Cluster authority management method and device, first node, storage medium and computer program product

By receiving requests on the first node and calling the cross-domain cluster setting components, unified permission management for cross-domain multi-clusters in the big data component is realized, complexity problems of cluster management and operation and maintenance are solved, and management efficiency is improved.

CN119945749APending Publication Date: 2025-05-06CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 0 Cites 1 Cited by

Patent Information

Application Number
CN202411996718.0
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-12-30
Publication Date
2025-05-06

AI Technical Summary

Technical Problem

In big data components, cluster construction time is different and management operation and maintenance personnel are complex, making it difficult to manage permission control in a unified manner, and it is impossible to realize a unified view and operation and maintenance across multiple clusters.

Method used

By receiving requests on the first node, calling the setting components of each cross-domain cluster, performing management and viewing operations, unified permission management for cross-domain multi-clusters is realized.

Benefits of technology

It realizes unified management of cross-domain multi-clusters, reduces the difficulty of cluster management and operation and maintenance, reduces manual operation and maintenance costs, and improves cluster management efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119945749A_ABST
    Figure CN119945749A_ABST
Patent Text Reader

Abstract

The invention discloses a cluster authority management method and device, a first node, a storage medium and a computer program product, and the method comprises the steps that the first node receives a first request which is triggered at a first user interface of the first node, the authority management module is used for requesting to manage and / or check the authority of one or more cross-domain clusters; and executing a setting operation corresponding to the first request on each cluster corresponding to the first request by calling a setting component of each cluster corresponding to the first request.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of big data technology, and in particular to a cluster authority management method, device, first node, storage medium and computer program product. Background Art

[0002] At present, with the increase of business and massive data of enterprises, enterprises have successively built multiple resource pools, and each resource pool has deployed multiple clusters to meet the use needs of big data components. Due to the different time of cluster construction and the complex personnel who manage and operate the clusters at the same time, there are still management difficulties and operation difficulties in the permission control of big data components. Summary of the invention

[0003] To solve related technical problems, embodiments of the present application provide a cluster authority management method, device, first node, storage medium and computer program product.

[0004] The technical solution of the embodiment of the present application is implemented as follows:

[0005] The present application provides a cluster authority management method, the method comprising:

[0006] receiving a first request, where the first request is triggered in a first user interface of the first node and is used to request management and / or viewing of permissions of one or more cross-domain clusters;

[0007] By calling the setting component of each cluster corresponding to the first request, the setting operation corresponding to the first request is performed on each cluster corresponding to the first request.

[0008] The present application also provides a cluster authority management device, including:

[0009] A first receiving unit, configured to receive a first request, where the first request is triggered in a first user interface of the first node and is configured to request management and / or viewing of permissions of one or more cross-domain clusters;

[0010] The calling unit is configured to perform a setting operation corresponding to the first request on each cluster corresponding to the first request by calling a setting component of each cluster corresponding to the first request.

[0011] The embodiment of the present application further provides a first node, including a processor and a memory for storing a computer program that can be run on the processor.

[0012] Wherein, the processor is used to execute the steps of any of the above methods when running the computer program.

[0013] An embodiment of the present application further provides a storage medium on which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above methods are implemented.

[0014] An embodiment of the present application also provides a computer program product, including a computer program, which implements the steps of any of the above methods when executed by a processor.

[0015] In the cluster authority management method, device, first node, storage medium and computer program product provided in the embodiments of the present application, the first node receives a first request, which is triggered in the first user interface of the first node and is used to request the management and / or viewing of the authority of one or more cross-domain clusters; by calling the setting component of each cluster corresponding to the first request, the setting operation corresponding to the first request is performed on each cluster corresponding to the first request. The above scheme can manage and / or view one or more cross-domain clusters by calling the setting components of one or more cross-domain clusters, so that users can achieve unified management of multiple cross-domain clusters in the first user interface, which greatly reduces the difficulty of cluster management and operation and maintenance, reduces the cost of manual operation and maintenance, and improves cluster management efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0016] Figure 1 A schematic diagram of a flow chart of a cluster authority management method according to an embodiment of the present application;

