Processing Method, Device and Electronic Device of Server Cluster
By setting up reverse proxy services in the CDH cluster, mutual trust access and service diversion of multiple clusters are achieved, and the problems of high pressure and complex configuration in the existing technology are solved, and dynamic mutual trust and reduced KDC pressure are achieved.
Patent Information
- Application Number
- CN202211346058.2
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-31
- Publication Date
- 2025-05-27
- Estimated Expiration
- 2042-10-31
AI Technical Summary
The existing cross-cluster access solutions for multiple existing CDH clusters with Kerberos authentication have problems such as excessive KDC pressure, troubles in configuration, and inability to dynamically increase cluster mutual trust, which has certain limitations.
By setting up a reverse proxy service, the management nodes of the first server cluster and the second server cluster are allowed to access the main library of the key distribution center, while other nodes access different backup libraries respectively, to achieve detailed service diversion and reduce the pressure on the key distribution center.
It realizes mutual trust access to multiple clusters, is simple to configure, can dynamically increase mutual trust clusters, reduce the pressure of KDC access, and prevents abnormal service caused by pressure in the key distribution center.
Smart Images

Figure CN115914226B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of data processing, and in particular, to a processing method, apparatus, and electronic device for a server cluster. Background Art
[0002] Kerberos is an identity authentication protocol applied to the authentication of a CDH (Cloudera's Distribution Including Apache Hadoop) cluster. It can access cluster services through a client Keytab (password book). However, by default, there can only be one server-side KDC (Key Distribution Center) configuration for the same client. Therefore, it can only access one CDH cluster through this configuration and cannot access multiple clusters simultaneously for cross-cluster operations on the clusters.
[0003] For cross-cluster operations, existing cross-cluster access solutions for multiple CDH clusters with Kerberos authentication have problems such as excessive KDC pressure, cumbersome configuration, and inability to dynamically increase cluster mutual trust, and have certain limitations. Summary of the Invention
[0004] In view of this, an object of the present invention is to provide a processing method, apparatus, and electronic device for a server cluster to reduce the pressure on the key distribution center and prevent the key distribution center from malfunctioning due to pressure.
[0005] In a first aspect, an embodiment of the present invention provides a processing method for a server cluster. A client node accesses a first server cluster through a key distribution center to enable the first server cluster to process the business of the client node. The method includes: setting multiple standby key distribution centers based on the primary database of the key distribution center; setting a reverse proxy service to enable the management nodes of the first server cluster and the second server cluster to access the primary database of the key distribution center, and other nodes of the first server cluster and the second server cluster to access different standby databases of the key distribution center respectively, where the other nodes are nodes other than the management nodes; and the client node accesses the first server cluster or the second server cluster through the key distribution center and the reverse proxy service to enable the first server cluster or the second server cluster to process the business of the client node.
[0006] Second aspect, an embodiment of the present invention further provides a processing device for a server cluster. A client node accesses a first server cluster through a key distribution center so that the first server cluster processes the services of the client node. The device includes: a standby database setting module for the key distribution center, configured to set multiple standby databases for the key distribution center based on the primary database of the key distribution center; a reverse proxy service setting module, configured to set a reverse proxy service so that the management nodes of the first server cluster and the second server cluster access the primary database of the key distribution center, and other nodes of the first server cluster and the second server cluster respectively access different standby databases of the key distribution center; where the other nodes are nodes other than the management nodes; a server cluster access module, configured to enable the client node to access the first server cluster or the second server cluster through the key distribution center and the reverse proxy service, so that the first server cluster or the second server cluster processes the services of the client node.
[0007] Third aspect, an embodiment of the present invention further provides an electronic device, including a processor and a memory. The memory stores computer-executable instructions that can be executed by the processor. The processor executes the computer-executable instructions to implement the steps of the above-mentioned processing method for a server cluster.
[0008] Fourth aspect, an embodiment of the present invention further provides a computer-readable storage medium. The computer-readable storage medium stores computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions cause the processor to implement the steps of the above-mentioned processing method for a server cluster.
[0009] The embodiments of the present invention bring the following beneficial effects:
[0010] The embodiments of the present invention provide a processing method, device, and electronic device for a server cluster. By setting up a reverse proxy service, authentication mutual trust between the first server cluster and the second server cluster can be completed. By jointly processing the services of the client node by the first server cluster and the second server cluster, fine-grained service diversion can be achieved, the pressure on the key distribution center can be reduced, and it can be prevented that the key distribution center fails to provide normal services due to pressure.
[0011] Other features and advantages of the present disclosure will be described in the subsequent specification, or some features and advantages can be inferred from the specification without doubt, or can be known by implementing the above technologies of the present disclosure.
