25-07-2023 дата публикации
Номер: CN116488945A
Принадлежит:
The invention discloses a container network isolation method and system, and the method comprises the steps: creating a self-defined Network Policy resource under k8s, and filling a k8s Kind, namespace and name which are effective, so as to achieve the effective operation of a corresponding pod, and storing the k8s Kind, namespace and name in the k8s Kind, namespace and name in the k8s Kind, namespace and name in the k8s Kind, namespace and name in the k8s Kind. The method comprises the following steps: in a user mode program, monitoring the change of a Network Policy resource, and issuing an iptables nfquery rule to an effective pod kernel network protocol stack; the iptables nfquery rule is added at a first position after the traffic is popped out and is used for intercepting a data packet sent by an application program in a container; in the user mode program, the intercepted data packet is obtained, and after analysis is completed, an analyzed processing result is returned to nfquery ...
Подробнее