Traffic tag processing method, server and storage medium
Through the non-invasive dynamic traffic label setting method, using data plane and control plane components to generate and add traffic labels, the maintenance costs and risks caused by invasive settings in the prior art are solved, and more flexible routing capabilities and broader communication coverage are achieved.
Patent Information
- Application Number
- PCT/IB2025/050014
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-03
- Filing Date
- 2025-01-02
- Publication Date
- 2025-07-10
AI Technical Summary
The prior art requires intrusion of code when setting traffic labels for applications, resulting in increased maintenance costs and risks, and it is difficult to uniformly standardize the naming rules and formats of traffic labels.
Receive access requests through the target data surface component, determine whether they comply with dynamic marking rules, generate and add target traffic tags, realize non-invasive traffic tag settings, and use the control surface component to provide dynamic marking rules and label generation methods.
It reduces the maintenance costs and risks on the application side, achieves more flexible and scalable routing capabilities, and covers more communication scenarios.
Smart Images

Figure IB2025050014_10072025_PF_FP_ABST
Abstract
Description
[0001]Traffic Label Processing Method, Server, and Storage Medium This disclosure claims priority to Chinese patent application number 202410010272.3, filed with the China Patent Office on January 3, 2024, entitled "Traffic Label Processing Method, Server, and Storage Medium," the entire contents of which are incorporated herein by reference. Technical Field This disclosure relates to the field of computer technology, and more particularly to a traffic label processing method, server, and storage medium. Background: Service mesh is often used to describe the microservice network that constitutes an application and the interactions between applications. As the infrastructure layer that handles inter-service communication, a service mesh is responsible for constructing the complex service topology of modern cloud-native applications to reliably deliver requests. In a service mesh, an ingress gateway or mesh proxy receives application requests and routes them to the corresponding application service instance based on the traffic label carried in the request. Setting traffic labels for application requests is a critical step in implementing routing operations for different traffic types. Currently, some methods set traffic labels within application code, but these methods require intrusion into the application, resulting in high maintenance costs and risks. Therefore, a new solution is needed. SUMMARY OF THE INVENTION Various aspects of the present disclosure provide a traffic label processing method, server, and storage medium for dynamically setting traffic labels for application requests in a non-invasive manner, thereby reducing maintenance costs and risks on the application side. An embodiment of the present disclosure provides a traffic label processing method, comprising: receiving a first access request via a target data plane component; determining whether the first access request meets the rule validation conditions corresponding to a dynamic labeling rule; the dynamic labeling rule being issued by a control plane component; if so, generating a target traffic label according to the label generation method in the dynamic labeling rule; adding the target traffic label to the first access request to route and forward the first access request based on the target traffic label. Optionally, before determining whether the first access request meets the rule validation conditions corresponding to the dynamic labeling rule, the method further comprises: obtaining user-provided label configuration data via the control plane component; parsing the label configuration data to obtain an effective subject range and a dynamic labeling rule defined by the label configuration data; and issuing the dynamic labeling rule to the target data plane component based on the effective subject range.Optionally, the method further includes: obtaining metadata information of at least one application service instance in the data plane through the control plane component; and issuing the dynamic marking rule to the target data plane component based on the effective subject range, including: determining whether the at least one application service instance is within the effective subject range based on the metadata information of the at least one application service instance; and if any of the at least one application service instance is within the effective subject range, issuing the dynamic marking rule to the grid proxy component corresponding to the application service instance. Optionally, determining whether the first access request meets the rule effectiveness condition corresponding to the dynamic marking rule includes: performing at least one of the following judgment operations on the first access request, and determining that the first access request meets the rule effectiveness condition corresponding to the dynamic marking rule if the result of each of the at least one judgment operations is yes: determining whether the destination application service corresponding to the first access request is within the effective callee range corresponding to the rule effectiveness condition; and determining whether the calling protocol used by the first access request is within the effective protocol range corresponding to the rule effectiveness condition. Optionally, generating a target flow label according to a label generation method in the dynamic labeling rule includes: obtaining a header value having a specified header name from a request header of the first access request as the label value of the target flow label; or obtaining a label value corresponding to a specified label name from a label of a container group to which the container containing the target data plane component belongs as the label value of the target flow label; or obtaining a specified constant value as the label value of the target flow label; or obtaining a field value corresponding to a specified field from the request body of the first access request as the label value of the target flow label; or obtaining a parameter value corresponding to a specified query parameter from a query parameter of the first access request as the label value of the target flow label. Optionally, the method further includes: obtaining a context unique identifier of the first access request from the first access request; and establishing a mapping relationship between the target flow label and the context unique identifier; wherein the mapping relationship is used to query the target flow label according to the context unique identifier in the processing chain of the first access request.Optionally, after adding the target traffic label to the first access request, the method further includes: forwarding the first access request to a target application service instance proxied by the target data plane component; receiving a second access request returned by the target application service instance in response to the first access request; the second access request carrying the context unique identifier; querying the mapping relationship based on the context unique identifier to obtain the target traffic label corresponding to the context unique identifier; and adding the target traffic label to the second access request to route and forward the second access request based on the target traffic label. Optionally, the target data plane component includes an ingress gateway component of the data plane or any grid proxy component in the data plane. Embodiments of the present disclosure also provide a server comprising: a memory and a processor; the memory being configured to store one or more computer instructions; the processor being configured to execute the one or more computer instructions to perform the steps of the method provided in embodiments of the present disclosure. Embodiments of the present disclosure also