[0012] To make the above-mentioned objects, features, and advantages of the present disclosure more obvious and understandable, the following specific preferred embodiments are given below, and in conjunction with the accompanying drawings, detailed descriptions are as follows. Description of the Drawings
[0013] To more clearly illustrate the specific embodiments of the present invention or the technical solutions in the prior art, the following will briefly introduce the drawings required for the description of the specific embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0014] Figure 1 Schematic diagram of a cross-cluster access solution provided by an embodiment of the present invention;
[0015] Figure 2 Schematic diagram of another cross-cluster access solution provided by an embodiment of the present invention;
[0016] Figure 3 Flowchart of a processing method for a server cluster provided by an embodiment of the present invention;
[0017] Figure 4 Flowchart of another processing method for a server cluster provided by an embodiment of the present invention;
[0018] Figure 5 Schematic diagram of a server cluster authentication and mutual trust solution provided by an embodiment of the present invention;
[0019] Figure 6 Schematic diagram of the structure of a processing device for a server cluster provided by an embodiment of the present invention;
[0020] Figure 7 Schematic diagram of the structure of an electronic device provided by an embodiment of the present invention. Specific Embodiments
[0021] To make the objectives, technical solutions, and advantages of the embodiments of the present invention clearer, the following will clearly and completely describe the technical solutions of the present invention in conjunction with the drawings. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. All other embodiments obtained by those of ordinary skill in the art based on the embodiments of the present invention without creative efforts fall within the scope of protection of the present invention.
[0022] Kerberos is an encryption ticket-based authentication protocol applied to the authentication of CDH (Cloudera's Distribution Including Apache Hadoop) clusters. It can access cluster services through the client Keytab (password book). However, by default, there can only be one server KDC (Key Distribution Center) configuration for the same client. Therefore, it can only access one CDH cluster through this configuration and cannot access multiple clusters simultaneously for cross-cluster operations on the clusters.
[0023] For cross-cluster operations, there are the following two cross-cluster access solutions for CDH clusters with Kerberos authentication:
[0024] (1) Refer to Figure 1 the schematic diagram of a cross-cluster access solution shown in. Use the same KDC, and multiple clusters share the same KDC. All client configurations and cluster Kerberos configurations are the same. Among them, there is a separate client configuration file krb5.conf, which by default records the address of a KDC. This KDC address serves a certain CDH cluster. The Keytab password book is a separate file generated and signed by the KDC: A Keytab is a file that contains princIPals (used to reference an entry in the authentication service database) and the encrypted princIPal key. The Keytab file is unique for each host because the Key contains the hostname. The Keytab file is used to authenticate a princIPal on a host to Kerberos without manual interaction and saving plain-text passwords.
[0025] (2) Refer to Figure 2 the schematic diagram of another cross-cluster access solution shown in. Use different KDCs, but multiple authentication realms need to be configured for the CDH clusters and the clients, and cross-domain mutual trust needs to be specified. The specific steps can be as follows: Configure the trust ticket between the two cluster KDCs and add princIPals.
[0026] Modify the CDH cluster HDFS configuration, add the accessible realm, and configure the mapping rules for princIPal and user. Modify the krb5.conf of all node clients and add the accessible realm.
[0027] However, in the above two cross-cluster access solutions, in solution (1), using the same KDC will cause excessive pressure on the KDC, which may lead to cluster authentication delays and authentication failures, resulting in cluster service outages and affecting the business. Solution (2) has cumbersome configurations and cannot dynamically add mutually trusted clusters without affecting the business of other clusters. It is necessary to modify all CDH configurations and KDC tickets to achieve cross-domain authentication. In summary, the above two solutions have problems such as excessive KDC pressure, troublesome configurations, and inability to dynamically increase cluster mutual trust, and have certain limitations.
[0028] Based on this, a processing method, device, and electronic device for a server cluster provided by an embodiment of the present invention specifically relate to a Kerberos authentication mutual trust solution between multiple CDH clusters, which can achieve mutual trust access between multiple clusters, has simple configurations, can dynamically add mutually trusted clusters as needed without affecting the business of other CDH clusters, and can also separate and implement KDC authentication shunting according to cluster services, business types, etc., reducing the KDC access pressure.
[0029] To facilitate the understanding of this embodiment, first, a processing method for a server cluster disclosed in an embodiment of the present invention will be introduced in detail.
[0030] This embodiment provides a processing method for a server cluster. A client node accesses a first server cluster through a key distribution center so that the first server cluster processes the business of the client node.
[0031] The client node can access the key distribution center (KDC) according to the client configuration file krb5.conf, and then access the first server cluster through the KDC. The first server cluster processes the business of the client node.
[0032] In this embodiment, the original client node can only access the first server cluster through the key distribution center, and the business of the client node can only be processed by the first server cluster. This embodiment can enable the first server cluster and the second server cluster to authenticate and be mutually trusted. After authentication and mutual trust, the client node can access the first server cluster and the second server cluster through the key distribution center, and the business of the client node can only be processed by the first server cluster or the second server cluster.
[0033] Based on the above description, refer to Figure 3 the flowchart of a processing method for a server cluster shown below. The processing method for the server cluster includes the following steps:
[0034] Step S302, set up standby libraries of multiple key distribution centers based on the master library of the key distribution center.
[0035] The Key Distribution Center (KDC) is a service running on a physically secure server. The KDC maintains a database of account information for all security principals in the realm.
