Multi-tenant implementation method for disk array system, electronic device and storage medium
By adding tenant identification parameters and modifying permission determination logic in the interface layer of the disk array system, the problem that existing systems cannot quickly realize multi-tenant capabilities is solved, and business resources isolation and management of different tenants are realized, reducing the expansion cost.
Patent Information
- Application Number
- CN202510332211.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-20
- Publication Date
- 2025-06-17
- Estimated Expiration
- 2045-03-20
AI Technical Summary
It is difficult for existing disk array systems to consider multi-tenant capabilities in the early stage of design, which leads to high cost in the later expansion of multi-tenant functions and the inability to quickly realize multi-tenant capabilities.
By adding tenant identification parameters in the interface layer of the disk array system, modifying the permission determination logic of the configuration management interface, adding the tenant administrator group and reconstructing the user permission management module to achieve business resources isolation and management of different tenants.
It realizes rapid upgrades to support multi-tenant capabilities on existing disk array systems, ensuring mutual disagreement and business resource isolation between different tenants, reducing the cost of expansion.
Smart Images

Figure CN119883136B_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data storage, and particularly to a multi-tenant implementation method, an electronic device, and a storage medium for a disk array system. Background Art
[0002] With the development of technologies such as cloud computing and the Internet of Things, information technology is increasingly widely used in various fields of society, and information security is of crucial importance. In related technologies, business data is often stored on storage devices mainly based on disk array systems. In order to make full use of disk array resources, the concept of multi-tenancy has emerged. Through hardware, network, and virtualization isolation, different tenants can share the same set of disk array systems while ensuring data security and privacy.
[0003] Although multi-tenancy technology has advantages in realizing resource sharing and reducing costs, it is necessary to consider the ability to support multi-tenancy at the initial stage of disk array system design. Otherwise, the cost of later expansion is high. For users who did not originally consider multi-tenancy requirements, how to quickly implement multi-tenancy capabilities on existing disk array systems has become a challenge. Summary of the Invention
[0004] This application provides a multi-tenant implementation method, an electronic device, and a storage medium for a disk array system to at least solve the problem in related technologies that multi-tenancy capabilities cannot be quickly implemented on existing disk array systems.
[0005] This application provides a multi-tenant implementation method for a disk array system, including:
[0006] If the current disk array system needs to be upgraded to a version that supports multi-tenancy, a tenant identification parameter is added to the resource creation class interface in the interface layer of the current disk array system. The tenant identification parameter is used to indicate the tenant to which the created business resource belongs when creating a business resource;
[0007] Modify the permission determination logic of the configuration management class interface in the interface layer to perform configuration management isolation on business resources of different tenants;
[0008] Add the corresponding relationship between the tenant administrator group and the permission information of the tenant administrator group in the user group management module of the current disk array system;
[0009] Reconstruct the user permission management module of the current disk array system so that the user permission management module records the user information of the disk array system users;
[0010] Obtain a disk array system that supports multi-tenancy.
[0011] The present application also provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of any of the above multi-tenant implementation methods of the disk array system when executing the computer program.
[0012] The present application also provides a computer-readable storage medium storing a computer program, wherein the computer program implements the steps of any of the above multi-tenant implementation methods of the disk array system when executed by a processor.
[0013] The present application also provides a computer program product including a computer program, which implements the steps of any of the above multi-tenant implementation methods of the disk array system when executed by a processor.
[0014] Through the present application, by means of software upgrade, a tenant identification parameter is added to the resource creation class interface in the interface layer to indicate the tenant to which the created business resource belongs when creating a business resource, and the permission determination logic of the configuration management class interface is modified to perform configuration management isolation on the business resources of different tenants; the corresponding relationship between the tenant administrator group and the permission information of the tenant administrator group is added in the user management module; the user permission management module is reconstructed to record the user information of the disk array system users, ensuring that different tenants are unaware of each other and the business resource isolation, and obtaining a disk array system supporting multi-tenancy. Therefore, the technical problem of being unable to quickly implement the multi-tenant capability on the existing disk array system can be solved, and the technical effect of quickly implementing the multi-tenant capability on the existing disk array system is achieved. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] To more clearly illustrate the embodiments of the present application, the drawings required for the embodiments will be briefly introduced below. Obviously, the drawings in the following description are only some embodiments of the present application, and those of ordinary skill in the art can obtain other drawings based on these drawings without creative efforts.
[0016] Figure 1 It is a schematic structural diagram of a multi-tenant implementation system of a disk array system provided by an embodiment of the present application;
[0017] Figure 2 It is a schematic flowchart of a multi-tenant implementation method of a disk array system provided by an embodiment of the present application;
[0018] Figure 3 It is a schematic diagram of the API interface division of a disk array system supporting multi-tenancy provided by an embodiment of the present application;
[0019] Figure 4 It is a schematic diagram of the resource division of a disk array system supporting multi-tenancy provided by an embodiment of the present application;
[0020] Figure 5 It is a flowchart showing the implementation method of multi-tenant for another disk array system provided by the embodiments of the present application;
[0021] Figure 6 It is a flowchart of the target logic provided by the embodiments of the present application;
[0022] Figure 7 It is a schematic structural diagram of the user information table provided by the embodiments of the present application;
[0023] Figure 8 It is a schematic structural diagram of the business resource information table provided by the embodiments of the present application;
[0024] Figure 9 It is a schematic structural diagram of the user group information table provided by the embodiments of the present application;
[0025] Figure 10 It is a schematic structural diagram of the tenant information table provided by the embodiments of the present application;
[0026] Figure 11 It is a schematic structural diagram of the disk array system supporting multi-tenant provided by the embodiments of the present application;
[0027] Figure 12 It is a classification schematic diagram of the users of the disk array system supporting multi-tenant provided by the embodiments of the present application;
[0028] Figure 13 It is a schematic hardware structure diagram of an electronic device provided by the embodiments of the present application. Detailed implementation manners
[0029] Next, the technical solutions in the embodiments of the present application will be clearly and completely described in conjunction with the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only a part of the embodiments of the present application, rather than all the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.
