Access methods, storage nodes, and data centers

By deploying a symmetric gateway in the data center, the problem that storage nodes cannot actively access the compute nodes is solved, the function of multi-tenant sharing of storage node file directories is realized, and private client deployment is supported, improving the flexibility and efficiency of the data center.

CN118713852BActive Publication Date: 2025-05-02HUAWEI TECH CO LTD
View PDF 2 Cites 0 Cited by

Patent Information

Application Number
CN202410591406.5
Authority / Receiving Office
CN · China
Patent Type
Patents(China)
Current Assignee / Owner
Priority Date
2023-03-27
Filing Date
2023-06-21
Publication Date
2025-05-02
Estimated Expiration
2043-06-21

AI Technical Summary

Technical Problem

In the prior art, asymmetric gateways cannot support storage nodes to actively access computing nodes, resulting in multi-tenants being unable to share the same file directory in storage nodes and being unable to deploy private clients to access files in storage nodes.

Method used

By deploying a symmetric gateway in the data center, the storage node allows actively establishing connections with the virtual instance of the computing node and interacting through the virtual network, providing target information of files in the storage node, such as lock release information or metadata for access by the virtual instance.

Benefits of technology

It realizes shared access to the same file directory in the storage node by multiple tenants, supports private clients to deploy on compute nodes, and improves the flexibility and efficiency of the data center.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN118713852B_ABST
    Figure CN118713852B_ABST
Patent Text Reader

Abstract

Provided are an access method, a storage node, and a data center, and relate to the field of IT technology. The method comprises: a storage node can actively establish a connection with a virtual instance running in a computing node, and actively synchronize target information for accessing a target file to the virtual instance under the connection, so that the computing node can use the target information to access data from the storage node, and the storage node can support multi-tenants of the computing node to perform shared locked access to target files in the same file directory, and can support the deployment of private clients on the computing nodes.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] This application is a divisional application. The application number of the original application is 202310748431.5, and the original application date is June 21, 2023. The entire contents of the original application are incorporated into this application by reference. Technical Field

[0002] The embodiments of the present application relate to the field of IT technology, and in particular to an access method, a storage node, and a data center. Background Art

[0003] At present, with the development of Internet services, distributed computing and other technologies, data centers may include computing nodes and storage nodes, where computing nodes can run applications and storage nodes can store data. Computing nodes and storage nodes can interact through gateways in the network to support tenants of computing nodes to access data stored in storage nodes.

[0004] The gateway deployed in the network in the related art is an asymmetric gateway, which can support the distribution of requests from computing nodes to storage nodes so as to forward the requests to the storage nodes for data access.

[0005] However, the asymmetric gateway does not support the distribution of computing nodes to requests from storage nodes, which results in the problem that storage nodes cannot actively access computing nodes. Summary of the invention

[0006] The present application provides an access method, a storage node, and a data center. In this method, in order to realize shared access of multiple tenants of a computing node to the same file in a storage node and ensure the consistency of the file, the virtual instance of the tenant running in the computing node can access the file in the storage node only when the target information of the file (such as lock release information) is obtained. The storage node can actively notify the virtual instance of the target information of the file when the lock of the file is released, so that the virtual instance can access the file in the storage node. Thus, the storage node actively accesses the virtual instance, and shared access of multiple tenants to files in the storage node is realized.

[0007] In addition, in order to deploy a private client (virtual instance) in a computing node to access a file in a storage node, the storage node can synchronize the target information (such as metadata) of the file to the private client before the private client accesses the file, so that the private client can access the file in the storage node. Thus, the virtual instance in the computing node is deployed as a private client by actively accessing the virtual instance through the storage node.

[0008] In one possible implementation, the present application provides an access method. A data center includes multiple computing nodes and storage nodes, a first virtual instance is running in the multiple computing nodes, and the multiple computing nodes interact with the storage nodes through a virtual network. The method includes: the storage node pre-stores the target file, or the storage node receives and stores the target files from the multiple computing nodes; the storage node actively requests to establish a first connection with the first virtual instance; the storage node sends a first message to the first virtual instance through the first connection, and the first message is used to provide target information for accessing the target file; in response to receiving a second message sent by the first virtual instance based on the first message, the storage node accesses the target file.

[0009] Among them, the virtual instance of the present application can be a virtual machine or a container. The implementation scheme of the virtual instance can be flexibly adopted according to the needs, and there is no limitation here.

[0010] The virtual network is different from the physical network. It is a virtual network superimposed on the physical network. There are many types of virtual networks, among which the overlay network is a virtual network. In some embodiments, the virtual network in which the computing nodes and storage nodes interact in the data center can be implemented as a VPC network, wherein the VPC network is an overlay network.

[0011] The first virtual instance may be a virtual instance running on one computing node, or may be a virtual instance running on at least two computing nodes respectively, which is not limited here.

[0012] The storage node can support pre-storage of some files (such as pictures, documents, etc., without specific limitation). In addition, the storage node can also support receiving and storing files from multiple computing nodes.

[0013] Then the target file to be accessed by the first virtual instance may be a file pre-stored in the storage node, or may be a file written into the storage node by one of the multiple computing nodes, or at least two computing nodes.

[0014] In addition, the first virtual instance to access the target file may be the same as or different from the virtual instance (represented as the third virtual instance) in the plurality of computing nodes that writes the target file to the storage node; and the first virtual instance and the third virtual instance may be virtual instances of the same tenant or virtual instances of different tenants. In other words, the method of the present application may be applied to the scenario of shared access to the same target file by the same tenant, or to the scenario of shared access to the same target file by at least two tenants.

[0015] It should be understood that whether or not the storage node supports pre-storage of files does not affect the method of the present application of providing the target information of the target files from multiple computing nodes stored in the storage node to the first virtual instance in the multiple computing nodes, so that multiple virtual instances can share access to the same target file in the storage node.

[0016] In the embodiment of the present application, the application scenarios in which the storage node actively accesses the computing node may include scenario 1 and scenario 2.

[0017] In scenario 1, both the storage node and the computing node use the NFS standard protocol (such as NFS V3 protocol) to access data. When the computing node accesses the target file stored on the storage node, it uses a locking method to access the file.

[0018] In scenario 2, both the storage node and the computing node use private protocols for data access. For example, the first virtual instance is a client of the private protocol (referred to as the private client). Then, when the computing node accesses the target file stored on the storage node, it can use the metadata of the target file to access the file.

[0019] Regarding scenario 1, in the related art, the file directories accessed by multiple tenants of multiple computing nodes in the storage node are independent and different from each other. In order for multiple tenants to share access to the same file directory in the storage node, the storage node needs to actively send information to the computing node indicating the lock release of the target file requested to be accessed by the computing node. However, because the storage node in the related art cannot actively access the computing node, the storage node cannot actively send the lock release information to the virtual instance that needs to access the target file. As a result, the data center of the related art does not support multiple tenants sharing the same file directory in the storage node, and thus does not support multiple tenants to share and lock files in the same file directory in the storage node.

[0020] Applied to scenario 1, in an embodiment of the present application, a storage node can actively establish a first connection with a first virtual instance in a plurality of computing nodes, and the storage node can reuse the first connection to send a message that can provide target information for accessing a target file to the first virtual instance, so that the storage node in the virtual network can actively access the computing node and send a first message to the first virtual instance in the computing node to provide the target information required for the first virtual instance to access the target file to the first virtual instance. The storage node actively provides the target information (such as the lock release information) to the first virtual instance to access the target file, so that the first virtual instance can access the target file from the storage node based on the target information. In this way, the data center can support multiple tenants sharing the same file directory in the storage node. When the access lock of the target file requested to be accessed by the first virtual instance has been released, the storage node can actively send the lock release information to the first virtual instance, enabling multiple tenants to share and lock the target files in the same file directory in the storage node.

[0021] Regarding scenario 2, because the storage node in the related art cannot actively access the computing node, the storage node cannot synchronize the file metadata to the computing node, and the private client accesses the file in the storage node through the file metadata. Therefore, the data center in the related art does not support deploying virtual instances of private protocols (also called private clients) in multiple computing nodes to access files in the storage node.

[0022] Applied to scenario 2, in an embodiment of the present application, a storage node can actively establish a first connection with a first virtual instance in a plurality of computing nodes, and the storage node can reuse the first connection to send a message that can provide target information for accessing a target file to the first virtual instance, so that the storage node in the virtual network can actively access the computing node and send a first message to the first virtual instance in the computing node to provide the target information required for the first virtual instance to access the target file to the first virtual instance. The storage node actively provides the target information (e.g., the metadata of the target file) to the first virtual instance to be accessed, so that the first virtual instance can access the target file from the storage node based on the target information. In this way, the data center can support the deployment of private clients in multiple computing nodes, and the storage node can actively synchronize the metadata of the target file stored by the private client to the private client, so that the private client can use the metadata synchronized by the storage node to access the target file stored in the storage node. However, in the data center in the related art, the computing node cannot deploy a private client because the storage node cannot synchronize metadata with the computing node.

[0023] In addition, when the above-mentioned first virtual instance sends the second message to the storage node based on the first message, the connection used may be a connection between the first virtual instance and the storage node actively established, which is a long connection used to access the target file. This connection is different from the above-mentioned first connection, which may be a short connection.

[0024] In a possible implementation, the target information is used to indicate that the access lock to the target file has been released; or, the target information is used to provide metadata of the target file, wherein different files have different metadata.

[0025] In the embodiments of the present application, application scenarios in which a storage node actively accesses a computing node may include the above-mentioned scenario 1 and the above-mentioned scenario 2.

[0026] In scenario 1, both the storage node and the computing node use the NFS standard protocol (such as NFS V3 protocol) to access data. When the computing node accesses the target file stored on the storage node, it uses a locking method to access the file.

[0027] In scenario 1, in the related art, due to the limitation that the gateway in the data center is an asymmetric gateway, in a multi-tenant scenario, although there is a need for shared locking of the same file (or files in the same directory) in the storage node by multiple tenants. However, the storage node in the related art cannot actively establish a connection with the computing node, nor can it actively send a message to the virtual instance in the computing node indicating that the file lock has been released. As a result, the related art does not support the scenario where multiple tenants share and lock the same file, making the file directories of each tenant independent of each other, and does not support shared access by multiple tenants to files in the same file directory.

[0028] In scenario 1, in an embodiment of the present application, in a scenario where there are multiple tenants of multiple computing nodes, the storage node interacts with the computing node through a virtual network. In this scenario, there may be a need for multiple tenants (which may be different virtual instances of the same enterprise or virtual instances of different enterprises) to share access to the same target file. In order to achieve shared access to the same file by multiple tenants, after the lock of the target file requested to be locked by the first virtual instance is released by other virtual instances, indicating that the target file has been accessed by other virtual instances, the storage node can actively establish a connection with the first virtual instance to notify the first virtual instance of the target information (such as lock release information) indicating that the access lock to the target file has been released through the first connection, thereby enabling multiple tenants to share locked access to the same file in the storage node. The storage node supports a shared file directory, and the target files in the shared file directory can support shared access by multiple tenants.

[0029] In scenario 2, both the storage node and the computing node use private protocols for data access. For example, the first virtual instance is a private client. When the computing node accesses a target file stored on the storage node, it can use the metadata of the target file to access the file.

[0030] In scenario 2, in the related art, due to the limitation that the gateway used for data exchange between the storage node and the computing node is an asymmetric gateway, the storage node cannot actively establish a connection with the computing node, and cannot push the metadata of the file stored by the storage node to the computing node through the connection. Therefore, the data center in the related art does not support the deployment of private clients on the computing nodes.

[0031] In scenario 2, in an embodiment of the present application, a private client (e.g., a first virtual instance) may be deployed in a computing node. In order to enable the private client to access files on a storage node, the storage node of the present application may actively establish a first connection with the first virtual instance in the computing node, and synchronize the metadata of the target file stored in the storage node to the first virtual instance (here, the private client) through the first connection. In this way, the private client deployed in the computing node may use the metadata synchronized by the storage node to access the target file stored in the storage node. Then, in the case where the metadata of the target file is updated, the storage node may actively synchronize the updated metadata to the private client, so that the private client may use the timely updated metadata to accurately access the target file in the storage node. Moreover, the target file may also be a file written by other private clients, thereby enabling multiple private clients to achieve the effect of shared access to the target file in the shared directory in the storage node.

[0032] In a possible implementation, the method further includes: the storage node receiving a third message from the first virtual instance through the second connection; and the storage node actively requesting to establish a first connection with the first virtual instance based on the third message.

[0033] The second connection is a connection between the storage node and the first virtual instance, and the second connection is different from the first connection.

[0034] In the above scenario 1, the second connection may be a connection actively established by the storage node with the first virtual instance.

[0035] In the above scenario 2, the second connection may be a connection actively established by the first virtual instance with the storage node.

[0036] In an embodiment of the present application, in order to actively establish a first connection with the first virtual instance for pushing target information to the first virtual instance, the storage node needs to receive a third message from the first virtual instance, which may be a message of a preset type, and use the third message to obtain address information about the first virtual instance required for establishing the first connection, so as to establish the first connection with the first virtual instance, thereby ensuring that the address of the destination end (e.g., the first virtual instance) used to establish the first connection can be used to receive the target information.

[0037] For example, the storage node may use the third message to obtain the IP address of the first virtual instance. Optionally, the port number of the first virtual instance used to establish the first connection may be extracted from the message content of the third message, thereby establishing the first connection between the storage node and the first virtual instance.

[0038] For example, in scenario 1, the third message may be a message for providing a port number, which is a port number for receiving information that the access lock of the target file has been released. In this way, the storage node can extract the IP address of the first virtual instance and the port number of the first virtual instance used to establish a first connection from the third message from the first virtual instance, so that the storage node can establish a first connection with the corresponding port of the first virtual instance to send the information that the access lock of the target file has been released to the corresponding port of the first virtual instance.

[0039] In scenario 2, the third message may be a message requesting synchronization of metadata information, so that the storage node can extract the IP address of the first virtual instance from the third message from the first virtual instance, and actively establish a first connection with the first virtual instance requesting synchronization of metadata information, so as to synchronize the metadata to the first virtual instance.

[0040] In this embodiment, when the storage node actively establishes the first connection with the first virtual instance, it can use the message received from the previous connection that has been established between the storage node and the first virtual instance to actively establish the next connection (here is the first connection) with the first virtual instance. This can ensure that the storage node can obtain the information (such as address information) of the destination end (such as the first virtual instance) required to establish the first connection in advance through the received message before establishing the first connection, and the first connection established using the information obtained in advance can be used to transmit the target information, thereby avoiding the problem that the actively established connection cannot transmit the target information.

[0041] In a possible implementation, the multiple computing nodes run first virtual instances of multiple tenants, the multiple computing nodes running first virtual instances of different tenants run in different virtual networks, and the target information is used to indicate that the access lock to the target file has been released.

[0042] In the above scenario 1, there are multiple tenants of multiple computing nodes, and the computing nodes of different tenants run in different virtual networks. Taking the virtual network as a VPC network as an example, the computing nodes running the virtual instances of tenant A run in VPC network 1, and the computing nodes running the virtual instances of tenant B run in VPC network 2.

[0043] In an embodiment of the present application, different virtual instances of the same tenant can share access to the target file stored in the storage node, and virtual instances of different tenants can also share access to the target file. Then, after the access lock of the target file being shared has been released, the storage node can use the first connection actively established with the first virtual instance to notify the first virtual instance of the information that the access lock has been released, so as to realize shared access to the same target file by different virtual instances in a multi-tenant scenario.

[0044] In a possible implementation, the method further includes: the storage node receiving a fourth message from the first virtual instance through a third connection, wherein the fourth message is used to provide information requesting an access lock on the target file; the storage node determining, in response to the fourth message, that the access lock on the target file is occupied by a second virtual instance running in the multiple computing nodes; wherein the first connection is a connection between the storage node and the first virtual instance that is actively requested to be established when the storage node determines that the access lock on the target file is released.

[0045] This embodiment can be applied to the above scenario 1:

[0046] In a multi-tenant scenario, the third connection may be a connection actively established by the first virtual instance with the storage node.

[0047] In order to access the target file, the first virtual instance may first send a lock request (an example of the fourth message) for the target file to the storage node through the third connection. When the storage node detects that the target file requested to be locked by the first virtual instance is being locked and accessed by the second virtual instance, it needs to wait for the lock of the target file to be released before allowing the first virtual instance to access the target file. The second virtual instance and the first virtual instance may be different virtual instances of the same tenant (e.g., tenant A), or virtual instances of different tenants (e.g., tenant A and tenant B mentioned above).

[0048] Then, when the storage node detects that the lock of the target file requested to be locked by the first virtual instance has been released, it can actively establish a first connection with the first virtual instance, and notify the first virtual instance of the information indicating that the access lock to the target file has been released through the first connection. In the related art, due to the limitation that the gateway between the multiple computing nodes and the storage node is an asymmetric gateway, the storage node cannot actively establish a connection with the first virtual instance when it detects that the lock of the target file requested to be locked by the first virtual instance has been released, and it is even more impossible to notify the first virtual instance of the information indicating that the access lock to the target file has been released through the gateway. The technical solution of the embodiment of the present application can be in the scenario of multi-tenant shared access to files in the storage node. The storage node can promptly notify the corresponding first virtual instance of the information that the access lock of the target file requested to be accessed by the first virtual instance through the first connection actively established with the first virtual instance, so as to speed up the access efficiency of multi-tenants to shared files.

[0049] In a possible implementation, the method further includes: when the storage node determines that the access lock of the target file is released, the storage node actively requests to establish the second connection with the first virtual instance based on the fourth message; the storage node sends a fifth message to the first virtual instance through the second connection, wherein the fifth message is used to query the port number for notifying the target information; and the third message is used to provide the port number of the first virtual instance.

