A cluster expansion method, product, device and medium
By creating a virtual network card in a private cloud cluster and establishing a secure shell protocol tunnel, the problem that private cloud hosts and public cloud hosts cannot be interconnected in a weak network environment is solved, and cluster expansion and resource management are efficient.
Patent Information
- Application Number
- CN202411347877.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-09-26
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2044-09-26
AI Technical Summary
In a weak network environment, private cloud hosts and public cloud hosts cannot achieve two-way interconnection, resulting in the existing k8s cluster being unable to manage public cloud nodes and public cloud edge nodes being unable to join the cluster normally.
By creating the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, and establishing a secure shell protocol tunnel based on the public network Internet protocol address and virtual network card of the public cloud host, two-way communication between the public cloud host and the private cloud host is realized, and finally controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel.
It realizes two-way communication between public cloud hosts and private cloud hosts, solves the problem that private cloud clusters cannot manage public cloud nodes, reduces server management costs, and improves development efficiency.
Smart Images

Figure CN118890358B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of cloud technology, and in particular to a cluster expansion method, product, device and medium. Background Art
[0002] At present, artificial intelligence platforms are based on container cluster management systems (Kubernetes, k8s) for resource management and scheduling, building an efficient deep learning development environment for enterprises. Since the scale of platforms deployed in private clouds is limited and cannot meet the needs of temporary expansion of computing scale, temporarily purchasing servers on public cloud platforms is an economical and practical method.
[0003] However, there are problems with the network communication between private cloud and public cloud, such as the private cloud host has no fixed public Internet Protocol (IP), can only communicate with the public cloud host in one direction, and the network is unstable. These problems make the existing k8s cluster unable to manage public cloud nodes, and the public cloud edge nodes cannot join the cluster normally due to network restrictions.
[0004] In view of the above problems, how to solve the problem that the private cloud host and the public cloud host of the cluster cannot be interconnected in a two-way manner in a weak network environment is an urgent problem to be solved by technical personnel in this field. Summary of the invention
[0005] The purpose of the present invention is to provide a cluster expansion method, product, device and medium to solve the problem that the private cloud host and the public cloud host of the cluster cannot be interconnected in a bidirectional manner in a weak network environment.
[0006] In order to solve the above technical problems, the present invention provides a cluster expansion method, which is applied to a private cloud cluster; the method comprises:
[0007] When receiving a request from a public cloud host to join the private cloud cluster, obtaining a public Internet Protocol address of the public cloud host;
[0008] Creating a first virtual network card of the public cloud host and a second virtual network card of the private cloud host; wherein the private cloud host is the master node of the private cloud cluster;
[0009] Establishing a secure shell protocol tunnel between the public cloud host and the private cloud host based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host, and the second virtual network card of the private cloud host;
[0010] The public cloud host is controlled to join the private cloud cluster through a secure shell protocol tunnel.
[0011] On the one hand, the step of creating a first virtual network card of the public cloud host and a second virtual network card of the private cloud host includes:
[0012] Obtaining allocatable Internet Protocol address segments to be selected;
[0013] Preprocessing the to-be-selected Internet Protocol address segment to remove the allocated Internet Protocol addresses in the to-be-selected Internet Protocol address segment;
[0014] Based on the preprocessed selected Internet Protocol address segment, determine a first Internet Protocol address corresponding to the first virtual network card and a second Internet Protocol address corresponding to the second virtual network card respectively;
[0015] A first virtual network card is created according to the first Internet Protocol address, and a second virtual network card is created according to the second Internet Protocol address.
[0016] On the other hand, the establishing of a secure shell protocol tunnel between the public cloud host and the private cloud host based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host, and the second virtual network card of the private cloud host includes:
[0017] Based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, a secure shell protocol tunnel is established between the public cloud host and the private cloud host using secure shell protocol virtual private network technology;
[0018] Configuring policy routing based on the private cloud host to forward traffic accessing the first Internet Protocol address to the first virtual network card;
[0019] Policy routing is configured based on the public cloud host to forward traffic accessing the second Internet Protocol address to the second virtual network card.
[0020] On the other hand, before controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel, after establishing a secure shell protocol tunnel between the public cloud host and the private cloud host based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, the method further includes:
[0021] The relevant information of the public cloud host is saved in a database; wherein the relevant information of the public cloud host includes at least the name of the public cloud host, the public Internet Protocol address, the name of the first virtual network card and the corresponding first Internet Protocol address;
[0022] Monitor the status of the secure shell protocol tunnel according to the relevant information of the public cloud host in the database, and determine whether the secure shell protocol tunnel is successfully established;
[0023] If it is confirmed that the secure shell protocol tunnel is successfully established, then after a preset period, return to the step of monitoring the state of the secure shell protocol tunnel according to the relevant information of the public cloud host in the database to determine whether the secure shell protocol tunnel is successfully established;
[0024] If it is confirmed that the secure shell protocol tunnel establishment fails, return to the step of obtaining the public Internet Protocol address of the public cloud host.
[0025] On the other hand, monitoring the state of the secure shell protocol tunnel according to the relevant information of the public cloud host in the database to determine whether the secure shell protocol tunnel is successfully established includes:
[0026] Determine whether the second virtual network card of the private cloud host is operating normally;
[0027] If it is confirmed that the second virtual network card of the private cloud host is not operating normally, it is confirmed that the secure shell protocol tunnel establishment fails;
[0028] If it is confirmed that the second virtual network card of the private cloud host is operating normally, then obtaining relevant information of the public cloud host in the database to determine whether the first virtual network card and its corresponding first Internet Protocol address exist;
[0029] If it is confirmed that the first virtual network card and the first Internet Protocol address corresponding to it do not exist, it is confirmed that the secure shell protocol tunnel establishment fails;
[0030] If it is confirmed that the first virtual network card and its corresponding first Internet Protocol address exist, it is confirmed that the secure shell protocol tunnel is successfully established.
[0031] On the other hand, after confirming that the secure shell protocol tunnel establishment fails, the method further includes:
[0032] Determining whether the secure shell protocol tunnel is successfully re-established after a preset time;
[0033] If it is confirmed that the secure shell protocol tunnel is successfully re-established after the preset time, then the process ends;
[0034] If it is confirmed that the secure shell protocol tunnel is not successfully re-established after the preset time, an alarm message indicating that the secure shell protocol tunnel establishment timeout is output.
[0035] On the other hand, controlling the public cloud host to join the private cloud cluster through a secure shell protocol tunnel includes:
[0036] Obtain relevant information of the public cloud host; wherein the relevant information of the public cloud host includes at least the name of the public cloud host, the public Internet Protocol address, the name of the first virtual network card and the corresponding first Internet Protocol address;
[0037] Determining whether the public cloud host meets preset requirements for joining the private cloud cluster according to relevant information of the public cloud host;
[0038] If it is confirmed that the public cloud host does not meet the preset requirements for joining the private cloud cluster, prohibiting the public cloud host from joining the private cloud cluster;
[0039] If it is confirmed that the public cloud host meets the preset requirements for joining the private cloud cluster, the public cloud host is added to the private cloud cluster based on the cloud core of the private cloud host.
