A method for high-availability deployment of federated peer clusters in edge environments
By deploying federated peer control plane and data plane components in each edge cluster, resource mapping and management are implemented, and the single point of failure, resource management imbalance and IP address conflict of existing edge federation clusters are solved, and the effects of high availability and resource elastic scaling are achieved.
Patent Information
- Application Number
- CN202510247095.5
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-06-06
- Estimated Expiration
- 2045-03-04
AI Technical Summary
Existing edge federated clusters have problems such as single point of failure risk, unbalanced resource management, and IP address conflicts, making it difficult to achieve high availability and resource elastic scaling.
Deploy federated peer control surface components and data surface components in each edge cluster, realize resource mapping and management through virtual nodes, automatically handle network IP address conflicts, and automatically reconnect the missing cluster through VPN tunnels.
It realizes the coordinated work of high availability and resource management between edge clusters, avoids single point of failure, improves resource utilization and elastic scaling capabilities, and solves IP address conflict problems.
Smart Images

Figure CN119743483B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of edge cluster technology, and in particular to a method for high-availability deployment of a federated peer cluster in an edge environment. Background Art
[0002] As cloud-native technologies represented by Kubernetes continue to mature, a large number of users deploy, use and manage multiple container clusters in the edge field to manage edge intelligent devices and scientific computing, and the multi-cloud and multi-cluster strategy is becoming more and more obvious. In the edge environment, multiple edge clusters run independently outdoors, isolated from each other, unable to perceive each other's operating status and dynamic resource usage; there is a lack of unified task management across clusters, there is a risk of single point failure, and it is difficult to form a systematic federated deployment and collaborative management.
[0003] At present, the existing edge federation clusters include control plane clusters and data plane clusters. The control plane cluster is a cluster in which control plane components are deployed in any edge cluster to control and coordinate the data plane cluster. The data plane cluster is a cluster in which data proxy components are deployed in other edge clusters except the control plane cluster to receive control data information of the control plane components and perform related control actions. It can be seen that the edge federation cluster deploys control plane components only in one edge cluster and data plane components in other edge clusters. The relationship between the edge clusters is not equal and has a primary and secondary distinction.
[0004] However, this edge federation cluster has many drawbacks:
[0005] (1) When an edge cluster joins or leaves an edge federation cluster, the cluster role relationship needs to be manually configured, and cross-cluster network communication cannot be automatically achieved;
[0006] (2) The control plane cluster acts as the control brain to coordinate and control different data plane clusters. If the control plane cluster is destroyed or disconnected, the control data information will be lost, and then the various data plane clusters will not be able to work together normally;
[0007] (3) After the edge federation cluster is established, the edge clusters cannot perceive each other's total resource volume and resource usage status, resulting in problems such as unbalanced resource usage and fragmented verification, and unable to provide elastic expansion and contraction of resources across clusters;
[0008] (4) The internal network IP address segments of multiple edge clusters may overlap, and various edge clusters cannot negotiate to resolve IP address conflicts. Summary of the invention
[0009] The present invention provides a method for high-availability deployment of a federated peer cluster in an edge environment, which is used to solve the above-mentioned problems existing in the existing edge federated cluster.
[0010] The present invention provides a method for high-availability deployment of a federated peer cluster in an edge environment, the method comprising: deploying a federated peer control plane component and a federated peer data plane component in each edge cluster, each federated peer control plane component being in a peer relationship with each other; wherein, when a network peer connection is established between any two edge clusters, if authentication is successful, the federated peer control plane components of the two edge clusters respectively create virtual nodes of a peer cluster in their respective clusters through their respective federated peer data plane components, thereby realizing resource mapping and management of their respective peer clusters.
[0011] Furthermore, the federated peer control plane components include: a network IP address management module, a NAT mapping operation module, a virtual Kubelet management module and a cluster peer management module; the federated peer data plane components include: virtual nodes and computing nodes.
[0012] Furthermore, if the authentication is successful, the virtual Kubelet management modules of the two edge clusters respectively create virtual nodes of the peer cluster in their respective clusters through their respective virtual Kubelets, obtain node mapping of the peer cluster, and thus realize bidirectional resource management of the two edge clusters.