[0050] This embodiment can be applied to the above scenario 1:

[0051] In a multi-tenant scenario, when the storage node detects that the access lock of the target file requested to be locked by the first virtual instance has been released, before notifying the first virtual instance that the access lock of the target file has been released, the storage node can obtain from the first virtual instance the port number of the port of the first virtual instance for receiving information that the access lock has been released, so that the storage node can use the port number to establish a first connection with the first virtual instance, which can be used to send control information such as information indicating that the access lock of the target file has been released, thereby avoiding the situation where the established first connection cannot be used to send the target information.

[0052] In order to obtain the above port number from the first virtual instance, the storage node can use the fourth message (a message of a preset type, such as a lock request for a target file) received from the first virtual instance in the previous connection (here the third connection) established with the first virtual instance to actively establish the next connection (here the second connection) with the first virtual instance. This ensures that the information (such as address information) of the destination (such as the first virtual instance) required to establish the second connection can be obtained in advance, and the second connection established using the information obtained in advance can be used to transmit the port number of the first virtual instance for notifying the target information, ensuring that the port number can be reliably obtained by the storage node.

[0053] In one possible implementation, the multiple computing nodes interact with the storage node through a gateway in the virtual network, and the method further includes: the storage node sends first session information to the gateway; the storage node sends a request to establish the first connection to the gateway; and the gateway forwards the request to establish the first connection to the first virtual instance based on the first session information.

[0054] In combination with any of the above implementations, multiple computing nodes and storage nodes may interact with each other via a gateway within a virtual network.

[0055] For example, the virtual network is a VPC network, and the gateway is a VPC gateway.

[0056] Since the VPC gateway in the related art is an asymmetric gateway, it does not have a strategy for distributing the storage node's request to a specific computing node. Therefore, in the related art, after the storage node sends a connection establishment request to the computing node through the VPC gateway, the VPC gateway does not have a computing node allocation strategy and is unable to forward the establishment request to the computing node, so that it does not support the storage node to establish a reverse connection with the computing node and actively send messages to the computing node.

[0057] Then in the embodiment of the present application, in order to enable the storage node to actively establish a connection (here, the first connection) with the first virtual instance in the computing node in the scenario where the storage node and the computing node interact through the gateway in the virtual network, and send a message on the connection. When the storage node actively establishes the first connection with the first virtual instance, the storage node can not only send the establishment request of the first connection to the VPC gateway, but also send the first session information to the VPC gateway. The VPC gateway can determine the virtual address of the virtual instance to which the establishment request of the first connection from the storage node needs to be distributed based on the first session information, so as to forward the establishment request of the first connection to the first virtual instance according to the virtual address, so as to realize the establishment of the reverse connection from the storage node to the computing node. In this way, although the VPC gateway itself does not have the allocation strategy of the computing node of the reverse connection, when establishing the reverse first connection, the storage node can synchronize the session information related to the first connection to be established to the VPC gateway, so that the VPC gateway can use the session information as the address mapping between the two ends of the first connection to realize the forwarding of the establishment request of the first connection of the storage node (and the above-mentioned first message), so that the corresponding message can be forwarded to the destination end of the first connection.

[0058] Exemplarily, the first session information may include a mapping relationship between a physical address (or virtual address) of a source end (here, a storage node) of the first connection and a virtual address of a destination end (here, a first virtual instance) of the first connection.

[0059] Exemplarily, as described in the above embodiment, when actively establishing the first connection, the storage node may actively establish the first connection based on the message received from the previously established connection between the first virtual instance (here is the third message, such as a message notifying the port number), then the above first session information may be the session information generated using the message received from the previous connection.

[0060] In addition, this embodiment takes the storage node actively establishing a first connection with the first virtual instance as an example to illustrate the specific implementation process of the storage node actively establishing a connection. In other embodiments, when the storage node actively establishes the above-mentioned second connection with the first virtual instance, the implementation principle is similar and will not be repeated here.

[0061] In a possible implementation, the plurality of computing nodes interact with the storage node in the virtual network via a remote direct memory access (RDMA) protocol.

[0062] For example, the virtual network is a VPC network, and the gateway in the above virtual network is a VPC gateway.

[0063] Since the VPC gateway in the related art is an asymmetric gateway, it does not have a strategy for distributing the storage node's request to a specific computing node. Therefore, in the related art, after the storage node sends a connection establishment request to the computing node through the VPC gateway, the VPC gateway does not have a computing node allocation strategy and is unable to forward the establishment request to the computing node, so that it does not support the storage node to establish a reverse connection with the computing node.

[0064] Then, in an embodiment of the present application, in order to enable the storage node to actively establish a connection with the computing node and send messages in a virtual network deployed with an asymmetric gateway, in this embodiment, the storage node can interact with the computing node through the RDMA protocol when interacting with the computing node through the virtual network. In this way, the storage node and the computing node can interact in a direct manner without going through the asymmetric gateway (such as the VPC gateway).

[0065] In the direct-through mode, the storage node and multiple computing nodes all support the RDMA protocol, so that the address information of both parties is transparent to each other. In other words, the storage node and the first virtual instance can each determine the destination address of their message without the need for the gateway to distribute the destination of their message. In this solution, the interaction between the storage node and the computing node does not need to go through the VPC gateway. The interaction is carried out through the RDMA protocol, which can bypass the VPC gateway, so that the storage node in the virtual network can actively establish a connection with the computing node and actively send messages to support multi-tenants to share and lock the same file directory in the storage node, as well as deploy private clients in the computing node.

[0066] In a possible implementation, the multiple computing nodes run first virtual instances of multiple tenants, and the multiple computing nodes running first virtual instances of different tenants run in different virtual networks. The method also includes: the storage node determines the original IP address of the first virtual instance based on the third message; the storage node determines a global IP address corresponding to the original IP address, wherein the global IP address is used to identify the first virtual instance running in the virtual network; the storage node actively requests to establish a first connection with the first virtual instance based on the mapping relationship between the original IP address and the global IP address.

[0067] Taking the virtual network as a VPC network as an example, multiple computing nodes belong to multiple tenants. To ensure data security and isolation between different tenants, the computing nodes of multiple tenants are connected to different VPC networks. For example, the computing nodes of tenant A are connected to VPC network 1, and the computing nodes of tenant B are connected to VPC network 2.

[0068] Although the IP addresses of virtual instances in multiple computing nodes in the same VPC network are unique, the IP addresses of virtual instances in each VPC network are customized. When the IP address of the virtual instance is IPv4, the IP addresses of virtual instances in different VPC networks may be the same, resulting in the inability to identify the virtual instance by its IP address.

[0069] The application scenarios of this embodiment may include the above-mentioned scenario 1 and the above-mentioned scenario 2. In other words, whether it is a multi-tenant scenario or a private protocol scenario, there may be a problem that the IP address of the virtual instance connected to the virtual network cannot identify the virtual instance.

[0070] For example, the first virtual instance is a virtual instance 2 in VPC network 1, and its original IP address is cip1, but the original IP address of a virtual instance 2 in VPC network 2 is also cip1.

[0071] In order to solve this problem, the storage node can extract the original IP address of the first virtual instance, such as cip1, from the third message (the third message is the message received by the storage node using the previous connection with the first virtual instance), and then the storage node can determine the global IP address corresponding to cip1, such as cip100. The global IP address can identify which virtual instance of which VPC network the first virtual instance comes from, thereby uniquely identifying the first virtual instance. For example, the global IP address corresponding to the original IP address of the above-mentioned virtual instance 2 is cip101, which is different from the above-mentioned cip100.

[0072] Exemplarily, when the storage node first receives a message from the first virtual instance, it can assign a corresponding global IP address to its original IP address. Then, when the storage node subsequently receives a message from the first virtual instance, it can directly obtain the global IP address corresponding to the original IP address.

[0073] In this way, when the storage node processes a message from the first virtual instance (such as the third message mentioned above), in order to determine which virtual instance in which VPC network the message belongs to, the IP address in the message can be converted into the corresponding global IP address to process the message.

[0074] In this way, the storage node uses a global IP address (such as cip100) to identify the first virtual instance internally, but the first virtual instance cannot recognize the global IP address. Then, when the storage node actively establishes a first connection with the first virtual instance, the storage node can convert the global IP address of the first virtual instance in the request to establish the first connection into the original IP address, and then issue the establishment request. Thus, in the case where the physical IP address of the virtual instance cannot identify the virtual instance, the storage node can also establish the first connection with the accurate address of the first virtual instance by means of address conversion. This embodiment can solve the problem that the original IP address of the virtual instance cannot identify the virtual instance in a scenario where multiple computing nodes connected to the virtual network run virtual instances of multiple tenants.

[0075] In some embodiments, in an implementation where the storage node interacts with the computing node through an asymmetric gateway, the virtual address of the destination in the first session information may include not only the virtual address of the virtual network (e.g., VPC1) where the first virtual instance is located, but also the original IP address of the first virtual instance.

[0076] In a possible implementation manner, the method further includes: the storage node sending a first message to the first virtual instance through the first connection based on the mapping relationship.

[0077] In an embodiment of the present application, when the storage node actively establishes a first connection with the first virtual instance, the first virtual instance side does not know the global IP address used internally in the storage node to identify the first virtual instance in VPC network 1, and the global IP address is used to identify the virtual instance within the storage node.

[0078] Then, when the storage node sends the first message through the first connection, it can convert the global IP address in the address of the destination end (here is the first virtual instance) in the first message into the corresponding original IP address, for example, from cip100 to cip1, and then send out the first message to ensure that the first message can be reliably and accurately sent to the specific port of the first virtual instance in VPC network 1, and will not be sent to other virtual instances outside the first connection, nor will it be sent to ports on connections other than the first connection to the first virtual instance.

[0079] In one possible implementation, the present application provides a storage node. The storage node is used to communicate with multiple computing nodes through a virtual network, and a first virtual instance is running in the multiple computing nodes. The storage node includes: a storage module, which is used to pre-store target files, or to receive and store target files from the multiple computing nodes; a first connection establishment module, which is used to actively request to establish a first connection with the first virtual instance; a first sending module, which is used to send a first message to the first virtual instance through the first connection, and the first message is used to provide target information for accessing the target file; an access module, which is used to access the target file in response to receiving a second message sent by the first virtual instance based on the first message.

[0080] In a possible implementation, the target information is used to indicate that the access lock to the target file has been released; or, the target information is used to provide metadata of the target file, wherein different files have different metadata.

[0081] In a possible implementation, the storage node further includes: a first receiving module, configured to receive a third message from the first virtual instance through a second connection; and the first connection establishing module, configured to actively request to establish a first connection with the first virtual instance based on the third message.

[0082] In a possible implementation, the multiple computing nodes run first virtual instances of multiple tenants, the multiple computing nodes running first virtual instances of different tenants run in different virtual networks, and the target information is used to indicate that the access lock to the target file has been released.

[0083] In a possible implementation, the storage node further includes: a second receiving module, configured to receive a fourth message from the first virtual instance through a third connection, wherein the fourth message is used to provide information for requesting an access lock on the target file; a first determining module, configured to determine, in response to the fourth message, that the access lock on the target file is occupied by a second virtual instance running in the plurality of computing nodes; and the first connection establishing module, specifically configured to actively request to establish the first connection with the first virtual instance when determining that the access lock on the target file is released.

[0084] In a possible implementation, the storage node also includes: a second connection establishment module, used to actively request to establish the second connection between the first virtual instance based on the fourth message when it is determined that the access lock of the target file is released; a second sending module, used to send a fifth message to the first virtual instance through the second connection, wherein the fifth message is used to query the port number of the target information; and the third message is used to provide the port number of the first virtual instance.

[0085] In a possible implementation, the multiple computing nodes run first virtual instances of multiple tenants, and the multiple computing nodes running first virtual instances of different tenants run in different virtual networks. The storage node also includes: a second determination module, used to determine the original IP address of the first virtual instance based on the third message; a third determination module, used to determine the global IP address corresponding to the original IP address, wherein the global IP address is used to identify the first virtual instance running in the virtual network; the first connection establishment module, specifically used to actively request to establish a first connection with the first virtual instance based on the mapping relationship between the original IP address and the global IP address.

[0086] In a possible implementation manner, the first sending module is specifically configured to send the first message to the first virtual instance through the first connection based on the mapping relationship.

[0087] In a possible implementation, the storage node is used to interact with the multiple computing nodes in the virtual network through an RDMA protocol.

[0088] In one possible implementation, the present application provides a data center, which may include the storage nodes and computing nodes described in any one of the above implementations, and the data center also includes a gateway deployed in the virtual network, and the multiple computing nodes interact with the storage nodes through the gateway; the storage node also includes: a third sending module, used to send first session information to the gateway; the first connection establishment module, specifically used to send the first connection establishment request to the gateway; the gateway includes: a forwarding module, used to forward the first connection establishment request to the first virtual instance based on the first session information.

[0089] The effects of the storage nodes and data centers in the above-mentioned embodiments are similar to the effects of the access methods in the above-mentioned embodiments, and will not be described in detail here.

[0090] In a possible implementation, the present application provides a storage node. The storage node includes a processor and a memory, wherein the processor is configured to execute instructions stored in the memory, so that the storage node executes the method in any one of the above implementations.

[0091] The effect of the storage node of this embodiment is similar to the effect of the access method of the above-mentioned embodiments, and will not be repeated here.

[0092] In a possible implementation, the present application provides a data center. The data center includes multiple computing nodes and storage nodes, the multiple computing nodes run a first virtual instance, the multiple computing nodes interact with the storage nodes through a virtual network, and the storage nodes include a processor and a memory, the processor is used to execute instructions stored in the memory, so that the storage node executes the method in any one of the above implementations.

[0093] In a possible implementation, the virtual network includes a gateway, and the gateway may include a processor and a memory. The processor may be used to execute instructions in the memory so that the gateway forwards the first connection establishment request to the first virtual instance based on the first session information.

[0094] The effect of the data center of this embodiment is similar to the effect of the access method of the above-mentioned embodiments, and will not be repeated here.

[0095] In a possible implementation, the present application provides a computer-readable storage medium. The computer-readable storage medium includes computer program instructions, and when the computer program instructions are executed by a storage node, the storage node executes the method in any one of the above implementations.

[0096] The effect of the computer-readable storage medium of this embodiment is similar to the effect of the access method executed by the storage node in the above-mentioned embodiments, and will not be described in detail here.

[0097] In a possible implementation, the present application provides a computer-readable storage medium. The computer-readable storage medium includes computer program instructions, and when the computer program instructions are executed by a gateway in a virtual network, the gateway can forward the first connection establishment request to the first virtual instance based on the first session information.

[0098] The effect of the computer-readable storage medium of this embodiment is similar to the effect of the access method executed by the gateway in the above-mentioned embodiments, and will not be repeated here.

[0099] In a possible implementation, the present application provides a computer program product including instructions. When the instructions are executed by a storage node, the storage node executes the method in any one of the above implementations.

[0100] The effect of the computer program product of this embodiment is similar to the effect of the access method executed by the storage node in the above-mentioned embodiments, and will not be described in detail here.

[0101] In a possible implementation, the present application provides a computer program product including instructions. When the instructions are executed by a gateway in a virtual network, the gateway can forward the first connection establishment request to the first virtual instance based on the first session information.

[0102] The effect of the computer program product of this embodiment is similar to the effect of the access method executed by the gateway in the above-mentioned embodiments, and will not be described in detail here. BRIEF DESCRIPTION OF THE DRAWINGS

[0103] In order to more clearly illustrate the technical solutions of the embodiments of the present application, the drawings required for use in the description of the embodiments of the present application will be briefly introduced below. Obviously, the drawings described below are only some embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0104] Figure 1 is a schematic diagram of a system architecture shown as an example;

[0105] Figure 2 A schematic diagram of a system processing process in a related art is shown as an example;

[0106] Figure 3a A schematic diagram of a system architecture is shown as an example;

[0107] Figure 3b is a schematic diagram of another system architecture shown as an example;

[0108] Figure 4a A schematic diagram showing an exemplary system interaction process;

[0109] Figure 4b is a schematic diagram of another system interaction process shown as an example;

[0110] Figure 5a A flowchart of a data access process is shown as an example;

[0111] Figure 5b A flowchart of a data access process is shown as an example;

[0112] Figure 5c A flowchart of a data access process is shown as an example;

[0113] Figure 6a A schematic diagram of a message in a data access process is shown as an example;

[0114] Figure 6b A schematic diagram of a message in a data access process is shown as an example;

[0115] Figure 6c A schematic diagram of a message in a data access process is shown as an example;

[0116] Figure 7 A schematic diagram of a system architecture is shown as an example;

[0117] Figure 8a is a schematic diagram of the structure of a storage node shown as an example;

[0118] Figure 8b is a schematic diagram of the structure of a data center shown as an example;

[0119] Fig. 9 is a schematic diagram of the structure of a storage device shown as an example;

[0120] Fig.10 is a schematic diagram of the structure of a storage device shown as an example;

[0121] Fig.11 The figure is a schematic diagram of the structure of a storage device cluster shown as an example. DETAILED DESCRIPTION

[0122] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0123] The term "and / or" in this article is merely a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can mean: A exists alone, A and B exist at the same time, and B exists alone.

[0124] The terms "first" and "second" in the description and claims of the embodiments of the present application are used to distinguish different objects rather than to describe a specific order of objects. For example, a first target object and a second target object are used to distinguish different target objects rather than to describe a specific order of target objects.

[0125] In the embodiments of the present application, words such as "exemplary" or "for example" are used to indicate examples, illustrations or descriptions. Any embodiment or design described as "exemplary" or "for example" in the embodiments of the present application should not be interpreted as being more preferred or more advantageous than other embodiments or designs. Specifically, the use of words such as "exemplary" or "for example" is intended to present related concepts in a specific way.