[0040] On the other hand, the cloud core based on the private cloud host adds the public cloud host to the private cloud cluster, including:
[0041] Adding the first Internet Protocol address of the public cloud host to the certificate of the cloud core of the private cloud host, and restarting the cloud core of the private cloud host;
[0042] Performing initialization operations on the public cloud host through a configuration management tool;
[0043] A command for joining the private cloud cluster is executed based on the public cloud host to add the public cloud host to the private cloud cluster.
[0044] On the other hand, after controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel, the method further includes:
[0045] Determine whether there is a training task currently being executed;
[0046] If it is confirmed that there is a training task currently being executed, the training task is scheduled to the public cloud host through the secure shell protocol tunnel.
[0047] On the other hand, after controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel, the method further includes:
[0048] Apply to create a target training task;
[0049] Determine whether the target training task is a distributed task;
[0050] If it is confirmed that the target training task is not a distributed task, the target training task is directly executed;
[0051] If it is confirmed that the target training task is a distributed task, a communication connection is established between the containers of all edge nodes in the private cloud cluster to execute the target training task through each edge node;
[0052] Among them, all edge nodes include the private cloud host and the public cloud host that has joined the private cloud cluster.
[0053] On the other hand, establishing a communication connection between containers of all edge nodes in the private cloud cluster includes:
[0054] Create container services corresponding to the containers of each edge node;
[0055] Inject the name of each container service into the container of the corresponding edge node through environment variables;
[0056] Parse the name of the container service of each edge node to obtain the container service Internet Protocol address of all containers;
[0057] A communication connection is established between containers of all edge nodes in the private cloud cluster based on each container service Internet Protocol address.
[0058] On the other hand, it also includes:
[0059] monitoring a deactivation instruction for the public cloud host;
[0060] When receiving a deactivation instruction for the public cloud host, disconnecting the secure shell protocol tunnel between the public cloud host and the private cloud host;
[0061] Reclaim allocated Internet Protocol resources.
[0062] In order to solve the above technical problem, the present invention also provides a computer program product, including a computer program or instructions, which implement the steps of the above cluster expansion method when executed by a processor.
[0063] In order to solve the above technical problems, the present invention further provides a cluster expansion device, comprising:
[0064] Memory for storing computer programs;
[0065] The processor is used to implement the steps of the above-mentioned cluster capacity expansion method when executing the computer program.
[0066] In order to solve the above technical problem, the present invention further provides a computer-readable storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the above cluster expansion method are implemented.
[0067] The cluster expansion method provided by the present invention is applied to a private cloud cluster; specifically, when a request from a public cloud host to join a private cloud cluster is received, the public Internet Protocol address of the public cloud host is obtained; a first virtual network card of the public cloud host and a second virtual network card of the private cloud host are created; wherein the private cloud host is a master node of the private cloud cluster; based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, a secure shell protocol tunnel is established between the public cloud host and the private cloud host; and the public cloud host is controlled to join the private cloud cluster through the secure shell protocol tunnel.
[0068] The beneficial effects of the present invention are that when a private cloud cluster is expanded and a public cloud host needs to be added to the private cloud cluster, a first virtual network card of the public cloud host and a second virtual network card of the private cloud host are created; based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, a secure shell protocol tunnel is established between the public cloud host and the private cloud host, thereby realizing two-way communication between the public cloud host and the private cloud host; finally, the public cloud host is controlled to join the private cloud cluster through the secure shell protocol tunnel, thereby realizing the management of the public cloud host by the private cloud cluster, and the public cloud host can be directly scheduled and resource managed through the management platform of the private cloud cluster subsequently, thereby reducing the management cost of the server and improving the development efficiency.
[0069] On the other hand, the present invention specifically obtains the allocable Internet Protocol address segment to be selected; pre-processes the Internet Protocol address segment to be selected to remove the allocated Internet Protocol address in the Internet Protocol address segment to be selected; based on the pre-processed Internet Protocol address segment to be selected, respectively determine the first Internet Protocol address corresponding to the first virtual network card and the second Internet Protocol address corresponding to the second virtual network card; create the first virtual network card according to the first Internet Protocol address, and create the second virtual network card according to the second Internet Protocol address, thereby realizing the creation of virtual network cards of the public cloud host and the private cloud host. Based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, a secure shell protocol tunnel is established between the public cloud host and the private cloud host using the secure shell protocol virtual private network technology; based on the private cloud host, policy routing is configured to forward the traffic accessing the first Internet Protocol address to the first virtual network card; based on the public cloud host, policy routing is configured to forward the traffic accessing the second Internet Protocol address to the second virtual network card, thereby realizing the establishment of an SSH tunnel, so as to facilitate two-way communication between the public cloud host and the private cloud host.
[0070] In addition, the present invention also provides a computer program product, a cluster expansion device and a medium, with the same effects as above. BRIEF DESCRIPTION OF THE DRAWINGS
[0071] In order to more clearly illustrate the embodiments of the present invention, the following briefly introduces the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0072] Figure 1 A schematic diagram of the communication between the current public cloud host and the private cloud host provided by an embodiment of the present invention;
[0073] Figure 2 A flow chart of a cluster expansion method provided by an embodiment of the present invention;
[0074] Figure 3 A network topology diagram of SSH tunnel communication provided by an embodiment of the present invention;
[0075] Figure 4 A schematic diagram of a cluster capacity expansion device provided by an embodiment of the present invention;
[0076] Figure 5 A schematic diagram of a cluster capacity expansion device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0077] The following will be combined with the drawings in the embodiments of the present invention to clearly and completely describe the technical solutions in the embodiments of the present invention. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of the present invention.
[0078] The core of the present invention is to provide a cluster expansion method, product, device and medium to solve the problem that the private cloud host and the public cloud host of the cluster cannot be interconnected in both directions in a weak network environment.
[0079] In order to enable those skilled in the art to better understand the solution of the present invention, the present invention is further described in detail below in conjunction with the accompanying drawings and specific implementation methods.
[0080] Currently, when a public cloud host is purchased, it has an intranet Internet Protocol (IP) address and a public IP address. These two IP addresses correspond to each other and can be accessed through the Internet. The public IP address of the public cloud host will be forwarded to the intranet host. Therefore, the private cloud host can access the public cloud host through a unified public switch export.
