Traffic management method, service mesh system, apparatus, and cluster
By introducing a multi-tenant shared L7 proxy mechanism into the service grid system, the problems of low computing resource utilization and high scheduling pressure are solved, load balancing of L7 proxy and efficient utilization of resources are realized, and the system's computing resource utilization and traffic management are improved.
Patent Information
- Application Number
- PCT/CN2024/142165
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-03-06
- Filing Date
- 2024-12-25
- Publication Date
- 2025-07-03
AI Technical Summary
In the existing ambient mode service mesh system, each tenant exclusively occupies the application layer agent to cause low computing resource utilization, high pressure for computing resources to be idle and scheduling, and the tenant lacks professional knowledge to cause difficulties in maintaining L7 agents, and configuring redundant information storage is wasted memory resources.
By introducing a mechanism for multi-tenant sharing of L7 agents in the service grid system, L7 agents perform traffic management based on tenant identification service configuration information, optimize load balancing and resource utilization of L7 agents, reduce the number of L7 agents, and uniformly create and manage L7 agents to reduce computing resource requirements and memory redundancy.
It improves the computing resource utilization rate of L7 agents, reduces scheduling pressure, saves computing resources and memory resources, improves the timeliness of traffic management of new services, and ensures isolation between tenants and efficient utilization of resources.
Smart Images

Figure CN2024142165_03072025_PF_FP_ABST
Abstract
Description
Traffic management method, service grid system, device and cluster
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office of China on December 25, 2023, with application number 202311817785.7 and application name “A service grid system”, and the Chinese patent application filed with the State Intellectual Property Office of China on March 6, 2024, with application number 202410256865.8 and application name “Traffic management method, service grid system, device and cluster”, all contents of which are incorporated by reference into this application. Technical Field
[0002] The present application relates to the field of data processing technology, and in particular to a traffic management method, service grid system, device and cluster. Background Art
[0003] Currently, typical service mesh technologies use sidecars to manage traffic between services, including traffic routing, load balancing, and flow control. Sidecars are injected into container groups, and installing or upgrading them requires restarting the container group, which increases the workload of the node where the container group resides.
[0004] The industry has proposed an ambient service mesh technology. Ambient mode, also known as sidecarless mode, splits the sidecar functionality into transport-layer proxies and application-layer proxies. These proxies are isolated from the container group, thus avoiding the sidecar's drawback of increasing the workload of the node hosting the container group.
[0005] In the existing ambient model, each tenant has its own dedicated application-layer proxy, which manages traffic for only that tenant's services. Because each application-layer proxy occupies independent computing resources, significant amounts of computing resources inevitably remain idle during periods of low service availability, resulting in low resource utilization. Summary of the Invention
[0006] The embodiments of the present application provide a traffic management method, a service grid system, an apparatus, and a cluster, which can improve the computing resource utilization of the service grid system.
[0007] In a first aspect, a traffic management method is provided, which is applied to a service grid system, wherein the service grid system includes a first business node and a proxy cluster; wherein the first business node runs a first transport layer L4 proxy and a first business container group of a first tenant; the proxy cluster runs a first application layer L7 proxy, the first L7 proxy includes configuration information of multiple services, different services in the multiple services belong to the same tenant or different tenants, and the service configuration information is used by the first L7 proxy to perform traffic management on the service data packets; the method includes: the first L4 proxy receives a first data packet sent by the first business container group; the first L4 proxy sends the first tenant's identifier and the first data packet to the first L7 proxy; the first L7 proxy identifies the configuration information of the first service in the configuration information of multiple services based on the identifier of the first tenant, and the first service belongs to the first tenant; the first L7 proxy performs traffic management on the first data packet based on the configuration information of the first service.
[0008] Through the method provided in the first aspect, the same L7 proxy can include the configuration information of services for multiple tenants. When traffic management is required for data packets of a tenant's service, the L7 proxy obtains the tenant's identifier and, based on the tenant's identifier, obtains the configuration information of the tenant's service from the configuration information of services for multiple tenants. Traffic management can then be performed on data packets of the tenant's service based on the configuration information of the tenant's service. In this way, the same L7 proxy can perform traffic management on data packets of services for multiple tenants, enabling multi-tenant sharing of the L7 proxy. Multi-tenant sharing of the L7 proxy can improve the computing resource utilization of the L7 proxy and reduce the scheduling pressure of the L7 proxy, for the following reasons.
[0009] First, the idle phases of the services of different tenants are often not completely consistent. That is, the idle phases of different tenants are usually different. When the services of some tenants are in the idle phase, the services of other tenants may be in the busy phase. This can avoid the L7 agent from being idle and improve the computing resource utilization of the L7 agent.
[0010] Secondly, multiple tenants can share the L7 proxy, eliminating the need for each tenant to create an L7 proxy, reducing the number of L7 proxies in the service mesh system. This not only reduces the computing resources required to deploy L7 proxies in the service mesh system, but also reduces the scheduling pressure on L7 proxies.
[0011] Furthermore, the L7 proxy is shared by multiple tenants, eliminating the need to create L7 proxies at the tenant level. Service mesh system administrators can pre-create one or more L7 proxies in the proxy cluster. Whenever a new service is created, the service mesh system console can send the service's configuration information to the L7 proxy, enabling the L7 proxy to manage traffic for that service's data packets based on the service's configuration information. This improves the timeliness of traffic management for new services.
[0012] Furthermore, the L7 proxy is shared by multiple tenants, rather than being dedicated to any one tenant. This allows administrators to create L7 proxies centrally, controlling the redundancy of service configuration information. Specifically, whenever a new service is created, the service grid system's console can send the service's configuration information to N L7 proxies, where N is an integer greater than or equal to 1 and the size of N is configurable by the administrator. This prevents redundant storage of service configuration information in the L7 proxies, conserving L7 proxy memory resources.
[0013] In one possible implementation, the first service node also runs a second service container group of a second tenant; the method includes: a first L4 agent receives a second data packet sent by the second service container group; the first L4 agent sends the identifier of the second tenant and the second data packet to the first L7 agent; the first L7 agent identifies, based on the identifier of the second tenant, configuration information of the second service in configuration information of multiple services, and the second service belongs to the second tenant; the first L7 agent performs traffic management on the second data packet based on the configuration information of the second service.
[0014] In this implementation, the first L7 proxy can manage traffic for both the first tenant's service data packets and the second tenant's service data packets. In other words, the first tenant and the second tenant can share the first L7 proxy, thereby improving the first L7 proxy's computing resource utilization and reducing the L7 proxy's scheduling pressure.
[0015] In one possible implementation, the first service includes the service corresponding to the first data packet and other services; the first L7 agent performs traffic management on the first data packet based on the configuration information of the first service, including: the first L7 agent identifies the configuration information of the service corresponding to the first data packet in the configuration information of the first service based on the identifier of the service corresponding to the first data packet; the first L7 agent performs traffic management on the first data packet based on the configuration information of the service corresponding to the first data packet.
[0016] The first L7 proxy can perform traffic management on data packets of multiple services of the first tenant. When the first L7 proxy needs to perform traffic management on data packets of a certain service, it can identify the configuration information of the service from the configuration information of multiple services of the first tenant based on the identifier of the service, and then perform traffic management on the data packets of the service based on the configuration information of the service.
[0017] In one possible implementation, the proxy cluster runs multiple L7 proxies; the first L4 proxy sends the identifier of the first tenant and the first data packet to the first L7 proxy, including: the first L4 proxy identifies the L7 proxy including the configuration information of the first tenant's service from multiple L7 proxies based on the identifier of the first tenant; the first L4 proxy identifies the L7 proxy including the configuration information of the service corresponding to the first data packet from the L7 proxies including the configuration information of the service of the first tenant based on the identifier of the service corresponding to the first data packet, and obtains the first L7 proxy.
[0018] When the proxy cluster runs multiple L7 proxies, the L4 proxy can identify the L7 proxy that includes the configuration information of the first tenant's service from the multiple L7 proxies based on the tenant's identifier, so that the data packets of the first tenant's service can be sent to the L7 proxy that includes the configuration information of the first tenant's service, and then the traffic management of the data packets of the first tenant's service can be performed through the L7 proxy.
[0019] In one possible implementation, the proxy cluster also runs a second L7 proxy, which includes configuration information of at least one service; the first L4 proxy sends the identifier of the first tenant and the first data packet to the first L7 proxy, including: when the number of services belonging to the first tenant in multiple services is greater than the number of services belonging to the first tenant in at least one service, the first L4 proxy sends the identifier of the first tenant and the first data packet to the first L7 proxy.
[0020] For ease of description, an L7 proxy that includes service configuration information is referred to as an L7 proxy that supports that service. An L7 proxy that supports a large number of services of the first tenant is preferably selected to perform traffic management on data packets of the first tenant's services. This can reduce data transmission between the first tenant's service container groups for the following reasons.
[0021] Two or more services of the same tenant may be executed sequentially, that is, the output of one service is the input of the next service. When the L7 agent performs traffic management on data packets of two or more services of the same tenant, the two or more services share a routing cache. Among them, the routing cache saves the addresses of the target service instances (that is, one or some specific business container groups) of two or more services. When two or more services can be provided by the same business container group, by sharing the address of the routing cache, the L7 agent can send the data packets of the two or more services to the same target service instance, thereby scheduling the data packets of the two or more services into the same business container group. In this way, the processing of the data packets of the two or more services can be completed in the same business container group, saving data transmission between business container groups.
[0022] An L7 proxy that supports more services of the first tenant is more likely to support two or more services executed sequentially within the first tenant, and the services requiring traffic management are likely to belong to two or more services. Therefore, an L7 proxy that supports more services of the first tenant is preferably selected to perform traffic management on data packets of the first tenant's services. This increases the probability that data packets of two or more services of the first tenant will be processed by the same service container group, thereby reducing data transmission between service container groups.
[0023] In one possible implementation, the proxy cluster also runs a second L7 proxy, which also includes configuration information of the first service; the first L4 proxy sends the first tenant's identifier and the first data packet to the first L7 proxy, including: when the load of the second L7 proxy is greater than the load of the first L7 proxy, the first L4 proxy sends the first tenant's identifier and the first data packet to the first L7 proxy.
[0024] In this implementation, L7 proxies with light loads are preferentially selected to perform traffic management on services that currently require traffic management, thereby ensuring load balancing among multiple L7 proxies and improving the overall resource utilization of multiple L7 proxies.
[0025] In one possible implementation, the service grid system further includes: a console connected to the proxy cluster; the method further includes: the console sending configuration information of two or more services to the same L7 proxy in the proxy cluster; wherein the two or more services belong to the same tenant, or the output of one of the two or more services is the input of another service.