[0036] Along with other information of each security principal, the KDC stores an encryption key known only to the security principal and the KDC. This key is also called the long-term key and is used for exchange between the security principal and the KDC. In most implementation protocols, the long-term key is regenerated from the user's login password. When the KDC distributes keys, both communicating hosts need to apply to the KDC for a session key, and the permanent session key shared by both is used when the host communicates with the KDC.
[0037] In this embodiment, for the Key Distribution Center (KDC), multiple standby KDCs (such as KDC1, KDC2, etc.) can be set up for the main library of the KDC. After setting up the standby KDCs, the data of the KDC main library can be synchronously transferred to each standby KDC at regular intervals.
[0038] Step S304: Set up a reverse proxy service so that the management nodes of the first server cluster and the second server cluster can access the main library of the Key Distribution Center, and other nodes of the first server cluster and the second server cluster can respectively access different standby libraries of the Key Distribution Center; where other nodes refer to nodes other than the management nodes.
[0039] After setting up the standby KDCs, this embodiment also needs to set up a reverse proxy service, such as the nginx service. The nginx service is a high-performance HTTP (Hyper Text Transfer Protocol) and reverse proxy Web (World Wide Web) service.
[0040] The reverse proxy service is located between the user and the target server. However, for the user, the reverse proxy server is equivalent to the target server, that is, the user can directly access the reverse proxy server to obtain the resources of the target server. At the same time, the user does not need to know the address of the target server and does not need to make any settings on the user side. The reverse proxy server is usually used for Web acceleration, that is, using the reverse proxy as a front-end machine of the Web server to reduce the load on the network and the server and improve the access efficiency.
[0041] In this embodiment, through the set reverse proxy service, the management nodes of the first server cluster and the second server cluster can access the main library of the Key Distribution Center, and other nodes of the first server cluster and the second server cluster can respectively access different standby libraries of the Key Distribution Center, thereby achieving fine-grained traffic diversion.
[0042] Step S306: The client node accesses the first server cluster or the second server cluster through the key distribution center and the reverse proxy service, so that the first server cluster or the second server cluster processes the services of the client node.
[0043] In this embodiment, the first server cluster and the second server cluster can be authenticated and trusted through the set reverse proxy service, that is, both the first server cluster and the second server cluster can communicate with the client node. The client node can access the first server cluster or the second server cluster through the key distribution center and the reverse proxy service, use the accessed first server cluster or the second server cluster as the server cluster for processing services, and let the accessed first server cluster or the second server cluster process the services of the client node.
[0044] The embodiment of the present invention provides a processing method for a server cluster. By setting up a reverse proxy service, the authentication and mutual trust between the first server cluster and the second server cluster can be completed. By jointly processing the services of the client node by the first server cluster and the second server cluster, the detailed diversion of services can be realized, the pressure on the key distribution center can be reduced, and the key distribution center can be prevented from malfunctioning due to pressure.
[0045] As Figure 4 shown in the flowchart of another processing method for a server cluster in the optional embodiment, the processing method for the server cluster in the optional embodiment includes the following steps:
[0046] Step S402: Set up multiple standby libraries of the key distribution center based on the main library of the key distribution center.
[0047] In this embodiment, nginx diversion and the scheme of migrating the newly added mutual trust CDH cluster KDC are mainly adopted. First, the mutual trust between the two clusters (that is, the first server cluster CDH1 and the second server cluster CDH2) needs to be completed.
[0048] Specifically, in this embodiment, multiple standby libraries of the key distribution center can be established; the data of the main library of the key distribution center is regularly synchronized to multiple standby libraries of the key distribution center.
[0049] See Figure 5 shown in the schematic diagram of a server cluster authentication and mutual trust scheme. The first server cluster CDH1 can be used normally. New standby libraries KDC1 and KDC2 of the key distribution center are added, and the data of the main library of the key distribution center (that is, the KDC main library) is regularly synchronized to multiple standby libraries KDC1 and KDC2 of the key distribution center.
[0050] Step S404: Set a first port in the reverse proxy service to enable the management nodes of the first server cluster and the second server cluster to access the primary database of the key distribution center through the first port; set a second port in the reverse proxy service to enable other nodes of the first server cluster to access the first standby database of the key distribution center; set a third port in the reverse proxy service to enable other nodes of the second server cluster to access the second standby database of the key distribution center.
[0051] In this embodiment, a new nginx service can be added to a server, and IP (Internet Protocol) shunting can be implemented according to reverse proxy. As Figure 5 shown, the shunting situation can be as follows:
[0052] (1) First port: Designate that the management nodes (such as SCM Server IP) of the first server cluster CDH1 and the second server cluster CDH2 can access, and the first port points to the primary database of the key distribution center (such as port 88 of the KDC primary database).
[0053] (2) Second port: Designate that other nodes (such as the cluster IP of CDH1) of the first server cluster CDH1 can access, and the second port points to the first standby database of the key distribution center (such as port 88 of KDC1).
