Inter-tenant network connection method and apparatus, electronic device, and computer readable medium

By acquiring and determining tenant information sets and namespace information sets, network policy information is created, resolving the network connection anomalies between tenants caused by the CNI plugin, and realizing custom configuration and stable connection of the network between tenants.

CN116599846BActive Publication Date: 2026-03-17JD DIGITS HAIYI INFORMATION TECHNOLOGY CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-05-05
Publication Date
2026-03-17

AI Technical Summary

Technical Problem

In existing technologies, when using CNI plugins to implement custom configurations for tenant networks, network connectivity issues between multiple tenants often arise.

Method used

By acquiring pre-configured network connection custom resource information, determining tenant information sets and namespace information sets, creating network policy information, and establishing network connections between tenants based on this information.

Benefits of technology

It enables custom configuration of network connections between tenants, quickly and efficiently establishes stable network connections between tenants, and solves the problem of abnormal network connections.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN116599846B_ABST
    Figure CN116599846B_ABST
Patent Text Reader

Abstract

Embodiments of the present disclosure disclose an inter-tenant network connection method, device, electronic equipment and computer readable medium. A specific embodiment of the method comprises: obtaining first network connection custom resource information; in response to receiving an inter-tenant network connection event, determining a first network connection tenant information set corresponding to the first network connection custom resource information; determining a first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set, obtaining a first namespace information set group; for each first namespace information in the first namespace information set group, creating network policy information corresponding to the first namespace information as first network policy information; and establishing an inter-tenant network connection for the first network connection tenant information set according to the first network policy information set group. The embodiment is related to cloud computing, and can quickly and efficiently realize inter-tenant network connection.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of this disclosure relate to the field of computer technology, and more particularly to methods, apparatuses, electronic devices, and computer-readable media for inter-tenant network connectivity. Background Technology

[0002] Currently, container orchestration platforms in the cloud-native field have powerful container orchestration capabilities, open network interfaces, and support for custom container networks. For tenant network configuration, the common approach is to use CNI (Container Network Interface) plugins to implement custom configurations for the tenant's corresponding tenant network.

[0003] However, the inventors discovered that the following technical problems often arise when using the above method:

[0004] When using CNI plugins to customize tenant network configurations, issues such as abnormal network connections between multiple tenants often arise.

[0005] The information disclosed in this background section is only intended to enhance the understanding of the background of the inventive concept, and therefore may contain information that does not constitute prior art known to those skilled in the art. Summary of the Invention

[0006] The summary portion of this disclosure is intended to provide a brief overview of the concepts, which will be described in detail in the detailed description portion. This summary portion is not intended to identify key or essential features of the claimed technical solutions, nor is it intended to limit the scope of the claimed technical solutions.

[0007] Some embodiments of this disclosure provide methods, apparatuses, electronic devices, and computer-readable media for inter-tenant network connectivity to address the technical problems mentioned in the background section above.

[0008] In a first aspect, some embodiments of this disclosure provide a method for inter-tenant network connectivity, comprising: acquiring pre-configured first network connection custom resource information; in response to receiving an inter-tenant network connectivity event for the first network connection custom resource information, determining a first network connection tenant information set corresponding to the first network connection custom resource information; determining a first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set, thereby obtaining a first namespace information set group; for each first namespace information in the first namespace information set group, creating network policy information corresponding to the first namespace information as first network policy information; and establishing an inter-tenant network connectivity for the first network connection tenant information set according to the obtained first network policy information set group.

[0009] Optionally, the above method further includes: obtaining pre-configured first tenant custom resource information; in response to receiving a tenant definition event for the first tenant custom resource information, determining a second namespace information set and a tenant information set corresponding to the first tenant custom resource information; determining network policy information corresponding to each second namespace information in the second namespace information set as second network policy information to obtain a second network policy information set; and performing association establishment for the second namespace information set and the tenant information set based on the second network policy information set.

[0010] Optionally, the above method further includes: obtaining pre-configured second network connection custom resource information and second tenant custom resource information; in response to receiving a namespace establishment event, determining a defined tenant information set based on the second tenant custom resource information; establishing an internal network for each defined tenant in the defined tenant information set; in response to determining that the internal network of each defined tenant has been established, determining a second network connection tenant information set based on the second network connection custom resource information, wherein the second network connection tenant information set is a subset of the defined tenant information set; and establishing an inter-tenant network for the second network connection tenant information set.

[0011] Optionally, the above method further includes: in response to receiving a network connection adjustment event for the first network connection tenant information set, obtaining the first network policy information set group and network connection adjustment information; adjusting the network policy information in the first network policy information set group that corresponds to the network connection adjustment information to generate first network policy adjustment information, thereby obtaining the first network policy adjustment information set group; and performing inter-tenant network adjustment for the corresponding network connection tenant information subset according to the first network policy adjustment information set group.

[0012] Optionally, the above method further includes: in response to receiving an association relationship adjustment event for tenant-namespace association information, obtaining tenant-namespace relationship adjustment information; adjusting at least one second network policy information in the second network policy information set that is associated with the tenant-namespace relationship adjustment information to obtain at least one second network policy adjustment information; and performing association relationship adjustment for the tenant-namespace association information based on the at least one second network policy adjustment information.

[0013] Optionally, determining the first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set includes: using a namespace selector to determine the first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set.

[0014] Optionally, the tenant network connections between the various first network connection tenant information in the aforementioned first network connection tenant information set are pre-isolated based on the target tenant network isolation plugin.

[0015] Secondly, some embodiments of this disclosure provide an inter-tenant network connection apparatus, comprising: an acquisition unit configured to acquire pre-configured first network connection custom resource information; a first determination unit configured to, in response to receiving an inter-tenant network connection event for the first network connection custom resource information, determine a first network connection tenant information set corresponding to the first network connection custom resource information; a second determination unit configured to determine a first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set, thereby obtaining a first namespace information set group; a creation unit configured to, for each first namespace information in the first namespace information set group, create network policy information corresponding to the first namespace information, as first network policy information; and an establishment unit configured to, based on the obtained first network policy information set group, establish an inter-tenant network connection for the first network connection tenant information set.

