Disaster recovery method for VPN service in cloud environment, product, equipment and medium
By synchronizing and updating the control plane data and address mapping relationship of the cloud management platform during the switching of the cloud management environment, the address adaptation problem of VPN gateway nodes during the switching of the cloud management environment is solved, and the continuity and stability of VPN services are achieved.
Patent Information
- Application Number
- CN202510838393.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-07-22
- Estimated Expiration
- 2045-06-23
AI Technical Summary
In the cloud environment VPN service, the VPN gateway node cannot adapt to address changes when switching the cloud environment, resulting in the VPN service interruption.
Periodically synchronize the control plane data of the cloud management main environment to the cloud management backup environment, destroy the main environment service and start the backup environment service after meeting the preset switching conditions, update the message queue and OVN-SB physical address collection to ensure that the VPN gateway node communicates with the new environment through logical addresses.
Reduce data synchronization time during switching, improve recovery efficiency, ensure the continuity and stability of VPN services, and adapt to cloud management environment address changes.
Smart Images

Figure CN120358242A_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud computing technology, and particularly to a disaster recovery method, product, device and medium for cloud environment VPN services. Background Art
[0002] With the development of cloud computing, enterprises' demand for cloud environment VPN services has been increasing continuously. However, cloud environment VPN (Virtual Private Network, a technology for establishing a dedicated data communication network using a public network) services face many challenges, including network failures, data loss, and security threats, etc. To solve these problems, cloud environment VPN services need to have strong disaster recovery capabilities to ensure the reliability and security of the services.
[0003] When the cloud management environment undergoes a switch, the cloud management address changes and cannot be used. Then, the message queue of the cloud management platform and the OVN-SB VPN gateway node also change their addresses, and the VPN gateway node will cause the VPN service to be unable to be used normally due to the change of the environment address.
[0004] It can be seen that when the cloud management environment undergoes a switch, how to enable the VPN gateway node to adapt to the change of the cloud management environment address so that the VPN service can still be carried out between the VPN gateway node and the new cloud management main environment is a problem that those skilled in the art need to solve. Summary of the Invention
[0005] The purpose of the embodiments of the present invention is to provide a disaster recovery method, device, equipment and medium for cloud environment VPN services, so that when the cloud management environment undergoes a switch, the VPN gateway node can adapt to the change of the cloud management environment address to realize that the VPN service can still be carried out between the VPN gateway node and the new cloud management main environment. The specific solutions are as follows: In the first aspect, the present invention discloses a disaster recovery method for cloud environment VPN services, including: Periodically synchronize the control plane data of the cloud management main environment in the cloud management platform to the cloud management standby environment; When the cloud management platform currently meets the preset cloud environment switch condition, start the disaster recovery switch process of the cloud management platform; Destroy the cloud management service of the cloud management main environment and start the cloud management service of the cloud management standby environment to switch the cloud management standby environment to the new cloud management main environment; Drift the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management main environment, and update the set of OVN-SB physical addresses recorded in the VPN gateway node based on the set of physical addresses of each management node in the new cloud management main environment; Control the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue and the set of OVN-SB physical addresses, so as to provide VPN services between the VPN gateway node and the new cloud management main environment.
[0006] Optionally, the disaster recovery method for the cloud environment VPN service further includes: Deploy a cloud management main environment and a cloud management standby environment in the cloud management platform; wherein, the number of nodes, operating system, and hardware configuration of the cloud management main environment and the cloud management standby environment are the same; Configure the physical addresses, Secure Shell (SSH) protocol ports, and login credentials of the cloud management main environment and the cloud management standby environment.
[0007] Optionally, the disaster recovery method for the cloud environment VPN service further includes: When a cloud environment switching instruction is obtained through a preset user instruction issuing interface, or when it is monitored that the operating state of the cloud management main environment is an abnormal state, it is determined that the cloud management platform currently meets the preset cloud environment switching conditions.
[0008] Optionally, starting the cloud management service of the cloud management standby environment to switch the cloud management standby environment to the new cloud management main environment includes: If the number of cloud management standby environments is multiple, select a target cloud management standby environment from the multiple cloud management standby environments, and start the cloud management service of the target cloud management standby environment to switch the target cloud management standby environment to the new cloud management main environment; Wherein, the target cloud management standby environment corresponds to the standby environment instruction obtained through the preset user instruction issuing interface, or the target cloud management standby environment is the cloud management standby environment selected according to the load status of each cloud management standby environment.
[0009] Optionally, drifting the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management main environment includes: Drift the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management main environment through the underlying network component of the cloud management platform; wherein, the underlying network component is any one of a load balancer, a virtual router, and a floating logical address manager.
[0010] Optionally, drifting the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management main environment through the underlying network component of the cloud management platform includes: Change the first mapping relationship between the logical address of the message queue in the cloud management platform and the physical address of the original cloud management main environment to the second mapping relationship between the logical address of the message queue and the physical address of the new cloud management main environment through the underlying network component of the cloud management platform.
[0011] Optionally, updating the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management main environment includes: Query the currently managed VPN gateway node in the virtual switch database of the new cloud management main environment; wherein, the VPN gateway node includes a VPN proxy component of the Neutron virtual network. Change the OVN-SB physical address set recorded in the VPN proxy component to the physical address set of each management node in the new cloud management main environment through the disaster recovery service in the new cloud management main environment.
[0012] Optionally, controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue and the OVN-SB physical address set includes: Control the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management main environment through the OVN-SB physical address set. If the identification information of the VPN proxy component is queried in the Neutron component of the new cloud management main environment, control the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue.
[0013] Optionally, the step of if the identification information of the VPN proxy component is queried in the Neutron component of the new cloud management main environment, then controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue includes: Query whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management main environment. If the identification information of the VPN proxy component exists in the Neutron component, control the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue. If the identification information of the VPN proxy component does not exist in the Neutron component, determine the current retry count. If the current retry count is less than the first preset threshold, based on the delayed retry mechanism, re-jump to the step of querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management main environment, and update the current retry count.
[0014] Optionally, controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue includes: Controlling the VPN gateway node to obtain the VPN configuration information sent by the new cloud management main environment through the logical address of the message queue, so that the VPN gateway node forwards the VPN configuration information to the IPsec component; wherein, the VPN configuration information is the configuration information generated by the Neutron component in the new cloud management main environment.
[0015] Optionally, controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management main environment through the set of OVN-SB physical addresses includes: Controlling the VPN gateway node to establish a communication link with the OVN-SB in the new cloud management main environment through the set of OVN-SB physical addresses, and controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link.
