IP Library Granted Patent US 12,231,398
Granted Patent B2
US 12,231,398 · App. 17/684,160 · Granted Feb 18, 2025

Per-namespace IP address management method for container networks

Inventors: Qiang Tang (Beijing, CN); Zhaoqian Xiao (Beijing, CN)
Assignee: VMware LLC
H04L61/5061G06F9/45558H04L12/4633H04L12/4641H04L12/66H04L49/70H04L61/2592H04L67/133G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,231,398
App. No.
17/684,160
Granted
Feb 18, 2025
Kind
B2
Abstract

Some embodiments of the invention provide a method of sending data in a network that includes multiple worker nodes, each worker node executing at least one set of containers, a gateway interface, and a virtual local area network (VLAN) tunnel interface. The method configures the gateway interface of each worker node to associate the gateway interface with multiple subnets. Each subnet is associated with a namespace, a first worker node executes a first set of containers of a first namespace, and a second worker node executes a second set of containers of the first namespace and a third set of containers of a second namespace. The method sends data between the first set of containers and the second set of containers through a VLAN tunnel between the first and second worker nodes.

Claims (35)

1. A method of sending data in a network comprising a plurality of worker nodes, each worker node executing at least one set of containers, a gateway interface, and a virtual local area network (VLAN) tunnel interface, the method comprising:

configuring the gateway interface of each worker node to associate the gateway interface with a plurality of subnets, wherein (i) each subnet is associated with a namespace, (ii) a first worker node executes a first set of containers of a first namespace, and (iii) a second worker node executes a second set of containers of the first namespace and a third set of containers of a second namespace;

sending data between the first set of containers and the second set of containers through a VLAN tunnel between the first and second worker nodes; and sending data between the first set of containers and the third set of containers through the gateway interface;

assigning a static IP address to the first set of containers by storing the static IP address in a configuration file of the first set of containers; and

migrating the first set of containers from the first worker node to the second worker node while maintaining the static IP address of the set of contain.

2. The method of claim 1 , wherein sending data between the first set of containers and the third set of containers through the gateway comprises sending the data from the gateway of the first worker node through the VLAN interface of the first worker node and through the VLAN interface of the second worker node.

3. The method of claim 1 , wherein sending data between the first and second sets of containers through the VLAN tunnel comprises (i) performing layer 2 (L2) lookups to reach the VLAN interfaces of the first and second worker nodes and (ii) encapsulating the data at the VLAN interfaces of the first and second worker nodes.

4. The method of claim 3 , wherein encapsulating data at the VLAN interfaces comprises encapsulating the data with a Geneve tunnel header.

5. The method of claim 1 , wherein the VLAN tunnel interface and the gateway interface are interfaces of a virtual switch.

6. The method of claim 5 , wherein the virtual switch further comprises a virtual Ethernet interface associated with each set of containers.

7. The method of claim 6 further comprising sending data between the second set of containers and the third set of containers through the virtual Ethernet interface associated with the second set of containers, the gateway of the second worker node, and the virtual Ethernet interface associated with third set of containers.

8. The method of claim 7 , wherein the second worker node further executes a fourth set of containers of the first namespace, the method further comprising sending data between the second set of containers and the fourth set of containers through the virtual Ethernet interface associated with the second set of containers and the virtual Ethernet interface associated with third set of containers, but not the gateway of the second worker node.

9. The method of claim 1 , wherein the first set of containers execute within a first pod of the first namespace on the first worker node, the second set of containers execute within a second pod of the first namespace on the second worker node, and the third set of containers execute within a third pod of the second namespace on the second worker node.

10. The method of claim 1 , wherein each namespace is assigned a set of IP addresses.

11. The method of claim 10 , wherein:

the first namespace is assigned a first set of IP address;

the second namespace is assigned a second set of IP addresses; and

the first set of IP addresses has a different number of IP addresses than the second set of IP addresses.

12. The method of claim 10 , wherein a fourth set of containers of the first namespace is instantiated on the first worker node, the method further comprising:

sending, from a network interface of the first worker node, a remote procedure call (RPC) request to a server of the network; and in response to the RPC, receiving an IP address for the fourth set of containers from the first set of IP addresses assigned to the first namespace.

13. The method of claim 12 , wherein the received IP address is assigned to the fourth set of containers by an IP address management interface of the first worker node.

14. The method of claim 1 , wherein the network is an Antrea Kubernetes network.

15. A non-transitory machine readable medium storing a program for execution by a set of processing units, the program for sending data in a network comprising a plurality of worker nodes, each worker node executing at least one set of containers, a gateway interface, and a virtual local area network (VLAN) tunnel interface, the program comprising sets of instructions for:

configuring the gateway interface of each worker node to associate the gateway interface with a plurality of subnets, wherein (i) each subnet is associated with a namespace, (ii) a first worker node executes a first set of containers of a first namespace, and (iii) a second worker node executes a second set of containers of the first namespace and a third set of containers of a second namespace;

sending data between the first set of containers and the second set of containers through a VLAN tunnel between the first and second worker nodes; and

sending data between the first set of containers and the third set of containers through the gateway interface;

assigning a static IP address to the first set of containers by storing the static IP address in a configuration file of the first set of containers; and

migrating the first set of containers from the first worker node to the second worker node while maintaining the static IP address of the set of contain.

16. The non-transitory machine readable medium of claim 15 , wherein the set of instructions for sending data between the first set of containers and the third set of containers through the gateway comprises a set of instructions for sending the data from the gateway of the first worker node through the VLAN interface of the first worker node and through the VLAN interface of the second worker node.

17. The non-transitory machine readable medium of claim 15 , wherein:

the VLAN tunnel interface and the gateway interface are interfaces of a virtual switch that further comprises a virtual Ethernet interface associated with each set of containers; and

the program further comprises a set of instructions for sending data between the second set of containers and the third set of containers through the virtual Ethernet interface associated with the second set of containers, the gateway of the second worker node, and the virtual Ethernet interface associated with third set of containers.

18. The non-transitory machine readable medium of claim 15 ,

wherein: each namespace is assigned a set of IP addresses, the first namespace is assigned a first set of IP addresses; the second namespace is assigned a second set of IP addresses; and

the first set of IP addresses has a different number of IP addresses than the second set of IP addresses.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 1, 2022
From: TANG, QIANG; XIAO, ZHAOQIAN
To: VMWARE, INC.
Reel/Frame 059138/0621 →