[0016] Optionally, the apparatus further includes: acquiring pre-configured first tenant-defined resource information; in response to receiving a tenant definition event for the first tenant-defined resource information, determining a second namespace information set and a tenant information set corresponding to the first tenant-defined resource information; determining network policy information corresponding to each second namespace information in the second namespace information set as second network policy information to obtain a second network policy information set; and performing association establishment for the second namespace information set and the tenant information set based on the second network policy information set.

[0017] Optionally, the apparatus further includes: acquiring pre-configured second network connection custom resource information and second tenant custom resource information; in response to receiving a namespace establishment event, determining a defined tenant information set based on the second tenant custom resource information; establishing an internal network for each defined tenant in the defined tenant information set corresponding to the defined tenant; in response to the establishment of the internal network for each defined tenant, determining a second network connection tenant information set based on the second network connection custom resource information, wherein the second network connection tenant information set is a subset of the defined tenant information set; and establishing an inter-tenant network for the second network connection tenant information set.

[0018] Optionally, the apparatus further includes: in response to receiving a network connection adjustment event for the first network connection tenant information set, acquiring the first network policy information set group and network connection adjustment information; adjusting the network policy information in the first network policy information set group that corresponds to the network connection adjustment information to generate first network policy adjustment information, thereby obtaining the first network policy adjustment information set group; and performing inter-tenant network adjustment for the corresponding network connection tenant information subset according to the first network policy adjustment information set group.

[0019] Optionally, the apparatus further includes: in response to receiving an association relationship adjustment event for tenant-namespace association information, obtaining tenant-namespace relationship adjustment information; adjusting at least one second network policy information in the second network policy information set that is associated with the tenant-namespace relationship adjustment information to obtain at least one second network policy adjustment information; and performing association relationship adjustment for the tenant-namespace association information based on the at least one second network policy adjustment information.

[0020] Optionally, the first determining unit can be configured to: use a namespace selector to determine the first namespace information set corresponding to each network connection tenant information in the aforementioned first network connection tenant information set.

[0021] Optionally, the tenant network connections between the various first network connection tenant information in the aforementioned first network connection tenant information set are pre-isolated based on the target tenant network isolation plugin.

[0022] Thirdly, some embodiments of this disclosure provide an electronic device, including: one or more processors; and a storage device having one or more programs stored thereon, such that when the one or more programs are executed by the one or more processors, the one or more processors implement the method as described in any implementation of the first aspect.

[0023] Fourthly, some embodiments of this disclosure provide a computer-readable medium having a computer program stored thereon, wherein the program, when executed by a processor, implements the method as described in any implementation of the first aspect.

[0024] Fifthly, some embodiments of this disclosure provide a computer program product, including a computer program that, when executed by a processor, implements the method described in any of the implementations of the first aspect above.

[0025] The above embodiments of this disclosure have the following beneficial effects: The inter-tenant network connection method of some embodiments of this disclosure can quickly and efficiently realize inter-tenant network connections. Specifically, the cause of related inter-tenant network connection anomalies is that: using CNI plugins to implement custom configuration of tenant networks often leads to inter-tenant network connection anomalies. Based on this, the inter-tenant network connection method of some embodiments of this disclosure firstly obtains pre-configured first network connection custom resource information for subsequent determination of tenant information to be connected between tenants, and through the first network connection custom resource information, custom configuration of inter-tenant network connections can be realized. Then, in response to receiving an inter-tenant network connection event for the aforementioned first network connection custom resource information, a first network connection tenant information set corresponding to the aforementioned first network connection custom resource information is determined. Here, the first network connection tenant information set is determined for subsequent determination of first namespace information, thereby enabling subsequent inter-tenant network connections based on the first namespace corresponding to the tenant. Next, the first namespace information set corresponding to each network connection tenant information in the aforementioned first network connection tenant information set is determined, resulting in a first namespace information set group. Here, the namespace information set corresponding to each network connection tenant information is used to construct the corresponding network policy information to achieve inter-tenant network connectivity. Furthermore, for each first namespace information in the aforementioned first namespace information set, network policy information corresponding to that first namespace information is created as the first network policy information. Here, the obtained first network policy information can characterize the connection execution policy of the corresponding tenant's inter-tenant network to achieve subsequent inter-tenant network connectivity. Finally, based on the obtained first network policy information set, an inter-tenant network connection is established for the aforementioned first network connection tenant information set to achieve stable inter-tenant network connectivity. In summary, custom configuration of the inter-tenant network can be achieved through the first network connection custom resource information. Based on this, by establishing corresponding network policy information within the first namespace corresponding to the first network connection tenant information, stable inter-tenant network connectivity can be achieved quickly and efficiently. Attached Figure Description

[0026] The above and other features, advantages, and aspects of the embodiments of this disclosure will become more apparent from the accompanying drawings and the following detailed description. Throughout the drawings, the same or similar reference numerals denote the same or similar elements. It should be understood that the drawings are schematic, and elements are not necessarily drawn to scale.

[0027] Figure 1 This is a schematic diagram illustrating an application scenario of a tenant network connection method according to some embodiments of the present disclosure;

[0028] Figure 2 This is a flowchart of some embodiments of the inter-tenant network connection method according to the present disclosure;

[0029] Figure 3 This is a flowchart of some other embodiments of the inter-tenant network connection method according to the present disclosure;

[0030] Figure 4 This is a schematic diagram of inter-tenant network adjustment in some embodiments of the inter-tenant network connection method according to this disclosure;

[0031] Figure 5 This is a schematic diagram of the structure of some embodiments of the inter-tenant network connection device according to the present disclosure;

[0032] Figure 6 This is a schematic diagram of the structure of an electronic device suitable for implementing some embodiments of the present disclosure. Detailed Implementation

[0033] Embodiments of this disclosure will now be described in more detail with reference to the accompanying drawings. While some embodiments of this disclosure are shown in the drawings, it should be understood that this disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided to provide a more thorough and complete understanding of this disclosure. It should be understood that the accompanying drawings and embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of protection of this disclosure.