[0016] Optionally, controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link includes: Querying whether there is a chassis_private table in the OVN-SB; wherein, the chassis_private table is used to store private configuration information related to physical hosts; If the chassis_private table does not exist in the OVN-SB and the current query count is not greater than the second preset threshold, then based on the delay retry mechanism, jump back to the step of querying whether there is a chassis_private table in the OVN-SB until the current query count is greater than the second preset threshold; If the chassis_private table exists in the OVN-SB, then control the VPN proxy component in the VPN gateway node to add the identification information of the VPN proxy component to the chassis_private table through the communication link.
[0017] In a second aspect, the present invention discloses a computer program product, including computer programs / instructions, which when executed by a processor implement the steps of the disaster recovery method for cloud environment VPN services disclosed above.
[0018] In a third aspect, the present invention discloses an electronic device, including: A memory for storing computer programs; A processor for executing a computer program to implement the steps of the disaster recovery method for the cloud environment VPN service disclosed above.
[0019] In a fourth aspect, the present invention discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the disaster recovery method for the cloud environment VPN service disclosed above are implemented.
[0020] It can be seen that the present invention periodically synchronizes the control plane data of the main cloud management environment in the cloud management platform to the standby cloud management environment; when the cloud management platform currently meets the preset cloud environment switching condition, the disaster recovery switching process of the cloud management platform is started; the cloud management service of the main cloud management environment is destroyed, and the cloud management service of the standby cloud management environment is started to switch the standby cloud management environment to the new main cloud management environment; the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform is drifted based on the physical address of the new main cloud management environment, and the OVN-SB physical address set recorded in the VPN gateway node is updated based on the physical address set of each management node in the new main cloud management environment; the VPN gateway node is controlled to communicate with the new main cloud management environment through the logical address of the message queue and the OVN-SB physical address set, so as to perform VPN services between the VPN gateway node and the new main cloud management environment.
[0021] The beneficial effects are as follows: The present invention periodically synchronizes the control plane data of the main cloud management environment in the cloud management platform to the standby cloud management environment, enabling the standby cloud management environment to obtain the control plane data of the main management environment in advance. When subsequent primary and standby environment switching is required, the data synchronization time during switching can be reduced, the recovery efficiency can be improved, and the continuity of the VPN service can be ensured. Further, if the cloud management platform currently meets the preset cloud environment switching conditions, it indicates that the primary and standby cloud management environments need to be switched, that is, the original standby cloud management environment becomes the new main cloud management environment. Next, it is necessary to update both the address of the message queue in the cloud management platform and the set of OVN-SB physical addresses recorded in the VPN gateway node. Specifically, the logical address of the message queue remains unchanged, but the mapping relationship between the logical address and the physical address changes, so that the VPN gateway node will not perceive that the physical address of the message queue has changed. And based on the set of physical addresses of each management node in the new main cloud management environment, the set of OVN-SB physical addresses recorded in the VPN gateway node is updated to adapt to the control plane of the new main cloud management environment. After completing the modification of the VPN gateway node configuration, the VPN gateway node can be controlled to communicate with the new main cloud management environment through the logical address of the message queue and the set of OVN-SB physical addresses, so as to provide VPN services between the VPN gateway node and the new main cloud management environment. That is to say, when the cloud management environment switches, the VPN gateway node can adapt to the change of the cloud management environment address to realize that the VPN service can still be carried out between the VPN gateway node and the new main cloud management environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0022] To more clearly illustrate the embodiments of the present invention, the following will briefly introduce the drawings required for the embodiments. Obviously, the drawings in the following description are only some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can be obtained based on these drawings.
[0023] Figure 1 It is a flowchart of a disaster tolerance method for cloud environment VPN services provided by an embodiment of the present invention; Figure 2 It is a specific disaster tolerance architecture diagram of the VPN control plane provided by an embodiment of the present invention; Figure 3 It is a schematic diagram of a specific disaster tolerance switching process provided by an embodiment of the present invention; Figure 4 It is a flowchart of a disaster tolerance method for cloud environment VPN services provided by an embodiment of the present invention; Figure 5 It is a schematic structural diagram of a disaster tolerance device for cloud environment VPN services provided by an embodiment of the present invention; Figure 6 It is a structural diagram of an electronic device provided by an embodiment of the present invention. Detailed implementation manners
[0024] Next, the technical solutions in the embodiments of the present invention will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present invention. Obviously, the described embodiments are only a part of the embodiments of the present invention, rather than all the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present invention.
[0025] With the development of cloud computing, enterprises' demand for cloud environment VPN services is increasing continuously. However, cloud environment VPN services face many challenges, including network failures, data loss, and security threats, etc. To solve these problems, cloud environment VPN services need to have strong disaster tolerance capabilities to ensure the reliability and security of the services.
[0026] When the cloud management environment switches, if the cloud management address changes, then the message queue of the cloud management platform and the OVN-SBVPN gateway node also have address changes, and the VPN gateway node will cause the VPN service to not be able to be used normally due to the environmental address change.
[0027] The terms "including" and "having" in the specification of the present invention and the above accompanying drawings, as well as any variations related to "including" and "having", are intended to cover non-exclusive inclusion. For example, a process, method, system, product, or device that includes a series of steps or units is not limited to the listed steps or units, but may include steps or units not listed.
[0028] To enable those skilled in the art of this technology to better understand the solution of the present invention, the present invention will be further described in detail below in conjunction with the accompanying drawings and specific implementation manners.
[0029] Next, a disaster tolerance solution for a cloud environment VPN service provided by the embodiments of the present invention will be introduced in detail. Figure 1 A disaster tolerance method for a cloud environment VPN service provided by an embodiment of the present invention includes: Step S11: Periodically synchronize the control plane data of the cloud management main environment in the cloud management platform to the cloud management standby environment.
[0030] In this embodiment, it also includes: deploying a cloud management main environment and a cloud management standby environment in the cloud management platform; wherein, the number of nodes, operating system, and hardware configuration of the cloud management main environment and the cloud management standby environment are the same; configuring the physical addresses, Secure Shell protocol ports, and login credentials of the cloud management main environment and the cloud management standby environment.
[0031] It is understandable that several cloud management environments are deployed in the cloud management platform, and the roles of each cloud management environment are set, that is, 1 cloud management main environment is deployed. That is to say, only one environment provides services externally at the same time. The remaining deployed cloud management environments are cloud management backup environments. The number of cloud management backup environments can be deployed according to the actual scenario requirements. Moreover, the number of nodes, operating systems, and hardware configurations of the cloud management main environment and the cloud management backup environments are the same. After completing the basic network configuration and hardware configuration, it is also necessary to configure the physical addresses (IPs), Secure Shell (SSH) ports, and login credentials of the cloud management main environment and the cloud management backup environments. The login credentials include the login username and password and are used to access nodes and remotely execute deployment commands during the deployment process. After the disaster recovery configuration is completed, the cloud management service is deployed in the main environment, and only the disaster recovery service and related basic services are deployed in the backup environment.