[0030] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variant thereof are intended to cover a non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements but also includes other elements not expressly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects and are not used to describe a specific order or sequence.
[0031] To enable those skilled in the art of the present technology to better understand the solution of this application, the following further detailed description of this application will be given in conjunction with the accompanying drawings and specific embodiments.
[0032] With the development of technologies such as cloud computing, Internet of Things, and mobile computing, information technology is increasingly widely applied in various fields of society, and information security is of vital importance. In today's data centers, the data of business systems is regarded as crucial assets and is often stored on storage devices mainly based on disk array systems, which constitute the core support of the data center.
[0033] With the continuous increase in the capacity of storage devices and the continuous improvement of performance, there is a situation where disk array resources cannot be fully utilized. To achieve the full utilization of disk array resources, the concept of multi-tenancy has emerged. It not only enables more efficient use of disk array resources but also ensures data isolation between different tenants, allowing different tenants to use the same set of disk array systems as if they were using separate sets of disk array systems.
[0034] Multi-tenancy means building multiple virtual storage systems in a set of physical storage devices of a disk array, so that each tenant corresponds to a virtual storage system, providing a flexible, easy-to-manage, and low-cost shared storage solution for multiple tenants. At the same time, it ensures the security and privacy of data are not violated, enabling each tenant to enjoy the experience as if they independently own a dedicated storage system.
[0035] In related technologies, there are three ways to implement multi-tenancy capabilities on a set of disk array systems: hardware isolation, network isolation, and virtualization isolation.
[0036] Among them, the hardware isolation method: allocate hardware resources such as the central processing unit (CPU), memory, and hard disks of the disk array system to different tenants, so that each tenant logs in to the independent disk array system business software running on the allocated hardware resources and configures and manages the disk array resources using their respective disk array system business software.
[0037] The network isolation method: different tenants use different logical Internet Protocol (IP) addresses, and different tenants configure and manage their respective disk array resources by accessing different addresses. Among them, if tenants with the same logical IP address are in the same local area network, they need to be isolated through a virtual local area network (VLAN).
[0038] Virtualization isolation method: A disk array system is divided into multiple virtual storage partitions. One virtual storage partition corresponds to one tenant, and the virtual storage partitions can be isolated by virtual machines or containers for different tenants to use.
[0039] Although the above three methods can all implement the multi-tenant capability on the disk array system, it is necessary to consider supporting the multi-tenant capability at the initial stage of the disk array system design. For example, consider multi-tenancy in hardware design, consider multi-tenancy in virtualization software or operating system software, and the disk array basic software supports multi-tenancy, etc. If it is costly to expand the support for the multi-tenant capability during the subsequent system maintenance period. For users who did not consider the multi-tenant requirement when purchasing the disk array system originally, when the situations such as department splitting, device idleness, and new business occur later, and it is necessary to expand the support for the multi-tenant capability on the current disk array system, then how to quickly implement the multi-tenant capability on the existing disk array system has become a challenge.
[0040] To solve the above problems, the embodiments of the present application provide a method for implementing multi-tenancy of a disk array system. The method includes: If the current disk array system needs to be upgraded to a version that supports multi-tenancy, then add a tenant identification parameter to the resource creation class interface in the interface layer of the current disk array system. The tenant identification parameter is used to indicate the tenant to which the created business resource belongs when creating a business resource; modify the permission determination logic of the configuration management class interface in the interface layer to perform configuration management isolation on the business resources of different tenants; add the corresponding relationship between the tenant administrator group and the permission information of the tenant administrator group in the user group management module of the current disk array system; reconstruct the user permission management module of the current disk array system so that the user permission management module records the user information of the disk array system users; obtain a disk array system that supports multi-tenancy. The method provided by the above solution, on the basis of keeping the original hardware and basic software of the disk array system unchanged, re-implements the interface layer of the disk array system, reconstructs the original user permission management module and user group management module, ensures that different tenants are unaware of each other and the business resource isolation, and achieves the technical effect of quickly implementing the multi-tenant capability on the existing disk array system through software upgrade.
[0041] In order to enable those skilled in the art of this technical field to better understand the method of the present application, the present application will be further described in detail below with reference to the accompanying drawings and specific embodiments.
[0042] Combined with the specific application environment architecture or specific hardware architecture on which the execution of the method for implementing multi-tenancy of a disk array system depends, the specific application environment architecture or specific hardware architecture is described herein.
[0043] The multi-tenant implementation method, electronic device, and storage medium of the disk array system provided by the embodiments of the present application are applicable to quickly implementing multi-tenant capabilities on a disk array system that does not support multi-tenant capabilities. As Figure 1 shown, it is a schematic structural diagram of the multi-tenant implementation system of the disk array system based on the embodiments of the present application. The system mainly includes a client and a disk array system. The client is used to send an upgrade command to the disk array system, and the disk array system is used to receive the upgrade command sent by the client. In response to the upgrade command, the multi-tenant implementation method of the disk array system provided by the embodiments of the present application is executed to upgrade the disk array system and obtain a disk array system that supports multi-tenancy.
[0044] The embodiments of the present application provide a multi-tenant implementation method for a disk array system, which is applied to the CPU in the disk array system. Figure 2 It is a schematic flowchart of a multi-tenant implementation method for a disk array system provided by the embodiments of the present application. As Figure 2 shown, the process includes the following steps:
[0045] Step S201, if the current disk array system needs to be upgraded to a version that supports multi-tenancy, a tenant identification parameter is added to the resource creation class interface in the interface layer of the current disk array system. The tenant identification parameter is used to indicate the tenant to which the created business resource belongs when creating a business resource.