[0034] It should also be noted that, for ease of description, only the parts relevant to the invention are shown in the accompanying drawings. Unless otherwise specified, the embodiments and features described in this disclosure can be combined with each other.

[0035] It should be noted that the concepts of "first" and "second" mentioned in this disclosure are used only to distinguish different devices, modules or units, and are not used to limit the order of functions performed by these devices, modules or units or their interdependencies.

[0036] It should be noted that the terms "a" and "a plurality of" used in this disclosure are illustrative rather than restrictive, and those skilled in the art should understand that, unless otherwise expressly indicated in the context, they should be understood as "one or more".

[0037] The names of messages or information exchanged between multiple devices in the embodiments of this disclosure are for illustrative purposes only and are not intended to limit the scope of such messages or information.

[0038] Before performing any of the operations involving the information disclosed herein (such as custom resource information of the first network connection), the relevant organizations or individuals shall fulfill their obligations, including conducting information security impact assessments, informing the information subjects, and obtaining prior authorization and consent from the information subjects.

[0039] This disclosure will now be described in detail with reference to the accompanying drawings and embodiments.

[0040] Figure 1 This is a schematic diagram of an application scenario of a tenant network connection method according to some embodiments of the present disclosure.

[0041] exist Figure 1In this application scenario, firstly, the electronic device 101 can obtain pre-configured first network connection custom resource information 102. In this application scenario, the first network connection custom resource information 102 may include: network connections between a first tenant and a second tenant, and network connections between a third tenant and a fourth tenant. Then, in response to receiving a tenant-to-tenant network connection event for the aforementioned first network connection custom resource information 102, the electronic device 101 can determine the first network connection tenant information set 103 corresponding to the aforementioned first network connection custom resource information 102. In this application scenario, the first network connection tenant information set 103 may include: first tenant information 1031, second tenant information 1032, third tenant information 1033, and fourth tenant information 1034. Next, the electronic device 101 can determine the first namespace information set corresponding to each network connection tenant information in the aforementioned first network connection tenant information set 103, obtaining a first namespace information set group. In this application scenario, the first namespace information set 104 corresponding to the first tenant information 1031 includes: namespace C 1041 and namespace D 1042. The first namespace information set corresponding to the second tenant information 1032 includes: namespace A 105. The first namespace information set corresponding to the third tenant information 1033 includes: namespace B 106. The first namespace information set 107 corresponding to the fourth tenant information 1034 includes: namespace F 1071 and namespace O 1072. Furthermore, for each first namespace information in the above-mentioned first namespace information set group, the electronic device 101 can create network policy information corresponding to the above-mentioned first namespace information as the first network policy information; in this application scenario, the first namespace information set 104 corresponds to the first network policy information set 108. The first network policy information set 108 includes: first network policy information 1081 corresponding to namespace C 1041 and first network policy information 1082 corresponding to namespace D 1042. The first namespace information 105 corresponds to the first network policy information set 109. The first namespace information 106 corresponds to the first network policy information set 110. The first namespace information set 107 corresponds to the first network policy information set 111. The first network policy information set 111 includes: first network policy information 1111 corresponding to namespace F 1071, and first network policy information 1112 corresponding to namespace O 1072. Finally, based on the obtained first network policy information set, inter-tenant network connections are established for the aforementioned first network connection tenant information set 103.

[0042] It should be noted that the aforementioned electronic device 101 can be either hardware or software. When the electronic device is hardware, it can be implemented as a distributed cluster consisting of multiple servers or terminal devices, or as a single server or a single terminal device. When the electronic device is software, it can be installed in the hardware devices listed above. It can be implemented as, for example, multiple software programs or software modules used to provide distributed services, or as a single software program or software module. No specific limitations are made here.

[0043] It should be understood that Figure 1 The number of electronic devices shown is merely illustrative. Any number of electronic devices can be used depending on the implementation requirements.

[0044] Continue to refer to Figure 2 The diagram illustrates a flow 200 of some embodiments of an inter-tenant network connectivity method according to the present disclosure. This inter-tenant network connectivity method includes the following steps:

[0045] Step 201: Obtain the pre-configured custom resource information for the first network connection.

[0046] In some embodiments, the entity executing the above-described inter-tenant network connection method (e.g.) Figure 1 The electronic device 101 shown can obtain pre-configured first network connection custom resource information via wired or wireless connection. This first network connection custom resource information can be pre-configured tenant resource information representing communication (i.e., network connection) between tenants. In practice, the first network connection custom resource information can be a CR (Custom Resource) resource with a specific data structure for multiple tenants. The CR resource defines the tenant information that requires network connection between tenants. This tenant information can represent the tenant's identity. It should be noted that a tenant can be for a single user or a group of users, and there are at least one corresponding namespace. It should also be noted that different tenants are isolated using at least one corresponding namespace. The namespace can be a namespace under Kubernetes (a container orchestration platform). Kubernetes supports multiple virtual clusters, all relying on the same physical cluster. These virtual clusters are called namespaces. Namespaces are Kubernetes cluster-level resources. In practice, corresponding namespaces can be created for different users, tenants, environments, or projects. Namespaces can be used to separate resources such as process trees, network interfaces, mount points, and inter-process communication.

[0047] It should be noted that the aforementioned execution entity can be a tenant controller. This tenant controller can be a pre-configured controller. It can also be a controller that processes configuration information related to tenants.

[0048] In some optional implementations of certain embodiments, the tenant network connections between the various first network connection tenant information in the aforementioned first network connection tenant information set are pre-isolated based on a target tenant network isolation plugin. This target tenant network isolation plugin may be a CNI (Container Network Interface) plugin.

