Method, apparatus and electronic device for data processing
By creating virtual private cloud networks and flat networks for cloud hosts, and combining self-service systems and security group management access rules, the problem of user inconvenience caused by the separation of management networks and business networks in private cloud architecture is solved, enabling flexible and efficient access to the cloud platform.
Patent Information
- Application Number
- CN202411418917.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2024-10-11
- Publication Date
- 2025-11-18
- Estimated Expiration
- 2044-10-11
Smart Images

Figure CN119520016B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of information technology, and more specifically, to a data processing method, apparatus, and electronic device. Background Technology
[0002] In a private cloud architecture, the lack of separation between the management network and the business network poses challenges to business security and cloud platform reliability. By implementing a public-oriented transformation of the private cloud architecture, separating the business network from the management network, the cloud platform is accessed via a data communication network, improving security and reliability. However, this approach also results in a cloud platform that is not as user-friendly as a typical public cloud.
[0003] There is currently no effective solution to the above problems. Summary of the Invention
[0004] This application provides a data processing method, apparatus, and electronic device to at least solve the technical problem in the related art where separating the service network and management network of a cloud platform makes it inconvenient for users to use.
[0005] According to one aspect of the embodiments of this application, a data processing method is provided, comprising: receiving an access request sent by a target object; if the access request is to access the Internet, providing a first access path through a virtual private cloud network created for a cloud host, and accessing the Internet through the first access path; if the access request is to access a cloud platform, providing a second access path through a flat network created for the cloud host, and accessing the cloud platform through the second access path.
[0006] Optionally, before receiving the access request sent by the target object, the method further includes: receiving an inbound security group created by the self-service system, wherein the inbound security group is used to control the access rules for entering the self-service system, the self-service system is deployed in a cloud host, the self-service system is used to assist the cloud platform in processing the access request sent by the target object, and the cloud platform includes cloud hosts; and receiving an outbound security group created by the self-service system, wherein the outbound security group is used to control the access rules for entering the cloud platform.
[0007] Optionally, the method further includes: receiving cloud resource demand information selected by the target object in the cloud resource template; sending the cloud resource demand information to the cloud platform through a self-service system; receiving the approval result of the cloud platform on the cloud resource demand information; and receiving the cloud resources allocated by the cloud platform to the cloud host based on the approval result.
[0008] Optionally, the cloud resource template is determined by: determining the resource information contained in the cloud resource template, wherein the resource information includes at least one of the following: virtual machine configuration, network service, database service; creating the cloud resource template based on the resource information, security policy, and usage permissions; verifying whether the template configuration of the cloud resource template is correct, and publishing the cloud resource template to the designated organization after the cloud resource template has been verified.
[0009] Optionally, the cloud resources allocated by the cloud platform to the cloud host can be received based on the approval result, including: receiving cloud resources allocated by the cloud platform according to the cloud resource demand information if the approval result is approved; and receiving approval failure information sent by the cloud platform if the approval result is not approved.
[0010] Optionally, the method further includes: obtaining resource operation requests initiated by the target object through the self-service system; automatically initiating an approval process for the resource operation request when the resource operation request includes operations on preset resources; and executing the resource operation request if the approval result of the approval process is approval passed.
[0011] Optionally, after obtaining the resource operation request initiated by the target object through the self-service system, the method further includes: obtaining the request information in the resource operation request; generating an order record based on the resource operation request and the request information; and storing the order record in the database.
[0012] According to another aspect of the embodiments of this application, a data processing apparatus is also provided, comprising: a receiving module for receiving an access request sent by a target object; a first access module for providing a first access path through a virtual private cloud network created for a cloud host and accessing the Internet through the first access path when the access request is to access the Internet; and a second access module for providing a second access path through a flat network created for a cloud host and accessing the cloud platform through the second access path when the access request is to access a cloud platform.
[0013] According to another aspect of the embodiments of this application, an electronic device is also provided, including: a memory for storing program instructions; and a processor connected to the memory for executing program instructions to perform the following functions: receiving an access request sent by a target object; if the access request is to access the Internet, providing a first access path through a virtual private cloud network created for a cloud host, and accessing the Internet through the first access path; if the access request is to access a cloud platform, providing a second access path through a flat network created for a cloud host, and accessing the cloud platform through the second access path.
[0014] According to another aspect of the embodiments of this application, a non-volatile storage medium is also provided, the non-volatile storage medium including a stored computer program, wherein the device where the non-volatile storage medium is located executes the above-described data processing method by running the computer program.
[0015] According to another aspect of the embodiments of this application, a computer program product is also provided, including computer instructions that, when executed by a processor, implement the above-described data processing method.