[0026] The configuration information of two or more services that need to be executed sequentially is sent to the same L7 agent, so that the same L7 agent can be used to support traffic management of the data packets of the two or more services, so that the data packets of the two or more services can be scheduled to the same service container group, and the data packets of the two or more services are processed by the same service container group, thereby saving data transmission between service container groups.
[0027] In a possible implementation, the proxy cluster runs multiple L7 proxies; wherein, among the multiple L7 proxies, the same L7 proxy includes configuration information of a minimum number of services, or the same L7 proxy includes configuration information of a minimum number of tenants.
[0028] In this implementation, when selecting an L7 proxy to support a newly created service, preference is given to L7 proxies that support fewer services. This ensures load balancing across multiple L7 proxies. Alternatively, when selecting an L7 proxy to support a newly created service, preference is given to L7 proxies that support fewer tenants. This prevents the same L7 proxy from serving as an affinity L7 proxy for multiple tenants simultaneously, thus preventing excessive load on the L7 proxy.
[0029] In one possible implementation, the service grid system further includes a second service node, which runs a second L4 agent and a third service container group. The first L7 agent performs traffic management on the first data packet based on configuration information of the first service, including: the first L7 agent selects the third service container group as the target container group for the first data packet; the first L7 agent sends the first data packet and an identifier of the first tenant to the second L4 agent; the method further includes: the second L4 agent confirms, based on the identifier of the first tenant, that the first tenant and the tenant to which the third service container group belongs are the same tenant; and the second L4 agent sends the first data packet to the third service container group.
[0030] In this implementation, the outbound L4 proxy of the service mesh only sends a packet to the target service container group after confirming that the tenant to which the packet belongs is the same tenant. This ensures isolation between tenants.
[0031] In a second aspect, a service grid system is provided, which includes a first business node and an agent cluster; wherein the first business node runs a first L4 agent and a first business container group of a first tenant; the agent cluster runs a first L7 agent, and the first L7 agent includes configuration information of multiple services, different services in the multiple services belong to the same tenant or different tenants, and the configuration information of the service is used by the first L7 agent to perform traffic management on the data packets of the service; wherein the first L4 agent is used to: receive a first data packet sent by the first business container group; the first L4 agent is used to: send the identifier of the first tenant and the first data packet to the first L7 agent; the first L7 agent is used to: identify the configuration information of the first service in the configuration information of multiple services based on the identifier of the first tenant, and the first service belongs to the first tenant; the first L7 agent is used to: perform traffic management on the first data packet based on the configuration information of the first service.
[0032] In one possible implementation, the first service node also runs a second service container group of a second tenant; the first L4 agent is further used to: receive a second data packet sent by the second service container group; the first L4 agent is further used to: send the second tenant's identifier and the second data packet to the first L7 agent; the first L7 agent is further used to: based on the identifier of the second tenant, identify the configuration information of the second service in the configuration information of multiple services, and the second service belongs to the second tenant; the first L7 agent is further used to: perform traffic management on the second data packet based on the configuration information of the second service.
[0033] In one possible implementation, the first service includes a service corresponding to the first data packet and other services; the first L7 agent is used to: identify the configuration information of the service corresponding to the first data packet in the configuration information of the first service based on the identifier of the service corresponding to the first data packet; and perform traffic management on the first data packet based on the configuration information of the service corresponding to the first data packet.
[0034] In one possible implementation, the proxy cluster also runs a second L7 proxy, which includes configuration information of at least one service; the first L4 proxy is used to: when the number of services belonging to the first tenant in multiple services is greater than the number of services belonging to the first tenant in at least one service, send the first tenant's identifier and the first data packet to the first L7 proxy.
[0035] In one possible implementation, the proxy cluster also runs a second L7 proxy, which also includes configuration information of the first service; the first L4 proxy is used to: when the load of the second L7 proxy is greater than the load of the first L7 proxy, send the first tenant's identifier and the first data packet to the first L7 proxy.
[0036] In one possible implementation, the service grid system further includes: a console connected to the proxy cluster; the console is used to: send configuration information of two or more services to the same L7 proxy in the proxy cluster; wherein the two or more services belong to the same tenant, or the output of one of the two or more services is the input of another service.
[0037] In one possible implementation, the service grid system further includes a second service node, which runs a second L4 agent and a third service container group. The first L7 agent is configured to select the third service container group as a target container group for the first data packet, send the first data packet and an identifier of the first tenant to the second L4 agent, and confirm, based on the identifier of the first tenant, that the first tenant and the tenant to which the third service container group belongs are the same tenant, and send the first data packet to the third service container group.
[0038] In a third aspect, a traffic management method is provided, which is applied to a first L7 agent in a service grid system, the service grid system including a first business node and an agent cluster; wherein the first business node runs a first L4 agent and a first business container group of a first tenant; the first L7 agent runs in the agent cluster, the first L7 agent includes configuration information of multiple services, different services in the multiple services belong to the same tenant or different tenants, and the service configuration information is used by the first L7 agent to perform traffic management on the service data packets; the method includes: the first L7 agent receives the first tenant's identifier and a first data packet sent by the first L4 agent, the first data packet is received by the first L4 agent from the first business container group; the first L7 agent identifies the configuration information of the first service in the configuration information of multiple services based on the identifier of the first tenant, and the first service belongs to the first tenant; the first L7 agent performs traffic management on the first data packet based on the configuration information of the first service.
[0039] In one possible implementation, the first service node also runs a second service container group of a second tenant; the method includes: a first L7 agent receives an identifier of the second tenant and a second data packet sent by a first L4 agent, where the second data packet is received by the first L4 agent from the second service container group; the first L4 agent sends the identifier of the second tenant and the second data packet to the first L7 agent; the first L7 agent identifies, based on the identifier of the second tenant, configuration information of the second service in configuration information of multiple services, where the second service belongs to the second tenant; and the first L7 agent performs traffic management on the second data packet based on the configuration information of the second service.
[0040] In one possible implementation, the first service includes the service corresponding to the first data packet and other services; the first L7 agent performs traffic management on the first data packet based on the configuration information of the first service, including: the first L7 agent identifies the configuration information of the service corresponding to the first data packet in the configuration information of the first service based on the identifier of the service corresponding to the first data packet; the first L7 agent performs traffic management on the first data packet based on the configuration information of the service corresponding to the first data packet.
[0041] In one possible implementation, the proxy cluster also runs a second L7 proxy, which includes configuration information of at least one service; the first L7 proxy receives the identifier and the first data packet of the first tenant sent by the first L4 proxy, including: when the number of services belonging to the first tenant in multiple services is greater than the number of services belonging to the first tenant in at least one service, the first L7 proxy receives the identifier and the first data packet of the first tenant sent by the first L4 proxy.
[0042] In one possible implementation, the proxy cluster also runs a second L7 proxy, which also includes configuration information of the first service; the first L7 proxy receives the identifier of the first tenant and the first data packet sent by the first L4 proxy, including: when the load of the second L7 proxy is greater than the load of the first L7 proxy, the first L7 proxy receives the identifier of the first tenant and the first data packet sent by the first L4 proxy.
[0043] In one possible implementation, the service grid system further includes: a console connected to the proxy cluster; the method further includes: a first L7 proxy receiving and recording configuration information of two or more services from the console; wherein the two or more services belong to the same tenant, or the output of one of the two or more services is the input of another service.
[0044] In one possible implementation, the service grid system further includes a second service node, which runs a second L4 agent and a third service container group. The first L7 agent performs traffic management on the first data packet based on the configuration information of the first service, including: the first L7 agent selects the third service container group as the target container group for the first data packet; the first L7 agent sends the first data packet and an identifier of the first tenant to the second L4 agent; wherein the second L4 agent is configured to: confirm, based on the identifier of the first tenant, that the first tenant and the tenant to which the third service container group belongs are the same tenant; and send the first data packet to the third service container group.
[0045] In a fourth aspect, a traffic management device is provided, which is configured in a first L7 agent in a service grid system, and the service grid system includes a first business node and an agent cluster; wherein the first business node runs a first L4 agent and a first business container group of a first tenant; the first L7 agent runs in the agent cluster, and the first L7 agent includes configuration information of multiple services, different services in the multiple services belong to the same tenant or different tenants, and the configuration information of the service is used by the first L7 agent to perform traffic management on the data packets of the service; the device includes: a receiving module, for receiving an identifier of the first tenant and a first data packet sent by the first L4 agent, the first data packet is received by the first L4 agent from the first business container group; an identification module, for identifying the configuration information of the first service in the configuration information of multiple services based on the identifier of the first tenant, and the first service belongs to the first tenant; a management module, for performing traffic management on the first data packet based on the configuration information of the first service.
[0046] In one possible implementation, the first service node also runs a second service container group of a second tenant; the receiving module is further used to: receive the identifier of the second tenant and a second data packet sent by the first L4 agent, where the second data packet is received by the first L4 agent from the second service container group; the identification module is further used to: based on the identifier of the second tenant, identify configuration information of the second service in configuration information of multiple services, where the second service belongs to the second tenant; and the management module is further used to: perform traffic management on the second data packet based on the configuration information of the second service.
[0047] In one possible implementation, the first service includes the service corresponding to the first data packet and other services; the management module is used to: identify the configuration information of the service corresponding to the first data packet in the configuration information of the first service based on the identifier of the service corresponding to the first data packet; and perform traffic management on the first data packet based on the configuration information of the service corresponding to the first data packet.
[0048] In one possible implementation, the proxy cluster also runs a second L7 proxy, which includes configuration information of at least one service; the receiving module is used to: when the number of services belonging to the first tenant in multiple services is greater than the number of services belonging to the first tenant in at least one service, receive the first tenant's identifier and the first data packet sent by the first L4 proxy.
[0049] In one possible implementation, the proxy cluster also runs a second L7 proxy, which also includes configuration information of the first service; the receiving module is used to: when the load of the second L7 proxy is greater than the load of the first L7 proxy, receive the first tenant's identifier and the first data packet sent by the first L4 proxy.
[0050] In one possible implementation, the service grid system further includes: a console connected to the proxy cluster; a receiving module configured to receive and record configuration information of two or more services from the console; wherein the two or more services belong to the same tenant, or the output of one of the two or more services is the input of another service.
[0051] In one possible implementation, the service grid system further includes a second service node, which runs a second L4 agent and a third service container group. The management module is configured to: cause the first L7 agent to select the third service container group as the target container group for the first data packet; the first L7 agent to send the first data packet and an identifier of the first tenant to the second L4 agent; wherein the second L4 agent is configured to: confirm, based on the identifier of the first tenant, that the first tenant and the tenant to which the third service container group belongs are the same tenant; and send the first data packet to the third service container group.