provide a computer-readable storage medium storing a computer program, which, when executed by the processor, can implement the steps of the method provided in embodiments of the present disclosure. The present disclosure also provides a computer program that, when executed on a computer, causes the computer to perform the steps of the method provided in the present disclosure. In this embodiment, a target data plane component receives a first access request and determines whether the first access request meets the rule validity conditions corresponding to a dynamic tagging rule issued by a control plane component. If so, a target traffic label is generated according to the label generation method specified in the dynamic tagging rule and added to the first access request to route and forward the first access request based on the target traffic label. This implementation implements dynamic traffic label setting based on the target data plane component and the control plane component. This allows traffic labels to be set for application access requests without intruding on the code of the application issuing the access request, thereby reducing maintenance costs and risks on the application side. Furthermore, dynamic tagging rules can be used to flexibly tag access requests, achieving more scalable and flexible routing capabilities, thereby covering a wider range of communication scenarios. BRIEF DESCRIPTION OF THE DRAWINGS The drawings described herein are used to provide a further understanding of the present disclosure and constitute a part of the present disclosure. The illustrative embodiments of the present disclosure and their descriptions are used to explain the present disclosure and do not constitute an improper limitation on the present disclosure.In the accompanying drawings: Figure 1 is a schematic diagram of the structure of a service grid provided by an exemplary embodiment of the present disclosure; Figure 2 is a flowchart of a traffic label processing method provided by an exemplary embodiment of the present disclosure; Figure 3 is a schematic diagram of the tracking of the processing link of a first access request provided by an exemplary embodiment of the present disclosure; Figure 4 is a flowchart of the traffic label processing method provided by an exemplary embodiment of the present disclosure executed in a service grid; Figure 5 is a schematic diagram of the structure of a server provided by an exemplary embodiment of the present disclosure. DETAILED DESCRIPTION To further clarify the objectives, technical solutions, and advantages of the present disclosure, the technical solutions of the present disclosure will be described clearly and completely below in conjunction with the specific embodiments of the present disclosure and the corresponding drawings. Obviously, the described embodiments are only some of the embodiments of the present disclosure, and are not exhaustive. All other embodiments derived by persons of ordinary skill in the art based on the embodiments of the present disclosure without inventive effort are within the scope of protection of the present disclosure. The terms used in the embodiments of the present disclosure are for the purpose of describing specific embodiments only and are not intended to limit the present disclosure. As used in the embodiments of the present disclosure and the appended claims, the singular forms "a," "an," "the," and "the" are intended to include the plural forms, unless the context clearly indicates otherwise. "A plurality" generally includes at least two, but does not exclude the inclusion of at least one. It should be understood that the term "and / or" as used herein merely describes an associative relationship between associated objects, indicating that three relationships can exist. For example, "A and / or B" can represent: A alone, A and B simultaneously, or B alone. Furthermore, the character " / " herein generally indicates that the associated objects are in an "or" relationship. It should also be noted that the terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a product or system comprising a list of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such product or system. Without further limitation, the elements specified by the phrase "comprising a..." do not exclude the presence of additional identical elements in the product or system comprising the elements. To more clearly describe the technical solutions provided by various embodiments of the present disclosure, the following describes the service mesh architecture and some related concepts involved in the embodiments of the present disclosure. A service mesh is a dedicated infrastructure layer used to implement reliable, fast, and secure inter-service calls within a microservices architecture.The service grid primarily facilitates secure and reliable communication between multiple microservices. Microservices refer to applications being broken down into multiple smaller services or instances, distributed across different clusters / machines. Application service instances are also referred to as workloads. Each application service instance is bound to a grid proxy to facilitate communication and management between services. As shown in Figure 1 , microservices include application service instance A and application service instance B, which form the functional application layer of service grid 100. In one embodiment, application service instances A and B run as containers / processes on a machine / workload container group. In one embodiment, application service instance A can be a product query service, and application service instance B can be a product ordering service. As shown in Figure 1 , application service instance A and grid proxy 103 coexist in machine / workload container group 109, while application service instance B and grid proxy 105 coexist in machine / workload container group 110. Grid proxies 103 and 105 form the data plane of service grid 100. Grid proxies 103 and 105 run as container / process 104 and container / process 106, respectively. Application service instance A and application service instance B run as container / process 107 and container / process 108, respectively. Grid proxy 103 and application service instance A can communicate bidirectionally, while grid proxy 105 and application service instance B can communicate bidirectionally. Furthermore, grid proxy 103 and grid proxy 105 can also communicate bidirectionally with each other. In one embodiment, all traffic for application service instance A is routed to the appropriate destination through grid proxy 103, and all network traffic for application service instance B is routed to the appropriate destination through grid proxy 105. In one embodiment, the functionality of the extended data plane layer can be implemented by writing a custom filter for the proxy (Envoy) in the service grid 100. The grid proxy configuration can be to enable the service grid to correctly proxy service traffic and achieve service interoperability and service governance.Grid proxy 103 and grid proxy 105 can be configured to perform at least one of the following functions: service discovery, health checking, routing, load balancing, authentication and authorization, and observability. As shown in FIG1 , service grid 100 also includes a control plane layer. The control plane layer can be comprised of a set of services running in a dedicated namespace, hosted by a managed control plane component 101 on a machine / workload container (machine / pod) 102. As shown in FIG1 , managed control plane component 101 communicates bidirectionally with grid proxy 103 and grid proxy 105. Managed control plane component 101 is configured to perform certain control and management functions. For example, managed control plane component 101 receives telemetry data transmitted by grid agents 103 and 105 and can further aggregate this telemetry data. For these services, managed control plane component 101 can also provide user-oriented application programming interfaces (APIs) to facilitate manipulation of network behavior and provide configuration data to grid agents 103 and 105. In a service