Container communication method, electronic device, and medium
By using MPLS technology to encapsulate and transmit IP packets in the container network, the problem of communication abnormalities between containers caused by IP ACL is solved, and the communication capability between containers is improved.
Patent Information
- Application Number
- PCT/CN2025/072022
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-15
- Filing Date
- 2025-01-13
- Publication Date
- 2025-07-24
AI Technical Summary
In the prior art, container network communications are intercepted due to the setting of IP ACLs, which affects normal communications between containers.
MPLS technology is used to encapsulate IP packets, generate MPLS packets, and transmit them through MPLS tunneling to avoid intercepting IP ACLs and realize communication between containers.
It reduces the limitations of IP ACL on container IP packets, improves communication capabilities between containers, and reduces communication abnormalities.
Smart Images

Figure CN2025072022_24072025_PF_FP_ABST
Abstract
Description
Container communication method, electronic device, and medium
[0001] CROSS-REFERENCE TO RELATED APPLICATIONS
[0002] This patent application claims priority to Chinese patent application 202410057526.7 filed with the State Intellectual Property Office of China on January 15, 2024, and the disclosure of this Chinese patent application is incorporated herein by reference in its entirety. Technical Field
[0003] The present application relates to the field of container communication technology, and in particular to a container communication method, electronic device, and medium. Background Art
[0004] Currently, communication between different nodes in the container network is carried out using IP packets. For nodes whose containers are located in the same local area network, IP packets are sent using IPv4 or IPv6 packet lookup routing. For nodes whose containers are located in different local area networks, IP packets are sent using IP tunneling. Summary of the Invention
[0005] This application proposes a container communication method, electronic device, and medium, aiming to reduce the restrictions of IP ACL on container IP packets and improve the communication capabilities between containers.
[0006] To achieve the above-mentioned objectives, a first aspect of the present application provides a container communication method, which is applied to a first node, and the method includes: obtaining destination address information of an IP message to be forwarded in a source container, wherein the destination address information is the global address information of a destination container located at a second node, and the source container is configured in the first node; determining a forwarding label based on the destination address information; encapsulating the IP message according to the forwarding label to obtain an MPLS message; and sending the MPLS message to a next-hop node, so that the next-hop node sends the MPLS message to the destination container according to the forwarding label.
[0007] To achieve the above-mentioned objectives, the second aspect of the present application provides a container communication method, which is applied to a second node, the method comprising: receiving an MPLS message, wherein the MPLS message includes a forwarding label; when the label value of the forwarding label is a first label value, performing label popping on the MPLS message to obtain an IP message, wherein the IP message includes destination address information, the destination address information is the global address information of the destination container, and the destination container is located in the second node; and forwarding the IP message to the destination container according to the destination address information.
[0008] To achieve the above-mentioned objectives, the third aspect of the present application provides a container communication method, which is applied to a third node, the method comprising: receiving an MPLS message, wherein the MPLS message includes a forwarding label and an IP message to be forwarded to a destination container, and the destination container is configured in a second node; when the label value of the forwarding label is a second label value, determining a target forwarding label based on the forwarding label; and replacing the forwarding label in the MPLS message with the target forwarding label, and sending the MPLS message after the label replacement to the next hop node according to the target forwarding label.
[0009] To achieve the above-mentioned purpose, the fourth aspect of an embodiment of the present application proposes an electronic device, which includes a memory and a processor, wherein the memory stores a computer program, and when the processor executes the computer program, it implements any one of the methods described in the first to third aspects above.
[0010] To achieve the above-mentioned purpose, the fifth aspect of the embodiments of the present application proposes a computer-readable storage medium on which a computer program is stored. When the computer program is executed by a processor, it implements any method described in the above-mentioned first to third aspects. BRIEF DESCRIPTION OF THE DRAWINGS
[0011] FIG1 is a schematic diagram of a process flow of a container communication method provided in an embodiment of the present application;
[0012] FIG2 is a schematic diagram of the process of step S102 in FIG1 according to an embodiment of the present application;
[0013] FIG3 is a flow chart of a container communication method provided in an embodiment of the present application;
[0014] FIG4 is a schematic structural diagram of a first node provided in an embodiment of the present application;
[0015] FIG5 is a schematic diagram of a flow chart of a container communication method provided in an embodiment of the present application;
[0016] FIG6 is a schematic diagram of the process of step S402 in FIG5 provided in an embodiment of the present application;
[0017] FIG7 is a schematic structural diagram of a second node provided in an embodiment of the present application;
[0018] FIG8 is a schematic diagram of a flow chart of a container communication method provided in an embodiment of the present application;
[0019] FIG9 is a schematic diagram of a flow chart of a container communication method provided in an embodiment of the present application;
[0020] FIG10 is a schematic structural diagram of a third node provided in an embodiment of the present application;
[0021] FIG11 is a schematic diagram of a flow chart of a container communication method provided in an embodiment of the present application;
[0022] FIG12 is a schematic diagram of the structure of an electronic device provided in an embodiment of the present application. DETAILED DESCRIPTION
[0023] In order to make the purpose, technical solutions and advantages of this application more clear, the following further describes this application in detail with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain this application and are not intended to limit this application.
[0024] It should be noted that, unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by those skilled in the art to which this application belongs. The terms used herein are only for the purpose of describing the embodiments of this application and are not intended to limit this application.
[0025] Currently, communication between different nodes in the container network is carried out using IP packets. For nodes whose containers are located in the same local area network, IP packets are sent using IPv4 or IPv6 packet lookup routing. For nodes whose containers are located in different local area networks, IP packets are sent using IP tunneling.
[0026] In real production environments, for network security, even when nodes communicate in the same local area network, IP access control lists (ACLs) are set on routers and switches to filter IP packets. This causes some IP packets sent by containers to be intercepted, leading to abnormal communication between containers.
[0027] The embodiments of the present application provide a container communication method, electronic device, and medium, which are intended to reduce the restrictions of IP ACL on IP packets of containers and improve the communication capabilities between containers.
[0028] First, the nouns appearing in this application are explained:
[0029] Multi-Protocol Label Switching (MPLS): A new technology that uses labels to guide high-speed, efficient data transmission over open communications networks. This technology combines the advantages of Layer 2 (L2) switching and Layer 3 (L3) routing, organically integrating Layer 2 infrastructure with Layer 3 routing. Layer 3 routing is implemented at the network edge, while Layer 2 switching is employed at the MPLS network core. MPLS implements packet forwarding by switching labels at each node. It does not modify existing routing protocols and can be implemented on a variety of Layer 2 physical media, including Asynchronous Transfer Mode (ATM), Frame Relay (FR), Ethernet, and Point-to-Point Protocol (PPP). MPLS effectively complements Layer 2 technologies with Layer 3 routing, leveraging Layer 2's superior traffic management and the flexibility of Layer 3 "hop-by-hop" routing to achieve end-to-end Quality of Service (QoS).
[0030] The embodiments of the present application provide a container communication method, electronic device, and medium, which are specifically described through the following embodiments. First, the container communication method provided by the embodiments of the present application is described.
[0031] It should be noted that the first node, second node and third node appearing in this application are used to refer to node identities. For the same node, when the node needs to send the IP message generated by the internal container to the outside, the node is the first node, and it can be artificially determined as the source node in the MPLS technology architecture according to the steps executed by the first node; when the node needs to forward the IP message or MPLS message to the outside, the node is the third node, and it can be artificially determined as the intermediate node in the MPLS technology architecture according to the steps executed by the third node; when the node needs to receive the IP message and forward it to the internal container, or decapsulate the MPLS message and forward it to the internal container, the node is the second node, and it can be artificially determined as the end node in the MPLS technology architecture according to the steps executed by the second node.
[0032] Figure 1 is a flow chart of a container communication method provided in an embodiment of the present application, which is applied to a first node. As shown in Figure 1 , the container communication method includes but is not limited to the following steps S101 to S104.
[0033] In step S101, the destination address information of the IP packet to be forwarded in the source container is obtained.
[0034] In step S102, a forwarding label is determined according to the destination address information.
[0035] In step S103, the IP message is encapsulated according to the forwarding label to obtain an MPLS message.
[0036] In step S104, the MPLS message is sent to the next hop node, so that the next hop node sends the MPLS message to the destination container according to the forwarding label.