[0126] In the description of the embodiments of the present application, unless otherwise specified, the meaning of "multiple" refers to two or more than two. For example, multiple processing units refer to two or more processing units; multiple systems refer to two or more systems.

[0127] At present, with the development of Internet services, distributed computing and other technologies, Data Center Networking (DCN) technology has been widely used.

[0128] The architecture of the data center network of this application is introduced below.

[0129] The data center network of the present application may include computing nodes, storage nodes, and a business network.

[0130] Among them, a gateway can be deployed in the business network. Before the improvement of this application, the gateway was an asymmetric gateway (it can also be named a load balancer in some scenarios). After the improvement of the data center network in this application, the gateway deployed in the business network can be a symmetric gateway.

[0131] Definition of the asymmetric gateway: The asymmetric gateway can distribute storage nodes in response to requests from computing nodes and forward the requests to the distributed storage nodes. However, after receiving the request from the storage node, the asymmetric gateway cannot distribute the request to the computing node, and thus cannot forward the active request of the storage node to the computing node.

[0132] The gateway of the present application is a symmetric gateway. Compared with an asymmetric gateway, the symmetric gateway can not only distribute storage nodes in response to requests from computing nodes, but also forward the requests to the distributed storage nodes. In addition, after receiving the request from the storage node, the symmetric gateway can also distribute the request to the computing node, thereby forwarding the active request of the storage node to the computing node.

[0133] The computing nodes of the present application may run the services of tenants, and the storage nodes may store data, wherein the storage nodes may pre-store data, and in addition, the computing nodes may also write data to the storage nodes.

[0134] Compute nodes and storage nodes can exchange data through the business network.

[0135] Among them, the computing nodes can access the data in the storage nodes through the gateway in the business network.

[0136] When the number of tenants of computing nodes is small, the business network may be a physical network.

[0137] Then the gateway of the present application may be deployed in the above-mentioned physical network to distribute the requests of the computing nodes to the storage nodes, and distribute the requests of the storage nodes to the computing nodes.

[0138] When there are many tenants of computing nodes, virtual networks can be deployed on top of the physical networks of computing nodes and storage nodes. Then the above business network can be a virtual network to support the massive tenants of computing nodes to access the data in the storage nodes. In this way, both computing nodes and storage nodes are connected to the virtual network and interact through the virtual network.

[0139] In some embodiments, compared with a gateway deployed in a physical network, a gateway deployed in a virtual network not only has the function of message distribution, but also has the function of converting between a virtual address in the virtual network and a physical address in the physical network.

[0140] There are many types of virtual networks, among which an overlay network is a type of virtual network. The data center network of the present application can be applied to various types of virtual networks.

[0141] Among them, the overlay network is an asymmetric network, that is, it supports the distribution function of requests from computing nodes to storage nodes, but does not support the distribution function of requests from storage nodes to computing nodes.

[0142] When the service network between the computing nodes and the storage nodes of the present application is an overlay network, optionally, the asymmetric gateway in the overlay network can be improved to a symmetric gateway so that the data center network supports the storage nodes to actively access the computing nodes.

[0143] Among them, the Virtual Private Cloud (VPC) network is an overlay network. The computing nodes and storage nodes of the present application can exchange data through the VPC network. Among them, a VPC gateway can be deployed in the VPC network. The VPC gateway was an asymmetric gateway before the improvement. After the improvement of the present application, the VPC gateway in the VPC network is a symmetric gateway.

[0144] Combine the following Figure 1 , taking the business network in the data center network as the VPC network and the gateway in the VPC network as the VPC gateway as an example, the architecture and functions of the data center network of this application are explained.

[0145] like Figure 1 As shown, the data center network may include a computing cluster 101, a storage cluster 102, and a VPC network.

[0146] The VPC network may include Figure 1 The VPC gateway 103 , the VPC network 1 to which tenant A in the computing cluster 101 is connected, the VPC network 2 to which tenant B is connected, and the VPC network 0 to which the storage cluster 102 is connected are shown.

[0147] The computing cluster 101 and the storage cluster 102 can interact with each other through the VPC gateway 103 .

[0148] like Figure 1 As shown, computing cluster 101 may include multiple computing nodes, each of which may be a computing server. Computing nodes 11 to 14 and computing nodes 21 to 24 are exemplarily shown here. The present application does not limit the number of computing nodes.

[0149] Among them, computing nodes 11 to 14 are connected to VPC network 1, and computing nodes 11 to 14 run the services of tenant A; computing nodes 21 to 24 are connected to VPC network 2, and computing nodes 21 to 24 run the services of tenant B.

[0150] In addition, the computing nodes running different tenants' businesses are connected to different VPC networks to isolate the businesses of different tenants and ensure the isolation of data of different tenants.

[0151] Taking the computing node 11 of tenant A as an example, the computing node 11 may include multiple virtual instances, here virtual instances 1 to 3, where the virtual instances may be virtual machines or containers (not limited here), for executing the services of tenant A. Similarly, the virtual instances 1 to 3 in the computing node 21 of tenant B may all be used to execute the services of tenant B.

[0152] The IP addresses (also referred to as original IP addresses or physical IP addresses) of the virtual instances connected to the same VPC network are different. For example, the IP addresses of virtual instances 1 to 3 in computing node 11 are different, and the IP addresses of the virtual instances between computing nodes 11 to 14 are also different. Similarly, the IP addresses of the virtual instances in computing nodes 21 to 24 of tenant B are also different.

[0153] However, considering that the IP addresses of virtual instances of different tenants are customized by each tenant, the IP addresses of virtual instances of different tenants may be the same.

[0154] The storage cluster 102 may include multiple storage nodes, each of which may be a storage server. Storage nodes 31 to 3n are exemplarily shown here, where n is a positive integer. The present application does not limit the number of storage nodes.

[0155] The storage nodes in the storage cluster 102 can be used to store data. In the cloud scenario, each storage node in the storage cluster 102 is also connected to the VPC network (here, VPC network 0) to support data access by a large number of tenants under the VPC network. Among them, the storage nodes 31 to 3n connected to the same VPC network have different IP addresses (also expressed as original IP addresses or physical IP addresses).

[0156] like Figure 1 As shown, there is a VPC gateway 103 between the VPC network 1 and the VPC network 2 connected to the computing cluster 101 and the VPC network 0 connected to the storage cluster 102. The VPC gateway 103 was originally an asymmetric gateway, but the present application improves the VPC gateway 103 so that the VPC gateway 103 of the present application is a symmetric gateway.

[0157] The following example takes the business network as a VPC network and the asymmetric gateway in the business network as a VPC gateway. Figure 2 To describe the data interaction process between computing nodes and storage nodes in a data center network in the related art, and introduce the problem faced by the data center network in the related art that does not support storage nodes actively sending messages to computing nodes.

[0158] Figure 2 The system architecture shown is similar to Figure 1 The modules in the system architecture shown are the same. For specific functions and meanings, please refer to Figure 1 The introduction of , I will not go into details here.

[0159] Figure 2 The VPC gateway 103a shown is an asymmetric gateway before improvement in the present application, and different reference numerals are used to distinguish the asymmetric gateway in the related art from the symmetric gateway in the present application.

[0160] Reference Figure 2 , the virtual instance 1 of tenant A initiates an IO request. The physical IP address of the virtual instance 1 is represented by cip1. Since the computing node 11 is deployed in the VPC network 1, the source IP address of the IO request is superimposed on cip with the ID of the VPC network 1 to which the virtual instance 1 belongs (represented by vpc1), and the source IP address of the IO request is represented by the virtual address vpc1:cip1.

[0161] The IO request can flow into the VPC gateway 103a through the VPC network 1, and the VPC gateway 103a can allocate a storage node to the IO request in the storage cluster 102 according to a preset rule, for example, to allocate storage node 31, wherein the IP address of the storage node 31 is represented by sip1. In addition, the VPC gateway 103a can generate corresponding session information 1: vpc1:cip1->sip1, to indicate that a connection is established between the virtual instance 1 in the VPC network 1 and the storage node 1. Among them, vpc1:cip1 represents the virtual IP address of the virtual instance 1 in the computing node 11, and the physical IP address of the virtual instance 1 is represented by cip1.

[0162] Then, the VPC gateway can forward the IO request to the storage node 31 in the VPC network 0; the storage node 31 receives the IO request and sends the IO response to the IO request to the VPC gateway 103a. The VPC gateway 103a can forward the IO response to the virtual instance 1 of the computing node 11 in the VPC network 1 according to the mapping relationship of the IP address in the above session information 1.

[0163] In the above description, sip1 is the physical IP address of storage node 31, and the virtual IP address of storage node 31 is vpc0:sip1. vpc0 represents the ID of VPC network 0 to which storage node 31 is connected. In other words, the virtual IP address of storage node 31 is the ID of the VPC network attached to its physical IP address. Considering that storage cluster 102 is only connected to one VPC network 0, and the physical IP addresses of storage nodes deployed in the same VPC network are different, sip1 can be used to identify the IP address of storage node 31. Therefore, Figure 2 In the embodiment, the destination IP address in the session information 1 is represented by sip1. In other embodiments, the destination IP address in the above session information 1 may also be represented by vpc0:sip1.

[0164] However, in some scenarios (such as the following scenarios 1 and 2), the storage node also needs to actively access the computing node to send messages to the computing node.

[0165] In scenario 1, both the storage node and the computing node use the NFS standard protocol (such as NFS V3 protocol) to access data. When the computing node accesses files stored on the storage node, it can use a locking method to access the files.

[0166] In scenario 1, if Figure 2As shown, the virtual instance 1 within the computing node 11 of tenant A can reuse the connection established with the storage node 31, and initiate a lock request for the file in the storage node to the VPC gateway 103a through the VPC network 1. The VPC gateway 103a can forward the lock request to the storage node 31 according to the session information 1.

[0167] The storage node 31 detects that the lock of the file requested to be locked by the virtual instance 1 is occupied by other virtual instances of the tenant A, or by virtual instances of other tenants (for example, tenant B). Then, after the lock of the file is released by other virtual instances, the storage node 31 needs to send a response to the lock request to the virtual instance 1 of tenant A, for example, the storage node 31 needs to notify the virtual instance 1 of the message indicating that the lock of the file has been released.

[0168] However, in the related art, Figure 2 The VPC gateway 103a shown is an asymmetric gateway. Only when the computing node actively initiates an IO request to the VPC gateway 103a, the VPC gateway 103a will allocate the storage node to the IO request according to the preset rules, and establish a mapping of vpc:cip to sip (such as the above session information 1) to establish a connection between the computing node and the storage node. As for the response message of the lock request actively sent by the storage node 31 to the VPC gateway 103a through the VPC network 0, the VPC gateway 103a does not have the allocation strategy or allocation rules of the computing node or virtual instance, and cannot distribute the response message of the lock request to the computing node, nor can it determine which virtual instance to allocate the response message to. Figure 2 As shown by the “X” in the circle, the storage node 31 cannot forward the response message of the lock request to the virtual instance 1 of the computing node 11 through the VPC gateway 103a.

[0169] Therefore, the data center network in the related art does not support multiple virtual instances (which can be different virtual instances of the same tenant or virtual instances of different tenants) to share and lock the same file in the storage node. The file directories of different tenants on the storage cluster 102 side are independent of each other, and multiple tenants cannot share and lock the same file directory.

[0170] In the above Figure 2 In the example, both computing nodes and storage nodes use the NFS standard protocol for data access to illustrate the problem that the data center network in the related art does not support the storage node to actively access the computing node.

[0171] Scenario 2: When both the storage node and the computing node use private protocols for data access, the virtual instance running the tenant's business in the computing node can be called a private client. Then, when the computing node accesses files stored on the storage node, it can use the file's metadata to access the file. In scenario 2, the storage node needs to actively establish a connection with the virtual instance in the computing node, and then synchronize the file's metadata information to the virtual instance on the connection.

[0172] However, since the gateway in the service network of the data center in the related art is an asymmetric gateway (for example Figure 2 The VPC gateway 103a is an asymmetric gateway), which makes it impossible for the storage node to actively synchronize the metadata information of the file to the computing node. Therefore, the data center network in the related art does not support the deployment of private clients in the computing node, so that the private client can access the file through the metadata of the file stored on the storage node.

[0173] Of course, the scenarios where the storage node needs to actively access the computing node are not limited to the above scenarios 1 and 2.

[0174] In summary, the data center network in the related art, because the computing node accesses the files in the storage node through the asymmetric gateway, there is a problem that the storage node cannot actively establish a connection with the computing node and actively send messages to the computing node through the connection, so that the data center network in the related art cannot actively access the computing node through the storage node to support the application scenario of the computing node accessing the files stored in the storage node. For example, scenario 1 of multi-tenant shared file access, or scenario 2 of deploying a private client in the computing node.

[0175] also, Figure 2 The VPC gateway 103a shown in the figure only supports the TCP protocol but not the Remote Direct Memory Access (RDMA) protocol. Figure 2 In the above process, the virtual instance actively connects to the storage node on the VPC network through the TCP protocol and accesses the data of the storage node on the TCP connection. The RDMA protocol is a high-performance network protocol. In the cloud scenario, when the computing node accesses data to the storage node through the VPC gateway, it only accesses data through the TCP protocol, and the data access performance is low.

[0176] In addition, since computing nodes of different tenants need to be connected to different virtual networks (such as VPC networks), for example, tenant A is connected to VPC network 1, and tenant 2 is connected to VPC network 2, the physical IP addresses of virtual instances (hereinafter referred to as clients) of different tenants can be customized by each tenant, so that the physical IP addresses of virtual instances between different tenants may be the same. Figure 2 The physical IP address of virtual instance 1 in tenant A's computing node 11 is cip1. Figure 2 The physical IP address of virtual instance 2 in computing node 21 of tenant B is also cip1.

[0177] To this end, the present application provides an access method that can realize the active establishment of a connection between a storage node and a computing node in a data center network, and actively send a message to the computing node on the connection, so that the computing node can use the message to access the file stored in the storage node through the storage node. As described above, the file can be a file pre-stored in the storage node, or a file received and stored by the storage node from the computing node, which is not limited here.

[0178] In this way, in the scenario where multiple tenant instances share access to files in the same file directory on the storage node, the storage node of the present application can actively send a message to the virtual instance in the computing node indicating that the lock of the file requested to be locked has been released, so that the data center network supports the shared locked access of multiple tenant virtual instances (which can be multiple virtual instances of the same tenant, or multiple virtual instances of different tenants) to the files in the same file directory stored in the storage node, so that multiple tenants can share locked access to the same file directory in the storage node. Among them, the files in the sharable file directory in the storage node may include files pre-stored on the storage node, and / or files written to the storage node by at least one virtual instance in at least one computing node.

[0179] In addition, private clients can also be deployed on computing nodes. The storage nodes of the present application actively send messages to private clients, which can provide metadata information of files stored in the storage nodes. In this way, the data center network of the present application can support the deployment of private clients on computing nodes, so that private clients can use metadata synchronized by storage nodes through private protocols to access corresponding files on storage nodes. The file can be a file pre-stored on the storage node, or a file written to the storage node by other private clients, which is not limited here.

[0180] As described above, the application scenario of the storage node actively accessing the computing node can be the above-mentioned scenario 1 corresponding to multiple tenants sharing access to the same file directory in the storage node, or it can be the above-mentioned scenario 2 of accessing files stored in the storage node through a private client deployed on the computing node.

[0181] The following describes the technical solutions of the access method of the present application applied to the above-mentioned scenario 1 and the above-mentioned scenario 2 respectively in combination with different examples.

[0182] In addition, as described above, the business network for interaction between the computing nodes and the storage nodes of the present application can be a physical network or a virtual network. When the business network is a virtual network, in the following examples 1 to 5, the virtual network is a VPC network (for example, an application Figure 1 When the virtual network is another type of virtual network, the implementation principle is similar and will not be described here.

[0183] Example 1

[0184] In this example 1, the virtual network for interaction between computing nodes and storage nodes is taken as a VPC network as an example. Figure 1 The architecture shown is used to describe the method of the present application.

[0185] This example 1 can be applied to the scenario 1 described above.

[0186] In order to enable the data center network to support multiple tenants to share the same file directory in the storage node, so that multiple tenants can share locked access to the same file directory. In this example 1, it mainly describes that when a virtual instance requests locked access to a file stored in a storage node, but the file is being locked by other virtual instances, then after the lock of the file is released, how can the storage node actively establish a connection with the virtual instance that previously requested to lock it, and actively notify the virtual instance through the connection that the lock of the file it requested to lock has been released, so that the virtual instance can access the target file in the shared file directory in the storage node in a timely manner. This allows a file directory that is shared and accessed by multiple tenants to exist in the storage node, and supports shared access to the file directory by multiple tenants.

[0187] Combined with the above Figure 1 , please refer to Figure 3a , Figure 4a , Figure 5a to Figure 5c , Figures 6a to 6c To understand the technical solution of this example 1.

[0188] Reference Figure 3aIn this embodiment, a scenario in which computing nodes and storage nodes interact through a VPC gateway 103 is used as an example to illustrate that the VPC gateway 103 supports the TCP protocol, so that the storage nodes connected to the VPC network 0 and the virtual instances of each tenant in the computing cluster 101 connected to the VPC network 1 and the VPC network 2 can interact through the VPC gateway 103 using the TCP protocol.

[0189] like Figure 3a As shown, the virtual instance 1 running in the computing node 11 connected to the VPC network 1 can send a lock request for the target file stored in the storage cluster 102 to the VPC gateway 103. The VPC gateway 103 can distribute the lock request to the storage node 31 to forward the lock request to the storage node 31. When the storage node 31 determines that the access lock of the stored target file is occupied, it indicates that other virtual instances in the computing cluster 101 are performing locked access to the target file. Then, when the storage node 31 determines that the access lock of the target file has been released, the storage node 31 can send a response message to the lock request (for example, information for notifying that the access lock of the target file has been released) to the VPC gateway 103 and synchronize the session information (for example, session information 2 or session information 3) used to forward the response message.

