Cloud resource deployment method and device, electronic equipment and storage medium

By generating and running the configuration files of the Infrastructure as Code tool, and automatically creating and registering cloud resources on the cloud platform, the problem of insufficient automation of the Infrastructure as Code tool in cloud resource deployment is solved, and more efficient cloud resource management and deployment is achieved.

CN119917112APending Publication Date: 2025-05-02ZHEJIANG ZEEKR INTELLIGENT TECH CO LTD +1

Patent Information

Application Number
CN202411993923.1
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-31
Publication Date
2025-05-02

AI Technical Summary

Technical Problem

The infrastructure-as-code tool has limited automation in cloud resource deployment tasks and requires more human operations, especially after the database instance is created, it cannot be automatically registered on the data management platform, and after the cloud resource information is created, it cannot be registered on the configuration management database.

Method used

By receiving users' cloud resource requirements, if there is a corresponding preset resource template, inject the requirements parameters into the template to generate the configuration file of the infrastructure, code tool, run the creation command to create cloud resources on the cloud platform, and register it with the data management platform, configuration management database, bastion machine and operation and maintenance automation platform.

Benefits of technology

It has implemented the introduction of automated operations based on the original infrastructure as code tools, enhanced the degree of automation, simplified the creation and deployment of cloud resources, avoided errors caused by manual operations, and ensured that cloud resources can be managed in a unified manner.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119917112A_ABST
    Figure CN119917112A_ABST
Patent Text Reader

Abstract

The invention provides a cloud resource deployment method and apparatus, an electronic device and a storage medium. The method comprises the steps of receiving a cloud resource demand of a user; if the corresponding preset resource template exists in the cloud resource type required by the user, injecting parameters carried by the cloud resource requirement into the preset resource template, and generating a configuration file of an infrastructure, namely a code tool; running a cloud resource creation command to call a cloud resource interface according to the configuration file, acquiring information required for creating a cloud resource type required by a user, and creating a cloud resource required by the user on a cloud platform based on the acquired information; and registering the created cloud resources to a data management platform, a configuration management database, a bastion host and / or an operation and maintenance automation platform. According to the method and the device, the automation degree of the infrastructure, namely a code tool, is enhanced, the overall process of cloud resource creation and deployment is simplified, and errors possibly caused by manual operation are avoided at the same time.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] One or more embodiments of the present specification relate to the technical field of cloud resource configuration, and in particular, to a cloud resource deployment method, device, electronic device, and storage medium. Background Art

[0002] Infrastructure as Code (IaC) is a software development practice that converts traditional infrastructure management tasks into code, allowing infrastructure configuration, deployment, and management to be automated programmatically. The core idea of ​​this tool is to treat infrastructure as part of the software, define version control, and automate the life cycle of the entire IT infrastructure by writing and maintaining code. For example, it allows developers to write executable script files in a descriptive programming language to automatically deploy, update, and maintain cloud resources.

[0003] However, although infrastructure as code tools provide multiple commands to manage infrastructure and greatly simplify many complex IT processes, they still face challenges in specific scenarios. For example, infrastructure as code tools have limited automation in cloud resource deployment tasks and require more manual operations. Summary of the invention

[0004] The present disclosure provides a cloud resource deployment method, the method comprising:

[0005] Receive cloud resource requirements from users;

[0006] If there is a corresponding preset resource template for the cloud resource type required by the user, inject the parameters carried by the cloud resource requirement into the preset resource template to generate a configuration file for the infrastructure as code tool;

[0007] Run a cloud resource creation command to call a cloud resource interface according to the configuration file, obtain information required to create a cloud resource type required by the user, and create the cloud resource required by the user on the cloud platform based on the obtained information;

[0008] Register the created cloud resources to the data management platform, configuration management database, bastion host, and / or operation and maintenance automation platform.

[0009] Optionally, the method further includes:

[0010] Creating a directory for each type of cloud resource, the directory containing configuration files of the infrastructure as code tool for the type of cloud resource;

[0011] In the directory created for each type of cloud resource, define the configuration and management logic of that type of cloud resource;

[0012] A main directory is created, where the main directory contains a main configuration file of the infrastructure as code tool, where the main configuration file is used to reference and combine directories corresponding to all types of cloud resources.

[0013] Optionally, after generating a configuration file of the infrastructure as code tool, the method further includes:

[0014] Creating a repository in a version control system for accessing or modifying historical versions of a file;

[0015] Add the generated infrastructure as code tool configuration files to the repository created in the version control system;

[0016] Submitting status information of the configuration file to a repository created in the version control system, the status information including a version of the configuration file.

[0017] Optionally, the creating cloud resources required by the user on the cloud platform based on the acquired information includes:

[0018] Determine whether the cloud resource type required by the user requires password configuration;

[0019] If the cloud resource type required by the user requires a password, the password is obtained from the password vault or a random password is generated;

[0020] According to the obtained or generated password and the obtained information, the environment required for cloud resources is created on the cloud platform, and cloud resources required by the user are further created.

[0021] Optionally, the determining whether the cloud resource type required by the user requires a password to be configured includes:

[0022] Determine whether the cloud resource type required by the user is a virtual machine or a database;

[0023] If the cloud resource type required by the user is a virtual machine or a database, it is determined that the password needs to be configured for the cloud resource type required by the user.

[0024] Optionally, before registering the created cloud resources to the data management platform, the configuration management database, the bastion host and / or the operation and maintenance automation platform, the method further includes:

[0025] If the cloud resource type required by the user is a database, a database user is created for the created database instance and the database is initialized;

[0026] The created database instance and the configuration information including the database user and the database are registered on the data management platform.

[0027] Optionally, after registering the created cloud resources to the data management platform, the configuration management database, the bastion host and / or the operation and maintenance automation platform, the method further includes:

[0028] Monitor the deployment status of the created cloud resources to obtain the status files generated by the created cloud resources;

[0029] The state files generated by the created cloud resources are stored in the object storage of the private cloud.