[0032] For example Figure 2A specific VPN control plane disaster recovery architecture diagram is shown. In the cloud management platform, 1 cloud management main environment and 1 cloud management backup environment are deployed. Both the cloud management main environment and the cloud management backup environment include disaster recovery services (Disaster-recovery), control plane, virtual machine switch database (DB), and message queue. The control plane includes multiple nodes, and each node includes Neutron and OVN-SB. Openstack is an open-source infrastructure project for cloud computing. Neutron is a component responsible for network functions in the openstack project, supporting functions such as networks, subnets, security groups, firewalls, and VPNs. The Neutron-ovn-vpn-agent (i.e., the VPN proxy component of the Neutron virtual network) is responsible for receiving control node configurations at the compute node and distributing them to the IPsec component in the scenario where Neutron is docked with OVN in the OpenStack project. VPN is a technology that uses a public network (such as the Internet) to establish a dedicated data communication network. VPN creates a logically dedicated channel on the public network through tunneling technology, thereby achieving the same communication functions as a dedicated network. The IPsec component is a collection of protocols and services that provide security for the IP network and is a commonly used technology in VPNs. Network is a network resource of the cloud platform. A network can have multiple subnets. Subnet is a network resource of the cloud platform and is a separate network island on the cloud platform. Port is a network resource of the cloud platform. Multiple ports can be created under a subnet. A port contains IP address information, and the virtual network attached to the port can use the corresponding IP address. OVN (i.e., Open Virtual Network) is a distributed controller, mainly including processes such as ovn-controller and ovn-northd for translation work, and processes such as ovn-nb-db and ovn-sb-db that provide db-server services. Each process can exist in a cluster form to provide high availability guarantee. The DB database is a "warehouse that organizes, stores, and manages data according to data structures", which is a collection of a large amount of data that is long-term stored in a computer, organized, shareable, and uniformly managed. It exists in the product as a service provider, providing operations such as data storage, query, update, and deletion. Different modules may use different database types. For example, Octavia uses the myqsl database, and ovn uses the ovsdb database.
[0033] Neutron-ovn-vpn-agent is a proxy service deployed on the computing node in the scenario of Neutron connecting to OVN. It is the actual execution component that implements the VPN function. Neutron-ovn-vpn-agent is responsible for receiving the VPN configuration sent by Neutron through the message queue, sending the configuration to IPsec, implementing the VPN service through IPsec, and synchronizing the status of the currently created VPN service to Neutron. In addition to interacting with neutron, Neutron-ovn-vpn-agent also connects to the ovs-db of this node and the OVN-SB on the control node to monitor related database events. As mentioned above, the communication between Neutron-ovn-vpn-agent and Neutron, ovs-db and OVN-SB is based on message queues and Transmission Control Protocol (TCP) connections respectively. Therefore, the normal operation of Neutron-ovn-vpn-agent must know the communication addresses of the cloud management platform message queue and OVN-SB. If the cloud management platform is migrated, the cloud management address will change, and the addresses of the message queue and OVN-SB will also change.
[0034] It can be seen from the above cloud management platform disaster recovery architecture that the addresses exposed to the outside by the active and standby cloud management platforms are different, that is, the service addresses of Neutron, OVN-SB, and message queues on the management plane are also different. When the active and standby switching occurs on the cloud management platform, the Neutron-ovn-vpn-agent running on the VPN gateway node itself cannot automatically sense and switch, which will cause the VPN service to be unavailable.
[0035] The control plane data of the cloud management primary environment in the cloud management platform is periodically synchronized to the cloud management backup environment. The control plane data includes VPN configuration data and network status data. In this way, the data synchronization between the cloud management primary environment and the cloud management backup environment can be completed before the cloud environment is switched, so that the cloud management backup environment can be used as the new cloud management primary environment and ensure business continuity. In addition, the backup environment periodically synchronizes the control plane data from the primary environment to ensure the consistency of the primary and backup environment data, and the multi-copy mechanism ensures data security.
[0036] Step S12: When the cloud management platform currently meets the preset cloud environment switching conditions, the disaster recovery switching process of the cloud management platform is started.
[0037] In this embodiment, it also includes: when a cloud environment switching instruction is obtained through a preset user instruction issuing interface, or when the operating status of the cloud management main environment is monitored to be abnormal, it is determined that the cloud management platform currently meets the preset cloud environment switching conditions.
[0038] There are two specific preset cloud environment switching conditions. The first is when there is an abnormality in the primary environment, and cloud environment switching is forced. That is, the running state of the cloud management primary environment is periodically detected. If service abnormality is detected, that is, in an abnormal state, the service is migrated to the standby environment. That is to say, at this time, the preset cloud environment switching condition is met. In this case, the cloud environment can be automatically switched, and it is ensured that the VPN service can operate normally. The second is to actively switch the cloud environment. A cloud environment switching instruction is obtained through a preset user instruction issuing interface. This instruction is issued by the user through the preset user instruction issuing interface. At this time, the disaster recovery switching process of the cloud management platform is actively started. In this case, the situation where cloud environment switching cannot be performed because the running state is normal but the business scenario requires cloud environment switching at this time is avoided. After the user issues the instruction, the cloud environment can be actively switched.
[0039] Step S13: Destroy the cloud management service of the cloud management primary environment and start the cloud management service of the cloud management standby environment to switch the cloud management standby environment to the new cloud management primary environment.
[0040] For example Figure 3 As shown in a specific schematic diagram of the disaster recovery switching process, first destroy the cloud management service of the cloud management primary environment, and then start the cloud management service of the cloud management standby environment. In this way, the cloud management standby environment is switched to the new cloud management primary environment, and the original cloud management primary environment is no longer responsible for the VPN service, and the original cloud management primary environment is switched to the new cloud management standby environment.
[0041] In this embodiment, starting the cloud management service of the cloud management standby environment to switch the cloud management standby environment to the new cloud management primary environment includes: if the number of cloud management standby environments is multiple, select a target cloud management standby environment from the multiple cloud management standby environments, and start the cloud management service of the target cloud management standby environment to switch the target cloud management standby environment to the new cloud management primary environment; wherein, the target cloud management standby environment corresponds to the standby environment instruction obtained through the preset user instruction issuing interface, or the target cloud management standby environment is the cloud management standby environment selected according to the load status of each cloud management standby environment.