[0013] Furthermore, the deployment method includes:
[0014] Distribute user-defined resource object instances to member clusters of the peer-to-peer network to be established, so that each peer member cluster in the peer-to-peer network uses WebHook to intercept and deploy user-defined resource object instances. The controller continuously corrects the status of user-defined resource object instances by defining control and coordination logic in advance, so as to achieve cluster peer management, network IP address management, resource mapping and deployment management control when the federal control plane components defined in the user-defined resources are deployed, and realize automatic deployment of federal peer clusters by federal peer control plane components and federal peer data plane components.
[0015] Furthermore, when establishing a network peer connection between two edge clusters,
[0016] When the connection is normal, obtain the federated peer cluster, and the resource information between the federated peer clusters is exchanged to achieve mutual deployment, scheduling and unloading of resources;
[0017] When the connection is abnormal, the normal peer cluster in the federated peer cluster stops the resource deployment, scheduling and unloading of the disconnected cluster, and continuously and automatically detects the viability of the disconnected cluster through the VPN tunnel until the network peer connection is established again and the disconnected cluster is determined to be active, and then the disconnected cluster is automatically added to the federated peer cluster.
[0018] Furthermore, when the network IP addresses of the two edge clusters conflict, the Pod external IP CIDR and NAT external IP CIDR between the two edge clusters are mapped to each other through the network IP address management module and NAT mapping operation module of the two edge clusters respectively, so as to obtain the NAT conversion and routing rule configuration of the network IP address.
[0019] Further, when the remote edge cluster joins the federated peer cluster, the network IP address management module determines whether the Pod CIDR of the remote edge cluster is available in the local edge cluster;
[0020] If it can be used, the network IP address management module reserves the network and maps the network IP address allocated in the remote edge cluster to the local edge cluster for use;
[0021] If it cannot be used, the network IP address management module will remap the Pod CIDR that conflicts with the remote edge cluster to a new address space and keep it for use.
[0022] Further, determining whether the Pod CIDR of the remote edge cluster is available in the local edge cluster includes:
[0023] The network IP address management module creates a list of all networks currently used by the local edge cluster, which is recorded as the local network list; when a new peer edge cluster is interconnected, the local network list is allocated and added to the remote network list of the remote edge cluster;
[0024] When the network of the peer edge cluster is active, the network is saved in the network lists of both parties; when the network of the peer edge cluster is disconnected or terminated, the network is removed from the network lists of both parties until the network of the peer edge cluster is joined or interconnected again, at which time the network is added back to the network lists of both parties.
[0025] Further, when the disconnected cluster is in a disconnected state or a terminated state, the VPN tunnel is used to continuously attempt to connect using the P2P protocol until the disconnected cluster comes back online, and then the VPN tunnel automatically establishes a connection.
[0026] Furthermore, a Kubernetes control plane component is deployed in each edge cluster. The Kubernetes control plane component is a Kube-API service, which is set on the management node of the edge cluster and is used to establish a communication connection with the cluster peer management module in the federated peer control plane component of the peer cluster and perform identity authentication. After the authentication is established, the cluster identity information between each other is exchanged.
[0027] In general, the present invention provides a method for high-availability deployment of a federated peer cluster in an edge environment. The technical solution conceived by the present invention can achieve the following beneficial effects compared with the prior art:
[0028] (1) The present invention deploys and runs the federated peer control plane components and the federated peer data plane components in each edge cluster at the same time, so that the federated peer control plane components in each member cluster are mutually peer-to-peer, have no subordinate relationship, and are not limited to a certain edge cluster. Even if an edge cluster joins or leaves the federated cluster, cross-cluster communication can be automatically achieved without affecting the stability of the entire federated peer cluster, as well as the existing network structure and resource management of each cluster, thereby realizing the network management of the edge cluster. In addition, the member clusters work together to avoid single point failures, enhance disaster recovery and backup capabilities, and ensure the high availability of the federated cluster control plane network.
[0029] (2) The present invention realizes cross-cluster resource management by synchronizing the total amount of resources and resource usage status through resource mapping between virtual nodes and edge clusters. It not only provides cross-cluster resource aggregation, dynamic resource allocation and resource scheduling capabilities, thereby improving resource utilization, reducing costs and increasing efficiency. It also provides the ability for multi-cluster computing resources and network status to perceive each other, thereby enhancing the cross-cluster elastic expansion and contraction and fault self-healing capabilities.