[0054] (3) Third port: Designate that other nodes (such as the cluster IP of CDH2) of the second server cluster CDH2 can access, and the third port points to the second standby database of the key distribution center (such as port 88 of KDC2).
[0055] After setting the reverse proxy service, this embodiment can also configure the first server cluster and the second server cluster. Specifically: Keep the services of the first server cluster and stop the services of the second server cluster, and adjust the configurations of the second server cluster and the client nodes; keep the services of the second server cluster and stop the services of the first server cluster, and adjust the configurations of the first server cluster and the client nodes.
[0056] When adjusting the configuration of the second server cluster, the host of the key distribution center of the second server cluster can be set to the address of the reverse proxy service, and the domain name configuration of the second server cluster can be set to the same domain name configuration as that of the first server cluster.
[0057] Among them, the KDC host of the second server cluster CDH2 can be set to the nginx address, the relevant domain name configuration of the second server cluster CDH2 can be modified to be the same as that of the first server cluster CDH1 cluster, and then the client configuration can be redeployed, the Keytab ticket can be regenerated, and the service can be started.
[0058] When adjusting the configuration of the first server cluster, the host of the key distribution center of the first server cluster can be set to the address of the reverse proxy service. The relevant domain name configuration of the first server cluster CDH1 does not need to be modified. Only the KDC host of the first server cluster CDH1 needs to be modified to the nginx address. Then, the client configuration can be redeployed, the Keytab ticket can be regenerated, and the service can be started.
[0059] At this time, the first server cluster CDH1 and the second server cluster CDH2 can already access each other across clusters. The server cluster configuration method of this embodiment is relatively simple. CDH clusters can be dynamically added for cross-cluster mutual trust access without changing the configurations of other clusters and without affecting the services of other clusters.
[0060] Step S406, the client node accesses the first server cluster or the second server cluster through the key distribution center and the reverse proxy service, so that the first server cluster or the second server cluster processes the business of the client node.
[0061] Through the foregoing steps, cross-cluster access between the first server cluster CDH1 and the second server cluster CDH2 can be completed. Therefore, the client node can access the first server cluster or the second server cluster through the key distribution center and the reverse proxy service, and the accessed first server cluster or second server cluster processes the business of the client node. Moreover, the configuration of this embodiment is relatively simple. CDH clusters can be dynamically added for cross-cluster mutual trust access without changing the configurations of other clusters and without affecting the services of other clusters.
[0062] In this embodiment, server clusters can also be continuously added. For example: obtain the third server cluster; establish the third standby library of the key distribution center; set the fourth port in the reverse proxy service so that other nodes of the third server cluster can access the third standby library of the key distribution center.
[0063] After the configurations of the first server cluster and the second server cluster are completed in this embodiment, CDH clusters (such as the third server cluster CDH3) can be dynamically added for mutual trust access, and the nginx proxy situation can also be timed according to specific services to achieve more refined traffic splitting.
[0064] As Figure 5 shown, a third standby library KDC3 of the key distribution center can be added, master-slave synchronization can be configured, and the fourth port can be set in the reverse proxy service (such as the nginx service): specify the third server cluster CDH3 (that is, Figure 5Other nodes (such as the cluster IP of CDH3) of the third-party user in it can be accessed. The fourth port points to the third standby library of the key distribution center (such as port 88 of KDC3), and the dynamic loading service takes effect. In addition, for the first port of the reverse proxy service: the management nodes (such as SCM Server IP) of the first server cluster CDH1, the second server cluster CDH2, and the third server cluster CDH3 are specified to be accessible, and the first port points to the main library of the key distribution center (such as port 88 of the KDC main library).
[0065] After that, the configuration of the third server cluster can be adjusted. For example: keep the services of the first server cluster and the second server cluster and stop the services of the third server cluster, and adjust the configuration of the third server cluster and the client nodes.
[0066] All services of the third server cluster CDH3 cluster can be stopped, and the services of the first server cluster CDH1 and the second server cluster CDH2 can be kept. The KDC host of the third server cluster CDH3 can be set to the nginx address, the relevant domain name configuration of the third server cluster CDH3 can be modified to be the same as that of the first server cluster CDH1 cluster, and then the client configuration can be redeployed, the Keytab ticket can be regenerated, and the service can be started. At this time, the mutual trust configuration operation of the first server cluster CDH1, the second server cluster CDH2, and the third server cluster CDH3 is completed.
[0067] As Figure 5 shown, in addition to the solution of the newly added third standby library KDC3, the present application can also enable other nodes of the third server cluster CDH3 to access KDC1 or KDC2, and the mutual trust configuration operation of the first server cluster CDH1, the second server cluster CDH2, and the third server cluster CDH3 can also be realized.
[0068] Through the foregoing steps, cross-cluster access of the first server cluster CDH1, the second server cluster CDH2, and the third server cluster CDH3 can be completed. For example: the client node accesses the first server cluster, the second server cluster, or the third server cluster through the key distribution center and the reverse proxy service, so that the first server cluster, the second server cluster, or the third server cluster processes the business of the client node.