[0016] In this embodiment, by receiving an access request sent by the target object; when the access request is to access the Internet, a first access path is provided through a virtual private cloud network created for the cloud host, and the Internet is accessed through the first access path; when the access request is to access the cloud platform, a second access path is provided through a flat network created for the cloud host, and the cloud platform is accessed through the second access path. This achieves the goal of flexibly and efficiently managing the cloud host's access to the Internet and cloud platform resources, thereby improving the technical effect of network access flexibility and solving the technical problem in related technologies where separating the business network and management network of the cloud platform makes it inconvenient for users to use. Attached Figure Description
[0017] The accompanying drawings, which are included to provide a further understanding of this application and form part of this application, illustrate exemplary embodiments and are used to explain this application, but do not constitute an undue limitation of this application. In the drawings:
[0018] Figure 1 This is a hardware structure block diagram of a computer terminal for implementing a data processing method according to an embodiment of this application;
[0019] Figure 2 This is a flowchart of a data processing method according to an embodiment of this application;
[0020] Figure 3 This is a structural diagram of a data processing apparatus according to an embodiment of this application. Detailed Implementation
[0021] To enable those skilled in the art to better understand the present application, the technical solutions in the embodiments of the present application will be clearly and completely described below with reference to the accompanying drawings. Obviously, the described embodiments are only some embodiments of the present application, and not all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative effort should fall within the scope of protection of the present application.
[0022] It should be noted that the terms "first," "second," etc., in the specification, claims, and accompanying drawings of this application are used to distinguish similar objects and are not necessarily used to describe a specific order or sequence. It should be understood that such data can be interchanged where appropriate so that the embodiments of this application described herein can be implemented in orders other than those illustrated or described herein. Furthermore, the terms "comprising" and "having," and any variations thereof, are intended to cover non-exclusive inclusion; for example, a process, method, system, product, or apparatus that comprises a series of steps or units is not necessarily limited to those steps or units explicitly listed, but may include other steps or units not explicitly listed or inherent to such processes, methods, products, or apparatus.
[0023] The information collected in this application embodiment is information and data authorized by the user or fully authorized by all parties. The collection, storage, use, processing, transmission, provision, disclosure and application of the relevant data all comply with the relevant laws, regulations and standards of the relevant regions, and necessary confidentiality measures have been taken. It does not violate public order and good morals, and provides corresponding operation entry points for users to choose to authorize or reject the automated decision results. If the user chooses to reject, the process will proceed to the expert decision-making process.
[0024] First, some nouns or terms that appear in the explanation of the embodiments of this application shall be interpreted as follows:
[0025] VPC (Virtual Private Cloud): A technology used in cloud computing environments to achieve resource isolation and security.
[0026] A cloud platform, also known as a cloud computing platform, is a computing service platform based on cloud computing technology, used to provide flexible, scalable, and shareable computing resources and system services. The process of activating and executing cloud resources is implemented within the cloud platform system. In a cloud platform that combines private and public cloud environments, administrators log in as administrators and activate and deliver cloud servers to customers based on the cloud resource parameters required by the order.
[0027] In a private cloud architecture, the lack of separation between the management network and the business network poses challenges to business security and cloud platform reliability. By implementing a public-oriented transformation of the private cloud architecture and separating the business network from the management network, the cloud platform is accessed via a Data Communication Network (DCN), improving security and reliability. However, this approach can lead to issues where the cloud platform is not as user-friendly as a typical public cloud, such as the lack of self-service pages, resulting in a poor user experience.
[0028] To address the problems existing in related technologies, embodiments of this application provide a data processing method that can be run on... Figure 1 The computer terminal shown is explained below.
[0029] The data processing method embodiments provided in this application can be executed on a mobile terminal, computer terminal, or similar computing device. Figure 1 A hardware block diagram of a computer terminal for implementing a data processing method is shown. Figure 1 As shown, the computer terminal 10 may include one or more processors (shown as 102a, 102b, ..., 102n in the figure) (the processor may include, but is not limited to, a microprocessor MCU or a programmable logic device FPGA, etc.), a memory 104 for storing data, and a transmission module 106 for communication functions connected via wired and / or wireless networks. In addition, it may also include: a display, a keyboard, a cursor control device, an input / output interface (I / O interface), a universal serial bus (USB) port (which may be included as one of the ports of the I / O interface), a network interface, and a BUS bus. Those skilled in the art will understand that... Figure 1 The structure shown is for illustrative purposes only and does not limit the structure of the aforementioned electronic device. For example, computer terminal 10 may also include... Figure 1 The more or fewer components shown, or having the same Figure 1 The different configurations shown.
[0030] It should be noted that the aforementioned one or more processors and / or other data processing circuits are generally referred to herein as "data processing circuits". These data processing circuits may be implemented wholly or partially as software, hardware, firmware, or any other combination thereof. Furthermore, the data processing circuits may be a single, independent processing module, or may be wholly or partially integrated into any other element in the computer terminal 10. As involved in the embodiments of this application, the data processing circuits serve as processor control (e.g., selection of a variable resistor termination path connected to an interface).
