Method, apparatus, device, and medium for performing resource scheduling in a cluster

By creating network service instances in the cluster and utilizing Kubernetes' CRD and IPtables configuration, the problem of inconsistent access methods of resource instances in different clusters is solved, and unified management and efficient communication of cross-cluster resource access is realized.

CN117082012BActive Publication Date: 2025-07-29BEIJING VOLCANO ENGINE TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202311120170.9
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Filing Date
2023-08-31
Publication Date
2025-07-29
Estimated Expiration
2043-08-31

AI Technical Summary

Technical Problem

Resource instances in different clusters have custom input/output interface access methods, making it difficult to access resource instances within the cluster from outside the cluster in a unified manner, thereby affecting communication between application functional units.

Method used

Create a network service instance, use the network address and port of the resource instance to establish a network link, update the network status, and start the resource instance for communication after detecting the link establishment, and achieve cross-cluster resource access through Kubernetes' CRD function and IPtables configuration.

Benefits of technology

It realizes the management of resource instance access in a unified manner in different cluster environments, reduces port management overhead, and is suitable for cross-cluster service grid governance and service registration scenarios.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN117082012B_ABST
    Figure CN117082012B_ABST
Patent Text Reader

Abstract

Methods, apparatuses, devices, and media for performing resource scheduling in a cluster are provided. In one method, a network service instance for managing a resource instance's network service is created. Using the network address of the resource instance and the network port assigned to the resource instance, a network link for accessing the resource instance is established. Based on the network link, the network state in the network service instance is updated. In response to detecting that the network state indicates that the network link has been established, the resource instance is started to communicate with the started resource instance via the network link. Using the exemplary implementation of the present disclosure, an access method that does not rely on the dedicated capabilities of any specific cluster is provided. In this way, resource instance access under multiple clusters is managed in a general and unified manner.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Exemplary implementations of the present disclosure generally relate to network management, and particularly to methods, apparatuses, devices, and computer-readable storage media for performing resource scheduling in a cluster. Background Art

[0002] With the development of network technology, various cluster solutions have been proposed. Providers of each cluster can develop their respective cluster technologies based on a general cluster architecture. Each cluster can provide its own resource instances, and different functional units in an application may depend on resource instances in different clusters to achieve the overall function of the application. However, resource instances in different clusters can have custom input / output interface access methods, which causes the application to have to access resource instances in the custom ways of each cluster. At this time, it is difficult to access resource instances inside the cluster in a unified manner from outside the cluster, resulting in difficulties in communication between various functional units in the application. At this time, it is desirable to access various resource instances in the cluster in a more convenient and effective manner. Summary of the Invention

[0003] In a first aspect of the present disclosure, a method for performing resource scheduling in a cluster is provided. In this method, a network service instance for managing a network service of a resource instance is created. A network link for accessing the resource instance is established by using the network address of the resource instance and the network port assigned to the resource instance. The network state in the network service instance is updated based on the network link. In response to detecting that the network state indicates that the network link has been established, the resource instance is started to communicate with the started resource instance via the network link.

[0004] In a second aspect of the present disclosure, an apparatus for performing resource scheduling in a cluster is provided. The apparatus includes: a creation module configured to create a network service instance for managing a network service of a resource instance; an establishment module configured to establish a network link for accessing the resource instance by using the network address of the resource instance and the network port assigned to the resource instance; an update module configured to update the network state in the network service instance based on the network link; and a start module configured to, in response to detecting that the network state indicates that the network link has been established, start the resource instance to communicate with the started resource instance via the network link.

[0005] In a third aspect of the present disclosure, an electronic device is provided. The electronic device includes: at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions causing the electronic device to perform the method according to the first aspect of the present disclosure when executed by the at least one processing unit.

[0006] In a fourth aspect of the present disclosure, there is provided a computer-readable storage medium having stored thereon a computer program, which when executed by a processor causes the processor to implement the method according to the first aspect of the present disclosure.

[0007] It should be understood that the content described in this content part is not intended to define the key features or important features of the implementation manners of the present disclosure, nor is it used to limit the scope of the present disclosure. Other features of the present disclosure will become easily understandable through the following description. BRIEF DESCRIPTION OF THE DRAWINGS

[0008] In the following, in conjunction with the drawings and with reference to the following detailed description, the above and other features, advantages and aspects of the various implementation manners of the present disclosure will become more apparent. In the drawings, the same or similar reference numerals denote the same or similar elements, where:

[0009] Figure 1 A block diagram of a cluster environment according to an exemplary implementation manner of the present disclosure is shown;

[0010] Figure 2 A block diagram for performing resource scheduling in a cluster according to some implementation manners of the present disclosure is shown;

[0011] Figure 3 A block diagram for performing resource scheduling in a cluster based on a network service instance according to some implementation manners of the present disclosure is shown;

[0012] Figure 4 A block diagram for injecting an initial container into a resource instance according to some implementation manners of the present disclosure is shown;

[0013] Figure 5 A block diagram for establishing a resource instance and starting to access the resource instance according to some implementation manners of the present disclosure is shown;

[0014] Figure 6 A block diagram for destroying a resource instance according to some implementation manners of the present disclosure is shown;

[0015] Figure 7 A flowchart of a method for performing resource scheduling in a cluster according to some implementation manners of the present disclosure is shown;

[0016] Figure 8 A block diagram of an apparatus for performing resource scheduling in a cluster according to some implementation manners of the present disclosure is shown; and

[0017] Figure 9 A block diagram of a device capable of implementing multiple implementation manners of the present disclosure is shown. DETAILED DESCRIPTION OF THE EMBODIMENTS

[0018] Embodiments of the present disclosure will be described in more detail below with reference to the accompanying drawings. Although certain embodiments of the present disclosure are shown in the drawings, it should be understood that the present disclosure can be implemented in various forms and should not be construed as limited to the embodiments set forth herein. On the contrary, these embodiments are provided to more thoroughly and completely understand the present disclosure. It should be understood that the drawings and embodiments of the present disclosure are only for exemplary purposes and are not used to limit the protection scope of the present disclosure.

