Application infrastructure resource architecture audit method, system and related equipment
Through the automated application infrastructure resource architecture audit method, the infrastructure feasibility study plan submitted by developers is obtained and analyzed, and the application architecture audit opinion list is generated, which solves the problems of inefficiency and poor quality in the existing technology, and achieves an efficient and accurate audit process.
Patent Information
- Application Number
- CN202211325366.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2022-10-27
- Publication Date
- 2025-08-15
- Estimated Expiration
- 2042-10-27
AI Technical Summary
The existing application architecture audit methods are inefficient, poor in quality, easy to miss manual audits, and high thresholds for new employees, making it difficult to ensure the timeliness and accuracy of the audit standards.
Through the automated application infrastructure resource architecture audit method, the infrastructure feasibility study plan submitted by developers is obtained, the background information and operation and maintenance basic information of the target new physical subsystem are confirmed, the application architecture diagram and physical deployment diagram are generated, and the audit opinion list is generated based on the infrastructure resource information analysis.
It improves the efficiency and quality of application architecture audits, reduces the risk of omissions from manual audits, reduces the dependence on auditor experience, and simplifies the difficulty of training for new employees.
Smart Images

Figure CN116009931B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of information technology, and in particular to an application infrastructure resource architecture audit method, system and related equipment. Background Art
[0002] Before a new application system is deployed and launched in a data center, the application operation and maintenance department will review the application architecture based on the resource requirements and deployment plan proposed by the development department, and submit it to the resource department for review. Finally, a relatively complete plan is formed and resource application begins.
[0003] In related technologies, application architecture is reviewed manually. However, manual review still has the following problems:
[0004] 1. Due to the triviality of audit points, complex scenarios and diverse conditions, the manual audit process is prone to omissions.
[0005] 2. Since audit standards and technical knowledge cover a wide range, manual audits require application administrators to have sufficient experience. However, standards and specifications are constantly changing. If application administrators cannot absorb the latest information in a timely manner, updates cannot be guaranteed.
[0006] 3. The workflow and knowledge system of application architecture review are relatively complex, involving a large amount of technical accumulation and communication skills. The threshold is high for new employees, and it is difficult to train new application administrators.
[0007] From this we can see that the existing application architecture audit method has low audit efficiency and poor audit quality. Summary of the Invention
[0008] In view of this, an embodiment of the present invention provides an application infrastructure resource architecture audit method, system and related equipment to achieve the purpose of improving audit efficiency and audit quality.
[0009] To achieve the above objectives, the embodiments of the present invention provide the following technical solutions:
[0010] A first aspect of an embodiment of the present invention discloses a method for auditing an application infrastructure resource architecture, the method comprising:
[0011] Obtaining an infrastructure feasibility study plan submitted by any developer, where the developer fills out a work order according to the infrastructure feasibility study process requirements;
[0012] According to the infrastructure feasibility study plan, confirm the background information of the target new physical subsystem involved in the infrastructure feasibility study plan, and synchronize the basic operation and maintenance information of the target new physical subsystem in the physical subsystem management system;
[0013] Confirming an application architecture diagram of the target newly created physical subsystem based on the basic operation and maintenance information, and analyzing the application architecture diagram to obtain an application architecture diagram analysis result;
[0014] Based on the analysis results of the application architecture diagram, confirm the physical deployment diagram of the target new physical subsystem, and synchronize the infrastructure resource information of the target new physical subsystem in the version management system;
[0015] Analyze the infrastructure feasibility study plan based on the infrastructure resource information and generate judgment conclusions and rectification suggestions;
[0016] Generate resource estimation logic based on the judgment conclusions and rectification opinions and the preset resource estimation logic framework, combined with the infrastructure feasibility study plan;
[0017] Based on the resource estimation logic, the infrastructure feasibility study plan is reviewed and an application architecture review opinion list is generated.
[0018] Optionally, the step of confirming, based on the infrastructure feasibility study plan, background information of the target new physical subsystem involved in the infrastructure feasibility study plan, and synchronizing basic operation and maintenance information of the target new physical subsystem in the physical subsystem management system includes:
[0019] According to the infrastructure feasibility study plan, obtaining pre-established basic information of a target new physical subsystem from a physical subsystem management system, the basic information including project establishment background information of the target new physical subsystem;
[0020] Based on the project background information, and in accordance with pre-entered launch plan evaluation criteria, the estimated launch time of the infrastructure feasibility study plan is evaluated. The launch plan evaluation criteria at least include the co-organizer review and evaluation time, resource application and supply time, and holidays;
[0021] Based on the estimated time of going online, basic operation and maintenance information of the target newly-built physical subsystem is synchronized in the physical subsystem management system, where the basic operation and maintenance information includes the layering, business domain, and technology stack of the target newly-built physical subsystem.
[0022] Optionally, obtaining pre-established basic information of a target newly built physical subsystem from a physical subsystem management system according to the infrastructure feasibility study plan includes:
[0023] Based on the infrastructure feasibility study plan, confirm whether the target new physical subsystem involves a phased construction plan or a phased promotion plan;
[0024] If applicable, generate a batch date plan for resource supply;
[0025] Based on the infrastructure feasibility study plan, confirm whether the target new physical subsystem involves multi-active / disaster recovery construction;
[0026] If applicable, set the physical information of the deployment resources;
[0027] Based on the infrastructure feasibility study plan, confirm the technology stack to be adopted by the target new physical subsystem;
[0028] Based on the resource supply batch date plan, the physical information of the deployed resources, and the technology stack, the project establishment background information of the target new physical subsystem is obtained.
[0029] Optionally, confirming the application architecture diagram of the target newly-built physical subsystem based on the basic operation and maintenance information, and analyzing the application architecture diagram to obtain an application architecture diagram analysis result includes:
[0030] Determine other related systems of the target newly built physical subsystem and other related system information based on the basic operation and maintenance information;
[0031] Determining the deployment location of the target newly built physical subsystem and other related systems in a pre-set overall architecture system;
[0032] Based on the deployment location, drawing the target newly created physical subsystem and other related systems at appropriate locations of the overall architecture system;
[0033] Analyze and review the relevant resources of the other related systems based on the other related system information to obtain an application architecture diagram analysis result;
[0034] According to the target, transaction relationships and data transmission information between the physical subsystem and other related systems are newly created, and transaction lines and data lines are visualized.
