle bandwidth. When downwardly adjusting the currently restricted bandwidths corresponding to some or all priorities, the bandwidth collection module 201 subtracts the total restricted bandwidth of the node from the sum of the current actual bandwidths of multiple priorities. The difference is the contention bandwidth. The module then adjusts downward the currently restricted bandwidths corresponding to each priority in ascending order until the total reduction reaches the same value as the contention bandwidth. For all or some of the priorities that have been downwardly adjusted, except for the last adjusted priority, the adjusted currently restricted bandwidth becomes the corresponding lowest restricted bandwidth.Exemplarily, the priorities are sorted from low to high. The first priority is adjusted first. The difference e obtained by subtracting the minimum bandwidth corresponding to the priority from the current bandwidth limit is compared with the contention bandwidth size f. If the difference e obtained is greater than the contention bandwidth size f, the first priority is adjusted downward by an amount equal to the contention bandwidth size f, and the second priority is not adjusted further. If the difference e obtained is less than the contention bandwidth size f, the current bandwidth limit of the first priority after adjustment is the minimum bandwidth limit corresponding to the priority, and the remaining contention bandwidth size is fe. Then, the current bandwidth limit of the second priority is adjusted further. The difference g obtained by subtracting the minimum bandwidth corresponding to the priority from the current bandwidth limit is compared with fe. If the difference g is greater than fe, the second priority is adjusted downward by an amount equal to the contention bandwidth size fe, and the third priority is not adjusted further. If the difference g obtained is less than the contention bandwidth size fe, the current bandwidth limit of the second priority after adjustment is the minimum bandwidth limit corresponding to the priority. At this point, the remaining contention bandwidth is feg. The current bandwidth limits for the third, fourth, and so on priorities are then reduced. The principle is the same and will not be repeated here. For example, there are three priorities, ranked from low to high: L2, L1, and L0. The corresponding current actual bandwidths are 30M, 20M, and 30M, respectively. The node's total bandwidth limit is 70M. 30M + 20M + 30M > 70M. The contention bandwidth is (30M + 20M + 30M) - 70M = 20M. Therefore, the current bandwidth limits for some or all priorities need to be reduced.The specific method is as follows: The current restricted bandwidths of L0, L1, and L2 are 10M, 25M, and 35M, respectively, and the corresponding minimum restricted bandwidths are 5M, 15M, and 20M, respectively. First, adjust the current restricted bandwidth of L2. Since 35M-20M=15M, and 15M is less than the contention bandwidth of 20M, the adjustment range of the current restricted bandwidth of L2 is 15M. After adjustment, the current restricted bandwidth of L0 is 20M, which is equal to the minimum restricted bandwidth of L2. At this time, the contention bandwidth becomes 20M-15M=5M, so start adjusting the current restricted bandwidth of L1. Since 25M-15M=10M, which is greater than the current contention bandwidth of 5M, the adjustment range of the current restricted bandwidth of L1 is 5M of the contention bandwidth. After adjustment, the current restricted bandwidth of L1 is 20M, and the current restricted bandwidth of L0 is no longer adjusted. In this way, when there is idle bandwidth, the current bandwidth limits corresponding to some or all priorities can be adjusted upwards in descending order. The adjusted current bandwidth limits for each priority level, except for the last adjusted one, can reach the maximum bandwidth limits, thereby maximizing the processing speed of higher-priority tasks. When there is contention for bandwidth, the current bandwidth limits corresponding to some or all priorities can be adjusted downwards in ascending order. The adjusted current bandwidth limits for all priorities, except for the last adjusted one, can reach the minimum bandwidth limits, thereby minimizing the impact of contention on higher-priority tasks caused by contention for lower-priority tasks. Bandwidth limiting module 202 is configured to determine a target priority for a data packet to be sent, and determine whether to release the data packet based on the current actual bandwidth corresponding to the target priority and the current bandwidth limits. The target priority is one of multiple priority levels. Optionally, when the bandwidth limiting module 202 determines whether to release the data packet based on the current actual bandwidth and the current limited bandwidth corresponding to the target priority, it is specifically configured to: release the data packet if the current actual bandwidth corresponding to the target priority is less than the current limited bandwidth; and discard the data packet if the current actual bandwidth corresponding to the target priority is not less than the current limited bandwidth.In summary, the bandwidth limiting system provided in this embodiment includes: a bandwidth collection module 201 for collecting the current actual bandwidth corresponding to each of multiple priority levels and adjusting the current limited bandwidth corresponding to each priority level based on the current actual bandwidth corresponding to the multiple priorities, the pre-configured total limited bandwidth of the node, and the limited bandwidth range corresponding to each priority level; a bandwidth limiting module 202 for determining the target priority level corresponding to a data packet to be sent and determining whether to release the data packet based on the current actual bandwidth and current limited bandwidth corresponding to the target priority level. The configuration rules are simple and easy to maintain, and node processing efficiency is high. In the case of a mixed deployment of multiple priorities, dynamic and precise regulation of the bandwidth corresponding to each priority level can be achieved, thereby improving node resource utilization. Optionally, the bandwidth limiting system also includes a configuration module for obtaining the total limited bandwidth and the limited bandwidth range corresponding to each priority level sent by an application program interface (API) server. Optionally, the configuration module can specifically be used to obtain the total limited bandwidth and the limited bandwidth range corresponding to each priority level configured by a user through the API server. For example, Figure 3 is a schematic diagram of a user-side configuration interface provided by an embodiment of the present disclosure. As shown in Figure 3, to configure the node's total bandwidth limit and the bandwidth limit ranges corresponding to priorities 10, 11, and 12 for node 1, the bandwidth limit ranges include a maximum bandwidth limit and a minimum bandwidth limit. After the user enters the desired values ​​in the corresponding