[0042] It can be understood that if the number of cloud management standby environments is multiple, then when selecting the target cloud management standby environment from the multiple cloud management standby environments, the load status of each cloud management standby environment can be considered, that is, select a suitable target cloud management standby environment from each cloud management standby environment according to the load status of each cloud management standby environment. For example, the target cloud management standby environment is the standby environment with the smallest load, or it can also be directly specified by the user, that is, the standby environment identification information is carried in the standby environment instruction obtained through the preset user instruction issuing interface, so as to determine the cloud management standby environment corresponding to the standby environment identification information as the target cloud management standby environment.
[0043] Step S14: Drift the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management main environment, and update the OVN-SB physical address set recorded in the VPN gateway node based on the physical address sets of the management nodes in the new cloud management main environment.
[0044] It should be noted that for the VPN gateway node, regardless of how the cloud management environment is switched, the logical address of the message queue will never change. That is to say, there is no need for the VPN gateway node to perceive that the physical address of the message queue is changing. It can be understood that due to the switching of the cloud management environment, the physical address of the message queue actually changes. Therefore, in this embodiment, the logical address of the message queue is kept unchanged, but the mapping relationship between the logical address and the physical address is changed. That is, during the switching process, there is a mapping relationship between the logical address and the physical address of the original cloud management main environment, that is, there is a mapping relationship between the logical address of the message queue and the original physical address. After switching, the mapping relationship between the logical address of the message queue and the original physical address needs to be updated to the mapping relationship between the logical address of the message queue and the physical address of the new cloud management main environment, so as to complete the drift of the mapping relationship, and the VPN gateway node will not perceive that the physical address of the message queue is changing.
[0045] In this embodiment, the updating of the OVN-SB physical address set recorded in the VPN gateway node based on the physical address sets of the management nodes in the new cloud management main environment includes: querying the currently managed VPN gateway node in the virtual switch database of the new cloud management main environment; wherein, the VPN gateway node includes a VPN proxy component of the Neutron virtual network; changing the OVN-SB physical address set recorded in the VPN proxy component to the physical address sets of the management nodes in the new cloud management main environment through the disaster recovery service in the new cloud management main environment.
[0046] Check the VPN gateway nodes in the nodes managed by the new cloud management main environment, and modify the service configuration for each VPN gateway node, that is, query the currently managed VPN gateway node in the virtual switch database of the new cloud management main environment. The VPN gateway node includes a VPN proxy component of the Neutron virtual network (i.e., Neutron-ovn-vpn-agent), and the disaster recovery service in the new cloud management main environment changes the OVN-SB physical address set recorded in the VPN proxy component to the physical address sets of the management nodes in the new cloud management main environment.
[0047] Step S15: Control the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue and the set of OVN-SB physical addresses, so as to perform VPN services between the VPN gateway node and the new cloud management main environment.
[0048] After changing the address configurations of the message queue and the set of OVN-SB physical addresses, start the Neutron-ovn-vpn-agent service in the VPN gateway node.
[0049] In this embodiment, the controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue and the set of OVN-SB physical addresses includes: controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management main environment through the set of OVN-SB physical addresses; if the identification information of the VPN proxy component is queried in the Neutron component of the new cloud management main environment, then control the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue.
[0050] During the restart and registration process of the Neutron-ovn-vpn-agent service, it is necessary to first complete the registration of Agent information with OVN-SB, and then restart the Neutron-ovn-vpn-agent service, that is, Neutron-ovn-vpn-agent synchronizes the VPN service configuration with Neutron. The registration process is that the VPN gateway node registers the identification information of the VPN proxy component with the OVN-SB in the new cloud management main environment through the set of OVN-SB physical addresses. If the identification information of the VPN proxy component can be queried in the Neutron component of the new cloud management main environment, it means the registration is successful, and then the VPN gateway node can be controlled to communicate with the new cloud management main environment through the logical address of the message queue to complete the synchronization of the VPN service configuration with Neutron.
[0051] In this embodiment, if the identification information of the VPN proxy component is queried in the Neutron component of the new cloud management main environment, controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue includes: querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management main environment; if the identification information of the VPN proxy component exists in the Neutron component, controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue; if the identification information of the VPN proxy component does not exist in the Neutron component, determining the current retry count, and if the current retry count is less than the first preset threshold, based on the delayed retry mechanism, re-jumping to the step of querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management main environment, and updating the current retry count.
[0052] It can be understood that only after the Neutron-ovn-vpn-agent registers with the OVN-SB will there be corresponding identification information of the VPN proxy component in Neutron. However, due to a certain delay in the synchronization of the identification information of the VPN proxy component, when the Neutron-ovn-vpn-agent queries the vpn service associated with the current VPN-agent, the identification information of the VPN proxy component may not be found, resulting in the inability to synchronize the VPN service to the current node normally. Therefore, it is necessary to query whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management main environment; if the identification information of the VPN proxy component exists in the Neutron component, control the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue; if the identification information of the VPN proxy component does not exist in the Neutron component, determine the current retry count. If the current retry count is less than the first preset threshold, based on the delayed retry mechanism, re-jump to the step of querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management main environment, and update the current retry count, that is, set the delayed retry mechanism. If the query fails, perform a delayed retry. The retry count and retry interval can be configured by the user. By default, the interval is 5 seconds and the retry count is 60 times, that is, every 5 seconds, try to query again whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management main environment until the retry count reaches 60 times. In this way, it is possible to avoid the situation where the Agent information of the VPN proxy component is successfully registered with the OVN-SB, but due to the delay in the synchronization of the VPN service information, the subsequent configuration information synchronization cannot be performed.
[0053] In this embodiment, controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue includes: controlling the VPN gateway node to obtain the VPN configuration information sent by the new cloud management main environment through the logical address of the message queue, so that the VPN gateway node can forward the VPN configuration information to the IPsec component; wherein, the VPN configuration information is the configuration information generated by the Neutron component in the new cloud management main environment.
[0054] The process of synchronizing the configuration information during the communication between the VPN gateway node and the new cloud management main environment is specifically as follows: The new cloud management main environment sends the configuration information generated by the Neutron component to the message queue. The VPN gateway node obtains the VPN configuration information from the message queue through the logical address of the message queue. Then, the VPN gateway node converts the VPN configuration information into a target instruction that meets the preset recognition requirements of the IPsec component. Next, the VPN gateway node forwards the target instruction to the IPsec component so that the IPsec component can recognize the target instruction and implement the VPN service.
[0055] In this embodiment, controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management main environment through the OVN-SB physical address set includes: controlling the VPN gateway node to establish a communication link with the OVN-SB in the new cloud management main environment through the OVN-SB physical address set, and controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link.