[0035] Optionally, analyzing and reviewing relevant resources of the other related systems based on the other related system information to obtain application architecture diagram analysis results includes:
[0036] Determine, based on the basic operation and maintenance information, the user operation mode of the target newly built physical subsystem and the external liaison organization and external liaison method information;
[0037] According to the user operation mode, matching the target newly created physical subsystem with a preset specified user channel, and confirming that the target newly created physical subsystem has a corresponding associated system and whether the transaction line and data line of the associated system are correct;
[0038] Based on the external contact organization and external contact method information, confirm whether the resources requested by the target new physical subsystem are deployed in the correct security zone and whether corresponding network security measures are in place;
[0039] Compare the deployment locations of the associated systems to confirm whether the associated systems have special network requirements across regions and data centers.
[0040] Optionally, the step of confirming a physical deployment diagram of the target newly created physical subsystem based on the analysis result of the application architecture diagram, and synchronizing infrastructure resource information of the target newly created physical subsystem in a version management system includes:
[0041] Based on the analysis results of the application architecture diagram, and in accordance with the pre-defined interaction mode between internal and external systems, determine the security areas and security subnets of the infrastructure resources in the infrastructure feasibility study plan;
[0042] According to the pre-set outbound and inbound visit scenarios, the correct security measures are matched to the infrastructure resources, and the corresponding information of the obtained security zones and security subnets is visualized in the physical deployment diagram;
[0043] According to the architectural design in the infrastructure feasibility study plan, the corresponding relationship between domain names and load balancing is set, and the configuration information is obtained and exported;
[0044] Generate a network access relationship framework for network access relationship allocation based on pre-set external organization communication relationships and dedicated line construction requirements, and visualize the obtained network resource information in the physical deployment diagram;
[0045] The infrastructure resource information of the target newly created physical subsystem is synchronized in the version management system.
[0046] Optionally, analyzing the infrastructure feasibility study plan based on the infrastructure resource information to generate a judgment conclusion and rectification suggestions includes:
[0047] Analyzing, based on the infrastructure resource information, whether the versions of various components in the infrastructure feasibility study plan comply with version deployment specifications;
[0048] By using the pre-set standard deployment modes of each component, the deployment plans of each component in the infrastructure feasibility study plan are compared to see whether they are reasonable and whether they can meet the high availability requirements, and judgment conclusions and rectification suggestions are generated.
[0049] A second aspect of an embodiment of the present invention discloses an application infrastructure resource architecture audit system, the system comprising:
[0050] An acquisition module is used to acquire an infrastructure feasibility study plan submitted by any developer, wherein the infrastructure feasibility study plan is obtained by the developer filling out a work order according to the infrastructure feasibility study process requirements;
[0051] A physical subsystem background confirmation module is used to confirm the background information of the target new physical subsystem involved in the infrastructure feasibility study plan according to the infrastructure feasibility study plan, and synchronize the basic operation and maintenance information of the target new physical subsystem in the physical subsystem management system;
[0052] An application architecture diagram confirmation module is used to confirm the application architecture diagram of the target newly-built physical subsystem based on the basic operation and maintenance information, and analyze the application architecture diagram to obtain an application architecture diagram analysis result;
[0053] A physical deployment diagram confirmation module is used to confirm the physical deployment diagram of the target new physical subsystem based on the analysis result of the application architecture diagram, and synchronize the infrastructure resource information of the target new physical subsystem in the version management system;
[0054] An analysis module, configured to analyze the infrastructure feasibility study plan based on the infrastructure resource information and generate a judgment conclusion and rectification suggestions;
[0055] A resource estimation logic generation module is used to generate resource estimation logic based on the judgment conclusion and rectification opinions and the preset resource estimation logic framework, combined with the infrastructure feasibility study plan;
[0056] An audit module is used to audit the infrastructure feasibility study plan based on the resource estimation logic and generate an application architecture audit opinion list.
[0057] A third aspect of an embodiment of the present invention discloses an electronic device, the electronic device including a processor;
[0058] The memory is used to store computer programs;
[0059] The processor is configured to implement the application infrastructure resource architecture audit method as described in any one of the first aspects of the embodiments of the present invention when calling and executing the computer program stored in the memory.
[0060] A fourth aspect of an embodiment of the present invention discloses a computer storage medium, in which computer-executable instructions are stored. When the computer-executable instructions are loaded and executed by a processor, an application infrastructure resource architecture audit method as described in any one of the first aspects of the embodiment of the present invention is implemented.
[0061] Based on the above-mentioned embodiments of the present invention, an application infrastructure resource architecture audit method, system, and related equipment are provided. The method includes: obtaining an infrastructure feasibility study plan submitted by any developer, the infrastructure feasibility study plan being obtained by the developer filling out a work order according to the infrastructure feasibility study process requirements; confirming background information of the target new physical subsystem involved in the infrastructure feasibility study plan when it is newly created, and synchronizing basic operation and maintenance information of the target new physical subsystem in a physical subsystem management system; confirming an application architecture diagram of the target new physical subsystem based on the basic operation and maintenance information, and analyzing the application architecture diagram to obtain an application architecture diagram analysis result; confirming a physical deployment diagram of the target new physical subsystem based on the application architecture diagram analysis result, and synchronizing infrastructure resource information of the target new physical subsystem in a version management system; analyzing the infrastructure feasibility study plan based on the infrastructure resource information to generate a judgment conclusion and rectification opinions; generating resource estimation logic based on the judgment conclusion and rectification opinions and a preset resource estimation logic framework in combination with the infrastructure feasibility study plan; and reviewing the infrastructure feasibility study plan based on the resource estimation logic to generate an application architecture audit opinion list. In this plan, based on the infrastructure feasibility study plan submitted by the developer, the background information, application architecture diagram and physical deployment diagram of the target new physical subsystem involved in the infrastructure feasibility study plan are confirmed respectively. Then, based on the synchronized infrastructure resource information, the infrastructure feasibility study plan is analyzed. According to the generated resource estimation logic, the infrastructure feasibility study plan is reviewed, and a list of application architecture review opinions is generated, thereby improving the review efficiency and quality. BRIEF DESCRIPTION OF THE DRAWINGS
[0062] In order to more clearly illustrate the embodiments of the present invention or the technical solutions in the prior art, the following briefly introduces the drawings required for use in the embodiments or the description of the prior art. Obviously, the drawings described below are merely embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0063] Figure 1 A flowchart of a method for auditing an application infrastructure resource architecture provided by an embodiment of the present invention;
[0064] Figure 2 A schematic diagram of a process for confirming background information for a target physical subsystem involved in an infrastructure feasibility study plan provided by an embodiment of the present invention;
[0065] Figure 3A schematic diagram of a process for confirming an application architecture diagram of a target newly created physical subsystem provided by an embodiment of the present invention;
[0066] Figure 4 A schematic diagram of a process for confirming a physical deployment diagram of a target newly created physical subsystem provided by an embodiment of the present invention;
[0067] Figure 5 A schematic diagram of a process for analyzing a feasibility study plan for infrastructure according to an embodiment of the present invention;
[0068] Figure 6 A schematic diagram of the structure of an application infrastructure resource architecture audit system provided by an embodiment of the present invention;
[0069] Figure 7 A schematic structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0070] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of the present invention.