input boxes and clicks the confirm button, the user-side sends the node's total bandwidth limit and the bandwidth limit ranges corresponding to each priority level to the configuration module via the API server. This allows users to flexibly configure the node's total bandwidth limit and the bandwidth limit ranges corresponding to each priority level as needed, improving configuration and modification flexibility. Optionally, the node is deployed with at least one container for processing data packets. The configuration module is further configured to obtain the priority level corresponding to each container. When determining the target priority level corresponding to a data packet to be sent, the bandwidth limiting module 202 is specifically configured to determine the container corresponding to the data packet based on the data packet's characteristic information, where the target priority level of the data packet is the priority level of the corresponding container. Specifically, the configuration module may also obtain the priority level corresponding to each container configured by the user via the application programming interface server. Multiple containers run in a node. Users can divide containers into multiple priorities based on the types of tasks processed by the applications running in the containers.In one example, when the task type corresponding to a container is an online task, the priority can be set to L0; when the task type corresponding to the container is an offline task, the priority can be set to L1, where priority L0 is higher than L1. In another example, online and offline tasks can be divided more finely to obtain more priority types. For example, online tasks can be divided into live broadcast tasks and voice call tasks, with the priority corresponding to live broadcast tasks set to L0 and the priority corresponding to voice call tasks set to L1. Offline tasks can be divided into model training tasks and data analysis tasks, with the priority corresponding to model training tasks set to L2 and the priority corresponding to data analysis tasks set to L3, where the priority levels L0 > L1 > L2 > L3. The bandwidth limiting module 202 can determine the container corresponding to a data packet based on the characteristic information of the data packet. The priority of the container is the target priority of the data packet. The characteristic information may include Internet Protocol (IP) information, port information, or a Control Group (CGroup) ID (Identity Document). The IP and port information can be used in combination, that is, the container corresponding to a packet is determined based on both the IP and port information of the packet. The CGroup ID can be used alone, that is, the container corresponding to a packet can be determined based solely on the CGroup ID of the packet. The present disclosure determines the container corresponding to a packet based on the characteristic information of the packet and determines the priority of the packet based on the container, without relying on a complex tree structure, thereby improving the efficiency of priority determination. Furthermore, in cloud-native scenarios, the same node may have multiple network namespaces. When using the Qdisc solution, the classification ID may be lost when the packet traverses different network namespaces, resulting in packet classification failure. This embodiment determines the priority of the packet based on the container corresponding to the packet. Even if the node corresponds to multiple different network namespaces, this does not affect the priority determination, effectively improving the accuracy of priority determination.FIG4 is a schematic diagram of the workflow of a bandwidth collection module 201 provided in an embodiment of the present disclosure. As shown in FIG4 , when a data packet is detected, the priority corresponding to the data packet is first determined based on the IP address and / or port number of the data packet. For example, when the IP address is 127.0.0.1, the corresponding priority is L2, and when the IP address is 127.0.0.2 and the port number (Dport) is 60, the corresponding priority is L0. All data packets entering the bandwidth collection module 201 within a preset period are classified according to priority. The current actual bandwidth (current_bps) corresponding to priorities L0, L1, and L2 is calculated and stored. The current actual bandwidth corresponding to priorities L0, L1, and L2 is summed and compared with the total restricted bandwidth of the node. Based on the comparison result and the restricted bandwidth range corresponding to priorities L0, L1, and L2 configured by the user, the restricted bandwidth range has a minimum value of the minimum restricted bandwidth (min_bps) and a maximum value of the maximum restricted bandwidth (max_bps). The current bandwidth limit (max_bps) of L2 is adjusted to obtain and store the adjusted current bandwidth limit. Figure 5 illustrates a workflow diagram of a bandwidth limiting module 202 according to an embodiment of the present disclosure. As shown in Figure 5, when a data packet is detected, the priority of the data packet is first determined. Based on the priority of the data packet, the current actual bandwidth (current_bps) and the current bandwidth limit (max_bps) corresponding to the priority are obtained. A determination is then made as to whether the current actual bandwidth corresponding to the priority is less than the current bandwidth limit. If so, the data packet is allowed to pass; if not, the data packet is discarded. Optionally, the node includes at least one network interface card (NIC); the bandwidth collection module 201 and bandwidth limitation module 202 are configured to be mounted to the at least one NIC to collect and limit bandwidth for data packets corresponding to the at least one NIC. Specifically, a node includes at least one network interface card (NIC). The TC module of each of the at least one NIC is equipped with a bandwidth collection module 201 and a bandwidth limiting module 202. The bandwidth collection module 201 can collect bandwidth for data packets received by the corresponding NIC, and the bandwidth limiting module 202 can limit bandwidth for data packets received by the corresponding NIC. Optionally, the configuration module is further configured to automatically attach the bandwidth collection module 201 and the bandwidth limiting module 202 to the TC module of the newly added NIC in response to the addition of a NIC to the node.The bandwidth collection module 201 and bandwidth limiting module 202 can be mounted on multiple physical network cards. Program operation does not rely on Qdisc locks, fully utilizing multiple processor cores. Optionally, each of the at least one network card has an inbound queue and an outbound queue. The inbound queue of any network card includes packets sent from the network card to the container, and the outbound queue includes packets sent from the container to the network card. The bandwidth collection module 201 is specifically configured to collect bandwidth for the inbound queue and the outbound