[0017] Figure 2 This is a schematic diagram of permission management in an embodiment of the present application;

[0018] Figure 3 This is a schematic diagram of unified authority management according to an embodiment of the present application;

[0019] Figure 4 This is an example diagram of a first relationship representation form of an embodiment of the present application;

[0020] Figure 5 This is a sixth information reporting schematic diagram of an embodiment of the present application;

[0021] Figure 6 This is an example diagram of an interface coding type according to an embodiment of the present application;

[0022] Figure 7 A schematic diagram of a second relationship establishment process according to an embodiment of the present application;

[0023] Figure 8 A flowchart of a cluster authority management method according to an embodiment of the present application;

[0024] Fig. 9A schematic flow chart of a method for determining fourth information based on first information and a first relationship according to an embodiment of the present application;

[0025] Fig.10 This is an example diagram of a second user interface according to an embodiment of the present application;

[0026] Fig.11 This is a schematic diagram of the structure of a cluster authority management device according to an embodiment of the present application;

[0027] Fig.12 This is a schematic diagram of the first node structure of an embodiment of the present application. DETAILED DESCRIPTION

[0028] In the field of big data, with the dual increase of business and massive data of enterprises, enterprises will successively build multiple resource pools, and deploy multiple clusters in each resource pool to meet the usage needs of big data components of different tenants and different businesses. Considering security issues, enterprises need to control and isolate the usage rights of big data components of different tenants or different users. However, due to the different time of cluster construction and the complexity of personnel managing and operating the clusters at the same time, there are problems of operation and maintenance difficulties and inability to maintain unified maintenance in the control of permissions of big data components. To address this problem, independent permission management is generally performed for each cluster, and independent permission data views are seen, which cannot achieve unified management and visualization, which brings inconvenience to the actual operation and maintenance and usage process.

[0029] Among the related technologies, Apache Sentry and Apache Ranger provide big data component permission management functions, which can achieve basic permission control and viewing for a single cluster. However, due to the limitations of the framework, these two frameworks themselves cannot provide unified management and unified view of big data components in cross-domain multi-cluster scenarios. That is, the current framework can only manage a single cluster and can only visualize permission data for a single cluster, but cannot achieve cross-domain cluster management and cross-domain multi-cluster visualization.

[0030] Based on this, in various embodiments of the present application, a first node receives a first request, which is triggered in a first user interface of the first node, and is used to request management and / or viewing of permissions for one or more cross-domain clusters; by calling the setting component of each cluster corresponding to the first request, the setting operation corresponding to the first request is performed on each cluster corresponding to the first request. The above scheme can manage and / or view one or more cross-domain clusters by calling the setting components of one or more cross-domain clusters, so that users can achieve unified management of cross-domain multi-clusters in the first user interface, greatly reducing the difficulty of cluster management and operation and maintenance, reducing the cost of manual operation and maintenance, and improving cluster management efficiency.

[0031] The present application is further described in detail below in conjunction with the accompanying drawings and embodiments.

[0032] The embodiment of the present application provides a cluster authority management method, which is applied to a first node. The first node can establish a connection with the authority management node (second node) on each cluster in each domain, and manage the authority of each cluster across the domain by interacting with the authority management node on each cluster. The first node can be understood as a unified management node, such as Figure 1 As shown, the method includes:

[0033] Step 101: Receive a first request.

[0034] The first request is triggered in the first user interface of the first node, and is used to request management and / or viewing of permissions for one or more cross-domain clusters.

[0035] Here, receiving the first request may be that the first node receives the first request through a unified permission management application program interface (API); the first request is used to request management or viewing of permissions for one or more cross-domain clusters, or to request management and viewing of permissions for one or more cross-domain clusters, for example, the first request is used to request deletion of permissions for one or more cross-domain clusters and to view the permissions of the one or more cross-domain clusters after deletion; the first request includes at least one or more cross-domain cluster identifiers or resource pool identifiers, and the cluster permission operation type corresponding to the first request; when the first request includes the identifier of the resource pool, the first request is used to request management and / or viewing of permissions for all clusters under the resource pool corresponding to the identifier of the resource pool. Managing permissions for clusters includes creating or adding permissions, deleting permissions, and modifying permissions.