[0071] In this application, the terms "comprises," "comprising," or any other variations thereof are intended to encompass non-exclusive inclusion, such that a process, method, article, or apparatus that includes a list of elements includes not only those elements but also other elements not explicitly listed, or elements inherent to such process, method, article, or apparatus. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not preclude the presence of additional identical elements in the process, method, article, or apparatus that includes the element.
[0072] The terms "first," "second," "third," "fourth," and so on (if any) in the specification and claims of this application and the accompanying drawings are used to distinguish similar objects and are not necessarily used to describe a particular order or sequence. It should be understood that the terms used in this manner are interchangeable where appropriate, so that the embodiments described herein can be implemented in an order other than that shown or described herein.
[0073] As can be seen from the background technology, the existing application architecture audit method has low audit efficiency and poor audit quality.
[0074] Therefore, an embodiment of the present invention provides an application infrastructure resource architecture audit method, system and related equipment. In this solution, based on the infrastructure feasibility study plan submitted by the developer, the background information, application architecture diagram and physical deployment diagram of the target new physical subsystem involved in the infrastructure feasibility study plan are confirmed respectively, and then the infrastructure feasibility study plan is analyzed based on the synchronized infrastructure resource information. According to the generated resource estimation logic, the infrastructure feasibility study plan is audited, thereby generating an application architecture audit opinion list, thereby improving the audit efficiency and audit quality.
[0075] like Figure 1 , which is a flow chart of an application infrastructure resource architecture audit method provided by an embodiment of the present invention.
[0076] The application infrastructure resource architecture audit method mainly includes the following steps:
[0077] Step S101: Obtain an infrastructure feasibility study plan submitted by any developer.
[0078] In step S101, the infrastructure feasibility study plan is obtained by developers filling out a work order according to the infrastructure feasibility study process requirements.
[0079] The infrastructure feasibility study plan shall at least include an introduction to key background information, architectural design of application deployment, deployment plan and resource requirements.
[0080] Among them, resource requirements include at least servers, storage and networks.
[0081] In the specific implementation of step S101, the developer fills out a work order according to the infrastructure feasibility study process requirements to obtain an infrastructure feasibility study plan, and submits the infrastructure feasibility study plan. The backend then obtains the infrastructure feasibility study plan submitted by any developer.
[0082] Step S102: according to the infrastructure feasibility study plan, confirm the background information of the target new physical subsystem involved in the infrastructure feasibility study plan, and synchronize the basic operation and maintenance information of the target new physical subsystem in the physical subsystem management system.
[0083] It should be noted that the physical subsystem management system is another related system that contains all the attribute information of the physical subsystem and is an important auxiliary system to support infrastructure feasibility studies.
[0084] In the process of specifically implementing step S102, necessary information in the infrastructure feasibility study plan is extracted based on the infrastructure feasibility study plan submitted by the developer. First, the background information of the target new physical subsystem involved in the infrastructure feasibility study plan when it is newly built is confirmed. That is to say, the background information of the target new physical subsystem involved in the infrastructure feasibility study plan when it is newly built is extracted, and the basic operation and maintenance information of the target new physical subsystem is synchronized in the physical subsystem management system.
[0085] Optionally, step S102 is performed to confirm the background information of the target new physical subsystem involved in the infrastructure feasibility study plan according to the infrastructure feasibility study plan, and synchronize the basic operation and maintenance information of the target new physical subsystem in the physical subsystem management system, such as Figure 2 FIG. 1 is a flow chart of a method for confirming background information of a target physical subsystem involved in an infrastructure feasibility study plan according to an embodiment of the present invention, which mainly includes the following steps:
[0086] Step S201: According to the infrastructure feasibility study plan, basic information of a pre-established target new physical subsystem is obtained from the physical subsystem management system.
[0087] In step S201 , the basic information includes the project establishment background information of the target new physical subsystem.
[0088] In the process of implementing step S201, based on the infrastructure feasibility study plan submitted by the developer, the physical subsystem management system is called to obtain basic information of the target new physical subsystem involved in the pre-established infrastructure feasibility study plan from the physical subsystem management system, and specifically obtain the project background information of the target new physical subsystem.
[0089] Optionally, the process of executing step S201 to obtain pre-established basic information of the target new physical subsystem from the physical subsystem management system according to the infrastructure feasibility study plan mainly includes the following steps:
[0090] Step S11: According to the infrastructure feasibility study plan, confirm whether the target new physical subsystem involves a phased construction plan or a phased promotion plan. If so, execute step S12.
[0091] In the process of implementing step S11, according to the infrastructure feasibility study plan, confirm whether the target new physical subsystem involves a batch construction plan or a batch promotion plan, that is, confirm whether the new system involves a batch construction plan or a batch promotion plan. If so, execute step S12.
[0092] Step S12: Generate a resource supply batch date plan.
[0093] In the specific implementation of step S12, when it is confirmed that the target newly-built physical subsystem involves a batch construction plan or a batch promotion plan, a batch date plan for resource supply is generated.
[0094] Step S13: According to the infrastructure feasibility study plan, confirm whether the target new physical subsystem involves multi-active / disaster recovery construction. If so, execute step S14.
[0095] In step S13, multiple active instances refer to multiple active instances. In actual applications, multiple active instances are deployed in multiple data centers to reduce the risk of overall data center failure. However, in principle, multiple active instances can also be deployed within a single data center.
[0096] In the process of implementing step S13, according to the infrastructure feasibility study plan, confirm whether the target new physical subsystem involves multi-active / disaster recovery construction, that is, confirm whether the new system involves multi-active / disaster recovery construction. If so, execute step S14.
[0097] Step S14: Set the physical information of the deployment resources.
[0098] In step S14 , the physical information of the deployed resources includes the data center and environment where the resources are deployed.
[0099] In the specific implementation of step S14 , when it is confirmed that the target newly-built physical subsystem involves active / disaster recovery construction, the physical information of the deployed resources is set, that is, the data center and environment of the deployed resources are set.
[0100] Step S15: According to the infrastructure feasibility study plan, confirm the technology stack used by the target new physical subsystem.
[0101] In the specific implementation of step S15, the technology stack used by the target new physical subsystem is confirmed according to the infrastructure feasibility study plan, that is, the technology stack used by the new system is confirmed to correspond to the resource construction specifications, standards and requirements under different technology stacks.
[0102] Step S16: Based on the resource supply batch date plan, the physical information of the deployed resources, and the technology stack, the project establishment background information of the target new physical subsystem is obtained.