[0069] The client node can access the first server cluster CDH1, the second server cluster CDH2, or the third server cluster CDH3 through the key distribution center and the reverse proxy service, and the accessed first server cluster CDH1, the second server cluster CDH2, or the third server cluster CDH3 processes the business of the client node, so as to achieve more detailed traffic splitting.
[0070] As Figure 5As shown, in addition, more server clusters can be added in this embodiment, such as: CDH4, CDH5... CDHn, to achieve more refined traffic diversion through more server clusters.
[0071] The above method provided by the embodiment of the present invention can achieve mutual trust access among multiple clusters, with simple configuration. Without affecting the services of other CDH clusters, mutual trust clusters can be dynamically added as needed, and KDC authentication traffic diversion can also be achieved separately according to cluster services, business types, etc., reducing the KDC access pressure.
[0072] The above method provided by the embodiment of the present invention has the following advantages: simple configuration, can dynamically add CDH clusters for cross-cluster mutual trust access, does not require changing the configurations of other clusters, and does not affect the services of other clusters. More refined traffic diversion can be performed according to the business, reducing the KDC pressure and preventing the KDC from abnormal services due to pressure. The KDC-related tickets can be uniformly managed through the main library of the KDC, reducing the maintenance costs of multiple clusters.
[0073] Corresponding to the above method embodiment, the embodiment of the present invention provides a processing device for a server cluster. The client node accesses the first server cluster through the key distribution center to enable the first server cluster to process the business of the client node. As Figure 6 shown in the structural schematic diagram of a processing device for a server cluster, the processing device for the server cluster includes:
[0074] The standby library setting module 61 of the key distribution center is used to set multiple standby libraries of the key distribution center based on the main library of the key distribution center;
[0075] The reverse proxy service setting module 62 is used to set the reverse proxy service to enable the management nodes of the first server cluster and the second server cluster to access the main library of the key distribution center, and the other nodes of the first server cluster and the second server cluster respectively access different standby libraries of the key distribution center; where the other nodes are the nodes except the management nodes;
[0076] The server cluster access module 63 is used for the client node to access the first server cluster or the second server cluster through the key distribution center and the reverse proxy service to enable the first server cluster or the second server cluster to process the business of the client node.
[0077] The embodiment of the present invention provides a processing device for a server cluster. By setting the reverse proxy service, the authentication mutual trust between the first server cluster and the second server cluster can be completed. By jointly processing the business of the client node by the first server cluster and the second server cluster, the refined traffic diversion of the business can be achieved, reducing the pressure on the key distribution center and preventing the key distribution center from abnormal services due to pressure.
[0078] The standby database setting module of the above key distribution center is used to establish standby databases for multiple key distribution centers; and synchronize the data of the master database of the key distribution center to the standby databases of multiple key distribution centers regularly.
[0079] The above reverse proxy service setting module is used to set a first port in the reverse proxy service, so that the management nodes of the first server cluster and the second server cluster can access the master database of the key distribution center through the first port; set a second port in the reverse proxy service, so that other nodes of the first server cluster can access the first standby database of the key distribution center; set a third port in the reverse proxy service, so that other nodes of the second server cluster can access the second standby database of the key distribution center.
[0080] The above device further includes: a server cluster configuration module, which is used to keep the service of the first server cluster and stop the service of the second server cluster, and adjust the configurations of the second server cluster and the client nodes; keep the service of the second server cluster and stop the service of the first server cluster, and adjust the configurations of the first server cluster and the client nodes.
[0081] The above server cluster configuration module is used to set the host of the key distribution center of the second server cluster as the address of the reverse proxy service, and configure the domain name of the second server cluster to be the same as the domain name configuration of the first server cluster; the above server cluster configuration module is used to set the host of the key distribution center of the first server cluster as the address of the reverse proxy service.
[0082] The above device further includes: a third server cluster processing module, which is used to obtain the third server cluster; establish a third standby database of the key distribution center; set a fourth port in the reverse proxy service, so that other nodes of the third server cluster can access the third standby database of the key distribution center.
[0083] The above third server cluster processing module is further used to keep the services of the first server cluster and the second server cluster and stop the service of the third server cluster, and adjust the configurations of the third server cluster and the client nodes.
[0084] The above third server cluster processing module is further used to enable the client nodes to access the first server cluster, the second server cluster or the third server cluster through the key distribution center and the reverse proxy service, so that the first server cluster, the second server cluster or the third server cluster processes the services of the client nodes.
[0085] The processing device of the server cluster provided by the embodiment of the present invention has the same technical features as the processing method of the server cluster provided by the above embodiment, so it can also solve the same technical problems and achieve the same technical effects.
[0086] An embodiment of the present invention further provides an electronic device for running the processing method of the above server cluster; refer to Figure 7 As shown in the schematic structural diagram of an electronic device, the electronic device includes a memory 100 and a processor 101. Among them, the memory 100 is used to store one or more computer instructions, and the one or more computer instructions are executed by the processor 101 to perform the following steps:
[0087] Based on the main library of the key distribution center, set up multiple standby libraries of the key distribution center; set up a reverse proxy service so that the management nodes of the first server cluster and the second server cluster can access the main library of the key distribution center, and other nodes of the first server cluster and the second server cluster respectively access different standby libraries of the key distribution center; where the other nodes are nodes other than the management nodes; the client node accesses the first server cluster or the second server cluster through the key distribution center and the reverse proxy service, so that the first server cluster or the second server cluster processes the business of the client node.