[0190] In this way, the VPC gateway 103 can forward the lock request response message to the virtual instance 1 in the corresponding computing node 11 according to the synchronized session information, so that the storage node 31 can actively send a message (here, the lock request response message) to the virtual instance 1 in the computing node 11. Afterwards, the virtual instance 1 can use the lock request response message to access the target file from the storage node 31. This allows the data center network to support multiple virtual instances to share and lock access to the target file in the same file directory in the shared storage cluster 102.

[0191] In this example 1, Figure 3a The virtual instance 1 running in the computing node 11 shown represents the first virtual instance requesting locked access to the target file stored in the storage cluster 102. In other embodiments, any virtual instance running in the computing cluster 101 can be the first virtual instance. In this example 1, the storage node 31 in the storage cluster 102 stores the target file as an example. In other embodiments, the target file in the file directory for multi-tenant shared access can be stored in one or more storage nodes in the storage cluster 102, which is not limited here.

[0192] Combination Figure 3a ,like Figure 4a As shown, the virtual instance 1 in the computing node 11 connected to the VPC network 1 can also be represented as the client 1.

[0193] like Figure 4a As shown, in the scenario where the storage node 31 actively notifies the client 1 that the access lock of the target file requested to be accessed has been released (hereinafter referred to as the lock notification message), the following may be included: Figure 4a (1) The operation process shown in 1. Figure 4a (2) The operation process 2 shown in Figure 4a (3) Operation process 3 shown.

[0194] exist Figure 2 The technical solution of the related art shown in the figure only includes Figure 4a In the operation process 1 shown in (1), since the storage node cannot actively establish a connection with the virtual instance through the VPC gateway 103a, the related technology cannot be implemented. Figure 4a (2) The operation process 2 and Figure 4a Operation process 3 shown in (3) makes it impossible for the storage node to send the lock notification message to the client.

[0195] Among them, operation process 1 is as follows Figure 4a The client 1 shown in (1) actively establishes a connection to the storage node 31 (represented by the first connection here), and sends a lock request to the storage node 31 through the VPC gateway 103 on the first connection.

[0196] In the scenario where the storage node 31 actively sends a lock notification message to the client 1, in order to send the lock notification message to the client 1, the storage node 31 needs to Figure 4a The operation process 2 shown in (2) is to obtain the lock notification port number of client 1 from client 1.

[0197] like Figure 4a As shown in (2), the storage node 31 can use the lock request received in the first connection established with the client 1 to actively establish a second connection with the client 1. And the storage node 31 can send a message indicating the query lock notification port to the client 1 through the VPC gateway 103 on the established second connection, and receive a message indicating the lock notification port replied by the client 1 on the second connection, so as to obtain the port number (here represented by cport3) used by the client 1 for lock notification.

[0198] In such Figure 4a After operation process 2 shown in (2), the storage node 31 can use the lock notification port message received in the second connection established with the client 1 to obtain the port number of the lock notification of the client 1, so as to actively establish a third connection with the client 1 through the VPC gateway 103. And the storage node can send the lock notification message (here, the message notifying that the requested lock has been released) to the client 1 through the VPC gateway 103 on the established third connection.

[0199] Figure 4a (2) and Figure 4a The two operation processes in (3) are scenarios where the storage node needs to actively send messages to the client.

[0200] It should be understood that in the scenario where the storage node actively sends a message to the client, the storage node 31 cannot reuse the message encapsulation information of the control plane and the data plane. Figure 4a (1) The first connection actively established by the client 1 is performed as follows Figure 4a (2) The encapsulation and sending of the message indicating the query lock notification port cannot reuse the first connection to perform the following operations: Figure 4a (3) shows the encapsulation and sending of the message indicating that the lock requested by the notification has been unlocked. In contrast, the storage node 31 can only actively re-establish a new connection with the client (such as the second connection or the third connection), and encapsulate and send a message indicating the query lock notification port to the client 1 on the second connection, and encapsulate and send a message indicating that the lock requested by the notification has been unlocked to the client 1 on the third connection.

[0201] In this embodiment, the storage node 31 actively establishes a connection with the client 1 (for example Figure 4a When the second connection or the third connection shown in the figure is established, the message received from the previous connection established between the storage node 31 and the client 1 can be used to actively establish the next connection with the client 1 (for example Figure 4a This ensures that the storage node 31 can obtain the information (such as address information) of the destination (client 1 here) required for actively establishing the connection through the above-mentioned message in advance before actively establishing the connection, and the first connection established using the information obtained in advance can be used to transmit the target information, thereby avoiding the problem that the actively established connection cannot transmit the target information.

[0202] Combine the following Figure 5a to Figure 5c as well as Figures 6a to 6c , to describe Figure 4a The three operation processes shown in the figure are described in detail. It also describes how the storage node 31 uses the message received from the last connection established with the client 1 to generate the session information (e.g. Figure 3a , Figure 4aWhen the storage node 31 requests to actively establish a connection with the client 1, the session information generated in advance is synchronized to the VPC gateway 103, so that when the VPC gateway 103 itself is not configured with a distribution strategy for virtual instances or computing nodes, the VPC gateway 103 can use the session information synchronized from the storage node 31 to establish an active connection between the storage node 31 and the client 1, and forward the message of the storage node 31 to the client 1 according to the session information. Figure 1 , Figure 3a , Figure 4a The VPC gateway 103 in the example can support the distribution function of the messages from the storage nodes, thereby achieving the effect that the storage node 31 actively accesses the computing node through the VPC gateway 103.

[0203] Figure 5a An example is shown Figure 4a (1) The detailed implementation process of the operation process 1 and the operation steps of the method of the present application related to the operation process 1.

[0204] Figure 6a An example is shown Figure 5a The process shown includes a message header of a message, schematic contents of forward key1 and reverse key1 related to a first connection, and schematic contents of forward key2 and reverse key2 related to a second connection to be established.

[0205] Among them, the "forward" described in each embodiment of this document refers to the direction of sending messages from the client to the storage node, for example, the source end is the client and the destination end is the storage node; "reverse" refers to the direction of sending messages from the storage node to the client, for example, the source end is the storage node and the destination end is the client.

[0206] First, combined with Figure 3a and Figure 4a , please refer to Figure 5a and Figure 6a ,like Figure 5a As shown, the process may include the following steps:

[0207] S301, client 1 sends a request to establish a first connection to VPC gateway 103.

[0208] For example, client 1 needs to Figure 3aTo perform a write operation on a target file stored in the storage cluster 102 shown in the figure, in order to ensure that the file is written correctly, before performing the write operation, the client 1 needs to send a lock request for the file to the storage cluster 102 to lock the file and prevent other clients from performing read and write operations on the file. Before the client 1 sends the lock request, the client 1 first needs to establish a connection with the storage node in the storage cluster 102, and the client 1 can send a request to establish a connection with the storage node (here, the first connection establishment request) to the VPC gateway 103.

[0209] The target file may be a file pre-stored in the storage cluster 102 , or may be a target file written to the storage cluster 102 by multiple computing nodes in the computing cluster 101 .

[0210] In some embodiments, the target file may be located in a multi-tenant shared file directory of the storage cluster 102, so that virtual instances of multiple enterprises, or multiple virtual instances of the same enterprise, can perform shared locked access to the files in the file directory.

[0211] In some embodiments, the target file may also be located in a file directory of a single tenant of the storage cluster 102, so that multiple virtual instances of the tenant (corresponding to an enterprise) can perform shared locked access to the files in the file directory.

[0212] The request to establish the first connection may include the IP address and port number of the client 1. Figure 3a As shown, client 1 is connected to VPC network 1, then the source address of the first connection establishment request is a virtual address, for example, represented by vpcID:cipID:cportID, where vpcID represents the ID of the VPC network to which client 1 belongs, here is vpc1:cipID represents the physical IP address of client 1, here is cip1; cportID represents the port number of client 1 for this connection establishment, here is cport1. Among them, vpcID:cipID:cportID means that the physical address of the client also encapsulates the virtual address of the VPC network to which it belongs (for example, vpcID). Among them, when client 1 connected to VPC network 1 requests to establish a first connection, the source address of the first connection establishment request (here is the address of client 1) is represented by vpc1:cip1:cport1.

[0213] S302 , the VPC gateway 103 allocates a storage node 31 .

[0214] Please refer to Figure 2As described in the related art, the VPC gateway 103 may allocate a storage node in the storage cluster 102, here port 1 of the storage node 31, to the establishment request of the first connection according to a preset rule.

[0215] For example, the physical IP address of the storage node 31 is represented by sip1, and the port number of port 1 of the storage node 31 is represented by sport1. The physical IP address and port number of the storage node 31 establishing the first connection this time are represented by sip1:sport1.

[0216] As mentioned above, refer to Figure 3a Since the storage cluster 102 is only connected to one VPC network, which is VPC network 0, the IP addresses (expressed as sip) between different storage nodes in the storage cluster 102 must be different. Therefore, the sip1 of the above storage node 31 can identify the storage node 31, and sip1:sport1 can identify the physical address of port 1 of the storage node 31.

[0217] Of course, in other embodiments, the physical address of the storage node 31 may also be represented by vpc0:sip1:sport1, wherein the meaning of vpc0:sip1:sport1 is the same as the meaning of the virtual address vpc1:cip1:cport1 of the client 1, and the ID of the VPC network to which the storage node 31 belongs is also encapsulated on the basis of the physical address of the storage node 31 to identify the physical address of the storage node 31.

[0218] Reference Figure 3a and Figure 4a (1) When the VPC gateway 103 responds to the request to establish the first connection and allocates port 1 of the storage node 1 in the storage cluster 102 to establish a connection with port 1 of the client 1, it can generate session information (session) 1 related to the first connection to be established, wherein session 1 may include a mapping between address information of both ends of the connection to be established, here a mapping between port number 1 of the client 1 and port number 1 of the storage node 31, and the mapping relationship between them is represented by vpc1:cip1:cport1--sip1:sport1.

[0219] S303 , the VPC gateway 103 forwards the first connection establishment request to the storage node 31 .

[0220] The message header of the message may include 5 tuples, namely, source IP, source port number, destination IP, destination port number and protocol number.

[0221] like Figure 6aAs shown, in this step, the header of the message for establishing the first connection forwarded by the VPC gateway 103 to the storage node 31 (the protocol number is not shown here) is represented by vpc1:cip1:cport1->sip1:sport1, wherein the left side of "->" in the schematic expression of the message header in each embodiment of the present application represents the source IP and the source port number, and the right side of "->" represents the destination IP and the destination port number.

[0222] Table 1 is a schematic diagram showing the structure of a message header of the request for establishing the first connection.

[0223] The packet header is represented by vpc1:cip1:cport1->sip1:sport1.

[0224] Table 1

[0225] Source IP Source port number Destination IP Destination port number vpc1:cip1 cport1 sip1 or vpc0:sip1 sport1

[0226] For explanation of the contents of each item in Table 1, please refer to the above introduction of Example 1, which will not be repeated here.

[0227] S304: The first connection between the client 1 and the storage node 31 is established successfully.

[0228] Among them, the client 1 and the storage node 31 establish a first connection of the TCP protocol through the VPC gateway 103. The process of establishing the first connection may include three handshakes. The specific details are not repeated here. Through the three handshakes, in S304, the port 1 of the client 1 and the port 1 of the storage node 1 establish a first connection.

[0229] S305 , the client 1 sends a lock request to the gateway 301 , and the gateway 301 forwards the lock request to the storage node 31 .

[0230] For example, see Figure 6a Similar to S303, the message header of the lock request sent by client 1 to VPC gateway 103 is indicated by vpc1:cip1:cport1->sip1:sport1. The structure of the message header can be found in Table 1 (for a specific explanation, please refer to the introduction of S303, which will not be repeated here).

[0231] Furthermore, the VPC gateway 103 may forward the lock request to the port 1 of the storage node 31 according to the mapping relationship in the session information 1 generated when the first connection is established.

[0232] S306: After receiving the lock request, the storage node 31 checks and determines that the lock is occupied by another client.

[0233] For example, the target file requested to be locked by client 1 is currently being written by other clients of tenant A or by the client of tenant B. In this case, storage node 31 can determine that the lock of the target file is occupied by other clients and can only wait for the lock of the file to be released before responding to the lock request of client 1 to lock the target file.

[0234] After S305 , the storage node may execute S307 .

[0235] S307 , the storage node 31 may determine that the lock request received through S305 is a message of a preset type.

[0236] The message of the preset type may be a message indicating a lock request (eg Figure 4a (1) lock request), unlock request message, lock notification port message (e.g. Figure 4a (2) The message of the query lock notification port shown in FIG.

[0237] Each storage node in the storage cluster 102 of the present application may be configured with keywords and values ​​of preset types of messages in advance through configuration files or configuration management programs. After receiving a message, the storage node may identify whether the message belongs to the preset type of message through the keywords and values ​​here.

[0238] For example, if the keyword is an address offset and the value is 1010, then after the storage node parses the received message, it is determined that the value of the parsed message after the address offset is 1010, indicating that the message is a message of a preset type.

[0239] After S307 , while the storage node 31 is waiting for the lock of the target file requested by the client 1 to be released, the storage node 31 may execute S308 b , and may optionally execute S308 a .

[0240] S308a, the storage node 31 may generate a forward key1 and a reverse key1 associated with the first connection.

[0241] After the storage node 31 identifies that the received message (here, the lock request in S305 ) is a message of a preset type, the storage node may generate a forward key1 and a reverse key1 related to the first connection based on the lock request.

[0242] S308b, the storage node 31 generates a forward key2 and a reverse key2 related to the second connection to be established.

[0243] After the storage node 31 identifies that the received message (here, the lock request in S305) is a message of a preset type, the storage node may generate a forward key2 and a reverse key2 related to the second connection to be established based on the lock request.

[0244] This application does not limit the execution order between S308a and S308b.

[0245] The implementation principles of S308a and S308b are similar. Here, the implementation process of S308b is taken as an example to illustrate the generation process of forward key2 and reverse key2.

[0246] Please refer to Figure 1 and Figure 3a Since the computing nodes of different tenants are deployed in different VPC networks, the messages received by the storage cluster 102 from the computing cluster 101 may come from multiple VPC networks (for example, VPC network 1 and VPC network 2), and the physical IP addresses of virtual instances in different VPC networks may be the same (for example, the physical IP addresses of virtual instance 1 of tenant A and virtual instance 2 of tenant B are both cip1). For example, if the physical IP addresses of the virtual instances in the computing nodes are encoded in IPv4, there may be a problem that the physical IP addresses of virtual instances of different tenants are the same.

[0247] Please refer to Figure 6a , then the storage node 31 parses the lock request in S305, thereby removing the vpcID (here vpc1) of the source address in the message header to determine the physical address of client 1, which is cip1:cport1, where the physical IP address of client 1 is cip1.

[0248] Due to the messages from tenants of different VPC networks, the physical IP addresses of clients of different tenants may be repeated (for example, all are cip1), so that the physical IP address of the client cannot uniquely identify the physical address of the client. Then the storage node 31 can convert the physical IP address (cip1) of client 1 corresponding to the above lock request into a global physical IP address (here cip100).

[0249] Exemplarily, when the storage cluster 102 first receives a message from the client 1, it can assign a corresponding global physical IP address to its physical IP address. Then, when the storage cluster 102 subsequently receives a message from the client 1, it can directly obtain the global physical IP address corresponding to the physical IP address of the client 1 in the message.

[0250] The global physical IP address can uniquely identify the physical IP address of the client 1, so that the storage node 31 can distinguish the physical IP address of each virtual instance in the computing node in the multi-VPC network through the global physical IP address.

[0251] For example Figure 3a The physical IP addresses of the virtual instance 1 of tenant A and the virtual instance 2 of tenant B are both cip1, but the storage node 31 can convert cip1 of the virtual instance 1 of tenant A into a global physical IP address: cip100, and convert cip1 of the virtual instance 1 of tenant B into a global physical IP address: cip101.

[0252] In this way, on the storage cluster 102 side, each virtual instance in the computing cluster 101 connected to multiple VPC networks can be identified by the global physical IP address, and the global physical IP address can be used to distinguish messages from different virtual instances.

[0253] In this way, the storage node 31 can extract the physical IP address of client 1 in the VPC network 1 for the lock request of client 1, and determine the global physical IP address (used to represent the global IP address inside the storage node 31) corresponding to the physical IP address of client 1 (used to represent the original IP address) to obtain the mapping relationship between cip100 and vpc1:cip1, where cip100 can identify vpc1:cip1.

[0254] The storage node 31 can internally use a physical address to identify the client, as well as the IP and port number of the storage node 31. When the storage node 31 receives a message from the computing cluster 101 from the VPC network, or sends a message to the computing cluster 101 through the VPC network 0, since the computing cluster 101 is connected to the VPC network (a virtual network), the storage node 31 can use a virtual address in the message to identify the address of the client 1 and the storage node 31.

[0255] As mentioned above, "forward" means the direction of sending messages from the client to the storage node, for example, the source end is the client and the destination end is the storage node; "reverse" means the direction of sending messages from the storage node to the client, for example, the source end is the storage node and the destination end is the client.

[0256] Reference Figure 6a Based on the lock request, the storage node 31 obtains the mapping relationship between cip100 and vpc1:cip1, and obtains the port number of the client 1 corresponding to the first connection (here is cport1) and the port number of the storage node 31 (here is sport), so that the forward key1 can be generated. The forward key1 is indicated by expression 1.

