A Method for Dynamically Automatically Assembling a Network of Federal Peer Clusters in an Edge Environment
By creating a unique identity for each edge cluster in an edge environment and using the network management control module to establish peer cluster resources and VPN tunnel endpoint information, the single point of failure and automatic assembly of edge federation clusters in harsh environments is solved, and dynamic automatic assembly networks and cross-cluster network traffic management between multi-edge clusters are realized.
Patent Information
- Application Number
- CN202510247027.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-04
- Publication Date
- 2025-06-13
- Estimated Expiration
- 2045-03-04
AI Technical Summary
Existing edge federated clusters are prone to abnormal situations such as cluster destruction, network disconnection and weak network in harsh environments, resulting in resource interconnection and scheduling failure, a single point of failure risk, and lack the ability to automatically assemble and refined network traffic management.
By creating unique identity credentials in each edge cluster, using the network management control module to establish peer cluster resources and VPN tunnel endpoint information, establishing secure tunnels for resource synchronization and exchange, realizing dynamic automatic assembly of networks between multi-edge clusters.
It realizes automatic assembly of networks between multiple edge clusters in an edge environment, avoids single point of failure, simplifies network configuration, meets the timeliness and maneuverability requirements of the wild environment, and provides cross-cluster network traffic management capabilities.
Smart Images

Figure CN119743485B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the field of edge cluster technology, and in particular to a method for dynamically and automatically assembling a network of a federated peer cluster in an edge environment. Background Art
[0002] With the development of containerization technology and the widespread application of edge computing, users use a large number of containers to cluster, orchestrate and manage edge devices, thereby realizing cloud-edge collaboration and intelligent computing.
[0003] The existing edge federation cluster includes a master edge cluster and multiple slave edge clusters. The multiple slave edge clusters are controlled by the master edge cluster. After the master edge cluster and the slave edge clusters are connected to the network, the master edge cluster manages cross-edge cluster tasks through resource distribution strategies and resource differentiation coverage configuration strategies.
[0004] However, the edge environment has diverse characteristics such as harsh environment and sudden situations. Therefore, it is very easy for abnormal situations such as edge cluster destruction, network disconnection and weak network to occur in the edge federation cluster. Abnormal situations will cause the edge cluster to lose connection, resulting in the inability to interconnect and schedule resources between the normal edge cluster and the disconnected edge cluster; especially when the network of the main edge cluster is abnormal, other slave edge clusters cannot work together; and each slave edge cluster is independent of each other, without strong connection, and the network may not be interoperable. If the main edge cluster is destroyed, the federation cluster will be unavailable as a whole, and there is a risk of single point failure.
[0005] In addition, since the networks of the slave edge clusters are not interoperable, in order to achieve network connectivity of the edge federation cluster, manual identity authentication is required to identify the identities of both parties, and switch the network master-slave relationship or configuration of the master edge cluster and the slave edge cluster to achieve cross-cluster network connectivity; and when the lost edge cluster network is restored, it is also necessary to manually configure the network for reassembly, and the lost edge cluster cannot automatically rejoin the federation cluster; not only does it have poor configuration flexibility and a complex and error-prone configuration process, it cannot meet the timeliness and mobility requirements of edge device collaboration in the field environment; it also lacks the ability to manage refined network traffic across clusters, and there are network isolation and security issues across clusters. Summary of the invention
[0006] The present invention provides a method for dynamically and automatically assembling a network of a federated peer cluster in an edge environment, which is used to solve the above-mentioned problems existing in the existing edge federated cluster.
[0007] The present invention provides a method for dynamically and automatically assembling a network of a federated peer cluster in an edge environment, the method comprising:
[0008] Each edge cluster creates a unique identity credential; the local edge cluster establishes an authentication communication connection between the local edge cluster and the remote edge cluster through the authentication management module and the Kube-API service module of the remote edge cluster. Conversely, the remote edge cluster establishes an authentication communication connection between the remote edge cluster and the local edge cluster through the authentication management module and the Kube-API service module of the local edge cluster; and performs mutual peer identity authentication based on the identity credentials of both parties.
[0009] After the peer identity authentication is successful, the local edge cluster and the remote edge cluster create peer cluster resources and VPN tunnel endpoint information between the local edge cluster and the remote edge cluster through their respective network management control modules, establish a secure tunnel based on the peer cluster resources and VPN tunnel endpoint information, and use the secure tunnel to synchronize and exchange the peer cluster resources, realizing an automatically assembled network among multiple edge clusters.
[0010] Furthermore, the network management control module includes a network management module, a gateway controller, and a routing controller.
[0011] The network management module is used to create peer cluster resources and VPN tunnel endpoint information between the local edge cluster and the remote edge cluster, and use the secure tunnel to synchronize the peer cluster resources.
[0012] The gateway controller is used to obtain the peer cluster resources and VPN tunnel endpoint information, and use the peer cluster resources to establish the secure tunnel and manage, update, and maintain the secure tunnel.