[0030] (3) The present invention sets up a network IP address management module and a NAT mapping operation module to map the Pod external IP CIDR and the NAT external IP CIDR between the two edge clusters to each other, obtain the NAT conversion and routing rule configuration of the network IP address, and avoid the problem of network IP address conflict. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] In order to more clearly illustrate the technical solutions in the present invention or the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative work.
[0032] Figure 1 It is a schematic diagram of the architecture of a method for high-availability deployment of a federated peer cluster in an edge environment provided by the present invention;
[0033] Figure 2 It is a schematic diagram of a federated peer cluster deployment method for high-availability deployment of a federated peer cluster in an edge environment provided by the present invention;
[0034] Figure 3It is a federated peer cluster control logic diagram of a method for high-availability deployment of a federated peer cluster in an edge environment provided by the present invention. DETAILED DESCRIPTION
[0035] In order to make the purpose, technical solution and advantages of the present invention clearer, the technical solution of the present invention will be clearly and completely described below in conjunction with the drawings and embodiments of the present invention. Obviously, the described embodiments are part of the embodiments of the present invention, not all of the embodiments. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without creative work belong to the scope of protection of the present invention.
[0036] It should be noted that, in the description of the embodiments of the present invention, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a method, step or device including a series of elements includes not only those elements, but also includes other elements not explicitly listed, or also includes elements inherent to such method, step or device. In the absence of further restrictions, the elements defined by the sentence "include a ..." do not exclude the existence of other identical elements in the method, step or device including the elements.
[0037] The English and English abbreviations involved in this invention are explained as follows:
[0038] NAT: Network Address Translation;
[0039] Kubele: is a proxy component on the Kubernetes worker node and runs on each node;
[0040] Kubernetes: a unified resource orchestration platform for containers;
[0041] WebHook: HTTP-based callback function that enables event-driven, lightweight communication between APIs;
[0042] Pod: a workload resource object provided by a container cluster and the smallest unit of container orchestration management;
[0043] CIDR: Classless Inter-Domain Routing, which aggregates and allocates network IP addresses;
[0044] VPN: Virtual Private Network;
[0045] P2P: peer-to-peer network communication protocol;
[0046] CNI: container orchestration platform network interface;
[0047] Service: the service object provided by the container cluster, which implements the network layer 4 access of the container service;
[0048] Ingress: A service object provided by a container cluster that implements Layer 7 network access to container services.
[0049] In order to achieve the peer relationship between each member cluster in the federated peer cluster, the existing network structure and resource management of each cluster are not affected when the peer relationship is established, and the overall stability is not affected when the cluster joins or leaves the federated peer cluster. The present invention provides a method for high-availability deployment of a federated peer cluster in an edge environment, wherein the federated peer cluster includes multiple edge clusters, such as Figure 1 As shown, the method includes:
[0050] A federated peer control plane component and a federated peer data plane component are deployed in each edge cluster. Each federated peer control plane component is in a peer relationship with each other and has no subordinate relationship. When a network peer connection is established between any two edge clusters, if the authentication is successful, the federated peer control plane components of the two edge clusters respectively create virtual nodes of the peer cluster in their respective clusters through their respective federated peer data plane components to achieve resource mapping and management of their respective peer clusters.
[0051] That is to say, the federated peer control plane components and the federated peer data plane components are deployed in each cluster, so that each cluster in the federated peer cluster is peer to each other, without master-slave distinction, and works together to ensure the high availability of the federated peer cluster.
[0052] The federated peer control plane is set up on the computing node, including: network IP address management module, NAT mapping operation module, virtual Kubelet management module and cluster peer management module.
[0053] The network IP address management module is used to manage the network IP addresses between federated peer clusters. When there is overlap in network IP addresses, it is fed back to the NAT mapping operation module to map and convert the network IP addresses, thereby preventing IP address conflicts.
[0054] The NAT mapping operation module is used to obtain the network IP addresses between federated peer clusters and map and convert them.
[0055] The virtual Kubelet management module is used to monitor the control logic of the virtual Kubelet and deploy and manage the virtual Kubelet.
[0056] The cluster peer management module is used to connect and assemble different edge cluster networks to achieve peer management of network clusters.
[0057] The federated peer data plane is used to carry the network, resources, and workloads distributed by the control plane, and works together through the mapping of local cluster resources and remote cluster resources. The federated peer data plane components include virtual nodes and computing nodes.