[0049] Step 202: In response to receiving a tenant network connection event for the aforementioned first network connection custom resource information, determine the first network connection tenant information set corresponding to the aforementioned first network connection custom resource information.

[0050] In some embodiments, in response to receiving an inter-tenant network connection event for the aforementioned first network connection custom resource information, the executing entity may determine the first network connection tenant information set corresponding to the first network connection custom resource information. The inter-tenant network connection event may be an event that executes a corresponding inter-tenant network connection. The aforementioned first network connection tenant information set may be the set of tenant information to be connected to the network mentioned in the first network connection custom resource information.

[0051] In practice, the aforementioned first network connection tenant information set can be {"the first tenant connects to the second tenant", "the third, fourth, and fifth tenants connect to the network"}. The corresponding first network connection tenant information set can include: first tenant information, second tenant information, third tenant information, fourth tenant information, and fifth tenant information.

[0052] As an example, the aforementioned execution entity can receive inter-tenant network connection events for the first network connection's custom resource information through the apiserver (interface service) in k8s (Kubernetes, a container orchestration platform).

[0053] As yet another example, the aforementioned execution entity can generate a set of tenant information for a first network connection by determining the tenant field in the custom resource information of the first network connection.

[0054] Step 203: Determine the first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set above, and obtain the first namespace information set group.

[0055] In some embodiments, the executing entity may determine the first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set, thereby obtaining a first namespace information set group. The first namespace information set may include at least one first namespace information. The first namespace information may correspond to the identifier information of a namespace. The association between the network connection tenant information and the corresponding first namespace information set is a pre-established relationship.

[0056] In some optional implementations of certain embodiments, the execution entity may utilize a namespace selector to determine the first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set. The namespace selector may be a tag-based namespace selector. In practice, the namespace selector may be a namespaces selector.

[0057] Step 204: For each first namespace information in the first namespace information set group, create network policy information corresponding to the first namespace information as the first network policy information.

[0058] In some embodiments, the execution entity may create network policy information corresponding to each first namespace information in the first namespace information set group, as the first network policy information. The first network policy information may be a Network Policy resource. A network policy is a specification of the communication rules allowed between Pods (the smallest deployable computing unit created and managed in Kubernetes) and with other Network Endpoints. A Network Policy can be applied to pods under a corresponding namespace to implement corresponding network connection management.

[0059] Step 205: Based on the obtained first network policy information set, establish inter-tenant network connections for the aforementioned first network connection tenant information set.

[0060] In some embodiments, the aforementioned executing entity may establish inter-tenant network connections for the aforementioned first network connection tenant information set based on the obtained first network policy information set.

[0061] In practice, the first network connection tenant information set includes: first tenant information, second tenant information, third tenant information, fourth tenant information, and fifth tenant information. The aforementioned first network connection tenant information set is {"the first tenant connects to the second tenant", "the third, fourth, and fifth tenants connect to the network"}. Therefore, the aforementioned executing entity can establish a network connection between "the first tenant" and "the second tenant", and can also establish a network connection between the third, fourth, and fifth tenants.

[0062] As an example, the aforementioned execution entity can utilize open-source calico network plugins, flannel network plugins, and / or cilium network plugins to establish inter-tenant network connections for the aforementioned first network connection tenant information set based on the obtained first network policy information set.

[0063] In some optional implementations of certain embodiments, after step 205, the steps further include:

[0064] The first step is to obtain pre-configured second network connection custom resource information and second tenant custom resource information. The second network connection custom resource information can also be pre-configured tenant resource information representing communication (i.e., network connection) between tenants. The second network connection custom resource information can be the same as or different from the first network connection custom resource information. The second tenant custom resource information can represent the mapping between tenants and namespaces. For example, the second tenant custom resource information can include: the mapping between "tenant A" and "namespace A", "tenant B" and "namespace B", and "tenant C" and "namespace C".

[0065] The second step involves, in response to the received namespace creation event, determining the tenant information set based on the aforementioned second tenant-defined resource information. The namespace creation event can be an event that establishes at least one namespace corresponding to a tenant. The tenant information in the tenant information set can be tenant information involved in the second tenant-defined resource information.

[0066] In practice, in response to receiving a namespace creation event, the aforementioned execution entity can filter out the "tenant information field" from the second tenant's custom resource information to generate a set of defined tenant information.

[0067] The third step is to establish the internal network for each defined tenant in the defined tenant information set. The internal network of a defined tenant can be a container network between the containers in the corresponding pod.

[0068] As an example, the aforementioned execution entity can establish a plugin through the relevant internal network to create an internal network for each defined tenant in the defined tenant information set.

[0069] Fourth, in response to determining that the internal network of each defined tenant has been established, a second network connection tenant information set is determined based on the aforementioned second network connection custom resource information. This second network connection tenant information set is a subset of the aforementioned defined tenant information set. Furthermore, the second network connection tenant information in the second network connection tenant information set may include tenant information for those seeking inter-tenant network connections.

[0070] As an example, the aforementioned execution entity can filter out information associated with the tenant field from the network connection custom resource information to obtain a second network connection tenant information set.

[0071] The fifth step is to establish an inter-tenant network for the aforementioned second network connection tenant information set.

[0072] The specific implementation method will not be elaborated here.

[0073] In some optional implementations of certain embodiments, after step 205, the steps further include:

[0074] The first step is to obtain the first network policy information set and network connection adjustment information in response to receiving a network connection adjustment event for the first network connection tenant information set.

[0075] Among them, network connection adjustment events can be events that adjust network connections between tenants. Network connection adjustment information can include: information about each tenant whose network connection has changed and information about the changes for each tenant.

[0076] The second step involves adjusting the network policy information corresponding to the network connection adjustment information in the first network policy information set to generate the first network policy adjustment information, thus obtaining the first network policy adjustment information set. The first network policy adjustment information can characterize the network connection status of the corresponding tenant after adjustment. The network policy information corresponding to the network connection adjustment information can be the network policy information of the tenant involved in the network connection adjustment information.