[0257] vpc1:cip1:cport1+sip1:sport1-》cip100:cport1+sip1:sport1, expression 1a

[0258] As described above, since the storage cluster 102 is only connected to one VPC network 0, the physical addresses of different storage nodes can identify the storage node. In the forward key1, reverse key1, forward key2, reverse key2, forward key3, and reverse key3 generated in each embodiment of this document, the physical IP address of the storage node 31 (for example, sip1) can be used to represent the virtual IP address of the storage node 31 (for example, vpc0:sip1), expressed as sip1:sport1.

[0259] Alternatively, in other embodiments, forward key1, reverse key1, forward key2, reverse key2, forward key3, and reverse key3 reflect the mapping relationship between the virtual IP address and the physical IP address of the storage node, such as the mapping between vpc0:sip1 and sip1. For example, forward key1 can also be represented by expression 1b.

[0260] vpc1:cip1:cport1+vpc0:sip1:sport1-》cip100:cport1+sip1:sport1, expression 1b

[0261] In Expression 1b, the virtual address of the storage node 31 is represented by vpc0:sip1:sport1.

[0262] The physical meaning of the forward key1 indicated by the above expression 1a or expression 1b is shown in Table 2a.

[0263] As shown in Table 2a, the forward key 1 is divided into a Key part and a Value part that map to each other. Since it is a "forward" key, the Key part is composed of the virtual addresses of the client 1 and the storage node 31, and the Value part is composed of the physical addresses of the client 1 and the storage node 31, forming a mapping from the virtual address to the physical address.

[0264] As shown in Table 2a, the forward key1 is divided into four entries: source IP, source port number, destination IP, and destination port number.

[0265] As shown in Table 2a, the Key of the source IP is vpc1:cip1, the Key of the source port number is cport1, the Key of the destination IP is sip1 or vpc0:sip1, and the Key of the destination port number is sport1.

[0266] The value of the source IP is cip100, the value of the source port number is cport1, the value of the destination IP is sip1, and the value of the destination port number is sport1.

[0267] Table 2a

[0268] Forward key1 Source IP Source port number Destination IP Destination port number Key part vpc1:cip1 cport1 sip1 or vpc0:sip1 sport1 Value cip100 cport1 sip1 sport1

[0269] Similarly, refer to Figure 6a The storage node 31 may also generate a reverse key1 related to the first connection based on the lock request, and the reverse key1 is indicated by Expression 2.

[0270] sip1:sport1+cip100:cport1-》sip1:sport1+vpc1:cip1:cport1, expression 2

[0271] The physical meaning of the reverse key1 shown in the above expression 2 is shown in Table 2b.

[0272] Table 2b

[0273] Reverse key1 Source IP Source port number Destination IP Destination port number Key part sip1 sport1 cip100 cport1 Value sip1 sport1 vpc1:cip1 cport1

[0274] As shown in Table 2b, the reverse key 1 is divided into a Key part and a Value part that map to each other. Since it is a "reverse" key, the Key part is composed of the physical addresses of the client 1 and the storage node 31, and the Value part is composed of the virtual addresses of the client 1 and the storage node 31, forming a mapping from the physical address to the virtual address.

[0275] As shown in Table 2b, reverse key1 is divided into four entries: source IP, source port number, destination IP, and destination port number.

[0276] As shown in Table 2b, the Key of the source IP is sip1 or vpc0:sip1, the Key of the source port number is sport1, the Key of the destination IP is cip100, and the Key of the destination port number is cport1.

[0277] The value of the source IP is sip1, the value of the source port number is sport1, the value of the destination IP is vpc1:cip1, and the value of the destination port number is cport1.

[0278] The above-mentioned forward key1 and reverse key1 are the forward key and reverse key related to the first connection. Then the physical IP address, virtual IP address of the client 1 involved in the first connection, and the port number of the client 1 used by the first connection, the virtual IP address, physical IP address of the storage node 31 and the port number of the storage node 31 used by the first connection can all be determined through the lock request message of the preset type in S305, and the storage node 31 also generates a mapping relationship between vpc1:cip1 and cip100, so that the above-mentioned forward key1 and reverse key1 can be generated.

[0279] In one possible implementation, Figure 5a After S305 shown, the storage node 31 determines that the lock of the file requested by the client 1 is not occupied by other clients, then the storage node 31 can send a response message to the client 1 on the first connection, and the client 1 can send a request message to the storage node 31 on the first connection.

[0280] Then in this scenario, when the storage node 31 reuses the first connection to send a response message, as described above, the storage node 31 uses physical addresses to represent the source address and destination address of the message. For example, the source IP of the response message to be sent by the storage node on the first connection is sip, the source port number is sport1, the destination IP is cip100, and the destination port number is cport1. The forward key1 and reverse key2 mentioned above can both be the contents of the flow table information inside the storage node 31. Then the storage node 31 can use the source IP, source port number, destination IP, and destination port number in the message header of the response message to query the flow table information and determine whether the values ​​of the above four types of information in the message header hit the Key part in the flow table information, as shown in Table 2b above. The values ​​of the four items in the Key part of the reverse key1 shown in Table 2b are the same as the values ​​of the four information of the above response message. The storage node 31 may determine that the response message hits the reverse key1, and may modify the values ​​of the four types of information in the response message that match the Key part in the reverse key1 to the values ​​of the four table items in the corresponding Value part in the reverse key1.

[0281] In this way, the source IP in the header of the modified response message is sip, the source port number is sport1, the destination IP is vpc:cip1, and the destination port number is cport1. Figure 3a , the storage node 31 may send the modified response message to the VPC gateway 103 through the VPC network 0, and the VPC gateway 103 may Figure 4a The session information 1 shown in (1) sends the modified response message to the client 1 on the first connection.

[0282] In this embodiment, when the storage node 31 needs to send a response message to the client 1 through the first connection that has been established, the storage node 31 can use the above-mentioned reverse key1 to find the original client 1 (address is vni:cip1:cport1) that established the first connection, so as to facilitate sending the message to the client 1.

[0283] Similarly, when the above-mentioned client 1 needs to continue to send a request message to the storage node 31 on the first connection, the storage node 31 can query the flow table information of the received request message, and can determine that the message header of the request message can hit the Key part of the forward key1 in the flow table information, thereby modifying the content of the message header of the request message that hits the above-mentioned Key part to the Value part corresponding to the Key part in the forward key1, and then, the storage node 31 can distribute or process the modified message.

[0284] In this way, when the storage node receives a message sent by the client on the first connection, the storage node can perform address conversion on the message according to the forward key1 associated with the first connection, so that the address of the message can be converted from a virtual address to a corresponding physical address, so that the storage node can distribute or process the message after the address conversion.

[0285] In this embodiment, multiple computing nodes in the computing cluster 101 are connected to multiple VPC networks, resulting in different VPC networks for different tenants. When the IP addresses of the tenants' virtual instances are encoded in IPv4, the IP addresses of the virtual instances of different tenants may be the same, resulting in the problem that the physical IP address of the virtual instance cannot identify the virtual instance.

[0286] Then in this embodiment, after the client 1 actively establishes the first connection with the storage node 31 through the VPC gateway 103, the storage node 31 can determine the global physical IP address (for example, cip100) corresponding to the physical IP address (for example, cip1) of the client 1 connected to the VPC network 1, wherein the global physical IP address can identify the client 1 as the client 1 in the VPC network 1. In other words, cip100 can be used to identify vpc1:cip1. And, when the storage node 31 determines that the message received from the client 1 through the first connection (here is the lock request in S305) is a message of a preset type, the storage node 31 can use the mapping relationship between the physical IP address of the client 1 and the global physical IP address (here is the mapping between cip1 and cip100) to determine the mapping relationship between the virtual address of the client 1 and the global physical IP address (here is the mapping between vpc1:cip1 and cip100), thereby generating the forward key1 and reverse key1 related to the first connection (refer to the above Table 2a, Table 2b, or Figure 6a The forward key1 and the reverse key1 can express the address conversion relationship between the source end and the destination end of the first connection.

[0287] Then, after the storage node 31 generates the forward key1 and the reverse key1, when receiving a message from the client 1 through the first connection, the storage node 31 can convert the source address in the message from the virtual address to the global physical address according to the forward key1, and then process the message after the address conversion; in addition, after the storage node 31 generates the forward key1 and the reverse key1, when sending a message to the client 1 through the first connection, the storage node 31 can convert the destination address in the message from the global physical address to the virtual address according to the reverse key1, and then send the message after the address conversion. In this way, when the client's physical IP address cannot identify the client, the storage node 31 can use the forward key1 and reverse key1 related to the first connection to directly convert the virtual address of client 1 and the global physical address of the message related to the first connection, so as to determine whether the message is from or to be sent to client 1, without having to redetermine the global physical address of the source end (here is the client) of the message each time a message is received through the first connection, and without having to redetermine the virtual address of the destination end (here is the client) of the message each time a message is sent through the first connection. It is possible to eliminate the need to redetermine which virtual instance the message is from or to which the message is sent each time a message is sent and received through the first connection, thereby improving the sending and receiving efficiency and processing efficiency of messages between the storage node and client 1.

[0288] In this way, the storage node 31 of the present application can identify the received preset type of message (here is a lock request), and generate the flow table information (such as forward key1, reverse key1) required for the current connection (here is the first connection) and the next connection to be established with client 1 (here is the second connection) based on the message, so that the reverse key (such as reverse key1) in the flow table information can be used to convert the destination address of the message to be sent through the first connection (from the global physical address to the virtual address) to send the message to the designated client, and the forward key (such as forward key1) in the flow table information can be used to convert the source address of the message received through the first connection (from the virtual address to the global physical address), so that the storage node 31 can perform process distribution and other processing on the message after the address conversion.

[0289] Continue to refer to Figure 5a In the above S308b, the storage node 31 can use the message (here is the lock request) received from the previous connection (here is the first connection) established with the client 1 to generate the conversion relationship between the virtual address of the client 1 and the global physical address, such as forward key2 and reverse key2, which is required for the storage node 31 to actively establish the next connection (here is the second connection) with the client 1, so that the storage node 31 can actively establish the second connection with the client 1. And the storage node 31 can use the forward key2 and reverse key2 generated before establishing the second connection to directly convert the virtual address of the client 1 and the global physical address for the message related to the second connection, so as to quickly determine which client (here is the client 1) and which port the message is from or to be sent to, so as to quickly process the message. There is no need to redetermine the global physical address of the source end (here is the client) of the message each time a message is received through the second connection, nor is there a need to redetermine the virtual address of the destination end (here is the client) of the message each time a message is sent through the second connection. This can improve the efficiency of sending and receiving and processing messages on the second connection between the storage node and the client 1.

[0290] In this embodiment, when the storage node 31 generates the forward key2 and the reverse key2 related to the second connection to be established, Figure 4a As shown in (2), the purpose of the storage node 31 establishing the second connection is to send a message indicating the query lock notification port, which is a control message. The TCP protocol stipulates the port information used by the client and the storage node for transmitting control messages. For example, the port information is respectively the client's port 2 (represented by cport2) and the storage node's port 2 (represented by sport2). The above sport1 and cport1 are both port numbers for transmitting data messages stipulated by the TCP protocol.

[0291] In S308b, the storage node 31 can generate forward key2 and reverse key2 associated with the second connection according to the port number of the storage node (here sport2) and the port number of the client (here cport2) agreed in the protocol for transmitting control messages, the virtual IP address of client 1 (here vpc1:cip1) determined based on the above lock request, the global physical IP address of client 1 (here cip100), the physical IP address of storage node 1 (here sip1), the virtual IP address of storage node 1 (also sip1 here, or vpc0:sip1), and the mapping relationship between vpc1:cip1 and cip100.

[0292] like Figure 6a As shown, the forward key2 is represented by expression 3a.

[0293] vpc1:cip1:cport2+sip1:sport2-》cip100:cport2+sip1:sport2, expression 3a

[0294] Among them, the physical meaning of the forward key2 represented by the above expression 3a is shown in Table 3a.

[0295] The principle of the forward key2 shown in Table 3a is similar to the principle of the forward key1 shown in Table 2a above, and will not be repeated here.

[0296] Table 3a

[0297] Forward key2 Source IP Source port number Destination IP Destination port number Key part vpc1:cip1 cport2 sip1 or vpc0:sip1 sport2 Value cip100 cport2 sip1 sport2

[0298] like Figure 6a As shown, the reverse key2 is represented by expression 3b.

[0299] sip1:sport2+cip100:cport2-》sip1:sport2+vpc1:cip1:cport2, expression 3b

[0300] The physical meaning of the reverse key2 shown in the above expression 3b is shown in Table 3b.

[0301] Table 3b

[0302] Reverse key2 Source IP Source port number Destination IP Destination port number Key part sip1 sport2 cip100 cport2 Value sip1 sport2 vpc1:cip1 cport2

[0303] The principle of the reverse key2 shown in Table 3b is similar to the principle of the reverse key1 shown in Table 2b above, and will not be repeated here.

[0304] In a possible implementation, the forward key1, reverse key1, forward key2, reverse key2 described in the present application, and the forward key3 and reverse key3 described later may all be contents in the flow table information of the storage node 31 of the present application.

[0305] exist Figure 4a (1) Figure 5a , Figure 6a Afterwards, refer to Figure 4a (2) Figure 5b , Figure 6b , to describe the process of the storage node 31 actively establishing a second connection with the client 1 using the reverse key2 generated by the lock request from the client 1 received in the previous connection. Among them, when the storage node 31 actively establishes the second connection with the client 1, the session information 2 related to the reverse key2 can be synchronized to the VPC gateway 103, so that the VPC gateway 103 can distribute the storage node 31's request to establish a connection to the client 1 according to the session information 2, thereby realizing the distribution of messages from the storage node to the client, thereby realizing the storage node 31 actively establishing a second connection with the client 1. When the storage node 31 actively establishes the second connection with the client 1, the reverse key2 can be used to determine which port of which client the connection request should be sent to. In the related art, when the storage node 31 establishes a connection with the client, it is not possible to generate the reverse key2, and thus it is impossible to determine which virtual instance to send the connection establishment request to.

[0306] In addition, this embodiment also describes how the storage node 31 converts the client's virtual address and the global physical address of the message related to the second connection according to the forward key2 and reverse key2 generated before establishing the second connection, thereby improving the sending and receiving efficiency and processing efficiency of the message related to the second connection.

[0307] In addition, this embodiment also describes how the VPC gateway 103 uses the session information 2 synchronized from the storage node 31 when establishing the second connection to distribute the message related to the second connection to which client or which storage node, so that the VPC gateway 103 can send the message related to the second connection to the port of the client or the port of the storage node corresponding to the second connection, and avoid sending the message to the corresponding port of other connections between the client 1 and the storage node 31.

[0308] Figure 5b An example is shown Figure 4a (2) The detailed implementation process of operation process 2 shown and the operation steps of the method of the present application related to operation process 2.

[0309] Figure 6bAn example is shown Figure 5b The process shown shows the message header of the message, and the schematic contents of the forward key3 and the reverse key3 related to the third connection to be established.

[0310] First, combined with Figure 3a and Figure 4a , please refer to Figure 5b and Figure 6b ,like Figure 5b As shown, the Figure 5b S400 to S411 can be Figure 5a The operations after the process, such as Figure 5b As shown, in Figure 5a After the steps shown, the process of the method of the present application may further include the following steps:

[0311] S400: Modify the initial establishment request of the second connection according to the reverse key2.

[0312] As mentioned above, the storage node 31 uses physical addresses to represent the source and destination addresses of the message. Figure 6b As shown, the message header of the initial establishment request of the second connection to be established (the protocol number is not shown here) is represented by sip1:sport2->cip100:cport2. Among them, in the schematic expression of the message header in each embodiment of the present application, the left side of "->" represents the source IP and the source port number, and the right side of "->" represents the destination IP and the destination port number.

[0313] Table 4a is a schematic diagram showing the structure of a message header of the initial establishment request of the second connection.

[0314] The message header is represented by sip1:sport2->cip100:cport2.

[0315] Table 4a

[0316] Source IP Source port number Destination IP Destination port number sip1 or vpc0:sip1 sport2 cip100 cport2

[0317] Then the storage node 31 can use the source IP, source port number, destination IP, and destination port number in the message header of the initial establishment request to query the flow table information and determine whether the values ​​of the above four types of information in the message header hit the Key part in the flow table information. As shown in the above Table 3b, the values ​​of the four items in the Key part of the reverse key2 shown in Table 3b are the same as the values ​​of the four information in the message header of the above initial establishment request. The storage node 31 can determine that the initial establishment request hits the reverse key2, and can modify the values ​​of the four types of information in the initial establishment request that match the Key part in the reverse key2 to the values ​​of the four items in the Value part of the corresponding reverse key2. In this way, Figure 6b As shown, the message header in the modified initial establishment request (which can be called the second connection establishment request) in S401a is indicated by sip1:sport2->vpc1:cip1:cport2, wherein the source IP in the message header is sip, the source port number is sport2, the destination IP is vpc:cip1, and the destination port number is cport2.

[0318] S401a, the storage node 31 sends a request to establish a second connection to the VPC gateway 103.

[0319] Reference Figure 5b , the storage node 31 can send the modified initial establishment request (also called the second connection establishment request) to the VPC gateway 103 through the VPC network 0.

[0320] Before the storage node 31 of the present application establishes the second connection with the client, Figure 5a S308b shown in FIG. 1 generates a reverse key 2 for establishing a reverse connection in advance, which can be used in Figure 4a In the operation process 2 shown in (2), when the storage node 31 actively establishes a connection with the client 1, the reverse key 2 can be used to determine which port of which client the connection request should be sent to. In the related art, when the storage node 31 establishes a connection with the client, the reverse key 2 cannot be generated, and thus it is impossible to determine which virtual instance to send the connection establishment request to.