[0013] The routing controller is used to obtain the peer cluster resources, and use the peer cluster resources to configure routing policies and routing rules, and intercept and forward cross-cluster network traffic according to the routing policies and routing rules.
[0014] Furthermore, the peer cluster resources include: API services, authentication addresses, authentication identifiers, network configurations, resource provisions, and statuses of the local edge cluster and the remote edge cluster.
[0015] The VPN tunnel endpoint information includes: VPN tunnel addresses, VPN authentication certificates, Pod CIDRs, external Pod CIDRs, NAT CIDRs, and external NAT CIDRs of the local edge cluster and the remote edge cluster.
[0016] Furthermore, the network management module includes a peer cluster management unit and a tunnel endpoint management unit.
[0017] The peer cluster management unit within each edge cluster creates corresponding peer cluster type resources.
[0018] The peer cluster management unit of the local edge cluster creates a local network configuration, which represents a remote peer cluster, and synchronously obtains the corresponding remote network configuration;
[0019] After obtaining the local network configuration and the remote network configuration simultaneously, the tunnel endpoint management unit creates corresponding VPN tunnel endpoint information and synchronizes the VPN tunnel endpoint information to the gateway controller and the routing controller in real time; the gateway controller and the routing controller dynamically adjust the tunnel endpoints according to the VPN tunnel endpoint information.
[0020] Further, the secure tunnel establishes a connection through the gateway controller, and prevents IP address conflicts by filling the routing table and configuring the corresponding network address translation rules.
[0021] Further, when configuring the routing policy and routing rules, creating the VPN tunnel endpoint information, and configuring the network address translation rules, the gateway controller creates an independent network namespace, places all information in the network namespace, and uses the network namespace to realize the synchronization and exchange of the peer cluster resources.
[0022] Further, the network namespace includes:
[0023] Two independent network namespaces of the host network namespace and the gateway network namespace; among them, the gateway network namespace is newly created;
[0024] Create a pair of network cards; one end marked as the host network card interface is set in the host network namespace, and one end marked as the gateway network card interface is set in the gateway network namespace;
[0025] Initialize the secure tunnel of the cross-cluster gateway to realize the connection, management, update and maintenance of the secure tunnel.
[0026] Further, the routing controller includes a virtual network Operator sub-component and a routing Operator sub-component;
[0027] The virtual network Operator sub-component is used to automatically update the general network virtualization encapsulation protocol device forwarding data table entries and monitor the routing controller in the network namespace where the peer cluster components are deployed;
[0028] The routing Operator sub-component is used to control and adjust the VPN tunnel endpoint information, and configure the routing policy and routing rules for each tunnel endpoint object instance according to the running nodes.
[0029] Further, when the routing controller and the gateway controller run on the same node, the routing policy and routing rules are configured to send all traffic through the geneve network card interface, the gateway network card interface of the gateway controller, and the host network card interface in sequence.
[0030] Further, when the routing controller runs on the first node and the gateway controller runs on the second node, the routing policy and routing rules are configured to send all traffic through the geneve network card interface of the first node, the geneve network card interface of the second node, and the tunnel network card interface of the gateway controller in sequence.
[0031] Generally speaking, the present invention provides a method for dynamically and automatically assembling a network of a federated peer cluster in an edge environment. Through the technical solution conceived by the present invention, the following beneficial effects can be achieved compared with the prior art:
[0032] (1) The present invention uses the network management and control module to create peer cluster resources and VPN tunnel endpoint information, establishes a secure tunnel according to the peer cluster resources and VPN tunnel endpoint information, and uses the secure tunnel to synchronize and exchange peer cluster resources. Multiple edge clusters automatically assemble a peer network by exchanging peer cluster resources and establishing secure tunnels, and then form a federated peer cluster; in the federated peer cluster of the present invention, the identities of each edge cluster are equal, there is no master-slave distinction in the cluster roles, and the networks are interconnected with each other. Even when one of the clusters has an abnormality, the resource interconnection and resource scheduling between the clusters can be ensured, and the federated peer cluster can operate normally.
[0033] (2) When the edge cluster joins the federated peer cluster, the present invention will automatically perform identity authentication and establish a dynamic secure tunnel, avoiding the joining of untrusted edge clusters; and in the edge computing scenario, when the edge cluster joins or loses contact, there is no need to manually reconfigure the network or reassemble it, and network automatic authentication, network automatic assembly, and cross-cluster services can also be performed, realizing the dynamic assembly of the edge federated peer cluster; the configuration is simple and flexible, not easy to make mistakes, and can meet the timeliness and mobility requirements of edge device collaboration in the field environment.
[0034] (3) The present invention realizes the management of cross-cluster network traffic and high-performance communication by setting up a routing controller and a gateway controller to intercept and forward network traffic within the cluster.