[0088] In an optional embodiment of the present invention, the step of setting up multiple standby libraries of the key distribution center based on the main library of the key distribution center includes: establishing multiple standby libraries of the key distribution center; regularly synchronizing the data of the main library of the key distribution center to multiple standby libraries of the key distribution center.
[0089] In an optional embodiment of the present invention, the step of setting up a reverse proxy service includes: setting a first port in the reverse proxy service so that the management nodes of the first server cluster and the second server cluster can access the main library of the key distribution center through the first port; setting a second port in the reverse proxy service so that other nodes of the first server cluster can access the first standby library of the key distribution center; setting a third port in the reverse proxy service so that other nodes of the second server cluster can access the second standby library of the key distribution center.
[0090] In an optional embodiment of the present invention, after the step of setting up a reverse proxy service, the method further includes: maintaining the service of the first server cluster and stopping the service of the second server cluster, and adjusting the configurations of the second server cluster and the client node; maintaining the service of the second server cluster and stopping the service of the first server cluster, and adjusting the configurations of the first server cluster and the client node.
[0091] In an optional embodiment of the present invention, the step of adjusting the configuration of the second server cluster includes: setting the host of the key distribution center of the second server cluster as the address of the reverse proxy service, and setting the domain name configuration of the second server cluster to be the same as the domain name configuration of the first server cluster; the step of adjusting the configuration of the first server cluster includes: setting the host of the key distribution center of the first server cluster as the address of the reverse proxy service.
[0092] In an alternative embodiment of the present invention, the method further includes: obtaining a third server cluster; establishing a third standby library of the key distribution center; and setting a fourth port in the reverse proxy service to enable other nodes of the third server cluster to access the third standby library of the key distribution center.
[0093] In an alternative embodiment of the present invention, after the step of setting the fourth port in the reverse proxy service, the method further includes: maintaining the services of the first server cluster and the second server cluster and stopping the service of the third server cluster, and adjusting the configurations of the third server cluster and the client nodes.
[0094] In an alternative embodiment of the present invention, after the step of setting the fourth port in the reverse proxy service, the method further includes: the client node accessing the first server cluster, the second server cluster or the third server cluster through the key distribution center and the reverse proxy service, so that the first server cluster, the second server cluster or the third server cluster processes the business of the client node.
[0095] In the implementation of the present invention, by setting the reverse proxy service, the authentication mutual trust between the first server cluster and the second server cluster can be completed. By jointly processing the business of the client node by the first server cluster and the second server cluster, the detailed diversion of the business can be realized, the pressure on the key distribution center can be reduced, and the abnormal service caused by the pressure on the key distribution center can be prevented.
[0096] Further, Figure 7 The electronic device shown further includes a bus 102 and a communication interface 103, and the processor 101, the communication interface 103 and the memory 100 are connected through the bus 102.
[0097] Among them, the memory 100 may include a high-speed random access memory (RAM, Random Access Memory), and may also include a non-volatile memory, such as at least one disk memory. Through at least one communication interface 103 (which can be wired or wireless), the communication connection between the system network element and at least one other network element can be realized, and the Internet, wide area network, local area network, metropolitan area network, etc. can be used. The bus 102 can be an ISA bus, a PCI bus or an EISA bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of simplicity of representation, Figure 7 only a bidirectional arrow is used in the figure, but it does not mean that there is only one bus or one type of bus.
[0098] The processor 101 may be an integrated circuit chip with the ability to process signals. In the implementation process, each step of the above method can be completed by the integrated logic circuit of the hardware in the processor 101 or the instructions in the form of software. The above-mentioned processor 101 may be a general-purpose processor, including a central processing unit (CPU for short), a network processor (NP for short), etc.; it may also be a digital signal processor (DSP for short), an application specific integrated circuit (ASIC for short), a field-programmable gate array (FPGA for short), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components. It can implement or execute each method, step and logic block diagram disclosed in the embodiments of the present invention. The general-purpose processor may be a microprocessor or the processor may also be any conventional processor, etc. The steps of the method disclosed in combination with the embodiments of the present invention can be directly embodied as being executed and completed by the hardware decoding processor, or executed and completed by the combination of the hardware and software modules in the decoding processor. The software module may be located in a mature storage medium in the art such as a random access memory, a flash memory, a read-only memory, a programmable read-only memory, or an electrically erasable programmable memory, a register, etc. This storage medium is located in the memory 100, and the processor 101 reads the information in the memory 100 and combines its hardware to complete the steps of the method in the foregoing embodiments.