mesh, ingress gateways (such as API Gateways) are primarily responsible for processing external traffic ingress and providing API management and access control. Mesh proxies (such as Sidecar Proxy) are responsible for communication and management between application service instances. Together, they form the service mesh infrastructure, enabling fine-grained traffic control, policy enforcement, and security protection. In a service mesh, an endpoint typically refers to the network address of an application service instance, that is, the specific network location of the application service instance within the service mesh, typically including information such as an IP address and port number. When a mesh proxy receives an external request, it forwards it to the corresponding application service instance endpoint. In a service mesh, traffic labels are a mechanism used to mark and manage traffic. Typically, when an application service instance registers with the service mesh, it carries traffic labels that describe specific attributes or identifiers of the application service instance.When the grid proxy of an application service instance receives a request from the application service instance, it determines the target application service instance corresponding to the request based on the traffic label and predefined routing rules, and routes the request to the target application service instance. In some typical methods, traffic labels can be set for the application by intruding into the application code, so that the application service instance corresponding to the application carries the traffic label in the requests it issues. In some solutions, traffic labels can be set manually within the application code. For example, a traffic label setting API can be called within the application code to set the label for the application's outbound traffic. In other solutions, a third-party framework or library can be used to set traffic labels for the application's outbound traffic. In still other solutions, AOP (Aspect Oriented Programming) technology can be used to automatically embed traffic label setting code within the application. These intrusive traffic label setting methods require modifying the application or using a third-party framework or library, increasing maintenance costs and risks. On the other hand, the process of setting traffic labels requires standardized naming rules, formats, and details for traffic labels, further increasing the management costs and risks of traffic labels. To address the above technical issues, some embodiments of the present disclosure provide a solution. The technical solutions provided by various embodiments of the present disclosure are described in detail below, in conjunction with the accompanying figures. Figure 2 is a flow chart of a traffic label processing method provided by an exemplary embodiment of the present disclosure. The method may include the steps shown in Figure 2: Step 201: Receive a first access request via a target data plane component. Step 202: Determine whether the first access request meets the rule validation conditions corresponding to a dynamic labeling rule issued by a control plane component. Step 203: If the request meets the conditions, generate a target traffic label based on the label generation method specified in the dynamic labeling rule. Step 204: Add the target traffic label to the first access request to route and forward the first access request based on the target traffic label. In this embodiment, the target data plane component may be an ingress gateway component or any mesh proxy component of the data plane. The ingress gateway component is the entry point to the service mesh. It is primarily responsible for tagging incoming access requests from within or outside the service mesh according to dynamic tagging rules and forwarding them to different destinations. The mesh proxy component acts as a proxy for workloads within the service mesh, acting as a proxy for both egress and ingress traffic for the application service instances corresponding to the workloads.Any mesh proxy component is primarily responsible for tagging ingress traffic from an ingress gateway component or other mesh proxy components according to dynamic tagging rules, and may also tag egress traffic from the proxy application service instances. When the target data plane component is implemented as an ingress gateway component, the first access request may be an access request sent by an application outside the service mesh to the ingress gateway of the service mesh. The ingress gateway component may tag the first access request according to the dynamic tagging rules and forward the tagged first access request to a mesh proxy component within the service mesh according to routing rules. When the target data plane component is implemented as any mesh proxy component, the first access request may be an access request forwarded by the ingress gateway to the mesh proxy component. The mesh proxy component may tag the first access request according to the dynamic tagging rules and forward the tagged first access request to the application service instance proxied by the mesh proxy component. When the target data plane component is implemented as any mesh proxy component, the first access request may also be an egress access request sent by the application service instance proxied by the mesh proxy component. The grid proxy component may tag the egress access request according to dynamic tagging rules and forward the tagged first access request to another grid proxy component or an egress gateway component. The dynamic tagging rules are generated by the control plane component in the service grid. Before dynamically tagging the access request, the control plane component may obtain user-provided tag configuration data and parse the tag configuration data to obtain the dynamic tagging rules. The tag configuration data is used to configure the dynamic generation method for traffic labels. Optionally, the tag configuration data may include at least effective subject information. This effective subject information describes the subjects (e.g., workloads or workload groups) to which the traffic label is applied. The effective subject information may vary for different tag configuration data. For example, when new workloads are added to the service grid, new user-provided tag configuration data may be obtained. The effective subject information in this tag configuration data may include the identification of the new workload. For another example, when modifying the traffic label of a specified workload, new label configuration data provided by the user can be obtained. The effective subject information in this label configuration data can include the identification of these specified workloads. When parsing the label rule configuration data, the control plane component can parse the effective subject information in the label rule configuration data to determine the effective subject scope of the traffic label. Optionally, the label configuration data can also include labeling rule description information, which can include definition information about the traffic label's rule effectiveness conditions and the label generation method.The rule validation condition definition information describes the conditions that must be met to trigger tagging of the access request. The tag generation method definition information describes the user-defined tag name and the method for obtaining the user-defined tag value. The tag configuration data can be provided to the control plane component of the service grid in the form of a configuration file, allowing the control plane component to obtain dynamic tagging rules for access requests from the configuration file without intruding on the application issuing the access request. The configuration file can be flexibly provided based on tag configuration requirements. When a new application service instance is added to the service grid, the tag configuration data can be updated by updating the configuration file. After obtaining the user-provided tag configuration data, the control plane component can parse the tag