[0081] However, in order to protect the security of the cluster, the private cloud will not configure a public IP address for each device. The switch where the public network is located, as the unified Internet exit of the private cloud, will not forward the traffic to a single host in the private cloud, so the communication is one-way. Figure 1 The present invention provides a schematic diagram of the current public cloud host and the private cloud host communicating with each other. Figure 1 As shown, the public cloud host cannot access the private cloud host through the private cloud host's intranet IP address and the public network switch IP address. Therefore, in order to solve the above problem, the present invention provides a cluster expansion method. It should be noted that the method provided by the present invention is applied to a private cloud cluster. It can be understood that a private cloud cluster is a k8s cluster.
[0082] Figure 2 A flow chart of a cluster expansion method provided by an embodiment of the present invention. Figure 2 As shown, the method includes:
[0083] S10: When receiving a request from a public cloud host to apply for joining a private cloud cluster, obtaining a public Internet Protocol address of the public cloud host.
[0084] In a private cloud cluster, the edge needs to regularly report the resource status of the edge node, so the edge and the cloud, that is, the public cloud host and the private cloud host need to be able to communicate with each other. Specifically, when a request is received from a public cloud host to join a private cloud cluster, the public IP address of the public cloud host is first obtained. It can be understood that a public IP address is an IP address that can be uniquely identified globally on the Internet. It is assigned by the Internet service provider to devices connected to the Internet for communication on the Internet. The public IP address can be seen and accessed by other devices on the Internet.
[0085] S11: Create a first virtual network card for the public cloud host and a second virtual network card for the private cloud host.
[0086] Among them, the private cloud host is the master node of the private cloud cluster.
[0087] Furthermore, a first virtual network card of the public cloud host and a second virtual network card of the private cloud host are created. A virtual network card is a network interface card simulated in software. It is not a real, physically existing device, but the operating system and application programs will regard it as a real network interface. Virtual network cards can be used in a variety of scenarios, including virtualized environments, virtual private networks (VPN) connections, and network tunnels. In this embodiment, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host are mainly used to establish a two-way communication connection between the public cloud host and the private cloud host. In this embodiment, there is no restriction on the specific process of creating the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, which depends on the specific implementation situation.
[0088] In addition, the private cloud host in this embodiment is the master node (Master Node) of the private cloud cluster, which is the management and control center of the cluster and is responsible for coordinating and scheduling other nodes in the cluster.
[0089] S12: Based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host, and the second virtual network card of the private cloud host, a secure shell protocol tunnel is established between the public cloud host and the private cloud host.
[0090] After creating a first virtual network card of the public cloud host and a second virtual network card of the private cloud host, a secure shell (SSH) tunnel is established between the public cloud host and the private cloud host based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host.
[0091] SSH tunnel is a method of using SSH protocol to encrypt other protocols or network connections. It mainly achieves secure data transmission by establishing an encrypted communication channel between the local computer and the remote SSH server. The functions of SSH tunnel mainly include encrypted data transmission. Through SSH tunnel, unencrypted network traffic can be encrypted and transmitted to ensure the privacy and security of data transmission; bypass firewall restrictions and complete some Transmission Control Protocol (TCP) connections that could not be established before; and securely access services on remote servers without exposing these services to the Internet. In summary, by using SSH tunnel, users can establish a secure communication channel in an insecure network environment, protect the transmission of sensitive data, and achieve flexible access to remote services. In this embodiment, SSH tunnel is specifically used to achieve two-way communication between public cloud hosts and private cloud hosts.
[0092] It should be noted that the present embodiment does not limit the process of establishing the secure shell protocol tunnel, and it depends on the specific implementation situation.
[0093] S13: Control the public cloud host to join the private cloud cluster through the secure shell protocol tunnel.
[0094] Finally, control the public cloud host to join the private cloud cluster through the SSH tunnel, so that the public cloud host can be uniformly managed through the private cloud cluster. It should be noted that the public cloud host that has successfully joined the private cloud cluster is an edge node of the private cloud cluster. The management platform of the private cloud cluster can schedule tasks to the public cloud host, and users can create development and training tasks on the public cloud host through the platform.
[0095] It should be noted that the specific process of controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel is not limited in this embodiment, and depends on the specific implementation situation.
[0096] In this embodiment, when the private cloud cluster is expanded and the public cloud host needs to be added to the private cloud cluster, a first virtual network card of the public cloud host and a second virtual network card of the private cloud host are created; based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, a secure shell protocol tunnel is established between the public cloud host and the private cloud host, thereby realizing two-way communication between the public cloud host and the private cloud host; finally, the public cloud host is controlled to join the private cloud cluster through the secure shell protocol tunnel, thereby realizing the management of the public cloud host by the private cloud cluster, and the public cloud host can be subsequently directly scheduled and resource managed through the management platform of the private cloud cluster, thereby reducing the management cost of the server and improving development efficiency.
[0097] Based on the above embodiments, in some embodiments, creating a first virtual network card of a public cloud host and a second virtual network card of a private cloud host includes:
[0098] S111: Obtain allocatable Internet Protocol address segments to be selected;
[0099] S112: pre-processing the Internet Protocol address segment to be selected to remove the allocated Internet Protocol addresses in the Internet Protocol address segment to be selected;
[0100] S113: Based on the preprocessed selected Internet Protocol address segment, determine a first Internet Protocol address corresponding to the first virtual network card and a second Internet Protocol address corresponding to the second virtual network card respectively;
[0101] S114: Create a first virtual network card according to the first Internet Protocol address, and create a second virtual network card according to the second Internet Protocol address.
[0102] In order to create virtual network cards for public cloud hosts and private cloud hosts respectively, in this embodiment, data query is specifically used to obtain the allocable candidate IP address segment. For example, the allocable candidate IP address segment in the private cloud cluster is 10.10.5.0 / 24. At the same time, the candidate IP address segment needs to be preprocessed to remove the allocated IP addresses in the candidate IP address segment.
[0103] Further, based on the preprocessed candidate IP address segment, the first IP address corresponding to the first virtual network card and the second IP address corresponding to the second virtual network card are determined respectively. For example, the first IP address can be determined to be 10.10.5.1, and the second IP address can be determined to be 10.10.4.15. Finally, the first virtual network card is created according to the first IP address, and the second virtual network card is created according to the second IP address.
[0104] It should be noted that this embodiment introduces the addition of a public cloud host to a private cloud cluster, and it is necessary to create a first virtual network card for the public cloud host and a second virtual network card for the private cloud host. When there are multiple public cloud hosts joining the private cloud cluster, it is necessary to create a corresponding first virtual network card for each public cloud host, and it is necessary to ensure that the first IP addresses corresponding to each first virtual network card are different; on the other hand, it is also necessary to create second virtual network cards corresponding to the number of public cloud hosts for private cloud hosts (the names of each second virtual network card cannot be repeated), and it is necessary to ensure that the second IP addresses corresponding to each second virtual network card are the same, so as to ensure a one-to-one correspondence between the first virtual network card and the second virtual network card, so as to facilitate the subsequent creation of a network tunnel between the public cloud host and the private cloud host.