[0077] The third step is to adjust the information set group according to the first network strategy mentioned above, and perform inter-tenant network adjustments for the corresponding network connection tenant information subset.

[0078] As an example, the aforementioned execution entity can utilize open-source calico network plugins, flannel network plugins, and / or cilium network plugins to adjust the information set group according to the first network policy mentioned above, and perform inter-tenant network adjustments for the corresponding network connection tenant information subset.

[0079] The above embodiments of this disclosure have the following beneficial effects: The inter-tenant network connection method of some embodiments of this disclosure can quickly and efficiently realize inter-tenant network connections. Specifically, the cause of related inter-tenant network connection anomalies is that: using CNI plugins to implement custom configuration of tenant networks often leads to inter-tenant network connection anomalies. Based on this, the inter-tenant network connection method of some embodiments of this disclosure firstly obtains pre-configured first network connection custom resource information for subsequent determination of tenant information to be connected between tenants, and through the first network connection custom resource information, custom configuration of inter-tenant network connections can be realized. Then, in response to receiving an inter-tenant network connection event for the aforementioned first network connection custom resource information, a first network connection tenant information set corresponding to the aforementioned first network connection custom resource information is determined. Here, the first network connection tenant information set is determined for subsequent determination of first namespace information, thereby enabling subsequent inter-tenant network connections based on the first namespace corresponding to the tenant. Next, the first namespace information set corresponding to each network connection tenant information in the aforementioned first network connection tenant information set is determined, resulting in a first namespace information set group. Here, the namespace information set corresponding to each network connection tenant information is used to construct the corresponding network policy information to achieve inter-tenant network connectivity. Furthermore, for each first namespace information in the aforementioned first namespace information set, network policy information corresponding to that first namespace information is created as the first network policy information. Here, the obtained first network policy information can characterize the connection execution policy of the corresponding tenant's inter-tenant network to achieve subsequent inter-tenant network connectivity. Finally, based on the obtained first network policy information set, an inter-tenant network connection is established for the aforementioned first network connection tenant information set to achieve stable inter-tenant network connectivity. In summary, custom configuration of the inter-tenant network can be achieved through the first network connection custom resource information. Based on this, by establishing corresponding network policy information within the first namespace corresponding to the first network connection tenant information, stable inter-tenant network connectivity can be achieved quickly and efficiently.

[0080] Further reference Figure 3 The diagram illustrates a flow 300 of another embodiment of a method for inter-tenant network connectivity according to the present disclosure. This inter-tenant network connectivity method includes the following steps:

[0081] Step 301: Obtain the pre-configured custom resource information for the first network connection.

[0082] Step 302: In response to receiving a tenant network connection event for the aforementioned first network connection custom resource information, determine the first network connection tenant information set corresponding to the aforementioned first network connection custom resource information.

[0083] Step 303: Determine the first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set above, and obtain the first namespace information set group.

[0084] Step 304: For each first namespace information in the first namespace information set group, create network policy information corresponding to the first namespace information as the first network policy information.

[0085] Step 305: Based on the obtained first network policy information set, establish inter-tenant network connections for the aforementioned first network connection tenant information set.

[0086] In some embodiments, the specific implementation of steps 301-305 and the resulting technical effects can be found in [reference needed]. Figure 2 Steps 201-205 in the corresponding embodiments will not be repeated here.

[0087] Step 306: Obtain the pre-configured custom resource information for the first tenant.

[0088] In some embodiments, the executing entity (e.g. Figure 1 The electronic device 101 shown can obtain pre-configured first tenant-defined resource information. This first tenant-defined resource information can represent the correspondence between a tenant and a namespace. The first tenant-defined resource information can be the same as or different from the second tenant-defined resource information.

[0089] Step 307: In response to receiving the tenant definition event for the first tenant's custom resource information, determine the second namespace information set and the tenant information set corresponding to the first tenant's custom resource information.

[0090] In some embodiments, in response to receiving a tenant definition event for the aforementioned first tenant-customized resource information, the executing entity may determine a second namespace information set and a tenant information set corresponding to the first tenant-customized resource information. The tenant definition event may be an event that defines the association between a tenant and a namespace. The second namespace information in the second namespace information set may be information related to namespace fields in the first tenant-customized resource information. The tenant information in the aforementioned tenant information set may be information related to tenant fields in the first tenant-customized resource information.

[0091] As an example, the aforementioned execution entity can receive tenant definition events for the custom resource information of the first tenant through the API server.

[0092] As an example, the aforementioned execution entity can use the namespaces selector to determine the second namespace information set corresponding to the first tenant's custom resource information.

[0093] Step 308: Determine the network policy information corresponding to each second namespace information in the above second namespace information set, and use it as the second network policy information to obtain the second network policy information set.

[0094] In some embodiments, the execution entity may determine the network policy information corresponding to each second namespace information in the second namespace information set, and use this as the second network policy information set to obtain the second network policy information set. The second network policy information may be a Network Policy resource. The second network policy information can be applied to pods under the corresponding namespace to define the correspondence between tenants and namespaces.

[0095] Step 309: Based on the second network policy information set, establish the association between the second namespace information set and the tenant information set.

[0096] In some embodiments, the execution entity may establish an association between the second namespace information set and the tenant information set based on the second network policy information set.

[0097] As an example, the aforementioned execution entity can utilize open-source calico network plugins, flannel network plugins, and / or cilium network plugins to establish associations between the aforementioned second namespace information set and the aforementioned tenant information set based on the aforementioned second network policy information set.

[0098] In some optional implementations of certain embodiments, after step 309, the steps further include:

[0099] The first step is to respond to a received association relationship adjustment event regarding the tenant-namespace relationship information, and then obtain the tenant-namespace relationship adjustment information. The tenant-namespace relationship can be a relationship representing the association between the tenant and the namespace, defined by the first tenant's custom resource information. The association relationship adjustment event can be an event that adjusts the association relationship between the tenant and the namespace. The tenant-namespace relationship adjustment information can represent the adjustment status between the tenant and the namespace.