[0037] It should be noted that the destination address information here is the global address information of the destination container located at the second node (ie, the end node in the MPLS technical architecture), and the source container is configured in the first node.
[0038] For the source container, when the source container needs to communicate with the destination container through the network, the source container needs to send an IP message to the destination container. Since the container is an encapsulated network inside the first node, when the destination container is configured in the second node, the source container and the destination container need to communicate across nodes, which involves the communication between nodes at the physical level. When communicating between nodes, IP ACL will be enabled, and IP ACL will intercept IP messages based on specific address information. In order to prevent the IP message sent by the source container from being affected by the IP ACL in each subsequent node during the transmission process, it is necessary to use the MPLS protocol for message transmission to avoid the IP message interception executed by IP ACL. To this end, the IP message to be sent needs to be converted into an MPLS message before the message sending and receiving at the node level can be realized.
[0039] Based on this, when the source container needs to send an IP packet to the destination container, the first node becomes the source node in the MPLS technology architecture, and the second node becomes the end node. The first node must first obtain the IP packet to be forwarded from the source container. Because the IP packet carries the destination address information indicating the destination container, the first node can extract the address information from the IP packet to obtain the destination address information.
[0040] Since the node network to which the first node and the second node belong uses MPLS technology to send and receive messages between nodes, when the node network is networked, an MPLS tunnel is established based on any two nodes as source and end nodes. For each MPLS tunnel, along the direction from the end node in the tunnel to the source node, the end node allocates a forwarding label to the source node and each intermediate node. Therefore, each node will record one or more label values corresponding to each MPLS tunnel to which it belongs in one or more tables, thereby using forwarding labels to realize the transmission and reception of MPLS messages between nodes with other nodes. It should be noted that an MPLS tunnel includes one or more Label Switched Paths (LSPs).
[0041] Based on this, the destination address information corresponding to the IP packet can be used to query the second node where the corresponding destination container is located. The next hop node is determined by querying the MPLS tunnel corresponding to the first node as the source node and the second node as the end node. The label assigned to the next hop node in the MPLS tunnel is determined as the forwarding label. This forwarding label is encapsulated into the IP packet to obtain the MPLS packet.
[0042] In MPLS technology, except for the source node and the end node, other nodes do not extract the data portion of the MPLS message or analyze the destination address information in the IP message. Therefore, the first node can directly send the MPLS message formed by the IP message to the next-hop node without considering the impact of the next-hop node's IP ACL on the IP message. This can avoid the IP ACL in the next-hop node from intercepting the IP message sent by the source container, allowing the next-hop node to continue sending the IP message to the destination container in the form of an MPLS message based on the forwarding label. After receiving the MPLS message, the second node can send the complete IP message sent by the source container to the destination container.
[0043] In the embodiment of the present application, by encapsulating the IP message of the source container into an MPLS message and sending it to the next hop node, the restrictions on the IP message of the source container set by the IP ACL set in subsequent nodes, including the next hop node, are reduced, the communication capability between containers is improved, and thus the situation of abnormal communication between containers caused by node IP ACL is reduced.
[0044] It should be noted that the IP messages here are diverse and can be IP messages of the ipv4 protocol or IP messages of the ipv6 protocol. This embodiment of the present application does not limit this.
[0045] It should be noted that the specific forms of the next hop node here are various, so that sending the MPLS message to the destination container can include but is not limited to the following embodiments.
[0046] In one embodiment, the next hop node is a second node serving as an end node, and the MPLS message is sent directly to the second hop node.
[0047] In one embodiment, the next hop node is an intermediate node, and the next hop node performs label replacement or label popping according to forwarding labels corresponding to the next two hop nodes relative to the first node, thereby sending the MPLS message to the second node.
[0048] It should be noted that the specific form of one or more label values corresponding to each MPLS tunnel to which each node record belongs is diverse, and can be the following embodiments or other embodiments, and the embodiments of the present application are not limited to this.
[0049] In one embodiment, for a certain node in a node network, the node is an edge device (Label Edge Router, LER) in the node network. At this time, the node will not serve as an intermediate node in any MPLS tunnel formed by the node network. Therefore, the node can record the label value corresponding to one or more previous-hop nodes in each MPLS tunnel in which it is the end node (i.e., the incoming label), and can record the label value corresponding to one or more next-hop nodes in each MPLS tunnel in which it is the source node (i.e., the outgoing label).
[0050] In one embodiment, for a certain node in a node network, the node belongs to a switching device (Label Switching Router, LSR) in the node network. At this time, the node can serve as an intermediate node in a part of the MPLS tunnel formed by the node network. Therefore, the node can record the label value (i.e., incoming label) corresponding to one or more previous-hop nodes in each MPLS tunnel in which it is the end node, can record the label value (i.e., outgoing label) corresponding to one or more next-hop nodes in each MPLS tunnel in which it is the source node, and can record the label value corresponding to one or more previous-hop nodes and one or more next-hop nodes in each MPLS tunnel in which it is the intermediate node.
[0051] In one embodiment, due to special needs, some nodes are set to only serve as source nodes to send MPLS messages, and other nodes need to send messages to these nodes through other network protocols. At this time, these nodes all serve as source nodes in their corresponding MPLS tunnels to communicate with other nodes. Therefore, for each of these nodes, the node can record the label value corresponding to one or more next-hop nodes in each MPLS tunnel.
[0052] In one embodiment, due to special needs, some nodes are set to only serve as end nodes to receive MPLS messages, and other nodes need to receive messages sent by these nodes through other network protocols. At this time, these nodes all serve as end nodes in their corresponding MPLS tunnels to communicate with other nodes. Therefore, for each of these nodes, the node can record the label values corresponding to one or more previous-hop nodes in each MPLS tunnel.
[0053] In one embodiment, due to special needs, some nodes are set to act only as intermediate nodes to forward MPLS messages, and the messages generated locally by the nodes need to be sent through other network protocols. At this time, these nodes act as intermediate nodes in their respective corresponding MPLS tunnels to communicate with other nodes. Therefore, for each of these nodes, the node can record the label values corresponding to one or more previous-hop nodes and one or more next-hop nodes in each MPLS tunnel.
[0054] It should be noted that the specific forms of recording label values in one or more tables are diverse. For example, multi-table recording is performed based on nodes, and all incoming label values and outgoing label values corresponding to a one-hop node are recorded in the same table; for another example, a node only has one table, and all incoming label values and outgoing label values learned by itself are recorded in the same table, etc. The embodiments of the present application are not limited to this.
[0055] It should be noted that the first node and the second node here may belong to the same local area network or different local area networks, and the following embodiments may be used depending on the local area network, but are not limited thereto.
[0056] In one embodiment, the first node and the second node are located in the same local area network, and the first node and the second node are connected to the same Layer 2 switch or the same router. After the MPLS protocol is enabled, the Layer 2 switch or router can send the MPLS message of the first node to the next hop node and filter the IP message through the configured IP ACL. It should be noted that the Layer 2 switch or router here can serve as a third node (i.e., an intermediate node) or as a directly connected device between the first node and the second node, and this embodiment of the application is not limited to this.
[0057] In one embodiment, the first node and the second node are located in different local area networks, the first node is connected to a first layer 2 switch, the second node is connected to a second layer 2 switch, the first layer 2 switch and the second layer 2 switch are connected to a layer 3 switch or a layer 3 router, and all switches and routers have the MPLS protocol enabled, thereby transmitting the MPLS message to the next hop node located in the same local area network or a different local area network until the end node (i.e., the second node) receives the MPLS message.
[0058] In one embodiment, the first node and the second node are located in different local area networks, and the first node and the second node are connected to the same router. After the MPLS protocol is enabled on the router, the MPLS message of the first node can be directly sent to the second node in the different local area network, and the IP message can be filtered through the set IP ACL.
[0059] In one embodiment, the first node and the second node are located in different local area networks (LANs), the first node is connected to a first router, the second node is connected to a second router, the first router and the second router are connected to each other or to an additional router, and all routers enable the MPLS protocol, thereby transmitting the MPLS message to the next hop node located in the same LAN or a different LAN, until the end node (i.e., the second node) receives the MPLS message.
[0060] It should be noted that the specific method of determining the forwarding label according to the destination address information is diverse, and can be the following embodiments or other embodiments, and the embodiments of the present application are not limited to this.