[0031] The memory 104 can be used to store software programs and modules of application software, such as program instructions / data storage devices corresponding to the data processing method in this embodiment. The processor executes various functional applications and data processing by running the software programs and modules stored in the memory 104, thereby implementing the aforementioned data processing method. The memory 104 may include high-speed random access memory and may also include non-volatile memory, such as one or more magnetic storage devices, flash memory, or other non-volatile solid-state memory. In some instances, the memory 104 may further include memory remotely located relative to the processor, and these remote memories can be connected to the computer terminal 10 via a network. Examples of such networks include, but are not limited to, the Internet, corporate intranets, local area networks, mobile communication networks, and combinations thereof.
[0032] The transmission module 106 is used to receive or send data via a network. Specific examples of the network described above may include a wireless network provided by the communication provider of the computer terminal 10. In one example, the transmission module 106 includes a Network Interface Controller (NIC), which can connect to other network devices via a base station to communicate with the Internet. In another example, the transmission module 106 may be a Radio Frequency (RF) module, used for wireless communication with the Internet.
[0033] The display may be, for example, a touchscreen liquid crystal display (LCD) that allows the user to interact with the user interface of the computer terminal 10.
[0034] It should be noted here that, in some optional embodiments, the above... Figure 1 The computer terminal shown may include hardware elements (including circuitry), software elements (including computer code stored on a computer-readable medium), or a combination of both hardware and software elements. It should be noted that... Figure 1 This is only one instance of a specific particular instance, and is intended to illustrate the types of components that may exist in the aforementioned computer terminal.
[0035] In the above operating environment, this application provides a method embodiment for data processing. It should be noted that the steps shown in the flowchart in the accompanying drawings can be executed in a computer system such as a set of computer-executable instructions. Also, although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in a different order than that shown here.
[0036] Figure 2 This is a flowchart of a data processing method according to an embodiment of this application, such as... Figure 2As shown, the method includes the following steps:
[0037] Step S202: Receive the access request sent by the target object.
[0038] Step S204: If the access request is to access the Internet, a first access path is provided through the Virtual Private Cloud (VPC) network created for the cloud host, and the Internet is accessed through the first access path.
[0039] In step S204 above, VPC is a service provided by public cloud providers that allows users (or target objects) to create an isolated, user-configurable, and managed virtual network environment within a public cloud environment. Users have complete control over their virtual network environment, including selecting IP address ranges, creating subnets, and configuring network access control policies.
[0040] In this embodiment of the application, the first access path can be created in the following way:
[0041] 1. Create a VPC instance: On the cloud service provider's console, create a new VPC instance and select a name, CIDR block (Classless Inter-Domain Router, used to define the IP address range within the VPC), and region for the created VPC.
[0042] 2. Create a subnet: Create a subnet in the VPC. A subnet defines a specific range of IP addresses within the VPC. Each subnet is associated with a specific availability zone.
[0043] 3. Configure security groups: Security groups act as virtual firewalls, controlling traffic entering and leaving one or more subnets. You can create security group rules to allow or deny specific types of network traffic, such as allowing HTTP or HTTPS traffic.
[0044] 4. Configure a NAT gateway or Elastic IP (EIP): To enable resources within a VPC subnet to access the internet, a NAT gateway or EIP needs to be configured. A NAT gateway allows multiple resources within the subnet to access the internet through a single public IP address, without requiring a separate EIP for each resource. An EIP, on the other hand, assigns a public IP address to a single resource, enabling it to directly access the internet.
[0045] By providing a primary access path to the VPC network created for the cloud host and configuring a NAT gateway or EIP along with corresponding routing and security policies, the cloud host can securely and efficiently access the Internet.
[0046] Step S206: If the access request is to access the cloud platform, a second access path is provided through the flat network created for the cloud host, and the cloud platform is accessed through the second access path.
[0047] In step S206 above, a flat network is a simplified network architecture that reduces network layers and complexity, improving network flexibility and scalability. In cloud platforms, flat networks are typically used to connect cloud hosts and other components of the cloud platform to achieve efficient internal communication. In an optional embodiment, a flat network can manage the network for the cloud platform.
[0048] In this embodiment of the application, the second access path can be created in the following manner:
[0049] 1. Cloud Server Network Configuration: In the cloud platform, configure a flat network for the cloud server. For example, you can select or create a flat network instance and connect the cloud server to that network. The cloud server's network interface will be configured to use the flat network's IP address range to communicate with other cloud servers or cloud platform components connected to the same network.
[0050] 2. Cloud Platform Network Architecture: The cloud platform's network architecture needs to support the deployment and management of a flat network. This includes configuring network switches, routers, and firewalls to ensure unimpeded communication between cloud hosts. The cloud platform also needs to provide necessary network services, such as DNS and DHCP, to support network configuration and domain name resolution for cloud hosts.
[0051] 3. Access Control Policies: To ensure the security of the cloud platform, access control policies need to be configured to restrict access to the cloud platform. This includes setting firewall rules, using security groups or network ACLs (Access Control Lists) to restrict network traffic. In a flat network, appropriate access control policies can be configured to allow cloud hosts to access other components of the cloud platform while blocking unauthorized access.