[0052] In a fifth aspect, a computing device cluster is provided, comprising at least one computing device, each computing device comprising a processor and a memory; the processor of at least one computing device is used to execute instructions stored in the memory of at least one computing device, so that the computing device cluster executes the method provided in the second aspect.
[0053] In a sixth aspect, a computer-readable storage medium is provided, comprising computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method provided in the second aspect.
[0054] In a seventh aspect, a computer program product comprising instructions is provided. When the instructions are executed by a computer device cluster, the computer device cluster executes the method provided in the second aspect.
[0055] The beneficial effects of the second to seventh aspects can be referred to the above description of the beneficial effects of the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0056] FIG1 is a schematic diagram of the structure of a service grid system provided in an embodiment of the present application;
[0057] FIG2 is a schematic diagram of the structure of an L7 proxy provided in an embodiment of the present application;
[0058] FIG3 is a schematic diagram of a service configuration method provided in an embodiment of the present application;
[0059] FIG4 is a schematic diagram of a service configuration method provided in an embodiment of the present application;
[0060] FIG5 is a flow chart of a service configuration method provided in an embodiment of the present application;
[0061] FIG6 is a flow chart of a traffic management method provided in an embodiment of the present application;
[0062] FIG7 is a flow chart of a traffic management method provided in an embodiment of the present application;
[0063] FIG8 is a schematic structural diagram of a flow management device provided in an embodiment of the present application;
[0064] FIG9 is a schematic diagram of the structure of a computing device provided in an embodiment of the present application;
[0065] FIG10 is a schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application;
[0066] FIG11 is a schematic diagram of a structure of a computing device cluster connected via a network provided in an embodiment of the present application. DETAILED DESCRIPTION
[0067] The following describes the solutions provided by the embodiments of the present application in conjunction with the accompanying drawings. In the embodiments of the present application, "plurality" refers to two or more. "First," "second," and the like are merely used to distinguish similar objects and are not necessarily used to describe a specific order or number of objects.
[0068] To facilitate understanding of the solutions provided by the embodiments of the present application, the technical terms that may be involved in the embodiments of the present application are first introduced.
[0069] Microservice architecture (microservice architecture): A service-oriented architecture (SOA) that divides complex systems into multiple small services or applications. These small services or applications are called microservices. Each microservice is responsible for implementing an independent business logic. Microservices are built around business functions and can be deployed independently. Microservices are interdependent and can provide a range of functions. Microservices are easy to understand and modify, which brings flexibility in language and framework selection. Microservices can run in containers. Among them, multiple containers containing microservices with high interdependence can form a container group. Among them, in the K8S (Kubernetes) system, the container group can be encapsulated into a pod.
[0070] Business container: refers to the container that runs microservices.
[0071] Business container group: A container group consisting of multiple business container groups. Typically, the microservices running in the business containers in the same container group have high dependencies.
[0072] Service mesh: A service mesh is a technology that manages services (such as microservices) provided by business containers through a data proxy outside the business container. Specifically, the data proxy obtains data packets sent by the business container and performs service management (such as traffic management) on the data packets to send the data packets to the data proxy of the target container group. The data proxy of the target container group sends the data packets to the target container group. Among them, the behavior of the data proxy obtaining the data packets sent by the container group can be called entering the service mesh, and the behavior of the data proxy sending the data packets to the target container group is called exiting the service mesh.
[0073] Service governance, also known as SOA governance, is a general term for the methods used to ensure the normal operation of each microservice instance in a microservices architecture and the normal communication between different microservice instances. Microservice instances can also be called service instances or business container instances.
[0074] Traffic management: Also known as traffic service governance, it is a type of service governance. Traffic management typically includes traffic routing, load balancing, flow control, and flow observation.
[0075] Service configuration information: This information is used by the data proxy to manage the traffic of service data packets. Service data packets are data packets sent to service instances of that service. Service configuration information may include the number of service instances, the addresses of the service instances, and the maximum processing capacity of the service instances. For example, the maximum processing capacity of a service instance may be the service instance's throughput.
[0076] Data agent: Also known as a data plane agent, it is a module or device used to perform service governance on the data plane for service instances. A data agent can be a process, where the data agent process can run in a container. In sidecar mode, the data agent is the sidecar. In ambient mode, data agents include transport layer agents and application layer agents. In the open system interconnection (OSI) network model, the transport layer is layer 4 (L4) and the application layer is layer 7 (L7). Therefore, the transport layer agent can also be called an L4 agent, and the application layer agent can also be called an L7 agent. Among them, the L4 agent is used to implement low-level traffic management, such as routing data packets based on the transmission control protocol (TCP). The L7 agent is used to implement high-level traffic management, such as routing data packets based on the service metadata information (such as service name, version, etc.) in the data packet. The functions of the L4 agent and L7 agent will be described in detail below and will not be repeated here.
[0077] Node: used to run a business container group and / or a data agent. Typical nodes include virtual machines (VMs), computers (e.g., servers), bare metal servers, etc. Among them, the node used to run a business container group can be called a business node, wherein, in the embodiment of the present application, the L4 agent also runs in the business node. The node used to run the L7 agent can be called an agent node. One or more business nodes can form a business cluster, and one or more agent nodes can form an agent cluster. The agent cluster can also be called a hosting cluster or an agent hosting cluster.
[0078] In the related art, in order to achieve isolation between different tenants, each tenant has an exclusive L7 agent. Specifically, the tenant is responsible for creating and maintaining the tenant's L7 agent, and the tenant's L7 agent only performs traffic management on data packets sent by the tenant's business container group. There are a large number of tenants in the service grid system, and each tenant may create multiple L7 agents, which means that there are a large number of L7 agents in the service grid system. Among them, each L7 agent runs in a separate container, and a large number of agents require a large number of containers. Each container has exclusive fixed computing resources, such as a central processing unit (CPU), memory resources, etc. Typically, a tenant's business has a busy phase and an idle phase. In the idle phase of the tenant's business, the tenant's L7 agent is idle, resulting in low computing resource utilization.
[0079] Moreover, the scheduling pressure of a large number of L7 agents is high. For example, a lot of work is required to select nodes for deploying L7 agents.
[0080] Furthermore, because L7 proxies are tenant-specific, and different tenants may have different numbers of services, they may also require different numbers of L7 proxies. Therefore, it's difficult for service mesh system administrators to uniformly create and maintain L7 proxies, requiring tenants to do so themselves. This increases their workload. Furthermore, tenants often lack the expertise to professionally maintain L7 proxies, leading to a higher risk of L7 proxy failures. For example, when upgrading L7 proxies, due to tenants' lack of expertise, there is a significant risk of identification issues.
[0081] Furthermore, tenants often create multiple L7 proxies, exceeding their business needs and wasting computing resources. Furthermore, in related art, whenever a console detects the creation of an L7 proxy, it sends the configuration information for all services belonging to the tenant to that L7 proxy. This means that each L7 proxy for a tenant stores the configuration information for all of its services. This results in highly redundant storage of service configuration information within the L7 proxy, consuming significant memory resources.
[0082] Referring to Figure 1, an embodiment of the present application provides a service grid system, which includes one or more business nodes and an agent cluster. The business node is used to run a business container group and an L4 agent, and the agent cluster is used to run an L7 agent. The L7 agent may include configuration information of multiple services. Different services among the multiple services may belong to different tenants, that is, the same L7 agent may include configuration information of services of different tenants. The configuration information of the service is used by the L7 agent to perform traffic management on the data packets of the service, that is, the same L7 agent can perform traffic management on the data packets of services of different tenants, that is, multiple tenants can share the L7 agent. When a business container group of a tenant sends a data packet, the L4 agent can send the data packet and the identifier of the tenant to the L7 agent. The L7 agent can identify the configuration information of the tenant's service from the configuration information of multiple services based on the tenant's identifier, and then can perform traffic management on the data packet based on the configuration information of the tenant's service.
[0083] In the service grid system provided in the embodiments of the present application, multiple tenants share the L7 proxy, improving the utilization of the L7 proxy's computing resources. Specifically, the idle phases of services of different tenants are usually different. When the services of some tenants are idle, the services of other tenants may be busy. This can prevent the L7 proxy from being idle, thereby improving the utilization of the L7 proxy's computing resources.
[0084] Furthermore, multiple tenants can share the L7 proxy, eliminating the need for each tenant to create an L7 proxy, thus reducing the number of L7 proxies in the service mesh system. This not only reduces the computing resources required to deploy L7 proxies in the service mesh system, but also reduces the scheduling pressure on the L7 proxies.
[0085] Furthermore, the L7 proxy is shared by multiple tenants, eliminating the need to create L7 proxies at the tenant level. Service mesh system administrators can pre-create one or more L7 proxies in the proxy cluster. Whenever a new service is created, the service mesh system console can send the service's configuration information to the L7 proxy, allowing the L7 proxy to manage the service's data packets based on the service's configuration information.
[0086] Furthermore, L7 proxies are centrally created by administrators, allowing for control over the redundancy of service configuration information. Specifically, whenever a new service is created, the service grid system's console can send the service's configuration information to N L7 proxies, where N is an integer greater than or equal to 1 and the size of N is configurable by the administrator. This prevents redundant storage of service configuration information within the L7 proxies, conserving L7 proxy memory resources.
[0087] Next, the service grid system provided in the embodiment of the present application is introduced in detail.
[0088] As shown in Figure 1, the service grid system includes multiple service nodes, such as service node 100 and service node 200. A service node can be deployed with multiple service container groups and at least one L4 agent. For example, service node 100 is deployed with service container group 110, service container group 120, and L4 agent 130. For another example, service node 200 is deployed with service container group 210, service container group 220, and L4 agent 230. Different service container groups within the same service node can belong to different tenants or the same tenant. The same tenant can deploy service container groups in different service nodes. For example, service container group 110 and service container group 210 belong to tenant A1, while service container group 120 and service container group 220 belong to tenant A2. The L4 agent is node-level, meaning that the L4 agent can manage data packets sent by multiple service container groups within the service node where the L4 agent is located. For example, an L7 agent is selected for data packets sent by a service container group, and a connection (e.g., a TCP connection) is established between the L4 agent and the selected L7 agent.
[0089] The service grid system includes a proxy cluster 300. Proxy cluster 300 is composed of at least one proxy node. Proxy cluster 300 may be deployed with one or more L7 proxies, such as L7 proxy 310 and / or L7 proxy 320. An L7 proxy may run on one or more proxy nodes in proxy cluster 300. Furthermore, a proxy node may run one or more L7 proxies.