[0035] (4) The present invention realizes the isolation and security control from the existing network of the edge cluster by creating network namespaces, customizing network namespaces, network interfaces, routing policies, and routing rules, supports multi-cluster joint task scheduling and resource scheduling, and also supports multi-cluster joint elastic, distributed, and collaborative computing. Description of the Drawings
[0036] To more clearly illustrate the technical solutions in the present invention or the prior art, the following will briefly introduce the drawings required for the description of the embodiments or the prior art. Obviously, the drawings in the following description are some embodiments of the present invention. For those of ordinary skill in the art, without creative efforts, other drawings can also be obtained based on these drawings.
[0037] Figure 1 It is a schematic flowchart of a method for dynamically and automatically assembling a federated peer cluster network in an edge environment provided by the present invention;
[0038] Figure 2 It is a schematic overall architecture diagram of a method for dynamically and automatically assembling a federated peer cluster network in an edge environment provided by the present invention;
[0039] Figure 3 It is a schematic control logic diagram between various user-defined resources and the network management and control module of a method for dynamically and automatically assembling a federated peer cluster network in an edge environment provided by the present invention;
[0040] Figure 4 It is a schematic diagram of the network management and control module of a method for dynamically and automatically assembling a federated peer cluster network in an edge environment provided by the present invention;
[0041] Figure 5 It is a schematic architecture diagram of the gateway network namespace and security tunnel of different clusters of the gateway controller of a method for dynamically and automatically assembling a federated peer cluster network in an edge environment provided by the present invention;
[0042] Figure 6 It is a schematic architecture diagram of the routing controller and the gateway controller on the same node of a method for dynamically and automatically assembling a federated peer cluster network in an edge environment provided by the present invention;
[0043] Figure 7 It is a schematic architecture diagram of the routing controller and the gateway controller on different nodes of a method for dynamically and automatically assembling a federated peer cluster network in an edge environment provided by the present invention. Detailed implementation manners
[0044] To make the objectives, technical solutions, and advantages of the present invention clearer, the following will clearly and completely describe the technical solutions in the present invention in conjunction with the drawings and embodiments in the present invention. Obviously, the described embodiments are some, but not all, of the embodiments of the present invention. Based on the embodiments in the present invention, all other embodiments obtained by those of ordinary skill in the art without creative efforts fall within the protection scope of the present invention.
[0045] It should be noted that in the description of the embodiments of the present invention, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a method, step or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such method, step or device. Without further limitation, an element defined by the statement "including one..." does not exclude the existence of another identical element in the method, step or device including the said element.
[0046] The term explanations of the English and English abbreviations involved in the present invention are as follows in sequence:
[0047] Kube-API service: Kubernetes API Server, which is an application that provides Kubernetes function services and is responsible for cluster status storage;
[0048] Kubernetes: A unified resource orchestration platform for containers;
[0049] API: Application Programming Interface;
[0050] VPN: Virtual Private Network;
[0051] Pod: A workload resource object provided by the container cluster, the smallest unit of container orchestration and management;
[0052] CIDR: Classless Inter-Domain Routing, which aggregates and manages network IP addresses;
[0053] NAT: Network Address Translation;
[0054] Operator: An operation controller that manages and maintains the application life cycle in the container cluster;
[0055] geneve: General Network Virtualization Encapsulation Protocol;
[0056] Etcd: A high-performance distributed key-value (k-v) database;
[0057] Service: A service object provided by the container cluster, which realizes the four-layer network access of the container service;
[0058] UDP: User Datagram Protocol;
[0059] CRD: Custom Resource Definition, which extends the custom resource ability of users based on Kubernetes;
[0060] WebHook: An HTTP-based callback function, which can implement event-driven lightweight communication between APIs;
[0061] CNI: Container Orchestration Platform Network Interface;
[0062] IPAM: Management of network IP addresses;
[0063] Overlay Network: Virtualized network technology built on top of the underlying physical network;
[0064] Underlay Network: Underlying physical network;
[0065] CR: Custom Resource Object Instance, extending the resources required by users based on Kubernetes;
[0066] MAC: LAN address.
[0067] The present invention provides a method for dynamically and automatically assembling a network for an edge federated peer cluster. By establishing a secure tunnel to dynamically and automatically network multiple edge clusters, establishing and communicating between cross-cluster networks, it realizes the automatic establishment of peer networks in the federated peer cluster, high-speed communication between networkings, and network traffic management. As Figure 1 shown, the method specifically includes:
[0068] S101: Each edge cluster creates a unique identity credential; the local edge cluster establishes an authentication communication connection between the local edge cluster and the remote edge cluster through the authentication management module and the Kube-API service module of the remote edge cluster. Conversely, the remote edge cluster establishes an authentication communication connection between the remote edge cluster and the local edge cluster through the authentication management module and the Kube-API service module of the local edge cluster; and performs mutual peer identity authentication based on the identity credentials of both parties.