[0052] When accessing the cloud platform via a second access path, the following process can be used:
[0053] 1. Routing Configuration: The network architecture of the cloud platform requires the configuration of appropriate routing rules to ensure that cloud hosts can access other components of the cloud platform through a flat network. This involves configuring static routes, dynamic routing protocols, or default gateways.
[0054] 2. Packet Forwarding: When a cloud host initiates a request to access the cloud platform, the data packet is sent to the default gateway or router on the flat network. The router will forward the data packet to other components of the cloud platform according to the configured routing rules.
[0055] 3. Response Processing: Other components of the cloud platform will process the cloud host's request and generate a response data packet. The response data packet will be returned to the cloud host along the same path, completing the entire access process.
[0056] By providing a second access path to the cloud platform through a flat network created for the cloud host, and configuring appropriate routing, access control policies and security measures, efficient and secure access to the cloud platform by the cloud host can be achieved.
[0057] In step S202 of the above data processing method, before receiving the access request sent by the target object, the method further includes: receiving an inbound security group created by the self-service system, wherein the inbound security group is used to control the access rules for entering the self-service system, the self-service system is deployed in a cloud host, the self-service system is used to assist the cloud platform in processing the access request sent by the target object, and the cloud platform includes cloud hosts; and receiving an outbound security group created by the self-service system, wherein the outbound security group is used to control the access rules for entering the cloud platform.
[0058] In this embodiment, the self-service system is a system deployed on a cloud host. Its main function is to assist the cloud platform in processing access requests from target objects (e.g., users, applications, or other services). The self-service system provides a mechanism that enables target objects to access resources or services on the cloud platform more conveniently and independently. A cloud host is a basic building block in a cloud computing environment; it is a virtual or physical server that runs applications and services. The self-service system is deployed on a cloud host, which meets the configuration requirements of a self-service system based on a private cloud. A cloud platform is a collection that provides computing resources (such as servers, storage, databases, etc.) and services (such as software development, testing, deployment, etc.). The cloud platform allows users to access and use these resources and services via the Internet. The cloud platform includes cloud hosts, i.e., the environment in which the self-service system is deployed. A security group is a network security policy that defines a set of rules for controlling network traffic entering and leaving the cloud host or cloud platform. These rules can allow or deny traffic based on conditions such as IP address, port number, and protocol type. Specifically, an inbound security group is a set of rules that control access to the self-service system (i.e., the cloud host). By configuring inbound security groups, you can restrict which IP addresses, ports, and protocols can access the self-service system, thereby improving system security. Outbound security groups are a set of rules that control access rules originating from the self-service system (i.e., cloud hosts) and entering the cloud platform. By configuring inbound and outbound security groups for the self-service system, you ensure that only network traffic conforming to security policies can enter or exit the self-service system, thus guaranteeing the security of data transmission.
[0059] The above data processing method further includes: receiving cloud resource demand information selected by the target object in the cloud resource template; sending the cloud resource demand information to the cloud platform through the self-service system; receiving the approval result of the cloud platform on the cloud resource demand information; and receiving the cloud resources allocated by the cloud platform to the cloud host based on the approval result.
[0060] In this embodiment, a cloud resource template is a predefined configuration that describes attributes such as the type, quantity, and performance requirements of cloud resources. These templates make it easier for users to select cloud resources that suit their needs. Target objects (users, applications, etc.) browse and select the cloud resources they need from the cloud resource templates through some interface (e.g., web interface, API call, etc.). These selections may include, for example, virtual machine specifications, storage type and size, network configuration, etc. Once the target object makes a selection, this cloud resource requirement information is received. A self-service system is an intermediate layer that receives the target object's cloud resource requirement information and is responsible for transmitting this information to the cloud platform. Furthermore, the self-service system may contain logic to process or verify this requirement information to ensure it complies with the cloud platform's requirements or policies. Once verified, the self-service system sends the cloud resource requirement information to the cloud platform for further processing. After receiving the cloud resource requirement information, the cloud platform performs a series of checks and approval processes. These checks may include, for example, verifying user permissions, checking resource availability, and assessing resource costs. The approval result may be a simple "approval" or "rejection," or it may contain more detailed information, such as resource parameters that need to be adjusted or additional cost information. The self-service system receives and processes these approval results and then provides feedback to the target user. Specifically, if the approval result is "approved," the cloud platform will begin allocating the necessary cloud resources to the cloud host. The allocated resources may include, for example, virtual machine instances, storage volumes, network interfaces, etc. The self-service system is responsible for receiving this allocated resource information and presenting it to the target user. The target user can now use these resources to run applications, store data, or perform other tasks. This process embodies the self-service characteristics of a cloud computing environment, enabling the target user to quickly and flexibly access cloud resources according to their needs. Simultaneously, the approval and verification mechanisms of the cloud platform and the self-service system ensure the security and compliance of resource allocation.
[0061] In the above steps, the cloud resource template is determined in the following ways: determining the resource information contained in the cloud resource template, wherein the resource information includes at least one of the following: virtual machine configuration, network service, database service; creating the cloud resource template based on the resource information, security policy and usage permissions; verifying whether the template configuration of the cloud resource template is correct, and publishing the cloud resource template to the designated organization after the cloud resource template has been verified.