[0090] The L7 proxy can include configuration information for multiple services and, based on this service configuration information, can perform traffic management on data packets for those services. Different services within these multiple services can belong to the same tenant or different tenants. That is, different services within these multiple services can be provided by the same tenant's service container group or by different tenants' service container groups. In other words, the L7 proxy no longer manages traffic at a tenant granularity, but rather at a service granularity.
[0091] In some embodiments, as shown in FIG2 , the L4 agent 130 includes an interception module 131, an acquisition module 132, and a sending module 133. The interception module 131 can intercept data packets sent by a service container group in the service node 100, allowing the data packets sent by the service container group to enter the service grid. For example, the service container group 110 sends a data packet 111, and the interception module 131 intercepts the data packet 111. The acquisition module 132 can parse the data packet 111 to obtain the identifier of the service container group 110. Exemplarily, the identifier of the container group can be the Internet Protocol (IP) address of the container group. The acquisition module 132 can parse the data packet 111 to obtain the source IP address (SrcIP), thereby obtaining the IP address of the service container group 110. Based on the identifier of the service container group 110, the acquisition module 132 can then obtain the identifier of the tenant to which the service container group 110 belongs from the grid console 400 of the service grid system.
[0092] The grid console, also known as the grid control plane or console, is used to control the L7 proxy, L4 proxy, etc. in the service grid system, and to provide administrators of the service grid system with an interface (such as an application programming interface (API)) for managing the service grid system.
[0093] The sending module 133 in the L4 agent 130 may send the data packet 111 and the tenant's identifier to the L7 agent 310 .
[0094] In some embodiments, as shown in FIG2 , L7 agent 310 includes one or more listeners, such as listener 311 and listener 312. In one example, data packet 111 may include a service identifier for the service requested by data packet 111. In one example, the service identifier may be a service IP (Svc IP). Different listeners in L7 agent 310 correspond to different services, and a listener is configured to listen for data packets for the service corresponding to the listener. A listener may detect the service identifier in a data packet sent to L7 agent 310. If the service represented by the service identifier corresponds to the service corresponding to the listener, the listener receives the data packet.
[0095] In some embodiments, as shown in FIG2 , the L7 agent 310 includes multiple tenant listeners. Different tenant listeners among the multiple tenant listeners are configured to listen to and receive data packets from services of different tenants. For example, the listener for tenant A1 is configured to listen to and receive data packets from the services of tenant A1 (e.g., data packet 111 ), and the listener for tenant A2 is configured to listen to and receive data packets from the services of tenant A2 (e.g., data packet 121 ).
[0096] L7 proxy 310 includes multiple tenant service listeners. A tenant service listener is used to listen for and receive calls to a tenant's service. Because services from different tenants may share the same service ID, the L7 proxy uses the service ID in conjunction with the tenant's ID to identify the service. In other words, a service's unique ID consists of the service ID and the tenant's ID. For example, the unique ID of tenant A1's service 1 consists of the service ID and tenant A1's ID, while the unique ID of tenant A2's service 2 consists of the service ID and tenant A2's ID.
[0097] Continuing with FIG2 , L7 proxy 310 includes a traffic management module 313. After receiving data packet 111, traffic management module 313 can obtain the configuration information of tenant A1's service from the stored configuration information of multiple services. Then, based on the configuration information of tenant A1's service, it can perform traffic management on data packet 111. For example, based on the service instance load balancing (LB) policy, it can select a target service instance for data packet 111 and send data packet 111 to the selected target service instance.
[0098] In some embodiments, L7 agent 310 also includes an observation module 314. Observation module 314 is configured to observe and collect statistics on the path and time taken to send data packets to a service instance. Based on the observed information, observation module 314 generates an observation report and submits it to the service grid system's observation center.
[0099] The above article briefly introduces the functions of L7 proxy. Next, we will introduce how to deploy L7 proxy.
[0100] In the embodiments of the present application, the L7 proxies deployed in proxy cluster 300 are created by the administrator of the service grid system. In some embodiments, before the service grid system is officially put into use, the administrator of the service grid system can create one or more L7 proxies in proxy cluster 300. For example, the administrator of the service grid system can create a corresponding number of L7 proxies based on the capacity of the service grid system. The capacity of the service grid system refers to the maximum number of service container groups that can be deployed in the service grid system.
[0101] Referring to Figure 3 , whenever a tenant service is created, grid console 400 can send the service's configuration information, service identifier, and A1's identifier to one or more L7 proxies, enabling the L7 proxies to manage traffic for the service's data packets based on the service configuration information. In some embodiments, as shown in Figure 3 , when a service for tenant A1 is created in a service node, the service node can execute step 301 to send the service's configuration information, service identifier, and tenant A1's identifier to grid console 400. Grid console 400 can then execute step 302 to select an L7 proxy for the service.
[0102] After selecting the L7 agent, the grid console 400 executes step 303a to send the service configuration information, service identifier, and tenant A1 identifier to the selected L7 agent. Upon receiving the service configuration information, service identifier, and tenant A1 identifier, the L7 agent can associate the service configuration information, service identifier, and tenant A1 identifier to obtain an association relationship among the service configuration information, service identifier, and tenant A1 identifier. For example, the service configuration information, service identifier, and tenant A1 identifier are recorded in the association list. In this way, the configuration information of the service of tenant A1 can be obtained through the identifier of tenant A1, and the configuration information of the service of tenant A1 can be obtained through the identifier of tenant A1 and the identifier of the service.
[0103] The grid console also performs step 303b to send the association relationship between the selected L7 agent and tenant A1 to the L4 agent in each business node in the service grid system, so that the L4 agent can identify the L7 agent including the configuration information of the tenant A1 service based on the association relationship.
[0104] A service container group can include multiple containers. Each container, as a service instance, can provide a service. The services provided by containers in the same service container group are closely related. For example, the output of a service provided by one container often serves as the input for a service provided by another container. Containers in the same container group share storage space, which can be memory or cache. Thus, if data packets for two or more services that need to be executed sequentially are scheduled to the same service container group, the containers in the same service container group process the data packets for these two or more services, eliminating the need to transfer related data between container groups. For example, containers B11 and B12 in service container group B1 provide services C1 and C2, respectively. Containers B21 and B22 in service container group B2 also provide services C1 and C2, respectively. The output of service C1 serves as the input for service C2. Data packets for service C1 and service C2 require sequential processing. If data packets for both services are scheduled to service container group B1, the result of container B11 processing the data packet for service C1 (i.e., the output of service C1) can be stored in the storage space shared by containers B11 and B12. When processing data packets from service C2, container B12 can retrieve the output of service C1 from this storage space, thus saving data transmission between service container groups. If data packets from service C1 are dispatched to service container group B1, and data packets from service C2 are dispatched to service container group B2, service container group B2 needs to retrieve the output of service C1 from service container group B1 when processing data packets from service C2. This requires data transmission between the service container groups.
[0105] 4 , in step 302 , the grid console 400 selects an L7 agent based on the affinity between services, so as to send configuration information of multiple services with affinity to the same L7 agent.
[0106] In some embodiments, there is affinity between the services of the same tenant, so the configuration information of the services of the same tenant can be sent to the same L7 agent. When the L7 agent performs traffic management on data packets of two or more services of the same tenant, the data packets of the two or more services share a routing cache. The routing cache stores the address of the target service instance (i.e., one or some specific business container groups) of the data packet. When the two or more services can be provided by the same business container group, the L7 agent can send the data packets of the two or more services to the same target service instance by sharing the address of the routing cache, thereby scheduling the data packets of the two or more services into the same business container group. The two or more services can be two or more services that need to be executed sequentially, so that data transmission between business container groups can be saved.
[0107] In some embodiments, there is affinity between two or more services that need to be executed sequentially. Therefore, the configuration information of the two or more services that need to be executed sequentially can be sent to the same L7 agent. When the L7 agent performs traffic management on the data packets of the two or more services, the two or more services share a routing cache. The routing cache stores the address of the target service instance of the data packet. When the two or more services are provided by the same business container group, the L7 agent can send the data packets of the two or more services to the same target service instance by sharing the address of the routing cache, thereby scheduling the data packets of the two or more services into the same business container group. In this way, data transmission between business container groups can be saved.
[0108] Affinity services refer to services belonging to the same tenant or services that require sequential execution. Services that require sequential execution also belong to the same tenant. Therefore, affinity services are tenant-specific. An L7 proxy that includes configuration information for services with affinity for a particular tenant is called an affinity L7 proxy for that tenant.
[0109] In some embodiments, the proxy cluster 300 runs multiple L7 proxies. In step 302, an L7 proxy that includes configuration information for the fewest number of services may be selected from the multiple L7 proxies. That is, when a service is created, the configuration information for the created service is sent to the L7 proxy that includes configuration information for the fewest number of services. In one example, when selecting an L7 proxy based on affinity between services, the L7 proxy that includes configuration information for the fewest number of services is selected from the multiple L7 proxies, and the configuration information for the created service is sent to the L7 proxy that includes configuration information for the fewest number of services. This allows the L7 proxy that includes configuration information for the fewest number of services to perform traffic management on data packets for the created service to achieve load balancing.
[0110] In some embodiments, the proxy cluster 300 runs multiple L7 proxies. When selecting an L7 proxy based on the affinity between services, the L7 proxy containing the configuration information of the fewest tenants is selected from the multiple L7 proxies to send the configuration information of the created service to the L7 proxy containing the configuration information of the fewest tenants, so that the L7 proxy containing the configuration information of the fewest tenants performs traffic management on the data packets of the created service. The tenant configuration information is the configuration information of the tenant's service. Sending a service with affinity to a tenant to the L7 proxy with the configuration information of the fewest tenants can prevent the same L7 proxy from becoming the affinity proxy for multiple tenants at the same time, or in other words, reduce the risk of the same L7 proxy becoming the affinity L7 proxy for multiple tenants at the same time.
[0111] In some embodiments, the annotation section of the YAML file used to create a service records the affinities between services. The grid console 400 can retrieve the annotation section of the service's YAML file and, through this information, determine which services have affinities. YAML is a markup language and a format for expressing serialized data, commonly used for creating services. Creating a service can specifically involve creating a container that provides the service.
[0112] In some embodiments, the L7 proxy can be deployed using the method shown in FIG5 .
[0113] First, the administrator of the service grid system may create one or more L7 proxies such as the L7 proxy 310 in the proxy cluster 300 through step 501 .