configuration data to obtain the scope of the effective subjects and the dynamic tagging rules defined in the tag configuration data. The control plane component can parse the tag rule description information in the tag configuration data to obtain the dynamic tagging rules. Optionally, the control plane component can parse the rule validation condition definition information for the traffic tag to obtain the rule validation condition. Optionally, the control plane component can parse the tag generation method definition information for the traffic tag to obtain the tag generation method. The rule validation conditions describe the conditions under which workload traffic is labeled. The label generation method describes the processing method used to generate traffic labels for workload traffic. Optionally, the rule validation conditions defined in the label configuration data may include at least one of effective callee information and effective protocol information. The effective callee information limits the scope of target application service instances for which the traffic label is effective. Optionally, the control plane component may parse the effective callee information in the label configuration data to determine the effective callee scope of the traffic label. The effective protocol scope limits the scope of calling protocols for which the traffic label is effective. Optionally, the control plane component may parse the protocol calling information in the label configuration data to determine the effective protocol scope of the traffic label. Optionally, the label generation method definition information in the label configuration data may be described using a label rule expression. The label rule expression describes the specific method for calculating the label value based on a user-specified label name. For example, the label rule expression may describe obtaining the value of a specified field from specified information as the label value. The control plane component can parse the label rule expression to obtain the label generation method defined by the label configuration data. The control plane component can parse the effective subject information in the label configuration data to obtain the effective subject range.After obtaining the effective subject scope, the control plane component can distribute dynamic marking rules based on the effective subject scope to target data plane components within the effective subject scope, so that the target data plane components can mark ingress / egress traffic according to the dynamic marking rules. In some optional embodiments, the control plane component can obtain metadata information for at least one application service instance in the data plane. The metadata information for any application service instance can include: the application service name corresponding to the application service instance, the namespace in which it resides, the runtime node environment in which it resides, the operating system used, the supported monitoring services, and at least one of other attribute tags. Accordingly, when distributing dynamic marking rules based on the effective subject scope to the target data plane component, the control plane component can determine whether the at least one application service instance is within the effective subject scope based on the metadata information of the at least one application service instance. If any of the at least one application service instance is within the effective subject scope, the control plane component can distribute the dynamic marking rules to the grid proxy component (i.e., the target data plane component) corresponding to the application service instance. Based on the above, after receiving the first access request, the target data plane component may determine whether the first access request meets the rule validation conditions corresponding to the dynamic labeling rule. If so, a target traffic label is generated according to the label generation method in the dynamic labeling rule. Optionally, the rule validation conditions may include: an effective callee range and / or an effective protocol range. The following will further illustrate the above determination process using the first access request as an example. In some optional embodiments A1, when determining whether the first access request meets the rule validation conditions corresponding to the dynamic labeling rule, the target data plane component may determine whether the destination application service corresponding to the first access request is within the effective callee range corresponding to the rule validation conditions. If the destination application service corresponding to the first access request is within the effective callee range corresponding to the rule validation conditions, the target data plane component may determine that the first access request meets the rule validation conditions corresponding to the dynamic labeling rule. In other optional embodiments A2, when determining whether the first access request meets the rule validation conditions corresponding to the dynamic labeling rule, the target data plane component may determine whether the calling protocol used by the first access request is within the effective protocol range corresponding to the rule validation conditions. If the calling protocol used by the first access request is within the effective protocol range corresponding to the rule effectiveness condition, it can be determined that the first access request meets the rule effectiveness condition corresponding to the dynamic marking rule.In some further optional embodiments A3, when determining whether a first access request meets the rule validation conditions corresponding to a dynamic labeling rule, the target data plane component may determine whether the destination application service corresponding to the first access request is within the effective callee range corresponding to the rule validation conditions, and whether the calling protocol used by the first access request is within the effective protocol range corresponding to the rule validation conditions. If the destination application service corresponding to the first access request is within the effective callee range corresponding to the rule validation conditions, and the calling protocol used by the first access request is within the effective protocol range corresponding to the rule validation conditions, then the first access request may be determined to meet the rule validation conditions corresponding to the dynamic labeling rule. If the first access request meets the rule validation conditions corresponding to the dynamic labeling rule, the target data plane component may generate a target traffic label according to the label generation method specified in the dynamic labeling rule. The following will use some label generation methods as examples for illustrative description. In some optional embodiments B1, the target data plane component may obtain a header value with a specified header name from the request header of the first access request as the label value of the target traffic label. For example, when the target data plane component is implemented as an ingress gateway component, the ingress gateway component may obtain a header value with a specified header name from the received access request as the label value corresponding to the target flow label. When the target data plane component is implemented as a grid proxy component, the grid proxy component may obtain a header value with a specified header name from the request entering the grid proxy component as the label value corresponding to the target flow label. For another example, when the target data plane component is implemented as a grid proxy component, the grid proxy component may obtain a header value with a specified header name from the request sent to the grid proxy component by the proxy application service instance as the label value corresponding to the target flow label. These examples are not listed here. In some optional embodiments B2, the target data plane component may obtain a label value corresponding to a specified