[0062] In this embodiment, before creating a cloud resource template, it is first necessary to determine what resource information the template will include. This resource information may include, for example, virtual machine configurations (such as CPU, memory, storage size, etc.), network services (such as network bandwidth, IP address, load balancing, etc.), and database services (such as database type, capacity, backup strategy, etc.). After determining the resource information, the next step is to create the cloud resource template based on this information, security policies, and usage permissions. Security policies may include, for example, network isolation, data encryption, and access control, to ensure resource security. Usage permissions define which users or organizations can access and use the template. After the template is created, it needs to be verified to ensure the correctness and validity of the template configuration. Verification may include, for example, checking whether the template configuration meets the requirements of the cloud platform, verifying whether the resource information is complete and conflict-free, and testing whether the template deployment process is smooth. If problems are found during verification, corresponding modifications and re-verification are required. Once the template passes verification, it can be published to the designated organization or user group. The publishing process may involve, for example, uploading the template to the cloud platform's repository, updating the template's metadata (such as description, version, etc.), and notifying relevant users or organizations. This process embodies the characteristics of resource management and automated deployment in a cloud computing environment. By creating and publishing cloud resource templates, the complexity of resource deployment can be simplified, deployment efficiency and consistency can be improved, while ensuring resource security and compliance.
[0063] In the above steps, receiving cloud resources allocated to the cloud host by the cloud platform based on the approval result includes: receiving cloud resources allocated by the cloud platform according to the cloud resource demand information if the approval result is approved; and receiving approval failure information sent by the cloud platform if the approval result is not approved.
[0064] In this embodiment, after the cloud resource request information submitted by the target object goes through the cloud platform's approval process, if the approval result is "approved," it means that the cloud platform has confirmed that these requests meet resource availability and security requirements. In this case, the cloud platform will allocate corresponding cloud resources based on the submitted cloud resource request information. These resources may include, for example, virtual machine instances, storage volumes, network interfaces, database services, etc. The target object (or its agent, such as a self-service system) will receive the cloud resource information allocated by the cloud platform, including the specific configuration of the resource, access credentials, location, etc. The received cloud resources can be used by the target object to run applications, store data, or perform other tasks.
[0065] If the approval result is "approval failed," it means that the cloud platform discovered some issues during the approval process, preventing the approval of these cloud resource requests. In this case, the cloud platform will send an approval failure message to the target entity (or its agent). This information may include, for example, the reason for the approval failure, possible modification suggestions, and guidelines for resubmitting the request. The target entity needs to make corresponding adjustments based on the approval failure message and can then resubmit the cloud resource request information for re-approval. The above process reflects the approval and resource management characteristics of a cloud computing environment. Through the approval process, the cloud platform can ensure that the allocation of cloud resources meets resource availability and security requirements, thereby maintaining the stability and security of the cloud environment. At the same time, by providing approval failure information and guidelines for resubmitting the request, the cloud platform also helps the target entity better adjust to successfully obtain the required cloud resources.
[0066] In another optional embodiment, cloud resource templates can also be configured and generated in the self-service system and published to a designated organization. These templates are used to add new cloud resource cards that can be applied for in service requests. Users configure these cloud resource cards to create the cloud host resources they require. The self-service system receives user applications, sends the application information to the cloud platform, and receives cloud resource demand information corresponding to the application information returned by the cloud platform. It also receives approval requests initiated by users corresponding to the cloud resource demand information, obtains the approval results of the requests, and sends the approval results to the cloud platform for execution.
[0067] The above data processing method further includes: obtaining resource operation requests initiated by the target object through the self-service system; automatically initiating an approval process for the resource operation request when the resource operation request includes operations on preset resources; and executing the resource operation request if the approval process results in approval.
[0068] In this embodiment, the target object (which may be a user, application, or service) initiates an operation request for cloud resources through a self-service system. These operation requests may include, for example, creating, modifying, or deleting cloud resources, or making some configuration changes to cloud resources. The self-service system receives these operation requests and forwards them to the backend approval system or cloud platform for processing. Upon receiving a resource operation request, the system checks whether the request involves preset resources. Preset resources may refer to resources that require special approval due to security, compliance, or resource limitations, such as applying for virtual machines, cloning virtual machines, canceling virtual machine subscriptions, canceling cloud disk subscriptions, expanding cloud disk capacity, or changing computing specifications. If the resource operation request includes operations on preset resources, the system automatically triggers an approval process. This approval process may involve multiple approval nodes, each of which may be handled by different approvers or system components. The approval process evaluates the rationality, security, and compliance of the resource operation request based on a series of rules and standards. If the resource operation request passes all nodes of the approval process and the approval result is "approved," the system will execute the resource operation request. The execution process may involve creating, modifying, or deleting resources on a cloud platform, or making configuration changes to resources. The execution result is fed back to the target, informing them whether the operation was successful, and any potential impact or follow-up steps. This entire process embodies the resource management and approval control characteristics of a cloud computing environment. By combining self-service systems and approval processes, it ensures that requests for cloud resource operations comply with security, compliance, and resource limitations, thereby maintaining the stability and security of the cloud environment. At the same time, this process also improves the efficiency and automation of resource operations, making it easier for target users to manage and use cloud resources.