[0099] The embodiments of the present invention also provide a computer-readable storage medium, which stores computer-executable instructions. When the computer-executable instructions are called and executed by a processor, the computer-executable instructions cause the processor to implement the above-mentioned processing method of the server cluster, and the following steps can be executed:
[0100] Based on the main library of the key distribution center, set up multiple standby libraries of the key distribution center; set up a reverse proxy service so that the management nodes of the first server cluster and the second server cluster can access the main library of the key distribution center, and the other nodes of the first server cluster and the second server cluster respectively access different standby libraries of the key distribution center; wherein, the other nodes are the nodes except the management nodes; the client node accesses the first server cluster or the second server cluster through the key distribution center and the reverse proxy service, so that the first server cluster or the second server cluster processes the services of the client node.
[0101] In an alternative embodiment of the present invention, the steps of setting up standby repositories of multiple key distribution centers based on the primary repository of the key distribution center include: establishing standby repositories of multiple key distribution centers; and synchronizing the data of the primary repository of the key distribution center to the standby repositories of multiple key distribution centers at regular intervals.
[0102] In an alternative embodiment of the present invention, the steps of setting up a reverse proxy service include: setting a first port in the reverse proxy service to enable the management nodes of the first server cluster and the second server cluster to access the primary repository of the key distribution center through the first port; setting a second port in the reverse proxy service to enable other nodes of the first server cluster to access the first standby repository of the key distribution center; and setting a third port in the reverse proxy service to enable other nodes of the second server cluster to access the second standby repository of the key distribution center.
[0103] In an alternative embodiment of the present invention, after the steps of setting up the reverse proxy service, the method further includes: maintaining the service of the first server cluster and stopping the service of the second server cluster, and adjusting the configurations of the second server cluster and the client nodes; and maintaining the service of the second server cluster and stopping the service of the first server cluster, and adjusting the configurations of the first server cluster and the client nodes.
[0104] In an alternative embodiment of the present invention, the steps of adjusting the configuration of the second server cluster include: setting the host of the key distribution center of the second server cluster to the address of the reverse proxy service, and setting the domain name configuration of the second server cluster to be the same as that of the first server cluster; the steps of adjusting the configuration of the first server cluster include: setting the host of the key distribution center of the first server cluster to the address of the reverse proxy service.
[0105] In an alternative embodiment of the present invention, the method further includes: obtaining a third server cluster; establishing a third standby repository of the key distribution center; and setting a fourth port in the reverse proxy service to enable other nodes of the third server cluster to access the third standby repository of the key distribution center.
[0106] In an alternative embodiment of the present invention, after the step of setting the fourth port in the reverse proxy service, the method further includes: maintaining the services of the first server cluster and the second server cluster and stopping the service of the third server cluster, and adjusting the configurations of the third server cluster and the client nodes.
[0107] In an alternative embodiment of the present invention, after the step of setting the fourth port in the reverse proxy service, the method further includes: the client node accessing the first server cluster, the second server cluster or the third server cluster through the key distribution center and the reverse proxy service, so that the first server cluster, the second server cluster or the third server cluster processes the business of the client node.
[0108] In the implementation of the present invention, by setting up a reverse proxy service, the authentication mutual trust between the first server cluster and the second server cluster can be completed. By jointly processing the services of the client nodes by the first server cluster and the second server cluster, the fine-grained diversion of services can be realized, the pressure on the key distribution center can be reduced, and it can be prevented that the key distribution center fails to provide normal services due to pressure.
[0109] The computer program product of the processing method, device and electronic device of the server cluster provided by the embodiment of the present invention includes a computer-readable storage medium storing program codes. The instructions included in the program codes can be used to execute the methods in the foregoing method embodiments. For the specific implementation, reference can be made to the method embodiments and will not be elaborated herein.
[0110] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described system and / or device can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0111] In addition, in the description of the embodiments of the present invention, unless otherwise clearly defined and limited, the terms "installation", "connection" and "connection" should be understood in a broad sense. For example, it can be a fixed connection, a detachable connection or an integral connection; it can be a mechanical connection or an electrical connection; it can be a direct connection or an indirect connection through an intermediate medium, and it can be the communication inside two components. For those of ordinary skill in the art, the specific meanings of the above terms in the present invention can be understood according to specific situations.
[0112] If the function is implemented in the form of a software function unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of the present invention, in essence, or the part that contributes to the prior art or a part of the technical solution can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, an electronic device or a network device, etc.) to execute all or part of the steps of the methods of the various embodiments of the present invention. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, Read-Only Memory), random access memories (RAM, Random Access Memory), magnetic disks or optical discs that can store program codes.
[0113] In the description of the present invention, it should be noted that the orientation or positional relationship indicated by the terms "center", "upper", "lower", "left", "right", "vertical", "horizontal", "inner", "outer", etc. is based on the orientation or positional relationship shown in the drawings. It is only for the convenience of describing the present invention and simplifying the description, rather than indicating or implying that the device or element referred to must have a specific orientation, be constructed and operated in a specific orientation. Therefore, it should not be construed as a limitation to the present invention. In addition, the terms "first", "second", and "third" are only used for descriptive purposes and cannot be construed as indicating or implying relative importance.