[0019] In the description of the embodiments of the present disclosure, the term "comprising" and its like shall be understood as an open inclusion, that is, "including but not limited to". The term "based on" shall be understood as "at least partially based on". The term "an embodiment" or "the embodiment" shall be understood as "at least one embodiment". The term "some embodiments" shall be understood as "at least some embodiments". There may also be other explicit and implicit definitions hereinafter. As used herein, the term "model" may represent the association relationship between various data. For example, the above association relationship can be obtained based on various technical solutions known currently and / or to be developed in the future.

[0020] It can be understood that the data involved in the technical solution (including but not limited to the data itself, the acquisition or use of the data) should comply with the requirements of the corresponding laws, regulations and related provisions.

[0021] It can be understood that before using the technical solutions disclosed in the embodiments of the present disclosure, the types, usage scopes, usage scenarios, etc. of the personal information involved in the present disclosure should be informed to the user and the user's authorization should be obtained through appropriate means according to the relevant laws and regulations.

[0022] For example, when receiving the user's active request, a prompt message is sent to the user to clearly prompt the user that the operation requested by the user will require the acquisition and use of the user's personal information. Thus, the user can autonomously choose whether to provide personal information to the software or hardware such as an electronic device, an application program, a server or a storage medium that executes the operation of the technical solution of the present disclosure according to the prompt message.

[0023] As an optional but non-limiting embodiment, the manner of sending a prompt message to the user in response to receiving the user's active request may be, for example, in the form of a pop-up window, and the prompt message may be presented in text in the pop-up window. In addition, the pop-up window may also carry a selection control for the user to select "agree" or "disagree" to provide personal information to the electronic device.

[0024] It is understandable that the above-mentioned notification and the process of obtaining user authorization are only illustrative and do not limit the implementation manner of the present disclosure. Other manners that comply with relevant laws and regulations can also be applied to the implementation manner of the present disclosure.

[0025] As used herein, the term "in response to" means a state in which a corresponding event occurs or a condition is satisfied. It will be understood that the timing of the execution of subsequent actions performed in response to the event or condition and the time when the event occurs or the condition is established are not necessarily strongly correlated. For example, in some cases, the subsequent action can be immediately executed when the event occurs or the condition is established; while in other cases, the subsequent action can be executed after a period of time after the event occurs or the condition is established.

[0026] Example environment

[0027] See Figure 1 Describe an overview of the application environment according to an exemplary implementation manner of the present disclosure. Figure 1 FIG. 100 is a block diagram showing a cluster environment according to an exemplary implementation manner of the present disclosure. As Figure 1 shown, different providers can establish their respective clusters 110,..., and 120 based on a basic cluster architecture (e.g., Kubernetes architecture and / or various cluster architectures known currently and / or to be developed in the future). Each cluster can have its own dedicated functions developed on top of the infrastructure. For example, cluster 110 can provide resource instance 112 and cluster 120 can provide resource instance 122.

[0028] In the application 130 developed across clusters, different functional units may depend on resource instances in different clusters to achieve the overall function of the application. At this time, each resource instance needs to communicate with other requesters outside the cluster (e.g., other resource instances, other functional modules in application 130, etc.). However, resource instances in different clusters can have their own dedicated input / output interface access methods, which makes it difficult to access resource instances inside the cluster from outside the cluster in a unified manner, thereby making it difficult for each functional unit in the application to communicate with each other.

[0029] With the wide use of cloud technologies based on Kubernetes-based PAAS (Platform As A Service) containers, multi-cloud and polymorphic scenarios have become the norm in application development. Cross-cluster scheduling and deployment of applications in multi-cloud and polymorphic scenarios have become the norm. Although the Kubernetes clusters are networked with each other, the respective backend resource instances corresponding to the applications (e.g., Pods) are located in the private environments of their respective clusters. At this time, when implementing application service traffic governance (also known as Service Mesh) and unified access to application traffic through the cloud's native gateway, there will be situations where the backend resource instances cannot be accessed.

[0030] Currently, technical solutions for cross-cluster resource access have been proposed. For example, cross-cluster resource access can be achieved based on the IP addresses of Pods in the cluster. However, in cases where a large amount of network communication is required, this technical solution consumes a huge amount of IPs. Further, when accessing the underlying data of Pods in different clusters, the dedicated access methods of each cluster need to be followed, which makes it difficult to manage cross-cluster communication in a unified manner. Another example is that cross-cluster communication can be achieved based on the pre-configured host port technology. However, this technical solution requires the pre-configuration of host port information and cannot automatically allocate host ports. At this time, cross-cluster traffic access of applications has become an urgent problem to be solved, and it is expected to access various resource instances in the cluster in a more convenient and effective manner.

