A mimicry hyper-convergence management device, a resource reallocation method, and a storage medium
By distributing HCI-Manager in a hyperconverged system and dispersing the bulk heterogeneous and discrete distribution, and using dynamic heterogeneous HCI-Manager execution volume pool and adjudication outputer to vote on resource operation requests, the problem of insufficient security defense of the existing hyperconverged system is solved, the credibility and real-time nature of resource allocation are achieved, and the security and ease of use of the system are enhanced.
Patent Information
- Application Number
- CN202211338761.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-28
- Publication Date
- 2025-07-01
- Estimated Expiration
- 2042-10-28
AI Technical Summary
The existing hyperconverged system management is insufficient security defense, cannot resist unknown threats and experience-based security attacks, and the resource allocation process is untrusted and is easily tampered with. The management system cannot be used normally when node failures.
Using a mimic hyperconvergence management device, the HCI-Manager execution body heterogeneous and discretely distributed on different nodes. The voting for resource operation requests is performed through the dynamic heterogeneous HCI-Manager execution body pool and adjudication outputer to ensure the credibility of resource allocation, and add Mimic-coordinator services to each node to achieve real-time synchronization of resource state.
It improves the security and service continuity of the hyper-converged system, ensures the credibility of the resource allocation process, enhances the ability to resist attacks, and realizes real-time update of resource allocation status and ease of use of the system.
Smart Images

Figure CN115828253B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of resource allocation, and specifically, to a mimicry hyper-converged management device, a resource reallocation method, and a storage medium. Background Art
[0002] With the rise of the Internet and distribution, a hyper-converged architecture based on virtualization, software-defined storage, and software-defined network has gradually emerged. The hyper-converged architecture solves the problems of complex architecture, difficult management, and scattered policies existing in traditional IT infrastructure. After adopting the hyper-converged architecture, when an enterprise needs more resources, the enterprise only needs to expand the cluster by adding nodes. For each added node, the corresponding computing, storage space, and performance can grow linearly, and the work of adding nodes is almost fully automatic.
[0003] Specifically, the hyper-converged infrastructure integrates resources such as computing, network, and storage as infrastructure, selects, combines, and customizes according to the specific business system requirements, and is a technical architecture for quickly building a data center and deploying a business system, as Figure 1 shown. There is no clear division of labor between computing and storage among the nodes of the hyper-converged system. The core storage and computing functions are implemented on the same server hardware resources (currently mainly x86 servers), and are encapsulated into a single, highly virtualized solution. Generally, software virtualization technologies (including virtualization of computing, network, storage, security, etc.) are integrated into a unit node (x86 server). Each unit node is aggregated through a network to achieve modular seamless horizontal expansion and build a unified resource pool.
[0004] However, all the security defenses in the management of existing hyper-converged systems are based on traditional security defense technologies for late passive defense, and have no resistance to unknown threats and security attacks based on experience. When in use, the management request is forwarded to the corresponding node through the management service for processing. Once the management request is tampered with during processing or forwarding, it cannot be guaranteed that the resource allocation is carried out according to the customer's wishes. The hijacker can allocate or damage the resources according to his own wishes, resulting in the untrustworthiness of the resource allocation process of the entire hyper-converged system and the malicious use of resources; and if a node fails, the address of other nodes needs to be queried to continue using the management system.
[0005] In order to solve the above existing problems, people have been seeking an ideal technical solution. Summary of the Invention
[0006] The purpose of the present invention is to overcome the deficiencies of the prior art, and thus provide a mimicry hyper-converged management device, a resource reallocation method, and a storage medium.