[0061] In one embodiment, a first node establishes a forwarding information base (FIB), a next hop label forwarding entry (NHLFE), and an incoming label map (ILM) through the MPLS protocol. For the first node serving as a source node, the first node queries the FIB table entry based on the destination address information to determine a target tunnel ID (Tunnel ID) corresponding to the destination address information. The source node in the MPLS tunnel corresponding to the target tunnel ID is the first node, and the end node is the second node. The corresponding NHLFE table entry is found based on the target tunnel ID, and the outgoing label in the corresponding NHLFE table entry is determined as a forwarding label.
[0062] Figure 2 is a flow chart of step S102 in Figure 1 according to an embodiment of the present application. As shown in Figure 2, step S102 includes but is not limited to the following sub-steps S201 and S202.
[0063] In step S201, a label forwarding table corresponding to the destination address information is obtained locally.
[0064] In step S202, the outgoing label corresponding to the next hop node is used as a forwarding label.
[0065] It should be noted that the label forwarding table here includes label forwarding path information, and the label forwarding path information includes the outgoing label corresponding to the next hop node.
[0066] It should be noted that MPLS technology requires relevant information such as outgoing interface information and incoming labels. This information can be stored in the label forwarding path information or in another table, and this is not limited in the embodiments of this application. For the sake of convenience, the following description of the embodiments of this application is based on the embodiment in which the outgoing interface information, incoming labels, and other relevant information are stored in the label forwarding path information. For the embodiment of multi-table storage, you can refer to the following embodiment and add the corresponding additional table lookup operations.
[0067] Specifically, each node in the node network stores a label forwarding table in the same format. The label forwarding path information in the label forwarding table includes information related to the tunnel ID. The first node first performs an MPLS tunnel query based on the destination address to determine the corresponding MPLS tunnel. Based on the MPLS tunnel, the node then searches the locally stored label forwarding table for information related to the tunnel ID. This determines the label forwarding table corresponding to the MPLS tunnel and uses the outgoing label included in the label forwarding path information in the table as the forwarding label.
[0068] It should be noted that the specific forms of the information related to the MPLS tunnel here are diverse, and can be the following embodiments or other embodiments, and the embodiments of the present application are not limited to this.
[0069] In one embodiment, the information related to the tunnel ID is the tunnel ID. The first node queries the FIB table to obtain the target tunnel ID of the MPLS tunnel corresponding to the case where the first node is the source node and the second node is the end node, and determines the next hop node to be used. The first node searches the locally stored label forwarding table based on the target tunnel ID and the next hop node, thereby determining the label forwarding table corresponding to both the target tunnel ID and the next hop node, and determines the outgoing label included in the label forwarding path information in the table as the forwarding label.
[0070] Because an MPLS tunnel has an unlimited number of LSPs, the first node may have one or more next-hop nodes for the same tunnel ID. Consequently, the same tunnel ID may correspond to one or more outgoing labels. The first node uses the target tunnel ID and the next-hop node used for this MPLS packet transmission to determine the unique outgoing label indicated by the target tunnel ID and the next-hop node as the forwarding label, allowing the first node to send the MPLS packet to the specified next-hop node.
[0071] In one embodiment, the information associated with the tunnel ID is network segment information, which is used to indicate the network segment allocated based on a specific node path in the node network. In this embodiment, in order to specify a specific portion or all of the transmission path used by the MPLS message in this message transmission, the specific node paths in the network are configured as the same network segment. The first node queries the FIB table to obtain the MPLS tunnel corresponding to itself as the source node and the second node as the end node, and determines the next hop node to be used. Based on the next hop node, the network segment to which it belongs is determined. Based on the network segment and the next hop node, information is retrieved from the locally stored label forwarding table to determine the label forwarding table corresponding to both the target network segment and the next hop node, and the outgoing label in the label forwarding path information in the table is determined as the forwarding label.
[0072] Since the node network is divided into one or more nodes through network segment configuration, the transmission path in the node network is relatively fixed, so that the node path contained in each LSP in MPLS is unified in the node network. Based on this, after the first node determines the network segment, since a label forwarding path information stores both the network segment information and the outgoing label, the next-hop node does not actually need to first perform a tunnel query based on the MPLS forwarding label and then determine the outgoing label. It only needs to directly query the incoming label and the network segment to which it belongs, and can directly determine the next two hop nodes relative to the first node and the outgoing labels corresponding to the next two hop nodes. In other words, in the process of the first node sending an MPLS message to the second node, the first node only needs to perform a tunnel query once, and no tunnel query is required in the subsequent MPLS message sending process.
[0073] It should be noted that in the various embodiments described above and below that utilize the label forwarding table, unlike the ILM table and NHLFE table, the label forwarding table does not record the operation type corresponding to the label. Therefore, the operation type information cannot be used to instruct the node to perform an action. Instead, the corresponding label operation is determined based on the specific label value of the forwarding label and whether the outgoing label is null. In the MPLS technical architecture, the nodes corresponding to the last hop and the last hop are assigned specific label values. The specific label values of the forwarding labels in this application follow the existing MPLS technical architecture. For the source node, since the IP packet generated by the container does not include a forwarding label, the outgoing label is not set to empty to indicate that a label push operation is performed on the IP packet. When the node finds that the forwarding label of the IP packet is empty but the outgoing label is not empty, the label is pushed on the IP packet. For the intermediate node, when the incoming label is 3 and the outgoing label is set to empty, a label pop operation is performed on the IP packet. When the node finds that the forwarding label of the IP packet is 3 and the outgoing label is empty, the label is popped on the IP packet. When the incoming label is not 3, it is not set to empty to indicate that a label swap operation is performed on the IP packet. When the node finds that the forwarding label of the IP packet is 3 but the outgoing label is not empty, the label is swapped on the IP packet. For the end node, the outgoing label is set to empty to indicate that a label pop operation is performed on the IP packet. When the node finds that the forwarding label of the IP packet is 0 and the label is empty, the label is popped on the IP packet.
[0074] The embodiment of the present application divides the LSP in the network into paths by using the network segments in which the label forwarding path information is stored, so that the MPLS message transmission of the node network is performed by querying the network segment. This enables the first node to complete the tunnel query for the entire MPLS message transmission through the network segment query, thereby improving the forwarding performance of subsequent MPLS messages, thereby improving the system throughput between the source container and the destination container.
[0075] In one embodiment, the MPLS message may be sent to the next hop node in the following manner: determining a target outbound interface according to outbound interface information, and sending the MPLS message to the next hop node according to the target outbound interface.
[0076] The embodiment of the present application uses a label forwarding table to replace the original ILM label table and NHLFE table, so that when the first node generates an MPLS message, it can determine the label by directly querying the label forwarding table without performing multiple table queries. Compared with the query scheduling of multiple tables, the embodiment of the present application can increase the query speed of the outgoing label, thereby increasing the generation speed of the MPLS message, thereby increasing the system throughput per unit time.
[0077] It should be noted that the specific sources of the label forwarding table of the first node may be various, and may be the following embodiments or other embodiments.
[0078] In one embodiment, the network to which the first node and the second node belong is a small network, and an MPLS tunnel is constructed by establishing a static LSP. A label forwarding table is constructed according to the defined MPLS tunnel, and the label forwarding table is uploaded to each node in the network.
[0079] FIG3 is a flow chart of a container communication method provided in an embodiment of the present application. In one embodiment, the first node is configured with a first node network card. As shown in FIG3, before step S101, the method also includes, but is not limited to, the following steps S301 to S305. Steps S101 to S104 in FIG3 are the same as the steps described with reference to FIG1 and are not repeated here.
[0080] In step S301, a global address configuration is performed on the first node network card to determine the global address information corresponding to the first node network card.
[0081] In step S302, global address configuration is performed for each container in the first node according to the global address information corresponding to the network card of the first node, so as to determine the global address information corresponding to each container in the first node.
[0082] In step S303, container routing learning is performed with other nodes in the domain through the Interior Gateway Protocol (IGP) to obtain global address information and routing information corresponding to the containers in other nodes in the domain.
[0083] In step S304, one or more label switching paths corresponding to the destination address information and one or more label forwarding path information corresponding to each of the one or more label switching paths are obtained according to the Label Distribution Protocol (LDP).
[0084] In step S305, a label forwarding table is constructed according to the label forwarding path information.