label name from the label of the container group to which the container containing the target data plane component belongs as the label value for the target flow label. In some optional embodiments B3, the target data plane component obtains a specified constant value as the label value for the target flow label. In some optional embodiments B4, the target data plane component may obtain the field value corresponding to a specified field from the request body of the first access request as the label value of the target traffic label. In some optional embodiments B5, the target data plane component may obtain the parameter value corresponding to a specified query parameter from the query parameters of the first access request as the label value of the target traffic label. It should be understood that in addition to the above-described embodiments, other label generation methods may be used to generate the label value of the target traffic label, which may be dynamically configured using label configuration data.In practice, multiple label generation methods can be obtained based on user-defined label configuration data, and label values can be obtained based on the obtained dynamic labeling rules. These methods are not listed here. After obtaining the target traffic label based on the above implementation, the target data plane component can add the target traffic label to the first access request to route and forward the first access request based on the target traffic label. Optionally, a dynamic traffic label can be added to the first access request by adding a header to the first access request. Optionally, the target data plane component can add a new header to the first access request. The header field of this new header contains the label name of the target traffic label, and the header value contains the label value of the target traffic label. It should be noted that the target data plane component can further obtain routing rules and route and forward the first access request based on the routing rules. The routing rules can be issued by the control plane component. It should be understood that the above-described dynamic labeling rules are merely illustrative. In practice, various dynamic labeling rules can be obtained based on user-defined label configuration data, and label values can be obtained based on the obtained dynamic labeling rules. These examples are not further detailed. In some optional embodiments, when the label configuration data defines a label name for a target traffic label, the control plane component can establish a mapping between the label name of the target traffic label and a routing destination as a routing rule and deliver this routing rule to the target data plane component. Furthermore, upon receiving an access request, the target data plane component can query the routing rules for a routing destination matching the label name of the target traffic label carried in the access request and perform routing forwarding based on this routing destination. In other optional embodiments, after parsing a dynamic labeling rule, the control plane component can generate a dynamic routing rule based on the dynamic labeling rule and deliver this dynamic routing rule to the target data plane component. For example, the control plane component can establish a mapping between the label value field of the target traffic label, the dynamic labeling rule, and the routing destination as a routing rule. Upon receiving an access request, the target data plane component may, based on the dynamic tagging rules corresponding to the tag value field, retrieve the tag value corresponding to the tag value field from the access request, thereby improving the routing rules. Furthermore, the target data plane component may perform routing and forwarding based on the tag value of the target traffic tag carried in the access request and the improved routing rules. In some optional embodiments, to preserve the target traffic tag in the processing chain of the first access request, the target data plane component may retrieve the context-unique identifier of the first access request from the first access request and establish a mapping relationship between the target traffic tag and the context-unique identifier. This mapping relationship is stored in the form of a key-value dictionary.The unique context identifier is carried throughout the entire processing chain of the first access request. The mapping relationship is used to query the target traffic label based on the unique context identifier during the processing chain of the first access request. The following description uses the processing chain between any grid proxy component and its proxied workload as an example. Optionally, after adding the target traffic label to the first access request, the grid proxy component may forward the first access request to the target application service instance proxied by the grid proxy component. After processing the first access request, the target application service instance may issue a second access request, which may be used to invoke another application service instance. The second access request carries the unique context identifier. Upon receiving the second access request returned by the target application service instance based on the first access request, the grid proxy component may query the mapping relationship based on the unique context identifier to obtain the target traffic label corresponding to the unique context identifier. The grid proxy component may then add the target traffic label to the second access request to route and forward the second access request based on the target traffic label. As shown in Figure 3, the first access request received by the grid proxy component carries a unique context identifier and a target traffic label, and the grid proxy component locally stores a mapping between the unique context identifier and the target traffic label (i.e., a key-value dictionary). When the grid proxy component forwards the first access request to the workload, the first access request carries the unique context identifier. The second request returned by the workload to the grid proxy component also carries the unique context identifier. The grid proxy component can then query the mapping based on the unique context identifier and add the target traffic label to the second request. Based on this implementation, if the application service instance cannot identify the target traffic label and cannot add the target traffic label to the second access request, the grid proxy component can track the target traffic label based on the established mapping. This allows the target traffic label to be applied throughout the entire processing chain of the first access request, reducing the risk of unsuccessful routing and forwarding due to the lack of a traffic label. In this embodiment, the target data plane component receives a first access request and determines whether the first access request meets the rule validity conditions corresponding to the dynamic labeling rule issued by the control plane component. If so, a target traffic label is generated according to the label generation method in the dynamic labeling rule and added to the first access request. The first access request is then routed and forwarded based on the target traffic label.In this implementation, dynamic flow label setting is implemented based on the target data plane components and control plane components. This allows flow labels to be set for application access requests without intruding on the code of the application issuing the access request, thereby reducing maintenance costs and risks on the application side. Furthermore, dynamic labeling rules can be used to flexibly label access requests, enabling more scalable and flexible routing capabilities and covering a wider range of communication scenarios. The following will further illustrate this embodiment of the disclosure with reference to the data plane and control plane structures shown in Figure 4. As shown in Figure 4, the service mesh controller 401 in the control plane can obtain metadata information for application service