[0007] To achieve the above object, a first aspect of the present invention provides a mimic hyper-converged management device, including:
[0008] An input proxy module, configured to receive a resource operation request sent by a client and copy and distribute it to each heterogeneous HCI-Manager executor in the dynamic heterogeneous HCI-Manager executor pool, where the resource operation request includes a query request and a change request;
[0009] A dynamic heterogeneous HCI-Manager executor pool, including two or more heterogeneous HCI-Manager executors sharing the resource allocation status of the hyper-converged system. Each heterogeneous HCI-Manager executor communicates and interconnects with the input proxy module, and is configured to calculate and generate a resource pre-operation result according to the resource operation request and the shared resource allocation status. The resource pre-operation result includes a target boundary node ID and an operation type tag, and finally sends an adjudication request including the resource pre-operation result to the adjudication outputter;
[0010] An adjudication outputter, which communicates and interconnects with each heterogeneous HCI-Manager executor respectively, receives adjudication requests output by different heterogeneous HCI-Manager executors, conducts a vote according to a preset adjudication rule, and outputs a trusted pre-operation result to the output proxy module;
[0011] An output proxy module, which communicates and interconnects with the adjudication outputter, is configured to receive the trusted pre-operation result and identify the operation type tag carried by the trusted pre-operation result. When the operation type tag carried by the trusted pre-operation result is a query tag, the trusted pre-operation result is output and forwarded to the client; when the operation type tag carried by the trusted pre-operation result is a change tag, the trusted pre-operation result is output and forwarded to each Mimic-coordinator service;
[0012] The Mimic-coordinator service is set on the nodes of the hyper-converged cluster, and is configured to query the target node ID in the trusted pre-operation result, determine whether it is the target node. If not, it updates the resource allocation status of the corresponding target node in the pre-stored cluster resource status according to the target node ID in the trusted pre-operation result; if so, it calls the qemu interface to execute the trusted pre-operation result on the resources in the node, and after the execution is completed, obtains the internal resource allocation status and pushes it to the negative feedback controller;
[0013] And a negative feedback controller, which is interconnected with the output proxy module, each heterogeneous HCI-Manager execution entity, and the input proxy module respectively, and is used to perform data synchronization or cleaning operations on abnormal heterogeneous HCI-Manager execution entities when the verdict outputter outputs a trusted pre-operation result; and is used to control the input proxy module to copy and distribute resource operation requests to each heterogeneous HCI-Manager execution entity in the dynamic heterogeneous HCI-Manager execution entity pool again when the verdict outputter does not output a trusted pre-operation result; and is also used to synchronously update the resource allocation status of the dynamic heterogeneous HCI-Manager execution entity pool according to the obtained internal resource allocation status.
[0014] The second aspect of the present invention provides a resource reallocation method, including the following steps:
[0015] The client generates a resource operation request, and copies and distributes it to each heterogeneous HCI-Manager execution entity in the dynamic heterogeneous HCI-Manager execution entity pool through the input proxy module;
[0016] The heterogeneous HCI-Manager execution entity calculates and generates a resource pre-operation result according to the resource operation request and the shared resource allocation status. The resource pre-operation result includes a target boundary node ID and an operation type tag, and finally sends a verdict request containing the resource pre-operation result to the verdict outputter;
[0017] The verdict outputter receives the verdict requests output by different heterogeneous HCI-Manager execution entities, conducts a vote according to the preset verdict rules, and outputs a trusted pre-operation result to the output proxy module;
[0018] The output proxy module receives the trusted pre-operation result and identifies the operation type tag carried by the trusted pre-operation result. When the operation type tag carried by the trusted pre-operation result is a query tag, it outputs and forwards the trusted pre-operation result to the client; when the operation type tag carried by the trusted pre-operation result is a change tag, it outputs and forwards the trusted pre-operation result to each Mimic-coordinator service;
[0019] The Mimic-coordinator service queries the target node ID in the trusted pre-operation result, judges whether it is the target node. If not, it updates the resource allocation status of the corresponding target node in the pre-stored cluster resource status according to the target node ID in the trusted pre-operation result; if so, it calls the qemu interface to execute the trusted pre-operation result on the resources in the node, and after the execution is completed, obtains the internal resource allocation status and pushes it to the negative feedback controller;
[0020] Meanwhile, when the verdict outputter outputs a credible pre-operation result, the negative feedback controller performs data synchronization or cleaning operations on abnormal heterogeneous HCI-Manager executors; or when the verdict outputter does not output a credible pre-operation result, the negative feedback controller controls the input proxy module to copy and distribute the resource operation request to each heterogeneous HCI-Manager executor again.
[0021] The third aspect of the present invention provides a readable storage medium, on which instructions are stored, and when the instructions are executed by a processor, the steps of the foregoing resource reallocation method are implemented.