[0100] The second step involves adjusting at least one second network policy information in the aforementioned second network policy information set that is associated with the aforementioned tenant-namespace relationship adjustment information, to obtain at least one second network policy adjustment information. Specifically, the at least one second network policy information associated with the aforementioned tenant-namespace relationship adjustment information can be at least one second network policy information corresponding to the namespace information involved in the tenant-namespace relationship adjustment information.

[0101] The third step is to adjust the association relationship between the tenant and the namespace based on at least one of the above-mentioned second network policy adjustment information.

[0102] As an example, the aforementioned execution entity can utilize open-source calico network plugins, flannel network plugins, and / or cilium network plugins to perform association adjustments on the aforementioned tenant-namespace association information based on at least one of the aforementioned second network policy adjustment information.

[0103] As an example, such as Figure 4 As shown, for the association relationship adjustment event, the tenant information set 401 corresponding to the tenant and namespace association relationship information includes: first tenant information 4011, second tenant information 4012, third tenant information 4013, and fourth tenant information 4014. The original network connection between first tenant information 4011 and second tenant information 4012, and the original network connection between third tenant information 4013 and fourth tenant information 4014, can be adjusted to a network connection between first tenant information 4011, second tenant information 4012, third tenant information 4013, and fourth tenant information 4014.

[0104] from Figure 3 It can be seen from this that, with Figure 2 Compared to the description of some corresponding embodiments, Figure 3 In some corresponding embodiments, the process 300 of the inter-tenant network connection method can quickly respond to tenant definition events and efficiently execute the association between namespaces and corresponding tenant information by using the obtained first tenant custom resource information.

[0105] Further reference Figure 5 As an implementation of the methods shown in the above figures, this disclosure provides some embodiments of an inter-tenant network connection device, which are similar to... Figure 2 Corresponding to the method embodiments shown, this inter-tenant network connection device can be specifically applied to various electronic devices.

[0106] like Figure 5 As shown, a tenant network connection device 500 includes: an acquisition unit 501, a first determination unit 502, a second determination unit 503, a creation unit 504, and an establishment unit 505. The acquisition unit 501 is configured to acquire pre-configured first network connection custom resource information; the first determination unit 502 is configured to, in response to receiving a tenant network connection event for the first network connection custom resource information, determine a first network connection tenant information set corresponding to the first network connection custom resource information; the second determination unit 503 is configured to determine a first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set, obtaining a first namespace information set group; the creation unit 504 is configured to, for each first namespace information in the first namespace information set group, create network policy information corresponding to the first namespace information, as first network policy information; and the establishment unit 505 is configured to, based on the obtained first network policy information set group, establish a tenant network connection for the first network connection tenant information set.

[0107] In some optional implementations of certain embodiments, the apparatus 500 further includes: a first information acquisition unit, a third determination unit, a fourth determination unit, and a first execution unit (not shown in the figure). The first information acquisition unit can be configured to: acquire pre-configured first tenant-defined resource information. The third determination unit can be configured to: in response to receiving a tenant definition event for the first tenant-defined resource information, determine a second namespace information set and a tenant information set corresponding to the first tenant-defined resource information. The fourth determination unit can be configured to: determine network policy information corresponding to each second namespace information in the second namespace information set, as second network policy information, to obtain a second network policy information set. The first execution unit can be configured to: perform association establishment for the second namespace information set and the tenant information set based on the second network policy information set.

[0108] In some optional implementations of certain embodiments, the apparatus 500 further includes: a second acquisition unit, a fifth determination unit, a first network establishment unit, a sixth determination unit, and a second network establishment unit (not shown in the figure). The second acquisition unit can be configured to: acquire pre-configured second network connection custom resource information and second tenant custom resource information. The fifth determination unit can be configured to: in response to receiving a namespace establishment event, determine a set of defined tenant information based on the second tenant custom resource information. The first network establishment unit can be configured to: establish an internal network for each defined tenant information corresponding to the defined tenant in the defined tenant information set. The sixth determination unit can be configured to: in response to determining that the internal network of each defined tenant has been established, determine a second network connection tenant information set based on the second network connection custom resource information, wherein the second network connection tenant information set is a subset of the defined tenant information set. The second network establishment unit can be configured to: establish an inter-tenant network for the second network connection tenant information set.

[0109] In some optional implementations of certain embodiments, the apparatus 500 further includes: a third acquisition unit, a first information adjustment unit, and a first network adjustment unit (not shown in the figure). The third acquisition unit can be configured to: in response to receiving a network connection adjustment event for the first network connection tenant information set, acquire the first network policy information set and network connection adjustment information. The first information adjustment unit can be configured to: adjust the network policy information in the first network policy information set corresponding to the network connection adjustment information to generate first network policy adjustment information, thus obtaining the first network policy adjustment information set. The first network adjustment unit can be configured to: perform inter-tenant network adjustments for the corresponding subset of network connection tenant information according to the first network policy adjustment information set.

[0110] In some optional implementations of certain embodiments, the apparatus 500 further includes: a fourth acquisition unit, a second information adjustment unit, and an association adjustment unit (not shown in the figure). The fourth acquisition unit can be configured to: acquire tenant-namespace relationship adjustment information in response to receiving an association adjustment event for tenant-namespace relationship information. The second information adjustment unit can be configured to: adjust at least one second network policy information in the second network policy information set that is associated with the tenant-namespace relationship adjustment information to obtain at least one second network policy adjustment information. The association adjustment unit can be configured to: perform association adjustment for the tenant-namespace relationship information based on the at least one second network policy adjustment information.

[0111] In some optional implementations of some embodiments, the first determining unit 502 may be further configured to: use a namespace selector to determine the first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set.

[0112] In some alternative implementations of some embodiments, the tenant network connections between the various first network connection tenant information in the aforementioned first network connection tenant information set are pre-isolated based on the target tenant network isolation plugin.