queue, respectively. The bandwidth limiting module 202 is specifically configured to limit bandwidth for the inbound queue and the outbound queue, respectively. Specifically, each of the at least one network card has an inbound queue and an outbound queue. The inbound queue includes packets sent from the network card to the container, and the outbound queue includes packets sent from the container to the network card. The bandwidth collection module 201 can collect bandwidth for the inbound queue and the outbound queue, respectively, and the bandwidth limiting module 202 can limit bandwidth for the inbound queue and the outbound queue, respectively. Optionally, in the egress direction, an EDT approach can be used to set an earliest departure time for packets in the outgoing queue. Using a time-based scheduling strategy for packet transmission can effectively reduce buffer occupancy and latency increases under high traffic conditions. In the ingress direction, a token bucket approach, such as that implemented through extended Berkeley Packet Filter (eBPF), can be used to transmit packets, with the bandwidth collection module 201 and bandwidth limiting module 202 determining whether to allow a packet to be transmitted. In this way, traffic in the ingress and egress directions of each network card are differentiated, and bandwidth collection and bandwidth limiting are performed separately, improving node resource utilization and packet processing efficiency. Optionally, the bandwidth collection module 201 and bandwidth limiting module 202 can perform bandwidth collection and bandwidth limiting only for the ingress queue, only for the egress queue, or for both the ingress and egress queues simultaneously, though this disclosure is not limited thereto. Optionally, the total restricted bandwidth of the node includes a total restricted bandwidth of the ingress and a total restricted bandwidth of the egress, and the restricted bandwidth range corresponding to each priority includes a restricted bandwidth range of the ingress and a restricted bandwidth range of the egress, so that bandwidth collection and bandwidth limitation are performed on the ingress queue based on the total restricted bandwidth of the ingress and the restricted bandwidth range of the ingress for each priority, and bandwidth collection and bandwidth limitation are performed on the egress queue based on the total restricted bandwidth of the egress and the restricted bandwidth range of the egress for each priority.Specifically, a network card corresponds to an inbound queue and an outbound queue. The inbound queue corresponds to the ingress, and the outbound queue corresponds to the egress. The total limited bandwidth of a node includes the total limited bandwidth of the inbound and the total limited bandwidth of the egress. The limited bandwidth range corresponding to each priority also includes the limited bandwidth range of the inbound and the limited bandwidth range of the egress. The bandwidth collection module 201 and the bandwidth limitation module 202 can collect bandwidth and limit bandwidth for the inbound queue based on the total limited bandwidth of the inbound and the limited bandwidth range of each priority. The bandwidth collection module 201 and the bandwidth limitation module 202 can collect bandwidth and limit bandwidth for the outbound queue based on the total limited bandwidth of the egress and the limited bandwidth range of each priority. In this way, the total limited bandwidth and the limited bandwidth range corresponding to each priority are set for the inbound and egress, respectively. Bandwidth collection is performed on the inbound and outbound queues, and the current actual bandwidth of each priority is determined. The current limited bandwidth is then determined based on the current actual bandwidth, the total limited bandwidth, and the limited bandwidth range of each priority. This allows the inbound and outbound queues to use different bandwidth limitation strategies, thereby improving the accuracy of the determined current limited bandwidth. Optionally, when collecting the current actual bandwidth corresponding to each of the multiple priority levels, the bandwidth collection module 201 is specifically configured to: determine the priority level corresponding to the data packets currently received or sent by the container within a preset period, and add the size of the data packets to the traffic level corresponding to the priority level; and determine the current actual bandwidth for each priority level based on the traffic level for each priority level within the preset period. The preset period can be flexibly set based on actual needs and is not a limitation. Specifically, within the preset period, the network card sends multiple data packets to the container, or vice versa, and for each data packet, determines the priority level corresponding to the data packet. For each priority level, the sizes of the data packets for that priority level are added to obtain the traffic level corresponding to that priority level. Based on the traffic level for that priority level within the preset period, the current actual bandwidth for that priority level is determined.For example, a node includes two containers, namely container 1 and container 2. Container 1 has a priority of L0, while container 2 has a priority of L1. A preset period is set at 1 second. Within 1 second, the network card sends three data packets to container 1: packet 1, packet 2, and packet 3, all of which have a priority of L0. It also sends two data packets to container 2: packet 4 and packet 5, both of which have a priority of L1. Therefore, the sizes of packets 1, 2, and 3 are accumulated, and the current actual bandwidth corresponding to priority L0 is determined based on the accumulated result. The sizes of packets 4 and 5 are accumulated, and the current actual bandwidth corresponding to priority L1 is determined based on the accumulated result. In this way, data packets received or sent by the container within the preset period are first classified according to priority, and the sizes of data packets of the same priority are accumulated. Based on the accumulated result, the current actual bandwidth of the priority can be determined. This improves the accuracy of the calculated current actual bandwidth for each priority. Optionally, the bandwidth collection module 201 is further configured to: after adding the size of the data packet to the traffic size of the corresponding priority, update the timestamp corresponding to the priority to the timestamp corresponding to the data packet. Specifically, for each data packet, after adding the size of the data packet to the traffic size of the corresponding priority, update the timestamp corresponding to the priority, and update the timestamp corresponding to the priority to the timestamp corresponding to the data packet. When determining the current actual bandwidth of each priority level based on the traffic size of each priority level within a preset period, the bandwidth collection module 201 is specifically configured to: calculate the bandwidth of each of a plurality of