[0105] In this embodiment, allocable Internet Protocol address segments to be selected are obtained; the Internet Protocol address segments to be selected are preprocessed to remove the allocated Internet Protocol addresses in the Internet Protocol address segments to be selected; based on the preprocessed Internet Protocol address segments to be selected, a first Internet Protocol address corresponding to the first virtual network card and a second Internet Protocol address corresponding to the second virtual network card are respectively determined; a first virtual network card is created according to the first Internet Protocol address, and a second virtual network card is created according to the second Internet Protocol address, thereby realizing the creation of virtual network cards for public cloud hosts and private cloud hosts.
[0106] On the basis of the above embodiments, in some embodiments, based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, a secure shell protocol tunnel is established between the public cloud host and the private cloud host, including:
[0107] S121: Based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host, and the second virtual network card of the private cloud host, a secure shell protocol tunnel is established between the public cloud host and the private cloud host using a secure shell protocol virtual private network technology;
[0108] S122: configuring policy routing based on the private cloud host to forward traffic accessing the first Internet Protocol address to the first virtual network card;
[0109] S123: Configure policy routing based on the public cloud host to forward traffic accessing the second Internet Protocol address to the second virtual network card.
[0110] In order to establish an SSH tunnel between the public cloud host and the private cloud host, in this embodiment, a secure shell protocol tunnel between the public cloud host and the private cloud host is established by using the secure shell protocol virtual private network (SSH_VPN) technology based on the public network IP address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host.
[0111] SSH_VPN technology is a technology that uses the SSH protocol to establish a secure tunnel to achieve secure remote access and data transmission. It creates an encrypted communication channel between the local computer and the remote SSH server, so that data is protected from eavesdropping and tampering during transmission.
[0112] Furthermore, policy routing is configured based on the private cloud host to forward traffic accessing the first IP address to the first virtual network card; policy routing is configured based on the public cloud host to forward traffic accessing the second IP address to the second virtual network card, thereby completing the establishment of the SSH tunnel.
[0113] Figure 3 The network topology diagram of SSH tunnel communication provided by the embodiment of the present invention. Figure 3 As shown in the figure, there are two second virtual network cards, tun0 and tun1, on the private cloud host, and the two public cloud hosts have corresponding first virtual network cards (tun0 and tun1 respectively). Therefore, for the private cloud host, the IP addresses of the two public cloud hosts are changed to the corresponding first IP addresses (10.10.5.1 / 2); for the two public cloud hosts, the IP address of the private cloud host is fixed to the second IP address (10.10.4.15). The first IP addresses (10.10.5.1 / 2) of the two public cloud hosts can be directly accessed from the private cloud host. The second IP address (10.10.4.15) of the private cloud host can be directly accessed from the public cloud host, thus achieving two-way communication.
[0114] In this embodiment, based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, a secure shell protocol tunnel is established between the public cloud host and the private cloud host using the secure shell protocol virtual private network technology; policy routing is configured based on the private cloud host to forward traffic accessing the first Internet Protocol address to the first virtual network card; policy routing is configured based on the public cloud host to forward traffic accessing the second Internet Protocol address to the second virtual network card, thereby realizing the establishment of an SSH tunnel to facilitate two-way communication between the public cloud host and the private cloud host.
[0115] Based on the above embodiments, in some embodiments, before controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel, after establishing a secure shell protocol tunnel between the public cloud host and the private cloud host based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, the method further includes:
[0116] S14: Save the relevant information of the public cloud host into the database;
[0117] The relevant information of the public cloud host includes at least the name of the public cloud host, the public Internet Protocol address, the name of the first virtual network card, and the corresponding first Internet Protocol address;
[0118] S15: Monitor the status of the secure shell protocol tunnel according to the relevant information of the public cloud host in the database to determine whether the secure shell protocol tunnel is successfully established; if so, return to step S15 after a preset period; if not, return to step S10.
[0119] In order to monitor the status of the SSH tunnel, in a specific implementation, after the SSH tunnel is established, the relevant information of the public cloud host is saved in the database. It should be noted that the relevant information of the public cloud host at least includes the name of the public cloud host, the public network IP address, the name of the first virtual network card and the corresponding first IP address, and may also include other information, which is not limited in this embodiment.
[0120] Further, based on the relevant information of the public cloud host in the database, the status of the SSH tunnel is monitored to determine whether the SSH tunnel is successfully established. In this embodiment, there is no restriction on the specific method for determining whether the SSH tunnel is successfully established, which depends on the specific implementation situation. If it is confirmed that the SSH tunnel is successfully established, after a preset period, the process returns to the step of monitoring the status of the SSH tunnel based on the relevant information of the public cloud host in the database to determine whether the SSH tunnel is successfully established, thereby continuing to monitor the SSH tunnel. If it is confirmed that the SSH tunnel fails to be established, the process returns to the step of obtaining the public IP address of the public cloud host to re-establish the SSH tunnel.
[0121] In this way, by monitoring the status of the SSH tunnel, the stability of two-way communication between the public cloud host and the private cloud host is guaranteed.
[0122] Based on the above embodiments, in some embodiments, monitoring the state of the secure shell protocol tunnel according to the relevant information of the public cloud host in the database to determine whether the secure shell protocol tunnel is successfully established includes:
[0123] S151: Determine whether the second virtual network card of the private cloud host is operating normally; if not, confirm that the secure shell protocol tunnel establishment fails; if so, proceed to step S152;
[0124] S152: Obtain relevant information of the public cloud host in the database, and determine whether the first virtual network card and its corresponding first Internet Protocol address exist; if not, confirm that the secure shell protocol tunnel fails to be established; if so, confirm that the secure shell protocol tunnel is successfully established.
[0125] In order to determine whether the SSH tunnel is successfully established, in this embodiment, it is specifically determined whether the second virtual network card of the private cloud host is operating normally. If it is confirmed that the second virtual network card of the private cloud host is not operating normally, it is confirmed that the SSH tunnel establishment has failed. If it is confirmed that the second virtual network card of the private cloud host is operating normally, the relevant information of the public cloud host in the database is obtained to determine whether the first virtual network card and its corresponding first IP address exist. If it is confirmed that the first virtual network card and its corresponding first IP address do not exist, it is confirmed that the SSH tunnel establishment has failed; if it is confirmed that the first virtual network card and its corresponding first IP address exist, it is confirmed that the SSH tunnel establishment has been successful.
[0126] In this way, it is possible to determine whether the SSH tunnel is successfully established.
[0127] In addition, in order to prevent the long-term SSH tunnel establishment failure from affecting the normal operation of the private cloud cluster, based on the above embodiment, in some embodiments, after confirming that the secure shell protocol tunnel establishment fails, the following is further included:
[0128] S153: Determine whether the secure shell protocol tunnel is successfully re-established after the preset time; if so, end; if not, proceed to step S154;
[0129] S154: Outputting alarm information indicating that the secure shell protocol tunnel establishment timed out.