[0022] The present invention has prominent substantive features and remarkable progress compared with the prior art. Specifically, the present invention provides a mimic hyper-converged management device, which improves the management of the existing hyper-converged system, makes the HCI-Manager heterogeneous, and distributes the heterogeneous HCI-Manager executors discretely on different nodes with heterogeneous CPUs, heterogeneous operating systems, and heterogeneous implementation languages, so that the attack behavior cannot tamper with the resource reallocation request by controlling a certain heterogeneous HCI-Manager executor, and further tamper with the resource allocation result. While ensuring the security and reliability of the heterogeneous HCI-Manager executor, the attack resistance ability and service continuity of the hyper-converged management system are improved;
[0023] The hijacked HCI-Manager management service will be cleaned offline, ensuring the credibility of the entire hyper-converged system resource allocation process, enhancing the built-in security characteristics of the heterogeneous HCI-Manager execution, and being able to effectively and actively resist attack behaviors based on known experience or unknown security vulnerabilities;
[0024] Add the Mimic-coordinator service to each node of the hyper-converged system. The Mimic-coordinator service of the target node calls the qemu interface to execute the credible pre-operation result on the resources in the node, and after the execution is completed, obtains the internal resource allocation status and pushes it to the negative feedback controller to achieve the synchronization and sharing of the hyper-converged system resource allocation status by the HCI-Manager executor; at the same time, the non-target node directly updates the resource allocation status of the corresponding target node in the pre-stored cluster resource status according to the target node ID in the credible pre-operation result. Compared with the traditional hyper-converged system that needs to wait for the synchronization of the master node, the present application can achieve the real-time update of the resource allocation status;
[0025] The Mimic-coordinator service of each node also detects the internal resource allocation status of the node at a preset time interval, so that the resource allocation status of the dynamic heterogeneous HCI-Manager executor pool can be synchronously updated when the cluster state changes caused by changes in the hardware or services of the cluster;
[0026] The client accesses the proxy, and even if a node fails, users can continue to access the hyper-converged system using the original IP, improving the usability of the system;
[0027] The hot-plug function of the mimic hyper-converged management device can quickly mimic the original hyper-converged cluster without a mimic structure, improving the security of the hyper-converged system. Description of the Drawings
[0028] Figure 1 is a schematic structural diagram of a traditional hyper-converged management system.
[0029] Figure 2 is a schematic structural diagram of the mimic hyper-converged management device of the present invention.
[0030] Figure 3 is a timing diagram of the query operation of the present invention.
[0031] Figure 4 is a timing diagram of the change operation of the present invention. Detailed Embodiments
[0032] The technical solutions of the present invention will be further described in detail below through specific embodiments.
[0033] As Figure 2 shown, a mimic hyper-converged management device includes: an input proxy module for receiving a resource operation request sent by a client and copying and distributing it to each heterogeneous HCI-Manager executor in the dynamic heterogeneous HCI-Manager executor pool, where the resource operation request includes a query request and a change request; specifically, the change request includes an addition request, a deletion request, and a modification request;
[0034] A dynamic heterogeneous HCI-Manager executor pool includes two or more heterogeneous HCI-Manager executors sharing the resource allocation status of the hyper-converged system. Each heterogeneous HCI-Manager executor is communicatively interconnected with the input proxy module and is used to calculate and generate a resource pre-operation result according to the resource operation request and the shared resource allocation status. The resource pre-operation result includes a target boundary node ID and an operation type tag, and finally sends a ruling request including the resource pre-operation result to the ruling outputter;
[0035] A ruling outputter is communicatively interconnected with each heterogeneous HCI-Manager executor, receives the ruling requests output by different heterogeneous HCI-Manager executors, votes according to preset ruling rules, and outputs a trusted pre-operation result to the output proxy module;
[0036] An output proxy module, which communicates with the adjudication outputter, is used to receive the trusted pre-operation result and identify the operation type tag carried by the trusted pre-operation result. When the operation type tag carried by the trusted pre-operation result is a query tag, the trusted pre-operation result is output and forwarded to the client; when the operation type tag carried by the trusted pre-operation result is a change tag, the trusted pre-operation result is output and forwarded to each Mimic-coordinator service;
[0037] The Mimic-coordinator service is set on the nodes of the hyper-converged cluster and is used to query the target node ID in the trusted pre-operation result to determine whether it is the target node. If not, the resource allocation status of the corresponding target node in the pre-stored cluster resource status is updated according to the target node ID in the trusted pre-operation result; if so, the qemu interface is called to execute the trusted pre-operation result on the resources within the node, and after the execution is completed, the internal resource allocation status is obtained and pushed to the negative feedback controller;
[0038] And a negative feedback controller, which is interconnected with the output proxy module, each heterogeneous HCI-Manager executor, and the input proxy module respectively, is used to perform data synchronization or cleaning operations on abnormal heterogeneous HCI-Manager executors when the adjudication outputter outputs a trusted pre-operation result; and is used to control the input proxy module to copy and distribute the resource operation request to each heterogeneous HCI-Manager executor again when the adjudication outputter does not output a trusted pre-operation result; and is also used to synchronously update the resource allocation status of the dynamic heterogeneous HCI-Manager executor pool according to the obtained internal resource allocation status.