[0030] The present disclosure also provides a cloud resource deployment device, the device comprising:

[0031] A receiving unit, used for receiving a user's cloud resource demand;

[0032] A generating unit, configured to inject the parameters carried by the cloud resource requirement into the preset resource template if there is a corresponding preset resource template for the cloud resource type required by the user, so as to generate a configuration file for the infrastructure as code tool;

[0033] A creation unit, configured to execute a cloud resource creation command to call a cloud resource interface according to the configuration file, obtain information required to create a cloud resource type required by the user, and create the cloud resource required by the user on the cloud platform based on the obtained information;

[0034] The registration unit is used to register the created cloud resources to the data management platform, configuration management database, bastion host and / or operation and maintenance automation platform.

[0035] The present disclosure also provides an electronic device, comprising a communication interface, a processor, a memory and a bus, wherein the communication interface, the processor and the memory are interconnected via the bus;

[0036] The memory stores machine-readable instructions, and the processor executes the above method by calling the machine-readable instructions.

[0037] The present disclosure also provides a machine-readable storage medium, wherein the machine-readable storage medium stores machine-readable instructions, and when the machine-readable instructions are called and executed by a processor, the above method is implemented.

[0038] Through the embodiments of the present disclosure, firstly, the user's cloud resource requirements are received. If there is a corresponding preset resource template for the cloud resource type required by the user, the parameters carried by the cloud resource requirements are injected into the preset resource template to generate a configuration file for the infrastructure as code tool; then the cloud resource creation command is run to call the cloud resource interface according to the configuration file to obtain the information required to create the cloud resource type required by the user, and based on the obtained information, the cloud resources required by the user are created on the cloud platform; finally, the created cloud resources are registered to the data management platform, configuration management database, bastion host and / or operation and maintenance automation platform. Accordingly, the present disclosure implements the introduction of automated operations such as registering cloud resource information on the platform and database on the basis of the original infrastructure as code tool, which not only enhances the automation level of the infrastructure as code tool and simplifies the overall process of cloud resource creation and deployment, but also avoids errors that may be caused by manual operations. In addition, this automated registration mechanism helps to ensure that all cloud resources can be effectively integrated into a unified management system to facilitate subsequent management and maintenance. BRIEF DESCRIPTION OF THE DRAWINGS

[0039] In order to more clearly illustrate the technical solutions of the embodiments of this specification, the drawings required for use in the description of the embodiments will be briefly introduced below. Obviously, the drawings described below are only some embodiments recorded in this specification. For ordinary technicians in this field, other drawings can be obtained based on these drawings without paying creative labor.

[0040] Figure 1 is a flow chart of a cloud resource deployment method shown in an exemplary embodiment;

[0041] Figure 2 It is a schematic diagram of a method for using an infrastructure as code tool shown in an exemplary embodiment;

[0042] Figure 3 is a flow chart of a method for creating cloud resources shown in an exemplary embodiment;

[0043] Figure 4 is a schematic diagram of a cloud resource registration location shown in an exemplary embodiment;

[0044] Figure 5 is a flow chart of another cloud resource deployment method shown in an exemplary embodiment;

[0045] Figure 6 is a hardware structure diagram of an electronic device shown in an exemplary embodiment;

[0046] Figure 7 It is a block diagram of a cloud resource deployment device shown in an exemplary embodiment. DETAILED DESCRIPTION

[0047] In order to enable those skilled in the art to better understand the technical solutions in this specification, the technical solutions in the embodiments of this specification will be clearly and completely described below in conjunction with the drawings in the embodiments of this specification. Obviously, the described embodiments are only part of the embodiments of this specification, not all of the embodiments. Based on the embodiments in this specification, all other embodiments obtained by ordinary technicians in this field without creative work should fall within the scope of protection of this specification.

[0048] It should be noted that: in other embodiments, the steps of the corresponding method are not necessarily performed in the order shown and described in this specification. In some other embodiments, the steps included in the method may be more or less than those described in this specification. In addition, a single step described in this specification may be decomposed into multiple steps for description in other embodiments; and multiple steps described in this specification may be combined into a single step for description in other embodiments.

[0049] Infrastructure as Code (IaC) is a software development practice that converts traditional infrastructure management tasks into code, allowing infrastructure configuration, deployment, and management to be automated programmatically. The core idea of ​​this tool is to treat infrastructure as part of the software, define version control, and automate the life cycle of the entire IT infrastructure by writing and maintaining code. For example, it allows developers to write executable script files in a descriptive programming language to automatically deploy, update, and maintain cloud resources.

[0050] However, although infrastructure as code tools provide multiple commands to manage infrastructure and greatly simplify many complex IT processes, they still face challenges in specific scenarios. For example, infrastructure as code tools have limited automation in cloud resource deployment tasks and require more manual operations. For example, after a database instance is created, it cannot be automatically registered on the data management platform, and after cloud resource information is created, it cannot be registered on the configuration management database.

[0051] In view of this, this specification aims to propose a technical solution that can automatically complete the entire set of creation and registration of cloud resource deployment.

[0052] During implementation, first, the user's cloud resource demand is received. If the cloud resource type required by the user exists a corresponding preset resource template, the parameters carried by the cloud resource demand are injected into the preset resource template to generate a configuration file for the infrastructure as code tool; further, a cloud resource creation command is run to call the cloud resource interface according to the configuration file to obtain the information required to create the cloud resource type required by the user, and based on the obtained information, the cloud resource required by the user is created on the cloud platform; finally, the created cloud resources are registered to the data management platform, configuration management database, bastion host and / or operation and maintenance automation platform.