[0069] In the above steps, after obtaining the resource operation request initiated by the target object through the self-service system, the method further includes: obtaining the request information in the resource operation request; generating an order record based on the resource operation request and the request information; and saving the order record in the database.
[0070] In this embodiment, upon receiving a resource operation request, the system extracts key information from the request. This information may include, for example, the identity of the target object, the type and quantity of the resource to be operated on, and configuration parameters. Based on the resource operation request and the extracted request information, the system generates an order record. This order record may contain detailed request information, such as the request type, target object, resource information, and operation time. The order record is the formal record of the resource operation request, used to track the processing status of the request, resource allocation, etc. After generating the order record, the system saves it in the database. The database is a key component in the cloud computing environment, used to store and manage various data, including user information, resource information, and order records. Saving order records facilitates subsequent resource management, auditing, and compliance checks. The entire process reflects the resource management and order processing characteristics of the cloud computing environment. Receiving resource operation requests, extracting request information, generating and saving order records through a self-service system ensures the transparency, traceability, and compliance of resource operations. Simultaneously, this process provides cloud computing service providers with an effective resource management tool, helping to improve service quality and customer satisfaction.
[0071] In another optional embodiment, when a user requests preset resources or performs risky operations in the self-service system, such as requesting virtual machines, cloning virtual machines, canceling virtual machine subscriptions, canceling cloud disk subscriptions, expanding cloud disk capacity, changing computing specifications, directly creating security groups, directly creating virtual machines, or directly creating cloud disks, an order record will be automatically generated. The order details the resource operations on the self-service system and is crucial for users to query information such as failed resource operations and resource deployment status. Therefore, each order within the order management system cannot be deleted. This order record provides users with a review panel where operations are traceable and resources are locatable. This self-service system addresses the issue of non-standardized resource and service delivery by providing definitions, applications, approvals, and management related to work orders and orders, meeting the need for standardized and rapid offline resource and service delivery.
[0072] Through the above steps, a self-service system is deployed on the cloud host, providing users with internet-based self-service access via the VPC network. Communication with the cloud platform is achieved through a flat network, bringing the cloud platform under management. User requests are sent to the cloud platform for processing in the form of work orders. The management network connects the self-service system and the cloud platform, enabling the smooth implementation of various work orders from the self-service system on the cloud platform. This achieves the goal of flexibly and efficiently managing cloud host access to the internet and cloud platform resources, thereby improving network access flexibility. Furthermore, it solves the technical problem of inconvenience for users after separating the business network and management network of the cloud platform in related technologies.
[0073] The self-service process in the above data processing method will be explained below with specific steps.
[0074] The self-service method is implemented through a series of service catalog operations. The service catalog, as an index of the cloud resource pool provided to customers, can be viewed as a back-end shelf for displaying goods. Users can create the cloud resource information they need in the cloud resource pool themselves, by configuring cloud resource templates in the service catalog. By building the service catalog, the required cloud resources, such as virtual machine templates, are treated as products. Only after publishing can the virtual machine be listed on the front-end shelf of the service application. Customers (applicants) can obtain the virtual machine configurations self-published by themselves in the service application, completing the virtual machine application and deployment. After the customer (applicant) completes the configuration and publication of the virtual machine template in the service catalog, a new card is added to the corresponding service application; this card represents the newly published virtual machine template, forming an application order. After the application order is formed, it enters the process management stage. Process management includes the necessary process configurations involved in risky operations involving important resources. When applying for or canceling virtual machines, cloud disks, or other resources, as well as self-service operations such as cloud disk expansion and changes in computing specifications, the corresponding process management will be automatically triggered, performing necessary process approval configurations. Once approved, the operation can be implemented. The self-service system retrieves the approval results of approval requests and sends them to the cloud platform. The system creates orders for self-service processes, allowing for the recording, tracking, and post-event auditing of application requests. Order factors include application content and basic information; users can view the factors triggering the current order based on these fields. Self-service system deployment includes operating system deployment and self-service software installation, while opening necessary ports on the VPC network and implementing necessary verification checks during deployment. The VPC network provides customers with an internet-accessible self-service system, and the management network connects the self-service system to the cloud platform, enabling the smooth execution of various work orders on the cloud platform.
[0075] Figure 3 This is a structural diagram of a data processing apparatus according to an embodiment of this application, such as... Figure 3 As shown, the device includes:
[0076] The receiving module 30 is used to receive access requests sent by the target object;
[0077] The first access module 32 is used to provide a first access path through the virtual private cloud network created for the cloud host when the access request is to access the Internet, and to access the Internet through the first access path.