[0130] In a specific implementation, after confirming that the SSH tunnel establishment fails, it is determined whether the SSH tunnel is successfully reestablished after a preset time. In this embodiment, there is no restriction on the preset time, which depends on the specific implementation situation.
[0131] If it is confirmed that the SSH tunnel is reestablished successfully after the preset time, the process ends directly. If it is confirmed that the SSH tunnel is not reestablished successfully after the preset time, it is considered that the SSH tunnel reconstruction has encountered an error or failure, and an alarm message indicating the SSH tunnel establishment timeout is output, thereby prompting the user to check the problems encountered in the SSH tunnel reconstruction in time, so as to avoid long-term SSH tunnel establishment failures affecting the normal operation of the private cloud cluster.
[0132] After the SSH tunnel connection is established, the private cloud host and the public cloud host are in intercommunication, and the edge cluster joining operation can be performed at this time. Based on the above embodiment, in some embodiments, controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel includes:
[0133] S131: Obtain relevant information of the public cloud host;
[0134] The relevant information of the public cloud host includes at least the name of the public cloud host, the public Internet Protocol address, the name of the first virtual network card, and the corresponding first Internet Protocol address;
[0135] S132: judging whether the public cloud host meets the preset requirements for joining the private cloud cluster according to the relevant information of the public cloud host; if not, proceeding to step S133; if yes, proceeding to step S134;
[0136] S133: Public cloud hosts are prohibited from joining private cloud clusters;
[0137] S134: The cloud core based on the private cloud host adds the public cloud host to the private cloud cluster.
[0138] In order for the public cloud host to join the private cloud cluster through the SSH tunnel, the relevant information of the public cloud host is specifically obtained. It is understandable that the relevant information of the public cloud host includes at least the name of the public cloud host, the public IP address, the name of the first virtual network card, and the corresponding first IP address. Further, based on the relevant information of the public cloud host, it is determined whether the public cloud host meets the preset requirements for joining the private cloud cluster. In this embodiment, there is no restriction on the preset requirements. For example, the name of the public cloud host, the public IP address, the name of the first virtual network card, and the corresponding first IP address need to comply with the specifications respectively, and do not repeat the information in the current private cloud cluster.
[0139] If it is confirmed that the public cloud host does not meet the preset requirements for joining the private cloud cluster, the public cloud host is prohibited from joining the private cloud cluster. If it is confirmed that the public cloud host meets the preset requirements for joining the private cloud cluster, the public cloud host is added to the private cloud cluster based on the cloud core (CloudCore) of the private cloud host.
[0140] It should be noted that CloudCore is the core component of the k8s cloud, which is mainly responsible for device management and instruction delivery. It consists of two parts: controllers and cloud center (CloudHub): Controllers are responsible for processing and managing resources on the nodes, including containers (POD) and configuration maps (ConfigMaps). When these resources are updated, Controllers will report the update status to CloudHub. CloudHub acts as a communication bridge between the cloud and the edge, forwarding the update status to the edge core (EdgeCore) so that corresponding operations can be performed on the edge node. This design can save transmission resources, improve the efficiency of instruction execution, avoid frequent communication and data transmission, and thus reduce network load. CloudCore based on private cloud host adds public cloud hosts to the private cloud cluster, specifically including:
[0141] S135: adding the first Internet Protocol address of the public cloud host to the certificate of the cloud core of the private cloud host, and restarting the cloud core of the private cloud host;
[0142] S136: performing an initialization operation on the public cloud host through a configuration management tool;
[0143] S137: Execute a command for joining the private cloud cluster based on the public cloud host to add the public cloud host to the private cloud cluster.
[0144] In the specific implementation, the first IP address of the public cloud host is added to the certificate of the CloudCore of the private cloud host, and the CloudCore of the private cloud host is restarted. Further, the initialization operation of the public cloud host is performed through the configuration management tool (ansible), which specifically includes configuring the firewall of the private cloud host and the public cloud host node, installing the necessary software for the public cloud host, installing docker, configuring time synchronization, installing the EdgeCore component of the edge computing framework (KubeEdge), loading the necessary images, etc. Finally, based on the public cloud host, the command to join the private cloud cluster is executed. At this time, the public cloud host will access the CloudCore of the private cloud host through the second IP address to join the private cloud cluster.
[0145] Based on the above embodiments, in some embodiments, after controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel, the method further includes:
[0146] S16: Determine whether there is a training task currently being executed; if it is confirmed that there is a training task currently being executed, proceed to step S17;
[0147] S17: Schedule the training task to the public cloud host through the secure shell protocol tunnel.
[0148] In the specific implementation, after adding the public cloud host to the private cloud cluster, in order to effectively utilize the computing resources of the public cloud host, it is specifically determined whether there is a training task currently being executed. If it is confirmed that there is no training task currently being executed, the process ends; if it is confirmed that there is a training task currently being executed, the training task is scheduled to the public cloud host through the SSH tunnel, and the public cloud host executes the training task, thereby effectively utilizing the computing resources of the public cloud host.
[0149] Based on the content in the above embodiments, the public cloud host has been added to the private cloud cluster as an edge node. However, the containers (PODs) running on different edge nodes cannot communicate with each other. In order to solve this problem, based on the above embodiments, in some embodiments, after controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel, it also includes:
[0150] S18: Apply to create a target training task;
[0151] S19: Determine whether the target training task is a distributed task; if not, proceed to step S20; if yes, proceed to step S21;
[0152] S20: directly execute the target training task;
[0153] S21: Establish communication connections between containers of all edge nodes in the private cloud cluster to execute target training tasks through each edge node;
[0154] Among them, all edge nodes include private cloud hosts and public cloud hosts that have joined the private cloud cluster.
[0155] In the specific implementation, an application is made to create a target training task to determine whether the target training task is a distributed task. If it is confirmed that the target training task is not a distributed task, it is confirmed that the target training task does not require communication between the edge node containers during execution, and the target training task can be executed directly. If it is confirmed that the target training task is a distributed task, it is necessary to establish communication between the containers of each edge node to execute the target training task through each edge node. It can be understood that edge nodes include private cloud hosts and public cloud hosts that have joined the private cloud cluster.
[0156] Specifically, establishing communication connections between containers of all edge nodes in a private cloud cluster includes:
[0157] S211: Create a container service corresponding to the container of each edge node;
[0158] S212: Inject the name of each container service into the container of the corresponding edge node through the environment variable;
[0159] S213: Parse the name of the container service of each edge node to obtain the container service Internet Protocol addresses of all containers;
[0160] S214: Establish communication connections between containers of all edge nodes in the private cloud cluster based on the Internet Protocol addresses of the container services.