[0053] For example, a company developer needs to create a new web application environment on the Amazon AWS cloud platform, including a VPC (Virtual Private Cloud), several EC2 (Elastic Compute Cloud) instances, an RDS (Relational Database Service) database instance, and some security group rules. The developer hopes to use a declarative configuration language to describe the expected state of these cloud resources and use Terraform in the IaC (Infrastructure as Code) tool to automatically create these resources. This process requires the following steps: Step 1: Developers write declarative configuration files: Developers use a declarative configuration language (such as Terraform's HCL) to describe the required cloud resources and their properties; for example, write the following: A VPC is required, where the VPC's classless inter-domain routing block is 10.0.0.0 / 16; three EC2 instances are required, each running the Ubuntu 20.04LTS operating system; an RDS MySQL database instance is required, version 5.7, with a storage capacity of 20GB; some security group rules are required to allow HTTP (port 80) and HTTPS (port 443) traffic to enter. Step 2: Receive the user's cloud resource requirements: Terraform reads the developer's declarative configuration file to understand the user's cloud resource requirements. If there is a corresponding preset resource template (a template file written using the Mako template engine, which is a special text file containing some special tags that can be replaced with actual parameter values) for the type of cloud resource required by the user, the parameters carried in the user's requirements are injected into these preset resource templates to generate Terraform's .tf file, which contains all the necessary cloud resource definitions and properties. Step 3: Create cloud resources: Run Terraform's creation command terraform apply, so that Terraform calls the Amazon AWS cloud platform's API according to the .tf configuration file generated in the second step to obtain the information required to create the cloud resources required by the developer (including creating VPC, EC2 instances, RDS database instances, and security group rules). Then, based on the information obtained from the API, Terraform creates the cloud resources required by the user on the Amazon AWS cloud platform and configures them accordingly. Step 4: Register cloud resources: The cloud resources created by Terraform will be automatically registered with the company's data management platform, configuration management database, bastion host, and / or operation and maintenance automation platform. For example, the relevant information of the RDS database instance will be registered with the company's data management platform for database management and monitoring.The relevant information of EC2 instances will be registered to the bastion host for centralized management and secure access control. The relevant information of VPC, EC2 instances, RDS database instances, and security group rules will be recorded in the configuration management database for subsequent management and monitoring. The status and properties of these resources will also be synchronized to the operation and maintenance automation platform to facilitate further automated operations, such as automatic expansion, backup and recovery, etc.

[0054] It can be seen that in the technical solution of this specification, when the user's cloud resource demand is received and there is a corresponding preset resource template for the cloud resource type required by the user, the parameters carried by the cloud resource demand are injected into the preset resource template to generate a configuration file for the infrastructure as code tool; then the cloud resource creation command is run to call the cloud resource interface according to the configuration file to obtain the information required to create the cloud resource type required by the user, and based on the obtained information, the cloud resource required by the user is created on the cloud platform; finally, the created cloud resources are registered to the data management platform, configuration management database, bastion host and / or operation and maintenance automation platform. Accordingly, the present disclosure implements the introduction of automated operations such as registering cloud resource information on the platform and database on the basis of the original infrastructure as code tool, which not only enhances the automation level of the infrastructure as code tool and simplifies the overall process of cloud resource creation and deployment, but also avoids errors that may be caused by manual operations. In addition, this automated registration mechanism helps to ensure that all cloud resources can be effectively integrated into a unified management system for easy subsequent management and maintenance.

[0055] The present disclosure is described below through specific embodiments in combination with specific application scenarios.

[0056] See also Figure 1 , Figure 1 This is a flow chart of a cloud resource deployment method shown in an exemplary embodiment. The method may perform the following steps:

[0057] Step 102: Receive the user's cloud resource requirements.

[0058] For example, developers use a declarative configuration language (such as Terraform's HCL) to describe the required cloud resources and their properties; for example, write the following: A VPC (Virtual Private Cloud) is required, where the VPC's classless inter-domain routing block is 10.0.0.0 / 16; three EC2 (Elastic Compute Cloud) instances are required, each running the Ubuntu 20.04LTS operating system; an RDS MySQL database instance is required, version 5.7, and the storage capacity is 20GB; some security group rules are required to allow HTTP (port 80) and HTTPS (port 443) traffic to enter. Terraform then reads the developer's declarative configuration file to understand the user's cloud resource requirements.

[0059] Among them, the declarative configuration language allows users to define the resources they need and their configurations, rather than writing a series of commands to achieve this state. Terraform uses its own configuration language (HCL) to define, manage, and version control cloud resources, so that the deployment, update, and version control of infrastructure can be managed like code. VPC (Virtual Private Cloud) is an isolated cloud environment that provides users with a logically isolated network space. In this embodiment, the VPC's classless inter-domain routing block 10.0.0.0 / 16 defines the VPC's IP address range.

[0060] EC2 (Elastic Compute Cloud) allows users to rent virtual servers in the cloud. RDS (Relational Database Service) is a managed database service where users can deploy and manage relational databases. Security groups are a virtual firewall on the Amazon AWS cloud platform that controls traffic in and out of EC2 instances. In this example, the security group rules allow HTTP (port 80) and HTTPS (port 443) traffic to enter, which defines the type of network traffic allowed.

[0061] Step 104: If there is a corresponding preset resource template for the cloud resource type required by the user, the parameters carried by the cloud resource requirement are injected into the preset resource template to generate a configuration file for the infrastructure as code tool.

[0062] For example, the cloud resource types required by developers are virtual private clouds, elastic computing clouds, databases, and security groups. These are common cloud resource requirements, and there are usually corresponding preset resource templates (template files written using the Mako template engine. Mako templates are special text files that contain some special tags that can be replaced with actual parameter values). Then, the parameters carried in the user requirements are injected into these preset resource templates to generate Terraform's .tf file. This configuration file contains all the necessary cloud resource definitions and properties.

[0063] Among them, the preset resource template is used to quickly deploy common cloud resource configurations. The preset resource template contains the basic structure and configuration of the resource, but some specific details (such as resource name, size, version, etc.) are designed as variable parameters. When the user's specific requirements (i.e. parameters) are injected into the preset resource template, a specific configuration file can be generated. The user's specific requirement parameters can be the name, size, version, network configuration, etc. of the resource. Mako is a Python template engine that allows Python expressions to be embedded in the template to dynamically generate content. In cloud resource management, Mako templates can be used to create cloud resource configuration files containing dynamic parameters. Terraform uses .tf files to define the configuration of cloud resources. .tf files are written in HCL (HashiCorp Configuration Language) to define the type, properties, and dependencies of resources.