sampling points within the preset period based on the timestamp and traffic size corresponding to the priority level, and determine the current actual bandwidth of the priority level within the preset period based on the bandwidth of the plurality of sampling points. Specifically, for each priority level, when calculating the current actual bandwidth of the priority level within a preset period, multiple sampling points may be selected within the preset period, and the current actual bandwidth may be calculated at each sampling point. The current actual bandwidth of each sampling point is calculated based on the timestamp and traffic volume corresponding to the priority level. Then, the current actual bandwidth corresponding to the multiple sampling points is averaged to determine the current actual bandwidth corresponding to the priority level within the preset period.Specifically, for any priority level, the cumulative size and timestamp of packets corresponding to that priority level may be constantly changing. A preset period is divided into multiple sampling points, each corresponding to a moment. For any sampling point, the cumulative size of packets at the moment corresponding to that sampling point can be determined based on the change in the cumulative size of packets at different timestamps. The current actual bandwidth corresponding to that sampling point can then be calculated based on the cumulative size of packets at the moment corresponding to that sampling point. Determining the current actual bandwidth for that priority level within the preset period based on the current actual bandwidth of multiple sampling points can reduce the probability of inaccurate current actual bandwidth measurement due to traffic jitter and improve the accuracy of current actual bandwidth measurement. In embodiments of the present disclosure, the current limited bandwidth can be adjusted based on pre-configured information and actually collected information to better meet actual requirements. For example, if the current actual bandwidth of each priority level determines that the current limited bandwidth is relatively idle, the current limited bandwidth of one or more priorities can be increased to maximize bandwidth utilization. Furthermore, the degree of increase can take into account the node's total limited bandwidth to avoid excessively high actual bandwidth after the increase, which could impact overall performance. If the current actual bandwidth of each priority level determines that the system is currently in a relatively busy state, the current bandwidth limit for one or more priorities can be lowered to reduce bandwidth contention. Optionally, the bandwidth collection module 201 and the bandwidth limitation module 202 are implemented using extended Berkeley Packet Filter (eBPF) technology. Specifically, the bandwidth collection module 201 and the bandwidth limitation module 202 can be programmed using extended Berkeley Packet Filter (eBPF) technology. Traditional rate limiting solutions rely on existing kernel modules in the kernel. Adjusting policies or adding new features requires modifying kernel modules, which is very inflexible. The present disclosure uses programmable eBPF to modify the execution logic in the Linux kernel, eliminating the need to replace kernel modules and ensuring real-time implementation. Optionally, the total limited bandwidth of the node and the limited bandwidth range corresponding to each priority are recorded in an eBPF data storage structure (eBPF map); the bandwidth collection module 201 is further used to: read the total limited bandwidth of the node and the limited bandwidth range corresponding to each priority from the eBPF data storage structure, and record the current actual bandwidth corresponding to each priority and the adjusted current limited bandwidth in the eBPF data storage structure; the bandwidth limiting module 202 is further used to: read the current actual bandwidth and current limited bandwidth corresponding to the target priority from the eBPF data storage structure.Specifically, the configuration module is further configured to record the received user-configured total node bandwidth limit and the bandwidth limit range corresponding to each priority level into the eBPF map. Specifically, the bandwidth collection module 201 collects the current actual bandwidth corresponding to each priority level, then sums the current actual bandwidth corresponding to each priority level, compares the summed result with the total node bandwidth limit, adjusts the current bandwidth limit corresponding to each priority level based on the comparison result, and records the adjusted current bandwidth limit and actual bandwidth corresponding to each priority level into the eBPF map. The bandwidth limiting module 202 reads the current bandwidth limit and actual bandwidth corresponding to each priority level from the eBPF map, and determines whether to pass the data packet based on the read current bandwidth limit and actual bandwidth corresponding to each priority level. Optionally, if each of the multiple network cards (NICs) is equipped with a bandwidth collection module 201, each of the multiple bandwidth collection modules 201 can calculate the current actual bandwidth of each priority level of the corresponding NIC at a preset period and write it into the eBPF map. The periodic recording method effectively reduces contention associated with reading and writing the eBPF map. For each priority level, the current actual bandwidths of the corresponding NICs collected by the bandwidth collection modules 201 are accumulated to obtain the current actual bandwidth corresponding to the priority level. The current actual bandwidths corresponding to each priority level are summed and compared with the node's total bandwidth limit. Based on the comparison result, the current bandwidth limit corresponding to each priority level is adjusted. The adjusted current bandwidth limit and the current actual bandwidth of each priority level are then recorded in the eBPF map. The bandwidth limiting module 202 reads the current bandwidth limit and the total actual bandwidth of each priority level from the eBPF map to determine whether to allow the packet to pass. In this way, using eBPF maps enables dynamic borrowing and returning of traffic from multiple network interfaces (NICs), improving overall node resource utilization and processing efficiency. Using eBPF maps as a configuration management portal allows for efficient and convenient rate limiting policies, with simplified configuration. In summary, the disclosed embodiments provide a bandwidth limiting system that addresses the inability of traditional bandwidth limiting solutions to support bandwidth contention and borrowing for multiple tasks in colocation scenarios. It supports any number of NICs on a node and offers the ability to dynamically adjust bandwidth limiting policies. It automatically allocates and adjusts bandwidth based on real-time task requirements and bandwidth resource availability, achieving better bandwidth utilization and task performance.Furthermore, the disclosed embodiments