[0114] Tenant A1 can create service A11 on service node 200 in step 502. Creating a service means creating a service container group, where the containers within the created service container group provide the service. Service node 200 can then send service A11's configuration information, service A11's identifier, and tenant A1's identifier to grid console 400 in step 503.
[0115] The grid console 400 may select an L7 proxy for the service A11 in step 504. The L7 proxy may be selected for the service A11 based on the affinity between services. Detailed description is provided above and will not be repeated here.
[0116] It can be assumed that in step 504, the L7 agent selected by the grid console 400 is the L7 agent 310. Then in step 505, the grid console 400 sends the configuration information of the service A11, the identifier of the service A11, and the identifier of the tenant A1 to the L7 agent 310.
[0117] The L7 agent 310 may establish an association between the configuration information of service A11, the identifier of service A11, and the identifier of tenant A1. The L7 agent 310 may save the configuration information of service A11 and the association. In some embodiments, the L7 agent 310 may create a tenant A1 listener in step 506. The tenant A1 listener is used to listen for data packets from tenant A1's service. In some embodiments, the L7 agent 310 may create a tenant A1 service A11 listener in step 507. The tenant A1 service A11 listener is used to listen for data packets from tenant A1's service A11.
[0118] The L7 agent 310 may also establish an association between the L7 agent and tenant A1 in step 508, and send the association between the L7 agent and tenant A1 to the grid console 400 in step 509. The grid console 400 may send the association between the L7 agent and tenant A1 to each L4 agent in the service grid system. The L4 agent may save the received association.
[0119] In some embodiments, the association between the L7 proxy and tenant A1 includes an association between the L7 proxy and tenant A1's service A11. In some embodiments, the association between the L7 proxy and tenant A1 is specifically an association between the L7 proxy identifier and tenant A1's identifier. The L7 proxy identifier and tenant A1 identifier can be recorded in an association list to associate the L7 proxy with tenant A1.
[0120] In this way, the deployment of the L7 proxy can be completed, and the L7 proxy can perform traffic management on the data packets of the services of the relevant tenants. Among them, through the traffic management method provided in the embodiment of the present application, the L7 proxy can implement traffic management on the data packets of the services of the relevant tenants.
[0121] Next, in conjunction with Figure 6, taking the L7 agent 310 and tenant A1 as an example, the traffic management method provided in the embodiment of the present application is introduced.
[0122] The L7 agent 310 includes configuration information of multiple services, where different services belong to the same tenant or different tenants, and the service configuration information is used by the L7 agent 310 to manage traffic of data packets of the service.
[0123] In step 601, service container group 110 sends data packet 111. Service container group 110 belongs to tenant A1, and data packet 111 may be a data packet requesting access to service A11 of tenant A1. That is, data packet 111 is a service request for accessing service A11. Service container group 110 includes at least one service container, and data packet 111 may be sent by one or more of the at least one service container.
[0124] The L4 agent 130 in the business node (i.e., business node 100) where the business container group 110 is located serves as the L4 agent in the inbound direction of the service grid and can intercept the data packet 111. When intercepting the data packet 111, the L4 agent 130 can obtain the identifier of the business container group 110. For example, the L4 agent 130 obtains the Src IP of the data packet 111 by parsing the data packet 111. The Src IP of the data packet 111 is the IP address of the business container group 110 and is an identifier of the business container group 110. In step 602, the L4 agent 130 can obtain the identifier of the tenant (i.e., tenant A1) to which the business container group 110 belongs based on the identifier of the business container group 110. Exemplarily, the L4 agent 130 can obtain the identifier of tenant A1 queried in the grid console 400 based on the identifier of the business container group 110.
[0125] In step 603, the L4 agent 130 can filter the L7 agents that include the configuration information of the services of tenant A1 from among the L7 agents deployed in the agent cluster 300 based on the identifier of tenant A1. Typically, the agent cluster 300 is deployed with multiple L7 agents, and some of the L7 agents include the configuration information of the services of tenant A1. Therefore, it is necessary to filter the L7 agents that include the configuration information of the services of tenant A1 from among the multiple L7 agents based on the identifier of tenant A1. The L4 agent stores the association relationship between the L7 agent and the tenant, and the L7 agent associated with the tenant includes the configuration information of the services of the tenant. The L4 agent 130 can obtain the L7 agent associated with tenant A1 based on the identifier of tenant A1 and the association relationship between the L7 agent and the tenant, that is, obtain the L7 agent that includes the configuration information of the services of tenant A1.
[0126] In some embodiments, tenant A1 may have multiple services, and the configuration information for these multiple services may be in different L7 proxies. That is, not all L7 proxies that include tenant A1's services may include the configuration information for service A11. In step 603, L7 proxies that include the configuration information for tenant A1's service A11 are filtered. L7 proxies that include the configuration information for tenant A1's services can first be filtered based on the identifier of tenant A1. Then, based on the identifier of service A11, L7 proxies that include the configuration information for tenant A1's services are filtered for those that include the configuration information for service A11.
[0127] When there is only one L7 proxy including the configuration information of the service A11 , the L7 proxy including the configuration information of the service A11 of the tenant A1 serves as the target L7 proxy for the data packet 111 .
[0128] When there are multiple L7 proxies including the configuration information of the service A11 , the L4 agent 130 may select a target L7 proxy for the data packet 111 from the multiple L7 proxies.
[0129] In some embodiments, the more services an L7 agent supports for tenant A1, the more likely it is to become the target L7 agent for data packet 111. An L7 agent supporting a service means that the L7 agent includes configuration information for the service. That is, an L7 agent including configuration information for a service can be considered to support the service. For example, L7 agent 310 includes configuration information for N services, and L7 agent 320 includes configuration information for M services, and both the N services and the M services include service A11. Where N and M are integers greater than or equal to 1. If the number of services belonging to tenant A1 among the N services is greater than the number of services belonging to tenant A1 among the M services, L4 agent 130 selects L7 agent 310 as the target L7 agent for data packet 111. That is, when the number of services belonging to tenant A1 among the services supported by L7 agent 310 is greater than the number of services belonging to tenant A1 among the services supported by L7 agent 320, L7 agent 310 serves as the target L7 agent for data packet 111.
[0130] In some embodiments, the lower the load of an L7 proxy, the greater the likelihood that the L7 proxy will become the target L7 proxy for data packet 111. For example, both L7 proxy 310 and L7 proxy 320 include configuration information for service A11. When the load of L7 proxy 320 is greater than the load of L7 proxy 310, L7 proxy 310 serves as the target L7 proxy for data packet 111. The load of an L7 proxy can be represented by the ratio of the L7 proxy's used capacity to its maximum capacity. This ratio is positively correlated with the load of the L7 proxy. In one example, the maximum capacity refers to the maximum number of connections, and the used capacity refers to the number of used connections or the actual number of connections. The term "connection" here refers to the connection between the L7 proxy and the service container group that issues the data packet. Specifically, the data packet for which the L7 proxy performs traffic management is issued by the service container group. When the L4 proxy selects the L7 proxy to perform traffic management on a data packet issued by a certain service container group, the L4 proxy establishes a connection between the L7 proxy and the service container group. Therefore, the maximum number of connections can also be referred to as the maximum number of service container groups that the L7 proxy can connect to, and the used number of connections can also be referred to as the number of service container groups to which the L7 proxy is connected. In one example, the maximum capacity refers to the maximum number of data packets that the L7 proxy can receive per unit time, and the used capacity refers to the number of data packets actually received by the L7 proxy per unit time.
[0131] In some embodiments, the scheduling coefficient of each L7 proxy including the configuration information of the service A11 may be calculated, and then the L7 proxy with the largest scheduling coefficient is used as the target L7 proxy for the data packet 111. The calculation formula of the scheduling coefficient is as follows.
[0132] The scheduling coefficient of the L7 agent = the tenant's weight × (the number of services belonging to tenant A1 among the services supported by the L7 agent / the total number of services supported by the L7 agent) × (1-the used capacity of the L7 agent / the maximum capacity of the L7 agent).
[0133] The tenant's weight may be a preset value. The administrator may set different weights for different L7 proxies for a tenant to set the priority of L7 proxy traffic management for packets of the tenant's service.
[0134] In the above manner, the target L7 proxy of the data packet 111 can be obtained.
[0135] The target L7 agent for the obtained data packet 111 may be set to the L7 agent 310. The L4 agent 130 sends the data packet 111 and the identifier of the tenant A1 to the L7 agent 310 in step 605. In some embodiments, the L4 agent 130 may send the data packet 111 and the identifier of the tenant A1 to the L7 agent 310 through a destination network address translation (DNAT) operation.
[0136] In step 606, the L7 agent can identify the configuration information of the services of tenant A1 from the configuration information of the multiple services included in L7 agent 310 based on the identifier of tenant A1. As described above, the identifier of tenant A1 and the configuration information of the services of tenant A1 are associated. Based on this association and the identifier of tenant A1, the L7 agent can identify the configuration information of the services of tenant A1.
[0137] Next, in step 607 , the L7 agent may perform traffic management on the data packet 111 based on the configuration information of the service of the tenant A1 identified in step 606 .
[0138] Data packet 111 is a data packet of service A11 of tenant A1. If the configuration information of the service of tenant A1 identified in step 606 is the configuration information of service A11, then in step 607, traffic management can be performed on data packet 111 directly based on the configuration information of the service of tenant A1 identified in step 606.
[0139] If the service configuration information of tenant A1 identified in step 606 includes configuration information of service A11 as well as configuration information of other services of tenant A1, in step 607, the configuration information of service A11 is first identified from the service configuration information of tenant A1 identified in step 606. Traffic management is then performed on data packet 111 based on the configuration information of service A11.
[0140] Data packet 111 includes the identifier of the service requested by data packet 111, namely, the identifier of service A11. L7 agent 310 can parse data packet 111 to obtain the identifier of service A11. Then, based on the identifier of service A11, L7 agent 310 identifies the configuration information of service A11 within the configuration information of the service of tenant A1 identified in step 606. Specifically, as described above, the service identifier and the service configuration information are associated. Based on this association and the identifier of service A11, L7 agent 310 can identify the configuration information of service A11.
[0141] In some embodiments, L7 agent 310's traffic management of data packet 111 may include selecting a target service instance for data packet 111. For example, if data packet 111 is a service request, L7 agent 310 may select a service instance to execute the service request. L7 agent 310 may be configured to select service container group 210 as the target service instance for data packet 111, i.e., select a service container in service container group 210 to process data packet 111. At this point, L7 agent 310 may, in step 608, send data packet 111 to an L4 agent (i.e., L4 agent 230) in the service node (i.e., service node 200) where service container group 210 resides. In step 610, L4 agent 230, acting as the outbound L4 agent for the service mesh, may forward the received data packet 111 to service container group 210. In some embodiments, L4 agent 230 may use DNAT to send data packet 111 to service container group 210.