[0103] Step S202: Based on the project background information and according to the pre-entered launch plan evaluation criteria, the estimated launch time of the infrastructure feasibility study plan is evaluated.
[0104] In step S202, the launch plan evaluation criteria include at least the co-organizer review and evaluation time, resource application and supply time, and holidays.
[0105] In the process of implementing step S202, based on the project background information and according to the pre-entered online plan evaluation standards, the estimated online time of the infrastructure feasibility study plan is evaluated, and when the infrastructure feasibility study plan is submitted, it is returned to the developer for confirmation, thereby ensuring timely and effective communication of the infrastructure feasibility study plan.
[0106] Step S203: Based on the estimated time of going online, the basic operation and maintenance information of the target newly created physical subsystem is synchronized in the physical subsystem management system.
[0107] In step S203 , the basic operation and maintenance information includes the layering, business domain, and technology stack of the target newly created physical subsystem, as well as the rating, operating hours, maintenance window, and business peak time period of the target newly created physical subsystem.
[0108] In the specific implementation of step S203 , based on the estimated time of going online, the basic operation and maintenance information of the target newly created physical subsystem is synchronized in the physical subsystem management system. In other words, the basic operation and maintenance information of the target newly created physical subsystem is displayed for the application administrator to extract and confirm.
[0109] Step S103: confirming the application architecture diagram of the target newly-created physical subsystem according to the basic operation and maintenance information, and analyzing the application architecture diagram to obtain an analysis result of the application architecture diagram.
[0110] It should be noted that the application architecture diagram has a pre-set overall architecture system, and developers only need to focus on information related to the new system (target new physical subsystem).
[0111] In the process of implementing step S103, based on the basic operation and maintenance information synchronized in the physical subsystem management system, specifically based on the layering, business domain and technology stack information of the target new physical subsystem, the application architecture diagram of the target new physical subsystem is confirmed, the application architecture diagram is analyzed, and the application architecture diagram analysis results are obtained.
[0112] Optionally, executing step S103, confirming the application architecture diagram of the target newly created physical subsystem according to the basic operation and maintenance information, and analyzing the application architecture diagram to obtain the analysis result of the application architecture diagram, such as Figure 3 FIG. 1 is a flow chart of confirming an application architecture diagram of a target newly-built physical subsystem provided by an embodiment of the present invention, which mainly includes the following steps:
[0113] Step S301: Determine other related systems and other related system information of the target newly created physical subsystem based on the basic operation and maintenance information.
[0114] Step S302: Determine the deployment location of the target newly-built physical subsystem and other related systems in the pre-set overall architecture system.
[0115] Step S303: Based on the deployment location, draw the target new physical subsystem and other related systems at the appropriate location of the overall architecture system.
[0116] Based on the above description, it can be understood that according to the layering, business domain, technology stack and other information of the target new physical subsystem synchronized in the physical subsystem management system, the new system (target new physical subsystem) and other related systems involved in the infrastructure feasibility study plan are clearly positioned in the overall architecture system and drawn in appropriate locations.
[0117] Step S304: Analyze and review the relevant resources of other related systems based on the information of other related systems to obtain analysis results of the application architecture diagram.
[0118] It should be noted that relevant resources refer to the network resources applied for in the infrastructure feasibility study plan and whether resources that meet relevant security requirements have been deployed based on special external connection methods.
[0119] In the specific implementation of step S304, the relevant resources of the other related systems are analyzed according to the information of the other related systems, and whether the relevant resources of the other related systems are reasonable is reviewed, thereby obtaining the analysis result of the application architecture diagram.
[0120] Optionally, the process of performing step S304 to analyze and review the relevant resources of other related systems based on the information of other related systems to obtain the analysis results of the application architecture diagram mainly includes the following steps:
[0121] Step S21: Determine the user operation mode of the target newly-built physical subsystem and the external contact organization and external contact mode information according to the basic operation and maintenance information.
[0122] Step S22: According to the user operation mode, the target newly created physical subsystem is matched with a preset specified user channel, and it is confirmed that the target newly created physical subsystem has a corresponding associated system, and whether the transaction line and data line of the associated system are correct.
[0123] Step S23: Based on the external contact organization and external contact method information, confirm whether the resources requested by the target new physical subsystem are deployed in the correct security area and whether corresponding network security measures are in place.
[0124] Step S24: Compare the deployment locations of the associated systems to confirm whether the associated systems have special network requirements across regions and data centers.
[0125] Step S305: Create transaction relationships and data transmission information between the target physical subsystem and other related systems, and visualize transaction lines and data lines.
[0126] In the specific implementation of step S305, the transaction relationship and data transmission information between the target newly created physical subsystem and other related systems are determined, and the transaction lines and data lines are visualized based on the transaction relationship and data transmission information between the target newly created physical subsystem and other related systems for analysis and review by the application administrator.
[0127] Step S104: Based on the analysis result of the application architecture diagram, confirm the physical deployment diagram of the target new physical subsystem, and synchronize the infrastructure resource information of the target new physical subsystem in the version management system.
[0128] In step S104, the infrastructure resource information includes security zones and other related security mechanism information, as well as network resource information.
[0129] Among them, network resources include but are not limited to dedicated lines, domain names, load balancing, and network access relationships.
[0130] It should be noted that the version management system is also an important support system for infrastructure feasibility studies. Version management is used to manage the supported version information of various infrastructure-related resources such as operating systems, middleware, and clients.
[0131] In the process of implementing step S104, based on the analysis results of the application architecture diagram, specifically according to the transaction relationship and data transmission information between the target new physical subsystem and other related systems, the physical deployment diagram of the target new physical subsystem is confirmed, and the infrastructure resource information of the target new physical subsystem is synchronized in the version management system.
[0132] Optionally, step S104 is performed to confirm the physical deployment diagram of the target new physical subsystem based on the analysis result of the application architecture diagram, and synchronize the infrastructure resource information of the target new physical subsystem in the version management system, such as Figure 4 FIG. 1 is a flow chart of confirming a physical deployment diagram of a target newly-built physical subsystem according to an embodiment of the present invention, which mainly includes the following steps:
[0133] Step S401: Based on the analysis results of the application architecture diagram and according to the pre-set interaction mode between the internal system and the external system, determine the security area and security subnet of the infrastructure resources in the infrastructure feasibility study plan.
[0134] In the process of implementing step S401, based on the analysis results of the application architecture diagram obtained, according to the pre-set interaction mode between the internal system and the external system, the security area and security subnet of the infrastructure resources in the infrastructure feasibility study plan are determined. That is to say, it is determined whether the security area and security subnet of the relevant resources in the infrastructure feasibility study plan are correct. If there are problems, the problematic security areas and security subnets are corrected or supplemented.