[0085] Before sending an IP packet to the destination container, the source container needs to know the destination address information and the MPLS tunnel between the first node and the second node in advance. First, the destination address information needs to be obtained through routing learning. During the routing learning process, the address information and routing information of other containers are also obtained. Based on this routing information, an MPLS tunnel is constructed to obtain the MPLS tunnel between the first node and the second node.
[0086] Specifically, a global address is configured for the loopback network card (Loopback) in the first node to obtain global address information corresponding to the loopback network card in the first node; a global address is configured for the first node network card according to the global address information corresponding to the loopback network card in the first node to determine the global address information corresponding to the first node network card; a global address is configured for each container in the first node according to the global address information corresponding to the first node network card to obtain global address information corresponding to each container in the first node.
[0087] Since the global addresses of the various containers of the first node are configured based on the global address information corresponding to the first node network card, the global address information corresponding to the various containers in the first node is bound to the global address information corresponding to the first node network card. Similarly, the global address information corresponding to the first node network card is bound to the global address information corresponding to the loopback network card in the first node. Due to the characteristics of the loopback network card, the global address information of the loopback network card can be used as the unique identifier of the node (Router ID), so that the global address information corresponding to the first node network card and the global address information corresponding to the various containers in the first node both carry the unique identifier of the first node.
[0088] Through the internal gateway protocol (IGP), the first node conducts container routing learning with other nodes in the domain to obtain the global address information and routing information corresponding to the containers in other nodes in the domain. In this process, the first node obtains the destination address information of the destination container through container routing learning.
[0089] After obtaining the routing information, the first node establishes an MPLS tunnel with other nodes in the domain through the label distribution protocol LDP, and obtains one or more LSPs, including one or more LSPs corresponding to the destination address information. Based on the one or more LSPs corresponding to the destination address information, one or more label forwarding path information corresponding to each of the one or more LSPs is obtained, and then a label forwarding table corresponding to the destination address information is constructed based on this label forwarding path information.
[0090] During this process, LDP distributes labels based on routes, so each route is assigned a label. However, due to the unique identifier, even if there are multiple container routes, the first node in an LSP will be assigned the same incoming label or outgoing label.
[0091] For example, assume that there are a first node, a second node, and a third node in a node network. The third node serves as an intermediate node. The first node has n source containers, and the second node has only one destination container. Theoretically, the first node would be assigned n outgoing labels due to the number of containers. However, due to the unique identifier, the first node is ultimately assigned only one outgoing label. When any source container on the first node sends an IP packet to the destination container on the second node, the outgoing label is used as the forwarding label.
[0092] In one embodiment, the internal gateway protocol IGP used by the first node is the Open Shortest Path First (OSDF) protocol, which improves the dynamic topology capability of the node network through dynamic routing learning and dynamic MPLS tunnel construction, making it easier for the node network to perform internal node changes and node internal container changes.
[0093] In one embodiment, when the label forwarding path information used by the first node includes a tunnel ID, MPLS tunnel division is performed according to the source node and the end node of each LSP, and corresponding tunnel IDs are allocated to the divided MPLS tunnels.
[0094] In one embodiment, when the label forwarding path information used by the first node includes network segments, network segments are divided according to the node paths in each LSP to obtain the network segments corresponding to each node path.
[0095] Figure 4 is a schematic diagram of the structure of the first node provided by an embodiment of the present application. In one embodiment, the source container in the first node is configured with a first container pair network card, and the first node is configured with a first network plug-in and a first node network card.
[0096] The first container pair (Veth pair) network card is configured to output the IP message of the source container; the first network plug-in is configured to encapsulate the IP message according to the forwarding label to obtain an MPLS message; and the first node network card is configured to send the MPLS message to the next hop node.
[0097] Before setting the first network plug-in, the first node network card will directly encapsulate the IP message output by the source container into other types of messages and output them externally. For example, it will encapsulate the IP message of the source container as the data portion into the IP message of the first node. During this process, it is difficult to encapsulate the IP message output by the source container into an MPLS message. Therefore, it is necessary to set the first network plug-in between the first node network card and the first container network card to implement the above embodiments.
[0098] Specifically, the first container pair of network cards includes a first container internal network card and a first container external network card. The source container's IP packet is output to the outside of the source container through the first container internal network card and input into the first node through the first container external network card. The first network plug-in creates a container network between the first container external network card and the first node network card. The first container external network card inputs the source container's IP packet into the container network, encapsulates the IP packet through the network, and outputs the encapsulated MPLS packet to the first node network card.
[0099] Figure 5 is a flow chart of a container communication method provided in an embodiment of the present application, which is applied to the second node. As shown in Figure 5, the container communication method includes but is not limited to the following steps S401 to S403.
[0100] In step S401, an MPLS message is received.
[0101] In step S402, when the label value of the forwarding label is the first label value, the label of the MPLS packet is popped to obtain an IP packet.
[0102] In step S403, the IP message is forwarded to the destination container according to the destination address information.
[0103] It should be noted that the MPLS message here includes a forwarding label, and the IP message includes destination address information. The destination address information is global address information of the destination container, and the destination container is located in the second node.
[0104] In one embodiment, each node in the node network is set to perform a label popping operation only at the last hop. After the second node receives the MPLS message from the previous node, the second node will query the forwarding label encapsulated in the MPLS message to perform the label popping action according to the label value of the forwarding label.
[0105] Specifically, when the forwarding label is the first label value, indicating that the second node is the end node in the MPLS technology architecture, the second node needs to perform a label popping operation on the MPLS packet to obtain the IP packet sent by the source container. Then, based on the destination address information carried in the IP packet, the second node forwards the IP packet to the destination container within the second node.
[0106] Because the source container's IP packet enters the second node in the form of an MPLS packet, the IP ACL set in the second node does not affect the MPLS packet. As a result, the source container's IP packet can enter the second node intact without being affected by the IP ACL set in the second node. As a result, the destination container can obtain the complete IP packet of the source container.
[0107] The embodiment of the present application receives an MPLS message encapsulated from the IP message of the source container and decapsulates it to obtain the IP message of the source container, thereby reducing restrictions on the IP message of the source container, including those imposed by the local IP ACL of the node, improving the communication capability between containers, and thus reducing communication anomalies between the source container and the destination container caused by the node IP ACL.
[0108] It should be noted that the specific form of the first label value here is diverse, determined by the IP protocol. When the IP packet sent by the source container is IPv6, the first label value is "2". When the IP packet sent by the source container is IPv4, the first label value is "0".
[0109] It should be noted that the specific forms of label popping for the MPLS message here are diverse, corresponding to the table building method of the first node, which can be the following embodiments or other embodiments, and the embodiments of this application are not limited to this.
[0110] In one embodiment, the second node establishes a FIB table, an NHLFE table, and an ILM table using the MPLS protocol. As the end node, the second node queries the corresponding ILM table based on the label value of the forwarding label. The ILM table records the label operation type for the MPLS packet. Since the label operation type corresponding to the first label value is pop, the second node directly forwards the IP packet to the destination container after popping the forwarding label.
[0111] In one embodiment, when the label forwarding path information used by the first node includes a tunnel ID, the label forwarding path information used by the second node also includes a corresponding tunnel ID. The second node is provided with an information table for recording tunnel IDs for tunnel query. The second node first performs an MPLS tunnel query based on the destination address to determine the corresponding MPLS tunnel. Based on the MPLS tunnel, the tunnel ID is retrieved from a locally stored label forwarding table to determine the label forwarding table corresponding to the MPLS tunnel.
[0112] For the second node as the end node, the forwarding label in the received MPLS message is the first label value, and the corresponding outgoing labels are all set to empty. Therefore, when the second node finds that the forwarding label is the first label value and the corresponding outgoing label is empty, it pops the label of the MPLS message to obtain an IP message.
[0113] In one embodiment, when the label forwarding path information used in the first node includes network segment information, the label forwarding path information used in the second node also includes network segment information.
[0114] Figure 6 is a flow chart of step S402 in Figure 5 according to an embodiment of the present application. As shown in Figure 6, step S402 includes but is not limited to the following sub-steps S501 to S502.
[0115] In step S501, local network segment information is obtained.
[0116] In step S502, a corresponding label forwarding table is determined locally according to the local network segment information and the first label value.
[0117] In step S503, when the outgoing label is empty, the label of the MPLS message is popped to obtain an IP message.