[0321] S401b, the storage node 31 sends the session information 2 related to the reverse key2 to the VPC gateway 103.

[0322] Among them, as shown in 4a(2), the session information 2 can be represented by sip1:sport2—vpc1:cip1:cport2, and the session information 2 can express the mapping relationship between the virtual address of the second connected storage node and the virtual instance, here is the mapping relationship between the storage node 31 with a physical IP of sip1 and a port number of sport2 and the client 1 with a virtual IP of vpc1:cip1 and a port number of cport2.

[0323] Of course, in some embodiments, the session message 2 related to the second connection synchronized by the storage node 31 to the VPC gateway 103 may also be the above-mentioned reverse key2 and / or forward key2.

[0324] S401a and S401b may be executed separately or combined in a message, which is not limited here.

[0325] S402 , VPC gateway 103 allocates client 1 to the request to establish the second connection according to session information 2 .

[0326] In the related art, when a storage node initiates a connection establishment request to a virtual instance, the VPC gateway is not configured with an allocation strategy for allocating computing nodes or virtual instances to requests from the storage node, so that the corresponding virtual instance cannot be allocated to the storage node's connection establishment request, and the reverse connection from the storage node to the virtual instance in the computing node cannot be achieved.

[0327] In the embodiment of the present application, before the storage node 31 establishes a connection with the client, a reverse key 2 is generated in advance, and the reverse key 2 can be used to perform address conversion on the connection request of the storage node 31, specifically, from a physical address to a virtual address. Then, the storage node 31 can send the second connection establishment request after the address conversion to the VPC gateway 103, and synchronize the session information 2 related to the reverse key 2 to the VPC gateway 103. Then, when the VPC gateway 103 distributes the second connection establishment request received from the storage node 31 to the client, it can determine the source IP (here is sip1) and the source port number (here is sport2) in the second connection establishment request, and match them with the session information 2, so as to use the synchronized session information 2 to take the client 1 with the corresponding virtual address vpc1:cip1:cport2 as the object to establish a connection with the storage node 31 with the physical address sip1:sport2.

[0328] Optionally, the VPC gateway 103 may store the session information 2 synchronized by the storage node 31 .

[0329] In this way, after the storage node 31 actively establishes the second connection with the client 1, the VPC gateway 103 can reuse the stored session information 2 related to the second connection to forward the message sent from the client 1 through the second connection to the corresponding port of the storage node 31, and forward the message sent from the storage node 31 through the second connection to the response port of the client 1. It is ensured that the messages of the same connection can be distributed by the VPC gateway 103 to the accurate ports at both ends of the connection.

[0330] S403, VPC gateway 103 forwards the request to establish the second connection to client 1.

[0331] Among them, VPC gateway 103 can distribute the second connection establishment request matching session information 2 to port 1 (port number is cport1) of client 1 with virtual IP vpc1:cip1 according to session information 2. In this way, after VPC gateway 103 receives the request from the storage node side, it can also use the session information synchronized by the storage node side to determine which client the request should be distributed to, thereby realizing the reverse connection from the storage node to the client.

[0332] S404: The second connection between the client 1 and the storage node 31 is established successfully.

[0333] Among them, the second connection is the connection between cport2 of client 1 with physical IP address cip1 in VPC network 1 and sport2 of storage node 31 with physical IP address sip1 in VPC network 0.

[0334] S405: The storage node 31 modifies the first message for querying the lock notification port on the second connection according to the reverse key2 to obtain a second message.

[0335] After the second connection is successfully established, the storage node 31 may generate a first message to be sent to the client 1 (whose global physical address is represented by cip100:cport2) for querying the lock notification port.

[0336] like Figure 6b As shown, the message header of the first message is represented by sip1:sport2->cip100:cport2 (the protocol number is not shown here). Among them, in the schematic expression of the message header in each embodiment of the present application, the left side of "->" represents the source IP and source port number, and the right side of "->" represents the destination IP and destination port number.

[0337] The structural diagram of the message header of the first message can be referred to the above Table 4a, which will not be repeated here.

[0338] In S405, the storage node 31 can use the source IP, source port number, destination IP, and destination port number in the message header of the first message to query the flow table information and determine whether the values ​​of the above four types of information in the message header hit the Key part in the flow table information. As shown in the above Table 3b, the values ​​of the four table items in the Key part of the reverse key2 shown in Table 3b are the same as the values ​​of the four information in the message header of the above first message. The storage node 31 can determine that the first message hits the reverse key2, and can modify the values ​​of the four types of information in the first message that match the Key part in the reverse key2 to the values ​​of the four table items in the corresponding Value part of the reverse key2. In this way, Figure 6bAs shown, the message header in the modified first message (which can be called the second message) in S406 is indicated by sip1:sport2->vpc1:cip1:cport2, wherein the source IP in the message header is sip, the source port number is sport2, the destination IP is vpc:cip1, and the destination port number is cport2.

[0339] S406 , the storage node 31 sends a second message for querying the lock notification port to the VPC gateway 103 , and the VPC gateway 103 forwards the second message to the client 1 according to the session information 2 .

[0340] The storage node 31 may send the second message after performing address conversion (from a physical address to a virtual address) using the reverse key2 to the VPC gateway 103 on the established second connection.

[0341] VPC gateway 103 can match the message header of the second message with the local session information. VPC gateway 103 can determine the source IP (here is sip1), source port number (here is sport2), destination IP (here is vpc1:cip1) and destination port number (cport2) of the second message, and match them with session information 2, so as to use the synchronized session information 2 to take client 1 with the virtual address vpc1:cip1:cport2 in session information 2 as the distribution object of the second message, so as to forward the second message to port 2 of client 1 according to the session information 2.

[0342] S407 , client 1 sends a third message indicating the lock notification port ( cport3 ) to VPC gateway 103 , and VPC gateway 103 forwards the third message to storage node 31 according to session information 2 .

[0343] Among them, client 1 can respond to the above-mentioned second message, carry the port information used for lock notification (here, port 3 of client 1, represented by cport3) in the third message, and send the third message to VPC gateway 103 on the above-mentioned second connection.

[0344] like Figure 6b As shown, the message header of the third message is represented by vpc1:cip1:cport2->sip1:sport2 (the protocol number is not shown here). Among them, in the schematic expression of the message header in each embodiment of the present application, the left side of "->" represents the source IP and the source port number, and the right side of "->" represents the destination IP and the destination port number. The message content of the third message may include information indicating cport3. That is to say, client 1 can reply to storage node 31 to notify it that cport3 of client 1 is the lock notification port.

[0345] Since VPC gateway 103 is synchronized from storage node 31 Figure 4a (2) shows session information 2, the VPC gateway 103 can determine that the third message received from the client 1 matches the session information 2, and thus distribute the third message to the port 2 (represented by sport2) of the storage node 31 according to the session information 2.

[0346] In this way, the VPC gateway 103 side stores the session information 2 synchronized to the VPC gateway 103 by the storage node 31 when actively establishing the second connection. The session information 2 may include the mapping relationship between sip1:sport2 and vpc1:cip1:cport2. Then, when the client 1 replies to the storage node 31 on the second connection (for example, the third message mentioned above), the VPC gateway 103 may forward the third message to the destination address indicated by the third message according to the session information 2, which is sip1:sport2 here, and will not forward the third message to any port other than port 2 of the storage node 31, to ensure that after the storage node 31 reversely establishes the second connection, the messages sent from the client 1 on the second connection to the storage node 31 can be correctly forwarded to port 2 of the storage node 31 corresponding to the second connection, so that the messages on the same connection can be distributed by the VPC gateway 103 to the same port of the same storage node.

[0347] S408: The storage node 31 determines that the third message belongs to a preset type of message.

[0348] The execution principle and implementation details of this step are similar to Figure 5a The execution principle and implementation details of S307 in are similar and will not be repeated here.

[0349] After S408, in S409, the storage node 31 modifies the third message on the second connection according to the forward key2 to obtain a fourth message.

[0350] After receiving the third message, the storage node 31 queries each forward key in the flow table information, and can determine that the message header of the third message hits the Key part of the forward key2 in the flow table information, thereby modifying the content of the message header of the third message that hits the above Key part to the Value part corresponding to the Key part in the forward key2. Figure 6b As shown, the message header in the third message (which can be called the fourth message) modified in S408 is indicated by cip100:cport2->sip1:sport2, wherein the source IP in the message header is cip100, the source port number is cport2, the destination IP is sip1, and the destination port number is sport2.

[0351] S410, the storage node 31 processes the fourth message and obtains the lock notification port cport3.

[0352] The storage node 31 may process the fourth message to obtain the message content in the fourth message, which is the lock notification port cport3.

[0353] S411, the storage node 31 generates a forward key3 and a reverse key3 related to the third connection based on cport3.

[0354] When the storage node 31 determines that the third message is a message of a preset type, the lock notification port cport3 can be obtained based on the third message (for example, the fourth message obtained after modifying the message header), thereby obtaining the lock notification port cport3 based on cport3 and the source end address and the destination end address in the third message or the fourth message (refer to Figure 6b The message header of the third message and the message header of the fourth message shown in FIG. 4 are used to generate a forward key3 and a reverse key3 related to the third connection to be established.

[0355] like Figure 6b As shown, the forward key3 is represented by expression 4a.

[0356] vpc1:cip1:cport3+sip1:sport2-》cip100:cport3+sip1:sport2, expression 4a

[0357] Among them, the physical meaning of the forward key3 shown in the above expression 4a is shown in Table 5a.

[0358] The principle of the forward key3 shown in Table 5a is similar to that of the forward key2 shown in Table 3a, and will not be repeated here.

[0359] Table 5a

[0360] Forward key3 Source IP Source port number Destination IP Destination port number Key part vpc1:cip1 cport3 sip1 or vpc0:sip1 sport2 Value cip100 cport3 sip1 sport2

[0361] like Figure 6b As shown, the reverse key3 is represented by expression 4b.

[0362] sip1:sport2+cip100:cport3-》sip1:sport2+vpc1:cip1:cport3, expression 4b

[0363] The physical meaning of the reverse key3 shown in the above expression 4b is shown in Table 5b.

[0364] Table 5b

[0365] Reverse key3 Source IP Source port number Destination IP Destination port number Key part sip1 sport2 cip100 cport3 Value sip1 sport2 vpc1:cip1 cport3

[0366] The reverse key3 shown in Table 5b has a similar principle to the reverse key2 shown in Table 3b, and will not be described in detail here.

[0367] In this embodiment, multiple computing nodes in the computing cluster 101 are connected to multiple VPC networks, resulting in different VPC networks for different tenants. When the IP addresses of the tenants' virtual instances are encoded in IPv4, the IP addresses of the virtual instances of different tenants may be the same, resulting in the problem that the physical IP address of the virtual instance cannot identify the virtual instance.

[0368] In this embodiment, the storage node 31 generates the forward key2 and reverse key2 related to the second connection before establishing the second connection. Then, when the storage node 31 receives a message from the client 1 through the second connection, it can convert the source address in the message from the virtual address to the global physical address according to the forward key2, and then process the message after the address conversion; in addition, after the storage node 31 generates the forward key2 and reverse key2, when sending a message to the client 1 through the second connection, it can convert the destination address in the message from the global physical address to the virtual address according to the reverse key2, and then send the message after the address conversion. In this way, when the client's physical IP address cannot identify the client, the storage node 31 can use the forward key2 and reverse key2 related to the second connection to directly convert the virtual address of client 1 and the global physical address of the message related to the second connection, so as to determine whether the message is from or to be sent to client 1, without having to redetermine the global physical address of the source end (here is the client) of the message each time the message is received through the second connection, nor is there a need to redetermine the virtual address of the destination end (here is the client) of the message each time the message is sent through the second connection. It is possible to eliminate the need to redetermine which virtual instance the message is from or to which the message is sent each time the message is received and sent through the second connection, thereby improving the sending and receiving efficiency and processing efficiency of messages between the storage node and client 1.

[0369] In this embodiment, when the storage node 31 determines that the message received from the client 1 through the second connection (here, the third message in S407) is a message of a preset type, the storage node 31 can use the mapping relationship between the physical IP address of the client 1 and the global physical IP address (here, the mapping between cip1 and cip100) to determine the mapping relationship between the virtual address of the client 1 and the global physical IP address (here, the mapping between vpc1:cip1 and cip100), thereby generating the forward key3 and reverse key3 related to the third connection to be established next time. The forward key3 and reverse key3 can express the address conversion relationship between the source and destination ends of the third connection. Before actively establishing the third connection with the client 1, the storage node 31 generates the flow table information required for the third connection in advance, here the forward key3 and reverse key3, so as to facilitate the use of the flow table information to enable the storage node 31 to actively establish a connection with the client 1.

[0370] exist Figure 4a (2) Figure 5b , Figure 6b Afterwards, refer to Figure 4a (3) Figure 5c , Figure 6c , to describe the process of this embodiment.

[0371] The principle and effect of the implementation process of this embodiment are similar to those in the previous embodiment. Figure 5b The implementation principle and effect of the processes from S400 to S406 are the same. It is just that the messages processed by the storage nodes are different. The processing process of this embodiment is briefly introduced below. The specific implementation details can refer to the detailed description of the previous embodiment, which will not be repeated here.

[0372] Figure 5c An example is shown Figure 4a (3) The detailed implementation process of operation process 3 shown and the operation steps of the method of the present application related to operation process 3. Figure 6c An example is shown Figure 5c The schematic contents of the message header of the message in the process shown.

[0373] Combined with Figure 3a and Figure 4b , please refer to Figure 5c and Figure 6c ,like Figure 5c As shown, the Figure 5c S500 to S506 are shown in FIG. Figure 5a S301 to S308b shown and Figure 5b The operations after S400 to S411 shown in FIG. Figure 5c As shown, in Figure 5bAfter the steps shown, the process of the method of the present application may further include the following steps:

[0374] S500: Modify the initial establishment request of the third connection according to the reverse key3.

[0375] Table 6a is a schematic diagram showing the structure of a message header of the initial establishment request of the third connection.

[0376] The message header is represented by sip1:sport2->cip100:cport3.

[0377] Table 6a

[0378]

[0379]

[0380] S501a , the storage node 31 sends a request to establish a third connection to the VPC gateway 103 .

[0381] S501b, the storage node 31 sends the session information 3 related to the reverse key3 to the VPC gateway 103.

[0382] S502 , VPC gateway 103 allocates client 1 to the request to establish the third connection according to session information 3 .

[0383] Optionally, the VPC gateway 103 may store the session information 3 synchronized by the storage node 31 .

[0384] S503, VPC gateway 103 forwards the request to establish the third connection to client 1.

[0385] S504: The third connection between the client 1 and the storage node 31 is established successfully.

[0386] S505 , the storage node 31 modifies the fifth message on the third connection for notifying that the requested lock has been unlocked according to the reverse key 3 , to obtain a sixth message.

[0387] S506 , the storage node 31 sends a sixth message for notifying that the requested lock has been unlocked to the VPC gateway 103 , and the VPC gateway 103 forwards the sixth message to the client 1 according to the session information 3 .

[0388] In the embodiment of the present application, it is different from the previous embodiment. In the previous embodiment, the port number of the client 1 in the reverse key2 used by the storage node 31 when actively establishing the second connection with the client is the port number agreed upon by the protocol. In the embodiment of the present application, when the storage node 31 actively establishes the third connection with the client 1, the port number of the client 1 in the reverse key3 used is the port number actively obtained from the client 1 by the storage node 31 through the last second connection actively established with the client 1. The port of the client 1 with this port number can be used to transmit the lock release message (such as the sixth message in S506).

[0389] The storage node of this embodiment can use the previous connection actively established with client 1 to obtain the address information required when it actively establishes the next connection with client 1, thereby ensuring that the next connection established can be used to transmit lock release messages, avoiding the situation where the established connection cannot be used to transmit target information (such as lock release messages).

[0390] Similarly, in some scenarios, when client 1 replies to storage node 1 on the third connection, storage node 1 can determine that the message header can hit forward key 3, and thus adjust the source address of the message according to forward key 3 (from virtual address to physical address), and then perform process distribution and other processing on the adjusted message. The specific details will not be repeated here. The method of using forward key 3 is similar to that of forward key 2 and forward key 1.

[0391] In some embodiments, when the storage node 31 establishes the second connection or the third connection, the session message synchronized to the VPC gateway 103 may also be the forward key2 and reverse key2 associated with the second connection, or the forward key3 and reverse key3 associated with the third connection.

[0392] For example, refer to Figure 6a and Figure 6b , since the address of the storage node is the same between the forward key and the reverse key corresponding to the same connection. Taking the second connection as an example, after the second connection is actively established by the storage node 31 using the reverse key2, the VPC gateway 103 can use the forward key2 to forward the message of port 2 of the client 1 to port 2 of the storage node 31 corresponding to the second connection, and will not send it to other ports of the storage node 31. In this way, after the storage node 31 establishes a reverse connection, the subsequent messages of the client 1 on the connection can be distributed to the same storage node by the VPC gateway 103.

[0393] It should be understood that in the above Example 1, the storage node supports information parsing of the VPC network as an example. In other words, the storage node supports removing the vpcID in the received message to determine the physical IP address of the client.

[0394] In the above example 1, before actively establishing a connection with the client 1, the storage node 31 of the present application can use the message received from the connection that has been established with the client 1 to generate the flow table information required for the next connection to be actively established. The flow table information may include the mapping between the virtual address vpc1:cip1 of the client 1 and the physical address (here, the global physical IP address cip100). Therefore, when the storage node 31 initiates a request to establish a connection, the physical address of the client 1 in the request can be converted into a virtual address according to the mapping in the flow table information, and then the request is sent; and the storage node 31 can send the mapping between the virtual address of the client 1 related to the connection and the virtual address (or physical address) of the storage node 31 to the VPC gateway 103 as session information.