[0046] Among them, the current disk array system is a disk array system that does not support multi-tenancy. In the case of needing to upgrade a disk array system that does not support multi-tenancy to a disk array system that supports multi-tenancy, on the basis of keeping the original hardware and basic software of the disk array system unchanged, targeted research and development and modification are carried out on the interface layer, user permission management module, and user group management module in the current disk array system to implement the multi-tenant function. Among them, the interface layer is the application programming interface (Application Programming Interface, abbreviated as: API) layer of the disk array system, that is, the API interface layer.
[0047] Figure 3 It is a schematic diagram of the API interface division of the disk array system that supports multi-tenancy provided by the embodiments of the present application. As Figure 3 shown, to support multi-tenancy, all API interfaces in the interface layer of the current disk array system are divided into system API interfaces and tenant API interfaces. The tenant API interfaces can be divided into resource creation class API interfaces, that is, resource creation class interfaces, and configuration management class API interfaces, that is, configuration management class interfaces, according to the resource operation type.
[0048] Among them, system users can operate all API interfaces, tenant users can only operate configuration management - related API interfaces, and the multi - tenant function only exposes configuration management - related API interfaces to each tenant. The resource creation - related interfaces can only be called by users who belong to the business administrator group among system administrators. Among them, the scope of action of system users is the entire disk array system.
[0049] Figure 4 This is a schematic diagram of resource partitioning for the disk array system supporting multi - tenants provided by the embodiments of the present application. As Figure 4 shown, to support multi - tenants, all resources of the current disk array system are divided into system resources and business resources. Among them, business resources are divided among different tenants. The business resources allocated to each tenant can be tenant 1 resources,......, tenant n resources, etc. The business resources of each tenant are further divided into tenant - global resources and tenant - user resources. Among them, tenant - global resources are tenant - overall information, such as: the total space used by the entire tenant, all users under the entire tenant, etc. Each ordinary tenant user can only operate the resources to which the user has permissions within the tenant. Tenant users in the tenant administrator group can access all resources under the tenant, thus ensuring resource isolation among tenants.
[0050] It should be noted that the API interfaces in the embodiments of the present application are implemented through interface functions. In the resource creation - related interfaces, a tenant identifier (Identifier, abbreviated as: id) parameter is added. The tenant identifier parameter indicates which tenant the currently created business resource (such as: volume) belongs to, and the default value of this parameter is the default tenant.
[0051] Step S202: Modify the permission determination logic of the configuration management - related interfaces in the interface layer to perform configuration management isolation for the business resources of different tenants.
[0052] Among them, in the interface layer, in addition to modifying the resource creation - related interfaces by adding a tenant id parameter, it is also necessary to modify the permission determination logic of the configuration management - related interfaces. In the permission determination logic, a tenant consistency check logic for users and business resources is added to perform configuration management isolation for the business resources of different tenants.
[0053] Step S203: Add the corresponding relationship between the tenant administrator group and the permission information of the tenant administrator group in the user group management module of the current disk array system.
[0054] The modification made to the user group management module of the current disk array system is to add the corresponding relationship between the tenant administrator group and the permission information of the tenant administrator group, so that users in the tenant administrator group can view all information of the tenant to which they belong, including information about other users under the tenant, adding users under the tenant, etc.
[0055] Step S204, reconstruct the user permission management module of the current disk array system so that the user permission management module records the user information of the disk array system users.
[0056] Among them, the modification made to the user permission management module of the current disk array system is to record two attributes that each disk array system user must include, namely the tenant to which the user belongs and the user group to which the user belongs. That is to say, the user information includes the tenant to which the user belongs and the user group to which the user belongs. The user group attribute represents the permission capabilities of the user, and the tenant to which the user belongs represents the permission scope of the user.
[0057] Step S205, obtain a disk array system that supports multi-tenancy.
[0058] Among them, by performing the processes of the above-mentioned step S201 to the above-mentioned step S204 on the current disk array system, a disk array system that supports multi-tenancy is obtained.
[0059] The multi-tenancy implementation method of the disk array system provided by this application, through software upgrade, adds a tenant identification parameter to the resource creation class interface in the interface layer, so that each business resource is clearly associated with a specific tenant at the beginning of creation, which realizes the effective isolation of business resources of different tenants. The business resources of each tenant are independently managed without interference. By modifying the permission determination logic of the configuration management class interface, strict isolation of business resources of different tenants is realized, and only users with the corresponding tenant permissions can perform configuration management operations on the resources of that tenant. By adding the corresponding relationship between the tenant administrator group and the permission information of the tenant administrator group, reconstructing the user permission management module of the current disk array system so that the user permission management module records the user information of the disk array system users, so that different user roles have corresponding permission scopes, ensuring the non-awareness between different tenants and the isolation of business resources, and realizing the technical effect of quickly realizing multi-tenancy capabilities on the existing disk array system.
[0060] An embodiment of this application provides a multi-tenancy implementation method for a disk array system, which is applied to the CPU in the disk array system. Figure 5 It is a schematic flowchart of a multi-tenancy implementation method for a disk array system provided by an embodiment of this application. As Figure 5 shown, this process includes the following steps:
[0061] Step S501, if the current disk array system needs to be upgraded to a version that supports multi-tenancy, then add a tenant identification parameter to the resource creation class interface in the interface layer of the current disk array system. The tenant identification parameter is used to indicate the tenant to which the created business resource belongs when creating a business resource. For details, please refer to Figure 2 Step S201 of the embodiment shown, which will not be elaborated here.
[0062] Step S502: Modify the permission determination logic of the configuration management class interface in the interface layer to isolate the configuration management of business resources for different tenants.