[0118] It should be noted that the corresponding label forwarding table here includes label forwarding path information, which includes the outgoing label corresponding to the next hop node, the network segment information corresponding to the local network segment information, and the incoming label corresponding to the first label value.
[0119] For the second node, a network segment search is performed in a locally stored label forwarding table according to the local network segment information, thereby determining one or more label forwarding tables.
[0120] If there is only one label forwarding table, it is the required label forwarding table. In this case, the second node will still search for the incoming label based on the forwarding label. Since there is only one label forwarding table, the incoming label in the label forwarding path information will definitely match the forwarding label. The second node will then query the label forwarding path information contained in the label forwarding table to determine the outgoing label stored in the label forwarding path information. If the second node finds that the corresponding outgoing label is empty, it removes the label from the MPLS packet, obtaining an IP packet.
[0121] When multiple label forwarding tables exist, the second node will filter these tables again based on the incoming label to determine the desired label forwarding table. The second node will then perform an incoming label search on these label forwarding tables based on the forwarding label to obtain the label forwarding table corresponding to the incoming label and the forwarding label. The second node will then query the label forwarding path information contained in the label forwarding table to determine the outgoing label stored in the label forwarding path information. If the second node finds that the corresponding outgoing label is empty, it removes the label from the MPLS packet to obtain the IP packet.
[0122] In the embodiment of the present application, LSPs in the network are divided into paths using the network segments in which label forwarding path information is stored, so that MPLS message transmission in the node network is performed by querying the network segments. This allows the second node to determine its operation on the forwarding label after receiving the MPLS message without performing a tunnel query, thereby improving the performance of forwarding IP messages to the destination container, thereby improving the system throughput between the source container and the destination container.
[0123] It should be noted that the specific sources of the label forwarding table of the second node here can be various, and can be the following embodiments or other embodiments.
[0124] In one embodiment, the network to which the first node and the second node belong corresponding to the first node is a small network. Similar to the first node, an MPLS tunnel is constructed by establishing a static LSP, and a label forwarding table is constructed according to the defined MPLS tunnel, and the label forwarding table is uploaded to each node in the network.
[0125] In one embodiment, the second node corresponding to the first node is configured with a second node network card. Before step S401, a global address configuration is performed on the second node network card to determine the global address information corresponding to the second node network card; a global address configuration is performed for each container in the second node based on the global address information corresponding to the second node network card to determine the global address information corresponding to each container in the second node; container routing learning is performed with other nodes in the domain through the internal gateway protocol IGP to obtain global address information and routing information corresponding to the containers in other nodes in the domain; one or more label switching paths corresponding to the destination address information and one or more label forwarding path information corresponding to the one or more label switching paths are obtained according to the label distribution protocol LDP; and one or more label forwarding tables are constructed corresponding to the one or more label forwarding path information.
[0126] Specifically, a global address is configured for the loopback network card in the second node to obtain global address information corresponding to the loopback network card in the second node; a global address is configured for the second node network card according to the global address information corresponding to the loopback network card in the second node to determine the global address information corresponding to the second node network card; a global address is configured for each container in the second node according to the global address information corresponding to the second node network card to obtain global address information corresponding to each container in the second node.
[0127] Similar to the first node, since the global address information corresponding to the second node network card is used as the basis for configuring the global addresses of each internal container, the global address information corresponding to each container in the second node is bound to the global address information corresponding to the first node network card. Similarly, the global address information corresponding to the second node network card is bound to the global address information corresponding to the loopback network card in the first node. Due to the characteristics of the loopback network card, the global address information of the loopback network card can be used as the unique identifier of the node (Router ID). This means that the global address information corresponding to the second node network card and the global address information corresponding to each container in the second node both carry the unique identifier of the second node.
[0128] Through the internal gateway protocol (IGP), the first node in the domain conducts container routing learning with other nodes in the domain to obtain the global address information and routing information corresponding to the containers in other nodes in the domain. In this process, the first node as the peer end obtains the destination address information of the destination container through container routing learning.
[0129] After the second node obtains the routing information, it constructs an MPLS tunnel with other nodes in the domain through the label distribution protocol LDP to obtain one or more LSPs. Based on the one or more LSPs corresponding to the destination address information, it obtains the corresponding label forwarding path information, and then constructs one or more label forwarding tables corresponding to the destination address information based on this label forwarding path information.
[0130] Similarly, in this process, since LDP distributes labels based on routes, each route will be distributed with a label, but due to the role of the unique identifier, the second node is allocated the same label in an LSP based on the container route.
[0131] In one embodiment, corresponding to the first node, when the IGP of the first node is the OSDF protocol, the IGP of the second node also corresponds to the OSDF protocol. Through dynamic routing learning and dynamic MPLS tunnel construction, the dynamic topology capability of the node network is improved, making it easier for the node network to perform internal node changes and node internal container changes.
[0132] In one embodiment, when the label forwarding path information used by the second node includes a tunnel ID, MPLS tunnel division is performed according to the source node and the end node of each LSP, and corresponding tunnel IDs are allocated to the divided MPLS tunnels.
[0133] In one embodiment, when the label forwarding path information used by the second node includes network segments, network segments are divided according to the node paths in each LSP to obtain the network segments corresponding to each node path.
[0134] Figure 7 is a schematic diagram of the structure of the second node provided in an embodiment of the present application. In one embodiment, the destination container is configured with a second container pair network card, and the second node is configured with a second network plug-in and a second node network card.
[0135] The second container pair network card is configured to receive an MPLS message; the second network plug-in is configured to, when the label value of the forwarding label is the first label value, pop the label of the MPLS message to obtain an IP message; the second node network card is configured to forward the IP message to the destination container according to the destination address information.
[0136] Specifically, the second container pair of network cards includes a second container internal network card and a second container external network card. The second node network card receives the MPLS message sent by the previous hop node and inputs it into the second node. The second network plug-in creates a container network between the second container external network card and the second node network card, decapsulates the MPLS message through the network, and outputs the IP message of the source container to the second container external network card. The second container external network card forwards the IP message of the source container to the second container internal network card, and the second container internal network card inputs the IP message of the source container into the destination container.
[0137] Figure 8 is a schematic diagram of the steps of a container communication method provided in an embodiment of the present application, which is applied to a third node. As shown in Figure 8, the container communication method includes but is not limited to the following steps S601 to S603.
[0138] In step S601, an MPLS message is received.
[0139] In step S602 , when the label value of the forwarding label is the second label value, a target forwarding label is determined according to the forwarding label.
[0140] In step S603, the forwarding label in the MPLS message is replaced with the target forwarding label, and the MPLS message after the label is replaced is sent to the next hop node according to the target forwarding label.
[0141] It should be noted that, in the third node, the MPLS packet includes a forwarding label and an IP packet to be forwarded to the destination container, and the destination container is configured in the second node.
[0142] In one embodiment, corresponding to the embodiment of the second node, each node in the node network is set to perform the label popping operation as the last hop. After the third node receives the MPLS message from the previous node, the third point will query the forwarding label encapsulated in the MPLS message to perform the label replacement action according to the label value of the forwarding label.
[0143] Specifically, when the forwarding label is the second label value, it indicates that the third node is an intermediate node. The third node needs to perform a label replacement action on the MPLS message and forward the MPLS message with the replaced label to the next hop node.
[0144] Because the source container's IP packet enters the third node in the form of an MPLS packet, similar to the second node, the IPACL set in the third node cannot intercept the MPLS packet. This allows the source container's IP packet to enter the third node intact without being affected by the IP ACL set in the third node, thereby allowing the source container's IP packet to be completely forwarded to the next-hop node.
[0145] The embodiment of the present application receives an MPLS message encapsulated from the IP message of the source container, replaces the forwarding label, obtains the MPLS message after the label is replaced, and sends it to the next hop node. This reduces the restrictions on the IP message of the source container, including the restrictions imposed by the local IP ACL of the node, improves the communication capability between containers, and thus reduces the situation where communication anomalies between the source container and the destination container are caused by the node IP ACL.
[0146] It should be noted that the second tag value here is a number greater than 3.
[0147] It should be noted that the specific forms of label replacement for MPLS messages here are diverse, corresponding to the table building method of the first node and the second node, which can be the following embodiments or other embodiments, and the embodiments of this application are not limited to this.