[0069] It should be noted that the identity credential is an identification credential used by the edge cluster to identify its own identity and is unique.
[0070] The authentication management module implements the access of remote edge cluster identity authentication and the exchange of peer cluster resources during the process where member clusters are peer networks with each other. Among them, a peer network refers to network roles with the same identity.
[0071] The Kube-API service module is a two-way authentication API service provided by Kubernetes native container orchestration, usually connected to Etcd, and Etcd is a cluster resource storage component provided by Kubernetes native container orchestration.
[0072] As Figure 2 shown, each edge cluster includes a Kube-API service module set on the management node, and an authentication management module and a network management control module set on the computing node.
[0073] Specifically, on the one hand, the local edge cluster establishes an authenticated communication connection with the Kube-API service module of the remote edge cluster through the authentication management service module and conducts identity authentication, and exchanges the cluster identity information between each other after establishing the authentication; on the other hand, the remote edge cluster also establishes an authenticated communication connection with the Kube-API service module of the local edge cluster through the authentication management service, conducts identity authentication, and exchanges the cluster identity information.
[0074] S102: After the peer identity authentication is successful, the local edge cluster and the remote edge cluster create the peer cluster resources and VPN tunnel endpoint information between the local edge cluster and the remote edge cluster through their respective network management and control modules, establish a secure tunnel based on the peer cluster resources and VPN tunnel endpoint information, and use the secure tunnel to synchronize and exchange the peer cluster resources, so as to realize the automatic assembled network between multiple edge clusters.
[0075] It should be noted that the peer cluster resources include the following of the local edge cluster and the remote edge cluster: API service, authentication address, authentication identifier, network configuration, resource supply and status; the VPN tunnel endpoint information includes the following of the local edge cluster and the remote edge cluster: VPN tunnel address, VPN authentication certificate, Pod CIDR, external Pod CIDR, NAT CIDR, and external NAT CIDR. The network management and control module in each edge cluster is responsible for the synchronization and exchange of the peer cluster resources.
[0076] As an embodiment, the network management and control module includes a network management module, a gateway controller, and a routing controller.
[0077] The network management module is used to create the peer cluster resources and VPN tunnel endpoint information between the local edge cluster and the remote edge cluster, and use the secure tunnel to realize the synchronization of the peer cluster resources.
[0078] Specifically, create the API service, authentication address, authentication identifier, network configuration, resource supply and status of the peer cluster associated with the remote edge cluster, and the VPN tunnel endpoint information required to establish a secure tunnel, and implement the NAT IP address allocation of Pods and Services between member clusters.
[0079] The gateway controller is used to obtain the peer cluster resources and VPN tunnel endpoint information, establish a secure tunnel using the peer cluster resources and VPN tunnel endpoints, and manage, update, and maintain the secure tunnel.
[0080] Specifically, a VPN tunnel is established through information such as the VPN tunnel address and VPN authentication certificate, the lifecycle of the secure tunnel leading to the remote edge cluster is managed and updated, and the gateway Pods in each member cluster are managed and updated. The traffic between different member clusters is forwarded through the secure tunnel UDP protocol, thereby managing and maintaining the normal network communication between the local edge cluster and the remote edge cluster.
[0081] The routing controller is used to obtain the VPN tunnel endpoint information and configure the routing policy and routing rules using the VPN tunnel endpoint information, and intercept and forward the network traffic within the cluster according to the routing policy and routing rules.
[0082] Specifically, corresponding routing policies and routing rules are configured for the gateway cross-cluster traffic, so that the cross-cluster traffic can be intercepted and routed on each node through the secure tunnel; that is, the routing controller obtains the VPN tunnel address, Pod CIDR, and NAT CIDR provided by the VPN tunnel endpoint information to configure the routing policy and routing rules, and then intercepts and forwards the network traffic within the cluster and forwards it to the tunnel provided by the gateway controller.
[0083] In other words, Kubernetes extends the default cloud-native resources through the Operator method of CRD resources + WebHook interception + Controller. The federated peer clusters are based on the user-defined resource cluster peer network, and through the dynamic assembly network of multiple edge clusters, the federated peer clusters discover the final state described by the user-defined resources in the custom network management module, gateway controller, routing controller, and peer clusters. That is, the CRD resource object instances are distributed to the member clusters of the peer network to be established, so that each member cluster in the peer network can use WebHook interception to deploy the CRD resource object instances, and the controller continuously corrects the state of the CRD resource object instances by defining the control reconciliation logic in advance, so as to achieve that the federated peer clusters defined in the CRD resources can automatically control the running state of the assembly network.
[0084] As an embodiment, as Figure 3 shown, the method for establishing a network management control module includes: establishing a plurality of user-defined resources and controllers. Among them, during the process of establishing a peer network by the federated peer clusters, both the local edge cluster and the remote edge cluster need to access the three service endpoints of each other.