[0395] In this way, when the storage node actively establishes a connection with the client 1, the VPC gateway 103 can forward the message of the corresponding storage node according to the session message related to the connection synchronized from the storage node 31, thereby realizing the reverse connection of the storage node to the client and realizing the message forwarding after the reverse connection.

[0396] In the above example 1, after the storage node 31 actively establishes a connection with the client 1 (for example, the second connection and the third connection mentioned above), the storage node 31 can identify the message to be sent or received as the message on the connection (for example, the request message of the client 1 and the response message of the storage node 31) by querying the forward key and reverse key related to the corresponding connection, so as to facilitate the request message and response message on the connection to be distributed to the same process for processing. Among them, the storage node 31 can distribute messages (for example, request messages and response messages) of different connections (for example, the first connection, the second connection, and the third connection are different connections) to different processes for processing.

[0397] For example, after the above-mentioned second connection is successfully established, the client 1 sends a message to the storage node 31 on the second connection, then the storage node 31 can determine that the received message hits the forward key2, indicating that the message is a message on the second connection corresponding to the reverse key2, then the storage node 31 can use the forward key2 to modify the source address of the message from vpc1:cip1:cport2 to cip100:cport2, and distribute the modified message to the process related to the second connection (for example, process 1) for processing. When the storage node 31 sends a message to the client 1 on the second connection, the message can hit the reverse key2, indicating that the message is a message on the second connection corresponding to the reverse key2, then the storage node 31 can use the reverse key2 to modify the destination address of the message from cip100:cport2 to vpc1:cip1:cport2, and distribute the modified message to the process related to the second connection (for example, the above-mentioned process 1) for processing.

[0398] Example 2

[0399] The implementation process, principle and effect of Example 2 are mostly the same as those of Example 1 above. The difference is that in Example 2, Figure 3a The virtual address of the virtual instance in each computing node in the computing cluster 101 shown can be encoded in IPv6. For example, the virtual address vpc1:cip1 of the virtual instance 1 running in the computing node 11 of tenant A is encoded in IPv6. In this way, the virtual addresses of the virtual instances of different tenants are different. Among them, the virtual address may include the physical IP address of the virtual instance 1 (represented by cip1) and the ID of the VPC network 1 to which the virtual instance 1 belongs (represented by vpc1).

[0400] In this way, the virtual address of the virtual instance encoded in IPv6 can identify the virtual instance, and the storage node 31 can use the virtual address of the source in the message from the client 1 to identify the client 1 without converting the physical IP address of the client 1 into a global physical IP address to identify the client 1.

[0401] Since the virtual address of client 1 can be used to uniquely identify client 1 inside storage node 31, different from example 1, in example 2, storage node 31 does not need to generate forward key 1 to forward key 3, and reverse key 1 to reverse key 3, nor does it need to use the corresponding forward key and the corresponding reverse key to modify the message of the relevant connection (specifically, the conversion from virtual address to physical address). Because the other processes of example 2 are similar to example 1.

[0402] However, in this example 2, the storage node 31 can still use the message received from the previous connection with the client 1 to generate session information related to the next connection actively established by the client 1, such as session information 2 related to the second connection, or session information 3 related to the third connection to synchronize to the VPC gateway 103.

[0403] Thus, in this example 2, before the storage node 31 establishes an active connection with the client 1, it is not necessary to generate a mapping between the virtual address of the client 1 and the global physical address (such as the above-mentioned forward keys and reverse keys). Instead, it is only necessary to generate an address mapping relationship between the storage node 31 and the client 1 related to the connection to be established (such as the above-mentioned session information 2 and session information 3). This can reduce the address conversion operations of the storage node 31, improve the speed at which the storage node actively establishes a connection with the client, and improve the storage node's processing efficiency for messages received from or sent to the client.

[0404] Example 3

[0405] The implementation process, principle and effect of Example 3 are similar to those of Example 1 above. Figure 3b As shown, the computing cluster 101 and the storage cluster 102 are not connected by Figure 3a Instead of interacting via the TCP protocol shown in the figure, the RDMA protocol is used to interact through the VPC network, which does not pass through the VPC gateway 103.

[0406] Different from Example 1 above, in Example 3, the interactions between the storage node 31 and the client 1 do not go through the VPC gateway 103. Moreover, when the storage node 31 actively establishes a connection with the client 1, there is no need to synchronize the session message generated in advance to the VPC gateway 103. The storage node 31 only needs to establish a connection with the client 1 according to the session message.

[0407] In this way, when the computing cluster 101 and the storage cluster 102 interact through the RDMA protocol, they do not pass through the VPC gateway in the VPC network (therefore, Figure 3b Not shown in Figure 3a The VPC gateway 103 shown, or the VPC network may not have a VPC gateway deployed therein), enables direct interaction between the computing cluster 101 and the storage cluster 102 through the RDMA protocol.

[0408] In the direct access mode, both the storage cluster 102 and the computing cluster 101 support the RDMA protocol, so that the address information of both parties is transparent to each other. In other words, the storage node and the virtual instance running in the computing cluster 101 can each determine the destination address of their message, without the need for the VPC gateway to distribute the destination of their message. In order to enable the storage node 31 to actively establish a connection with the client 1 and actively send a message on the connection to provide information that the access lock of the target file has been released, the storage node and the client can bypass the VPC gateway 103 when interacting, but directly visit each other through the RDMA protocol, thereby meeting the high-speed access of multiple tenants to the data in the storage cluster 102 in the cloud scenario, improving data access performance, and solving the problem of the storage node actively connecting to the virtual instance in the computing cluster 101.

[0409] Example 4

[0410] Example 4 may be a combination of the above-mentioned Example 2 and Example 3. In Example 4, if Figure 3a The virtual address of the virtual instance in each computing node in the computing cluster 101 shown can be encoded in IPv6, and the storage cluster 102 communicates with the computing cluster 101 in the VPC network through the RDMA protocol without passing through the VPC gateway.

[0411] In this example 4, before the storage node 31 actively establishes a connection with the client 1, it is not necessary to generate a mapping between the virtual address of the client 1 and the global physical address (such as the above-mentioned forward keys and reverse keys), nor is it necessary to synchronize the address mapping relationship between the storage node 31 and the client 1 (such as the above-mentioned session information 2 and session information 3) related to the connection to be established to the VPC gateway when the storage node 31 actively establishes a connection with the client 1. This can not only reduce the address conversion operations of the storage node 31, but also improve the speed at which the storage node actively establishes a connection with the client, as well as improve the processing efficiency of the messages received from the client or sent to the client. Moreover, the storage node 31 connects and accesses the client 1 through the RDMA protocol, which can improve the data access performance and meet the high-speed access requirements of a large number of tenants to the data of the storage node.

[0412] Example 5

[0413] In the above examples 1 to 4, the virtual instances in the storage cluster 102 and the computing cluster 101 all use the NFS V3 protocol to meet the shared access requirements of multiple tenants of the computing nodes to the same file directory in the storage nodes.

[0414] The implementation process, principles and effects of this Example 5 (specifically including Examples 5.1 to 5.4) are the same as most of the contents of Examples 1 to 4 above, except that the application scenario of Examples 1 to 4 above is Scenario 1 above, which is to meet the shared access requirements of multiple tenants of computing nodes to the same file directory in the storage node.

[0415] The application scenario of this example 5 can be the scenario 2 described above, that is, in this example 5, the virtual instance in the computing cluster 101 can be a private client, and the virtual instance in the computing cluster 101 and the storage node in the storage cluster 102 can use a private protocol. In this example 5, the storage node 31 can actively access the client 1 (here, the private client) to synchronize the metadata of the target file to the client 1, so that the client 1 can use the metadata synchronized by the storage node 31 to access the target file.

[0416] The following describes some scenarios in which a storage node synchronizes metadata to a virtual instance (here, a private client) in a computing node.

[0417] Among them, Figure 1 The storage nodes in the storage cluster 102 shown can store data and manage and store metadata information of the data. In some scenarios, the storage nodes need to actively push the metadata information of the data to the client so that the client caches the metadata information.

[0418] For example, in scenario A, the storage location of the file data is changed from one storage node to another storage node in the storage cluster 102, so that the metadata information of the file data is updated. In order for the client to correctly access the data in the storage cluster 102, the storage node needs to actively notify the client of the updated metadata information of the file data, so that the client can use the updated metadata to access the file data from the storage cluster 102.

[0419] Scenario B, for example, the client frequently accesses a certain file data in the storage cluster 102. In order to speed up the reading speed of the file data stored in the storage cluster 102 by the client, the storage cluster 102 can push the file data frequently accessed by the client to the client. In order to push the file data, the storage cluster 102 needs to actively query the metadata information such as the directory space size and cache size of the client, so as to push the file data to the corresponding directory space of the client.

[0420] Of course, in the scenario where the client and storage node use private protocols for data storage and access, there may be other scenarios besides scenario A or scenario B, which requires the storage node to actively access the client to synchronize metadata information, which is not restricted here.

[0421] Then in the scenario described in Example 5 where both the client and the storage node use private protocols for data storage and access, in order to enable the storage node to actively access the client to synchronize metadata information, the storage node of the present application can still adopt a similar scheme to Examples 1 to 4 to enable the storage node to actively establish a connection with the private client, thereby enabling the storage node to actively send a message for synchronizing metadata information to the private client on the connection, so that the private client can use the synchronized metadata information to access the target file from the storage node, wherein the target file can be a file pre-existing on the storage node, or a file written to the storage node by other private clients, and there is no limitation here.

[0422] Specifically, in the application scenario of this Example 5, four implementation solutions, Examples 5.1 to 5.4, can be provided to solve the problem that under a private protocol, the storage node cannot actively send messages to the client to synchronize metadata information.

[0423] Example 5.1

[0424] The implementation process, principles and effects of this example 5.1 are mostly the same as those in the above example 1. The difference is that before the storage node 31 actively connects to the client 1, the message of the preset type received by using the first connection established with the client 1 is not a lock request under the NAS protocol, nor is it the first message for querying the lock notification port, but a message of a specified type under the private protocol.

[0425] Furthermore, in the scenario where the virtual instance is a private client, in Example 5.1, the storage node 31 only needs to actively establish a connection with the client 1 once, and can use the actively established connection to push the metadata of the target file to the client 1, without actively establishing two connections. The port number of the client 1 determined when actively establishing the connection can be the port number for transmitting metadata agreed upon by the protocol, and does not need to be obtained from the client 1.

[0426] In this way, the data center network of the present application supports the deployment of private clients in the computing cluster 101, and the storage nodes in the storage cluster 102 can actively establish a connection with the private clients. Through the actively established connection, the storage nodes can synchronize the metadata information required for the private clients to access the target files to the private clients, such as the metadata information of the target files that the private clients access frequently, or the metadata information that has changed, etc. In this way, the private clients can use the synchronized metadata to quickly or accurately access the target files that are accessed frequently or whose metadata has changed.

[0427] Example 5.2

[0428] The implementation process, principles and effects of this Example 5.2 are mostly the same as those in the above Example 2. The difference between Example 5.2 and Example 2 is the same as the difference between Example 5.1 and Example 1 described in the previous embodiment, which is mainly reflected in the application scenario being a private protocol, and will not be repeated here.

[0429] In this example 5.2, the computing cluster 101 supports the deployment of private clients, and the virtual address of the private client is encoded in IPv6. Before the storage node 31 establishes an active connection with the client 1, it is not necessary to generate a mapping between the virtual address of the client 1 and the global physical address (such as the above-mentioned forward keys and reverse keys). It only needs to generate the address mapping relationship between the storage node 31 and the client 1 related to the connection to be established (such as the above-mentioned session information 2 and session information 3), thereby reducing the address conversion operations of the storage node 31, improving the speed at which the storage node actively establishes a connection with the private client, and improving the storage node's processing efficiency of messages received from or sent to the client.

[0430] Example 5.3

[0431] The implementation process, principles, and effects of this Example 5.3 are mostly the same as those of the above Example 3. The difference between Example 5.3 and Example 3 is the same as the difference between Example 5.1 and Example 1 described in Example 5.1, which is mainly reflected in the application scenario of a private protocol. The details will not be repeated here.

[0432] In this example 5.3, the computing cluster 101 supports the deployment of private clients, and the interactions between the storage node 31 and the client 1 of the private protocol do not go through the VPC gateway 103. In addition, when the storage node 31 actively establishes a connection with the client 1 of the private protocol, there is no need to synchronize the pre-generated session message to the VPC gateway 103. The storage node 31 only needs to establish a connection with the client 1 of the private protocol according to the session message. In the scenario where the private client is deployed in the computing node, the access performance of the private client to the data of the storage node can be improved.

[0433] Example 5.4

[0434] The implementation process, principles, and effects of this Example 5.4 are mostly the same as those of the above Example 4. The difference between Example 5.4 and Example 4 is the same as the difference between Example 5.1 and Example 1 described in Example 5.1, which is mainly reflected in the application scenario of a private protocol. The details will not be repeated here.

[0435] In this example 5.4, the computing cluster 101 supports the deployment of private clients. Before the storage node 31 actively establishes a connection with the client 1 (a private client in this example 5.4), it is not necessary to generate a mapping between the virtual address of the client 1 and the global physical address (such as the above-mentioned forward keys and reverse keys), nor is it necessary to synchronize the address mapping relationship between the storage node 31 and the client 1 (such as the above-mentioned session information 2 and session information 3) related to the connection to be established to the VPC gateway when the storage node 31 actively establishes a connection with the client 1. This can not only reduce the address conversion operations of the storage node 31, but also improve the speed at which the storage node actively establishes a connection with the client, and improve the processing efficiency of the messages received from or sent to the private client. Moreover, the storage node 31 connects and accesses the private client through the RDMA protocol, which can improve the data access performance of the private client to the storage cluster 102.

[0436] Example 6

[0437] The implementation process, principles, and effects of this Example 6 are mostly the same as those of Example 2 or Example 5.2 above. The difference between Example 6 and Example 2 or Example 5.2 above is that the network for communication between the computing nodes and the storage nodes in Example 2 or Example 5.2 above is a virtual network (such as a VPC network), while in this Example 6, the network for communication between the computing nodes and the storage nodes is a physical network.

[0438] When the number of tenants in the computing cluster is small, such as Figure 1 The computing cluster 101 and the storage cluster 102 shown may be connected via a physical network, that is, the service network for interaction between computing nodes and storage nodes may be a physical network, in which the symmetric gateway of the present application may be deployed.

[0439] In Example 6, different from the above Example 2 or Example 5.2, in Example 6, the computing nodes and storage nodes interact through a physical network rather than a virtual network, so the physical IP addresses of the virtual instances of different tenants of the computing cluster 101 are different, and each virtual instance can be identified.

[0440] Therefore, different from the above example 2 or example 5.2, in this example 6, the storage node 31 identifies the client 1 with the physical address of the client 1. In this example 6, before the storage node 31 establishes an active connection with the client 1, it is not necessary to generate a mapping between the virtual address of the client 1 and the global physical address (such as the above-mentioned forward keys and reverse keys). It only needs to generate a mapping relationship between the physical addresses of the storage node 31 and the client 1 related to the connection to be established (a kind of session information), thereby reducing the address conversion operation of the storage node 31, and improving the speed of the storage node actively establishing a connection with the client, as well as improving the storage node's processing efficiency of the message received from the client or sent to the client. And the storage node 31 can use the message received by the previous connection established with the client 1 before the connection is established to generate the above-mentioned session information for establishing this connection. In a scenario with fewer tenants, when there is a gateway that interacts between the computing node and the storage node, the storage node can realize active access to the computing node.

[0441] For the storage node 31 in the above examples 1 to 6, Figure 7 The structure of the storage node 31 is shown as an example. Figure 7 The introduction is similar to that of , so I will not repeat it here.

[0442] like Figure 7 As shown, the storage node 31 may include but is not limited to: a central processing unit (CPU) and a data processing unit (DPU). For example, the CPU and the DPU may be connected via a PCIe (peripheral component interconnect express) port.

[0443] The CPU may include but is not limited to: Network Attached Storage Server (NAS Server).

[0444] The DPU may include, but is not limited to: a data processing logic unit and a data control logic unit.

[0445] For example, the NPU and SPU may be implemented as software modules.

[0446] like Figure 7 As shown, the NAS Server may include a message type configuration module 10 .

[0447] The NPU may include but is not limited to: a message type matching module 11 , a flow table configuration module 12 , and a message modification module 13 .

[0448] The SPU may include but is not limited to: a flow table matching module 14 and a message processing module 15 .

[0449] Among them, the message type configuration module 10 can be used to configure the message type matching module 11 with keywords (such as address offset) and values ​​(such as encoding information) of a preset type of message through a configuration management program or a configuration file, so that the message type matching module 11 can be configured with keywords and values ​​of a preset type of message for identification of the message type.

[0450] The message type matching module 11 can be used to parse the message received from the network or to be sent according to the pre-configured keywords and values ​​of the preset type of message, and match the above keywords and values ​​on the parsed message to determine whether the message is a preset type of message.

[0451] The flow table configuration module 12 can be used to configure the flow table information (such as the various forward keys, reverse keys, etc. described above) for the flow table matching module 14 based on the message when the message type matching module 11 determines that the corresponding message is a message of a preset type. In this way, the flow table matching module 14 can be configured with flow table information.

[0452] The message matching module 14 can be used to determine whether the message hits the flow table according to the configured flow table information when the message type matching module 11 determines that the corresponding message is a message of a preset type;

[0453] The message modification module 13 can be used to modify the address in the message according to the hit flow table information when the message matching module 14 determines that the corresponding message hits the flow table, and send the modified message to the message processing module 15.