[0058] As an example, Figure 2 As shown, the federated peer data plane component includes a first virtual Kubelet set on a virtual node and a second virtual Kubelet set on a computing node; the first virtual Kubelet is used to map remote cluster resources; the second virtual Kubelet is used to map local cluster resources.
[0059] It should be noted that after a member cluster joins a federated peer cluster, the federated peer data plane component starts the virtual Kubelet component to simulate the operation of a virtual node, which maps the resources and workloads of the remote edge cluster.
[0060] In addition, a Kubernetes control plane component is deployed in each edge cluster. The Kubernetes control plane component is the Kube-API service, which is set up on the management node of the edge cluster and is used to establish a communication connection with the cluster peer management module in the federated peer control plane component of the peer cluster and perform identity authentication. After the authentication is established, the cluster identity information between each other is exchanged. Among them, the Kube-API service and Kubelet are the cluster API service and container management components provided by the Kubernetes native container orchestration, respectively.
[0061] It should be noted that the method for establishing a network peer connection between two edge clusters may be: the local edge cluster establishes a communication connection between the local edge cluster and the remote edge cluster through the authentication management module and the Kube-API service module of the remote edge cluster.
[0062] As an embodiment, when a network peer connection is established between two edge clusters, when the connection is normal, the federated peer cluster is obtained, and resource information is exchanged between the federated peer clusters to achieve mutual deployment, scheduling and unloading of resources; when the connection is abnormal, the normal peer cluster in the federated peer cluster stops the resource deployment, scheduling and unloading of the lost cluster, and continuously automatically detects the survivability of the lost cluster through the VPN tunnel until the network peer connection is established again and the lost cluster is determined to be active, and then the lost cluster is automatically added to the federated peer cluster.
[0063] It should be noted that successful authentication means that both parties perform identity authentication, which requires the exchange of cluster resource information, that is, the exchange of network authentication parameters; for example, network authentication parameters may include user-defined resources such as API services, authentication addresses, authentication identifiers, VPN tunnel addresses, and VPN authentication certificates.
[0064] As an embodiment, if the authentication is successful, the virtual Kubelet management modules of the two edge clusters respectively create virtual nodes of the peer cluster in their respective clusters through their respective virtual Kubelets, obtain the node mapping of the peer cluster, and thus realize bidirectional resource management of the two edge clusters.
[0065] Specifically, when the remote edge cluster establishes a network peer connection with the local edge cluster, the virtual Kubelet management module of the local edge cluster creates a virtual node through its virtual Kubelet to achieve node mapping of the remote edge cluster's network, resources, and workloads in the local edge cluster. The local edge cluster can then manage the resources provided by the remote edge cluster in the same way as it manages local resources.
[0066] Similarly, when the local edge cluster establishes a network peer connection with the remote edge cluster, the virtual Kubelet management module of the remote edge cluster creates a virtual node through its virtual Kubelet to achieve node mapping of the local edge cluster's network, resources, and workloads in the remote edge cluster. The remote edge cluster can then manage the resources provided by the local edge cluster in the same way as it manages remote resources.
[0067] The federated peer cluster performs resource mapping, resource sharing, network IP address management, network IP NAT mapping and other user-defined resources between customized virtual nodes and cluster resources.
[0068] As a specific embodiment, the deployment method includes: distributing user-defined resource object instances to member clusters of a peer network to be established, so that each peer member cluster in the peer network uses WebHook to intercept and deploy the user-defined resource object instances, and the controller continuously corrects the status of the user-defined resource object instances by defining control and coordination logic in advance, so that the federated peer control plane components and federated peer data plane components defined in the user-defined resources can automatically deploy the federated peer cluster, thereby realizing the control of cluster resource mapping, resource sharing, network IP address management and network IP NAT mapping when the federated peer cluster is deployed.
[0069] It should be noted that if Figure 3 As shown, the federated peer cluster deployment process includes: establishing multiple user-defined resources and controllers.
[0070] The resource mapping between virtual machine nodes and peer cluster resources includes: the federated peer cluster uses the standard nodes, Pods, operating systems, and capacity interfaces provided by the virtual Kubelet of Kubernetes to build a virtual node to map a remote edge cluster, and then maps the resource information of the remote edge cluster, so that the resources of the remote edge cluster can also be used in the local edge cluster.