instance C and gateway 405b. Users can provide label configuration data through a declarative API, and the flow label configuration controller 402 in the control plane can obtain this label configuration data. The flow label configuration generator 403 can parse the label configuration data to obtain dynamic labeling rules. The flow label configuration generator 403 includes a scope definition plug-in, a label rule definition plug-in, and an attribute definition plug-in. The scope definition plug-in is used to parse the label configuration data to determine the effective subject scope, effective callee scope, and effective protocol scope. The label rule definition plug-in is used to parse the label configuration data to determine dynamic labeling rules. The attribute definition plug-in is used to parse the label configuration data to determine attribute information corresponding to the label generation method. Its traffic label configuration generator 403 can distribute the dynamic labeling rules to the grid agent 404b and gateway 405b in the data plane based on the effective subject scope. Furthermore, the grid agent 404b can use the first traffic label processor 404a to generate a dynamic traffic label C1 for the application service instance C. The gateway 405b can use the second traffic label processor 405a to generate a dynamic traffic label B1 for the application service instance B. It should be noted that the execution entity of each step of the method provided in the above embodiment can be the same device, or the method can be executed by different devices. For example, steps 201 to 204 may be performed by device A; for another example, steps 201 and 202 may be performed by device A, and step 203 may be performed by device B; and so on. Furthermore, some of the processes described in the above embodiments and accompanying drawings include multiple operations that appear in a specific order. However, it should be understood that these operations may not be performed in the order in which they appear herein or may be performed in parallel. Operation sequence numbers, such as 201 and 202, are merely used to distinguish between different operations and do not represent any execution order.Furthermore, these processes may include more or fewer operations, and these operations may be performed sequentially or in parallel. It should be noted that terms such as "first" and "second" herein are used to distinguish between different messages, devices, modules, and the like, and do not represent a sequential order, nor do they limit "first" and "second" to different types. It should be noted that the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, and displayed data, etc.) involved in this disclosure are all authorized by the user or fully authorized by all parties. The collection, use, and processing of such data must comply with the relevant laws, regulations, and standards of the relevant countries and regions, and corresponding operation portals are provided for the user to choose to authorize or deny. Figure 5 illustrates a schematic diagram of the server structure provided by an exemplary embodiment of the present disclosure. As shown in Figure 5, the server includes a memory 501, a processor 502, and a communication component 503. Memory 501 is used to store computer programs and can be configured to store various other data to support operations on the server. Examples of such data include instructions for any application or method operating on the server. In some optional embodiments, the server illustrated in FIG. 5 is configured to perform a traffic label processing method. A processor 502 is coupled to a memory 501 and configured to execute a computer program in the memory 501, configured to: receive a first access request via a target data plane component; determine whether the first access request meets the rule validation conditions corresponding to a dynamic labeling rule issued by a control plane component; if so, generate a target traffic label according to the label generation method in the dynamic labeling rule; add the target traffic label to the first access request, and route the first access request based on the target traffic label. Optionally, before determining whether the first access request meets the rule validation conditions corresponding to the dynamic labeling rule, the processor 502 is further configured to: obtain user-provided label configuration data via the control plane component; parse the label configuration data to obtain an effective subject range and a dynamic labeling rule defined by the label configuration data; and issue the dynamic labeling rule to the target data plane component based on the effective subject range.Optionally, the processor 502 is further configured to: obtain metadata information of at least one application service instance in the data plane through the control plane component; and when issuing the dynamic marking rule to the target data plane component based on the effective subject range, the processor 502 is specifically configured to: determine, based on the metadata information of the at least one application service instance, whether the at least one application service instance is within the effective subject range; and if any of the at least one application service instance is within the effective subject range, issue the dynamic marking rule to the grid proxy component corresponding to the application service instance. Optionally, when determining whether the first access request meets the rule effectiveness condition corresponding to the dynamic marking rule, the processor 502 is specifically configured to: perform at least one of the following judgment operations on the first access request, and if the result of each of the at least one judgment operations is yes, determine that the first access request meets the rule effectiveness condition corresponding to the dynamic marking rule: determine whether the destination application service corresponding to the first access request is within the effective callee range corresponding to the rule effectiveness condition; and determine whether the calling protocol used by the first access request is within the effective protocol range corresponding to the rule effectiveness condition. Optionally, when generating the target flow label according to the label generation method in the dynamic labeling rule, the processor 502 is specifically configured to: obtain a header value having a specified header name from the request header of the first access request as the label value of the target flow label; or obtain a label value corresponding to a specified label name from the label of the container group to which the container containing the target data plane component belongs as the label value of the target flow label; or obtain a specified constant value as the label value of the target flow label; or obtain a field value corresponding to a specified field from the request body of the first access request as the label value of the target flow label; or obtain a parameter value corresponding to a specified query parameter from the query parameters of the first access request as the label value of the target flow label. Optionally, the processor 502 is further configured to: obtain a context unique identifier of the first access request from the first access request; establish a mapping relationship between the target flow label and the context unique identifier; and use the mapping relationship to query the target flow label according to the context unique identifier in the processing chain of the first access request.Optionally, after adding the target traffic label to the first access request, the processor 502 is further configured to: forward the first access request to a target application service instance proxied by the target data plane component; receive a second access request returned by the target application service instance in response to the first access request; the second access request carries the context unique identifier; query the mapping relationship based on the context unique identifier to obtain the target traffic label corresponding to