[0142] In some embodiments, in step 608, the L7 agent 310 sends the data packet 111 and the identifier of tenant A1 to the L4 agent 230. The L4 agent 230 may execute step 609 to verify, based on the identifier of tenant A1, that tenant A1 and the business container group 210 belong to the same tenant. Specifically, when the L7 agent 310 selects the business container group 210 as the service instance of the data packet 111, it may add the identifier of the business container group 210 to the data packet 111. For example, the identifier of the business container group 210 is the address of the business container group 210, and the L7 agent 310 adds the address of the business container group 210 to the field corresponding to the destination address of the data packet 111. The L4 agent 230 may parse the data packet 111 to obtain the identifier of the business container group 210. Then, based on the identifier of the business container group 210, the L4 agent 230 may query the grid console 400 to find the tenant to which the business container group 210 belongs. In step 609, L4 agent 230 may determine whether the identifier of tenant A1 is the same as the identifier of the tenant to which business container group 210 belongs. If they are the same, tenant A1 and business container group 210 belong to the same tenant. If they are not the same, tenant A1 and business container group 210 belong to different tenants.
[0143] The L4 agent 230 executes step 610 only when confirming that the tenant A1 and the business container group 210 belong to the same tenant, thereby further ensuring isolation between tenants.
[0144] In some embodiments, when the L4 agent 230 confirms that the tenant A1 and the business container group 210 belong to different tenants, the L4 agent 230 may issue an alarm or report an error.
[0145] In some embodiments, in addition to supporting services for tenant A1, L7 agent 310 also executes services for other tenants, such as services for tenant A2. That is, L7 agent 310 also includes configuration information for tenant A2's services. Tenant A2's service container group 120 can be configured to run in service node 100. When service container group 120 sends data packet 121, L4 agent 130 can send data packet 121 and tenant A2's identifier to L7 agent 310. Based on tenant A2's identifier, L7 agent 310 can identify tenant A2's configuration information from the multiple service configuration information included in L7 agent 310. L7 agent 310 can then perform traffic management on data packet 121 based on tenant A2's configuration information. Exemplarily, through traffic management, L7 agent 310 selects service container group 220 in service node 200 as the target service instance for data packet 121. L7 agent 310 sends data packet 121 and tenant A2's identifier to L4 agent 230. When the L4 agent 230 confirms, based on the identifier of the tenant A2 , that the tenant A2 and the service container group 220 belong to the same tenant, it sends the data packet 121 to the service container group 220 .
[0146] In summary, the same L7 proxy can manage traffic for data packets from multiple tenants' services, enabling multi-tenant sharing of the L7 proxy. This can improve the L7 proxy's computing resource utilization and reduce the L7 proxy's scheduling pressure.
[0147] Based on the content described above, an embodiment of the present application also provides a traffic management method. The method can be executed by a first L7 agent in a service grid system. The service grid system includes a first business node and a proxy cluster; wherein the first business node runs a first L4 agent and a first business container group of a first tenant; the first L7 agent runs in the proxy cluster, and the first L7 agent includes configuration information of multiple services, different services in the multiple services belong to the same tenant or different tenants, and the configuration information of the service is used by the first L7 agent to perform traffic management on the data packets of the service. The service grid system here can be the service grid system shown in Figure 1, the proxy cluster can be the proxy cluster 300 described above, the first L7 agent can specifically be the L7 agent 310 described above, the first business node can be the business node 100 described above, the first L4 agent can be the L4 agent 130 described above, and the first tenant can be the tenant A1 described above. As shown in Figure 7, the method includes the following steps.
[0148] In step 701, the first L7 agent receives the first tenant's identifier and a first data packet sent by the first L4 agent. The first data packet is received by the first L4 agent from the first service container group. The first service container group may be service container group 110 described above, and the first data packet may be data packet 111 described above. The specific implementation of step 701 can be found in the description of steps 601-605 in Figure 6 above and will not be repeated here.
[0149] In step 702, the first L7 agent identifies the configuration information of a first service from the configuration information of the plurality of services based on the identifier of the first tenant, and the first service belongs to the first tenant. The specific implementation of step 702 can be found in the description of step 606 in FIG. 6 above and will not be repeated here.
[0150] In step 703, the first L7 agent performs traffic management on the first data packet based on the configuration information of the first service. The specific implementation of step 702 can be found in the above description of step 607 in FIG6 and will not be repeated here.
[0151] In some embodiments, the first service node also runs a second service container group for a second tenant; the method includes: the first L7 agent receives the second tenant's identifier and a second data packet sent by the first L4 agent, where the second data packet is received by the first L4 agent from the second service container group; the first L4 agent sends the second tenant's identifier and the second data packet to the first L7 agent; the first L7 agent identifies the configuration information of a second service from the configuration information of the multiple services based on the identifier of the second tenant, where the second service belongs to the second tenant; and the first L7 agent performs traffic management on the second data packet based on the configuration information of the second service. The second tenant may be tenant A2 described above, the second service container group may be service container group 120 described above, and the second data packet may be data packet 121 described above.
[0152] In some embodiments, the first service includes the service corresponding to the first data packet and other services; the first L7 agent performs traffic management on the first data packet based on the configuration information of the first service, including: the first L7 agent identifies the configuration information of the service corresponding to the first data packet in the configuration information of the first service based on the identifier of the service corresponding to the first data packet; the first L7 agent performs traffic management on the first data packet based on the configuration information of the service corresponding to the first data packet. The service corresponding to the first data packet may be the service A11 described above. The specific implementation of this embodiment can be referred to the above description of step 606 in Figure 6, and will not be repeated here.
[0153] In some embodiments, the proxy cluster corresponding to the service of the first data packet also runs a second L7 proxy, and the second L7 proxy includes configuration information of at least one service; the first L7 proxy receives the identifier of the first tenant and the first data packet sent by the first L4 proxy, including: when the number of services belonging to the first tenant in the multiple services is greater than the number of services belonging to the first tenant in the at least one service, the first L7 proxy receives the identifier of the first tenant and the first data packet sent by the first L4 proxy. The second L7 proxy can be the L7 proxy 320 described above. The specific implementation of this embodiment can refer to the above description of steps 603-605 in Figure 6, and will not be repeated here.
[0154] In some embodiments, the proxy cluster further runs a second L7 proxy, which also includes configuration information for the first service; the first L7 proxy receives the first tenant's identifier and first data packet sent by the first L4 proxy, including: when the load of the second L7 proxy is greater than the load of the first L7 proxy, the first L7 proxy receives the first tenant's identifier and first data packet sent by the first L4 proxy. The second L7 proxy may be the L7 proxy 320 described above. The specific implementation of this embodiment can be found in the description of steps 603-605 in Figure 6 above, and will not be repeated here.
[0155] In some embodiments, the service grid system further comprises: a console connected to the proxy cluster; the method further comprises: the first L7 proxy receiving and recording configuration information of two or more services from the console; wherein the two or more services belong to the same tenant, or wherein the output of one of the two or more services is the input of another service. The specific implementation of this embodiment can be found in the above description of the embodiments shown in Figures 3-5 and will not be repeated here.
[0156] In some embodiments, the service grid system further includes a second service node, which runs a second L4 agent and a third service container group; the first L7 agent performs traffic management on the first data packet based on the configuration information of the first service, including: the first L7 agent selects the third service container group as the target container group for the first data packet; the first L7 agent sends the first data packet and the identifier of the first tenant to the second L4 agent; wherein the second L4 agent is used to: confirm that the first tenant and the tenant to which the third service container group belongs are the same tenant based on the identifier of the first tenant; and send the first data packet to the third service container group. The second service node can be the service node 200 described above, and the third service container group can also be the service container group 210 described above. The specific implementation of this embodiment can be referred to the above description of steps 608-610 in Figure 6, and will not be repeated here.
[0157] Through the above method, the same L7 proxy can include the configuration information of multiple tenants' services. When traffic management is required for a tenant's service data packets, the L7 proxy obtains the tenant's identifier and, based on the tenant's identifier, retrieves the tenant's service configuration information from the service configuration information of multiple tenants. Traffic management can then be performed on the tenant's service data packets based on the tenant's service configuration information. This enables the same L7 proxy to perform traffic management on the service data packets of multiple tenants, enabling multi-tenant sharing of the L7 proxy. Multi-tenant sharing of the L7 proxy can improve the L7 proxy's computing resource utilization and reduce the L7 proxy's scheduling pressure.
[0158] Referring to FIG8 , an embodiment of the present application provides a traffic management device 800. The device 800 is configured as a first L7 agent in a service grid system, wherein the service grid system includes a first service node and a proxy cluster; wherein the first service node runs a first L4 agent and a first service container group of a first tenant; wherein the first L7 agent runs in the proxy cluster, and the first L7 agent includes configuration information for multiple services, wherein different services in the multiple services belong to the same tenant or different tenants, and the service configuration information is used by the first L7 agent to perform traffic management on data packets of the services. As shown in FIG8 , the device 800 includes:
[0159] A receiving module 810 is configured to receive an identifier of the first tenant and a first data packet sent by the first L4 agent, where the first data packet is received by the first L4 agent from the first service container group;
[0160] an identification module 820, configured to identify, based on the identifier of the first tenant, configuration information of a first service from the configuration information of the plurality of services, the first service belonging to the first tenant;
[0161] The management module 830 is configured to perform traffic management on the first data packet based on the configuration information of the first service.
[0162] In some embodiments, the first service node also runs a second service container group of a second tenant; the receiving module 810 is further used to: receive the identifier of the second tenant and a second data packet sent by the first L4 agent, where the second data packet is received by the first L4 agent from the second service container group; the identification module 820 is further used to: based on the identifier of the second tenant, identify the configuration information of the second service in the configuration information of the multiple services, where the second service belongs to the second tenant; the management module 830 is further used to: perform traffic management on the second data packet based on the configuration information of the second service.
[0163] In some embodiments, the first service includes the service corresponding to the first data packet and other services; the management module 830 is used to: identify the configuration information of the service corresponding to the first data packet in the configuration information of the first service based on the identifier of the service corresponding to the first data packet; and perform traffic management on the first data packet based on the configuration information of the service corresponding to the first data packet.
[0164] In some embodiments, the agent cluster also runs a second L7 agent, which includes configuration information of at least one service; the receiving module 810 is used to: when the number of services belonging to the first tenant in the multiple services is greater than the number of services belonging to the first tenant in the at least one service, receive the identifier of the first tenant and the first data packet sent by the first L4 agent.