[0135] Step S402: According to the pre-set outbound visit scenarios and inbound visit scenarios, the correct security supporting measures are matched to the infrastructure resources, and the corresponding information of the obtained security zones and security subnets is visualized in the physical deployment diagram.
[0136] In the specific implementation of step S402, after determining the security areas and security subnets of the infrastructure resources in the infrastructure feasibility study plan, the correct security supporting measures are matched for the infrastructure resources according to the pre-set external outbound visit scenarios and external inbound visit scenarios. At the same time, the corresponding information of the obtained security areas and security subnets is visualized in the physical deployment diagram.
[0137] Step S403: According to the architecture design in the infrastructure feasibility study plan, the corresponding relationship between the domain name and the load balancing is set, and the configuration information is obtained and exported.
[0138] In the specific implementation of step S403, the corresponding relationship between the domain name and the load balancing is set according to the architecture design in the infrastructure feasibility study plan, the configuration information corresponding to the domain name and the load balancing is obtained, and the configuration information is exported.
[0139] Step S404: Generate a network access relationship framework for network access relationship allocation based on pre-set external organization communication relationships and dedicated line construction requirements, and visualize the obtained network resource information in a physical deployment diagram.
[0140] In the specific implementation of step S404, a network access relationship framework is generated for network access relationship allocation based on the pre-set external organization communication relationship and dedicated line construction requirements, network resource information is obtained, and the obtained network resource information is visualized in the physical deployment diagram.
[0141] Step S405: Synchronize the infrastructure resource information of the target newly created physical subsystem in the version management system.
[0142] In the specific implementation of step S405 , the infrastructure resource information of the target newly created physical subsystem is synchronized in the version management system, specifically the corresponding information of the security zone and the security subnet, as well as the network resource information.
[0143] Step S105: Analyze the infrastructure feasibility study plan based on the infrastructure resource information and generate judgment conclusions and rectification suggestions.
[0144] In the specific implementation of step S105, the versions and high availability of various components in the infrastructure feasibility study plan are analyzed based on the infrastructure resource information to obtain analysis results, and judgment conclusions and rectification suggestions are generated based on the analysis results.
[0145] It should be noted that the various components include but are not limited to various operating systems, databases, and middleware.
[0146] Optionally, step S105 is performed to analyze the infrastructure feasibility study plan based on the infrastructure resource information and generate the judgment conclusion and rectification suggestions, such as Figure 5 FIG. 1 is a flow chart of a feasibility study solution for analyzing infrastructure provided by an embodiment of the present invention, which mainly includes the following steps:
[0147] Step S501: Analyze, based on the infrastructure resource information, whether the versions of the various components in the infrastructure feasibility study plan comply with the version deployment specification.
[0148] In the specific implementation of step S501, based on the corresponding information of the security zone and the security subnet, as well as the network resource information, it is analyzed whether the versions of various operating systems, databases and middleware in the infrastructure feasibility study plan comply with the version deployment specifications.
[0149] Step S502: By comparing the pre-set standard deployment modes of each component, whether the deployment plans of each component in the infrastructure feasibility study plan are reasonable and whether they can meet the high availability requirements, and generate judgment conclusions and rectification suggestions.
[0150] In the process of implementing step S502, the deployment schemes of various components in the infrastructure feasibility study plan are compared through the pre-set standard deployment modes of various components to see whether they are reasonable and whether they can meet the high availability requirements. That is, the deployment schemes of various operating systems, databases and middleware in the infrastructure feasibility study plan are compared to see whether they are reasonable and whether they can meet the high availability requirements, and the comparison results are obtained. Then, based on the comparison results, judgment conclusions and rectification opinions are generated for reference by application administrators and developers.
[0151] Step S106: Generate resource estimation logic based on the judgment conclusions and rectification opinions and the preset resource estimation logic framework, combined with the infrastructure feasibility study plan.
[0152] In the process of implementing step S106, the resource estimation logic is generated based on the judgment conclusions and rectification opinions and the preset resource estimation logic framework (that is, the resource estimation logic provides a standard estimation framework), combined with the test data in the infrastructure feasibility study plan or the operation data collected in the production environment.
[0153] Step S107: Based on the resource estimation logic, review the infrastructure feasibility study plan and generate an application architecture review opinion list.
[0154] In the specific implementation of step S107, based on the resource estimation logic, the resource requirements in the infrastructure feasibility study plan are reviewed to see if they are reasonable, and suggestions for expansion or reduction are given. Then, a list of application architecture review opinions is generated.
[0155] Based on the above description, the present invention extracts necessary information from the infrastructure feasibility study plan submitted by the development department (developer) as input, directly feedbacks problem points according to system standards, or directly corrects and generates a correct deployment plan.
[0156] An application infrastructure resource architecture audit method provided by an embodiment of the present invention confirms the background information, application architecture diagram, and physical deployment diagram of the target new physical subsystem involved in the infrastructure feasibility study plan according to the infrastructure feasibility study plan submitted by the developer, and then analyzes the infrastructure feasibility study plan based on the synchronized infrastructure resource information. According to the generated resource estimation logic, the infrastructure feasibility study plan is audited, thereby generating an application architecture audit opinion list, thereby improving the audit efficiency and audit quality.
[0157] Corresponding to the above-mentioned application infrastructure resource architecture audit method shown in the embodiment of the present invention, the embodiment of the present invention also provides an application infrastructure resource architecture audit system, such as Figure 6 As shown, the application infrastructure resource architecture audit system includes: an acquisition module 601, a physical subsystem background confirmation module 602, an application architecture diagram confirmation module 603, a physical deployment diagram confirmation module 604, an analysis module 605, a resource estimation logic generation module 606 and an audit module 607.
[0158] The acquisition module 601 is used to acquire an infrastructure feasibility study plan submitted by any developer.
[0159] Among them, the infrastructure feasibility study plan is obtained by developers filling out a work order according to the requirements of the infrastructure feasibility study process.
[0160] The physical subsystem background confirmation module 602 is used to confirm the background information of the target new physical subsystem involved in the infrastructure feasibility study plan according to the infrastructure feasibility study plan, and synchronize the basic operation and maintenance information of the target new physical subsystem in the physical subsystem management system.
[0161] The application architecture diagram confirmation module 603 is used to confirm the application architecture diagram of the target newly-built physical subsystem according to the basic operation and maintenance information, and analyze the application architecture diagram to obtain an application architecture diagram analysis result.
[0162] The physical deployment diagram confirmation module 604 is used to confirm the physical deployment diagram of the target new physical subsystem based on the application architecture diagram analysis result, and synchronize the infrastructure resource information of the target new physical subsystem in the version management system.