[0031] Overview of cross-cluster resource access

[0032] To at least partially address the deficiencies in the prior art, according to an exemplary implementation of the present disclosure, a method for performing resource scheduling in a cluster is proposed. The present disclosure relates to the requirement scenario of cross-cluster resource access under multi-clusters. Generally speaking, network service instances can be established based on the underlying basic cluster architectures of the respective clusters, and the network service instances are used to manage the network communication between the resource instances within the clusters and the visitors outside the clusters.

[0033] See Figure 2 A summary of an exemplary implementation of the present disclosure is described. The Figure 2 shows a block diagram 200 for performing resource scheduling in a cluster according to some implementations of the present disclosure. As Figure 2As shown, for the resource instance 210 in a certain cluster, a network service instance 220 for managing the network service of the resource instance 210 can be created. For example, based on the Customer Resource Definition (CRD) function supported by the cluster infrastructure, the specific content of the network service (e.g., implemented through a class) can be defined. Further, the network service can be instantiated to generate the network service instance 220.

[0034] The network service instance 220 can record the network address 222 and network port 224 for providing the network service, and use the network address 222 of the resource instance 210 and the network port 224 assigned to the resource instance 210 to establish a network link for accessing the resource instance 210. In the case where the network link has been established, the network state 226 in the network service instance 220 can be updated based on the network link. At this time, it can be determined whether the network link has been successfully established through the network state 226. If it is detected that the network state 226 indicates that the network link has been established, the resource instance 210 can be started to communicate with the started resource instance via the network link.

[0035] Using the example implementation manner of the present disclosure, the network service instance 220 is established only based on the capabilities provided by the underlying basic cluster architecture, without the need to rely on any dedicated functions of the cluster provider. Therefore, the access problems of resource instances in various cluster environments can be solved in a unified manner. Further, the range of network ports can be flexibly configured. At this time, the allocated ports are unique within the node corresponding to the resource instance, rather than unique throughout the entire cluster. In this way, the number of available ports can be fully guaranteed. Thus, the proposed implementation manner is particularly suitable for scenarios such as service mesh governance across clusters, service registration across clusters, and cross-cluster gateway traffic invocation.

[0036] Detailed process of cross-cluster resource access

[0037] According to an example implementation of the present disclosure, the present invention is a set of general cross-cluster network intercommunication solutions. For ease of description, only Kubernetes is used as an example of the basic cluster architecture to describe the communication between multiple clusters developed based on the Kubernetes architecture hereinafter. Alternatively and / or additionally, the process of resource scheduling in the cluster can be implemented based on various cluster architectures that have been proposed and / or will be developed in the future, as long as the basic cluster architecture supports custom network service instances. Further, the resource instance herein can be, for example, an instance of the Pod resource in the Kubernetes architecture. Herein, a Pod is the smallest resource unit in the Kubernetes architecture. A Pod can include one or more containers. Each container in the Pod can share storage and network, and the Pod can have a single network address.

[0038] See Figure 3 Describe the architecture according to an example implementation of the present disclosure. Figure 3 FIG. 300 is a block diagram showing resource scheduling in a cluster based on network service instances according to some implementations of the present disclosure. As Figure 3 shown, cross-cluster resource instance access can be implemented based on three core parts: network service instance 220, monitor 330, and daemon 340. The client 310 can create a resource instance 210 (e.g., a Pod), and can create a corresponding network service instance 220 for the resource instance 210 to manage the network service of the resource instance 210. The network service instance 220 can be implemented based on the Kubernetes CRD function. Further, the monitor 330 and the daemon 340 can be used to complete the specific process for accessing the network instance 210.

[0039] According to an example implementation of the present disclosure, in the process of creating a network service instance, the cluster's custom resource definition function can be used to define the network service. For the Kubernetes architecture, the data structure of the network service can be defined based on the CRD function of Kubernetes. For example, the data structure of the network service can be defined as shown in Table 1 below.

[0040] Table 1 Example of the data structure of the network service

[0041]

[0042]

[0043] As shown in Code Segment 1 in Table 1, the data structure of a network service (for example, with the specific name PortMap) can be defined. The network service can include type metadata and object metadata. Further, the network service can include a data structure related to network configuration (for example, with the name PortMapSpec). Code Segment 2 shows the specific data structure of network configuration. For example, it can include: the name of the service instance PodName, the namespace of the service instance PodNS, the network address of the service instance PodIP, the network address of the node where the service instance is located HostIP, the container ports of the service instance ServicePorts, and so on. Further, Code Segment 3 shows the specific data structure related to network status. For example, the network status can be stored in string format.

[0044] It should be understood that the naming of each structure and variable above is exemplary. For example, PortMap is just an exemplary name for the network service, and the name of the network service can be customized based on various naming methods. For example, other names such as MyNetService can be used to define the network service. The name PortMapSpec of the network configuration data is also exemplary, and other names such as MySpec can be used to define the network configuration data.

[0045] According to an example implementation manner of the present disclosure, during the process of defining a network service, the service account configuration of a resource instance can be checked to determine whether the resource instance allows the customer resource definition function. Specifically, the ServiceAccount configuration of the Pod can be checked to determine whether the Pod has the permission to operate the Portmap CRD. When it is determined that there is the corresponding permission, the data structure of the network service can be defined, and a network service instance 220 can be obtained through an instantiation operation. In this way, without the need for the dedicated functions of the providers of each cluster, the underlying functions of the basic Kubernetes architecture can be directly called, thereby realizing cross-cluster access to resource instances.