[0064] Virtual Private Cloud (VPC), Elastic Compute Cloud (EC2), database (such as RDS) and security group are common cloud resources, and each resource type has its specific configuration requirements and parameters. When developers put forward cloud resource requirements and there are matching preset resource templates, they can use template engines (such as Mako) to read these templates and replace the placeholders or tags in the templates according to the user's required parameters to generate new .tf configuration files. These files contain all the necessary cloud resource definitions and properties, which can be directly read and executed by Terraform to deploy the corresponding resources in the cloud environment.

[0065] Step 106: Run the cloud resource creation command to call the cloud resource interface according to the configuration file, obtain the information required to create the cloud resource type required by the user, and create the cloud resource required by the user on the cloud platform based on the obtained information.

[0066] For example, running the Terraform creation command terraform apply enables Terraform to call the API of the Amazon AWS cloud platform according to the generated .tf configuration file to obtain the information required to create the cloud resources required by developers (including creating VPC, EC2 instances, RDS database instances, and security group rules). Based on the information obtained from the API, Terraform creates the cloud resources required by developers on the Amazon AWS cloud platform and configures them accordingly. Specifically, a VPC (Virtual Private Cloud) is created and configured with a specified classless inter-domain routing block; an EC2 instance is started and the specified operating system is installed; an RDS database instance is created and configured with a specified version and storage capacity; and security group rules are set to allow traffic from specific ports to enter.

[0067] Among them, cloud resource creation commands are commands of infrastructure as code tools that are used to trigger the creation process of cloud resources. These commands interact with the API of cloud service providers based on the parameters defined in the configuration files. In infrastructure as code tools, configuration files define the required cloud resources and their configurations. In Terraform, these files usually have the extension `.tf` and are written in HCL. Terraform's terraform apply command is a core command of Terraform, which is used to apply the resource status defined in the configuration file to the actual cloud environment. When this command is executed, Terraform reads the configuration file, generates an execution plan, and calls the corresponding cloud service API to create or update resources, and returns a success or failure prompt to the developer. Cloud service providers provide APIs that allow infrastructure as code tools to interact with cloud services to create and manage cloud resources. Once infrastructure as code tools (such as Terraform) determine the status of the required resources based on the configuration file, new resources will be created or existing resources will be modified through the cloud platform's API to match the definition in the configuration file.

[0068] Step 108: Register the created cloud resources to the data management platform, configuration management database, bastion host and / or operation and maintenance automation platform.

[0069] For example, the relevant information of the RDS database instance created by Terraform will be registered to the company's data management platform for database management and monitoring. The relevant information of the EC2 instance will be registered to the bastion host. The registration process usually involves adding the information of the new EC2 instance in the management interface of the bastion host, such as IP address, port number, login username and password or SSH key, etc., for centralized management and secure access control. The relevant information of VPC, EC2 instance, RDS database instance and security group rules will be recorded in the configuration management database for subsequent management and monitoring. The status and properties of these resources will also be synchronized to the operation and maintenance automation platform to facilitate further automated operations, such as automatic expansion, backup and recovery.

[0070] Among them, the data management platform is a platform for managing and monitoring data resources. In this embodiment, the relevant information of the RDS database instance (such as instance ID, access credentials, configuration parameters, etc.) is registered to the data management platform for database monitoring, performance analysis and security management. The configuration management database is a database system used to store and manage all configuration information of IT infrastructure. The relevant information of VPC, EC2 instance, RDS database instance and security group rules is recorded in the configuration management database to facilitate resource tracking and change management. The operation and maintenance automation platform is a platform for automating IT operation and maintenance tasks, such as automated deployment, backup and recovery, etc. The status and properties of cloud resources are synchronized to the operation and maintenance automation platform to facilitate the automated management and operation of cloud resources.

[0071] Among them, the bastion host is a security device specifically used to manage and control access to internal network resources. Through the bastion host, operation and maintenance personnel can centrally manage access to EC2 instances to ensure that only authorized users can access these resources. EC2 instances need to be registered to the bastion host because they are usually accessed remotely through SSH or remote desktop protocol. The bastion host is mainly used to manage remote access based on SSH or remote desktop protocol. Other cloud resource types do not need to be registered to the bastion host. For example, object storage services are usually accessed through API calls or web interfaces, rather than through direct terminal connections. Bastion hosts are not suitable for access control of this type of object storage services; databases are usually accessed through network connections and specific client tools, rather than through SSH or remote desktop protocols. Bastion hosts are not suitable for access control of this type of databases.

[0072] In the specific operation of the automatic registration process, Terraform or other infrastructure as code tools usually provide hooks (also known as hooks) or outputs (also known as outputs) functions, allowing specific operations to be performed after the resource is created, including registering cloud resource information to a data management platform, a configuration management database, or an operation and maintenance automation platform, and synchronizing cloud resource status and attributes as needed. The present disclosure does not limit the specific method of the registration process.

[0073] In order to facilitate those skilled in the art to understand this embodiment more intuitively, please refer to Figure 2 , Figure 2 FIG. 1 is a schematic diagram of a method for using an infrastructure as code tool, shown in an exemplary embodiment. Figure 2 As shown in the figure, the user proposes infrastructure requirements, such as the need to create cloud resources. Then, the user can use a declarative method to generate a configuration file. After receiving the generated configuration file, the infrastructure configuration tool parses the parameters therein and generates a plan for executing cloud resource creation. Then, according to the plan, the cloud platform's API interface is called to obtain relevant information for generating cloud resources, and cloud resource creation and management are completed on the cloud platform, such as registering with a data management platform.

[0074] In one embodiment shown, the method also includes: creating a directory for each type of cloud resource, the directory containing a configuration file of the infrastructure as code tool for that type of cloud resource; defining the configuration and management logic of that type of cloud resource in the directory created for each type of cloud resource; creating a master directory, the master directory containing a master configuration file of the infrastructure as code tool, the master configuration file being used to reference and combine directories corresponding to all types of cloud resources.