[0039] In a specific implementation, after each heterogeneous HCI-Manager executor marks the resource pre-operation result with an operation type tag according to the identified type, the resource pre-operation result is converted into an adjudication request in a preset format and sent to the adjudication outputter;
[0040] The adjudication outputter receives the adjudication requests output by different heterogeneous HCI-Manager executors, filters the adjudication requests according to the preset regular filtering rules to obtain a normalized adjudication request with a unified data structure format, and then conducts a vote according to the preset adjudication rules.
[0041] It can be understood that each heterogeneous HCI-Manager execution body in this embodiment can implement management operations on all nodes, and the number of heterogeneous HCI-Manager execution bodies is much larger than that in the existing hyper-converged management system, thus enhancing the continuity of the cluster storage service. Even if a certain heterogeneous HCI-Manager execution body is attacked or unavailable due to its own failure, other heterogeneous HCI-Manager execution bodies in the dynamic heterogeneous HCI-Manager execution body pool can still work, greatly improving the ability of the storage system to resist attacks such as denial of service.
[0042] Furthermore, different heterogeneous HCI-Manager execution bodies are deployed on CPU hardware with heterogeneous CPUs, operating systems, and disks, and this CPU hardware is deployed on different data nodes; in other embodiments, different heterogeneous HCI-Manager execution bodies can also be deployed on different containers or virtual machines to save hardware resources while ensuring data storage security.
[0043] The present invention uses mimicry technology to improve the management of the existing hyper-converged system, heterogeneousize the HCI-Manager, and discretely distribute the heterogeneous HCI-Manager execution bodies on different nodes with heterogeneous CPUs, operating systems, and implementation languages, so that the attack behavior cannot tamper with the resource reallocation request by controlling a certain heterogeneous HCI-Manager execution body, and further tamper with the resource allocation result. While ensuring the security and reliability of the heterogeneous HCI-Manager execution body, it improves the attack resistance and service continuity of the hyper-converged management system.
[0044] It should be noted that the adjudication rules of the adjudicator can be dynamically adjustable, and different preset adjudication rules are run at different times, so that external attacks cannot learn the adjudication rules under which the mimicry distributed storage system operates, prevent data leakage, and further improve the security of the mimicry distributed storage system.
[0045] This embodiment also gives a specific implementation manner of the preset adjudication rules of an adjudicator. The preset adjudication rules of the adjudicator are:
[0046] Pre-judge the number of adjudication requests received and execute different adjudication strategies according to the judgment results; specifically, when the number of adjudication requests received is 1, the resource pre-operation result included in the adjudication request is used as the trusted pre-operation result;
[0047] When the number of adjudication requests received is greater than 1 and is odd, the resource pre-operation result included in the adjudication requests with consistent content and the majority is used as the trusted pre-operation result;
[0048] When the number of adjudication requests received is even:
[0049] If the resource pre-operation results included in each arbitration request are consistent, then use the resource pre-operation result included in any one arbitration request as the trusted pre-operation result;
[0050] If the resource pre-operation results included in each arbitration request are inconsistent, and the voting result is M:N, then use the resource pre-operation result included in the arbitration requests with consistent content and the majority as the trusted pre-operation result; where M is not equal to N;
[0051] If the resource pre-operation results included in each arbitration request are inconsistent, the voting result is P*(1:1), and the trusted weights corresponding to each heterogeneous HCI-Manager executor are the same, then no trusted pre-operation result is output;
[0052] If the resource pre-operation results included in each arbitration request are inconsistent, the voting result is P*(1:1), and the trusted weights corresponding to each heterogeneous HCI-Manager executor are inconsistent, then use the resource pre-operation result corresponding to the heterogeneous HCI-Manager executor with the largest trusted weight as the trusted pre-operation result;
[0053] Among them, the initial weight of each heterogeneous HCI-Manager executor is configured to be 0; each time the arbiter outputs a trusted pre-operation result, the trusted weight of the heterogeneous HCI-Manager executor corresponding to the data distribution diagram used as the trusted pre-operation result is incremented by 1.
[0054] It should be noted that abnormal heterogeneous HCI-Manager executors include heterogeneous HCI-Manager executors that do not send arbitration requests, heterogeneous HCI-Manager executors that do not correspond to the trusted pre-operation result, and heterogeneous HCI-Manager executors with a trusted weight less than a preset value.
[0055] It can be understood that when the arbiter does not output a trusted data distribution result, a feedback message is generated; the feedback message is used to control the input proxy module through a negative feedback controller to re-copy and distribute the data distribution information acquisition request to each heterogeneous HCI-Manager executor in the dynamic heterogeneous HCI-Manager executor pool.