[0046] According to an example implementation manner of the present disclosure, if it is determined that the resource instance does not allow the customer resource definition function, the service account configuration is updated to allow the customer resource definition function. That is, if it is determined that there is no corresponding permission, the ClusterRoleBinding configuration of Portmap can be updated to ensure that the Pod has the permission to operate the Portmap CRD. In this way, it can be ensured that the Pod can operate the network service instance 220 defined in the above manner, and then use the network service instance 220 to manage the communication between the resource instance 210 and various visitors outside the cluster.

[0047] Continue to refer to Figure 3, a monitor program 330 can be used to manage the process of creating a network service instance 220, and a daemon program 340 can be used to manage the communication process after creation. In the process of implementing the monitor program 330, for example, the monitor program 330 can be named Webhook (or other names), and corresponding code can be written to implement the monitor program 330. Here, Webhook can represent a Kubernetes Mutating Admission Webhook, and Webhook can be set in the cluster in the form of a Kubernetes deployment resource.

[0048] According to an exemplary implementation manner of the present disclosure, a network service instance 220 can be established only when it is detected that an external access interface needs to be provided to a requester outside the cluster. For example, in response to detecting an access permission that allows a requester outside the cluster to access a resource instance, a network service instance is created. In this way, various resource consumptions involved in the instantiation process can be reduced, and an external access interface is provided only when needed.

[0049] Specifically, if an access permission that allows a requester outside the cluster to access a resource instance is detected, a network service instance 220 can be created. For example, the network service label of the resource instance can be detected. If it is detected that the network service label is set to active, it can be determined that the access permission is detected. In this way, it is possible to determine whether a network service instance 220 needs to be created in a simple and effective manner. For example, the following label of the created resource instance 210 can be detected: the specific setting of pod.kubernetes.io / portmap.

[0050] According to an exemplary implementation manner of the present disclosure, if the label is set to active, that is, it is detected that: pod.kubernetes.io / portmap: enabled, a network service instance 220 can be created. If the label is set to inactive, that is, it is detected that: pod.kubernetes.io / portmap: disabled, external access is not allowed at this time, so it can be operated in a conventional manner without creating a network service instance 220.

[0051] According to an exemplary implementation manner of the present disclosure, in the process of creating a network service instance 220, the monitor program 330 can update 302 the content of the resource instance 210. For example, an initialization container can be injected into the resource instance 210, and the initialization container in the resource instance 210 can be started to instantiate the network service, and then a network service instance 220 is created. See Figure 4 Describe more details, the Figure 4FIG. 400 is a block diagram showing the injection of an initial container into resource instance 210 according to some implementations of the present disclosure.

[0052] As Figure 4 shown, in the case where the pod.kubernetes.io / portmap label is detected to be set to active, the monitor 330 may inject the initialization container 410 into the resource instance 210. The role of the initialization container 410 is to create the network service instance 220 defined in the manner of Table 1 above. It should be understood that the resource instance 210 itself may include one or more containers: for example, the main service container 420 for executing the main business logic. Alternatively and / or additionally, the resource instance 210 may include service containers for executing other business logics. At this time, the initialization container 410 will be inserted before each service container and will be called first during the startup process of the resource instance 210.

[0053] Further, the monitor 330 may inject various required environment variables into the main service container 420, and the monitor 330 may add annotations so that each service container can directly use the network service provided by Portmap. Alternatively and / or additionally, the monitor 330 may store the updated resource instance in the cluster's database 350. In this way, it is convenient for various requesters inside and / or outside the cluster to obtain the required information via the database 350, thereby improving the access efficiency.

[0054] Return Figure 3 , according to an example implementation of the present disclosure, the communication process after creation can be managed by the daemon 340. During the implementation of the daemon 340, the daemon 340 can be named Daemon, and corresponding code can be written to implement the daemon 340. Here, the daemon 340 can be implemented based on the Kubernetes controller technology and deployed in the cluster in the form of a Kubernetes DaemonSet. At this time, the daemon 340 can observe the status of the network service instance 220, perform Natport port allocation through the port configuration algorithm, and create network address table (e.g., IPTables) rules to implement the NAT mapping between the Pod container port and the Natport port.

[0055] According to an example implementation of the present disclosure, during the establishment of the network link, the daemon 340 can detect the port allocation status of the resource instance 210. Specifically, the changes in Portmap can be observed by means of List and / or Watch. Further, based on the port allocation algorithm, the port allocation and release logic can be implemented by updating the bitmap.

[0056] Further, if it is detected that the port allocation status indicates that a network port has been allocated to resource instance 210, the address table of the cluster can be set to create a network link associated with the network port and the network address. Specifically, after a port has been allocated to resource instance 210, the daemon 340 can establish the corresponding network link by modifying the network address table in the cluster. Iptables is a user-space command-line program used to configure a packet filtering rule set in Linux and will not be elaborated here.

[0057] It should be understood that multiple network links can be supported in the Kubernetes architecture. In the context of the present disclosure, the following three types of network links can be set to support cross-cluster communication: a prerouting (PREROUTING) link, an output (OUTPUT) link, and a postrouting (POSTROUTING) link.

[0058] In the following, how to modify the network address table and then start the above various links will be described in detail. According to an exemplary implementation manner of the present disclosure, the rules in this chain will be applied before routing the data packet for the prerouting link. External access to the Pod is achieved through the DNAT rule. For example, the prerouting link can be set based on the manner shown in Table 2.