[0056] The registration process of the VPN gateway node with the OVN-SB in the new cloud management main environment: First, establish a communication connection. Specifically, after the Neutron-ovn-vpn-agent obtains the updated OVN-SB physical address set, it attempts to establish a TCP connection with the OVN-SB in the new cloud management main environment using this address set. Since the OVN-SB is served by multiple management nodes, the Neutron-ovn-vpn-agent will sequentially attempt to connect to each address in the address set until it successfully connects to an available OVN-SB management node, that is, determines the current OVN-SB physical address from the OVN-SB physical address set, and controls the VPN gateway node to attempt to establish a communication link with the OVN-SB management node corresponding to the current OVN-SB physical address. If the OVN-SB management node corresponding to the current OVN-SB physical address is available, it is determined that the communication link is successfully established. If the OVN-SB management node corresponding to the current OVN-SB physical address is unavailable, it is determined that the communication link establishment fails, and a new current OVN-SB physical address is determined from the OVN-SB physical address set, and then it jumps back to control the VPN gateway node to attempt to establish the current communication link with the OVN-SB management node corresponding to the current OVN-SB physical address; Second, perform registration. Specifically, control the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the successfully established communication link.
[0057] In this embodiment, controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link includes: querying whether there is a chassis_private table in the OVN-SB; where the chassis_private table is used to store private configuration information related to physical hosts; if there is no chassis_private table in the OVN-SB and the current query count is not greater than the second preset threshold, then based on the delayed retry mechanism, it jumps back to the step of querying whether there is a chassis_private table in the OVN-SB until the current query count is greater than the second preset threshold; if there is a chassis_private table in the OVN-SB, then control the VPN proxy component in the VPN gateway node to add the identification information of the VPN proxy component to the chassis_private table through the communication link.
[0058] The specific process of controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link is as follows: 1) Query whether there is a chassis_private table in the OVN-SB; wherein, the chassis_private table is used to store private configuration information related to physical hosts.
[0059] 2) If the chassis_private table does not exist in the OVN-SB and the current query count is not greater than the second preset threshold, then based on the delayed retry mechanism, re-jump to the step of querying whether there is a chassis_private table in the OVN-SB until the current query count is greater than the second preset threshold.
[0060] 3) If the chassis_private table exists in the OVN-SB, then control the VPN proxy component in the VPN gateway node to add the identification information of the VPN proxy component to the communication link to the chassis_private table, that is, add vpn-agent-id (i.e., the identification information of the VPN proxy component) to the entry of the corresponding VPN gateway node in the chassis_private table.
[0061] The entry of the VPN gateway node in the chassis_private is registered by the ovn-controller on the VPN gateway node. That is, when Neutron-ovn-vpn-agent is registered, there may not be a corresponding chassis_private entry, resulting in a registration failure. Therefore, for the disaster recovery environment, a delayed retry mechanism is adopted for the registration of the vpn-agent. Specifically, before registration, query whether there is a corresponding chassis_private entry. If not, perform a delayed retry. The number of retries and the retry interval can be configured by the user. The default selection is an interval of 5 seconds and 60 retries.
[0062] Thus, it can be seen that the present invention periodically synchronizes the control plane data of the cloud management main environment in the cloud management platform to the cloud management backup environment; when the cloud management platform currently meets the preset cloud environment switching condition, starts the disaster recovery switching process of the cloud management platform; destroys the cloud management service of the cloud management main environment, and starts the cloud management service of the cloud management backup environment to switch the cloud management backup environment to the new cloud management main environment; drifts the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management main environment, and updates the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management main environment; controls the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue and the OVN-SB physical address set, so as to perform VPN services between the VPN gateway node and the new cloud management main environment.
[0063] The beneficial effects are as follows: The present invention periodically synchronizes the control plane data of the cloud management main environment in the cloud management platform to the cloud management standby environment, enabling the cloud management standby environment to obtain the control plane data of the main environment in advance. When subsequent primary and standby environment switching is required, the data synchronization time during switching can be reduced, the recovery efficiency can be improved, and the continuity of the VPN service can be ensured. Further, if the cloud management platform currently meets the preset cloud environment switching conditions, it indicates that the primary and standby environments of the cloud management need to be switched, that is, the original cloud management standby environment becomes the new cloud management main environment. Next, it is necessary to update both the address of the message queue in the cloud management platform and the set of OVN-SB physical addresses recorded in the VPN gateway node. Specifically, the logical address of the message queue remains unchanged, but the mapping relationship between the logical address and the physical address changes, so that the VPN gateway node does not perceive that the physical address of the message queue has changed. And based on the set of physical addresses of each management node in the new cloud management main environment, the set of OVN-SB physical addresses recorded in the VPN gateway node is updated to adapt to the control plane of the new cloud management main environment. After completing the modification of the VPN gateway node configuration, the VPN gateway node can be controlled to communicate with the new cloud management main environment through the logical address of the message queue and the set of OVN-SB physical addresses, so as to provide VPN services between the VPN gateway node and the new cloud management main environment. That is to say, when the cloud management environment switches, the VPN gateway node can adapt to the change of the cloud management environment address to realize that the VPN service can still be carried out between the VPN gateway node and the new cloud management main environment.
[0064] See Figure 4 The embodiment of the present invention discloses a specific disaster recovery method for cloud environment VPN services. Compared with the previous embodiment, this embodiment further explains and optimizes the technical solution. It includes: Step S21: Periodically synchronize the control plane data of the cloud management main environment in the cloud management platform to the cloud management standby environment.
[0065] After the disaster recovery service of the cloud management standby environment is started, it periodically synchronizes the control plane data from the main environment, such as VPN configuration, network status, etc., and ensures data consistency and security through a multi-copy mechanism to prepare for rapid switching.
[0066] Step S22: When the cloud management platform currently meets the preset cloud environment switching conditions, start the disaster recovery switching process of the cloud management platform.
[0067] The disaster recovery service periodically detects the cloud management service of the primary environment, for example, periodically detects Neutron, message queue, OVN-SB, etc. If an abnormal state is found, such as a fault or a performance bottleneck, the disaster recovery switchover process is triggered; and manual active switchover is supported for scenarios such as environment upgrade. Specifically, the cloud environment switchover instruction can be obtained through a preset user instruction issuing interface.
[0068] Step S23: Destroy the cloud management service of the cloud management primary environment and start the cloud management service of the cloud management standby environment to switch the cloud management standby environment to the new cloud management primary environment.
[0069] Step S24: Based on the physical address of the new cloud management primary environment, the underlying network component of the cloud management platform drifts the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform; wherein, the underlying network component is any one of a load balancer, a virtual router, and a floating logical address manager.