the context unique identifier; and add the target traffic label to the second access request to route and forward the second access request based on the target traffic label. Optionally, the target data plane component includes an ingress gateway component of the data plane or any grid proxy component in the data plane. Furthermore, as shown in FIG5 , the server also includes other components such as a power supply component 504. FIG5 schematically illustrates only some components and does not imply that the server includes only the components shown in FIG5 . The memory 501 may be implemented by any type of volatile or non-volatile memory device or a combination thereof, such as static random-access memory (SRAM), electrically erasable programmable read-only memory (EEPROM), erasable programmable read-only memory (EPROM), programmable read-only memory (PROM), read-only memory (ROM), magnetic storage, flash memory, magnetic disk, or optical disk. The communication component 503 is configured to facilitate wired or wireless communication between the device in which the communication component is located and other devices.The device where the communication component is located can access a wireless network based on a communication standard, such as Wi-Fi (wireless network communication technology), 2G (such as Global System for Mobile Communications (GSM)), 3G (such as Wideband Code Division Multiple Access (WCDMA), 4G (such as Long Term Evolution (LTE)), 4G+ (such as upgraded Long Term Evolution (LTE-Advanced, LTE-A)), or 5G (fifth generation mobile communication technology (5th Generation Mobility Communications Technology)), or a combination thereof. In an exemplary embodiment, the communication component receives a broadcast signal or broadcast-related information from an external broadcast management system via a broadcast channel. In an exemplary embodiment, the communication component can be based on near field communication (NFC) technology, radio frequency identification (RFID) technology, or a combination thereof. This can be implemented using RFID (Radio Frequency Identification) technology, Infrared Data Association (IRDA) technology, Ultra Wide Band (UWB) technology, Bluetooth (BT) technology, and other technologies. The power supply component 504 is used to provide power to various components of the device where the power supply component resides. The power supply component may include a power management system, one or more power supplies, and other components associated with generating, managing, and distributing power for the device where the power supply component resides. In this embodiment, the target data plane component receives a first access request and determines whether the first access request meets the rule validation conditions corresponding to the dynamic tagging rule issued by the control plane component. If so, a target traffic label is generated based on the label generation method in the dynamic tagging rule and added to the first access request to route and forward the first access request based on the target traffic label. In this embodiment, dynamic traffic label setting is implemented based on the target data plane component and the control plane component. This allows traffic labels to be set for application access requests without intruding into the code of the application issuing the access request, thereby reducing maintenance costs and risks on the application side.On the other hand, dynamic tagging rules can be used to flexibly tag access requests, achieving more scalable and flexible routing capabilities, thereby covering more communication scenarios. Accordingly, embodiments of the present disclosure also provide a computer-readable storage medium storing a computer program. When executed, the computer program can implement the steps that can be performed by the server in the above-described method embodiments. Accordingly, embodiments of the present disclosure also provide a computer program that, when executed on a computer, causes the computer to perform the steps that can be performed by the server in the above-described method embodiments. Those skilled in the art will appreciate that embodiments of the present disclosure can be provided as methods, systems, or computer program products. Therefore, the present disclosure can take the form of entirely hardware embodiments, entirely software embodiments, or embodiments combining software and hardware aspects. Furthermore, the present disclosure can take the form of a computer program product implemented on one or more computer-usable storage media (including but not limited to disk storage, CD-ROM (Compact Disc Read-Only Memory), optical storage, etc.) containing computer-usable program code. The present disclosure is described with reference to flowcharts and / or block diagrams of methods, devices (systems), and computer program products according to embodiments of the present disclosure. It should be understood that each process flow and / or block in the flowcharts and / or block diagrams, as well as combinations of processes and / or blocks in the flowcharts and / or block diagrams, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, such that the instructions, when executed by the processor of the computer or other programmable data processing device, produce means for implementing the functions specified in one or more processes in the flowcharts and / or one or more blocks in the block diagrams. These computer program instructions can also be stored in a computer-readable memory capable of directing the computer or other programmable data processing device to operate in a specific manner, such that the instructions stored in the computer-readable memory produce an article of manufacture including instruction means for implementing the functions specified in one or more processes in the flowcharts and / or one or more blocks in the block diagrams. These computer program instructions can also be loaded onto a computer or other programmable data processing device, so that a series of operating steps are executed on the computer or other programmable device to produce a computer-implemented process, so that the instructions executed on the computer or other programmable device provide steps for implementing the functions specified in one or more processes in the flowchart and / or one or more boxes in the block diagram.In a typical configuration, a computing device includes one or more processors (CPUs), input / output interfaces, network interfaces, and memory. Memory may include non-permanent storage in computer-readable media, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. OMemory is an example of a computer-readable medium. Computer-readable media includes permanent and non-permanent, removable and non-removable media, and can be implemented by any method or technology to store information. Information can be computer-readable instructions, data structures, program modules, or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technologies, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic disk storage or other magnetic storage devices, or any other non-transmission medium that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transient computer-readable media, such as modulated data signals and carrier waves. It should also be noted that the terms "comprise," "include," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, product, or apparatus comprising a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, product, or apparatus. Without further limitation, an element defined by the phrase "comprising a..." does not preclude the presence of additional identical elements in the process, method, product, or apparatus comprising the recited element. The foregoing description is merely an example of the present disclosure and is not intended to limit the present disclosure. Various modifications and variations will readily occur to those skilled in the art. Any modifications, equivalent substitutions, improvements, and the like made within the spirit and principles of the present disclosure are intended to be encompassed by the claims of the present disclosure.