[0056] It should be noted that through the preset arbitration rules given in this embodiment, the arbiter can arbitrate and output various arbitration requests and generate a scheduling request, so as to realize the automatic operation and automatic adjustment of the entire hyper-converged architecture without manual participation.
[0057] In addition to automatic adjustment, in other embodiments, the negative feedback controller may also receive externally input control parameters or internally input control commitments to perform data synchronization, update, or cleaning on the dynamic heterogeneous HCI-Manager executor pool.
[0058] Embodiment 2
[0059] This embodiment provides a specific implementation manner of a dynamic heterogeneous HCI-Manager executor pool. The dynamic heterogeneous HCI-Manager executor pool includes three heterogeneous HCI-Manager executors, where one heterogeneous HCI-Manager executor is a native HCI-Manager executor, and the other two heterogeneous HCI-Manager executors are newly added HCI-Manager executors.
[0060] When the client makes a resource operation request, the resource operation request is distributed to the three heterogeneous HCI-Manager executors. The three heterogeneous HCI-Manager executors independently calculate and output resource pre-operation results and send them to the arbiter. The arbiter conducts a vote according to the preset arbitration rules and outputs a trusted pre-operation result to the output proxy module, thereby improving the security and reliability of resource reallocation.
[0061] In specific implementation, the node can be a physical machine, a virtual machine, or a container.
[0062] As Figure 2 shown, it should be noted that multiple containers run on each heterogeneous executor pool server; through different combinations, various heterogeneous HCI-Manager executors can be generated on limited hardware resources, thereby increasing the endogenous security of the mimic distributed storage system.
[0063] In a specific implementation manner, the first heterogeneous executor pool server is implemented using the CentOS community enterprise operating system, an x86 architecture processor, and Python; the second heterogeneous executor pool server is implemented using the Ubuntu operating system, a Feilin processor, and Perl; the third heterogeneous executor pool server is implemented using the Debian operating system, a Shenwei processor, and Java.
[0064] In other embodiments, in different application environments, different numbers of HCI-Manager services can be deployed, and heterogeneous HCI-Manager executors with different HCI-Manager implementation methods can also be deployed; in different environments, various combinations of HCI-Manager executors can be dynamically generated according to the actual environment, increasing the environmental dynamic heterogeneity complexity, thereby improving the overall anti-attack ability.
[0065] Embodiment 3
[0066] The difference between this embodiment and Embodiment 2 lies in that:
[0067] The Mimic-coordinator service of each node also detects the state change of the internal resource allocation status of the node at a preset time interval, and when a state change is detected, obtains the changed internal resource allocation status and pushes it to the negative feedback controller, so that the negative feedback controller synchronously updates the resource allocation status of the dynamic heterogeneous HCI-Manager executor pool according to the changed internal resource allocation status.
[0068] This is because under normal circumstances, the heterogeneous HCI-Manager executor cannot obtain the status information of the cluster in the hyper-converged architecture. Therefore, if the status information of the cluster changes (whether it is the cluster status change caused by user-triggered resource allocation or the cluster status change caused by the cluster's own detection of hardware or service changes), the Mimic-coordinator service needs to synchronize the changed internal resource allocation status to the executor, so as to ensure the normal operation of the mimic hyper-converged management.
[0069] Further, when the Mimic-coordinator service of an ordinary node detects a change in the internal resource allocation status, it sends the changed internal resource allocation status to the Mimic-coordinator service of the master node through inter-node communication; when the Mimic-coordinator service of the master node detects a change in the internal resource allocation status, it obtains the changed internal resource allocation status;
[0070] The Mimic-coordinator service of the master node summarizes and calculates the internal resource allocation status of all nodes, generates the updated cluster resource status, and publishes it to the ordinary nodes for update.
[0071] Among them, the master node is responsible for coordinating and managing other nodes in a distributed cluster, and all ordinary nodes must obey the arrangement of the master node.
[0072] The existence of the master node can ensure the orderly operation of other nodes and the consistency of the written data in the database cluster on each node. The consistency here means that the data is the same on each cluster node and there is no difference.
[0073] Under normal circumstances, a master node is elected from Node 1, Node 2, and Node 3 through election methods such as algorithms based on sequence number election (e.g., Bully algorithm), majority algorithm (e.g., Raft algorithm, ZAB algorithm), etc., and it coordinates and manages other nodes to ensure the orderly operation of the cluster and data consistency among nodes.