[0070] VIP (Virtual IP, that is, the logical address) serves as the logical entry of the message queue and has two characteristics. The first is the logical address characteristic: VIP is a virtual address that is not bound to a specific physical node and is dynamically mapped to the message queue node of the current primary environment through the network layer (load balancer, virtual router, and floating logical address manager) of the cloud management platform; the second is the embodiment of immutability: regardless of how the primary and standby environments are switched, the VIP of the message queue remains unchanged. For example, if the VIP of the message queue in the primary environment is 10.0.0.1, after switching to the standby environment, this VIP automatically drifts to the message queue node of the new primary environment, but its address 10.0.0.1 is always visible to the VPN gateway node (Neutron-ovn-vpn-agent).
[0071] In this embodiment, the underlying network component of the cloud management platform drifts the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management primary environment, including: the underlying network component of the cloud management platform changes the first mapping relationship between the logical address of the message queue in the cloud management platform and the physical address of the original cloud management primary environment to the second mapping relationship between the logical address of the message queue and the physical address of the new cloud management primary environment.
[0072] The underlying network component of the cloud management platform changes the first mapping relationship between the logical address of the message queue in the cloud management platform and the physical address of the original cloud management primary environment to the second mapping relationship between the logical address of the message queue and the physical address of the new cloud management primary environment. In this way, after the switchover, VIP points to the message queue physical node of the new cloud management primary environment, ensuring that Neutron-ovn-vpn-agent continues to receive configurations through the original VIP.
[0073] Step S25: Update the OVN-SB physical address set recorded in the VPN gateway node based on the physical address sets of each management node in the new cloud management main environment.
[0074] During the process of updating the OVN-SB physical address set recorded in the VPN gateway node based on the physical address sets of each management node in the new cloud management main environment, the logical structure of the address set remains unchanged (always representing "all management nodes"). Only the physical IP list in the set needs to be updated during the switch, and the VPN gateway node only needs to connect according to the "set" logic. After the standby environment is activated, the system batch-modifies the configuration of the VPN gateway node and updates the OVN-SB address set to ["192.168.1.202", "192.168.1.203"] (the new physical address list), but logically still represents "all management nodes".
[0075] All management nodes include Neutron component-related nodes and OVN-related nodes. Among them, regarding Neutron component-related nodes, Neutron is a component responsible for network functions in the OpenStack project, supporting functions such as networks, subnets, security groups, firewalls, and VPNs. In the cloud management environment, the related nodes of Neutron are responsible for processing and managing network-related configurations and operations, and are an important part of the management level of the cloud management platform. When configuring the VPN service, Neutron sends the VPN configuration to the Neutron-ovn-vpn-agent through the message queue, and its related nodes participate in the management and control process of the VPN service. Regarding OVN-related nodes, OVN is a distributed controller, mainly including processes such as ovn-controller and ovn-northd for translation work, as well as processes such as ovn-nb-db and ovn-sb-db providing db-server services. Each process can exist in the form of a cluster to provide high availability guarantee. Among them, the nodes where ovn-sb-db is located and the nodes where related processes such as ovn-controller run belong to management nodes. The Neutron-ovn-vpn-agent needs to connect to the ovn-sb of the control node to listen for relevant database events, and these control nodes where OVN-SB is located are part of "all management nodes".
[0076] Step S26: Control the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue and the OVN-SB physical address set, so as to perform VPN services between the VPN gateway node and the new cloud management main environment.
[0077] Re-establish communication through the logical address. The restarted Neutron-ovn-vpn-agent connects to the message queue through the original logical address. The network layer of the cloud management platform has mapped the logical address to the physical address of the message queue of the new primary environment. Therefore, the Agent does not need to perceive the change of the physical address and directly communicates with the Neutron component of the new primary environment. Configuration synchronization and service recovery: The Agent receives the VPN configuration (such as IPsec policy) issued by Neutron through the message queue, performs OVN-SB registration and Neutron data synchronization (success is ensured by the timeout retry mechanism), and finally restores the VPN service through IPsec.
[0078] Neutron component generates configuration: In the new cloud management environment, Neutron component generates VPN configuration based on system settings and user needs, covering key information such as tunnel parameters and security policies. Send configuration through message queue: Neutron component sends the generated VPN configuration through the VIP of the message queue. The message queue adopts the publish-subscribe mode and is responsible for reliable message delivery. VPN gateway node receives configuration: Neutron-ovn-vpn-agent of the VPN gateway node receives configuration through the VIP of the message queue. Because VIP is a fixed logical address, the underlying network component will map it to the physical node of the new master environment message queue, so that Neutron-ovn-vpn-agent can stably receive configuration without paying attention to changes in the physical address.
[0079] Configuration processing and execution: After receiving the configuration, Neutron-ovn-vpn-agent sends it to the IPsec component. IPsec establishes a secure tunnel through encryption, authentication and other operations to implement VPN services. Registration and synchronization operations: During the startup of Neutron-ovn-vpn-agent, it will register agent information with OVN-SB and query the associated VPN service with Neutron for configuration synchronization. If the registration or query fails, a timeout retry mechanism is used to ensure successful configuration synchronization. Feedback configuration status: After Neutron-ovn-vpn-agent completes configuration processing, it synchronizes the current VPN service status to Neutron through the message queue, such as connection status, configuration execution results, etc., so that the cloud management platform can monitor and manage VPN services.
[0080] Collect various types of monitoring data using the monitoring data collection tools deployed in each VPN gateway node. The various types of monitoring data are specifically real-time bandwidth, packet rate, concurrent connection count, and node resource utilization rate. Determine the node load status of each VPN gateway node based on the weighted results of the various types of monitoring data. Based on the node load status of each VPN gateway node, determine the priority of each VPN gateway node for providing VPN services, and control each VPN gateway node to communicate with the new cloud management main environment based on the logical address of the message queue and the set of OVN-SB physical addresses. In this way, dynamic load balancing of VPN connections is achieved, effectively avoiding single-node overload. Through real-time monitoring and accurate load assessment, resource utilization rate is improved, and the stability, reliability, and intelligent management level of the system are overall enhanced, supporting the efficient and elastic management of a large number of concurrent VPN connections.