[0075] For example, create a main directory under the root directory of the project. This main directory contains configuration files for all types of cloud resources and the main configuration file. In the main directory, create separate subdirectories for ECS virtual machines, MySQL database instances, and OSS (Object Storage Service). The 'ecs / ' directory is used to store configurations related to ECS virtual machines, the 'mysql / ' directory is used to store configurations related to MySQL database instances, and the 'oss / ' directory is used to store configurations related to object storage OSS. Then define the configuration and management logic of this type of cloud resource in each subdirectory. Define the basic information of the ECS virtual machine instance in the 'ecs / ' directory, such as the image ID and instance type used; define the basic properties of the MySQL database instance in the 'mysql / ' directory, such as the engine version and storage size; and define the name of the OSS bucket and its access control list in the 'oss / ' directory. Finally, create a main configuration file in the main directory, usually named 'main.tf', which is used to reference the configuration files in each subdirectory and combine them into a complete infrastructure definition. The main configuration file can contain references to each module, each corresponding to a type of cloud resource.

[0076] Among them, the management of various cloud resources in related technologies mainly relies on online operation and maintenance, which means that the operation and maintenance team usually needs to manually configure and manage resources through the cloud service provider's console, which is not only inefficient but also prone to errors. In this embodiment, through such a modular and centralized reference method, developers can clearly organize and manage different types of cloud resources, which can not only improve the efficiency and consistency of cloud resource management, but also enhance the linkage between resources within the cloud, thereby supporting more flexible, reliable and automated cloud infrastructure management.

[0077] In one embodiment shown, after generating a configuration file for the infrastructure as a code tool, the method further includes: creating a repository in a version control system, the version control system being used to access or modify historical versions of files; adding the generated configuration file for the infrastructure as a code tool to the repository created in the version control system; and submitting status information of the configuration file to the repository created in the version control system, the status information including the version of the configuration file.

[0078] For example, create a new repository on the version control system GitHub to store all Terraform configuration files (i.e., .tf files) and their historical versions. Add all Terraform configuration files (i.e., .tf files) in the project root directory to the repository created in the version control system. This includes all configuration files in the ecs / , mysql / , and oss / directories, as well as the main configuration file in the home directory. At the same time, submit the status information of these configuration files to the repository created in GitHub, including their version information. Each submission generates a unique identifier representing the version submitted. This makes it easy for developers to view the specific content of each change and roll back to a previous version when necessary.

[0079] In this embodiment, developers can access and modify historical versions of configuration files to facilitate backtracking and auditing.

[0080] A version control system is a system that records historical changes to files or projects. It allows users to view historical versions of files, compare differences between different versions, and roll back to a previous version when necessary. Common version control systems include GitLab, GitHub, or self-built Git servers, and Subversion (SVN).

[0081] In one embodiment shown, the creation of cloud resources required by the user on the cloud platform based on the acquired information includes: determining whether the type of cloud resource required by the user requires configuration of a password; if the type of cloud resource required by the user requires configuration of a password, obtaining the password from a password vault, or generating a random password; creating the environment required for the cloud resources on the cloud platform based on the acquired or generated password and the acquired information, and further creating the cloud resources required by the user.

[0082] For example, a developer of a company wants to deploy an application environment that includes a MySQL database and an ECS (Elastic Compute Service) virtual machine on a cloud platform. In this scenario, you need to configure a password for the MySQL database to ensure data security, and you also need to set a login password or SSH key for the ECS virtual machine, so that the developer can choose to use password authentication or SSH key pairs to log in. If the company already has a password vault, you can get the passwords for the MySQL database and ECS virtual machine from there. If there is no ready-made password, you can use a secure method to generate a random password, such as using a data source in a Terraform file to generate a random password.

[0083] Then, based on the existing password obtained from the password vault or the generated new password, combined with the specific information of the cloud resources required by the developer (this includes but is not limited to the version, storage capacity, network settings and other parameters of the specified MySQL database instance, as well as the selection of the appropriate operating system image, computing specifications, disk configuration and network configuration for the ECS virtual machine), a basic environment that meets the requirements is built on the selected cloud platform. Next, in this configured environment, the corresponding cloud resources are further deployed according to the specific needs of the developer, such as starting and configuring the MySQL database service to ensure that it can be accessed in a set secure manner; at the same time, the ECS virtual machine is activated and the necessary system initialization settings are completed to make it an ideal platform to support the operation of the application.

[0084] Among them, for each resource type, it is necessary to check whether a password needs to be configured. The three cloud resource types of virtual machines, databases, and Redis usually require passwords to be configured, because virtual machines usually need to set a login password or configure an SSH key pair to ensure secure access, and databases need to configure a strong password to protect the database instance to prevent unauthorized access. Although Redis itself does not use passwords, security can be enhanced by configuring access control lists (ACLs) or using password-protected Redis instances. A named vault is a system for securely storing and managing sensitive information such as passwords, keys, etc. Cloud server services allow users to rent virtual servers in a cloud environment. An SSH key pair is a public / private key pair used for authentication, which is used to securely log in to a virtual machine or server. Object storage services are used to store and retrieve unstructured data, such as files, pictures, etc. It usually ensures security through access control policies and signatures, rather than passwords.

[0085] In order to facilitate those skilled in the art to understand this embodiment more intuitively, please refer to Figure 3 , Figure 3 FIG. 1 is a flowchart of a method for creating cloud resources according to an exemplary embodiment. Figure 3 As shown, after running the cloud resource creation command and starting the cloud resource creation, the information required to create the cloud resource is obtained from the cloud platform; if the acquisition is successful, it is determined whether the type of cloud resource to be created requires a password to be configured. If the password has been configured, the password is obtained from the naming vault, and then the cloud resource environment is created; if the password is not configured, a random password is generated, the generated random password is uploaded to the password vault, and then the generated random password is returned to create the cloud resource environment; if the password does not need to be configured, the cloud resource environment is created directly. After the cloud resource environment is created, a cloud resource is created; if the creation is successful, it is determined whether the created cloud resource is a database. If so, a database user and a database need to be created; if it is not a database, it ends directly.