[0165] In some embodiments, the proxy cluster also runs a second L7 proxy, which also includes configuration information of the first service; the receiving module 810 is used to: when the load of the second L7 proxy is greater than the load of the first L7 proxy, receive the identifier of the first tenant and the first data packet sent by the first L4 proxy.
[0166] In some embodiments, the service grid system further includes: a console connected to the proxy cluster; the receiving module 810 is used to: receive and record configuration information of two or more services from the console; wherein the two or more services belong to the same tenant, or the output of one of the two or more services is the input of another service.
[0167] In some embodiments, the service grid system further includes a second service node, which runs a second L4 agent and a third service container group; the management module 830 is configured to: the first L7 agent selects the third service container group as the target container group for the first data packet; the first L7 agent sends the first data packet and the identifier of the first tenant to the second L4 agent; wherein the second L4 agent is configured to: based on the identifier of the first tenant, confirm that the first tenant and the tenant to which the third service container group belongs are the same tenant; and send the first data packet to the third service container group.
[0168] The receiving module 810, the identification module 820, and the management module 830 can all be implemented via software or hardware. For example, the implementation of the receiving module 810 will be described below using the receiving module 810 as an example. Similarly, the implementation of the identification module 820 and the management module 830 can refer to the implementation of the receiving module 810.
[0169] As an example of a software functional unit, the receiving module 810 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Furthermore, the computing instance may be one or more. For example, the receiving module 810 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone AZ or in different AZs, and each AZ includes one data center or multiple geographically close data centers. Generally, a region may include multiple AZs.
[0170] Similarly, multiple hosts / virtual machines / containers running the code can be distributed within the same VPC or across multiple VPCs. Typically, a VPC is set up within a region. Cross-region communication between two VPCs within the same region, or between VPCs in different regions, requires a communication gateway within each VPC to interconnect the VPCs.
[0171] As an example of a hardware functional unit, the receiving module 810 may include at least one computing device, such as a server. Alternatively, the receiving module 810 may be implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL), or any combination thereof.
[0172] The multiple computing devices included in the receiving module 810 can be distributed in the same region or in different regions. The multiple computing devices included in the receiving module 810 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the receiving module 810 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0173] It should be noted that, in other embodiments, the receiving module 810 can be used to execute any step in the method shown in FIG7 , the identifying module 820 can be used to execute any step in the method shown in FIG7 , and the management module 830 can be used to execute any step in the method shown in FIG7 . The steps that the receiving module 810 , the identifying module 820 , and the management module 830 are responsible for implementing can be specified as needed. The full functionality of the traffic management device 800 is achieved by having the receiving module 810 , the identifying module 820 , and the management module 830 respectively implement different steps in the method shown in FIG7 .
[0174] This application also provides a computing device 900. As shown in Figure 9, computing device 900 includes a bus 902, a processor 904, a memory 906, and a communication interface 908. Processor 904, memory 906, and communication interface 908 communicate with each other via bus 902. Computing device 900 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in computing device 900.
[0175] Bus 902 may be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, among others. Buses may be classified as address buses, data buses, control buses, and the like. For ease of illustration, FIG9 illustrates a single bus line, but this does not imply a single bus or type of bus. Bus 902 may include a path for transmitting information between various components of computing device 900 (e.g., memory 906, processor 904, and communication interface 908).
[0176] The processor 904 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0177] The memory 906 may include volatile memory, such as random access memory (RAM). The memory 906 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0178] The memory 906 stores executable program code, and the processor 904 executes the executable program code to respectively implement the functions of the aforementioned receiving module 810, identification module 820, and management module 830, thereby implementing the method shown in Figure 7. That is, the memory 906 stores instructions for executing the method shown in Figure 7.
[0179] The communication interface 908 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 900 and other devices or a communication network.
[0180] Embodiments of the present application also provide a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.
[0181] As shown in FIG10 , the computing device cluster includes at least one computing device 900. The memory 906 in one or more computing devices 900 in the computing device cluster may store the same instructions for executing the method shown in FIG7 .
[0182] In some possible implementations, the memory 906 of one or more computing devices 900 in the computing device cluster may also respectively store some instructions for executing the method shown in Figure 7. In other words, the combination of one or more computing devices 900 can jointly execute the instructions for executing the method shown in Figure 7.
[0183] It should be noted that the memory 906 in different computing devices 900 in the computing device cluster can store different instructions, each for executing part of the functions of the traffic management apparatus 800. In other words, the instructions stored in the memory 906 in different computing devices 900 can implement the functions of one or more of the receiving module 810, the identifying module 820, and the managing module 830.
[0184] In some possible implementations, one or more computing devices in a computing device cluster may be connected via a network. The network may be a wide area network (WAN) or a local area network (LAN), among others. FIG. 11 illustrates a possible implementation. As shown in FIG. 11 , two computing devices 900A and 900B are connected via a network. Specifically, the network is connected via a communication interface in each computing device. In this type of possible implementation, the memory 906 in the computing device 900A stores instructions for executing the functions of the receiving module 810. Simultaneously, the memory 906 in the computing device 900B stores instructions for executing the functions of the identification module 820 and the management module 830.
[0185] It should be understood that the functionality of the computing device 900A shown in FIG11 may also be implemented by multiple computing devices 900. Similarly, the functionality of the computing device 900B may also be implemented by multiple computing devices 900.
[0186] The present application also provides another computing device cluster. The connection relationship between the computing devices in this computing device cluster can be similar to the connection method of the computing device cluster described in Figures 10 and 11. However, the memory 906 in one or more computing devices 900 in this computing device cluster can store the same instructions for executing the method shown in Figure 7.
[0187] In some possible implementations, the memory 906 of one or more computing devices 900 in the computing device cluster may also respectively store some instructions for executing the method shown in Figure 7. In other words, the combination of one or more computing devices 900 can jointly execute the instructions for executing the method shown in Figure 7.
[0188] The present application also provides a computer program product comprising instructions. The computer program product may be software or a program product comprising instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device executes the method shown in FIG. 7 .
[0189] The present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a computing device, or a host migration device such as a data center that includes one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a magnetic tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to execute the method shown in FIG. 7 .
[0190] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit them. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not deviate the essence of the corresponding technical solutions from the protection scope of the technical solutions of the embodiments of the present application.
Claims
1. A traffic management method, characterized in that, The method is applied to a service mesh system, which includes a first business node and an agent cluster; wherein, a first transport layer L4 agent and a first business container group of a first tenant are running on the first business node; a first application layer L7 agent is running on the agent cluster, and the first L7 agent includes configuration information of multiple services, different services among the multiple services belong to the same tenant or different tenants, and the configuration information of the services is used for the first L7 agent to perform traffic management on the data packets of the services; the method includes: The first L4 agent receives a first data packet sent by the first business container group; The first L4 agent sends the identifier of the first tenant and the first data packet to the first L7 agent; Based on the identifier of the first tenant, the first L7 agent identifies the configuration information of a first service in the configuration information of the multiple services, and the first service belongs to the first tenant; Based on the configuration information of the first service, the first L7 agent performs traffic management on the first data packet.
2. The method according to claim 1, characterized in that, A second business container group of a second tenant is also running on the first business node; the method includes: The first L4 agent receives a second data packet sent by the second business container group; The first L4 agent sends the identifier of the second tenant and the second data packet to the first L7 agent; Based on the identifier of the second tenant, the first L7 agent identifies the configuration information of a second service in the configuration information of the multiple services, and the second service belongs to the second tenant; Based on the configuration information of the second service, the first L7 agent performs traffic management on the second data packet.
3. The method according to claim 1 or 2, characterized in that, The first service includes the service corresponding to the first data packet and other services; Based on the configuration information of the first service, the first L7 agent performs traffic management on the first data packet, including: Based on the identifier of the service corresponding to the first data packet, the first L7 agent identifies the configuration information of the service corresponding to the first data packet in the configuration information of the first service; Based on the configuration information of the service corresponding to the first data packet, the first L7 agent performs traffic management on the first data packet.
4. The method according to claim 3, characterized in that, Multiple L7 agents are running on the agent cluster; The first L4 agent sends the identifier of the first tenant and the first data packet to the first L7 agent, including: Based on the identifier of the first tenant, the first L4 agent identifies an L7 agent that includes the configuration information of the services of the first tenant from the multiple L7 agents; Based on the identifier of the service corresponding to the first data packet, the first L4 agent identifies an L7 agent that includes the configuration information of the service corresponding to the first data packet from the L7 agents that include the configuration information of the services of the first tenant, and obtains the first L7 agent.
5. The method according to any one of claims 1 to 4, characterized in that, A second L7 agent is also running on the agent cluster, and the second L7 agent includes the configuration information of at least one service; The first L4 agent sends the identifier of the first tenant and the first data packet to the first L7 agent, including: When the number of services belonging to the first tenant among the multiple services is greater than the number of services belonging to the first tenant among the at least one service, the first L4 proxy sends the identifier of the first tenant and the first data packet to the first L7 proxy.
6. The method according to any one of claims 1-4, characterized in that, The proxy cluster also runs a second L7 proxy, and the second L7 proxy also includes the configuration information of the first service; The first L4 proxy sending the identifier of the first tenant and the first data packet to the first L7 proxy includes: When the load of the second L7 proxy is greater than the load of the first L7 proxy, the first L4 proxy sends the identifier of the first tenant and the first data packet to the first L7 proxy.
7. The method according to any one of claims 1-6, characterized in that, The service mesh system further includes: a console connected to the proxy cluster; The method further includes: the console sending the configuration information of two or more services to the same L7 proxy in the proxy cluster; wherein, the two or more services belong to the same tenant, or the output of one of the two or more services is the input of another service.
8. The method according to claim 7, wherein The proxy cluster runs multiple L7 proxies; among the multiple L7 proxies, the same L7 proxy includes the configuration information of the smallest number of services, or the same L7 proxy includes the configuration information of the smallest number of tenants.
9. The method according to any one of claims 1-8, characterized in that, The service mesh system further includes a second service node, and the second service node runs a second L4 proxy and a third service container group; The first L7 proxy performs traffic management on the first data packet based on the configuration information of the first service, including: The first L7 proxy selects the third service container group as the target container group for the first data packet; The first L7 proxy sends the first data packet and the identifier of the first tenant to the second L4 proxy; The method further includes: The second L4 proxy confirms that the first tenant and the tenant to which the third service container group belongs are the same tenant based on the identifier of the first tenant; The second L4 proxy sends the first data packet to the third service container group.