[0163] The analysis module 605 is used to analyze the infrastructure feasibility study plan based on the infrastructure resource information and generate judgment conclusions and rectification suggestions.
[0164] The resource estimation logic generation module 606 is used to generate resource estimation logic based on the judgment conclusions and rectification opinions and the preset resource estimation logic framework in combination with the infrastructure feasibility study plan.
[0165] The review module 607 is used to review the infrastructure feasibility study plan based on resource estimation logic and generate an application architecture review opinion list.
[0166] Optional, based on the above Figure 6 The physical subsystem background confirmation module 602 shown includes:
[0167] The acquisition unit is used to acquire basic information of a pre-established target new physical subsystem from the physical subsystem management system according to the infrastructure feasibility study plan.
[0168] Among them, the basic information includes the project background information of the target new physical subsystem.
[0169] The evaluation unit is used to evaluate the estimated time to go online of the infrastructure feasibility study plan based on the project background information and the pre-entered online plan evaluation criteria.
[0170] Among them, the online plan evaluation standards include at least the co-organizer review and evaluation time, resource application and supply time, and holidays.
[0171] The synchronization unit is used to synchronize the basic operation and maintenance information of the target newly created physical subsystem in the physical subsystem management system based on the estimated time of going online.
[0172] Among them, the basic operation and maintenance information includes the layering, business domain and technology stack of the target new physical subsystem.
[0173] Optional, based on the above Figure 6 The physical subsystem background confirmation module 602 shown, the acquisition unit, includes:
[0174] The first confirmation sub-unit is used to confirm whether the target new physical subsystem involves a phased construction plan or a phased promotion plan based on the infrastructure feasibility study plan. If so, the generation sub-unit is executed.
[0175] Generate subunits for generating resource supply batch date plans.
[0176] The second confirmation sub-unit is used to confirm whether the target new physical subsystem involves multi-active / disaster recovery construction based on the infrastructure feasibility study plan. If so, the setting sub-unit is executed.
[0177] The setting subunit is used to set the physical information of the deployment resources.
[0178] The third confirmation sub-unit is used to confirm the technology stack adopted by the target new physical subsystem based on the infrastructure feasibility study plan.
[0179] Obtain the subunit, which is used to obtain the project background information of the target new physical subsystem based on the resource supply batch date plan, the physical information of the deployed resources, and the technology stack.
[0180] Optional, based on the above Figure 6 The application architecture diagram confirmation module 603 shown includes:
[0181] The first determining unit is configured to determine other related systems and other related system information of the target newly-built physical subsystem according to the basic operation and maintenance information.
[0182] The second determining unit is used to determine the deployment location of the target newly-built physical subsystem and other related systems in a pre-set overall architecture system.
[0183] The drawing unit is used to draw the target new physical subsystem and other related systems at the appropriate position of the overall architecture system based on the deployment location.
[0184] The analysis unit is used to analyze and review the relevant resources of other related systems based on the information of other related systems to obtain the analysis results of the application architecture diagram.
[0185] The visualization unit is used to create transaction relationships and data transmission information between the target new physical subsystem and other related systems, and visualize transaction lines and data lines.
[0186] Optional, based on the above Figure 6 The application architecture diagram confirmation module 603 shown, the analysis unit, includes:
[0187] Determine the sub-unit, which is used to determine the user operation mode of the target newly built physical subsystem and the external contact organization and external contact method information based on the basic operation and maintenance information.
[0188] The first confirmation sub-unit is used to match the preset specified user channel for the target new physical subsystem according to the user operation mode, and confirm that the target new physical subsystem has a corresponding associated system and whether the transaction line and data line of the associated system are correct.
[0189] The second confirmation sub-unit is used to confirm whether the resources applied for by the target new physical subsystem are deployed in the correct security area and whether corresponding network security measures are in place based on the information of the external contact organization and external contact method.
[0190] The third confirmation sub-unit is used to compare the deployment locations of the associated systems and confirm whether the associated systems have special network requirements across regions and data centers.
[0191] Optional, based on the above Figure 6 The physical deployment diagram confirmation module 604 shown includes:
[0192] The determination unit is used to determine the security areas and security subnets of the infrastructure resources in the infrastructure feasibility study plan based on the analysis results of the application architecture diagram and according to the pre-set interaction mode between the internal system and the external system.
[0193] The matching unit is used to match the correct security support measures for infrastructure resources based on pre-set external outbound and inbound scenarios, and visualize the corresponding information of the obtained security zones and security subnets in the physical deployment diagram.
[0194] The setting unit is used to set the corresponding relationship between the domain name and the load balancing according to the architecture design in the infrastructure feasibility study plan, obtain the configuration information and export it.
[0195] The allocation unit is used to generate a network access relationship framework for network access relationship allocation based on the pre-set external organization communication relationship and dedicated line construction requirements, and visualize the obtained network resource information in the physical deployment diagram.
[0196] The synchronization unit is used to synchronize the infrastructure resource information of the target newly created physical subsystem in the version management system.
[0197] Optional, based on the above Figure 6 The analysis module 605 shown includes:
[0198] The analysis unit is used to analyze whether the versions of various components in the infrastructure feasibility study plan comply with the version deployment specifications based on the infrastructure resource information.
[0199] The generation unit is used to compare whether the deployment plans of various components in the infrastructure feasibility study plan are reasonable and whether they can meet the high availability requirements through pre-set standard deployment modes of various components, and generate judgment conclusions and rectification suggestions.
[0200] It should be noted that the specific principles and execution processes of each module in the application infrastructure resource architecture audit system disclosed in the above embodiment of the present invention are the same as those of the application infrastructure resource architecture audit method implemented in the above embodiment of the present invention. Please refer to the corresponding parts of the application infrastructure resource architecture audit method disclosed in the above embodiment of the present invention, and no further details will be given here.
[0201] An application infrastructure resource architecture audit system provided by an embodiment of the present invention confirms, based on an infrastructure feasibility study plan submitted by a developer, the background information, application architecture diagram, and physical deployment diagram of the target new physical subsystem involved in the infrastructure feasibility study plan. Then, based on the synchronized infrastructure resource information, the infrastructure feasibility study plan is analyzed. Based on the generated resource estimation logic, the infrastructure feasibility study plan is audited, thereby generating an application architecture audit opinion list, thereby improving audit efficiency and audit quality.
[0202] Based on the application infrastructure resource architecture audit system disclosed in the above embodiment of the present invention, each of the above modules can be implemented by a hardware device consisting of a processor and a memory. Specifically, each of the above modules is stored in the memory as a program unit, and the processor executes the program unit stored in the memory to implement the application infrastructure resource architecture audit.