[0081] The beneficial effects of this application are as follows: By updating the set of OVN-SB physical addresses recorded in the VPN gateway node, it is ensured that the VPN gateway node can establish a reliable communication connection with each management node in the new cloud management main environment based on accurate physical addresses, laying a foundation for the subsequent registration of the Neutron-ovn-vpn-agent with OVN-SB and configuration synchronization. When the Neutron-ovn-vpn-agent registers agent information in the chassis_private table of OVN-SB, the delayed retry mechanism (default 5-second interval, 60 retries) is used to solve the registration failure problem caused by the ovn-controller not creating table entries in time or data synchronization delay, ensuring that the agent identity is correctly recognized and recorded by OVN-SB. When querying the associated VPN service from Neutron for configuration synchronization, first query and confirm the registration status of the agent in Neutron. If it is not found due to synchronization delay, trigger a delayed retry to ensure that Neutron can sense the existence of the agent, so that the VPN configuration information (such as IPsec policies, etc.) can be accurately sent to the Neutron-ovn-vpn-agent through the message queue. This solution that uses the set of OVN-SB physical addresses as the communication entry, the message queue as the configuration transmission channel, and combines the timeout retry mechanism effectively solves the configuration failure problem caused by data synchronization delay between components in the cloud management environment, realizes stable communication between the VPN gateway node and the new cloud management main environment, ensures the automatic synchronization and implementation of VPN service configurations, improves the reliability, robustness, and management efficiency of the entire system, avoids errors caused by manual intervention, adapts to the dynamically changing network requirements in the cloud management environment, and ensures the continuity and stability of VPN services.
[0082] Figure 5 The following is a schematic structural diagram of a disaster recovery device for a cloud environment VPN service provided by an embodiment of the present invention, including: A data synchronization module 11, which is used to periodically synchronize the control plane data of the cloud management main environment in the cloud management platform to the cloud management standby environment; A disaster recovery switching module 12, which is used to start the disaster recovery switching process of the cloud management platform when the cloud management platform currently meets the preset cloud environment switching conditions; An environment switching module 13, which is used to destroy the cloud management service of the cloud management main environment and start the cloud management service of the cloud management standby environment, so as to switch the cloud management standby environment to a new cloud management main environment; An address update module 14, which is used to drift the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management main environment, and update the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management main environment; A service execution module 15, which is used to control the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue and the OVN-SB physical address set, so as to perform a VPN service between the VPN gateway node and the new cloud management main environment.
[0083] It can be seen that the present invention periodically synchronizes the control plane data of the cloud management main environment in the cloud management platform to the cloud management standby environment; when the cloud management platform currently meets the preset cloud environment switching conditions, it starts the disaster recovery switching process of the cloud management platform; destroys the cloud management service of the cloud management main environment and starts the cloud management service of the cloud management standby environment, so as to switch the cloud management standby environment to a new cloud management main environment; drifts the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management main environment, and updates the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management main environment; controls the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue and the OVN-SB physical address set, so as to perform a VPN service between the VPN gateway node and the new cloud management main environment.
[0084] The beneficial effects are as follows: The present invention periodically synchronizes the control plane data of the main cloud management environment in the cloud management platform to the standby cloud management environment, enabling the standby cloud management environment to obtain the control plane data of the main management environment in advance. When subsequent primary and standby environment switching is required, the data synchronization time during switching can be reduced, the recovery efficiency can be improved, and the continuity of the VPN service can be ensured. Further, if the cloud management platform currently meets the preset cloud environment switching conditions, it indicates that the primary and standby cloud management environments need to be switched, that is, the original standby cloud management environment becomes the new primary cloud management environment. Next, it is necessary to update the address of the message queue in the cloud management platform and the set of OVN-SB physical addresses recorded in the VPN gateway node. Specifically, the logical address of the message queue remains unchanged, but the mapping relationship between the logical address and the physical address changes, so that the VPN gateway node will not perceive that the physical address of the message queue has changed. And based on the set of physical addresses of each management node in the new primary cloud management environment, the set of OVN-SB physical addresses recorded in the VPN gateway node is updated to adapt to the control plane of the new primary cloud management environment. After modifying the configuration of the VPN gateway node, the VPN gateway node can be controlled to communicate with the new primary cloud management environment through the logical address of the message queue and the set of OVN-SB physical addresses, so as to provide VPN services between the VPN gateway node and the new primary cloud management environment. That is to say, when the cloud management environment switches, the VPN gateway node can adapt to the change of the cloud management environment address to realize that VPN services can still be provided between the VPN gateway node and the new primary cloud management environment.
[0085] Further, the embodiment of the present application also discloses an electronic device. Figure 6 It is a structural diagram of an electronic device shown according to an exemplary embodiment. The content in the figure should not be considered as any limitation on the scope of use of the present application. The electronic device may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. Among them, the memory 22 is used to store a computer program, and the computer program is loaded and executed by the processor 21 to implement the relevant steps in the disaster tolerance method for cloud environment VPN services disclosed in any of the foregoing embodiments. In addition, the electronic device in this embodiment may specifically be an electronic computer.
[0086] In this embodiment, the power supply 23 is used to provide operating voltage for each hardware device on the electronic device; the communication interface 24 can create a data transmission channel between the electronic device and external devices, and the communication protocol it follows is any communication protocol applicable to the technical solution of the present application, and no specific limitation is imposed on it here; the input / output interface 25 is used to obtain external input data or output data to the outside, and its specific interface type can be selected according to specific application needs, and no specific limitation is made here.
[0087] In addition, as a carrier for storing resources, the memory 22 can be a read-only memory, a random access memory, a magnetic disk, an optical disc, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0088] Among them, the operating system 221 is used to manage and control each hardware device and the computer program 222 on the electronic device, and it can be Windows Server, Netware, Unix, Linux, etc. In addition to the computer program that can be used to complete the disaster recovery method of the cloud environment VPN service executed by the electronic device disclosed in any of the foregoing embodiments, the computer program 222 can further include computer programs that can be used to complete other specific tasks.
[0089] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the disaster recovery method of the cloud environment VPN service disclosed above is implemented. For the specific steps of this method, reference can be made to the corresponding content disclosed in the foregoing embodiments, and details will not be repeated here.
[0090] Furthermore, the embodiments of the present application also disclose a computer program product, including a computer program / instructions, and when the computer program / instructions are executed by a processor, the steps of the disaster recovery method of the cloud environment VPN service disclosed in any of the foregoing embodiments are implemented.
[0091] In this specification, the various embodiments are described in a progressive manner. Each embodiment focuses on the differences from other embodiments. For the same or similar parts between the various embodiments, reference can be made to each other. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the description is relatively simple, and reference can be made to the description in the method part for related parts.
[0092] Those skilled in the art can further realize that the units and algorithm steps of the examples described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the components and steps of the examples have been generally described according to their functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0093] The steps of the methods or algorithms described in connection with the embodiments disclosed herein may be implemented directly in hardware, in software modules executed by a processor, or in a combination thereof. The software modules may be located in a random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, hard disk, removable disk, CD-ROM, or any other form of storage medium well known in the art.
[0094] Finally, it should also be noted that in this document, relational terms such as first and second are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the term "comprising", "including" or any other variation thereof is intended to cover non-exclusive inclusion, so that a process, method, article or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, article or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, article or device comprising the element.