10. A service mesh system, characterized in that, The service mesh system includes a first service node and a proxy cluster; wherein, the first service node runs a first L4 proxy and a first service container group of the first tenant; the proxy cluster runs a first L7 proxy, and the first L7 proxy includes the configuration information of multiple services, and different services among the multiple services belong to the same tenant or different tenants, and the configuration information of the service is used for the first L7 proxy to perform traffic management on the data packets of the service; wherein, The first L4 proxy is configured to: receive the first data packet sent by the first service container group; The first L4 proxy is configured to: send the identifier of the first tenant and the first data packet to the first L7 proxy; The first L7 proxy is configured to: identify the configuration information of the first service belonging to the first tenant from the configuration information of the multiple services based on the identifier of the first tenant; The first L7 proxy is used for: performing traffic management on the first data packet based on the configuration information of the first service.
11. The service mesh system according to claim 10, wherein The first service node also runs a second service container group of a second tenant; The first L4 proxy is further used for: receiving a second data packet sent by the second service container group; The first L4 proxy is further used for: sending the identifier of the second tenant and the second data packet to the first L7 proxy; The first L7 proxy is further used for: identifying the configuration information of a second service belonging to the second tenant from the configuration information of the multiple services based on the identifier of the second tenant; The first L7 proxy is further used for: performing traffic management on the second data packet based on the configuration information of the second service.
12. The service mesh system according to claim 10 or 11, characterized in that, The first service includes the service corresponding to the first data packet and other services; The first L7 proxy is used for: identifying the configuration information of the service corresponding to the first data packet from the configuration information of the first service based on the identifier of the service corresponding to the first data packet; performing traffic management on the first data packet based on the configuration information of the service corresponding to the first data packet.
13. The service mesh system according to any one of claims 10-12, characterized in that, The proxy cluster also runs a second L7 proxy, and the second L7 proxy includes the configuration information of at least one service; The first L4 proxy is used for: when the number of services belonging to the first tenant among the multiple services is greater than the number of services belonging to the first tenant among the at least one service, sending the identifier of the first tenant and the first data packet to the first L7 proxy.
14. The service mesh system according to any one of claims 10-12, characterized in that The proxy cluster also runs a second L7 proxy, and the second L7 proxy also includes the configuration information of the first service; The first L4 proxy is used for: when the load of the second L7 proxy is greater than the load of the first L7 proxy, sending the identifier of the first tenant and the first data packet to the first L7 proxy.
15. The service mesh system according to any one of claims 10-14, characterized in that, The service mesh system further includes: a console connected to the proxy cluster; The console is used for: sending the configuration information of two or more services to the same L7 proxy in the proxy cluster; wherein, the two or more services belong to the same tenant, or the output of one of the two or more services is the input of another service.
16. The service mesh system according to any one of claims 10-15, characterized in that, The service mesh system further includes a second service node, and the second service node runs a second L4 proxy and a third service container group; The first L7 proxy is used for: selecting the third service container group as the target container group for the first data packet; sending the first data packet and the identifier of the first tenant to the second L4 proxy; The second L4 proxy is used for: confirming that the first tenant and the tenant to which the third service container group belongs are the same tenant based on the identifier of the first tenant; sending the first data packet to the third service container group.
17. A traffic management method, characterized in that, The method is applied to a first L7 proxy in a service mesh system, which includes a first business node and a proxy cluster; wherein, the first business node runs a first L4 proxy and a first business container group of a first tenant; the first L7 proxy runs in the proxy cluster, and the first L7 proxy includes configuration information of multiple services, different services among the multiple services belong to the same tenant or different tenants, and the configuration information of the services is used for the first L7 proxy to perform traffic management on the data packets of the services; the method includes: The first L7 proxy receives the identifier of the first tenant and a first data packet sent by the first L4 proxy, and the first data packet is received by the first L4 proxy from the first business container group; The first L7 proxy identifies the configuration information of a first service in the configuration information of the multiple services based on the identifier of the first tenant, and the first service belongs to the first tenant; The first L7 proxy performs traffic management on the first data packet based on the configuration information of the first service.
18. The method according to claim 17, wherein The first business node also runs a second business container group of a second tenant; the method includes: The first L7 proxy receives the identifier of the second tenant and a second data packet sent by the first L4 proxy, and the second data packet is received by the first L4 proxy from the second business container group; The first L4 proxy sends the identifier of the second tenant and the second data packet to the first L7 proxy; The first L7 proxy identifies the configuration information of a second service in the configuration information of the multiple services based on the identifier of the second tenant, and the second service belongs to the second tenant; The first L7 proxy performs traffic management on the second data packet based on the configuration information of the second service.
19. The method according to claim 17 or 18, characterized in that, The first service includes the service corresponding to the first data packet and other services; The first L7 proxy performs traffic management on the first data packet based on the configuration information of the first service, including: The first L7 proxy identifies the configuration information of the service corresponding to the first data packet in the configuration information of the first service based on the identifier of the service corresponding to the first data packet; The first L7 proxy performs traffic management on the first data packet based on the configuration information of the service corresponding to the first data packet.
20. The method according to any one of claims 17-19, characterized in that, A second L7 proxy also runs in the proxy cluster, and the second L7 proxy includes configuration information of at least one service; The first L7 proxy receives the identifier of the first tenant and a first data packet sent by the first L4 proxy, including: When the number of services belonging to the first tenant among the multiple services is greater than the number of services belonging to the first tenant among the at least one service, the first L7 proxy receives the identifier of the first tenant and the first data packet sent by the first L4 proxy.
21. The method according to any one of claims 17-20, characterized in that, A second L7 proxy also runs in the proxy cluster, and the second L7 proxy also includes the configuration information of the first service; The first L7 proxy receives the identifier of the first tenant and a first data packet sent by the first L4 proxy, including: When the load of the second L7 proxy is greater than the load of the first L7 proxy, the first L7 proxy receives the identifier of the first tenant and the first data packet sent by the first L4 proxy.
22. The method according to any one of claims 17 - 21, characterized in that The service mesh system further includes: a console connected to the proxy cluster; The method further includes: the first L7 proxy receives and records configuration information of two or more services from the console; wherein, the two or more services belong to the same tenant, or the output of one of the two or more services is the input of another service.
23. The method according to any one of claims 17 - 22, characterized in that, The service mesh system further includes a second service node, and the second service node runs a second L4 proxy and a third service container group; Based on the configuration information of the first service, the first L7 proxy performs traffic management on the first data packet, including: The first L7 proxy selects the third service container group as the target container group for the first data packet; The first L7 proxy sends the first data packet and the identifier of the first tenant to the second L4 proxy; Wherein, the second L4 proxy is used for: Based on the identifier of the first tenant, confirm that the first tenant and the tenant to which the third service container group belongs are the same tenant; Send the first data packet to the third service container group.
24. A traffic management device, characterized in that, The device is configured in the first L7 proxy in the service mesh system, and the service mesh system includes a first service node and a proxy cluster; wherein, the first service node runs a first L4 proxy and a first service container group of the first tenant; the first L7 proxy runs in the proxy cluster, and the first L7 proxy includes configuration information of multiple services, and different services among the multiple services belong to the same tenant or different tenants, and the configuration information of the services is used for the first L7 proxy to perform traffic management on the data packets of the services; the device includes: A receiving module, configured to receive the identifier of the first tenant and the first data packet sent by the first L4 proxy, where the first data packet is received by the first L4 proxy from the first service container group; An identifying module, configured to identify the configuration information of the first service in the configuration information of the multiple services based on the identifier of the first tenant, where the first service belongs to the first tenant; A management module, configured to perform traffic management on the first data packet based on the configuration information of the first service.
25. The device according to claim 24, characterized in that, The first service node further runs a second service container group of the second tenant; The receiving module is further configured to: receive the identifier of the second tenant and the second data packet sent by the first L4 proxy, where the second data packet is received by the first L4 proxy from the second service container group; The identifying module is further configured to: identify the configuration information of the second service in the configuration information of the multiple services based on the identifier of the second tenant, where the second service belongs to the second tenant; The management module is further configured to: perform traffic management on the second data packet based on the configuration information of the second service.
26. The device according to claim 24 or 25, characterized in that, The first service includes the service corresponding to the first data packet and other services; The management module is used for: Identify the configuration information of the service corresponding to the first data packet in the configuration information of the first service based on the identifier of the service corresponding to the first data packet; Perform traffic management on the first data packet based on the configuration information of the service corresponding to the first data packet.
27. The device according to any one of claims 24-26, characterized in that, The proxy cluster also runs a second L7 proxy, and the second L7 proxy includes the configuration information of at least one service; The receiving module is configured to: when the number of services belonging to the first tenant among the multiple services is greater than the number of services belonging to the first tenant among the at least one service, receive the identifier of the first tenant and the first data packet sent by the first L4 proxy.
28. The device according to any one of claims 24-26, characterized in that, The proxy cluster also runs a second L7 proxy, and the second L7 proxy also includes the configuration information of the first service; The receiving module is configured to: when the load of the second L7 proxy is greater than the load of the first L7 proxy, receive the identifier of the first tenant and the first data packet sent by the first L4 proxy.
29. The device according to any one of claims 24-28, characterized in that, The service mesh system further includes: a console connected to the proxy cluster; The receiving module is configured to: receive and record the configuration information of two or more services from the console; wherein, the two or more services belong to the same tenant, or the output of one of the two or more services is the input of another service.
30. The device according to any one of claims 24-29, characterized in that, The service mesh system further includes a second service node, and the second service node runs a second L4 proxy and a third service container group; The management module is configured to: The first L7 proxy selects the third service container group as the target container group for the first data packet; The first L7 proxy sends the first data packet and the identifier of the first tenant to the second L4 proxy; Wherein, the second L4 proxy is configured to: Based on the identifier of the first tenant, confirm that the first tenant and the tenant to which the third service container group belongs are the same tenant; Send the first data packet to the third service container group.
31. A cluster of computing devices, characterized in that, Comprising at least one computing device, each computing device includes a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 17 to 23.
32. A computer-readable storage medium, characterized in that, Comprising computer program instructions, when the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method according to any one of claims 17 to 23.
33. A computer program product comprising instructions, characterized in that, When the instructions are run by a computer device cluster, the computer device cluster is caused to execute the method according to any one of claims 17 to 23.
Citation Information
Patent Citations
Traffic management method, service grid system, device and cluster
CN120223632A
Application layer bandwidth limiting and sharing system and method based on double agents
CN116232900A
System supporting multi-tenant traffic forwarding, related cloud network and forwarding method
CN116405553A
Multi-tenant control plane management on computing platform
CN116601606A
Synchronization of logical network state between global and local managers
US11088902B1