are particularly applicable to clusters with hybrid resource deployments in cloud-native scenarios. They seamlessly integrate with cloud-native technologies such as containerization and microservices. By interfacing with cloud platforms, they enable precise monitoring, allocation, and management of online and offline bandwidth, improving resource utilization and performance in cloud-native environments. They can support high bandwidths of up to 10G (Gigabit per Second, Gbps) and above, enabling stable control and management of high-speed data flows. The disclosed embodiments also provide a bandwidth limiting method. Figure 6 is a schematic flow chart of a bandwidth limiting method provided by the disclosed embodiments. As shown in Figure 6, the execution entity can be any node in a cluster, which is configured to process data packets of multiple priorities. The method includes: Step 601: collecting the current actual bandwidth corresponding to each of the multiple priorities, and adjusting the current limited bandwidth corresponding to each priority based on the current actual bandwidth corresponding to the multiple priorities, the pre-configured total limited bandwidth of the node, and the limited bandwidth range corresponding to each priority; Step 602: determining the target priority corresponding to the data packet to be sent, and determining whether to release the data packet based on the current actual bandwidth and the current limited bandwidth corresponding to the target priority, where the target priority is one of the multiple priorities. Optionally, Step 601 can be implemented by a bandwidth collection module, and Step 602 can be implemented by a bandwidth limiting module. Optionally, the bandwidth limiting method provided by the present disclosure further includes: obtaining the total limited bandwidth and the limited bandwidth range corresponding to each priority sent by the application program interface server. Optionally, the node is deployed with at least one container, which is used to process data packets. The bandwidth limiting method provided in the present disclosure further includes: obtaining a priority corresponding to each container; and determining a target priority corresponding to a data packet to be sent, including: determining the container corresponding to the data packet based on characteristic information of the data packet, wherein the target priority of the data packet is the priority of the corresponding container. Optionally, the node includes at least one network interface card (NIC); the bandwidth collection module and the bandwidth limiting module are configured to be mounted on the at least one NIC to collect bandwidth and limit bandwidth for data packets corresponding to the at least one NIC. Optionally, each NIC has an inbound queue and an outbound queue, wherein the inbound queue of any NIC includes data packets sent by the NIC to the container, and the outbound queue includes data packets sent by the container to the NIC. The bandwidth collection module is specifically configured to collect bandwidth for the inbound queue and the outbound queue, respectively; and the bandwidth limiting module is specifically configured to limit bandwidth for the inbound queue and the outbound queue, respectively.Optionally, the total restricted bandwidth of the node includes the total restricted bandwidth of the ingress and the total restricted bandwidth of the egress, and the restricted bandwidth range corresponding to each priority includes the restricted bandwidth range of the ingress and the restricted bandwidth range of the egress. Bandwidth collection and bandwidth restriction are performed on the ingress queue based on the total restricted bandwidth of the ingress and the restricted bandwidth range of each priority, and bandwidth collection and bandwidth restriction are performed on the egress queue based on the total restricted bandwidth of the egress and the restricted bandwidth range of each priority. Optionally, adjusting the current restricted bandwidth corresponding to each priority based on the current actual bandwidth corresponding to the multiple priorities, the pre-configured total restricted bandwidth of the node, and the restricted bandwidth range corresponding to each priority includes: if the sum of the current actual bandwidths corresponding to the multiple priorities is less than the total restricted bandwidth of the node, adjusting the current restricted bandwidth corresponding to at least some of the priorities upward; and / or, if the sum of the current actual bandwidths corresponding to the multiple priorities is greater than the total restricted bandwidth of the node, adjusting the current restricted bandwidth corresponding to at least some of the priorities downward; wherein the current restricted bandwidth of any priority before and after the adjustment is within the corresponding restricted bandwidth range. Optionally, the restricted bandwidth range includes a maximum restricted bandwidth and a minimum restricted bandwidth; upwardly adjusting the current restricted bandwidth corresponding to at least some priorities includes: subtracting the sum of the current actual bandwidths of the multiple priorities from the total restricted bandwidth of the node to obtain the free bandwidth; sequentially increasing the current restricted bandwidth corresponding to each priority in descending order of priority until the total increase reaches the free bandwidth; wherein, for at least some priorities that have been increased, the adjusted current restricted bandwidth of any priority other than the last adjusted priority is the corresponding maximum restricted bandwidth; correspondingly, downwardly adjusting the current restricted bandwidth corresponding to at least some priorities includes: subtracting the total restricted bandwidth of the node from the sum of the current actual bandwidths of the multiple priorities to obtain the contention bandwidth; and sequentially decreasing the current restricted bandwidth corresponding to each priority in descending order of priority until the total decrease reaches the contention bandwidth; wherein, for at least some priorities that have been decreased, the adjusted current restricted bandwidth of any priority other than the last adjusted priority is the corresponding minimum restricted bandwidth. Optionally, determining whether to release the data packet based on the current actual bandwidth and the current limited bandwidth corresponding to the target priority includes: if the current actual bandwidth corresponding to the target priority is less than the current limited bandwidth, releasing the data packet; if the current actual bandwidth corresponding to the target priority is not less than the current limited bandwidth, discarding the data packet.Optionally, collecting the current actual bandwidth corresponding to each of multiple priority levels includes: determining the priority corresponding to a data packet currently received or sent by the container within a preset period, and adding the size of the data packet to the traffic size of the corresponding priority level; and