[0148] In one embodiment, a third node establishes a FIB table, an NHLFE table, and an ILM table through the MPLS protocol. For the third node as an intermediate node, the third node performs a tunnel query based on the label value of the forwarding label to obtain a corresponding ILM table, which records the tunnel ID of the corresponding MPLS tunnel. The corresponding NHLFE table is queried based on the tunnel ID. The NHLFE table records the outgoing interface, the next hop node, the outgoing label, and the label operation type, and the outgoing label is determined as the target forwarding label. Thus, the forwarding label is replaced according to the label operation type and the target forwarding label to obtain an MPLS message after the label is replaced.
[0149] In one embodiment, when the label forwarding path information used by the first and second nodes both includes a tunnel ID, and the label forwarding path information used by the third node also includes a tunnel ID, the third node similarly includes an information table for recording tunnel IDs for tunnel queries. The third node first queries the target tunnel ID corresponding to the MPLS tunnel based on the forwarding label. Based on the query target tunnel ID and the forwarding label, the third node searches a locally stored label forwarding table to determine the label forwarding table corresponding to both the target tunnel ID and the forwarding label.
[0150] For the third node serving as an intermediate node, the forwarding label in the received MPLS message is the second label value, and the corresponding outgoing labels are not set to empty. Therefore, when the third node finds that the forwarding label is the second label value and the corresponding outgoing label is not empty, it replaces the label of the MPLS message to obtain the MPLS message after the label is replaced.
[0151] In one embodiment, when the label forwarding path information used in the first node and the second node both includes network segment information, the label forwarding path information used in the third node also includes network segment information. In step S402, local network segment information is obtained; a corresponding label forwarding table is determined locally based on the local network segment information and the second label value; and the outgoing label is determined as the target forwarding label. It should be noted that the corresponding label forwarding table here includes label forwarding path information, and the label forwarding path information includes an outgoing label corresponding to the next hop node, network segment information corresponding to the local network segment information, and an incoming label corresponding to the second label value.
[0152] When the forwarding label of the MPLS packet is the second label value, it indicates that the third node is an intermediate node as defined in the MPLS technical architecture and needs to perform label replacement on the MPLS packet. The third node searches the locally stored label forwarding table based on the local network segment information to determine one or more label forwarding tables.
[0153] If there is only one label forwarding table, that table serves as the required label forwarding table. The second node will still search for incoming labels based on the forwarding label. Since there is only one label forwarding table, the incoming label in the label forwarding path information will definitely match the forwarding label. The third node will then query the label forwarding path information in the label forwarding table. If the corresponding outgoing label is not empty, the third node will determine that outgoing label as the corresponding target forwarding label.
[0154] If there are multiple label forwarding tables, the third node will filter them again based on the incoming label to determine the desired label forwarding table. The third node will then perform an incoming label search on these label forwarding tables based on the forwarding label to obtain the label forwarding table that corresponds to the incoming label and the forwarding label. The third node will then query the label forwarding path information contained in the label forwarding table. If the third node finds that the corresponding outgoing label is not empty, it will determine the outgoing label as the corresponding target forwarding label.
[0155] In the embodiment of the present application, LSPs in the network are divided into paths using network segments where label forwarding path information is stored, so that MPLS message transmission in the node network is performed by querying the network segments. This allows a third node to determine its operation on the forwarding label after receiving the MPLS message without performing a tunnel query, thereby improving the performance of forwarding IP messages to the destination container, thereby improving the system throughput between the source container and the destination container.
[0156] In an embodiment where the label forwarding path information also includes outbound interface information, the MPLS packet with the label replaced can be sent to the next hop node in the following manner: determining a target outbound interface based on the outbound interface information, and sending the MPLS packet with the label replaced to the next hop node via the target outbound interface. Specifically, the target outbound interface is determined based on outbound interface information located in the same label forwarding table as the target forwarding label, and the third node sends the MPLS packet with the label replaced to the next hop node using the target outbound interface.
[0157] It should be noted that the specific sources of the label forwarding table of the third node here can be various, and can be the following embodiments or other embodiments.
[0158] In one embodiment, the network corresponding to the first node, the second node, and the third node is a small network. The MPLS tunnel is constructed by establishing a static LSP. A label forwarding table is constructed according to the defined MPLS tunnel, and the label forwarding table is uploaded to each node in the network.
[0159] In one embodiment, the third node corresponding to the first node and the second node is configured with a third node network card. Before step S601, a global address configuration is performed on the third node network card to determine the global address information corresponding to the third node network card; a global address configuration is performed for each container in the third node according to the global address information corresponding to the third node network card to determine the global address information corresponding to each container in the third node; container routing learning is performed with other nodes in the domain through the internal gateway protocol IGP to obtain global address information and routing information corresponding to the containers in other nodes in the domain; one or more label switching paths corresponding to the destination address information and one or more label forwarding path information corresponding to the one or more label switching paths are obtained according to the label distribution protocol LDP; and one or more label forwarding tables are constructed according to the one or more label forwarding path information.
[0160] Specifically, a global address is configured for the loopback network card in the third node to obtain global address information corresponding to the loopback network card in the third node; a global address is configured for the network card of the third node according to the global address information corresponding to the loopback network card in the third node to determine the global address information corresponding to the network card of the third node; a global address is configured for each container in the third node according to the global address information corresponding to the network card of the third node to obtain global address information corresponding to each container in the third node.
[0161] Since the global addresses of each internal container are configured based on the global address information corresponding to the third-node network card, the global address information corresponding to each container in the third node is bound to the global address information corresponding to the third-node network card. Similarly, the global address information corresponding to the third-node network card is bound to the global address information corresponding to the loopback network card in the third node. Due to the characteristics of the loopback network card, the global address information of the loopback network card can be used as the unique identifier of the node (Router ID). This means that the global address information corresponding to the third-node network card and the global address information corresponding to each container in the third node both carry the unique identifier of the third node.
[0162] Through the internal gateway protocol (IGP), the third node conducts container routing learning with other nodes in the domain to obtain the global address information and routing information corresponding to the containers in other nodes in the domain. In this process, the third node obtains the destination address information of the destination container through container routing learning.
[0163] After obtaining the routing information, the third node constructs an MPLS tunnel with other nodes in the domain through the label distribution protocol LDP, obtains one or more LSPs, and obtains the corresponding label forwarding path information based on the one or more LSPs corresponding to the destination address information, thereby constructing one or more label forwarding tables corresponding to the destination address information based on this label forwarding path information.
[0164] Similarly, in this process, since LDP distributes labels based on routes, each route will be distributed with a label, but due to the role of the unique identifier, the third node is allocated the same label in an LSP based on the container route.
[0165] In one embodiment, corresponding to the first node and the second node, when the IGP of the first node and the second node is the OSDF protocol, the IGP of the third node also corresponds to the OSDF protocol. Through dynamic routing learning and dynamic MPLS tunnel construction, the dynamic topology capability of the node network is improved, making it easier for the node network to perform internal node changes and node internal container changes.
[0166] In one embodiment, when the label forwarding path information used by the third node includes a tunnel ID, MPLS tunnel division is performed according to the source node and the end node of each LSP, and corresponding tunnel IDs are allocated to the divided MPLS tunnels.
[0167] In one embodiment, when the label forwarding path information used by the third node includes network segments, network segments are divided according to the node paths in each LSP to obtain the network segments corresponding to each node path.
[0168] Figure 9 is a schematic diagram of the steps of the container communication method provided in an embodiment of the present application. As shown in Figure 9, after step S601, the container communication method also includes, but is not limited to, the following steps S701 to S703. Step S601 in Figure 9 is the same as step S601 described with reference to Figure 8 and will not be repeated here.
[0169] In step S701, when the label value of the forwarding label is the third label value, the label of the MPLS packet is popped to obtain an IP packet.
[0170] In step S702, a first configuration message and a second configuration message are generated.
[0171] In step S703, the first configuration message, the IP message, and the second configuration message are sent to the second node one by one according to the destination address information.
[0172] It should be noted that the IP message obtained here includes destination address information, which is address information of a destination container, and the destination container is configured in the second node.
[0173] It should be noted that the first configuration message is used to add configuration information to the access control list ACL in the second node so that the second node receives the IP message, and the second configuration message is used to delete the configuration information.
[0174] Note that the third tag value here is 3.
[0175] In one embodiment, when the forwarding label value is a third label value, it indicates that the third node is an intermediate node that is the previous hop of the second node. Due to the description of the third label value, the third node needs to perform a label popping operation locally in order to forward the IP packet to the second node.