[0085] Specifically, the service endpoints include: Kube-API service, authentication management service, and tunnel endpoint service. Among them, the Kube-API service is for both sides of the peer clusters to access the Kube-API service modules of each other, and is used to obtain the PodCIDR of the peer cluster and the running information of Pods across clusters in different replicas; the authentication management service: is used to perform authentication management on both clusters, and needs to access the identity authentication of both sides for security authentication; the tunnel endpoint service: is used to establish a secure tunnel and perform traffic interception and routing forwarding on the network traffic of both sides of the peer clusters based on the secure tunnel.
[0086] It should be noted that the identity authentication of both sides needs to exchange peer cluster resources and VPN tunnel endpoint information, including the exchange of network authentication parameters; for example, the network authentication parameters can include user-defined resources such as API services, authentication addresses, authentication identifiers, VPN tunnel addresses, and VPN authentication certificates. Among them, according to the nature of the resource information, each user-defined resource can include a resource specification and a resource status.
[0087] As an embodiment, the network configuration method of user-defined resources includes: each network configuration specifies the recipient in the resource specification part, and the resource status part is used to send a signal to the cluster that creates the resource to determine whether the network has been remapped by the remote edge cluster; only when the network address used by the local edge cluster and the tunnel configuration parameters are filled in the resource specification part, can a network configuration object instance be created. On the contrary, the resource status part of the network configuration is updated by the remote edge cluster that receives it and creates resources for it.
[0088] It should be noted that each edge cluster will create a network configuration pointing to the remote edge cluster, which contains the required network authentication parameters, and synchronize it to the remote edge cluster. After receiving it, the remote edge cluster will update its resource status part and synchronize the change of the resource status part to the original local edge cluster.
[0089] The network management and control module includes a network management module, a gateway controller, and a routing controller.
[0090] As an embodiment, the network management module is one of the core components for the federated peer cluster networking. As Figure 4 shown, it includes a peer cluster management unit and a tunnel endpoint management unit.
[0091] The peer cluster management unit in each edge cluster creates corresponding peer cluster type resources; the peer cluster management unit of the local edge cluster creates a local network configuration, which represents a remote peer cluster, and synchronously obtains the corresponding remote network configuration.
[0092] It should be noted that one local network configuration corresponds to one edge cluster. The network management module is used to implement network communication between peer clusters, create network configurations, and send the local network configuration to the remote edge cluster. At the same time, the network management module is also used to receive the remote network configuration of the remote edge cluster and configure the mapping of the remote network address used by the local edge cluster in the network configuration of the remote edge cluster. Among them, each network configuration will be synchronously replicated to the remote edge cluster it points to. Conversely, each remote edge cluster will create its own network configuration and synchronously replicate it to the original local edge cluster.
[0093] After obtaining the local network configuration and the remote network configuration simultaneously, the tunnel endpoint management unit creates the corresponding VPN tunnel endpoint information and synchronizes the VPN tunnel endpoint information to the gateway controller and the routing controller in real time; the gateway controller and the routing controller dynamically adjust the tunnel endpoints according to the VPN tunnel endpoint information.
[0094] That is to say, when the network management module collects the network configurations of the remote edge cluster and the local edge cluster simultaneously, the tunnel endpoint management unit will create the corresponding VPN tunnel endpoint information to simulate the network interconnection between the two edge clusters. Then, the gateway controller and the routing controller dynamically adjust the tunnel endpoints, laying a foundation for the establishment of the gateway tunnel, the configuration of routing policies and routing rules, traffic interception, and routing forwarding.
[0095] It should be noted that during peer-to-peer network management, the gateway controller is responsible for negotiating connection parameters with each remote edge cluster during the peer-to-peer interconnection process. Each member cluster has a network CNI address management IPAM plugin installed by default to be responsible for local cluster IP address management and handle possible network conflicts by configuring network address translation rules.
[0096] In addition, during the resource synchronization process from the remote edge cluster to the local edge cluster, the gateway controller is also used for Pod IP conversion; during the process of propagating local edge cluster resources to the remote edge cluster, it is used for service endpoint sharding mapping to realize the association between Service and Pod IP.
[0097] Specifically, the interconnection between peer clusters is achieved through the secure tunnel established by using the VPN. During the peer-to-peer establishment process of the secure tunnel, a dynamic connection is established according to the parameters negotiated by both parties. That is to say, the secure tunnel changes dynamically according to the changes in peer cluster resources and VPN tunnel endpoint information.
[0098] As an embodiment, the secure tunnel establishes a connection through the gateway controller, fills the routing table, and configures the corresponding network address translation rules to prevent IP address conflicts. Among them, the network address translation rules can be configured using iptables.