determining the current actual bandwidth of each priority level based on the traffic size of each priority level within the preset period. Optionally, the method further includes: updating the timestamp corresponding to the priority level to the timestamp corresponding to the data packet after adding the size of the data packet to the traffic size of the corresponding priority level; and determining the current actual bandwidth of each priority level based on the traffic size of each priority level within the preset period includes: for any priority level, calculating the bandwidth of each of multiple sampling points within the preset period based on the timestamp and traffic size corresponding to the priority level, and determining the current actual bandwidth of the priority level within the preset period based on the bandwidth of the multiple sampling points. Optionally, the method is implemented using extended Berkeley Packet Filter (eBPF) technology. Optionally, the total limited bandwidth of the node and the limited bandwidth range corresponding to each priority are recorded in an eBPF data storage structure. The method further includes: reading the total limited bandwidth of the node and the limited bandwidth range corresponding to each priority from the eBPF data storage structure, and recording the current actual bandwidth and adjusted current limited bandwidth corresponding to each priority in the eBPF data storage structure; and reading the current actual bandwidth and current limited bandwidth corresponding to the target priority from the eBPF data storage structure. The specific implementation principles and effects of the bandwidth limiting method provided in the embodiments of the present disclosure can be found in the technical solutions of the above embodiments and are not further described here. Figure 7 is a schematic structural diagram of an electronic device provided in an embodiment of the present disclosure. As shown in Figure 7, the electronic device of this embodiment may include: at least one processor 701; and a memory 702 communicatively connected to the at least one processor; wherein the memory 702 stores instructions executable by the at least one processor 701, wherein the instructions are executed by the at least one processor 701 to cause the electronic device to perform the method described in any of the above embodiments. Optionally, the memory 702 may be independent or integrated with the processor 701. The implementation principles and technical effects of the electronic device provided in this embodiment can be found in the aforementioned embodiments and will not be repeated here. This embodiment also provides a computer-readable storage medium storing computer-executable instructions. When a processor executes the computer-executable instructions, the method described in any of the aforementioned embodiments is implemented.The present disclosure also provides a computer program product, including a computer program. When executed by a processor, the computer program implements the method described in any of the aforementioned embodiments. In the several embodiments provided herein, it should be understood that the disclosed devices and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the module division described is merely a logical functional division. In actual implementation, other divisions may be used, such as combining or integrating multiple modules into another system, or omitting or not implementing certain features. The integrated modules implemented as software function modules can be stored in a computer-readable storage medium. The software function modules stored in a storage medium include instructions for causing a computer device (such as a personal computer, server, or network device) or a processor to perform some of the steps of the methods described in various embodiments of the present disclosure. It should be understood that the processor described above may be a central processing unit (CPU), or other general-purpose processor, a digital signal processor (DSP), an application-specific integrated circuit (ASIC), etc. The general-purpose processor may be a microprocessor or any conventional processor. The steps of the method disclosed in the application may be directly executed by a hardware processor or by a combination of hardware and software modules within the processor. The memory may include high-speed random access memory (RAM) or non-volatile memory (NVM), such as at least one disk storage device, or a USB flash drive. The storage medium may be a portable hard disk, read-only memory, magnetic disk, or optical disk. The above-mentioned storage medium may be implemented by any type of volatile or non-volatile storage device or a combination thereof, such as static random-access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The storage medium may be any available medium that can be accessed by a general-purpose or special-purpose computer. An exemplary storage medium is coupled to a processor so that the processor can read information from the storage medium and write information to the storage medium. Of course, the storage medium can also be a component of the processor. The processor and storage medium can be located in an application-specific integrated circuit (ASIC). Of course, the processor and storage medium can also exist as discrete components in an electronic device or a host control device. It should be noted that, in this document, the terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus comprising a series of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. Without further limitation, an element defined by the phrase "comprising a..." does not preclude the presence of other identical elements in the process, method, article, or apparatus comprising such element. The serial numbers of the above-mentioned embodiments of the present disclosure are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments. Through the above description of the embodiments, those skilled in the art will clearly understand that the above-mentioned embodiments and methods can be implemented using software plus the necessary general-purpose hardware platform, or hardware, although in many cases the former is a more preferred implementation.Based on this understanding, the technical solution of this disclosure, or the portion that contributes to the prior art, can be embodied in the form of a software product. This computer software product is stored in a storage medium (e.g., ROM / RAM, magnetic disk, or optical disk) and includes instructions for enabling a terminal device (such as a mobile phone, computer, server, air conditioner, or network device) to execute the methods described in the various embodiments of this disclosure. The above are merely preferred embodiments of this disclosure and are not intended to limit the scope of the patent. Any equivalent structures or equivalent processes derived from the disclosure and accompanying drawings, or any direct or indirect application in other related technical fields, are similarly encompassed within the scope of patent protection of this disclosure.