Claims
Claims 1. A method for processing traffic labels, comprising: Receive a first access request through the target data plane component; Determine whether the first access request meets the rule activation conditions corresponding to the dynamic tagging rule; The dynamic tagging rule is issued by the control plane component; if it meets the conditions, generate a target traffic tag according to the tag generation method in the dynamic tagging rule; add the target traffic tag to the first access request to perform routing and forwarding of the first access request according to the target traffic tag.
2. Before determining whether the first access request meets the rule activation conditions corresponding to the dynamic tagging rule in the method according to claim 1, it further includes: Obtain the tag configuration data provided by the user through the control plane component; Parse the tag configuration data to obtain the effective subject range and the dynamic tagging rule defined by the tag configuration data; according to the effective subject range, issue the dynamic tagging rule to the target data plane component.
3. The method according to claim 2 further comprises: Obtain the metadata information of at least one application service instance in the data plane through the control plane component; Issuing the dynamic tagging rule to the target data plane component according to the effective subject range includes: respectively determining whether the at least one application service instance is within the effective subject range according to the metadata information of the at least one application service instance; If any application service instance in the at least one application service instance is within the effective subject range, issue the dynamic tagging rule to the grid proxy component corresponding to the application service instance.
4. According to the method described in any one of claims 1-3, determining whether the first access request meets the rule activation conditions corresponding to the dynamic tagging rule includes: Perform at least one of the following judgment operations on the first access request, and when the results of the at least one judgment operation are all yes, determine that the first access request meets the rule activation conditions corresponding to the dynamic tagging rule: judge whether the destination application service corresponding to the first access request is within the effective callee range corresponding to the rule activation conditions; judge whether the call protocol adopted by the first access request is within the effective protocol range corresponding to the rule activation conditions.
5. According to the method described in any one of claims 1-4, generate a target traffic label according to the label generation method in the dynamic labeling rule, including: Obtain the header value with a specified header name from the request header of the first access request as the tag value of the target traffic tag; Alternatively, obtain the tag value corresponding to the specified tag name from the tags of the container group to which the container where the target data plane component is located belongs as the tag value of the target traffic tag; or obtain a specified constant value as the tag value of the target traffic tag; or obtain the field value corresponding to the specified field from the request body of the first access request as the tag value of the target traffic tag; or obtain the parameter value corresponding to the specified query parameter from the query parameters of the first access request as the tag value of the target traffic tag.
6. The method according to any one of claims 1-5, further comprising: Obtain the context unique identifier of the first access request from the first access request; Establish a mapping relationship between the target traffic tag and the context unique identifier; The mapping relationship is used to query the target traffic label according to the context unique identifier in the processing link of the first access request.
7. According to the method described in claim 6, after adding the target traffic label to the first access request, the method further includes: Forward the first access request to the target application service instance of the target data plane component proxy; Receive a second access request returned by the target application service instance according to the first access request; The second access request carries the context unique identifier; query the mapping relationship according to the context unique identifier to obtain the target traffic label corresponding to the context unique identifier; Add the target traffic label to the second access request to perform routing and forwarding on the second access request according to the target traffic label.
8. The method according to any one of claims 1-7, wherein the target data plane component comprises: The ingress gateway component of the data plane or any grid proxy component in the data plane.
9. A server, comprising: A memory and a processor; The memory is used to store one or more computer instructions; the processor is used to execute the one or more computer instructions for: performing the steps in the method according to any one of claims 1-8.
10. A computer-readable storage medium storing a computer program, the computer program, when executed by a processor, being capable of implementing the steps in the method according to any one of claims 1-8.
11. A computer program, when the computer program is executed on a computer, causing the computer to execute the steps in the method according to any one of claims 1-8.
Citation Information
Patent Citations
Flow management method and device for micro-service request, server and storage medium
CN111600930A
Edge traffic control method and device based on service grid, and storage medium
CN113285885A
Traffic identity label transmission method and device, electronic equipment and storage medium
CN114338682A
Target request sending method and device, storage medium and electronic device
CN116896578A