[0099] Under the Overlay virtual network of the cross-federation peer clusters, the nodes of the local edge cluster forward all the traffic of the Pods pointing to the remote edge cluster to the gateway controller, and enter the secure tunnel through the gateway controller; similarly, the remote edge cluster enters the virtual overlay network according to the traffic flowing out of the secure tunnel and reaches the node hosting the target Pod. The cross-node communication within the cluster is still provided by the default CNI of the cluster, and the Underlay network is also supported within the cluster.
[0100] As an example, as Figure 5 shown, the gateway controller includes a tunnel Operator sub-component. That is, a gateway controller including a tunnel Operator sub-component is created in the local edge cluster and the remote edge cluster respectively.
[0101] When configuring the routing policy and routing rules, creating the VPN tunnel endpoint information, and configuring the network address translation rules, the gateway controller creates an independent network namespace, places all the information in the network namespace, uses the network namespace to realize the synchronization and exchange of the peer cluster resources, and manages and maintains the secure tunnel, thus avoiding conflicts.
[0102] The gateway controller not only establishes a secure tunnel with other peer clusters, but also configures network address translation rules for the Pods of the remote edge cluster and the CIDR for preventing conflicts. The Pods in the gateway controller are deployed using Deployment, and its Pods run in the host network mode.
[0103] As an example, the network namespace includes:
[0104] Two independent network namespaces of the host network namespace and the gateway network namespace; among them, the gateway network namespace is newly created;
[0105] Create a pair of network cards; among them, one end marked as the host network card interface is set in the host network namespace, and one end marked as the gateway network card interface is set in the gateway network namespace;
[0106] Initialize the secure tunnel of the cross-cluster gateway to realize the connection, management, update and maintenance of the secure tunnel.
[0107] Furthermore, the gateway network namespace includes a gateway network card interface and a tunnel network card interface; the host network namespace includes a host network card interface and a physical network card.
[0108] The cross-cluster traffic generated by the local edge cluster workload is routed to the gateway network namespace before being processed. In the gateway network namespace, the Tunnel Operator sub-component controls and regulates the VPN tunnel endpoint information, creates a secure tunnel to the cluster described by the CR for each VPN tunnel endpoint information, and adds a static route for the remote edge cluster.
[0109] It should be noted that if there is a conflict between the local network address used in the local edge cluster and the remote network address in the remote edge cluster, the gateway controller will configure network address translation rules for the cross-cluster traffic. That is, in the host network namespace, the Tunnel Operator sub-component will add a routing policy and routing rules, indicating that the kernel must intercept and forward the traffic of all traffic from the remote edge cluster according to the content of the custom routing table.
[0110] It should be noted that the Tunnel Operator sub-component can adopt a pluggable architecture design, mainly based on the cluster interconnection security tunnel information carried by the VPN tunnel endpoint information, to provide different VPN implementations for cluster interconnection for different VPN technologies, rather than being limited to a certain VPN technology for implementation.
[0111] As an embodiment, the routing controller includes a Virtual Network Operator sub-component and a Routing Operator sub-component.
[0112] The routing controller runs on each node of the cluster, used to intercept the traffic within the cluster, and perform routing forwarding based on the routing policy and routing rules. The Pods within the routing controller can be deployed using Daemon Set, and its Pods can run in host network mode.
[0113] Furthermore, the host network namespace includes a host network card interface, a physical network card, and a geneve network card interface.
[0114] As an embodiment, when the routing controller runs on each node of the cluster, it includes:
[0115] When the routing controller starts, create a geneve network card interface on the host based on the geneve network protocol and add it to the host network namespace;
[0116] When the routing controller and the gateway controller run on the same node, configure the routing policy and routing rules to send the cross-cluster traffic to the gateway network card interface of the gateway controller;
[0117] When the routing controller and the gateway controller are running on different nodes, configure the routing policy and routing rules to send cross-cluster traffic to the tunnel NIC interface of the gateway controller. It should be noted that the management of the network by the routing controller is independent of the CNI plug-in that comes with the cluster and will not interfere with the existing network configuration or existing network interfaces. The routing controller uses a custom routing table for the routing required for cross-cluster traffic and forwards traffic through the geneve NIC interface it creates.
[0118] The virtual network operator subcomponent is used to automatically update the forwarding data table entries of the generic network virtualization encapsulation protocol device and monitor the routing controller in the network namespace where the peer cluster components are deployed. Among them, when the Pod is running on the current node, it is labeled with the MAC label address of the geneve device; when the Pod is running on a different node, the geneve forwarding data table of the geneve device is filled with the information of the remote tunnel endpoint.
[0119] The Routing Operator subcomponent is used to control the mediation and VPN tunnel endpoint information, and configure routing policies and routing rules for each tunnel endpoint object instance based on the running node.
[0120] like Figure 6 As shown, when the routing controller and the gateway controller run on the same node, the routing policy and routing rules are configured to send all traffic through the geneve network card interface, the gateway network card interface of the gateway controller, and the host network card interface in sequence.