[0095] The technical solutions provided in this application have been introduced in detail above. Specific examples are used in this document to illustrate the principles and implementation manners of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application; at the same time, for those of ordinary skill in the art, according to the idea of this application, there will be changes in the specific implementation manners and application scopes. In summary, the content of this specification should not be construed as a limitation to this application.
Claims
1. A disaster recovery method for a cloud environment VPN service, characterized in that, Including: Periodically synchronize the control plane data of the main cloud management environment in the cloud management platform to the backup cloud management environment; When the cloud management platform currently meets the preset cloud environment switching condition, start the disaster recovery switching process of the cloud management platform; Destroy the cloud management service of the main cloud management environment and start the cloud management service of the backup cloud management environment to switch the backup cloud management environment to the new main cloud management environment; Drift the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new main cloud management environment, and update the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new main cloud management environment; Control the VPN gateway node to communicate with the new main cloud management environment through the logical address of the message queue and the OVN-SB physical address set, so as to perform VPN services between the VPN gateway node and the new main cloud management environment.
2. The disaster recovery method for cloud environment VPN service according to claim 1, characterized in that, Also including: Deploy the main cloud management environment and the backup cloud management environment in the cloud management platform; wherein, the number of nodes, operating system, and hardware configuration of the main cloud management environment and the backup cloud management environment are the same; Configure the physical addresses, Secure Shell protocol ports, and login credentials of the main cloud management environment and the backup cloud management environment.
3. The disaster recovery method of the cloud environment VPN service according to claim 1, characterized in that, Also including: When obtaining a cloud environment switching instruction through a preset user instruction issuing interface, or when monitoring that the running state of the main cloud management environment is an abnormal state, it is determined that the cloud management platform currently meets the preset cloud environment switching condition.
4. The disaster recovery method for cloud environment VPN services according to claim 3, characterized in that The starting the cloud management service of the backup cloud management environment to switch the backup cloud management environment to the new main cloud management environment includes: If the number of backup cloud management environments is multiple, select a target backup cloud management environment from the multiple backup cloud management environments, and start the cloud management service of the target backup cloud management environment to switch the target backup cloud management environment to the new main cloud management environment; Wherein, the target backup cloud management environment corresponds to the backup environment instruction obtained through the preset user instruction issuing interface, or the target backup cloud management environment is the backup cloud management environment selected according to the load status of each backup cloud management environment.
5. The disaster recovery method for cloud environment VPN services according to any one of claims 1 to 4, characterized in that, The drifting the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new main cloud management environment includes: Drift the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new main cloud management environment through the underlying network component of the cloud management platform; wherein, the underlying network component is any one of a load balancer, a virtual router, and a floating logical address manager.
6. The disaster recovery method for cloud environment VPN service according to claim 5, characterized in that, The drifting the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform through the underlying network component of the cloud management platform based on the physical address of the new main cloud management environment includes: Change the first mapping relationship between the logical address of the message queue in the cloud management platform and the physical address of the original main cloud management environment to the second mapping relationship between the logical address of the message queue and the physical address of the new main cloud management environment through the underlying network component of the cloud management platform.
7. The disaster recovery method of the cloud environment VPN service according to claim 1, wherein, Updating the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management main environment includes: Querying the currently managed VPN gateway nodes in the virtual switch database of the new cloud management main environment; wherein, the VPN gateway node includes a VPN proxy component of the Neutron virtual network; Changing the OVN-SB physical address set recorded in the VPN proxy component to the physical address set of each management node in the new cloud management main environment through the disaster recovery service in the new cloud management main environment.
8. The disaster recovery method for cloud environment VPN service according to claim 7, characterized in that, Controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue and the OVN-SB physical address set includes: Controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management main environment through the OVN-SB physical address set; If the identification information of the VPN proxy component is queried in the Neutron component of the new cloud management main environment, controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue.
9. The disaster recovery method for cloud environment VPN service according to claim 8, characterized in that, The step of, if the identification information of the VPN proxy component is queried in the Neutron component of the new cloud management main environment, controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue includes: Querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management main environment; If the identification information of the VPN proxy component exists in the Neutron component, controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue; If the identification information of the VPN proxy component does not exist in the Neutron component, determining the current retry count. If the current retry count is less than the first preset threshold, based on the delayed retry mechanism, re-jumping to the step of querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management main environment, and updating the current retry count.
10. The disaster recovery method of the cloud environment VPN service according to claim 8, characterized in that, Controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue includes: Controlling the VPN gateway node to obtain the VPN configuration information issued by the new cloud management main environment through the logical address of the message queue, so that the VPN gateway node forwards the VPN configuration information to the IPsec component; wherein, the VPN configuration information is the configuration information generated by the Neutron component in the new cloud management main environment.
11. The disaster recovery method for cloud environment VPN service according to claim 8, characterized in that, Controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management main environment through the OVN-SB physical address set includes: Control the VPN gateway node to establish a communication link with the OVN-SB in the new cloud management main environment through the OVN-SB physical address set, and control the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link.
12. The disaster recovery method for the cloud environment VPN service according to claim 11, wherein The step of controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link includes: Query whether there is a chassis_private table in the OVN-SB; wherein, the chassis_private table is used to store private configuration information related to physical hosts; If the chassis_private table does not exist in the OVN-SB and the current query count is not greater than the second preset threshold, then based on the delayed retry mechanism, re-jump to the step of querying whether there is a chassis_private table in the OVN-SB until the current query count is greater than the second preset threshold; If the chassis_private table exists in the OVN-SB, then control the VPN proxy component in the VPN gateway node to add the identification information of the VPN proxy component to the chassis_private table through the communication link.
13. A computer program product comprising a computer program / instructions, characterized in that, When the computer program / instructions are executed by a processor, the steps of the disaster recovery method for the cloud environment VPN service according to any one of claims 1 to 12 are implemented.
14. An electronic device, characterized in that, Including: A memory for storing a computer program; A processor for executing the computer program to implement the steps of the disaster recovery method for the cloud environment VPN service according to any one of claims 1 to 12.
15. A computer-readable storage medium, characterized in that, A computer program is stored on the computer-readable storage medium, and when the computer program is executed by a processor, the steps of the disaster recovery method for the cloud environment VPN service according to any one of claims 1 to 12 are implemented.
Citation Information
Patent Citations
Disaster tolerance network managing system and login method of network managing subscriber end
CN101227333A
Rapid address switchover method used for realizing backup service and route forwarding unit
CN102752209A
SaaS-based cloud disaster recovery system and method
CN106713409A
System for providing virtual customer premises equipment services in network function virtualization environment, and network function virtualization cloud for the same
CN107623712A
Master-slave service system and master node fault recovery method and device
CN108964948A
Cited By
Cloud environment VPN service data plane high availability method and device
CN120979911A