[0063] Specifically, the above-mentioned step S502 includes:
[0064] Step S5021: Modify the permission determination logic of the configuration management class interface to the following target logic:
[0065] Receive a configuration management request from the disk array system. All external accesses to the disk array system must pass through the API interface layer. The API interface layer determines whether the corresponding API interface has permission to execute in the tenant environment by interacting with the user permission management module. The user permission management module depends on the user group management module and the tenant management module.
[0066] Obtain the target disk array system user identifier and configuration management information in the configuration management request.
[0067] Figure 6 This is a flowchart of the target logic of the embodiment of the present application. As Figure 6 shown, when receiving a configuration management request from the disk array system, that is, receiving a call to the configuration management class interface.
[0068] Obtain the API operation user, that is, obtain the user who calls the configuration management class interface. In the embodiment of the present application, obtain the target disk array system user identifier and configuration management information of the target disk array system user who calls the configuration management class interface from the configuration management request.
[0069] Obtain the target user information corresponding to the target disk array system user identifier from the user permission management module. Each disk array system user corresponds to a unique disk array system user identifier, that is, user id.
[0070] It should be noted that the user permission management module records the user information of the disk array system users through the user information table. Figure 7 This is a schematic diagram of the structure of the user information table provided by the embodiment of the present application. As Figure 7 shown, the user information table records the user information of each disk array system user such as user 1, user 2, user 3, etc. The user information includes user id, user name, affiliated user group id, affiliated tenant id, and other user attributes, etc. The tenant id of -1 represents that the disk array system user is a system user and does not belong to any tenant. The tenant id of 0 represents the default tenant. Among them, the affiliated user group id in the user information table is used to associate with the user group information table to obtain the user's permission information, and the affiliated tenant information in the user information table is used to associate with the tenant information table to limit the scope of action of the configuration management class interface of the business resources of the corresponding tenant users within the scope of the affiliated tenant.
[0071] Based on the user information table, obtain the target user information corresponding to the user identifier of the target disk array system.
[0072] Based on the target user information and the configuration management information, determine whether to allow the execution of the configuration management request.
[0073] Step S503, add the corresponding relationship between the tenant administrator group and the permission information of the tenant administrator group in the user group management module of the current disk array system. For details, please refer to Figure 2 Step S203 of the embodiment shown, which will not be elaborated here.
[0074] Step S504, reconstruct the user permission management module of the current disk array system so that the user permission management module records the user information of the disk array system users. For details, please refer to Figure 2 Step S204 of the embodiment shown, which will not be elaborated here.
[0075] Step S505, obtain a disk array system that supports multi-tenancy. For details, please refer to Figure 2 Step S205 of the embodiment shown, which will not be elaborated here.
[0076] The multi-tenancy implementation method of the disk array system provided by this application, by obtaining the target user information corresponding to the target disk array system user representation, and based on the target user information and the configuration management information, determines whether to allow the configuration management request, ensuring strict configuration management isolation of business resources between different tenants, avoiding the operation of one tenant affecting the data or configuration of other tenants, and enhancing the security of the overall system.
[0077] In some alternative embodiments, the multi-tenancy implementation method of the above disk array system further includes:
[0078] Step a1, for each created business resource, add the corresponding relationship between the business resource identifier of the business resource and the tenant identifier of the tenant to which the business resource belongs to the business resource information table in the interface layer for persistent storage in the disk array system.
[0079] Figure 8 It is a schematic structural diagram of the business resource information table provided by the embodiment of this application, as Figure 8 shown. Taking the business resource as a volume as an example, the business resource information table includes the corresponding relationship between the business resource identifier of each business resource and the tenant identifier of the tenant to which the business resource belongs, that is, the belonging tenant id, the volume name, and other volume attributes. Other volume attributes are the other original resource attributes of the volume.
[0080] By recording the correspondence between business resource identifiers and tenant identifiers, business resource isolation between different tenants is ensured. Only tenant users belonging to the tenant and system users with permissions can access the business resources.
[0081] By setting up a business resource information table, when a configuration management request is received through a configuration management class interface, permission determination is based on this business resource information table.
[0082] The multi-tenant implementation method of the disk array system provided by this application ensures that each business resource clearly belongs to a specific tenant by adding the correspondence between the business resource identifier corresponding to the business resource and the tenant identifier of the tenant to which the business resource belongs to the business resource information table in the interface layer, avoiding the problem of unclear resource ownership, helping to more accurately track the ownership of each business resource, and ensuring the accuracy of resource allocation.
[0083] In some alternative embodiments, the determination of whether to allow the execution of a configuration management request based on the target user information and configuration management information in the above target logic includes:
[0084] Step b1: Based on the target user information, determine the target user group identifier of the target user group to which the target disk array system user belongs.
[0085] As Figure 6 shown, after obtaining the API operation user, the user group is obtained according to the user, that is, based on the target user information, the target user group identifier of the target user group to which the target disk array system user belongs is determined.
[0086] Step b2: Based on the target user group identifier, obtain the permission information corresponding to the target user group identifier from the user group management module, where each user group corresponds to a unique user group identifier.
[0087] Among them, the associated permissions are obtained according to the user group, that is, based on the target user group identifier, the permission information corresponding to the target user group identifier is obtained from the user group management module.
[0088] It should be noted that the user group management module records the correspondence between user groups and the permission information of user groups through a user group information table. The user group information table stores all user group information in the disk array system, that is, the correspondence between all user groups and the permission information of user groups. User groups are used to implement role-based static permission control and custom permission control in the disk array system. Figure 9 This is the structural schematic diagram of the user group information table provided by the embodiment of this application. As Figure 9 shown, the user management module of the disk array system that supports multi-tenants includes the correspondence between user groups and the permission information of user groups, and the user group identifier is the group id.