[0071] It should be noted that when the local edge cluster and the remote edge cluster join the federated peer cluster, they have their own network IP CIDRs, and the two edge clusters are not known in advance, so the network IP CIDRs of the two edge clusters may overlap. In the edge environment, the federated peer control plane component of the federated peer cluster is not suitable for exclusive cluster deployment as a unified control center to manage the data plane member clusters, which is prone to exclusive control cluster anomalies, resulting in the loss of control of the entire federated peer cluster, and cannot meet the high-availability deployment requirements of the federated peer control plane.
[0072] Therefore, the federated peer control plane components and the federated peer data plane components of the federated peer cluster are deployed in the same member cluster. Member clusters do not distinguish between control clusters and working clusters, and are all regarded as ordinary member clusters. Clusters are peer clusters to each other.
[0073] The CNI installed by default in the Kubernetes cluster assigns a unique IP address to each Pod, which is valid within the cluster, allowing Pods to communicate directly with each other even without using Layer 4 Services or Layer 7 Ingress services. The federated peer cluster uses the resources shared by the remote edge cluster to extend to the local edge cluster, allowing Pods in each member cluster to communicate directly with each other without changing the default behavior of the original cluster.
[0074] It should be noted that before joining the federated peer cluster, each member cluster already has its own PodCIDR and external Pod CIDR address range. There may be overlapping Pod CIDR and external Pod CIDR address ranges, causing network IP address conflicts.
[0075] In order to avoid network IP address conflicts and ensure that each Pod IP address is reachable across member clusters without changing the default Pod CIDR and external Pod CIDR address range of each member cluster, the present invention automatically checks for network IP address conflicts through a network IP address management module in a federated peer cluster.
[0076] As an embodiment of the present invention, after a federated peer cluster is established, when a conflict occurs in the network IP addresses of two edge clusters, without changing the existing cluster network structure and network IP CIDR, the Pod external IP CIDR and NAT external IP CIDR between the two edge clusters are respectively mapped to each other through the network IP address management modules and NAT mapping operation modules of the two edge clusters to obtain the NAT conversion and routing rule configuration of the network IP address, thereby solving the problem of IP address conflict.
[0077] The network IP address management module is used to manage the network IP addresses between federated peer clusters. When there is overlap in network IP addresses, it is fed back to the NAT mapping operation module to map and convert the network IP addresses, thereby preventing IP address conflicts.
[0078] Furthermore, the network IP address resources and NAT mapping conversion resources currently used by the local edge cluster are managed, and the shared Pod IP addresses allocated by the remote edge cluster are converted to the corresponding IP addresses visible to the local edge cluster, and the endpoint IP addresses associated with the Service are converted during the resource mapping process.
[0079] As an embodiment, when a remote edge cluster joins a federated peer cluster, the network IP address management module determines whether the Pod CIDR of the remote edge cluster can be used in the local edge cluster; if it can be used, the network IP address management module reserves the network and maps the network IP address allocated in the remote edge cluster to the local edge cluster for use; if it cannot be used, the network IP address management module remaps the Pod CIDR that conflicts with the remote cluster to a new address space and retains it for use.
[0080] Furthermore, determine whether the Pod CIDR of the remote edge cluster is available in the local edge cluster, including:
[0081] The network IP address management module creates a list of all networks currently used by the local edge cluster, which is recorded as the local network list; when a new peer edge cluster is interconnected, the local network list is assigned and added to the remote network list of the remote edge cluster;
[0082] When the network of the peer edge cluster is active, the network is saved in the network lists of both parties; when the network of the peer edge cluster is disconnected or terminated, the network is removed from the network lists of both parties until the network of the peer edge cluster is joined or interconnected again, at which time the network is added back to the network lists of both parties and continues to be used.
[0083] With reference to the network IP address resources of the federated peer cluster network address conflict, the NAT mapping operation module is used to control and adjust the NAT mapping resources.
[0084] Specifically, the NAT mapping operation module obtains the external Pod CIDR to prevent conflicts, and the peer edge cluster exposes the workload of the network IP address that does not belong to the Pod CIDR address range. For each entry in the custom resource, the NAT mapping operation module configures a network address translation rule to send incoming traffic destined for the external Pod CIDR IP address to the correct workload. The workload targeted by the external network IP address can be a workload within a specific cluster or an external workload that can be reached from the current cluster.