[0078] The second access module 34 is used to provide a second access path through a flat network created for the cloud host when the access request is to access the cloud platform, and to access the cloud platform through the second access path.
[0079] In the receiving module of the aforementioned data processing device, the receiving module is further configured to receive an inbound security group created by the self-service system, wherein the inbound security group is used to control access rules for entering the self-service system, the self-service system is deployed in a cloud host, and the self-service system is used to assist the cloud platform in processing access requests sent by target objects, the cloud platform including cloud hosts; and to receive an outbound security group created by the self-service system, wherein the outbound security group is used to control access rules for entering the cloud platform.
[0080] In the receiving module of the aforementioned data processing device, the receiving module is further configured to receive cloud resource demand information selected by the target object in the cloud resource template; send the cloud resource demand information to the cloud platform through the self-service system; receive the approval result of the cloud platform on the cloud resource demand information; and receive the cloud resources allocated by the cloud platform to the cloud host based on the approval result.
[0081] The aforementioned data processing apparatus further includes a determining module 36, which is used to determine a cloud resource template. Specifically, the cloud resource template is determined by: determining the resource information contained in the cloud resource template, wherein the resource information includes at least one of the following: virtual machine configuration, network service, and database service; creating a cloud resource template based on the resource information, security policy, and usage permissions; verifying whether the template configuration of the cloud resource template is correct, and publishing the cloud resource template to a designated organization after the cloud resource template has been verified.
[0082] In the receiving module of the aforementioned data processing device, the receiving module is also used to receive cloud resources allocated by the cloud platform according to the cloud resource demand information when the approval result is approval passed; and to receive approval failure information sent by the cloud platform when the approval result is approval failed.
[0083] The aforementioned data processing apparatus also includes a processing module 38, which is used to acquire resource operation requests initiated by the target object through the self-service system; when the resource operation request includes operations on preset resources, it automatically initiates an approval process for the resource operation request; and if the approval result of the approval process is approval passed, it executes the resource operation request.
[0084] In the processing module of the aforementioned data processing device, the processing module is further configured to obtain request information from the resource operation request; generate an order record based on the resource operation request and the request information; and save the order record in the database.
[0085] It should be noted that, Figure 3The data processing apparatus shown is used to perform Figure 2 The data processing method shown above also applies to the data processing apparatus, and will not be repeated here.
[0086] This application also provides an electronic device, which includes a memory and a processor. The memory stores program instructions, and the processor is connected to the memory and executes program instructions to perform the following functions: receiving an access request sent by a target object; if the access request is to access the Internet, providing a first access path through a virtual private cloud network created for the cloud host, and accessing the Internet through the first access path; if the access request is to access a cloud platform, providing a second access path through a flat network created for the cloud host, and accessing the cloud platform through the second access path.
[0087] It should be noted that the aforementioned electronic equipment is used to perform Figure 2 The data processing method shown above also applies to this electronic device, and will not be repeated here.
[0088] This application also provides a non-volatile storage medium, which includes a stored computer program. The device containing the non-volatile storage medium executes the following data processing method by running the computer program: receiving an access request sent by a target object; if the access request is to access the Internet, providing a first access path through a virtual private cloud network created for the cloud host, and accessing the Internet through the first access path; if the access request is to access a cloud platform, providing a second access path through a flat network created for the cloud host, and accessing the cloud platform through the second access path.
[0089] It should be noted that the aforementioned non-volatile storage media is used for execution. Figure 2 The data processing method shown above also applies to this non-volatile storage medium, and will not be repeated here.
[0090] This application also provides a computer program product, including computer instructions that, when executed by a processor, implement the steps of the data processing methods in various embodiments of this application.
[0091] This application also provides a computer program that, when executed by a processor, implements the steps of the data processing methods in various embodiments of this application.
[0092] The sequence numbers of the embodiments in this application are for descriptive purposes only and do not represent the superiority or inferiority of the embodiments.
[0093] In the above embodiments of this application, the descriptions of each embodiment have different focuses. For parts not described in detail in a certain embodiment, please refer to the relevant descriptions of other embodiments.
[0094] In the several embodiments provided in this application, it should be understood that the disclosed technical content can be implemented in other ways. The device embodiments described above are merely illustrative; for example, the division of units can be a logical functional division, and in actual implementation, there may be other division methods. For instance, multiple units or components may be combined or integrated into another system, or some features may be ignored or not executed. Furthermore, the displayed or discussed mutual coupling, direct coupling, or communication connection may be through some interfaces; the indirect coupling or communication connection between units or modules may be electrical or other forms.
[0095] The units described as separate components may or may not be physically separate. The components shown as units may or may not be physical units; that is, they may be located in one place or distributed across multiple units. Some or all of the units can be selected to achieve the purpose of this embodiment according to actual needs.
[0096] Furthermore, the functional units in the various embodiments of this application can be integrated into one processing unit, or each unit can exist physically separately, or two or more units can be integrated into one unit. The integrated unit can be implemented in hardware or as a software functional unit.