[0089] The permission information of the user group includes static permissions and custom permissions. The static permission is UserDefined, indicating that the permission information of this user group is custom permission. The custom permissions are stored after the static permission, such as Figure 9 the custom permission (1), the custom permission (2),..., the custom permission (n) in
[0090] The static permission is Monitor (Audit Administrator Group), indicating that this user group is the audit administrator group, and this static permission is the static permission corresponding to the audit administrator group.
[0091] The static permission is SecurityAdmin (Security Administrator Group), indicating that this user group is the security administrator group, and this static permission is the static permission corresponding to the security administrator group.
[0092] The static permission is TenantAdmin (Tenant Administrator), indicating that this user group is the tenant administrator group newly added for the multi-tenant function, and this static permission is the static permission corresponding to the tenant administrator.
[0093] It should be noted that when the static permission is user-defined, the list of custom permissions after it must be set.
[0094] Step b3: Determine whether the configuration management information meets the permission information corresponding to the target user group identifier.
[0095] By comparing the actual operation of the API interface call with the specific permissions of this user, determine whether the API is allowed to execute. That is, determine whether the configuration management information meets the permission information corresponding to the target user group identifier.
[0096] Step b4: If the configuration management information meets the permission information corresponding to the target user group identifier, obtain the target business resource identifier in the configuration management information.
[0097] Among them, if the configuration management information meets the permission information corresponding to the target user group identifier. It means that the API is allowed to execute, that is, the subsequent process can continue.
[0098] When the API is allowed to execute, obtain the tenant id to which the API object belongs, that is, obtain the target business resource identifier in the configuration management information, and determine the first tenant identifier corresponding to the target business resource identifier according to the target business resource identifier.
[0099] Step b5: Based on the business resource information table in the interface layer, determine the first tenant identifier corresponding to the target business resource identifier.
[0100] Among them, the service resource information table includes the correspondence between service resource identifiers and the identifiers of the affiliated tenants. After obtaining the target service resource identifier, the first tenant identifier corresponding to the target service resource identifier can be determined according to the service resource information table, that is, the tenant ID of the target service resource corresponding to the target service resource identifier.
[0101] Step b6: Based on the target user information, determine the second tenant identifier of the second tenant to which the target disk array system user belongs.
[0102] Among them, obtaining the tenant ID to which the user belongs, that is, obtaining the tenant ID of the user who calls the API interface, that is, based on the target user information corresponding to the target disk array system user identifier, determine the second tenant identifier of the second tenant to which the target disk array system user belongs.
[0103] Step b7: Determine whether the first tenant identifier and the second tenant identifier are the same.
[0104] Among them, determining whether the first tenant identifier and the second tenant identifier are the same, that is, determining whether the tenant IDs of the object (such as a certain volume) and the subject (the user who calls the API interface) are the same, that is, determining whether the object and the user tenant are the same.
[0105] Step b8: If the first tenant identifier and the second tenant identifier are the same, it is determined that the configuration management request is allowed to be executed.
[0106] Among them, if the first tenant identifier and the second tenant identifier are the same, it is determined that the configuration management request is allowed to be executed, then the disk array system executes the configuration management request based on the configuration management information. That is, the API interface call is successful and the process ends.
[0107] The multi-tenant implementation method of the disk array system provided by this application realizes fine-grained permission control for the user's configuration management operations by obtaining the corresponding permission information based on the target user group identifier and determining whether the configuration management information meets the permission information. After verifying the user group permissions, it further compares whether the first tenant identifier corresponding to the target service resource identifier and the second tenant identifier of the second tenant to which the target disk array system user belongs are the same, ensuring that each tenant can only perform configuration management on its own service resources, avoiding resource confusion and data leakage between different tenants, realizing effective isolation of tenant resources, and providing an independent and secure usage environment for each tenant.
[0108] In some alternative embodiments, the above target logic further includes:
[0109] Step c1: If the configuration management information does not meet the permission information corresponding to the target user group identifier, it is determined that the configuration management request is not allowed to be executed.
[0110] Among them, if the configuration management information does not meet the permission information corresponding to the target user group identifier, that is, the API does not allow execution, it is determined that the configuration management request is not allowed to be executed, that is, the API interface call fails and the process ends.
[0111] The multi-tenant implementation method of the disk array system provided by this application determines that the configuration management request is not allowed to be executed when the configuration management information does not meet the permission information corresponding to the target user group identifier, effectively preventing illegal operations, protecting the system and data security, and avoiding data leakage.
[0112] In some optional implementation manners, the above target logic further includes:
[0113] Step d1, if the first tenant identifier and the second tenant identifier are inconsistent, it is determined that the configuration management request is not allowed to be executed.
[0114] If the first tenant identifier and the second tenant identifier are inconsistent, the API interface call fails, it is determined that the configuration management request is not allowed to be executed, and the process ends.
[0115] The multi-tenant implementation method of the disk array system provided by this application determines that the configuration management request is not allowed to be executed when the first tenant identifier and the second tenant identifier are inconsistent, ensuring that each tenant can only manage its own business resources, avoiding misoperations of business resources, improving the accuracy and security of resource management, and realizing the isolation of business resources for multi-tenants.
[0116] In some optional implementation manners, the user group management module in the disk array system supporting multi-tenants includes the corresponding relationship between user groups and the permission information of user groups. The permission information of user groups includes static permissions. User groups include a security administrator group, a tenant administrator group, an audit administrator group, and a business administrator group.
[0117] The static permissions of the security administrator group include creating or managing users, creating or managing tenants, setting access control, creating and associating roles or permissions, etc.
[0118] The static permissions of the tenant administrator group include viewing the information of the corresponding tenant, creating users of the corresponding tenant, etc. Among them, the corresponding tenant information is the information of the affiliated tenant. Ordinary tenant users can only view the information of themselves as tenant users.