[0113] It is understandable that the units described in the inter-tenant network connection device 500 are related to the reference Figure 2 The steps in the described method correspond accordingly. Therefore, the operations, features, and beneficial effects described above for the method also apply to the inter-tenant network connection device 500 and the units contained therein, and will not be repeated here.

[0114] The following is for reference. Figure 6 It illustrates electronic devices suitable for implementing some embodiments of this disclosure (e.g., Figure 1 A schematic diagram of the structure of electronic device 101)600 in the middle. Figure 6 The electronic device shown is merely an example and should not be construed as limiting the functionality and scope of the embodiments of this disclosure.

[0115] like Figure 6 As shown, the electronic device 600 may include a processing unit (e.g., a central processing unit, a graphics processing unit, etc.) 601, which can perform various appropriate actions and processes according to a program stored in a read-only memory 602 or a program loaded from a storage device 608 into a random access memory 603. The random access memory 603 also stores various programs and data required for the operation of the electronic device 600. The processing unit 601, the read-only memory 602, and the random access memory 603 are interconnected via a bus 604. An input / output interface 605 is also connected to the bus 604.

[0116] Typically, the following devices can be connected to the input / output interface 605: input devices 606 including, for example, a touchscreen, touchpad, keyboard, mouse, camera, microphone, accelerometer, gyroscope, etc.; output devices 607 including, for example, a liquid crystal display (LCD), speaker, vibrator, etc.; storage devices 608 including, for example, magnetic tape, hard disk, etc.; and communication devices 609. Communication device 609 allows electronic device 600 to communicate wirelessly or wiredly with other devices to exchange data. Although Figure 6 An electronic device 600 with various devices is shown; however, it should be understood that it is not required to implement or possess all of the devices shown. More or fewer devices may be implemented or possessed alternatively. Figure 6 Each box shown can represent a device or multiple devices as needed.

[0117] In particular, according to some embodiments of this disclosure, the processes described above with reference to the flowcharts can be implemented as computer software programs. For example, some embodiments of this disclosure include a computer program product comprising a computer program carried on a computer-readable medium, the computer program containing program code for performing the methods shown in the flowcharts. In such embodiments, the computer program can be downloaded and installed from a network via a communication device 609, or installed from a storage device 608, or installed from a read-only memory 602. When the computer program is executed by the processing device 601, it performs the functions defined above in the methods of some embodiments of this disclosure.

[0118] It should be noted that, in some embodiments of this disclosure, the computer-readable medium described above may be a computer-readable signal medium or a computer-readable storage medium, or any combination thereof. A computer-readable storage medium may be, for example,—but not limited to—an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof. More specific examples of a computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, random access memory (RAM), read-only memory (ROM), erasable programmable read-only memory (EPROM or flash memory), optical fiber, portable compact disk read-only memory (CD-ROM), optical storage device, magnetic storage device, or any suitable combination thereof. In some embodiments of this disclosure, a computer-readable storage medium may be any tangible medium containing or storing a program that can be used by or in conjunction with an instruction execution system, apparatus, or device. In some embodiments of this disclosure, a computer-readable signal medium may include a data signal propagated in baseband or as part of a carrier wave, carrying computer-readable program code. Such propagated data signals may take various forms, including but not limited to electromagnetic signals, optical signals, or any suitable combination thereof. A computer-readable signal medium can be any computer-readable medium other than a computer-readable storage medium, which can send, propagate, or transmit a program for use by or in connection with an instruction execution system, apparatus, or device. The program code contained on the computer-readable medium can be transmitted using any suitable medium, including but not limited to: wires, optical fibers, RF (radio frequency), etc., or any suitable combination thereof.

[0119] In some implementations, clients and servers can communicate using any currently known or future-developed network protocol such as HTTP (Hypertext Transfer Protocol) and can interconnect with digital data communication (e.g., communication networks) of any form or medium. Examples of communication networks include local area networks (“LANs”), wide area networks (“WANs”), the Internet (e.g., the Internet of Things), and peer-to-peer networks (e.g., ad hoc peer-to-peer networks), as well as any currently known or future-developed networks.

[0120] The aforementioned computer-readable medium may be included in the aforementioned electronic device; or it may exist independently and not assembled into the electronic device. The aforementioned computer-readable medium carries one or more programs that, when executed by the electronic device, cause the electronic device to: acquire pre-configured first network connection custom resource information; in response to receiving a tenant network connection event for the aforementioned first network connection custom resource information, determine a first network connection tenant information set corresponding to the aforementioned first network connection custom resource information; determine a first namespace information set corresponding to each network connection tenant information in the aforementioned first network connection tenant information set, obtaining a first namespace information set group; for each first namespace information in the aforementioned first namespace information set group, create network policy information corresponding to the aforementioned first namespace information as first network policy information; and establish a tenant network connection for the aforementioned first network connection tenant information set according to the obtained first network policy information set group.

[0121] Computer program code for performing operations of some embodiments of this disclosure can be written in one or more programming languages ​​or a combination thereof, including object-oriented programming languages ​​such as Java, Smalltalk, and C++, and conventional procedural programming languages ​​such as the "C" language or similar programming languages. The program code can be executed entirely on the user's computer, partially on the user's computer, as a standalone software package, partially on the user's computer and partially on a remote computer, or entirely on a remote computer or server. In cases involving remote computers, the remote computer can be connected to the user's computer via any type of network—including a local area network (LAN) or a wide area network (WAN)—or can be connected to an external computer (e.g., via the Internet using an Internet service provider).

[0122] The flowcharts and block diagrams in the accompanying drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of this disclosure. In this regard, each block in a flowchart or block diagram may represent a module, segment, or portion of code containing one or more executable instructions for implementing a specified logical function. It should also be noted that in some alternative implementations, the functions indicated in the blocks may occur in a different order than those indicated in the drawings. For example, two consecutively indicated blocks may actually be executed substantially in parallel, and they may sometimes be executed in reverse order, depending on the functions involved. It should also be noted that each block in the block diagrams and / or flowcharts, and combinations of blocks in the block diagrams and / or flowcharts, can be implemented using a dedicated hardware-based system that performs the specified function or operation, or using a combination of dedicated hardware and computer instructions.