[0114] Finally, it should be noted that the above embodiments are only specific embodiments of the present invention, which are used to illustrate the technical solutions of the present invention, rather than limiting them. The protection scope of the present invention is not limited thereto. Although the present invention has been described in detail with reference to the foregoing embodiments, those of ordinary skill in the art should understand that any person skilled in the art within the technical scope disclosed by the present invention can still modify the technical solutions described in the foregoing embodiments, or can easily conceive of changes, or make equivalent replacements for some of the technical features; and these modifications, changes or replacements do not make the essence of the corresponding technical solutions deviate from the spirit and scope of the technical solutions of the embodiments of the present invention, and should all be covered within the protection scope of the present invention. Therefore, the protection scope of the present invention should be subject to the protection scope of the claims.
Claims
1. A processing method for a server cluster, characterized in that, a client node accesses a first server cluster through a key distribution center, so that the first server cluster processes the services of the client node, and the method includes: setting a plurality of standby libraries of the key distribution center based on the main library of the key distribution center; setting a reverse proxy service, so that the management nodes of the first server cluster and the second server cluster access the main library of the key distribution center, and other nodes of the first server cluster and the second server cluster respectively access different standby libraries of the key distribution center; wherein, the other nodes are nodes other than the management nodes; the client node accesses the first server cluster or the second server cluster through the key distribution center and the reverse proxy service, so that the first server cluster or the second server cluster processes the services of the client node.
2. The method according to claim 1, characterized in that, the step of setting a plurality of standby libraries of the key distribution center based on the main library of the key distribution center includes: establishing a plurality of standby libraries of the key distribution center; timely synchronizing the data of the main library of the key distribution center to a plurality of standby libraries of the key distribution center.
3. The method according to claim 1, characterized in that, the step of setting a reverse proxy service includes: setting a first port in the reverse proxy service, so that the management nodes of the first server cluster and the second server cluster access the main library of the key distribution center through the first port; setting a second port in the reverse proxy service, so that other nodes of the first server cluster access the first standby library of the key distribution center; setting a third port in the reverse proxy service, so that other nodes of the second server cluster access the second standby library of the key distribution center.
4. The method according to claim 1, characterized in that, after the step of setting a reverse proxy service, the method further includes: maintaining the service of the first server cluster and stopping the service of the second server cluster, and adjusting the configurations of the second server cluster and the client node; maintaining the service of the second server cluster and stopping the service of the first server cluster, and adjusting the configurations of the first server cluster and the client node.
5. The method according to claim 4, characterized in that, the step of adjusting the configuration of the second server cluster includes: setting the host of the key distribution center of the second server cluster as the address of the reverse proxy service, and configuring the domain name of the second server cluster to be the same as the domain name configuration of the first server cluster; the step of adjusting the configuration of the first server cluster includes: setting the host of the key distribution center of the first server cluster as the address of the reverse proxy service.
6. The method according to claim 3, characterized in that, the method further includes: acquiring a third server cluster; establishing a third standby library of the key distribution center; Set a fourth port in the reverse proxy service so that other nodes of the third server cluster can access the third standby database of the key distribution center.
7. The method according to claim 6, wherein, after the step of setting a fourth port in the reverse proxy service, the method further includes: Maintain the services of the first server cluster and the second server cluster and stop the service of the third server cluster, and adjust the configurations of the third server cluster and the client nodes.
8. The method according to claim 6, wherein, after the step of setting a fourth port in the reverse proxy service, the method further includes: The client node accesses the first server cluster, the second server cluster or the third server cluster through the key distribution center and the reverse proxy service, so that the first server cluster, the second server cluster or the third server cluster processes the services of the client node.
9. A processing device for a server cluster, wherein, The client node accesses the first server cluster through the key distribution center so that the first server cluster processes the services of the client node. The device includes: A standby database setting module of the key distribution center, configured to set multiple standby databases of the key distribution center based on the primary database of the key distribution center; A reverse proxy service setting module, configured to set a reverse proxy service so that the management nodes of the first server cluster and the second server cluster can access the primary database of the key distribution center, and other nodes of the first server cluster and the second server cluster respectively access different standby databases of the key distribution center; wherein, the other nodes are nodes other than the management nodes; A server cluster access module, configured to enable the client node to access the first server cluster or the second server cluster through the key distribution center and the reverse proxy service, so that the first server cluster or the second server cluster processes the services of the client node.
10. An electronic device, wherein, It includes a processor and a memory. The memory stores computer executable instructions that can be executed by the processor. The processor executes the computer executable instructions to implement the steps of the server cluster processing method according to any one of claims 1-8.
11. A computer-readable storage medium, wherein, The computer-readable storage medium stores computer executable instructions. When the computer executable instructions are called and executed by a processor, the computer executable instructions cause the processor to implement the steps of the server cluster processing method according to any one of claims 1-8.
Citation Information
Patent Citations
Security authentication method for realizing multi-cloud management and control across public network
CN110855700A
High-availability authentication method for hadoop cluster kerberos
CN111597536A