Claims

Claims 1. A bandwidth limiting system, wherein: Applied to any node in a cluster, the cluster is used to process data packets of multiple priorities; the system includes: a bandwidth acquisition module, used to acquire the current actual bandwidth corresponding to each priority among multiple priorities, and adjust the current restricted bandwidth corresponding to each priority according to the current actual bandwidth corresponding to the multiple priorities, the pre-configured total restricted bandwidth of the node and the restricted bandwidth range corresponding to each priority; a bandwidth restriction module, used to determine the target priority corresponding to the data packet to be sent, and determine whether to release the data packet according to the current actual bandwidth corresponding to the target priority and the current restricted bandwidth, wherein the target priority is one of the multiple priorities.

2. The system according to claim 1, wherein: The bandwidth limiting system further includes: a configuration module, which is used to obtain the total limited bandwidth and the limited bandwidth range corresponding to each priority level sent by the application program interface server.

3. The system according to claim 2, wherein: The node is deployed with at least one container, and the at least one container is used to process data packets; the configuration module is also used to: obtain the priority corresponding to each container; when the bandwidth limitation module determines the target priority corresponding to the data packet to be sent, it is specifically used to: determine the container corresponding to the data packet according to the characteristic information of the data packet, wherein the target priority of the data packet is the priority of the corresponding container.

4. The system according to any one of claims 1 to 3, wherein: The node further includes at least one network card; the bandwidth collection module and the bandwidth limitation module are used to be mounted to the at least one network card to perform bandwidth collection and bandwidth limitation on data packets corresponding to the at least one network card.

5. The system according to claim 4, wherein: The at least one network card corresponds to an in-queue and an out-queue, wherein the in-queue of any network card includes data packets sent by the network card to the container, and the out-queue includes data packets sent by the container to the network card; the bandwidth collection module is specifically used to collect bandwidth for the in-queue and the out-queue respectively; the bandwidth limitation module is specifically used to limit bandwidth for the in-queue and the out-queue respectively.

6. The system according to claim 5, wherein: The total restricted bandwidth of the node includes the total restricted bandwidth of the inlet and the total restricted bandwidth of the outlet, and the restricted bandwidth range corresponding to each priority includes the restricted bandwidth range of the inlet and the restricted bandwidth range of the outlet, so that bandwidth collection and bandwidth limitation are performed on the in-queue according to the total restricted bandwidth of the inlet and the restricted bandwidth range of the inlet of each priority, and bandwidth collection and bandwidth limitation are performed on the out-queue according to the total restricted bandwidth of the outlet and the restricted bandwidth range of the outlet of each priority.

7. The system according to any one of claims 1 to 6, wherein: The bandwidth acquisition module is specifically used to adjust the current limited bandwidth corresponding to each priority according to the current actual bandwidth corresponding to the multiple priorities, the pre-configured total limited bandwidth of the node and the limited bandwidth range corresponding to each priority: 22 If the sum of the current actual bandwidths corresponding to the multiple priorities is less than the total restricted bandwidth of the node, the current restricted bandwidths corresponding to at least some of the priorities are adjusted upward; and / or, if the sum of the current actual bandwidths corresponding to the multiple priorities is greater than the total restricted bandwidth of the node, the current restricted bandwidths corresponding to at least some of the priorities are adjusted downward; The current restricted bandwidth before and after adjustment of any priority level is within the corresponding restricted bandwidth range.