[0074] Embodiment 4
[0075] This embodiment provides a resource reallocation method, including the following steps:
[0076] The client generates a resource operation request and copies and distributes it to each heterogeneous HCI-Manager executor in the dynamic heterogeneous HCI-Manager executor pool through the input proxy module;
[0077] The heterogeneous HCI-Manager executor calculates and generates a resource pre-operation result according to the resource operation request and the shared resource allocation status. The resource pre-operation result includes the target boundary node ID and the operation type tag, and finally sends a verdict request containing the resource pre-operation result to the verdict outputter;
[0078] The verdict outputter receives the verdict requests output by different heterogeneous HCI-Manager executors, conducts a vote according to the preset verdict rules, and outputs a credible pre-operation result to the output proxy module;
[0079] The output proxy module receives the credible pre-operation result and identifies the operation type tag carried by the credible pre-operation result. When the operation type tag carried by the credible pre-operation result is a query tag, it outputs and forwards the credible pre-operation result to the client; when the operation type tag carried by the credible pre-operation result is a change tag, it outputs and forwards the credible pre-operation result to each Mimic-coordinator service;
[0080] The Mimic-coordinator service queries the target node ID in the credible pre-operation result, determines whether it is the target node. If not, it updates the resource allocation status of the corresponding target node in the pre-stored cluster resource status according to the target node ID in the credible pre-operation result; if so, it calls the qemu interface to execute the credible pre-operation result on the resources in the node, and after the execution is completed, obtains the internal resource allocation status and pushes it to the negative feedback controller;
[0081] Meanwhile, when the verdict outputter outputs a credible pre-operation result, the negative feedback controller performs data synchronization or cleaning operations on the abnormal heterogeneous HCI-Manager execution bodies; or when the verdict outputter does not output a credible pre-operation result, the negative feedback controller controls the input proxy module to copy and distribute the resource operation requests to each heterogeneous HCI-Manager execution body again.
[0082] Figure 3 Fig. shows a timing diagram of a query operation. When the resource operation request is a query operation, the heterogeneous HCI-Manager execution body identifies the type of the resource operation request and queries the resource according to the resource operation request to generate a resource query result, and finally sends a verdict request containing the resource query result to the verdict outputter;
[0083] The verdict outputter receives the verdict requests output by different heterogeneous HCI-Manager execution bodies, performs a vote according to the preset verdict rules, and outputs a credible query result to the output proxy module;
[0084] The output proxy module receives the credible query result and outputs and forwards the credible query result to the client according to the carried query label.
[0085] Figure 4 Fig. shows a timing diagram of a change operation. When the resource operation request is a change operation, the heterogeneous HCI-Manager execution body identifies the type of the resource operation request and changes the resource according to the resource operation request to generate a resource change result, and finally sends a verdict request containing the resource change result to the verdict outputter;
[0086] The verdict outputter receives the verdict requests output by different heterogeneous HCI-Manager execution bodies, performs a vote according to the preset verdict rules, and outputs a credible change result to the output proxy module;
[0087] The output proxy module receives the credible change result and outputs and forwards the credible change result to each Mimic-coordinator service according to the carried change label.
[0088] The target Mimic-coordinator service calls the qemu interface to execute the credible pre-operation result on the resources within the node, and after the execution is completed, obtains the internal resource allocation status and pushes it to the negative feedback controller;
[0089] Other Mimic-coordinator services update the resource allocation status of the corresponding target node in the pre-stored cluster resource status according to the target node ID in the credible pre-operation result.
[0090] It can be understood that the Mimic - coordinator service of each node also detects the internal resource allocation status of the node at a preset time interval, and when it detects a change in the internal resource allocation status, it obtains the changed internal resource allocation status and pushes it to the negative feedback controller, so that the negative feedback controller synchronously updates the resource allocation status of the dynamic heterogeneous HCI - Manager execution body pool according to the changed internal resource allocation status.
[0091] Furthermore, when the Mimic - coordinator service of a common node detects a change in the internal resource allocation status, it sends the changed internal resource allocation status to the Mimic - coordinator service of the master node through inter - node communication; when the Mimic - coordinator service of the master node detects a change in the internal resource allocation status, it obtains the changed internal resource allocation status.
[0092] The Mimic - coordinator service of the master node aggregates and calculates the changed internal resource allocation status, generates an updated cluster resource status, and publishes it to the common nodes for update.
[0093] Embodiment 5
[0094] This embodiment provides a readable storage medium, on which instructions are stored, and when the instructions are executed by a processor, the steps of the resource re - allocation method described in Embodiment 4 are implemented.