[0121] like Figure 7 As shown, when the routing controller runs on the first node and the gateway controller runs on the second node, the routing policy and routing rules are configured to send all traffic in sequence through the geneve network card interface of the first node, the geneve network card interface of the second node and the tunnel network card interface of the gateway controller.
[0122] It should be noted that during the network routing forwarding process, all routes are inserted into the custom routing table. If the running gateway controller fails, all routes will be dynamically reconfigured to send traffic to the correct node where the new running workload instance is located.
[0123] In summary, the present invention provides a method for dynamically and automatically assembling a network of edge federated peer clusters. The edge federated peer clusters mainly include an authentication management module, a network management module, a gateway controller, and a routing controller, which cooperate together to be responsible for connecting and automatically assembling the networks of different edge clusters. The federated peer cluster network attempts to reuse existing networks, customize network namespaces, customize routing tables, and policy routing rules to isolate its network configuration and avoid changing the existing network configuration. Moreover, when establishing a connection and networking for peer clusters, no information needs to be input by the user, and the interconnection with different edge clusters can be automatically configured. The network interconnection between multiple edge clusters is completed in a dynamic and secure manner based on the existing network configuration of the clusters, without any change to the existing cluster network, and the flat network of multiple edge clusters can be automatically connected.
[0124] It should be noted that for the foregoing embodiments, for the sake of simple description, they are all expressed as a series of action combinations. However, those skilled in the art should know that this application is not limited by the described action sequence, because according to this application, certain steps can be performed in other sequences or simultaneously. Secondly, those skilled in the art should also know that the embodiments described in the specification are all preferred embodiments, and the actions and modules involved are not necessarily essential to this application.
[0125] In the above embodiments, the descriptions of the respective embodiments have their own emphases. For the parts not detailed in a certain embodiment, reference can be made to the relevant descriptions of other embodiments.
[0126] In the several embodiments provided by this application, it should be understood that the disclosed method or system can be implemented in other ways. For example, the above-described embodiments are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed.
[0127] The units described as separate components may or may not be physically separated. The components shown as units may or may not be physical units, that is, they can be located in one place, or they can be distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0128] In addition, in each embodiment of this application, the functional units can be integrated into one processing unit, or each unit can exist physically alone, or two or more units can be integrated into one unit. The above-integrated units can be implemented in the form of hardware or in the form of software functional units.
[0129] When the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable memory. Based on this understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a memory and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of this application.
[0130] Those of ordinary skill in the art can understand that all or part of the circuits in the above embodiments can be completed by instructing relevant hardware through a program. This program can be stored in a computer-readable memory, and the memory can include: a flash drive, a read-only memory (ROM), a random access memory (RAM), a magnetic disk, or an optical disc, etc.
[0131] The above are only exemplary embodiments of the present disclosure, and the scope of the present disclosure cannot be limited thereby. That is, any equivalent changes and modifications made in accordance with the teachings of the present disclosure still fall within the scope covered by the present disclosure. After considering the specification and practicing the present disclosure herein, those skilled in the art will readily think of other embodiments of the present disclosure. This application aims to cover any variations, uses, or adaptive changes of the present disclosure, and these variations, uses, or adaptive changes follow the general principles of the present disclosure and include common general knowledge or conventional technical means in the technical field not described in the present disclosure. The specification and embodiments are only regarded as exemplary, and the scope and spirit of the present disclosure are defined by the claims.
[0132] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0133] Those skilled in the art can easily understand that the above are only preferred embodiments of the present invention and are not used to limit the present invention. Any modifications, equivalent replacements, and improvements made within the spirit and principle of the present invention should be included in the protection scope of the present invention.
Claims
1. A method for dynamically assembling a network of federated peer clusters in an edge environment, characterized in that: The method comprises: Each edge cluster creates a unique identity credential; the local edge cluster establishes an authentication communication connection between the local edge cluster and the remote edge cluster through the authentication management module and the Kube-API service module of the remote edge cluster. Conversely, the remote edge cluster establishes an authentication communication connection between the remote edge cluster and the local edge cluster through the authentication management module and the Kube-API service module of the local edge cluster; and mutual identity authentication is performed based on the identity credentials of both parties; After the peer identity authentication is successful, the local edge cluster and the remote edge cluster create peer cluster resources and VPN tunnel endpoint information between the local edge cluster and the remote edge cluster through their respective network management control modules, and the network management control module includes a network management module, a gateway controller and a routing controller; a secure tunnel is established according to the peer cluster resources and VPN tunnel end information, and the secure tunnel is used to synchronize and exchange the peer cluster resources to realize automatic assembly network between multiple edge clusters; The network management module is used to receive the remote network configuration of the remote edge cluster, and configure the mapping of the remote network address used by the local edge cluster in the network configuration of the remote edge cluster; wherein each network configuration is synchronously copied to the remote edge cluster it points to, and vice versa, each remote edge cluster creates its own network configuration and synchronously copies it to the original local edge cluster; When the network management module obtains the local network configuration and the remote network configuration at the same time, the tunnel endpoint management unit creates the corresponding VPN tunnel endpoint information and synchronizes the VPN tunnel endpoint information to the gateway controller and the routing controller in real time; the gateway controller and the routing controller dynamically adjust the tunnel endpoint according to the VPN tunnel endpoint information.