[0059] Table 2 Link startup method

[0060]

[0061] According to an exemplary implementation manner of the present disclosure, when the firewall of the local machine sends out a data packet, the rules in the output link will be applied. At this time, the output link can achieve access to the local node where the Pod is located through the DNAT rule. For example, the output link can be set based on the manner shown in Table 3.

[0062] Table 3 Link startup method

[0063]

[0064] According to an exemplary implementation manner of the present disclosure, after routing the data packet, the rules in the postrouting link can be applied. At this time, the postrouting link can achieve access of the Pod to itself through the SNAT rule. For example, the output link can be set based on the manner shown in Table 4.

[0065] Table 4 Link setting method

[0066]

[0067] According to an example implementation of the present disclosure, after various operations related to network configuration have been completed, the initialization container can be exited. At this time, the rules in the corresponding link can be utilized to implement cross-cluster resource instance access. Specifically, after exiting the initialization container, the main service container in the resource instance 210 can be started. Further, communication can be performed between the main service container and a requester outside the cluster via a network link. Using the example implementation of the present disclosure, it is not necessary to rely on the dedicated functions of each cluster, but rather the IPTables configuration capabilities of the basic Kubernetes architecture of each cluster can be used to uniformly manage resource instance access between clusters established by different providers.

[0068] According to an example implementation of the present disclosure, the network status can be written into the configuration information of the resource instance so that the resource instance can obtain the network status through the configuration information. According to an example implementation of the present disclosure, the network status is written into the annotation of the resource instance so that a requester outside the resource instance can obtain the network status. Using the example implementation of the present disclosure, by storing redundant network status information at different locations in the cluster, it is convenient for different visitors to obtain the network status in the most convenient manner according to their own access capabilities, thereby realizing potential future cross-cluster access capabilities.

[0069] The details of each step for activating the cross-cluster access capability based on the network service instance 220 have been separately described above. In the following, refer to Figure 5 the overall process of activating the cross-cluster access capability, which Figure 5 shows a block diagram 500 for establishing a resource instance and starting to access the resource instance according to some implementation manners of the present disclosure. As Figure 5 shown, the client 310 can request 501 to create a resource instance and label the resource instance for which cross-cluster access is desired with the label: pod.kubernetes.io / portmap:enabled. It can be determined whether the label is activated, and if it is activated, the process continues. In the context of the present disclosure, the specific process of labeling the label is not limited. For example, the label can be manually set by an administrator at the client 310, or can be set by other management tools in the cluster called by the client 310.

[0070] Further, the API server 320 may request to update the resource instance where the update 502 was created. The monitor 330 may check whether the ServiceAccount of the resource instance has the permission to operate on the Portmap CRD. If not, it may update the PortmapClusterRoleBinding configuration to ensure that the Pod has the permission to operate on the Portmap CRD. Subsequently, the monitor 330 may inject an initializer into the resource instance and add necessary environment variables, annotations, etc. to perform the initialization 503. According to an example implementation of the present disclosure, the updated resource instance may be stored in a database, and the updated resource instance may be returned 504.

[0071] Further, the resource instance may be started 505, that is, at this time the resource instance 210 enters the running phase. The initialization container may be started first to request the creation 506 of the network service instance 220. The daemon 340 may continuously observe 507 (e.g., in a list and / or watch manner) the port allocation status of the Natport of the resource instance 210. The daemon 340 may allocate 507’ the Natport port and add IPtables rules, and accordingly update 508 the information in the network service instance 220.

[0072] Specifically, the Natport information may be updated to the annotation of the resource instance 210 for external use of Natport. If it is found that the port allocation is successful, the initialization container may be exited 510, and the main business container in the resource instance 210 may be started 510’. At this time, a network link has been established through the resource instance 210, so the resource instance 210 may return 510 the result to the client 310. At this time, communication may be performed between the main business container of the resource instance 210 and a requester outside the cluster via the established network link.

[0073] According to an example implementation of the present disclosure, in the case of cross-cluster access requirements, the life cycle of the network service instance 220 follows that of the resource instance 210. Refer to Figure 5 the described created network service instance 220 will be automatically deleted as the resource instance 210 is destroyed. Specifically, if it is detected that the resource instance 210 is destroyed, it is necessary to remove the network service instance 220, release the allocated network ports, and delete the communication link.

[0074] The destruction process is the reverse process of the creation process. Refer to Figure 6 for more details. Figure 6 FIG. 600 shows a block diagram for destroying a resource instance according to some implementations of the present disclosure. As Figure 6As shown, the client 310 may request 601 to delete the created resource instance 210. At this time, the API server 320 receives 602 the request and notifies the resource instance 210 of the deletion process.

[0075] The daemon 340 may monitor 603 the deletion process and request 603’ the API server 320 to delete the network service instance 220. The API server 320 may perform 604 the deletion operation. At this time, the previously created network service instance 220 may be automatically deleted, and the associated configuration mapping may be cascaded deleted. The daemon 340 may monitor 605 the deletion operation of the network service instance 220. When the deletion operation is detected, the previously allocated port may be automatically released 605’ and the set IPTables rules may be cleared. At this time, the deletion process ends, and the daemon 340 may return 606 the result to the client 310.

[0076] Using the example implementation of the present disclosure, in the process of performing cross-cluster access using network service instances, the creation and deletion of network service instances only depend on various capabilities in the basic cluster architecture, rather than depending on the dedicated capabilities separately developed by the providers of each cluster outside the basic cluster architecture.