[0095] In the above - mentioned embodiments, the descriptions of each embodiment have their own emphases. For parts not detailed or recorded in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0096] Those of ordinary skill in the art can realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, or a combination of computer software and electronic hardware. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Professional technicians can use different methods for each specific application to implement the described functions, but such implementation should not be considered to exceed the scope of this application.
[0097] In the embodiments provided in the present application, it should be understood that the disclosed systems and methods can be implemented in other ways. For example, the system embodiments described above are merely illustrative. For example, the division of the above modules is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed couplings or direct couplings or communication connections to each other can be indirect couplings or communication connections through some interfaces, devices or units, and can be in electrical, mechanical or other forms.
[0098] In addition, each functional unit in various embodiments of the present application can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above integrated unit can be implemented in the form of hardware or in the form of a software functional unit.
[0099] If the above integrated module is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, to implement all or part of the processes in the above method embodiments of the present application, it can also be completed by a computer program instructing relevant hardware. The above computer program can be stored in a computer-readable storage medium. When the computer program is executed by a processor, the steps of the above method embodiments can be implemented. Among them, the above computer program includes computer program code, and the above computer program code can be in the form of source code, object code, executable file or some intermediate form, etc.
[0100] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention and not to limit them; although the present invention has been described in detail with reference to the preferred embodiments, those of ordinary skill in the art should understand that it is still possible to modify the specific implementation manners of the present invention or perform equivalent replacements for some technical features; without departing from the spirit of the technical solutions of the present invention, they should all be covered by the scope of the technical solutions claimed in the present invention.
Claims
1. A mimicry hyper-convergence management device, characterized in that, including: an input proxy module, configured to receive a resource operation request sent by a client, and copy and distribute it to each heterogeneous HCI-Manager executor in the dynamic heterogeneous HCI-Manager executor pool, where the resource operation request includes a query request and a change request; a dynamic heterogeneous HCI-Manager executor pool, including two or more heterogeneous HCI-Manager executors sharing the resource allocation status of the hyper-converged system. Each heterogeneous HCI-Manager executor communicates and interconnects with the input proxy module, and is configured to calculate and generate a resource pre-operation result according to the resource operation request and the shared resource allocation status. The resource pre-operation result includes a target boundary node ID and an operation type tag, and finally sends an adjudication request including the resource pre-operation result to the adjudication outputter; an adjudication outputter, which communicates and interconnects with each heterogeneous HCI-Manager executor respectively, receives adjudication requests output by different heterogeneous HCI-Manager executors, conducts a vote according to preset adjudication rules, and outputs a trusted pre-operation result to the output proxy module; an output proxy module, which communicates and interconnects with the adjudication outputter, is configured to receive the trusted pre-operation result and identify the operation type tag carried by the trusted pre-operation result. When the operation type tag carried by the trusted pre-operation result is a query tag, forward the trusted pre-operation result to the client; when the operation type tag carried by the trusted pre-operation result is a change tag, forward the trusted pre-operation result to each Mimic-coordinator service; Mimic-coordinator services, which are set on the nodes of the hyper-converged cluster, are configured to query the target node ID in the trusted pre-operation result, determine whether it is the target node. If not, update the resource allocation status of the corresponding target node in the pre-stored cluster resource status according to the target node ID in the trusted pre-operation result; if so, call the qemu interface to execute the trusted pre-operation result on the resources within the node, and after the execution is completed, obtain the internal resource allocation status and push it to the negative feedback controller; and a negative feedback controller, which is interconnected with the output proxy module, each heterogeneous HCI-Manager executor and the input proxy module respectively, is configured to perform data synchronization or cleaning operations on abnormal heterogeneous HCI-Manager executors when the adjudication outputter outputs a trusted pre-operation result; and is configured to control the input proxy module to copy and distribute the resource operation request to each heterogeneous HCI-Manager executor again when the adjudication outputter does not output a trusted pre-operation result; and is also configured to synchronously update the resource allocation status of the dynamic heterogeneous HCI-Manager executor pool according to the obtained internal resource allocation status.
2. The mimicry hyper-converged management device according to claim 1, wherein: The Mimic - coordinator service of each node also detects changes in the internal resource allocation status of the node at a preset time interval. When a change in the status is detected, it obtains the changed internal resource allocation status and pushes it to the negative feedback controller, so that the negative feedback controller synchronously updates the resource allocation status of the dynamic heterogeneous HCI - Manager executor pool according to the changed internal resource allocation status.