2. According to claim 1, a method for dynamically assembling a network of federated peer clusters in an edge environment is characterized in that: The network management module is used to create peer cluster resources and VPN tunnel endpoint information between the local edge cluster and the remote edge cluster, and use the secure tunnel to synchronize peer cluster resources; The gateway controller is used to obtain the peer cluster resources and VPN tunnel endpoint information, and use the peer cluster resources and VPN tunnel endpoint information to establish the secure tunnel, and manage, update and maintain the secure tunnel; The routing controller is used to obtain the VPN tunnel endpoint information, and use the VPN tunnel endpoint information to configure routing policies and routing rules, and perform traffic interception and routing forwarding on cross-cluster network traffic according to the routing policies and routing rules.
3. According to claim 2, a method for dynamically assembling a network of federated peer clusters in an edge environment, characterized in that: The peer cluster resources include: API services, authentication addresses, authentication identifiers, network configuration, resource provisioning and status of local edge clusters and remote edge clusters; The VPN tunnel endpoint information includes: VPN tunnel address, VPN authentication certificate, Pod CIDR, Pod external CIDR, NAT CIDR and NAT external CIDR of the local edge cluster and the remote edge cluster.
4. According to claim 3, a method for dynamically assembling a network of federated peer clusters in an edge environment is characterized in that: The network management module includes a peer cluster management unit and a tunnel endpoint management unit; The peer cluster management unit in each edge cluster creates corresponding peer cluster type resources; The peer cluster management unit of the local edge cluster creates a local network configuration that represents a remote peer cluster and synchronously obtains the corresponding remote network configuration; After simultaneously acquiring the local network configuration and the remote network configuration, the tunnel endpoint management unit creates corresponding VPN tunnel endpoint information, and synchronizes the VPN tunnel endpoint information to the gateway controller and the routing controller in real time; The gateway controller and the routing controller dynamically adjust the tunnel endpoint according to the VPN tunnel endpoint information.
5. The method for dynamically assembling a network of a federated peer cluster in an edge environment according to claim 2, characterized in that: The secure tunnel establishes a connection through the gateway controller, and prevents IP address conflicts by filling in a routing table and configuring corresponding network address translation rules.
6. The method for dynamically assembling a network of a federated peer cluster in an edge environment according to claim 2, characterized in that: When configuring routing policies and routing rules, creating VPN tunnel endpoint information, and configuring network address translation rules, the gateway controller creates an independent network namespace, places all information in the network namespace, and uses the network namespace to synchronize and exchange peer cluster resources.
7. The method for dynamically assembling a network of a federated peer cluster in an edge environment according to claim 6, characterized in that: The network namespace includes: Two independent host network namespaces and gateway network namespaces; the gateway network namespace is newly created; Create a pair of network cards; one end marked as the host network card interface is set in the host network namespace, and the other end marked as the gateway network card interface is set in the gateway network namespace; Initialize a secure tunnel across cluster gateways to connect, manage, update, and maintain the secure tunnel.
8. The method for dynamically assembling a network of a federated peer cluster in an edge environment according to claim 2, characterized in that: The routing controller includes a virtual network operator subcomponent and a routing operator subcomponent; The virtual network operator subcomponent is used to automatically update the forwarding data table entries of the general network virtualization encapsulation protocol device and monitor the routing controller in the network namespace where the peer cluster component is deployed; The routing Operator subcomponent is used to control and adjust VPN tunnel endpoint information, and configure routing strategies and routing rules for each tunnel endpoint object instance according to the running node.
9. The method for dynamically assembling a network of a federated peer cluster in an edge environment according to claim 2, characterized in that: When the routing controller and the gateway controller are running on the same node, the routing strategy and routing rules are configured to send all traffic through the geneve network card interface, the gateway network card interface of the gateway controller and the host network card interface in sequence.
10. The method for dynamically assembling a network of a federated peer cluster in an edge environment according to claim 2, characterized in that: When the routing controller runs on the first node and the gateway controller runs on the second node, the routing strategy and routing rules are configured to send all traffic in sequence through the geneve network card interface of the first node, the geneve network card interface of the second node and the tunnel network card interface of the gateway controller.
Citation Information
Patent Citations
Security authentication method for realizing multi-cloud management and control across public network
CN110855700A
Creation method and device of trunking communication network, electronic equipment and storage medium
CN116471221A
Distributed data storage system with tunneling of management requests among scale-out clusters
US20250039087A1