[0086] In one embodiment shown, the determination of whether the cloud resource type required by the user requires a password to be configured includes: determining whether the cloud resource type required by the user belongs to a virtual machine or a database; if the cloud resource type required by the user belongs to a virtual machine or a database, determining that the cloud resource type required by the user requires a password to be configured.

[0087] For example, a developer of a company wants to deploy an application environment that includes a MySQL database and an ECS (Elastic Compute Service) virtual machine on a cloud platform. In addition, the developer also plans to use an object storage service to store some static files. In this scenario, the MySQL database belongs to the database type, and a password needs to be configured for the MySQL database to ensure data security. Usually, the database password is set through the database management interface or command line tools. The ECS virtual machine belongs to the virtual machine type and also needs to set login credentials. Developers can choose to set a login password for SSH login, or generate a pair of SSH keys (public key and private key), add the public key to the ECS instance, and use the private key for SSH login. For the object storage service that may be used later, since it mainly ensures security through access control policies and signatures, there is no need to configure a password.

[0088] Among them, a virtual machine is a computer simulated by software that can run multiple operating system instances on a single physical server. A database is a way to organize and store data, supporting efficient retrieval and management of data. An object storage service is a service for storing unstructured data (such as files, pictures, videos, etc.), and security is usually guaranteed through access control policies and signatures. Password authentication is a method of identity authentication by entering a password. An SSH key pair is an authentication method based on public key cryptography, consisting of a public key and a private key. The public key is stored on the server, and the private key is held by the user. An access control policy is a set of rules for managing who can access specific resources. An access control list can be set for an object storage service to specify which users or groups can access specific objects. Signatures are a technology used to verify the integrity and source of data, and are usually used in conjunction with access control policies.

[0089] In one embodiment shown, before registering the created cloud resources on a data management platform, a configuration management database, a bastion host and / or an operation and maintenance automation platform, the method further includes: if the cloud resource type required by the user belongs to a database, establishing a database user for the created database instance and initializing the database; registering the created database instance and the configuration information including the database user and the database on the data management platform.

[0090] For example, after creating a MySQL database instance on the Amazon AWS cloud platform, use Terraform's data source to generate a strong password for the new user app_user and store it in the managed service provided by Amazon Web Services. Terraform will then run the script to create a new database app_db and grant the app_user user appropriate permissions to the database. These permissions will be set according to the user's actual needs to ensure that the principle of least privilege is followed. After Terraform completes these steps, it registers the database instance and user's configuration information to the data management platform.

[0091] Among them, database instances usually require specific management and monitoring, such as performance monitoring, backup, recovery, and security management. Registering the configuration information of the database instance to the data management platform can ensure that the operation status of the database is properly tracked and managed. In addition, for security reasons, the database contains sensitive data, so strict access control and security measures are required. Registering database instances and user information to the data management platform can help maintain these security measures and ensure that only authorized users can access the database. At the same time, the database instance and the database configuration information will also be synchronized to the configuration management database and the operation and maintenance automation platform to ensure that the configuration and status of the database instance can be tracked.

[0092] See also Figure 4 , Figure 4 FIG. 1 is a schematic diagram of a cloud resource registration location shown in an exemplary embodiment. Figure 4 As shown, determine whether the created cloud resource type is a virtual machine. If it is a virtual machine, register the created cloud resource to the bastion host, and then register the created virtual machine instance to the configuration management database or the operation and maintenance automation platform; if it is not a virtual machine, determine whether the created cloud resource type is a database. If it is a database, register the created cloud resource to the data management platform, and then register the created virtual machine instance to the configuration management database or the operation and maintenance automation platform; if the created cloud resource type is neither a virtual machine nor a database, directly register the created virtual machine instance to the configuration management database or the operation and maintenance automation platform.

[0093] In one embodiment shown, after registering the created cloud resources to a data management platform, a configuration management database, a bastion host and / or an operation and maintenance automation platform, the method further includes: monitoring the deployment status of the created cloud resources to obtain status files generated by the created cloud resources; and storing the status files generated by the created cloud resources on the object storage of the private cloud.

[0094] For example, after completing the registration of the relevant information of the RDS database instance created by Terraform to the company's data management platform, the registration of the relevant information of the EC2 instance to the bastion host, and recording the relevant information of the VPC, EC2 instance, RDS database instance and security group rules in the configuration management database, and ensuring that the status and properties of these resources have been synchronized to the operation and maintenance automation platform, Terraform will then generate a state file containing the deployment status and configuration information of the cloud resources. These state files will be stored in the object storage service of the private cloud, such as using the AWS S3 service to store these files for data backup, audit tracking and performance analysis.

[0095] Among them, the Terraform state file records the current state of the infrastructure, including all created resources and their properties. The state file usually contains the configuration and status information of the cloud resources, and is used to record and restore the status of the resources. Storing the state file on the object storage of the private cloud can achieve more comprehensive management and backup. In this embodiment, the Terraform state file will show the state file content after creating the VPC, EC2 instance, RDS database instance and security group rules on the AWS cloud platform. In this embodiment, AWS S3 is used as the backend storage, and the S3 storage bucket and key path can be specified through the Terraform configuration.

[0096] In order to facilitate those skilled in the art to understand this embodiment more intuitively, please refer to Figure 5 , Figure 5 FIG. 1 is a flow chart of another cloud resource deployment method shown in an exemplary embodiment. Figure 5 As shown, the user proposes a cloud resource requirement. If there is no corresponding preset resource template for the cloud resource type required by the user, the user needs to manually create the cloud resource. If there is a corresponding preset resource template for the cloud resource type required by the user, the parameters carried by the cloud resource requirement are injected into the preset resource template to generate a configuration file for the infrastructure as code tool, and then the configuration file is uploaded to the version management system for easy backtracking. After that, the cloud resource creation command is run to create the cloud resource required by the user on the cloud platform, and then the created cloud resource is registered to the data management platform, configuration management database, bastion host and / or operation and maintenance automation platform. Finally, the state file generated by the created cloud resource is stored in the object storage.