[0119] The static permissions of the audit administrator group include viewing or managing the execution results and execution logs of configuration management requests, and performing audit log checks, without access permissions to storage, configuration, or data.
[0120] The static permissions of the business administrator group include creating and configuring management of business resources, etc. Configuration management includes viewing and modifying. For example, remote replication operators can create, modify, and view remote replication services, etc. Access to security-related elements or data is not allowed. Among them, the business administrator group can be divided into multiple groups according to specific businesses, such as the volume administrator group, the remote replication administrator group, etc.
[0121] It should be noted that the above user groups and the permission information of user groups can be modified according to the disk array systems of different manufacturers, and no specific restrictions are made here.
[0122] If the above user group types are set, that is, the user groups include the security administrator group, the tenant administrator group, the audit administrator group, and the business administrator group, then the permission information of the user groups, that is, the static permissions, is fixed and not allowed to be modified.
[0123] The multi-tenant implementation method of the disk array system provided by this application, by clarifying the permission information of each user group, strictly isolates the permission information between each user group, reducing the risk of system failures or data leakage caused by misoperations or malicious operations.
[0124] In some optional implementation manners, the user group further includes a custom user group, the permission information of the user group includes custom permissions, and the above target logic further includes:
[0125] Step e1, in the case that the user group management module does not include the target user group corresponding to the target user group identifier, set a custom user group in the user group management module, and determine the target user group as the custom user group.
[0126] Step e2, set the permission information of the custom user group as the custom permissions input by the user.
[0127] Among them, if the static permission is defined by the user indicating that the permission information of the user is custom permission, the permission information of the custom user group can be set or expanded by itself.
[0128] The multi-tenant implementation method of the disk array system provided by this application, by introducing the functions of custom user groups and custom permissions, not only improves the flexibility and adaptability of the system, but also enhances the fineness of permission management, supporting scalability in a multi-tenant environment.
[0129] In some optional implementation manners, the multi-tenant implementation method of the above disk array system further includes:
[0130] Step f1, add a tenant management module in the current disk array system. The tenant management module is used to save and manage the attribute information of each tenant. Among them, the attribute information at least includes the list of business resources belonging to the tenant.
[0131] Among them, the tenant management module saves and manages the attribute information of each tenant through the tenant information table. Figure 10 It is a schematic structural diagram of the tenant information table provided by the embodiment of the present application, as Figure 10 shown, the tenant information table includes the correspondence between the tenant identifiers of each tenant and the attribute information of each tenant. The attribute information includes the business resource list belonging to the tenant, that is, the associated resource list, tenant name, tenant quota, and other tenant attributes, etc. The tenant ID in the tenant information table starts from 0, and a tenant identifier of 0 represents that the tenant is the default tenant (Default_tenant).
[0132] After each business resource is successfully created, the corresponding business resource identifier also needs to be updated to the associated resource list field of the tenant information table.
[0133] It should be noted that only users belonging to the security administrator group among the system administrators can create tenants. The tenant management module is used to record the relevant information of the tenants created in the disk array system.
[0134] Figure 11 It is a schematic structural diagram of the disk array system supporting multi-tenancy provided by the embodiment of the present application. As Figure 11 shown, the disk array system supporting multi-tenancy includes the original hardware of the disk array system, the basic software of the disk array system, the interface layer of the disk array system, the user permission management module, the user group management module, and the tenant management module.
[0135] Among them, the interface layer of the disk array system is used to receive external calls, that is, to receive external access, and based on the user permission management module and the user group management module, determine whether the external access is allowed to be executed, so that the CPU of the disk array system executes the external access or does not execute the external access based on the determination result.
[0136] The tenant management module is used to record the relevant information of the tenants created in the disk array system to facilitate querying all the resources of a certain tenant.
[0137] The uses of the user permission management module and the user group management module are as described above, and will not be elaborated here.
[0138] The multi-tenancy implementation method of the disk array system provided by the present application, by adding a tenant management module, enables the system to have a clearer and more accurate grasp of the resources of each tenant, and then realizes the efficient allocation, scheduling, and monitoring of resources, which helps to ensure data security.
[0139] In some optional implementation manners, the above multi-tenancy implementation method of the disk array system further includes:
[0140] Step g1, if there are business resources in the current disk array system that are not bound to a specific tenant, then determine the tenant to which the unbound business resources belong as the default tenant.
[0141] Among them, to ensure the downward compatibility of the software, a default tenant is introduced. If there are business resources in the current disk array system that are not bound to a specific tenant, then determine the tenant to which the unbound business resources belong as the default tenant.
[0142] Step g2, during the process of upgrading the current disk array system to a multi-tenant-enabled disk array system, create a user in the tenant administrator group as the default tenant.
[0143] Upgrading from a low version that does not support multi-tenancy to a high version that supports multi-tenancy, the tenant attribute of the business resources in the current disk array system automatically becomes the default tenant, and a user in the tenant administrator group of the default tenant is automatically created during the upgrade process to facilitate the configuration and management after the upgrade. In this way, whether it is newly developing the multi-tenant function or upgrading the multi-tenant support ability on the existing disk array system, it can be well compatible, while taking into account security and convenience.
[0144] That is to say, the multi-tenant implementation method of the disk array system provided by this application can also be used at the initial stage of the disk array system design to implement the multi-tenant function of the disk array system.
[0145] The multi-tenant implementation method of the disk array system provided by this application, when upgrading the current disk array system, some old resources may not be bound to a specific tenant. By attributing them to the default tenant, a smooth transition of the system from a single-tenant to a multi-tenant architecture can be achieved. This method avoids the loss or chaos of resources during the upgrade process, ensures that the system can operate normally after the upgrade, and reduces the risks and costs brought by the upgrade. At the same time, creating a user for the default tenant in the tenant administrator group enables the upgraded system to effectively manage these old resources, ensuring the compatibility of the system and enabling the new architecture to seamlessly integrate with the data and operation modes of the old system.