[0176] At this time, there will be a situation where the MPLS message is forwarded to the third node, but the ACL of the second node denies the IP message of the third node, which makes it impossible for the IP message of the source container to be sent directly to the second node.
[0177] To this end, a first configuration message and a second configuration message in a different IP message format are generated, so that the IP message of the source container can be sent to the second node.
[0178] Specifically, when the label value of the forwarding label is the third label value, the MPLS message is label popped to obtain an IP message. A first configuration message and a second configuration message, which are different from the IP message format, are generated according to the ACL of the second node. The first configuration message is then sent to the second node to instruct the second node to add an ACL to allow the IP message to enter the second node. At this time, the IP message of the source container is sent to the second node, and then the second configuration message is sent to the second node to delete the previously added ACL, thereby maintaining the original ACL effect of the second node.
[0179] In the embodiment of the present application, the ACL in the second node is modified through the first configuration message and the second configuration message, so that a receiving window can be created in the second node to receive the IP message of the source container sent by the third node, while maintaining the effect of the original ACL.
[0180] Figure 10 is a schematic diagram of the structure of the third node provided in an embodiment of the present application. In one embodiment, the third node is configured with a third network plug-in and a third node network card.
[0181] In one embodiment, the third node network card is configured to receive an MPLS message and send the MPLS message with the label replaced to the next hop node according to the target forwarding label; the third network plug-in is configured to, when the label value of the forwarding label is the second label value, determine the target forwarding label according to the forwarding label, and replace the forwarding label in the MPLS message with the target forwarding label.
[0182] Specifically, the third-node network card receives the MPLS message sent by the previous-hop node and inputs it into the third node. The third network plug-in creates a container network in the third node, and replaces the label of the MPLS message through the network, thereby replacing the label of the received MPLS message, and then outputs the MPLS message with the replaced label to the third-node network card. The third-node network card sends the MPLS message with the replaced label according to the next set of information corresponding to the target forwarding label and the output interface information.
[0183] In one embodiment, the third node network card is configured to receive an MPLS message and send the MPLS message with the label replaced to the next hop node according to the target forwarding label; the third network plug-in is configured to, when the label value of the forwarding label is the second label value, determine the target forwarding label according to the forwarding label, and replace the forwarding label in the MPLS message with the target forwarding label.
[0184] Specifically, the third-node network card receives the MPLS message sent by the previous-hop node and inputs it into the third node. The second network plug-in creates a container network in the third node, and replaces the label of the MPLS message through the network, thereby replacing the label of the received MPLS message. The MPLS message with the replaced label is then output to the third-node network card. The third-node network card sends the MPLS message with the replaced label based on the next set of information and outbound interface information corresponding to the target forwarding label. It should be noted that if no container is set in the third node, the third container pair network card is not set. If a container is set in the third node, the third container pair network card is configured. When the third node can be configured with a third container pair network card, the received MPLS message is not affected by the third container pair network card.
[0185] Figure 11 is a flow chart of a container communication method provided by a general embodiment of the present application. Specifically, a first node obtains the destination address information of an IP packet to be forwarded in a source container; determines a forwarding label based on the destination address information; encapsulates the IP packet based on the forwarding label to obtain an MPLS packet; and sends the MPLS packet to a third node, which then sends the MPLS packet to the destination container based on the forwarding label.
[0186] The third node receives the MPLS message; when the label value of the forwarding label is the second label value, determines the target forwarding label according to the forwarding label; replaces the forwarding label in the MPLS message with the target forwarding label, and sends the MPLS message after the label is replaced to the second hop node according to the target forwarding label.
[0187] The second node receives the MPLS message; when the label value of the forwarding label is the first label value, the label of the MPLS message is popped to obtain an IP message; and the IP message is forwarded to the destination container according to the destination address information.
[0188] The present application also provides an electronic device comprising a memory and a processor, wherein the memory stores a computer program, and the processor implements the container communication method described above when executing the computer program. The electronic device can be any smart terminal, such as a tablet computer or an in-vehicle computer.
[0189] FIG12 is a schematic diagram of the structure of an electronic device provided by an embodiment of the present application. As shown in FIG12 , the electronic device 1200 includes a processor 1201 , a memory 1202 , an input / output interface 1203 , a communication interface 1204 , and a bus 1205 .
[0190] The processor 1201 can be implemented using a general-purpose CPU (Central Processing Unit), a microprocessor, an application-specific integrated circuit (ASIC), or one or more integrated circuits, and is used to execute relevant programs to implement the technical solutions provided in the embodiments of the present application.
[0191] The memory 1202 can be implemented in the form of a read-only memory (ROM), a static storage device, a dynamic storage device, or a random access memory (RAM). The memory 1202 can store an operating system and other application programs. When the technical solutions provided in the embodiments of this specification are implemented through software or firmware, the relevant program code is stored in the memory 1202 and is called by the processor 1201 to execute the container communication method of the embodiments of this application.
[0192] The input / output interface 1203 is used to implement information input and output.
[0193] The communication interface 1204 is used to realize communication interaction between this device and other devices. Communication can be achieved through wired means (such as USB, network cable, etc.) or wireless means (such as mobile network, WIFI, Bluetooth, etc.).
[0194] The bus 1205 transmits information between various components of the device (eg, the processor 1201 , the memory 1202 , the input / output interface 1203 , and the communication interface 1204 ).
[0195] The processor 1201 , the memory 1202 , the input / output interface 1203 and the communication interface 1204 are communicatively connected to each other within the device via a bus 1205 .
[0196] An embodiment of the present application further provides a computer-readable storage medium, which stores a computer program. When the computer program is executed by a processor, the above-mentioned container communication method is implemented.
[0197] The memory, as a non-transient computer-readable storage medium, can be used to store non-transient software programs and non-transient computer executable programs. In addition, the memory may include a high-speed random access memory and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In some embodiments, the memory may optionally include a memory remotely arranged relative to the processor, and these remote memories may be connected to the processor via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0198] The embodiments described in the embodiments of this application are intended to more clearly illustrate the technical solutions of the embodiments of this application and do not constitute a limitation on the technical solutions provided by the embodiments of this application. Those skilled in the art will appreciate that with the evolution of technology and the emergence of new application scenarios, the technical solutions provided in the embodiments of this application are also applicable to similar technical problems.
[0199] Those skilled in the art will understand that the technical solutions shown in the figures do not constitute a limitation on the embodiments of the present application, and may include more or fewer steps than shown in the figures, or a combination of certain steps, or different steps.
[0200] The technical features of the above embodiments can be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0201] In the embodiments of the present application, "at least one" refers to one or more, and "more" refers to two or more. "And / or" describes the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent the situation where A exists alone, A and B exist at the same time, or B exists alone. Among them, A and B can be singular or plural. The character " / " generally indicates that the previous and next associated objects are in an "or" relationship. "At least one of the following" and similar expressions refer to any combination of these items, including any combination of single or plural items. For example, at least one of a, b and c can mean: a exists alone, b exists alone, c exists alone, a and b exist at the same time, a and c exist at the same time, b and c exist at the same time, or a, b and c exist at the same time, wherein a, b, c can be single or multiple.
[0202] In the embodiments of the present application, "indication" may include direct indication and indirect indication, and may also include explicit indication and implicit indication. The information indicated by a certain information is called information to be indicated. In the specific implementation process, there may be many ways to indicate the information to be indicated, such as but not limited to, the information to be indicated may be directly indicated, such as indicating the information to be indicated itself or the index of the information to be indicated. The information to be indicated may also be indirectly indicated by indicating other information, wherein the other information is associated with the information to be indicated. It is also possible to indicate only a part of the information to be indicated, while the other parts of the information to be indicated are known or agreed in advance. For example, the indication of specific information may also be achieved by means of the arrangement order of each information agreed in advance (such as specified in the protocol), thereby reducing the indication overhead to a certain extent.
[0203] In the embodiments of this application, each term and English abbreviation is provided for convenience of description and shall not constitute any limitation to this application. This application does not exclude the possibility of defining other terms that can achieve the same or similar functions in existing or future agreements.
[0204] In the embodiments of this application, the terms "first," "second," and "third" are used for descriptive purposes only and should not be understood to indicate or imply relative importance or implicitly specify the number of the technical features indicated. Therefore, a feature specified as "first," "second," or "third" may explicitly or implicitly include one or more of the features.