[0097] Corresponding to the above-mentioned embodiment of the method for deploying cloud resources, this specification also provides an embodiment of a device for deploying cloud resources.

[0098] See also Figure 6 , Figure 6It is a hardware structure diagram of an electronic device shown in an exemplary embodiment. At the hardware level, the device includes a processor 602, an internal bus 604, a network interface 606, a memory 608 and a non-volatile memory 610, and of course may also include other required hardware. One or more embodiments of this specification can be implemented based on software, such as the processor 602 reading the corresponding computer program from the non-volatile memory 610 into the memory 608 and then running it. Of course, in addition to the software implementation, one or more embodiments of this specification do not exclude other implementation methods, such as logic devices or a combination of software and hardware, etc., that is to say, the execution subject of the following processing flow is not limited to each logic unit, but can also be hardware or logic devices.

[0099] See also Figure 7 , Figure 7 FIG. 1 is a block diagram of a cloud resource deployment device shown in an exemplary embodiment. The cloud resource deployment device can be applied to Figure 6 In the electronic device shown in the figure, the technical solution of this specification is implemented. The device may include:

[0100] A receiving unit 702 is used to receive a user's cloud resource demand;

[0101] A generating unit 704 is configured to inject the parameters carried by the cloud resource requirement into the preset resource template if there is a corresponding preset resource template for the cloud resource type required by the user, so as to generate a configuration file for the infrastructure as code tool;

[0102] The creation unit 706 is used to run a cloud resource creation command to call a cloud resource interface according to the configuration file, obtain information required to create a cloud resource type required by the user, and create the cloud resource required by the user on the cloud platform based on the obtained information;

[0103] The registration unit 708 is used to register the created cloud resources to the data management platform, the configuration management database, the bastion host and / or the operation and maintenance automation platform.

[0104] In this embodiment, the device further includes:

[0105] A second creation unit is used to create a directory for each type of cloud resource, wherein the directory contains a configuration file of an infrastructure as code tool for the type of cloud resource;

[0106] A definition unit is used to define the configuration and management logic of each type of cloud resource in the directory created for that type of cloud resource;

[0107] The third creation unit is used to create a main directory, wherein the main directory contains a main configuration file of the infrastructure as code tool, and the main configuration file is used to reference and combine directories corresponding to all types of cloud resources. In this embodiment, after generating the configuration file of the infrastructure as code tool, the device also includes:

[0108] A fourth creation unit, used to create a repository in a version control system, wherein the version control system is used to access or modify historical versions of files;

[0109] Add a unit for adding the generated configuration files of the infrastructure as code tool to the repository created in the version control system;

[0110] A submitting unit is used to submit the status information of the configuration file to the repository created in the version control system, wherein the status information includes the version of the configuration file.

[0111] In this embodiment, the creation unit includes:

[0112] A judgment subunit is used to judge whether the cloud resource type required by the user needs to be configured with a password;

[0113] A generation subunit, used for obtaining a password from a password vault or generating a random password if the cloud resource type required by the user requires configuration of a password;

[0114] A subunit is created to create an environment required for cloud resources on the cloud platform according to the obtained or generated password and the obtained information, and further create cloud resources required by the user.

[0115] In this embodiment, the judgment subunit is specifically used for:

[0116] Determine whether the cloud resource type required by the user is a virtual machine or a database;

[0117] If the cloud resource type required by the user is a virtual machine or a database, it is determined that the password needs to be configured for the cloud resource type required by the user.

[0118] In this embodiment, before registering the created cloud resources to the data management platform, the configuration management database, the bastion host and / or the operation and maintenance automation platform, the device further includes:

[0119] An establishment unit, used for establishing a database user for the created database instance and initializing the database if the cloud resource type required by the user belongs to a database;

[0120] The second registration unit is used to register the created database instance and the configuration information including the database user and the database on the data management platform.

[0121] The implementation process of the functions and effects of each unit in the above-mentioned device is specifically described in the implementation process of the corresponding steps in the above-mentioned method, and will not be repeated here.

[0122] For the device embodiments, since they basically correspond to the method embodiments, the relevant parts can refer to the partial description of the method embodiments. The device embodiments described above are only schematic, wherein the units described as separate components may or may not be physically separated, and the components displayed as units may or may not be physical units, that is, they may be located in one place, or they may be distributed on multiple network units. Some or all of the modules may be selected according to actual needs to achieve the purpose of the scheme of this specification. Ordinary technicians in this field can understand and implement it without paying creative work.

[0123] The systems, devices, modules or units described in the above embodiments may be implemented by computer chips or entities, or by products with certain functions. A typical implementation device is a computer, which may be in the form of a personal computer, a laptop computer, a cellular phone, a camera phone, a smart phone, a personal digital assistant, a media player, a navigation device, an email transceiver, a game console, a tablet computer, a wearable device or a combination of any of these devices.

[0124] In a typical configuration, a computer includes one or more processors (CPU), input / output interfaces, network interfaces, and memory.

[0125] The memory may include non-permanent storage in a computer-readable medium, random access memory (RAM) and / or non-volatile memory in the form of read-only memory (ROM) or flash RAM. The memory is an example of a computer-readable medium.

[0126] Computer-readable media include permanent and non-permanent, removable and non-removable media that can be used to store information by any method or technology. Information can be computer-readable instructions, data structures, program modules or other data. Examples of computer storage media include, but are not limited to, phase change memory (PRAM), static random access memory (SRAM), dynamic random access memory (DRAM), other types of random access memory (RAM), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), flash memory or other memory technology, compact disc read-only memory (CD-ROM), digital versatile disc (DVD) or other optical storage, magnetic cassettes, disk storage, quantum memory, graphene-based storage media or other magnetic storage devices or any other non-transmission media that can be used to store information that can be accessed by a computing device. As defined herein, computer-readable media does not include temporary computer-readable media (transitory media), such as modulated data signals and carrier waves.

[0127] The user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this disclosure are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data must comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to choose to authorize or refuse.