[0161] Specifically, the edge network (EdgeMesh) component in KubeEdge provides a service service_ip service proxy, and different services can request the service's k8s service_IP to communicate. Therefore, when the target training task is identified as a distributed task, a container service (service) corresponding to the container of each edge node is created. The name of the container service is injected into the container of the corresponding edge node through the environment variable, and the name of the container service of each edge node is parsed to obtain the container service Internet Protocol (service_IP) address of all containers. Finally, based on the service_IP address of each container, a communication connection is established between the containers of all edge nodes in the private cloud cluster. The established communication connection can realize communication between the containers of each edge node, thereby completing the distributed task.
[0162] In addition, due to the instability of network communication between private clouds and public clouds, and in order to ensure the security of internal services in private clouds, EdgeMesh can also be deployed only in public cloud hosts, that is, only container services between multiple public cloud hosts can communicate with each other, and services in private clouds and services in public clouds cannot communicate with each other, thereby achieving the execution of distributed tasks and ensuring the security of internal services in private clouds.
[0163] Based on the above embodiments, in some embodiments, the following further includes:
[0164] S22: monitoring the deactivation instruction of the public cloud host;
[0165] S23: When receiving a deactivation instruction for the public cloud host, disconnecting the secure shell protocol tunnel between the public cloud host and the private cloud host;
[0166] S24: Reclaim the allocated Internet protocol resources.
[0167] In the specific implementation, when the private cloud cluster no longer needs to use the public cloud host, in order to reduce cluster resource consumption, the deactivation instruction of the public cloud host is specifically monitored. When the deactivation instruction of the public cloud host is received, the SSH tunnel between the public cloud host and the private cloud host is disconnected, and the allocated IP resources are recovered, thereby saving the resource consumption of the private cloud cluster.
[0168] In the above embodiments, the cluster expansion method is described in detail. The present invention also provides a corresponding embodiment of the cluster expansion device.
[0169] Figure 4 A schematic diagram of a cluster expansion device provided by an embodiment of the present invention. Figure 4 As shown, the device comprises:
[0170] The acquisition module 10 is used to acquire the public Internet Protocol address of the public cloud host when receiving a request from the public cloud host to apply to join the private cloud cluster;
[0171] A creation module 11 is used to create a first virtual network card of a public cloud host and a second virtual network card of a private cloud host; wherein the private cloud host is a master node of a private cloud cluster;
[0172] Establishing module 12, for establishing a secure shell protocol tunnel between the public cloud host and the private cloud host based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host;
[0173] The control module 13 is used to control the public cloud host to join the private cloud cluster through the secure shell protocol tunnel.
[0174] In some embodiments, the creation module 11 includes:
[0175] A first acquisition submodule is used to acquire allocatable candidate Internet Protocol address segments;
[0176] A preprocessing submodule, used for preprocessing the to-be-selected Internet Protocol address segment to remove the allocated Internet Protocol addresses in the to-be-selected Internet Protocol address segment;
[0177] A first determination submodule, used to determine a first Internet Protocol address corresponding to the first virtual network card and a second Internet Protocol address corresponding to the second virtual network card respectively based on the preprocessed selected Internet Protocol address segment;
[0178] The first creation submodule is used to create a first virtual network card according to the first Internet Protocol address, and to create a second virtual network card according to the second Internet Protocol address.
[0179] In some embodiments, the establishment module 12 includes:
[0180] A first establishing submodule is used to establish a secure shell protocol tunnel between the public cloud host and the private cloud host using a secure shell protocol virtual private network technology based on a public Internet Protocol address of the public cloud host, a first virtual network card of the public cloud host, and a second virtual network card of the private cloud host;
[0181] A first configuration submodule, configured to configure policy routing based on the private cloud host to forward traffic accessing the first Internet Protocol address to the first virtual network card;
[0182] The second configuration submodule is used to configure policy routing based on the public cloud host to forward traffic accessing the second Internet Protocol address to the second virtual network card.
[0183] In some embodiments, it also includes:
[0184] A saving submodule, used to save the relevant information of the public cloud host to the database; wherein the relevant information of the public cloud host includes at least the name of the public cloud host, the public Internet Protocol address, the name of the first virtual network card and the corresponding first Internet Protocol address;
[0185] The first judgment submodule is used to monitor the status of the secure shell protocol tunnel according to the relevant information of the public cloud host in the database, and judge whether the secure shell protocol tunnel is successfully established; if it is confirmed that the secure shell protocol tunnel is successfully established, the first judgment submodule is triggered after a preset period; if it is confirmed that the secure shell protocol tunnel fails to be established, the acquisition module 10 is triggered.
[0186] In some embodiments, the first determination submodule includes:
[0187] The second judgment submodule is used to judge whether the second virtual network card of the private cloud host is operating normally; if it is confirmed that the second virtual network card of the private cloud host is not operating normally, it is confirmed that the secure shell protocol tunnel establishment fails; if it is confirmed that the second virtual network card of the private cloud host is operating normally, the third judgment submodule is triggered;
[0188] The third judgment submodule is used to obtain relevant information of the public cloud host in the database, and determine whether the first virtual network card and its corresponding first Internet Protocol address exist; if it is confirmed that the first virtual network card and its corresponding first Internet Protocol address do not exist, it is confirmed that the secure shell protocol tunnel has failed to be established; if it is confirmed that the first virtual network card and its corresponding first Internet Protocol address exist, it is confirmed that the secure shell protocol tunnel has been successfully established.
[0189] In some embodiments, it also includes:
[0190] The fourth judgment submodule is used to judge whether the secure shell protocol tunnel is successfully re-established after the preset time; if it is confirmed that the secure shell protocol tunnel is successfully re-established after the preset time, then the process ends; if it is confirmed that the secure shell protocol tunnel is not successfully re-established after the preset time, then the alarm submodule is triggered;
[0191] The alarm submodule is used to output alarm information indicating that the secure shell protocol tunnel establishment timeout has occurred.
[0192] In some embodiments, the control module 13 includes:
[0193] A second acquisition submodule is used to obtain relevant information of the public cloud host; wherein the relevant information of the public cloud host includes at least the name of the public cloud host, the public Internet Protocol address, the name of the first virtual network card, and the corresponding first Internet Protocol address;
[0194] The fifth judgment submodule is used to judge whether the public cloud host meets the preset requirements for joining the private cloud cluster according to the relevant information of the public cloud host; if it is confirmed that the public cloud host does not meet the preset requirements for joining the private cloud cluster, the public cloud host is prohibited from joining the private cloud cluster; if it is confirmed that the public cloud host meets the preset requirements for joining the private cloud cluster, the cluster joining processing submodule is triggered;
[0195] The cluster joining processing submodule is used to join the public cloud host to the private cloud cluster based on the cloud core of the private cloud host.
[0196] In some embodiments, the cluster joining processing submodule includes:
[0197] A first processing submodule, configured to add a first Internet Protocol address of the public cloud host to a certificate of a cloud core of the private cloud host, and restart the cloud core of the private cloud host;
[0198] The initialization submodule is used to perform initialization operations on the public cloud host through the configuration management tool;
[0199] The second processing submodule is used to execute a command for joining the private cloud cluster based on the public cloud host to add the public cloud host to the private cloud cluster.