8. The system according to claim 7, wherein: The restricted bandwidth range includes a maximum restricted bandwidth and a minimum restricted bandwidth; when the bandwidth acquisition module upwardly adjusts the current restricted bandwidth corresponding to at least part of the priorities, it is specifically used to: subtract the sum of the current actual bandwidths of the multiple priorities from the total restricted bandwidth of the node to obtain the idle bandwidth; in descending order of priority, sequentially increase the current restricted bandwidth corresponding to each priority until the total increase reaches the idle bandwidth; Among them, among at least some of the priorities that have been adjusted upward, for any other priority except the last adjusted priority, the adjusted current restricted bandwidth is the corresponding highest restricted bandwidth; when the bandwidth acquisition module adjusts downward the current restricted bandwidth corresponding to at least some of the priorities, it is specifically used to: subtract the total restricted bandwidth of the node from the sum of the current actual bandwidths of multiple priorities to obtain the contention bandwidth; in order from low to high priority, the current restricted bandwidth corresponding to each priority is sequentially lowered until the total reduction reaches the contention bandwidth; Among at least some of the priorities that have been adjusted downward, for any other priority except the last adjusted priority, the adjusted current limited bandwidth is the corresponding lowest limited bandwidth.

9. The system according to any one of claims 1 to 8, wherein: When the bandwidth limitation module determines whether to release the data packet based on the current actual bandwidth and the current limited bandwidth corresponding to the target priority, it is specifically used to: if the current actual bandwidth corresponding to the target priority is less than the current limited bandwidth, release the data packet; if the current actual bandwidth corresponding to the target priority is not less than the current limited bandwidth, discard the data packet.

10. The system according to any one of claims 1 to 8, wherein: When collecting the current actual bandwidth corresponding to each priority among multiple priorities, the bandwidth collection module is specifically used to: determine the priority corresponding to the data packet currently received or sent by the container within a preset period, and add the size of the data packet to the flow size of the corresponding priority; determine the current actual bandwidth of each priority according to the flow size of each priority within the preset period.

11. The system according to claim 10, wherein: The bandwidth acquisition module is also used to: after adding the size of the data packet to the flow size of the corresponding priority, update the timestamp corresponding to the priority to the timestamp corresponding to the data packet; when the bandwidth acquisition module determines the current actual bandwidth of each priority according to the flow size of each priority within a preset period, it is specifically used to: for any priority, calculate the bandwidth size of each sampling point in the preset period according to the timestamp and flow size corresponding to the priority, and determine the bandwidth size of the priority in the preset period according to the bandwidth size of the multiple sampling points. The current actual bandwidth within the preset period.

12. The system according to any one of claims 1 to 11, wherein: The bandwidth collection module and the bandwidth limitation module are implemented by using the extended Berkeley packet filtering eBPF technology.

13. The system according to claim 12, wherein: The total restricted bandwidth of the node and the restricted bandwidth range corresponding to each priority are recorded in the data storage structure of the eBPF; the bandwidth acquisition module is also used to: read the total restricted bandwidth of the node and the restricted bandwidth range corresponding to each priority from the data storage structure of the eBPF, and record the current actual bandwidth corresponding to each priority and the adjusted current restricted bandwidth into the data storage structure of the eBPF; The bandwidth limiting module is further used to: read the current actual bandwidth and the current limited bandwidth corresponding to the target priority from the data storage structure of the eBPF.

14. A bandwidth limiting method, wherein: Applied to any node in a cluster, the cluster is used to process data packets of multiple priorities, and the method includes: collecting the current actual bandwidth corresponding to each priority among the multiple priorities, and adjusting the current restricted bandwidth corresponding to each priority according to the current actual bandwidth corresponding to the multiple priorities, the pre-configured total restricted bandwidth of the node and the restricted bandwidth range corresponding to each priority; determining the target priority corresponding to the data packet to be sent, and determining whether to release the data packet according to the current actual bandwidth and the current restricted bandwidth corresponding to the target priority, wherein the target priority is one of the multiple priorities.

15. An electronic device, wherein: include: at least one processor; and a memory communicatively connected to the at least one processor; wherein the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor so that the electronic device executes the method of claim 14.

16. A computer-readable storage medium, wherein: The computer-readable storage medium stores computer-executable instructions, and when the processor executes the computer-executable instructions, the method according to claim 14 is implemented.

17. A computer program product comprising a computer program, wherein: When the computer program is executed by a processor, the method according to claim 14 is implemented.

Citation Information

Patent Citations

  • Network resource dynamic self-adaption method and system based on network flow priority

    CN112367276A

  • Network QoS (Quality of Service) configuration method, equipment and a medium

    CN113709810A

  • Firewall management method and system based on eBPF

    CN113949537A

  • Data transmission method and device and computer storage medium

    CN114448569A

  • Node equipment of cloud service system and resource processing method

    CN115344350A