[0203] The processor includes a kernel, which retrieves the corresponding program unit from the memory. One or more kernels can be configured, and the application infrastructure resource architecture can be audited by adjusting kernel parameters.
[0204] An embodiment of the present invention provides a computer storage medium, which includes a storage application infrastructure resource architecture audit program, wherein when the program is executed by a processor, it implements the application infrastructure resource architecture audit method as described in any one of the above embodiments.
[0205] An embodiment of the present invention provides a processor, which is used to run a program, wherein the application infrastructure resource architecture audit method disclosed in the above embodiment is executed when the program is run.
[0206] An embodiment of the present invention provides an electronic device, such as Figure 7 , which is a structural diagram of an electronic device 70 provided by an embodiment of the present invention.
[0207] The electronic device in the embodiment of the present invention may be a server, a PC, a PAD, a mobile phone, etc.
[0208] The electronic device includes at least one processor 701 , at least one memory 702 connected to the processor, and a bus 703 .
[0209] The processor 701 and the memory 702 communicate with each other via the bus 703. The processor 701 is configured to execute the program stored in the memory 702.
[0210] Memory 702 is used to store a program, which is used at least to: obtain an infrastructure feasibility study plan submitted by any developer, where the infrastructure feasibility study plan is obtained by the developer filling out a work order according to the requirements of the infrastructure feasibility study process; based on the infrastructure feasibility study plan, confirm the background information of the target new physical subsystem involved in the infrastructure feasibility study plan when it is newly built, and synchronize the basic operation and maintenance information of the target new physical subsystem in the physical subsystem management system; based on the basic operation and maintenance information, confirm the application architecture diagram of the target new physical subsystem, and analyze the application architecture diagram to obtain the application architecture diagram analysis results; based on the application architecture diagram analysis results, confirm the physical deployment diagram of the target new physical subsystem, and synchronize the infrastructure resource information of the target new physical subsystem in the version management system; based on the infrastructure resource information, analyze the infrastructure feasibility study plan to generate judgment conclusions and rectification opinions; based on the judgment conclusions and rectification opinions and the preset resource estimation logic framework, combined with the infrastructure feasibility study plan, generate resource estimation logic; based on the resource estimation logic, review the infrastructure feasibility study plan and generate an application architecture review opinion list.
[0211] The present application also provides a computer program product, which, when executed on an electronic device, is adapted to execute a program for initializing the following method steps:
[0212] Obtain the infrastructure feasibility study plan submitted by any developer. The infrastructure feasibility study plan is obtained by the developer filling out a work order according to the requirements of the infrastructure feasibility study process; based on the infrastructure feasibility study plan, confirm the background information of the target new physical subsystem involved in the infrastructure feasibility study plan, and synchronize the basic operation and maintenance information of the target new physical subsystem in the physical subsystem management system; based on the basic operation and maintenance information, confirm the application architecture diagram of the target new physical subsystem, and analyze the application architecture diagram to obtain the application architecture diagram analysis results; based on the application architecture diagram analysis results, confirm the physical deployment diagram of the target new physical subsystem, and synchronize the infrastructure resource information of the target new physical subsystem in the version management system; based on the infrastructure resource information, analyze the infrastructure feasibility study plan, generate judgment conclusions and rectification opinions; based on the judgment conclusions and rectification opinions and the preset resource estimation logic framework, combined with the infrastructure feasibility study plan, generate resource estimation logic; based on the resource estimation logic, review the infrastructure feasibility study plan, and generate a list of application architecture review opinions.
[0213] The present application is described with reference to the flowcharts and / or block diagrams of the methods, devices (systems), and computer program products according to the embodiments of the present application. It should be understood that each process and / or box in the flowchart and / or block diagram, as well as the combination of the processes and / or boxes in the flowchart and / or block diagram, can be implemented by computer program instructions. These computer program instructions can be provided to a processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing device to produce a machine, so that the instructions executed by the processor of the computer or other programmable data processing device generate instructions for implementing the steps in the process. Figure 1 a process or multiple processes and / or boxes Figure 1 A device that provides the functions specified in a block or multiple blocks.
[0214] In a typical configuration, the device includes one or more processors (CPUs), memory, and a bus. The device may also include input / output interfaces, network interfaces, and the like.
[0215] Memory may include non-permanent memory in a computer-readable medium, random access memory (RAM), and / or non-volatile memory, such as read-only memory (ROM) or flash RAM. Memory includes at least one memory chip. Memory is an example of a computer-readable medium.
[0216] Computer-readable media includes permanent and non-permanent, removable and non-removable media that can be implemented by any method or technology to store information. The information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include transitory computer-readable media (transitory media), such as modulated data signals and carrier waves.
[0217] Each embodiment in this specification is described in a progressive manner. The same or similar parts between the embodiments can be referred to each other. Each embodiment focuses on the differences from other embodiments. In particular, for system or system embodiments, since they are basically similar to method embodiments, the description is relatively simple. For relevant parts, refer to the partial description of the method embodiment. The system and system embodiments described above are merely schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules can be selected according to actual needs to achieve the purpose of the solution of this embodiment. A person of ordinary skill in the art can understand and implement it without expending creative work.
[0218] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of the present invention.
[0219] The above description of the disclosed embodiments is intended to enable one skilled in the art to implement or use the present invention. Various modifications to these embodiments will be readily apparent to one skilled in the art, and the general principles defined herein may be implemented in other embodiments without departing from the spirit or scope of the present invention. Therefore, the present invention is not limited to the embodiments shown herein but is intended to conform to the widest scope consistent with the principles and novel features disclosed herein.
Claims
1. A method for auditing application infrastructure resource architecture, characterized in that: The method comprises: Obtaining an infrastructure feasibility study plan submitted by any developer, where the developer fills out a work order according to the infrastructure feasibility study process requirements; According to the infrastructure feasibility study plan, confirm the background information of the target new physical subsystem involved in the infrastructure feasibility study plan, and synchronize the basic operation and maintenance information of the target new physical subsystem in the physical subsystem management system; Confirming an application architecture diagram of the target newly created physical subsystem based on the basic operation and maintenance information, and analyzing the application architecture diagram to obtain an application architecture diagram analysis result; Based on the analysis results of the application architecture diagram, confirm the physical deployment diagram of the target new physical subsystem, and synchronize the infrastructure resource information of the target new physical subsystem in the version management system; Analyze the infrastructure feasibility study plan based on the infrastructure resource information and generate judgment conclusions and rectification suggestions; Generate resource estimation logic based on the judgment conclusions and rectification opinions and the preset resource estimation logic framework, combined with the infrastructure feasibility study plan; Based on the resource estimation logic, the infrastructure feasibility study plan is reviewed and an application architecture review opinion list is generated.