[0200] In some embodiments, it also includes:
[0201] The sixth judgment submodule is used to determine whether there is a training task currently being executed; if it is confirmed that there is a training task currently being executed, the training task is scheduled to the public cloud host through the secure shell protocol tunnel.
[0202] In some embodiments, it also includes:
[0203] The application submodule is used to apply for creating a target training task;
[0204] The seventh judgment submodule is used to judge whether the target training task is a distributed task; if it is confirmed that the target training task is not a distributed task, the target training task is directly executed; if it is confirmed that the target training task is a distributed task, the communication connection establishment submodule is triggered;
[0205] The communication connection establishment submodule is used to establish the communication connection of the containers of all edge nodes in the private cloud cluster so as to execute the target training task through each edge node;
[0206] Among them, all edge nodes include private cloud hosts and public cloud hosts that have joined the private cloud cluster.
[0207] In some embodiments, the communication connection establishment submodule includes:
[0208] The second creation submodule is used to create a container service corresponding to the container of each edge node;
[0209] The injection submodule is used to inject the name of each container service into the container of the corresponding edge node through the environment variable;
[0210] A parsing submodule, used to parse the name of the container service of each edge node to obtain the container service Internet Protocol address of all containers;
[0211] The connection submodule is used to establish communication connections between containers of all edge nodes in the private cloud cluster based on the Internet Protocol addresses of each container service.
[0212] In some embodiments, it also includes:
[0213] A monitoring submodule, used to monitor the deactivation instructions for the public cloud host;
[0214] A connection disconnection submodule, used to disconnect the secure shell protocol tunnel between the public cloud host and the private cloud host when receiving a deactivation instruction for the public cloud host;
[0215] The resource recovery submodule is used to recover the allocated Internet protocol resources.
[0216] Since the embodiments of the apparatus part correspond to the embodiments of the method part, please refer to the description of the embodiments of the method part for the embodiments of the apparatus part, which will not be repeated here.
[0217] In addition, the present invention also provides a computer program product, including a computer program or instructions, which implement the steps of the above cluster expansion method when executed by a processor.
[0218] Figure 5 A schematic diagram of a cluster expansion device provided by an embodiment of the present invention. Figure 5 As shown in the figure, the cluster expansion equipment includes:
[0219] A memory 20, used for storing computer programs;
[0220] The processor 21 is configured to implement the steps of the cluster expansion method mentioned in the above embodiment when executing a computer program.
[0221] The cluster expansion device provided in this embodiment may include but is not limited to a smart phone, a tablet computer, a laptop computer, or a desktop computer.
[0222] Among them, the processor 21 may include one or more processing cores, such as a 4-core processor, an 8-core processor, etc. The processor 21 can be implemented in at least one hardware form of a digital signal processor (DSP), a field programmable gate array (FPGA), and a programmable logic array (PLA). The processor 21 may also include a main processor and a coprocessor. The main processor is a processor for processing data in an awake state, also known as a central processing unit (CPU); the coprocessor is a low-power processor for processing data in a standby state. In some embodiments, the processor 21 may be integrated with a graphics processing unit (GPU), and the GPU is responsible for rendering and drawing the content to be displayed on the display screen. In some embodiments, the processor 21 may also include an artificial intelligence (AI) processor, which is used to process computing operations related to machine learning.
[0223] The memory 20 may include one or more computer-readable storage media, which may be non-transitory. The memory 20 may also include a high-speed random access memory, and a non-volatile memory, such as one or more disk storage devices, flash memory storage devices. In this embodiment, the memory 20 is at least used to store the following computer program 201, wherein, after the computer program is loaded and executed by the processor 21, the relevant steps of the cluster expansion method disclosed in any of the aforementioned embodiments can be implemented. In addition, the resources stored in the memory 20 may also include an operating system 202 and data 203, etc., and the storage method may be temporary storage or permanent storage. Among them, the operating system 202 may include Windows, Unix, Linux, etc. Data 203 may include but is not limited to data involved in the cluster expansion method.
[0224] In some embodiments, the cluster expansion device may further include a display screen 22 , an input / output interface 23 , a communication interface 24 , a power supply 25 , and a communication bus 26 .
[0225] Those skilled in the art will understand that Figure 5 The structure shown in the figure does not constitute a limitation on the cluster expansion device, and may include more or fewer components than shown in the figure.
[0226] Finally, the present invention also provides an embodiment corresponding to a computer-readable storage medium. The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps recorded in the above method embodiment are implemented.
[0227] It is understandable that if the method in the above embodiment is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present invention, or the part that contributes to the prior art, or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium to execute all or part of the steps of the method described in each embodiment of the present invention. The aforementioned storage medium includes: U disk, mobile hard disk, read-only memory (ROM), random access memory (RAM), disk or optical disk, etc. Various media that can store program codes.
[0228] The above is a detailed introduction to a cluster expansion method, product, device and medium provided by the present invention. The various embodiments in the specification are described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same and similar parts between the embodiments can be referenced to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part description. It should be pointed out that for ordinary technicians in this technical field, without departing from the principle of the present invention, several improvements and modifications can be made to the present invention, and these improvements and modifications also fall within the scope of protection of the present invention.
[0229] It should also be noted that, in this specification, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "comprise", "include" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, an element defined by the statement "comprises a ..." does not exclude the presence of other identical elements in the process, method, article or device including the element.