[0097] If the integrated unit is implemented as a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to cause a computer device (which may be a personal computer, server, or network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of this application. The aforementioned storage medium includes various media capable of storing program code, such as USB flash drives, read-only memory (ROM), random access memory (RAM), portable hard drives, magnetic disks, or optical disks.
[0098] The above description is only a preferred embodiment of this application. It should be noted that for those skilled in the art, several improvements and modifications can be made without departing from the principle of this application, and these improvements and modifications should also be considered within the scope of protection of this application.
Claims
1. A data processing method, characterized in that, include: Receive access requests sent by the target object; In the case where the access request is to access the Internet, a first access path is provided through the virtual private cloud network created for the cloud host, and the Internet is accessed through the first access path. In the case where the access request is to access the cloud platform, a second access path is provided through the flat network created for the cloud host, and the cloud platform is accessed through the second access path. Before receiving the access request sent by the target object, the method further includes: receiving an inbound security group created by the self-service system, wherein the inbound security group is used to control the access rules for entering the self-service system, the self-service system is deployed in the cloud host, the self-service system is used to assist the cloud platform in processing the access request sent by the target object, and the cloud platform includes the cloud host; and receiving an outbound security group created by the self-service system, wherein the outbound security group is used to control the access rules for entering the cloud platform.
2. The method according to claim 1, characterized in that, The method further includes: Receive the cloud resource requirement information selected by the target object in the cloud resource template; The cloud resource demand information is sent to the cloud platform through the self-service system. Receive the approval result from the cloud platform regarding the cloud resource demand information; Based on the approval result, receive the cloud resources allocated by the cloud platform to the cloud host.
3. The method according to claim 2, characterized in that, The cloud resource template is determined in the following way: The resource information contained in the cloud resource template is determined, wherein the resource information includes at least one of the following: virtual machine configuration, network service, and database service; Based on the resource information, security policies, and usage permissions, create the cloud resource template; Verify that the cloud resource template configuration is correct, and after the cloud resource template passes verification, publish the cloud resource template to the designated organization.
4. The method according to claim 2, characterized in that, Receiving cloud resources allocated by the cloud platform to the cloud host based on the approval result includes: If the approval result is approved, the cloud resources allocated by the cloud platform according to the cloud resource demand information shall be received. If the approval result is that the approval is not approved, the cloud platform will be received with an approval failure message.
5. The method according to claim 1, characterized in that, The method further includes: Obtain the resource operation request initiated by the target object through the self-service system; When the resource operation request includes an operation on a preset resource, an approval process for the resource operation request is automatically initiated. If the approval result of the approval process is "approved", then the resource operation request is executed.
6. The method according to claim 5, characterized in that, After obtaining the resource operation request initiated by the target object through the self-service system, the method further includes: Obtain the request information from the resource operation request; Based on the resource operation request and the request information, an order record is generated; The order records are stored in the database.
7. A data processing apparatus, characterized in that, include: The receiving module is used to receive access requests sent by the target object; The first access module is configured to, when the access request is to access the Internet, provide a first access path through a virtual private cloud network created for the cloud host, and access the Internet through the first access path. The second access module is used to provide a second access path through a flat network created for the cloud host when the access request is to access the cloud platform, and to access the cloud platform through the second access path. The receiving module is further configured to receive an inbound security group created by the self-service system, wherein the inbound security group is used to control access rules for entering the self-service system, the self-service system is deployed in the cloud host, the self-service system is used to assist the cloud platform in processing access requests sent by the target object, and the cloud platform includes the cloud host; and to receive an outbound security group created by the self-service system, wherein the outbound security group is used to control access rules for entering the cloud platform.
8. An electronic device, characterized in that, include: Memory, used to store program instructions; The processor, connected to the memory, is configured to execute program instructions to perform the following functions: receiving an access request sent by a target object; if the access request is to access the Internet, providing a first access path through a virtual private cloud network created for the cloud host, and accessing the Internet through the first access path; if the access request is to access a cloud platform, providing a second access path through a flat network created for the cloud host, and accessing the cloud platform through the second access path. Before receiving the access request sent by the target object, the method further includes: receiving an inbound security group created by the self-service system, wherein the inbound security group is used to control the access rules for entering the self-service system, the self-service system is deployed in the cloud host, the self-service system is used to assist the cloud platform in processing the access request sent by the target object, and the cloud platform includes the cloud host; and receiving an outbound security group created by the self-service system, wherein the outbound security group is used to control the access rules for entering the cloud platform.
9. A non-volatile storage medium, characterized in that, The non-volatile storage medium includes a stored computer program, wherein the device containing the non-volatile storage medium executes the data processing method according to any one of claims 1 to 6 by running the computer program.
10. A computer program product comprising computer instructions, characterized in that, When the computer instructions are executed by the processor, they implement the data processing method according to any one of claims 1 to 6.
Citation Information
Patent Citations
Device for isolating business network and management network
CN108282462A
Business processing method, device and equipment and computer storage medium
CN112350931A