[0146] In some optional implementation manners, the above multi-tenant implementation method of the disk array system further includes:
[0147] Step h1, set the users in the system administrator who belong to the business administrator group to have the call permission for the resource creation type interfaces.
[0148] Step h2, set the tenant users to have the call permission for the configuration management type interfaces.
[0149] Among them, the scope of action of the tenant users is the tenant to which they belong.
[0150] Figure 12It is a classification schematic diagram of users of the disk array system supporting multi-tenancy provided by the embodiments of the present application. As Figure 12 shown, all users of the disk array system supporting multi-tenancy can be divided into system users and tenant users. System users can be divided into security administrator group users, audit administrator group users, business administrator group users, and custom user group users, i.e., custom permission administrator users, etc. according to their affiliated user groups. Tenant users can be divided into tenant administrator group users, ordinary tenant users, and custom user group users, etc. according to their affiliated user groups.
[0151] The multi-tenancy implementation method of the disk array system provided by the present application effectively prevents non-professionals or ordinary tenant users from randomly creating resources by strictly restricting that only users in the business administrator group can call resource creation class interfaces, avoiding the abuse and waste of resources, and ensuring the security and stability of system resources. Tenant users can only call configuration management class interfaces, and the permission scope is limited within the affiliated tenant, which ensures that tenant users can only configure and manage their own resources, prevents cross-tenant unauthorized operations, and protects the independence and security of data of each tenant.
[0152] In some optional implementation manners, the multi-tenancy implementation method of the above disk array system further includes:
[0153] When calling the resource creation class interface of the disk array system supporting multi-tenancy to create business resources, obtain the third tenant identifier of the third tenant to which the created business resource belongs.
[0154] Based on the third tenant identifier, obtain the attribute information of the third tenant corresponding to the third tenant identifier from the tenant management module.
[0155] Based on the tenant quota and the associated resource list in the attribute information of the third tenant, determine whether the business resources associated with the third tenant exceed a preset quota, and the preset quota is set based on the tenant quota. The associated resource list includes the business resources associated with the third tenant.
[0156] If the business resources associated with the third tenant exceed the preset quota, return the information that the business resources cannot be bound to the third tenant, so that the user can reset the tenant to which the created business resource belongs.
[0157] If the business resources associated with the third tenant do not exceed the preset quota, determine that the created business resources successfully belong to the third tenant.
[0158] The multi-tenant implementation method of the disk array system provided in this embodiment obtains the attribute information of the third tenant, including tenant quotas and associated resource lists, and compares the business resources associated with the third tenant with a preset limit to ensure that the business resources used by each tenant are within a reasonable range. This helps the system achieve refined resource allocation, avoid individual tenants over-occupying resources, improve resource utilization, and ensure the fairness and reasonableness of resource allocation in a multi-tenant environment.
[0159] In summary, the multi-tenant implementation method of the disk array system provided in the embodiments of this application keeps the original hardware and basic software in the current disk array system unchanged, adds a tenant management software module, and introduces a tenant information table in the tenant management module to store all tenant information in the system. A tenant administrator user group is added to the user group management module in the current disk array system, and users in the tenant administrator user group can view all information under the corresponding tenant. A user information table is set in the user permission management module in the current disk array system to store all user information in the system. The user information table includes fields for the affiliated user group and affiliated tenant, which are used to record the user group corresponding to each user (with corresponding operation permissions in the user group) and the corresponding tenant information. The API interface layer of the current disk array system needs to be modified correspondingly for the introduced tenant concept. The business resource information table in the system needs to add a field for the affiliated tenant id to record the tenant identifier to which the business resource belongs when it is created, which requires adding a tenant id parameter to all resource creation class API interfaces. The permission judgment logic of all configuration management class API interfaces needs to be modified. On the basis of the original matching of user group permissions and actual operation permissions, it is also necessary to perform the consistency matching of the affiliated tenants of the subject and object. Through the modification of the disk array service software API interface layer, adding a tenant management module, and reconstructing the user permission management module and user group management module, multi-tenant resource isolation and access control of the disk array system are achieved at the software level, which not only ensures the ability to virtualize a set of disk array systems into multiple independent devices, but also ensures the downward compatibility of the disk array system, while providing convenience and security.
[0160] Through the description of the above embodiments, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation method.
[0161] The embodiments of this application also provide an electronic device, as Figure 13 shown, including a processor 1301 and a memory 1302. The memory 1302 stores a computer program, and the processor 1301 is configured to run the computer program to execute the steps in any of the above embodiments of the multi-tenant implementation method of the disk array system.
[0162] An embodiment of the present application further provides a computer-readable storage medium, in which a computer program is stored. Wherein, the computer program is configured to execute the steps in any of the above embodiments of the multi-tenant implementation method of the disk array system when running.
[0163] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media such as USB flash drives, read-only memories (ROM for short), random access memories (RAM for short), external hard drives, magnetic disks, or optical discs that can store computer programs.
[0164] An embodiment of the present application further provides a computer program product. The above computer program product includes a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above embodiments of the multi-tenant implementation method of the disk array system.
[0165] An embodiment of the present application further provides another computer program product, including a non-volatile computer-readable storage medium. The non-volatile computer-readable storage medium stores a computer program, and when the computer program is executed by a processor, it implements the steps in any of the above embodiments of the multi-tenant implementation method of the disk array system.
[0166] Those skilled in the art can further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of the two. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0167] The above has introduced in detail a multi-tenant implementation method, an electronic device, and a storage medium of a disk array system provided by the present application. Specific examples are used in this article to elaborate on the principle and implementation manner of the present application. The description of the above embodiments is only used to help understand the method and its core idea of the present application. It should be noted that for those of ordinary skill in the art of this technology, without departing from the principle of the present application, several improvements and modifications can be made to the present application, and these improvements and modifications also fall within the protection scope of the claims of the present application.