[0077] The cross-cluster access technical solution according to an example implementation of the present disclosure does not depend on the dedicated capabilities of any specific cluster, and thus has generality and is suitable for managing resource instance access under multiple clusters in a unified manner. Further, through an efficient port management algorithm, automatic allocation and release of ports can be achieved, thereby avoiding various overheads such as port management. In addition, the allocable range of ports can be flexibly configured, thereby providing sufficient network ports for cross-cluster access in the case of large-scale data access.

[0078] Example process

[0079] Figure 7 A flowchart of a method 700 for performing resource scheduling in a cluster according to some implementations of the present disclosure is shown. At block 710, a network service instance for managing a resource instance is created. At block 720, a network link for accessing the resource instance is established using the network address of the resource instance and the network port assigned to the resource instance. At block 730, the network state in the network service instance is updated based on the network link. At block 740, it is detected whether the network state indicates that the network link has been established. If the detection result is yes, the method 700 proceeds to block 750. At block 750, the resource instance is started to communicate with the started resource instance via the network link.

[0080] According to an example implementation of the present disclosure, creating a network service instance includes: creating a network service instance in response to detecting an access permission that allows a requester outside the cluster to access a resource instance.

[0081] According to an example implementation of the present disclosure, detecting the access permission includes: detecting a network service label of the resource instance; and determining that the access permission is detected in response to detecting that the network service label is set to active.

[0082] According to an example implementation of the present disclosure, creating a network service instance includes: using the customer resource definition function of the cluster to define a network service; injecting an initialization container into the resource instance; and starting the initialization container in the resource instance to instantiate the network service to create a network service instance.

[0083] According to an example implementation of the present disclosure, defining the network service includes: determining whether the resource instance allows the customer resource definition function based on the service account configuration of the resource instance; and defining the network service in response to determining that the resource instance allows the customer resource definition function.

[0084] According to an example implementation of the present disclosure, the method 700 further includes: updating the service account configuration to allow the customer resource definition function in response to determining that the resource instance does not allow the customer resource definition function.

[0085] According to an example implementation of the present disclosure, the method 700 further includes: injecting an environment variable configuration into the main business container of the resource instance; and storing the updated resource instance in the database of the cluster.

[0086] According to an example implementation of the present disclosure, starting the resource instance includes: exiting the initialization container; and starting the main business container in the resource instance.

[0087] According to an example implementation of the present disclosure, the method 700 further includes: communicating between the main business container and a requester outside the cluster via a network link.

[0088] According to an example implementation of the present disclosure, establishing the network link includes: detecting the port allocation status of the resource instance; and setting the address table of the cluster to create a network link associated with the network port and the network address in response to detecting that the port allocation status indicates that a network port has been allocated to the resource instance.

[0089] According to an example implementation of the present disclosure, the method 700 further includes at least any one of the following: writing the network status into the configuration information of the resource instance so that the resource instance can obtain the network status through the configuration information; writing the network status into the annotation of the resource instance so that a requester outside the resource instance can obtain the network status.

[0090] According to an example implementation of the present disclosure, it further includes: removing the network service instance in response to detecting that the resource instance is destroyed; releasing the network port; and deleting the communication link.

[0091] According to an example implementation of the present disclosure, the network link includes at least any one of the following: a pre-routing link, an output link, and a post-routing link.

[0092] According to an example implementation of the present disclosure, the cluster is implemented based on the Kubernetes architecture, and the resource instance is an instance of the Pod resource in the cluster.

[0093] Example device and equipment

[0094] Figure 8 A block diagram of an apparatus 800 for performing resource scheduling in a cluster according to some implementations of the present disclosure is shown. As Figure 8 shown, the apparatus 800 includes: a creation module 810 configured to create a network service instance for managing a network service of a resource instance; an establishment module 820 configured to establish a network link for accessing the resource instance by using the network address of the resource instance and the network port assigned to the resource instance; an update module 830 configured to update the network state in the network service instance based on the network link; and a start module 840 configured to start the resource instance to communicate with the started resource instance via the network link in response to detecting that the network state indicates that the network link has been established.

[0095] According to an example implementation of the present disclosure, the creation module 810 includes: a detection module configured to detect whether there is an access permission that allows a requester outside the cluster to access the resource instance; and a creation module based on the detection configured to create a network service instance in response to detecting the access permission that allows a requester outside the cluster to access the resource instance.

[0096] According to an example implementation of the present disclosure, the detection module includes: a label detection module configured to detect the network service label of the resource instance; and a detection module based on the label configured to determine that the access permission is detected in response to detecting that the network service label is set to active.

[0097] According to an example implementation of the present disclosure, the creation module 810 includes: a definition module configured to define a network service by using the customer resource definition function of the cluster; an injection module configured to inject an initialization container into the resource instance; and an instantiation module configured to start the initialization container in the resource instance to instantiate the network service to create a network service instance.

[0098] According to an exemplary implementation of the present disclosure, the definition module includes: a function determination module configured to determine whether a resource instance allows a customer resource definition function based on the service account configuration of the resource instance; and a function-based module configured to define a network service in response to determining that the resource instance allows the customer resource definition function.

[0099] According to an exemplary implementation of the present disclosure, the apparatus 800 further includes: an update module configured to update the service account configuration to allow the customer resource definition function in response to determining that the resource instance does not allow the customer resource definition function.

[0100] According to an exemplary implementation of the present disclosure, the apparatus 800 further includes: an environment variable injection module configured to inject an environment variable configuration into the main service container of the resource instance; and a storage module configured to store the updated resource instance in the database of the cluster.