[0123] The units described in some embodiments of this disclosure can be implemented in software or hardware. The described units can also be housed in a processor; for example, a processor may be described as including an acquisition unit, a first determination unit, a second determination unit, a creation unit, and an establishment unit. The names of these units do not necessarily limit the specific unit; for example, the acquisition unit may also be described as "a unit that acquires pre-configured first network connection custom resource information."

[0124] The functions described above in this document can be performed, at least in part, by one or more hardware logic components. For example, exemplary types of hardware logic components that can be used, without limitation, include: Field Programmable Gate Arrays (FPGAs), Application-Specific Integrated Circuits (ASICs), Application Standard Products (ASSPs), System-on-Chip (SoCs), Complex Programmable Logic Devices (CPLDs), and so on.

[0125] Some embodiments of this disclosure also provide a computer program product, including a computer program that, when executed by a processor, implements any of the above-described inter-tenant network connection methods.

[0126] The above description is merely a selection of preferred embodiments of this disclosure and an explanation of the technical principles employed. Those skilled in the art should understand that the scope of the invention involved in the embodiments of this disclosure is not limited to technical solutions formed by specific combinations of the above-described technical features, but should also cover other technical solutions formed by arbitrary combinations of the above-described technical features or their equivalents without departing from the above-described inventive concept. For example, technical solutions formed by substituting the above-described features with (but not limited to) technical features with similar functions disclosed in the embodiments of this disclosure.

Claims

1. A method for inter-tenant network connection, applied to a container orchestration platform, comprising: obtaining pre-configured first network connection custom resource information, wherein the first network connection custom resource information comprises tenant information requiring inter-tenant network connection; in response to receiving an inter-tenant network connection event for the first network connection custom resource information, determining a first network connection tenant information set corresponding to the first network connection custom resource information; determining a first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set, to obtain a first namespace information set group; for each first namespace information in the first namespace information set group, creating network policy information corresponding to the first namespace information as first network policy information; establishing inter-tenant network connection for the first network connection tenant information set according to the obtained first network policy information set group.

2. The method of claim 1, wherein, The method further comprises: obtaining pre-configured first tenant custom resource information; in response to receiving a tenant definition event for the first tenant custom resource information, determining a second namespace information set and a tenant information set corresponding to the first tenant custom resource information; determining network policy information corresponding to each second namespace information in the second namespace information set as second network policy information, to obtain a second network policy information set; establishing an association relationship for the second namespace information set and the tenant information set according to the second network policy information set.

3. The method of claim 1, wherein, The method further comprises: obtaining pre-configured second network connection custom resource information and second tenant custom resource information; in response to receiving a namespace establishment event, determining a definition tenant information set according to the second tenant custom resource information; establishing an internal network of each definition tenant in the definition tenant information set; in response to determining that the internal network of each definition tenant has been established, determining a second network connection tenant information set according to the second network connection custom resource information, wherein the second network connection tenant information set is a subset of the definition tenant information set; establishing inter-tenant network for the second network connection tenant information set.

4. The method of claim 1, wherein, The method further comprises: in response to receiving a network connection adjustment event for the first network connection tenant information set, obtaining the first network policy information set group and network connection adjustment information; adjusting network policy information corresponding to the network connection adjustment information in the first network policy information set group to generate first network policy adjustment information, to obtain a first network policy adjustment information set group; performing inter-tenant network adjustment for the corresponding network connection tenant information subset according to the first network policy adjustment information set group.

5. The method of claim 2, wherein, The method further comprises: in response to receiving an association relationship adjustment event for tenant and namespace association relationship information, obtaining tenant and namespace relationship adjustment information; adjusting information in the at least one second network policy information in the second network policy information set associated with the tenant-namespace relationship adjustment information to obtain at least one second network policy adjustment information; performing, according to the at least one second network policy adjustment information, adjustment of the association relationship of the tenant-namespace association relationship information.

6. The method of claim 1, wherein, The determining of the first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set includes: The first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set is determined by using a namespace selector.

7. The method of claim 1, wherein, The tenant network connection between each first network connection tenant information in the first network connection tenant information set is pre-isolated based on a target tenant network isolation plug-in.

8. A tenant-to-tenant network connection apparatus applied to a container orchestration platform, comprising: an acquisition unit configured to acquire pre-configured first network connection custom resource information, wherein the first network connection custom resource information includes tenant information that needs to be connected between tenants; a first determination unit configured to determine, in response to receiving a tenant-to-tenant network connection event for the first network connection custom resource information, a first network connection tenant information set corresponding to the first network connection custom resource information; a second determination unit configured to determine a first namespace information set corresponding to each network connection tenant information in the first network connection tenant information set to obtain a first namespace information set group; a creation unit configured to create, for each first namespace information in the first namespace information set group, network policy information corresponding to the first namespace information as first network policy information; an establishment unit configured to establish tenant-to-tenant network connection for the first network connection tenant information set according to the obtained first network policy information set group.

9. An electronic device, comprising: one or more processors; a storage device having one or more programs stored thereon, when the one or more programs are executed by the one or more processors, the one or more processors implement the method of any one of claims 1-7.

10. A computer readable medium having stored thereon a computer program, wherein, The computer program is executed by the processor to implement the method of any one of claims 1-7.

11. A computer program product comprising a computer program which, when executed by a processor, implements the method according to any one of claims 1-7.

11. A computer program product comprising a computer program which, when executed by a processor, implements the method according to any one of claims 1-7.

Citation Information

Patent Citations

  • Container network configuration method and device, computing node, main node and storage medium

    CN114172802A

  • Multi-channel isolation safety protection method and system

    CN115766189A