3. The mimicry hyper-converged management device according to claim 2, wherein: When the Mimic - coordinator service of an ordinary node detects a change in the internal resource allocation status, it sends the changed internal resource allocation status to the Mimic - coordinator service of the master node through inter - node communication; when the Mimic - coordinator service of the master node detects a change in the internal resource allocation status, it obtains the changed internal resource allocation status. The Mimic - coordinator service of the master node aggregates and calculates the internal resource allocation status of all nodes, generates an updated cluster resource status, and publishes it to the ordinary nodes for update.
4. The mimicry hyper-converged management device according to claim 1, wherein: Abnormal heterogeneous HCI - Manager executors include those that have not sent adjudication requests, those that do not correspond to the trusted pre - operation results, and those with a trusted weight less than a preset value.
5. The mimicry hyper-converged management device according to claim 1, wherein: After each heterogeneous HCI - Manager executor tags the resource pre - operation result with the operation type according to the identified type, it converts the resource pre - operation result into an adjudication request in a preset format and sends it to the adjudication outputter. The adjudication outputter receives the adjudication requests output by different heterogeneous HCI - Manager executors, filters the adjudication requests according to a preset regular filtering rule, obtains a normalized adjudication request with a unified data structure format, and then conducts a vote according to the preset adjudication rule.
6. The mimicry hyper-converged management device according to claim 1, wherein: The change request includes an addition request, a deletion request, and a modification request.
7. A resource reallocation method, characterized in that, It includes the following steps: The client generates a resource operation request and distributes it through the input proxy module to each heterogeneous HCI - Manager executor in the dynamic heterogeneous HCI - Manager executor pool by replication. The heterogeneous HCI - Manager executor calculates and generates a resource pre - operation result according to the resource operation request and the shared resource allocation status. The resource pre - operation result includes the target boundary node ID and the operation type tag. Finally, it sends an adjudication request containing the resource pre - operation result to the adjudication outputter. The adjudication outputter receives the adjudication requests output by different heterogeneous HCI - Manager executors, conducts a vote according to the preset adjudication rule, and outputs a trusted pre - operation result to the output proxy module. The output proxy module receives the trusted pre-operation result and identifies the operation type tag carried by the trusted pre-operation result. When the operation type tag carried by the trusted pre-operation result is a query tag, it outputs and forwards the trusted pre-operation result to the client; when the operation type tag carried by the trusted pre-operation result is a change tag, it outputs and forwards the trusted pre-operation result to each Mimic-coordinator service; The Mimic-coordinator service queries the target node ID in the trusted pre-operation result and determines whether it is the target node. If not, it updates the resource allocation status of the corresponding target node in the pre-stored cluster resource status according to the target node ID in the trusted pre-operation result; If so, it calls the qemu interface to execute the trusted pre-operation result on the resources in the node, and after the execution is completed, it obtains the internal resource allocation status and pushes it to the negative feedback controller; Meanwhile, when the adjudication outputter outputs the trusted pre-operation result, the negative feedback controller performs data synchronization or cleaning operations on the abnormal heterogeneous HCI-Manager execution body; or when the adjudication outputter does not output the trusted pre-operation result, it controls the input proxy module to copy and distribute the resource operation request to each heterogeneous HCI-Manager execution body again.
8. The resource reallocation method according to claim 7, wherein: The Mimic-coordinator service of each node also detects the change of the internal resource allocation status of the node at a preset time interval, and when it detects that the status has changed, it obtains the changed internal resource allocation status and pushes it to the negative feedback controller, so that the negative feedback controller synchronously updates the resource allocation status of the dynamic heterogeneous HCI-Manager execution body pool according to the changed internal resource allocation status.
9. The resource reallocation method according to claim 7, characterized in that: When the Mimic-coordinator service of the ordinary node detects that the internal resource allocation status has changed, it sends the changed internal resource allocation status to the Mimic-coordinator service of the master node through inter-node communication; when the Mimic-coordinator service of the master node detects that the internal resource allocation status has changed, it obtains the changed internal resource allocation status; The Mimic-coordinator service of the master node summarizes and calculates the internal resource allocation status of all nodes, generates an updated cluster resource status and publishes it to the ordinary nodes for update.
10. A readable storage medium, on which instructions are stored, characterized in that: When executed by the processor, the instruction implements the steps of the resource reallocation method as described in any one of claims 7-9.
Citation Information
Patent Citations
High-speed light-weight mimetic virtual network construction method
CN108055232A
Mimicry distributed storage system, data reading and writing method and readable storage medium
CN111885124A