Claims
1. A method for implementing multi-tenancy in a disk array system, characterized in that: include: If the current disk array system needs to be upgraded to a version that supports multi-tenancy, a tenant identification parameter is added to the resource creation class interface in the interface layer of the current disk array system. The tenant identification parameter is used to indicate the tenant to which the created business resource belongs when creating a business resource; Modify the permission determination logic of the configuration management interface in the interface layer to isolate the configuration management of business resources of different tenants; Adding a correspondence between a tenant administrator group and permission information of the tenant administrator group in a user group management module of the current disk array system; Reconstructing the user authority management module of the current disk array system so that the user authority management module records the user information of the users of the disk array system; Obtain a disk array system that supports multi-tenancy; The step of modifying the permission determination logic of the configuration management interface in the interface layer to perform configuration management isolation on business resources of different tenants includes: Modify the permission determination logic of the configuration management interface to the following target logic: Receiving a configuration management request for the disk array system; Obtaining the target disk array system user identification and configuration management information in the configuration management request; Acquire target user information corresponding to the target disk array system user identifier from the user authority management module, wherein each disk array system user corresponds to a unique disk array system user identifier; Determining whether to allow the configuration management request to be executed based on the target user information and the configuration management information; The target logic determines whether to allow the configuration management request to be executed based on the target user information and the configuration management information, including: Based on the target user information, determining a target user group identifier of a target user group to which the target disk array system user belongs; Based on the target user group identifier, obtaining permission information corresponding to the target user group identifier from the user group management module, wherein each user group corresponds to a unique user group identifier; Determining whether the configuration management information satisfies the authority information corresponding to the target user group identifier; If the configuration management information satisfies the authority information corresponding to the target user group identifier, obtaining the target service resource identifier in the configuration management information; Determine, based on the service resource information table of the interface layer, a first tenant identifier corresponding to the target service resource identifier; Based on the target user information, determining a second tenant identifier of a second tenant to which the target disk array system user belongs; Determining whether the first tenant identifier and the second tenant identifier are consistent; If the first tenant identifier and the second tenant identifier are consistent, it is determined that the configuration management request is allowed to be executed.
2. The method for implementing multi-tenancy of a disk array system according to claim 1, characterized in that: The method further comprises: Each time a business resource is created, the correspondence between the business resource identifier corresponding to the business resource and the tenant identifier of the tenant to which the business resource belongs is added to the business resource information table of the interface layer.
3. The multi-tenant implementation method of the disk array system according to claim 1, characterized in that: The target logic also includes: If the configuration management information does not satisfy the authority information corresponding to the target user group identifier, it is determined that the configuration management request is not allowed to be executed.
4. The method for implementing multi-tenancy of a disk array system according to claim 1, characterized in that: The target logic also includes: If the first tenant identifier and the second tenant identifier are inconsistent, it is determined that the configuration management request is not allowed to be executed.
5. The multi-tenant implementation method of the disk array system according to claim 1, characterized in that: The user group management module in the disk array system supporting multiple tenants includes a correspondence between user groups and permission information of user groups, wherein the permission information of the user groups includes static permissions, and the user groups include a security administrator group, a tenant administrator group, an audit administrator group, and a business administrator group; The static permissions of the security administrator group include creating or managing users and creating or managing tenants; The static permissions of the tenant administrator group include viewing corresponding tenant information and creating corresponding tenant users; The static permissions of the audit administrator group include viewing or managing the execution results and execution logs of configuration management requests; The static permissions of the business administrator group include creation and configuration management of business resources.
6. The method for implementing multi-tenancy of a disk array system according to claim 5, characterized in that: The static permissions are fixed and cannot be modified.
7. The method for implementing multi-tenancy of a disk array system according to claim 5, characterized in that: The user group also includes a custom user group, the permission information of the user group includes custom permissions, and the target logic further includes: In a case where the user group management module does not include the target user group corresponding to the target user group identifier, setting a custom user group in the user group management module, and determining that the target user group is the custom user group; The permission information of the custom user group is set to the custom permission input by the user.
8. The method for implementing multi-tenancy of a disk array system according to claim 1, characterized in that: The method further comprises: A tenant management module is added to the current disk array system, and the tenant management module is used to store and manage attribute information of each tenant, wherein the attribute information at least includes a list of business resources belonging to the tenant.
9. The method for implementing multi-tenancy of a disk array system according to claim 1, characterized in that: The method further comprises: If there are service resources in the current disk array system that are not bound to the predetermined tenant, the tenant to which the service resources that are not bound to the predetermined tenant belong is determined as the default tenant; In the process of upgrading the current disk array system to a disk array system supporting multiple tenants, a user is created in the tenant administrator group as the default tenant.
10. The method for implementing multi-tenancy of a disk array system according to claim 1, characterized in that: The method further comprises: Setting the user who belongs to the business administrator group among the system administrators to have the calling authority of the resource creation class interface; Set the tenant user to have the permission to call the configuration management interface.
11. An electronic device, characterized in that: include: Memory for storing computer programs; A processor, configured to implement the steps of the multi-tenant implementation method of the disk array system according to any one of claims 1 to 10 when executing the computer program.
12. A computer-readable storage medium, characterized in that: The computer-readable storage medium stores a computer program, wherein the computer program, when executed by a processor, implements the steps of the multi-tenant implementation method of the disk array system according to any one of claims 1 to 10.
13. A computer program product, comprising a computer program, characterized in that When the computer program is executed by a processor, the steps of the multi-tenant implementation method of the disk array system as claimed in any one of claims 1 to 10 are implemented.
Citation Information
Patent Citations
Safety isolation method for cloud side multi-tenant data storage
CN104104513A
User management system and method
CN115375409A