Claims
1. A cluster expansion method, characterized in that: Applied to a private cloud cluster; the method comprises: When receiving a request from a public cloud host to join the private cloud cluster, obtaining a public Internet Protocol address of the public cloud host; Creating a first virtual network card of the public cloud host and a second virtual network card of the private cloud host; wherein the private cloud host is the master node of the private cloud cluster; Establishing a secure shell protocol tunnel between the public cloud host and the private cloud host based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host, and the second virtual network card of the private cloud host; Controlling the public cloud host to join the private cloud cluster through a secure shell protocol tunnel; When there are distributed tasks, create a container service corresponding to the container of each edge node; wherein the edge node is the public cloud host that has joined the private cloud cluster; Injecting the name of each container service into the container of the corresponding edge node through environment variables; Parsing the name of the container service of each edge node to obtain the container service Internet Protocol addresses of all containers; Establishing communication connections between containers of all edge nodes in the private cloud cluster based on each container service Internet Protocol address, so as to execute the distributed task through each edge node; The step of creating a first virtual network card of the public cloud host and a second virtual network card of the private cloud host includes: Obtaining allocatable Internet Protocol address segments to be selected; Preprocessing the to-be-selected Internet Protocol address segment to remove the allocated Internet Protocol addresses in the to-be-selected Internet Protocol address segment; Based on the preprocessed selected Internet Protocol address segment, determine a first Internet Protocol address corresponding to the first virtual network card and a second Internet Protocol address corresponding to the second virtual network card respectively; Creating a first virtual network card according to the first Internet Protocol address, and creating a second virtual network card according to the second Internet Protocol address; When there are multiple public cloud hosts joining the private cloud cluster, a corresponding first virtual network card is created for each public cloud host, and the first Internet Protocol address corresponding to each first virtual network card is different; second virtual network cards corresponding to the number of public cloud hosts are created for the private cloud hosts, and the names of the second virtual network cards are different, and the second Internet Protocol addresses corresponding to the second virtual network cards are the same; After establishing a secure shell protocol tunnel between the public cloud host and the private cloud host, the method further includes: Determine whether the second virtual network card of the private cloud host is operating normally; If it is confirmed that the second virtual network card of the private cloud host is not operating normally, it is confirmed that the secure shell protocol tunnel establishment fails; If it is confirmed that the second virtual network card of the private cloud host is operating normally, then obtain the relevant information of the public cloud host in the database to determine whether the first virtual network card and its corresponding first Internet Protocol address exist; wherein the relevant information of the public cloud host at least includes the name of the public cloud host, the public Internet Protocol address, the name of the first virtual network card and the corresponding first Internet Protocol address; If it is confirmed that the first virtual network card and the first Internet Protocol address corresponding to it do not exist, it is confirmed that the secure shell protocol tunnel establishment fails; If it is confirmed that the first virtual network card and its corresponding first Internet Protocol address exist, it is confirmed that the secure shell protocol tunnel is successfully established; The controlling the public cloud host to join the private cloud cluster through a secure shell protocol tunnel includes: Adding the first Internet Protocol address of the public cloud host to the certificate of the cloud core of the private cloud host, and restarting the cloud core of the private cloud host; Performing initialization operations on the public cloud host through a configuration management tool; A command for joining the private cloud cluster is executed based on the public cloud host to add the public cloud host to the private cloud cluster.
2. The cluster expansion method according to claim 1, characterized in that: The step of establishing a secure shell protocol tunnel between the public cloud host and the private cloud host based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host, and the second virtual network card of the private cloud host includes: Based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host and the second virtual network card of the private cloud host, a secure shell protocol tunnel is established between the public cloud host and the private cloud host using secure shell protocol virtual private network technology; Configuring policy routing based on the private cloud host to forward traffic accessing the first Internet Protocol address to the first virtual network card; Policy routing is configured based on the public cloud host to forward traffic accessing the second Internet Protocol address to the second virtual network card.
3. The cluster expansion method according to claim 1, characterized in that: Before controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel, after establishing a secure shell protocol tunnel between the public cloud host and the private cloud host based on the public Internet Protocol address of the public cloud host, the first virtual network card of the public cloud host, and the second virtual network card of the private cloud host, the method further includes: The relevant information of the public cloud host is saved in a database; wherein the relevant information of the public cloud host includes at least the name of the public cloud host, the public Internet Protocol address, the name of the first virtual network card and the corresponding first Internet Protocol address; Monitor the status of the secure shell protocol tunnel according to the relevant information of the public cloud host in the database, and determine whether the secure shell protocol tunnel is successfully established; If it is confirmed that the secure shell protocol tunnel is successfully established, then after a preset period, return to the step of monitoring the state of the secure shell protocol tunnel according to the relevant information of the public cloud host in the database to determine whether the secure shell protocol tunnel is successfully established; If it is confirmed that the secure shell protocol tunnel establishment fails, return to the step of obtaining the public Internet Protocol address of the public cloud host.
4. The cluster expansion method according to claim 1, characterized in that: After confirming that the secure shell protocol tunnel establishment fails, the method further includes: Determining whether the secure shell protocol tunnel is successfully re-established after a preset time; If it is confirmed that the secure shell protocol tunnel is successfully re-established after the preset time, then the process ends; If it is confirmed that the secure shell protocol tunnel is not successfully re-established after the preset time, an alarm message indicating that the secure shell protocol tunnel establishment timeout is output.
5. The cluster expansion method according to claim 1, characterized in that: The controlling the public cloud host to join the private cloud cluster through a secure shell protocol tunnel includes: Obtain relevant information of the public cloud host; wherein the relevant information of the public cloud host includes at least the name of the public cloud host, the public Internet Protocol address, the name of the first virtual network card and the corresponding first Internet Protocol address; Determining whether the public cloud host meets preset requirements for joining the private cloud cluster according to relevant information of the public cloud host; If it is confirmed that the public cloud host does not meet the preset requirements for joining the private cloud cluster, prohibiting the public cloud host from joining the private cloud cluster; If it is confirmed that the public cloud host meets the preset requirements for joining the private cloud cluster, the public cloud host is added to the private cloud cluster based on the cloud core of the private cloud host.
6. The cluster expansion method according to claim 1, characterized in that: After controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel, the method further includes: Determine whether there is a training task currently being executed; If it is confirmed that there is a training task currently being executed, the training task is scheduled to the public cloud host through the secure shell protocol tunnel.
7. The cluster expansion method according to claim 1, characterized in that: After controlling the public cloud host to join the private cloud cluster through the secure shell protocol tunnel, the method further includes: Apply to create a target training task; Determine whether the target training task is a distributed task; If it is confirmed that the target training task is not a distributed task, the target training task is directly executed; If it is confirmed that the target training task is a distributed task, a communication connection is established between the containers of all edge nodes in the private cloud cluster to execute the target training task through each edge node; Among them, all edge nodes include the private cloud host and the public cloud host that has joined the private cloud cluster.
8. The cluster expansion method according to claim 7, characterized in that: The establishing of the communication connection of the containers of all edge nodes in the private cloud cluster includes: Create container services corresponding to the containers of each edge node; Inject the name of each container service into the container of the corresponding edge node through environment variables; Parse the name of the container service of each edge node to obtain the container service Internet Protocol address of all containers; A communication connection is established between containers of all edge nodes in the private cloud cluster based on each container service Internet Protocol address.
9. The cluster expansion method according to any one of claims 1 to 8, characterized in that: Also includes: monitoring a deactivation instruction for the public cloud host; When receiving a deactivation instruction for the public cloud host, disconnecting the secure shell protocol tunnel between the public cloud host and the private cloud host; Reclaim allocated Internet Protocol resources.
10. A computer program product comprising a computer program or instructions, characterized in that When the computer program or instruction is executed by a processor, the steps of the cluster expansion method described in any one of claims 1 to 9 are implemented.
11. A cluster expansion device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the cluster capacity expansion method according to any one of claims 1 to 9 when executing the computer program.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, the steps of the cluster capacity expansion method according to any one of claims 1 to 9 are implemented.
Citation Information
Patent Citations
Dynamically defined virtual private network tunnels in hybrid cloud environments
CN108370340A
Hybrid cloud data processing method and device and electronic equipment
CN114124944A