[0101] According to an exemplary implementation of the present disclosure, the start module includes: an initialization exit module configured to exit the initialization container; and a main service start module configured to start the main service container in the resource instance.

[0102] According to an exemplary implementation of the present disclosure, the apparatus 800 further includes: a communication module configured to communicate between the main service container and a requester outside the cluster via a network link.

[0103] According to an exemplary implementation of the present disclosure, the establishment module includes: a port status detection module configured to detect the port allocation status of the resource instance; and a setting module configured to set the address table of the cluster to create a network link associated with the network port and the network address in response to detecting that the port allocation status indicates that a network port has been allocated to the resource instance.

[0104] According to an exemplary implementation of the present disclosure, the apparatus 800 further includes at least any one of the following: a first writing module configured to write the network status into the configuration information of the resource instance so that the resource instance can obtain the network status through the configuration information; and a second writing module configured to write the network status into the annotation of the resource instance so that a requester outside the resource instance can obtain the network status.

[0105] According to an exemplary implementation of the present disclosure, the apparatus 800 further includes: a removal module configured to remove the network service instance in response to detecting that the resource instance is destroyed; a release module configured to release the network port; and a deletion module configured to delete the communication link.

[0106] According to an example implementation of the present disclosure, a network link includes at least any one of the following: a pre-routed link, an output link, and a post-routed link.

[0107] According to an example implementation of the present disclosure, a cluster is implemented based on the Kubernetes architecture, and a resource instance is an instance of a Pod resource in the cluster.

[0108] Figure 9 A block diagram of a device 900 capable of implementing multiple implementations of the present disclosure is shown. It should be understood that Figure 9 The illustrated computing device 900 is merely exemplary and should not constitute any limitation on the functions and scope of the implementations described herein. Figure 9 The illustrated computing device 900 can be used to implement the methods described above.

[0109] As Figure 9 shown, the computing device 900 is in the form of a general-purpose computing device. The components of the computing device 900 may include, but are not limited to, one or more processors or processing units 910, a memory 920, a storage device 930, one or more communication units 940, one or more input devices 950, and one or more output devices 960. The processing unit 910 can be an actual or virtual processor and is capable of performing various processes according to the programs stored in the memory 920. In a multi-processor system, multiple processing units execute computer-executable instructions in parallel to improve the parallel processing ability of the computing device 900.

[0110] The computing device 900 generally includes multiple computer storage media. Such media can be any accessible media available to the computing device 900, including but not limited to volatile and non-volatile media, removable and non-removable media. The memory 920 can be volatile memory (such as registers, caches, random access memory (RAM)), non-volatile memory (such as read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory), or some combination thereof. The storage device 930 can be removable or non-removable media and can include machine-readable media, such as a flash drive, a magnetic disk, or any other media that can be used to store information and / or data (such as training data for training) and can be accessed within the computing device 900.

[0111] The computing device 900 may further include additional removable / non-removable, volatile / non-volatile storage media. Although not shown in Figure 9As shown, a disk drive for reading from and writing to a removable, non-volatile disk (such as a "floppy disk") and an optical disk drive for reading from and writing to a removable, non-volatile optical disk can be provided. In these cases, each drive can be connected to a bus (not shown) by one or more data medium interfaces. Memory 920 can include a computer program product 925 having one or more program modules configured to execute the various methods or actions of the various implementations of the present disclosure.

[0112] Communication unit 940 enables communication with other computing devices via a communication medium. Additionally, the functionality of the components of computing device 900 can be implemented in a single computing cluster or multiple computer machines that are capable of communicating via a communication connection. Thus, computing device 900 can operate in a networked environment using a logical connection to one or more other servers, network personal computers (PCs), or another network node.

[0113] Input device 950 can be one or more input devices such as a mouse, keyboard, trackball, etc. Output device 960 can be one or more output devices such as a display, speaker, printer, etc. Computing device 900 can also communicate with one or more external devices (not shown) as needed via communication unit 940, external devices such as storage devices, display devices, etc., communicate with one or more devices that enable a user to interact with computing device 900, or communicate with any device that enables computing device 900 to communicate with one or more other computing devices (e.g., a network card, modem, etc.). Such communication can be performed via an input / output (I / O) interface (not shown).

[0114] According to an exemplary implementation of the present disclosure, a computer-readable storage medium is provided, on which computer-executable instructions are stored, where the computer-executable instructions are executed by a processor to implement the method described above. According to an exemplary implementation of the present disclosure, a computer program product is also provided, the computer program product being tangibly stored on a non-transitory computer-readable medium and including computer-executable instructions, and the computer-executable instructions being executed by a processor to implement the method described above. According to an exemplary implementation of the present disclosure, a computer program product is provided, on which a computer program is stored, and the program, when executed by a processor, implements the method described above.

[0115] Aspects of the present disclosure are described herein with reference to the flowcharts and / or block diagrams of methods, apparatuses, devices, and computer program products according to the present disclosure. It should be understood that each block of the flowcharts and / or block diagrams, and the combinations of blocks in the flowcharts and / or block diagrams, can be implemented by computer-readable program instructions.

[0116] These computer-readable program instructions can be provided to a processing unit of a general-purpose computer, a special-purpose computer, or other programmable data processing apparatus to produce a machine such that the instructions, when executed by the processing unit of the computer or other programmable data processing apparatus, create means for implementing the functions / acts specified in one or more boxes of the flowchart and / or block diagram. These computer-readable program instructions can also be stored in a computer-readable storage medium that causes a computer, a programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer-readable medium storing the instructions comprises a manufacture including instructions that implement various aspects of the functions / acts specified in one or more boxes of the flowchart and / or block diagram.