[0085] Since member clusters that have passed mutual peer authentication automatically store network configuration and tunnel endpoint information in each member cluster to achieve resource synchronization between different clusters, member clusters that have passed mutual peer authentication can not only freely join or leave the federated docking cluster, but also become peer clusters in one direction. However, a certain edge cluster network of a federated peer cluster may also lose connection due to other reasons. When a disconnected cluster is mapped through a virtual node, the virtual node will also be in a disconnected state, and the mapped disconnected cluster will no longer accept task scheduling.
[0086] As an embodiment, when the disconnected cluster is in a disconnected state or terminated state, the VPN tunnel uses the P2P protocol to continuously try to connect until the disconnected cluster comes back online. The VPN tunnel automatically establishes a connection. The entire process does not require manual intervention and can ensure high-availability management of the federated peer cluster throughout its life cycle.
[0087] In summary, the present invention provides a method for high-availability deployment of a federated peer cluster in an edge environment, which realizes network management of peer edge clusters and is not limited to a certain edge cluster. Even when an edge cluster joins or leaves the federated peer cluster, it does not affect the stability of the entire federated peer cluster, nor does it affect the existing network structure and resource management within each edge cluster. The member clusters work together to ensure the high availability of the federated peer cluster.
[0088] It should be noted that, for the above-mentioned various embodiments, for the sake of simplicity of description, they are all expressed as a series of action combinations, but those skilled in the art should be aware that the present application is not limited by the described order of actions, because according to the present application, certain steps can be performed in other orders or simultaneously. Secondly, those skilled in the art should also be aware that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily required by the present application.
[0089] In the above embodiments, the description of each embodiment has its own emphasis. For parts that are not described in detail in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0090] In the several embodiments provided in this application, it should be understood that the disclosed method or system can be implemented in other ways. For example, the above-described embodiments are only schematic, and the division of the units is only a logical function division. There may be other division methods in actual implementation, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed.
[0091] The units described as separate components may or may not be physically separated, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed on multiple network units. Some or all of the units may be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0092] In addition, each functional unit in each embodiment of the present application may be integrated into one processing unit, or each unit may exist physically separately, or two or more units may be integrated into one unit. The above-mentioned integrated unit may be implemented in the form of hardware or in the form of software functional units.
[0093] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or the whole or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a memory, including a number of instructions for a computer device (which can be a personal computer, a server or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application.
[0094] Those skilled in the art will appreciate that all or part of the various circuits in the above embodiments may be completed by entering a program to instruct related hardware, and the program may be stored in a computer-readable memory, which may include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk, etc.
[0095] The above is only an exemplary embodiment of the present disclosure, and the scope of the present disclosure cannot be limited thereto. That is, any equivalent changes and modifications made according to the teachings of the present disclosure are still within the scope of the present disclosure. After considering the specification and practicing the disclosure here, those skilled in the art will easily think of the implementation scheme of the present disclosure. This application is intended to cover any modification, use or adaptation of the present disclosure, which follows the general principles of the present disclosure and includes common knowledge or customary technical means in the technical field not recorded in the present disclosure. The description and examples are regarded as exemplary only, and the scope and spirit of the present disclosure are defined by the claims.
[0096] The technical features of the above embodiments may be combined arbitrarily. To make the description concise, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, they should be considered to be within the scope of this specification.
[0097] It will be easily understood by those skilled in the art that the above description is only a preferred embodiment of the present invention and is not intended to limit the present invention. Any modifications, equivalent substitutions and improvements made within the spirit and principles of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for high-availability deployment of a federated peer cluster in an edge environment, wherein the federated peer cluster includes multiple edge clusters, characterized in that: The method comprises: A federated peer control plane component and a federated peer data plane component are deployed in each edge cluster, and each federated peer control plane component is in a peer relationship with each other; wherein, when a network peer connection is established between any two edge clusters, if the authentication is successful, the federated peer control plane components of the two edge clusters respectively create virtual nodes of the peer cluster in their respective clusters through their respective federated peer data plane components, thereby realizing resource mapping and management of their respective peer clusters; The federated peer control plane components include: a network IP address management module, a NAT mapping operation module, a virtual Kubelet management module and a cluster peer management module; the network IP address management module is used to manage the network IP addresses between federated peer clusters. When there is an overlap in network IP addresses, it is fed back to the NAT mapping operation module to map and convert the network IP addresses to prevent IP address conflicts; the NAT mapping operation module is used to obtain the network IP addresses between federated peer clusters and map and convert them; the cluster peer management module is used to connect and assemble different edge cluster networks to achieve network cluster peer management; The federated peer data plane components include: virtual nodes and computing nodes; if the authentication is successful, the virtual Kubelet management modules of the two edge clusters respectively create virtual nodes of the peer cluster in their respective clusters through their respective virtual Kubelets, obtain the node mapping of the peer cluster, and thus realize bidirectional resource management of the two edge clusters.