[0454] The message processing module 15 may be used to receive messages from the network or from the message modification module 13, and to process the received messages and then report the processed messages to the NAS Server for processing.

[0455] It should be understood that Figure 7 The schematic diagram of the framework structure of the storage node 31 is only shown for exemplary purposes. Each storage node in the storage cluster 102 of the present application may have more or fewer components than those shown in the figure, may combine two or more components, or may have different component configurations. Figure 7 The various components shown in the EMBODIMENTS 2000 may be implemented in hardware, software, or a combination of hardware and software, including one or more signal processing and / or application specific integrated circuits.

[0456] Figure 7The schematic diagram of the framework structure of the storage node 31 in FIG. 3 is taken as an example to describe the storage node 31 using the NAS protocol. In other embodiments, the storage node 31 may also be a storage node of a private protocol, and its structure may be similar to Figure 7 There are differences, which are not limited here.

[0457] The functions and effects achieved by the storage node 31 are similar to the functions and effects of the storage node 31 described in the method embodiments of the above-mentioned implementation modes, and are not described in detail here.

[0458] In a possible implementation, the present application provides a storage node. Figure 8a The structural diagram of the storage node 802 is shown as an example. The storage node 802 is used to communicate with multiple computing nodes through a virtual network, and the first virtual instance is running in the multiple computing nodes. The storage node 802 includes: a storage module 8021, which is used to pre-store target files, or receive and store target files from the multiple computing nodes 801; a first connection establishment module 8022, which is used to actively request to establish a first connection with the first virtual instance; a first sending module 8023, which is used to send a first message to the first virtual instance through the first connection, and the first message is used to provide target information for accessing the target file; an access module 8024, which is used to access the target file in response to receiving a second message sent by the first virtual instance based on the first message.

[0459] In a possible implementation, the target information is used to indicate that the access lock to the target file has been released; or, the target information is used to provide metadata of the target file, wherein different files have different metadata.

[0460] In a possible implementation, the storage node 802 also includes: a first receiving module, used to receive a third message from the first virtual instance through a second connection; and the first connection establishment module 8022, specifically used to actively request to establish a first connection with the first virtual instance based on the third message.

[0461] In one possible implementation, the multiple computing nodes 801 run the first virtual instances of multiple tenants, and the multiple computing nodes 801 running the first virtual instances of different tenants run in different virtual networks, and the target information is used to indicate that the access lock to the target file has been released.

[0462] In a possible implementation, the storage node 802 also includes: a second receiving module, used to receive a fourth message from the first virtual instance through a third connection, wherein the fourth message is used to provide information for requesting an access lock on the target file; a first determination module, used to determine, in response to the fourth message, that the access lock on the target file is occupied by the second virtual instance running in the multiple computing nodes 801; and the first connection establishment module 8022, specifically used to actively request to establish the first connection with the first virtual instance when it is determined that the access lock on the target file is released.

[0463] In a possible implementation, the storage node 802 also includes: a second connection establishment module, used to actively request to establish the second connection between the first virtual instance based on the fourth message when it is determined that the access lock of the target file is released; a second sending module, used to send a fifth message to the first virtual instance through the second connection, wherein the fifth message is used to query the port number of the target information; and the third message is used to provide the port number of the first virtual instance.

[0464] In a possible implementation, the multiple computing nodes 801 run the first virtual instances of multiple tenants, and the multiple computing nodes 801 running the first virtual instances of different tenants run in different virtual networks, and the storage node 802 also includes: a second determination module, used to determine the original IP address of the first virtual instance based on the third message; a third determination module, used to determine the global IP address corresponding to the original IP address, wherein the global IP address is used to identify the first virtual instance running in the virtual network; the first connection establishment module 8022 is specifically used to actively request to establish a first connection with the first virtual instance based on the mapping relationship between the original IP address and the global IP address.

[0465] In a possible implementation manner, the first sending module 8023 is specifically configured to send the first message to the first virtual instance through the first connection based on the mapping relationship.

[0466] In a possible implementation, the storage node 802 is used to interactively communicate with the multiple computing nodes in the virtual network through the RDMA protocol.

[0467] In a possible implementation, the present application provides a data center. Figure 8b For an exemplary structural diagram of a data center 800, please refer to Figure 8bThe data center 800 includes a plurality of computing nodes 801 and the storage nodes 802 described in the above embodiments, wherein the plurality of computing nodes 801 communicate with the storage nodes 802 through a virtual network. In addition, the data center 800 also includes a gateway 803 deployed in the virtual network, and the plurality of computing nodes 801 interact with the storage nodes 802 through the gateway 803. Figure 8b As shown, the storage node 802 also includes: a third sending module 8025, used to send the first session information to the gateway; the first connection establishment module 8022, specifically used to send the first connection establishment request to the gateway; the gateway 803 includes: a forwarding module 8031, used to forward the first connection establishment request to the first virtual instance based on the first session information.

[0468] The methods and effects achieved by the storage nodes and data centers of the above-mentioned embodiments are similar to the effects of the methods of the above-mentioned embodiments, and will not be repeated here.

[0469] Among them, the above modules can all be implemented by software, or can be implemented by hardware. Among them, the module is an example of a software functional unit, and the above module may include code running on a storage node. Among them, the storage node may be a physical host (storage device). Further, the above storage node may be one or more. For example, the storage module 8021 may include code running on multiple physical hosts. It should be noted that the multiple physical hosts used to run the code can be distributed in the same region (region) or in different regions. Furthermore, the multiple physical hosts used to run the code can be distributed in the same availability zone (AZ) or in different AZs, and each AZ includes a data center or multiple data centers with close geographical locations. Among them, usually a region can include multiple AZs.

[0470] Similarly, multiple physical hosts used to run the code can be distributed in the same VPC or in multiple VPCs. Usually, a VPC is set in a region. For cross-region communication between two VPCs in the same region and between VPCs in different regions, the above gateway needs to be set in each VPC to achieve interconnection between VPCs through the gateway.

[0471] As an example of a hardware functional unit, the module may include at least one storage device, such as a server, etc. Alternatively, the module may also be a device implemented by an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.

[0472] The multiple storage devices included in the above modules can be distributed in the same region or in different regions. The multiple storage devices included in the above modules can be distributed in the same AZ or in different AZs. Similarly, the multiple storage devices included in the above modules can be distributed in the same VPC or in multiple VPCs. The multiple storage devices can be any combination of storage devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.

[0473] It should be noted that, in other embodiments, the above modules can be used to execute Figure 5a to Figure 5c The corresponding steps in are performed to realize all the functions of the data center 800.

[0474] The present application also provides a storage device 900. Fig. 9 As shown, the storage device 900 includes: a bus 902, a processor 904, a memory 906 and a communication interface 909. The processor 904, the memory 906 and the communication interface 909 communicate with each other through the bus 902. The storage device 900 can be a server. It should be understood that the present application does not limit the number of processors and memories in the storage device 900.

[0475] The bus 902 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Fig. 9The bus 902 may include a path for transmitting information between various components of the storage device 900 (eg, the memory 906, the processor 904, and the communication interface 909).

[0476] The processor 904 may include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).

[0477] The memory 906 may include a volatile memory, such as a random access memory (RAM). The processor 904 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).

[0478] The memory 906 stores executable program codes, and the processor 904 executes the executable program codes to respectively implement the functions of the aforementioned storage module, the first connection establishment module, the first sending module, the access module, etc., thereby implementing the aforementioned access method, for example Figure 5a to Figure 5c That is, the memory 906 stores instructions for executing the access method.

[0479] The communication interface 909 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the storage device 900 and other devices or a communication network.

[0480] The embodiment of the present application also provides a storage device cluster. The storage device cluster includes at least one storage device. The storage device can be a server, such as a central server, an edge server, or a local server in a local data center.

[0481] like Fig.10 As shown, the storage device cluster includes at least one storage device 1000. The memory 1006 in one or more storage devices 1000 in the storage device cluster may store the same memory for executing the above (for example Figure 5a to Figure 5c The access method instructions shown.

[0482] In some possible implementations, the memory 1006 of one or more storage devices 1000 in the storage device cluster may also store partial instructions for executing the access method of the present application. In other words, the combination of one or more storage devices 1000 may jointly execute instructions for executing the access method.

[0483] It should be noted that the memory 1006 in different storage devices 1000 in the storage device cluster can store different instructions, which are respectively used to execute part of the functions of the data center. That is, the instructions stored in the memory 1006 in different storage devices 1000 can implement the functions of one or more modules of the aforementioned storage module, the first connection establishment module, the first sending module, the access module, etc.

[0484] In some possible implementations, one or more storage devices in the storage device cluster may be connected to one or more computing devices in the computing device cluster via a network, wherein the network may be a wide area network or a local area network, and the like. Fig.11 A possible implementation is shown. Fig.11 As shown, the computing device 1100A and the storage device 1100B are connected via a virtual network 1100C (e.g., VPC). In this type of possible implementation, the memory 1106 in the storage device 1100B stores instructions for executing the functions of the aforementioned storage module, the first connection establishment module, the first sending module, the access module, and other modules.

[0485] It should be understood that Fig.11 The functions of the computing device 1100A shown in FIG. 1100A may also be implemented by multiple computing devices 1100. Similarly, the functions of the storage device 1100B may also be implemented by multiple storage devices 1100.

[0486] The present application embodiment also provides another storage device cluster. The connection relationship between the storage devices in the storage device cluster can be similar to that of Fig. 9 and Fig.11 The connection mode of the storage device cluster is different in that the memory 1106 in one or more storage devices 1100 in the storage device cluster may store the same instructions for executing the above access method.

[0487] In some possible implementations, the memory 1106 of one or more storage devices 1100 in the storage device cluster may also store partial instructions for executing the access method. In other words, the combination of one or more storage devices 1100 may jointly execute instructions for executing the storage method.

[0488] It should be noted that the memory 1106 in different storage devices 1100 in the storage device cluster can store different instructions for executing some functions of the data center. That is, the instructions stored in the memory 1106 in different storage devices 1100 can implement the functions of one or more devices in the data center.

[0489] The present application also provides a computer program product including instructions. The computer program product may be a software or program product including instructions that can be run on a storage device or stored in any available medium. When the computer program product is run on at least one storage device, the at least one storage device executes the access method in the above embodiment.

[0490] The embodiment of the present application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that can be stored by a storage device or a data storage device such as a data center containing one or more available media. The available medium can be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk). The computer-readable storage medium includes instructions that instruct the storage device to execute the access method in the above embodiment.

[0491] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present invention, rather than to limit it. Although the present invention has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present invention.

Claims

1. An access method, characterized in that: The data center includes a plurality of computing nodes and storage nodes, the plurality of computing nodes run a first virtual instance, the plurality of computing nodes interact with the storage nodes through a virtual network, and the method includes: The storage node stores the target file; The storage node actively requests to establish a first connection with the first virtual instance; The storage node sends a first message to the first virtual instance through the first connection, where the first message is used to provide target information for accessing the target file; In response to receiving the second message sent by the first virtual instance based on the first message, the storage node accesses the target file.

2. The method according to claim 1, characterized in that: The target information is used to indicate that the access lock to the target file has been released; or, the target information is used to provide metadata of the target file, wherein different files have different metadata.

3. The method according to claim 1 or 2, characterized in that: The method further comprises: The storage node receives a third message from the first virtual instance through a second connection; The storage node actively requests to establish a first connection with the first virtual instance based on the third message.

4. The method according to claim 3, characterized in that The plurality of computing nodes run first virtual instances of a plurality of tenants, the plurality of computing nodes running first virtual instances of different tenants run in different virtual networks, and the target information is used to indicate that an access lock to the target file has been released.

5. The method according to claim 4, characterized in that The method further comprises: The storage node receives a fourth message from the first virtual instance through a third connection, wherein the fourth message is used to provide information requesting access lock on the target file; The storage node determines, in response to the fourth message, that the access lock of the target file is occupied by the second virtual instance running in the plurality of computing nodes; The first connection is a connection with the first virtual instance that is actively requested to be established when the storage node determines that the access lock of the target file is released.

6. The method according to claim 5, characterized in that The method further comprises: When the storage node determines that the access lock of the target file is released, the storage node actively requests to establish the second connection with the first virtual instance based on the fourth message; The storage node sends a fifth message to the first virtual instance through the second connection, wherein the fifth message is used to query the port number for notifying the target information; The third message is used to provide the port number of the first virtual instance.

7. The method according to any one of claims 1 to 2 and 4 to 6, characterized in that: The plurality of computing nodes interact with the storage node via a gateway in the virtual network, and the method further comprises: The storage node sends first session information to the gateway; The storage node sends a request to establish the first connection to the gateway; The gateway forwards the first connection establishment request to the first virtual instance based on the first session information.

8. The method according to any one of claims 1 to 2 and 4 to 6, characterized in that The multiple computing nodes interact with the storage node in the virtual network through a remote direct memory access (RDMA) protocol.

9. The method according to claim 3, characterized in that: The plurality of computing nodes run first virtual instances of a plurality of tenants, and the plurality of computing nodes running first virtual instances of different tenants run in different virtual networks, and the method further includes: The storage node determines the original IP address of the first virtual instance based on the third message; The storage node determines a global IP address corresponding to the original IP address, wherein the global IP address is used to identify the first virtual instance running in the virtual network; The storage node actively requests to establish a first connection with the first virtual instance based on the mapping relationship between the original IP address and the global IP address.

10. The method according to claim 9, characterized in that The method further comprises: The storage node sends a first message to the first virtual instance through the first connection based on the mapping relationship.

11. A storage node, characterized in that: The storage node is used to communicate with multiple computing nodes through a virtual network, the first virtual instance is run in the multiple computing nodes, and the storage node includes: A storage module, used for storing target files; A first connection establishment module, used for actively requesting to establish a first connection with the first virtual instance; A first sending module, configured to send a first message to the first virtual instance through the first connection, wherein the first message is used to provide target information for accessing the target file; An access module is used to access the target file in response to receiving a second message sent by the first virtual instance based on the first message.

12. The storage node according to claim 11, characterized in that: The target information is used to indicate that the access lock to the target file has been released; or, the target information is used to provide metadata of the target file, wherein different files have different metadata.

13. The storage node according to claim 11 or 12, characterized in that: The storage node also includes: A first receiving module, configured to receive a third message from the first virtual instance through a second connection; The first connection establishing module is specifically configured to actively request to establish a first connection with the first virtual instance based on the third message.

14. The storage node according to claim 13, characterized in that: The plurality of computing nodes run first virtual instances of a plurality of tenants, the plurality of computing nodes running first virtual instances of different tenants run in different virtual networks, and the target information is used to indicate that an access lock to the target file has been released.

15. The storage node according to claim 14, characterized in that: The storage node also includes: A second receiving module, configured to receive a fourth message from the first virtual instance through a third connection, wherein the fourth message is used to provide information requesting access lock on the target file; A first determining module, configured to determine, in response to the fourth message, that the access lock of the target file is occupied by a second virtual instance running in the plurality of computing nodes; The first connection establishing module is specifically configured to actively request to establish the first connection with the first virtual instance when it is determined that the access lock of the target file is released.

16. The storage node according to claim 15, characterized in that: The storage node also includes: a second connection establishing module, configured to actively request to establish the second connection with the first virtual instance based on the fourth message when determining that the access lock of the target file is released; A second sending module, configured to send a fifth message to the first virtual instance through the second connection, wherein the fifth message is used to query a port number for notifying the target information; The third message is used to provide the port number of the first virtual instance.

17. The storage node according to claim 13, characterized in that: The plurality of computing nodes run first virtual instances of a plurality of tenants, and the plurality of computing nodes running first virtual instances of different tenants run in different virtual networks, and the storage node further includes: A second determination module, configured to determine an original IP address of the first virtual instance based on the third message; a third determining module, configured to determine a global IP address corresponding to the original IP address, wherein the global IP address is used to identify the first virtual instance running in the virtual network; The first connection establishing module is specifically configured to actively request to establish a first connection with the first virtual instance based on a mapping relationship between the original IP address and the global IP address.

18. The storage node according to claim 17, characterized in that: The first sending module is specifically configured to send the first message to the first virtual instance through the first connection based on the mapping relationship.

19. The storage node according to any one of claims 11 to 12, characterized in that: The storage node is used to communicate with the multiple computing nodes in the virtual network through a remote direct memory access (RDMA) protocol.

20. A data center, comprising the storage node and computing node according to any one of claims 11 to 18, characterized in that: The data center further includes a gateway deployed in the virtual network, and the plurality of computing nodes interact with the storage nodes through the gateway; The storage module also includes: A third sending module, used for sending the first session information to the gateway; The first connection establishment module is specifically configured to send a request to establish the first connection to the gateway; The gateway comprises: A forwarding module is used to forward the establishment request of the first connection to the first virtual instance based on the first session information.

21. A storage node, characterized in that: The storage node comprises a processor and a memory, wherein the processor is configured to execute instructions stored in the memory, so that the storage node executes the method according to any one of claims 1 to 10.

22. A data center, characterized in that: The data center includes multiple computing nodes and storage nodes, a first virtual instance is run in the multiple computing nodes, the multiple computing nodes interact with the storage nodes through a virtual network, the storage nodes include a processor and a memory, the processor is used to execute instructions stored in the memory so that the storage node executes the method as described in any one of claims 1 to 10.

23. A computer-readable storage medium, characterized in that: The method comprises computer program instructions, which, when executed by a storage node, cause the storage node to perform the method according to any one of claims 1 to 10.

24. A computer program product comprising instructions, characterized in that When the instruction is executed by a storage node, the storage node is caused to perform the method according to any one of claims 1 to 10.

Citation Information

Patent Citations

  • Method and device for accessing desktop cloud virtual machine and desktop cloud controller

    CN107707622A

  • Input / output processing in a distributed storage node with rdma

    CN113287286A