[0117] The computer-readable program instructions may be loaded onto a computer, other programmable data processing apparatus, or other devices to cause a series of operational steps to be performed on the computer, other programmable data processing apparatus, or other devices to produce a computer-implemented process such that the instructions executed on the computer, other programmable data processing apparatus, or other devices implement the functions / acts specified in one or more boxes of the flowchart and / or block diagram.

[0118] The flowcharts and block diagrams in the figures illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various implementations of the present disclosure. In this regard, each box in the flowchart or block diagram may represent a module, a segment of code, or a portion of an instruction, and the module, segment of code, or portion of an instruction may include one or more executable instructions for implementing the specified logical function. In some alternative implementations, the functions noted in the boxes may occur out of the order noted in the figures. For example, two consecutive boxes may in fact be executed substantially in parallel, or they may sometimes be executed in the reverse order, depending on the functions involved. It should also be noted that each box in the block diagrams and / or flowcharts, and combinations of boxes in the block diagrams and / or flowcharts, can be implemented by special-purpose hardware-based systems that perform the specified functions or acts, or by combinations of special-purpose hardware and computer instructions.

[0119] The implementations of the present disclosure have been described above. The description is exemplary, not exhaustive, and is not limited to the disclosed implementations. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the described implementations. The choice of terms used herein is intended to best explain the principles of the implementations, the practical application, or improvements made to the technology in the marketplace, or to enable other ordinary skilled persons in the art to understand the various implementations disclosed herein.

Claims

1. A method for performing resource scheduling in a cluster, comprising: For a resource instance in the cluster, in response to detecting an access permission that allows a requester outside the cluster to access the resource instance, creating a network service instance for managing the network service of the resource instance; Using the network address of the resource instance and the network port assigned to the resource instance, establishing a network link for accessing the resource instance; Updating the network state in the network service instance based on the network link; And In response to detecting that the network state indicates that the network link has been established, starting the resource instance so as to communicate with the started resource instance via the network link; Wherein, creating the network service instance includes: Using the customer resource definition function of the cluster to define the network service; Injecting an initialization container into the resource instance; and Starting the initialization container in the resource instance to instantiate the network service to create the network service instance.

2. The method according to claim 1, wherein detecting the access permission includes: Detecting the network service label of the resource instance; And In response to detecting that the network service label is set to active, determining that the access permission is detected.

3. The method according to claim 1, wherein defining the network service includes: Based on the service account configuration of the resource instance, determining whether the resource instance allows the customer resource definition function; And In response to determining that the resource instance allows the customer resource definition function, defining the network service.

4. The method according to claim 3, further comprising: In response to determining that the resource instance does not allow the customer resource definition function, updating the service account configuration to allow the customer resource definition function.

5. The method according to claim 1, further comprising: Injecting an environment variable configuration into the main business container of the resource instance; And Storing the updated resource instance in the database of the cluster.

6. The method according to claim 5, wherein starting the resource instance includes: Exiting the initialization container; And Starting the main business container in the resource instance.

7. The method according to claim 6, further comprising: Communicating between the main business container and a requester outside the cluster via the network link.

8. The method according to claim 1, wherein establishing the network link includes: Detecting the port allocation status of the resource instance; And In response to detecting that the port allocation status indicates that the network port has been allocated to the resource instance, setting the address table of the cluster to create the network link associated with the network port and the network address.

9. The method according to claim 1, further comprising at least any one of the following: Writing the network state into the configuration information of the resource instance so that the resource instance can obtain the network state through the configuration information; Writing the network state into the annotation of the resource instance so that a requester outside the resource instance can obtain the network state.

10. The method according to claim 1, further comprising: In response to detecting that the resource instance is destroyed, Removing the network service instance; Releasing the network port; Delete the network link.

11. The method according to claim 1, wherein the network link includes at least any one of the following: a pre-routing link, an output link, and a post-routing link.

12. The method according to claim 1, wherein the cluster is implemented based on the Kubernetes architecture, and the resource instance is an instance of a Pod resource in the cluster.

13. An apparatus for performing resource scheduling in a cluster, comprising: a creation module configured to, for a resource instance in the cluster, in response to detecting an access permission that allows a requester outside the cluster to access the resource instance, create a network service instance for managing a network service of the resource instance; a establishment module configured to establish a network link for accessing the resource instance by using a network address of the resource instance and a network port assigned to the resource instance; an update module configured to update a network state in the network service instance based on the network link; and a start module configured to, in response to detecting that the network state indicates that the network link has been established, start the resource instance so as to communicate with the started resource instance via the network link; wherein the creation module is configured to define the network service by using a customer resource definition function of the cluster; inject an initialization container into the resource instance; and start the initialization container in the resource instance to instantiate the network service to create the network service instance.

14. An electronic device, comprising: at least one processing unit; and at least one memory coupled to the at least one processing unit and storing instructions for execution by the at least one processing unit, the instructions, when executed by the at least one processing unit, causing the electronic device to perform the method according to any one of claims 1 to 12.

15. A computer-readable storage medium having stored thereon a computer program, which when executed by a processor causes the processor to implement the method according to any one of claims 1 to 12.

Citation Information

Patent Citations

  • PaaS service data processing method and device, equipment and storage medium

    CN112243036A

  • Cross-cluster data request processing method and device and storage medium

    CN113746887A