[0205] The above-described embodiments merely represent several implementation methods of the present application. While the descriptions are relatively specific and detailed, they should not be construed as limiting the scope of the present application. It should be noted that a person skilled in the art may make various modifications and improvements without departing from the scope of the present application, and all such modifications and improvements fall within the scope of protection of the present application.
Claims
1. A container communication method, which is applied to a first node, and the method includes: Obtain the destination address information of the IP packet to be forwarded in the source container, where the destination address information is the global address information of the destination container located in the second node, and the source container is configured in the first node; Determine a forwarding label according to the destination address information; Encapsulate the IP packet according to the forwarding label to obtain an MPLS packet; and Send the MPLS packet to the next-hop node, so that the next-hop node sends the MPLS packet to the destination container according to the forwarding label.
2. The method according to claim 1, wherein, Determining a forwarding label according to the destination address information includes: Obtain a label forwarding table corresponding to the destination address information locally, where the label forwarding table includes label forwarding path information, and the label forwarding path information includes an output label corresponding to the next-hop node; and Use the output label corresponding to the next-hop node as the forwarding label.
3. The method according to claim 2, wherein The first node is configured with a first node network card, and Wherein, before obtaining the destination address information of the IP packet to be forwarded in the source container, the method further includes: Perform global address configuration on the first node network card to determine the global address information corresponding to the first node network card; Perform global address configuration on each container in the first node according to the global address information corresponding to the first node network card to determine the global address information corresponding to each container in the first node; Perform container route learning with other nodes in the domain through an Interior Gateway Protocol (IGP) to obtain the global address information and routing information of the containers in other nodes in the domain; Obtain one or more label switching paths corresponding to the destination address information according to the Label Distribution Protocol (LDP), and one or more label forwarding path information corresponding to each of the one or more label switching paths; and Construct the label forwarding table according to the label forwarding path information.
4. The method according to claim 3, wherein, The label forwarding path information further includes: input label, network segment information, and output interface information, and Wherein, sending the MPLS packet to the next-hop node includes: Determine a target output interface according to the output interface information, and send the MPLS packet to the next-hop node through the target output interface.
5. According to the method as claimed in any one of claims 1 to 4, wherein The source container is configured with a first container pair network card, the first node is configured with a first network plugin and a first node network card; The first container pair network card is configured to output the IP packet of the source container; The first network plugin is configured to encapsulate the IP packet according to the forwarding label to obtain the MPLS packet; The first node network card is configured to send the MPLS packet to the next-hop node.
6. A container communication method, which is applied to a second node, and the method includes: Receive an MPLS packet, where the MPLS packet includes a forwarding label; When the label value of the forwarding label is the first label value, perform label pop on the MPLS packet to obtain an IP packet, where the IP packet includes destination address information, and the destination address information is the global address information of the destination container, and the destination container is located in the second node; and Forward the IP packet to the destination container according to the destination address information.
7. The method according to claim 6, wherein, When the label value of the forwarding label is the first label value, performing label pop on the MPLS packet to obtain an IP packet includes: Obtain local network segment information; Determine a corresponding label forwarding table locally according to the local network segment information and the first label value, where the label forwarding table includes label forwarding path information, and the label forwarding path information includes an output label corresponding to the next-hop node, network segment information corresponding to the local network segment information, and an input label corresponding to the first label value; and When the output label is empty, perform label pop on the MPLS packet to obtain an IP packet.
8. The method according to claim 7, wherein The second node is configured with a second node network card, and Wherein, before receiving the MPLS packet, the method further includes: Perform global address configuration on the second node network card to determine the global address information corresponding to the second node network card; Perform global address configuration for each container in the second node according to the global address information corresponding to the second node network card to determine the global address information corresponding to each container in the second node; Perform container route learning with other nodes in the domain through the Interior Gateway Protocol (IGP) to obtain the global address information and routing information corresponding to the containers in other nodes in the domain; Obtain one or more label switching paths corresponding to the destination address information according to the Label Distribution Protocol (LDP), and one or more label forwarding path information corresponding to one or more of the label switching paths; and Construct one or more of the label forwarding tables according to one or more of the label forwarding path information.
9. The method according to any one of claims 6 to 8, wherein The destination container is configured with a second container pair network card, the second node is configured with a second network plugin and a second node network card; The second node network card is configured to receive the MPLS packet; The second network plugin is configured to perform label pop on the MPLS packet to obtain the IP packet when the label value of the forwarding label is the first label value; The second container pair network card is configured to forward the IP packet to the destination container according to the destination address information.
10. A container communication method, which is applied to a third node, and the method includes: Receive an MPLS packet, where the MPLS packet includes a forwarding label and an IP packet to be forwarded to a destination container, and the destination container is configured in a second node; When the label value of the forwarding label is the second label value, determine a target forwarding label according to the forwarding label; and Replace the forwarding label in the MPLS packet with the target forwarding label, and send the MPLS packet after replacing the label to the next-hop node according to the target forwarding label.
11. The method according to claim 10, wherein, When the label value of the forwarding label is the second label value, determining a target forwarding label according to the forwarding label includes: Obtaining local network segment information; Determining a corresponding label forwarding table locally according to the local network segment information and the second label value, where the label forwarding table includes label forwarding path information, and the label forwarding path information includes an output label corresponding to a next-hop node, network segment information corresponding to the local network segment information, and an input label corresponding to the second label value; and Determining the output label as the target forwarding label.
12. The method according to claim 11, wherein, The third node is configured with a third node network card, the IP packet includes destination address information, and Wherein, before receiving the MPLS packet, the method further includes: Performing global address configuration on the third node network card to determine the global address information corresponding to the third node network card; Performing global address configuration for each container in the third node according to the global address information corresponding to the third node network card to determine the global address information corresponding to each container in the third node; Performing container route learning with other nodes in the domain through an Interior Gateway Protocol (IGP) to obtain the global address information and routing information corresponding to the containers in other nodes in the domain; Obtaining one or more label switching paths corresponding to the destination address information according to the Label Distribution Protocol (LDP), and one or more label forwarding path information corresponding to one or more of the label switching paths; and Constructing one or more of the label forwarding tables according to one or more of the label forwarding path information.
13. The method according to claim 11, wherein, The label forwarding path information further includes: output interface information, and Wherein, sending the MPLS packet after replacing the label to the next-hop node according to the target forwarding label includes: Determining a target output interface according to the output interface information, and sending the MPLS packet after replacing the label to the next-hop node through the target output interface.
14. The method according to claim 10, wherein, After receiving the MPLS packet, the method further includes: When the label value of the forwarding label is the third label value, performing label pop-up on the MPLS packet to obtain an IP packet, where the IP packet includes destination address information, and the destination address information is the address information of the destination container, and the destination container is configured in the second node; Generating a first configuration packet and a second configuration packet, where the first configuration packet is used to add configuration information to an IP access control list in the second node to enable the second node to receive the IP packet, and the second configuration packet is used to delete the configuration information; and Sending the first configuration packet, the IP packet, and the second configuration packet to the second node one by one according to the destination address information.
15. According to the method as claimed in any one of claims 10 to 14, wherein, The third node is further configured with a third network plugin and a third node network card; The third node network card is configured to receive the MPLS packet, and the third network plugin is configured to perform one of the following: When the label value of the forwarding label is the second label value, determining a target forwarding label according to the forwarding label, and replacing the forwarding label in the MPLS packet with the target forwarding label; Alternatively, when the label value of the forwarding label is the third label value, pop the label from the MPLS packet to obtain the IP packet, and generate the first configuration packet and the second configuration packet; the third node network card is further configured to perform one of the following: send the MPLS packet after replacing the label to the next-hop node according to the target forwarding label; or, send the first configuration packet, the IP packet, and the second configuration packet to the second node one by one according to the destination address information.
16. An electronic device, comprising: A memory and a processor, where the memory stores a computer program, and the processor implements the method according to claims 1 to 15 when executing the computer program.
17. A computer-readable storage medium having a computer program stored thereon, characterized in that, The computer program, when executed by the processor, implements the method according to any one of claims 1 to 15.
Citation Information
Patent Citations
Method for forwarding message in data center network and related device
CN112152924A
Dual-stack cross-node communication method and system for container cloud platform
CN116132435A
Signaling private context forwarding tables for a private forwarding layer
US20180351857A1