2. The method according to claim 1, characterized in that The step of confirming background information of the target new physical subsystem involved in the infrastructure feasibility study plan according to the infrastructure feasibility study plan, and synchronizing basic operation and maintenance information of the target new physical subsystem in the physical subsystem management system includes: According to the infrastructure feasibility study plan, obtaining pre-established basic information of a target new physical subsystem from a physical subsystem management system, the basic information including project establishment background information of the target new physical subsystem; Based on the project background information, and in accordance with pre-entered launch plan evaluation criteria, the estimated launch time of the infrastructure feasibility study plan is evaluated. The launch plan evaluation criteria at least include the co-organizer review and evaluation time, resource application and supply time, and holidays; Based on the estimated time of going online, basic operation and maintenance information of the target newly-built physical subsystem is synchronized in the physical subsystem management system, where the basic operation and maintenance information includes the layering, business domain, and technology stack of the target newly-built physical subsystem.
3. The method according to claim 2, characterized in that According to the infrastructure feasibility study plan, obtaining basic information of the pre-established target new physical subsystem from the physical subsystem management system includes: Based on the infrastructure feasibility study plan, confirm whether the target new physical subsystem involves a phased construction plan or a phased promotion plan; If applicable, generate a batch date plan for resource supply; Based on the infrastructure feasibility study plan, confirm whether the target new physical subsystem involves multi-active / disaster recovery construction; If applicable, set the physical information of the deployment resources; Based on the infrastructure feasibility study plan, confirm the technology stack to be adopted by the target new physical subsystem; Based on the resource supply batch date plan, the physical information of the deployed resources, and the technology stack, the project establishment background information of the target new physical subsystem is obtained.
4. The method according to claim 1, wherein The step of confirming the application architecture diagram of the target newly-built physical subsystem based on the basic operation and maintenance information, and analyzing the application architecture diagram to obtain an application architecture diagram analysis result includes: Determine other related systems of the target newly built physical subsystem and other related system information based on the basic operation and maintenance information; Determining the deployment location of the target newly built physical subsystem and other related systems in a pre-set overall architecture system; Based on the deployment location, drawing the target newly created physical subsystem and other related systems at appropriate locations of the overall architecture system; Analyze and review the relevant resources of the other related systems based on the other related system information to obtain an application architecture diagram analysis result; According to the target, transaction relationships and data transmission information between the physical subsystem and other related systems are newly created, and transaction lines and data lines are visualized.
5. The method according to claim 4, characterized in that Analyzing and reviewing the related resources of the other related systems based on the other related system information to obtain the application architecture diagram analysis results includes: Determine, based on the basic operation and maintenance information, the user operation mode of the target newly built physical subsystem and the external liaison organization and external liaison method information; According to the user operation mode, matching the target newly created physical subsystem with a preset specified user channel, and confirming that the target newly created physical subsystem has a corresponding associated system and whether the transaction line and data line of the associated system are correct; Based on the external contact organization and external contact method information, confirm whether the resources requested by the target new physical subsystem are deployed in the correct security zone and whether corresponding network security measures are in place; Compare the deployment locations of the associated systems to confirm whether the associated systems have special network requirements across regions and data centers.
6. The method according to claim 1, characterized in that The step of confirming the physical deployment diagram of the target newly created physical subsystem based on the analysis result of the application architecture diagram, and synchronizing the infrastructure resource information of the target newly created physical subsystem in the version management system includes: Based on the analysis results of the application architecture diagram, and in accordance with the pre-defined interaction mode between internal and external systems, determine the security areas and security subnets of the infrastructure resources in the infrastructure feasibility study plan; According to the pre-set outbound and inbound visit scenarios, the correct security measures are matched to the infrastructure resources, and the corresponding information of the obtained security zones and security subnets is visualized in the physical deployment diagram; According to the architectural design in the infrastructure feasibility study plan, the corresponding relationship between domain names and load balancing is set, and the configuration information is obtained and exported; Generate a network access relationship framework for network access relationship allocation based on pre-set external organization communication relationships and dedicated line construction requirements, and visualize the obtained network resource information in the physical deployment diagram; The infrastructure resource information of the target newly created physical subsystem is synchronized in the version management system.
7. The method according to claim 1, characterized in that Analyzing the infrastructure feasibility study plan based on the infrastructure resource information and generating judgment conclusions and rectification suggestions include: Analyzing, based on the infrastructure resource information, whether the versions of various components in the infrastructure feasibility study plan comply with version deployment specifications; By using the pre-set standard deployment modes of each component, the deployment plans of each component in the infrastructure feasibility study plan are compared to see whether they are reasonable and whether they can meet the high availability requirements, and judgment conclusions and rectification suggestions are generated.
8. An application infrastructure resource architecture audit system, characterized in that: The system comprises: An acquisition module is used to acquire an infrastructure feasibility study plan submitted by any developer, wherein the infrastructure feasibility study plan is obtained by the developer filling out a work order according to the infrastructure feasibility study process requirements; A physical subsystem background confirmation module is used to confirm the background information of the target new physical subsystem involved in the infrastructure feasibility study plan according to the infrastructure feasibility study plan, and synchronize the basic operation and maintenance information of the target new physical subsystem in the physical subsystem management system; An application architecture diagram confirmation module is used to confirm the application architecture diagram of the target newly-built physical subsystem based on the basic operation and maintenance information, and analyze the application architecture diagram to obtain an application architecture diagram analysis result; A physical deployment diagram confirmation module is used to confirm the physical deployment diagram of the target new physical subsystem based on the analysis result of the application architecture diagram, and synchronize the infrastructure resource information of the target new physical subsystem in the version management system; An analysis module, configured to analyze the infrastructure feasibility study plan based on the infrastructure resource information and generate a judgment conclusion and rectification suggestions; A resource estimation logic generation module is used to generate resource estimation logic based on the judgment conclusion and rectification opinions and the preset resource estimation logic framework in combination with the infrastructure feasibility study plan; An audit module is used to audit the infrastructure feasibility study plan based on the resource estimation logic and generate an application architecture audit opinion list.
9. An electronic device, characterized in that: The electronic device includes a processor and a memory; The memory is used to store computer programs; The processor is configured to implement the application infrastructure resource architecture audit method according to any one of claims 1 to 7 when calling and executing the computer program stored in the memory.
10. A computer storage medium, characterized in that The computer storage medium stores computer executable instructions, and when the computer executable instructions are loaded and executed by the processor, the application infrastructure resource architecture audit method according to any one of claims 1 to 7 is implemented.
Citation Information
Patent Citations
Resource management method and device
CN110084486A
Infrastructure scheme auditing method and device, storage medium and electronic equipment
CN114637604A