[0128] It should also be noted that the terms "include", "comprises" or any other variations thereof are intended to cover non-exclusive inclusion, so that a process, method, commodity or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, commodity or device. In the absence of more restrictions, the elements defined by the sentence "comprises a ..." do not exclude the existence of other identical elements in the process, method, commodity or device including the elements.

[0129] The above is a description of a specific embodiment of the specification. Other embodiments are within the scope of the appended claims. In some cases, the actions or steps recorded in the claims can be performed in an order different from that in the embodiments and still achieve the desired results. In addition, the processes depicted in the drawings do not necessarily require the specific order or continuous order shown to achieve the desired results. In some embodiments, multitasking and parallel processing are also possible or may be advantageous.

[0130] The terms used in one or more embodiments of this specification are only for the purpose of describing specific embodiments, and are not intended to limit one or more embodiments of this specification. The singular forms of "one", "said" and "the" used in one or more embodiments of this specification and the appended claims are also intended to include plural forms, unless the context clearly indicates other meanings. It should also be understood that the term "and / or" used herein refers to and includes any or all possible combinations of one or more associated listed items.

[0131] It should be understood that although the terms first, second, third, etc. may be used to describe various information in one or more embodiments of this specification, these information should not be limited to these terms. These terms are only used to distinguish the same type of information from each other. For example, without departing from the scope of one or more embodiments of this specification, the first information may also be referred to as the second information, and similarly, the second information may also be referred to as the first information. Depending on the context, the word "if" as used herein may be interpreted as "at the time of" or "when" or "in response to determining".

[0132] The above description is merely a preferred embodiment of one or more embodiments of the present specification and is not intended to limit one or more embodiments of the present specification. Any modifications, equivalent substitutions, improvements, etc. made within the spirit and principles of one or more embodiments of the present specification shall be included in the scope of protection of one or more embodiments of the present specification.

Claims

1. A method for deploying cloud resources, characterized in that: The method comprises: Receive users’ cloud resource requirements; If there is a corresponding preset resource template for the cloud resource type required by the user, inject the parameters carried by the cloud resource requirement into the preset resource template to generate a configuration file for the infrastructure as code tool; Run a cloud resource creation command to call a cloud resource interface according to the configuration file, obtain information required to create a cloud resource type required by the user, and create the cloud resource required by the user on the cloud platform based on the obtained information; Register the created cloud resources to the data management platform, configuration management database, bastion host, and / or operation and maintenance automation platform.

2. The method according to claim 1, characterized in that The method further comprises: Creating a directory for each type of cloud resource, the directory containing configuration files of the infrastructure as code tool for the type of cloud resource; In the directory created for each type of cloud resource, define the configuration and management logic of that type of cloud resource; A main directory is created, where the main directory contains a main configuration file of the infrastructure as code tool, where the main configuration file is used to reference and combine directories corresponding to all types of cloud resources.

3. The method according to claim 1, characterized in that After generating a configuration file for the infrastructure as code tool, the method further includes: Creating a repository in a version control system for accessing or modifying historical versions of a file; Add the generated infrastructure as code tool configuration files to the repository created in the version control system; Submitting status information of the configuration file to a repository created in the version control system, the status information including a version of the configuration file.

4. The method according to claim 1, characterized in that The step of creating cloud resources required by the user on the cloud platform based on the acquired information includes: Determine whether the cloud resource type required by the user requires password configuration; If the cloud resource type required by the user requires a password, obtain the password from the password vault or generate a random password; According to the obtained or generated password and the obtained information, the environment required for cloud resources is created on the cloud platform, and cloud resources required by the user are further created.

5. The method according to claim 4, characterized in that The step of determining whether the cloud resource type required by the user requires a password to be configured includes: Determine whether the cloud resource type required by the user is a virtual machine or a database; If the cloud resource type required by the user is a virtual machine or a database, it is determined that the password needs to be configured for the cloud resource type required by the user.

6. The method according to claim 5, characterized in that Before registering the created cloud resources to the data management platform, the configuration management database, the bastion host and / or the operation and maintenance automation platform, the method further includes: If the cloud resource type required by the user is a database, a database user is created for the created database instance and the database is initialized; The created database instance and the configuration information including the database user and the database are registered on the data management platform.

7. The method according to claim 1, characterized in that After registering the created cloud resources to the data management platform, the configuration management database, the bastion host and / or the operation and maintenance automation platform, the method further includes: Monitor the deployment status of the created cloud resources to obtain the status files generated by the created cloud resources; The state files generated by the created cloud resources are stored in the object storage of the private cloud.

8. A cloud resource deployment device, characterized in that: The device comprises: A receiving unit, used for receiving a user's cloud resource demand; A generating unit, configured to inject the parameters carried by the cloud resource requirement into the preset resource template if there is a corresponding preset resource template for the cloud resource type required by the user, so as to generate a configuration file for the infrastructure as code tool; A creation unit, configured to execute a cloud resource creation command to call a cloud resource interface according to the configuration file, obtain information required to create a cloud resource type required by the user, and create the cloud resource required by the user on the cloud platform based on the obtained information; The registration unit is used to register the created cloud resources to the data management platform, configuration management database, bastion host and / or operation and maintenance automation platform.

9. An electronic device, characterized in that: It includes a communication interface, a processor, a memory and a bus, wherein the communication interface, the processor and the memory are interconnected via the bus; The memory stores machine-readable instructions, and the processor executes the method according to any one of claims 1 to 7 by calling the machine-readable instructions.

10. A machine-readable storage medium, characterized in that: The machine-readable storage medium stores machine-readable instructions, and when the machine-readable instructions are called and executed by the processor, the method according to any one of claims 1 to 7 is implemented.

Citation Information

Patent Citations

  • Infrastructure resource creating method and device based on DevOps platform

    CN114048029A

  • Cloud resource management method and device, server and storage medium

    CN115292071A

  • Cloud resource automatic creation method and cloud management platform

    CN118075139A

  • Terraform-based cloud resource automation method and device and storage medium

    CN118535343A

  • Deployment of cloud infrastructures using a cloud management platform

    US20230035600A1

Cited By

  • Cloud resource configuration method, apparatus and device, and computer readable storage medium

    CN120848951A