2. According to the method for high-availability deployment of a federated peer cluster in an edge environment in claim 1, it is characterized in that: The deployment method includes: Distribute user-defined resource object instances to member clusters of the peer-to-peer network to be established, so that each peer member cluster in the peer-to-peer network uses WebHook to intercept and deploy user-defined resource object instances. The controller continuously corrects the status of user-defined resource object instances by defining control and coordination logic in advance, so as to achieve cluster peer management, network IP address management, resource mapping and deployment management control when the federal control plane components defined in the user-defined resources are deployed, and realize automatic deployment of federal peer clusters by federal peer control plane components and federal peer data plane components.
3. According to the method for high-availability deployment of a federated peer cluster in an edge environment in claim 1, it is characterized in that: When establishing a network peering connection between two edge clusters, When the connection is normal, obtain the federated peer cluster, and the resource information between the federated peer clusters is exchanged to achieve mutual deployment, scheduling and unloading of resources; When the connection is abnormal, the normal peer cluster in the federated peer cluster stops the resource deployment, scheduling and unloading of the disconnected cluster, and continuously and automatically detects the viability of the disconnected cluster through the VPN tunnel until the network peer connection is established again and the disconnected cluster is determined to be active, and then the disconnected cluster is automatically added to the federated peer cluster.
4. The method for high-availability deployment of a federated peer-to-peer cluster in an edge environment according to claim 1, characterized in that: When the network IP addresses of two edge clusters conflict, the Pod external IP CIDR and NAT external IP CIDR between the two edge clusters are mapped to each other through the network IP address management module and NAT mapping operation module of the two edge clusters to obtain the NAT conversion and routing rule configuration of the network IP address.
5. The method for high-availability deployment of a federated peer cluster in an edge environment according to claim 4, characterized in that: When a remote edge cluster joins a federated peer cluster, the network IP address management module determines whether the Pod CIDR of the remote edge cluster is available in the local edge cluster; If it can be used, the network IP address management module reserves the network and maps the network IP address allocated in the remote edge cluster to the local edge cluster for use; If it cannot be used, the network IP address management module will remap the Pod CIDR that conflicts with the remote edge cluster to a new address space and keep it for use.
6. The method for high-availability deployment of a federated peer cluster in an edge environment according to claim 5, characterized in that: Determine whether the Pod CIDR of the remote edge cluster is available in the local edge cluster, including: The network IP address management module creates a list of all networks currently used by the local edge cluster, which is recorded as the local network list; when a new peer edge cluster is interconnected, the local network list is allocated and added to the remote network list of the remote edge cluster; When the network of the peer edge cluster is active, the network is saved in the network lists of both parties; when the network of the peer edge cluster is disconnected or terminated, the network is removed from the network lists of both parties until the network of the peer edge cluster is joined or interconnected again, at which time the network is added back to the network lists of both parties.
7. The method for high-availability deployment of a federated peer cluster in an edge environment according to claim 6, characterized in that: When the disconnected cluster is in a disconnected state or a terminated state, the VPN tunnel is used to continuously try to connect using the P2P protocol until the disconnected cluster comes back online, and then the VPN tunnel automatically establishes a connection.
8. The method for high-availability deployment of a federated peer cluster in an edge environment according to claim 1, characterized in that: A Kubernetes control plane component is also deployed in each edge cluster. The Kubernetes control plane component is a Kube-API service, which is set on the management node of the edge cluster. It is used to establish a communication connection with the cluster peer management module in the federated peer control plane component of the peer cluster and perform identity authentication. After the authentication is established, the cluster identity information between each other is exchanged.
Citation Information
Patent Citations
Data distributed storage management system oriented to edge device
CN115733848A
Serverless Kubernetes-oriented multi-tenant isolation method
CN117880099A