[0036] Step 102: Perform a setting operation corresponding to the first request on each cluster corresponding to the first request by calling a setting component of each cluster corresponding to the first request.

[0037] Here, by calling the setting component of each cluster in the one or more cross-domain clusters corresponding to the first request, the permissions of each cluster in the one or more cross-domain clusters corresponding to the first request are managed and / or viewed; the cluster setting component is used to manage and store the permissions of the cluster, and provide a representational state transfer (REST, RepresentationalState Transfer) API for external devices to call or modify the permissions of the cluster. The setting operation corresponding to the first request is to manage and / or view the permissions of the cluster.

[0038] It should be noted that before receiving the first request, the permissions of each cluster can be managed in advance, that is, the permissions in each cluster can be centralized and managed in a unified manner; for example, the Apache Ranger permission management framework is used to manage the permissions of each cluster of the Hadoop Distributed File System (HDFS), that is, each cluster has a second node with the ranger admin component of Apache Ranger deployed, and the second node is used to manage and store the permissions, user information and other information of the cluster where the second node is located, and provide a REST API to the outside world so that external devices can obtain or modify the permissions of the cluster; the ranger plugin component in Apache Ranger monitors each namespace (NS) in the cluster and dynamically pulls the permissions stored in the ranger admin component in real time. Considering that there are compatibility issues between the big data component and the Apache Ranger framework, and different versions of the permission management framework cannot be fully compatible, different clusters may also use different versions of the permission management framework. Therefore, different versions of the ranger admin component are deployed on clusters using different versions of the permission management framework to manage the big data component; for example, Figure 2 As shown, different clusters can use different versions of the permission management framework and deploy different versions of the ranger admin component (such as Figure 2 The first node can interact with the ranger admin components of each cluster to manage the permission-related information of each cluster, such as Figure 3 As shown, the first node may include a management module, and the management module provides a unified rights management API to implement unified rights management.

[0039] In this embodiment, the first node can call the cross-domain multi-cluster setting component to manage and / or view the permissions of the cross-domain multi-cluster, thereby realizing unified management of cluster permissions in the cross-domain multi-cluster scenario; the first user interface can provide a management and / or viewing interface for the permissions of the cross-domain multi-cluster, that is, the first user interface can provide a unified view of cluster permissions in the cross-domain multi-cluster scenario, thereby realizing unified viewing and management of one or more cross-domain clusters on a unified view, improving the flexibility and operability of operation and maintenance, reducing the cost and service of operation and maintenance, and improving the efficiency of permission management.

[0040] In order to manage and / or view cluster permissions through the setting component, in one embodiment, calling the setting component of each cluster corresponding to the first request to perform the setting operation corresponding to the first request on each cluster corresponding to the first request includes:

[0041] Acquire first information and second information from the first request, the first information representing identifiers of the one or more cross-domain clusters or identifiers of resource pools where the clusters are located, and the second information indicating permission operation types for the one or more cross-domain clusters;

[0042] Determine third information based on the first information and the second information, where the third information represents relevant information and / or relevant parameters of a first interface corresponding to the first request in a setting component of the one or more cross-domain clusters;

[0043] Based on the third information, a first interface of a setting component of the one or more cross-domain clusters is called to perform a setting operation corresponding to the first request on the one or more cross-domain clusters.

[0044] Here, the first request includes at least the first information and the second information; when the first request is received, the first information and the second information are obtained from the first request; when the first information and the second information are obtained, the third information is determined based on the first information and the second information, so that the first interface of the setting component of one or more cross-domain clusters can be found and called based on the third information.

[0045] In the case where the first request is used to request to view the permissions of one or more cross-domain clusters, the third information represents the relevant information of the first interface corresponding to the first request in the setting components of one or more cross-domain clusters, or the relevant information and related parameters of the first interface corresponding to the first request in the setting components of one or more cross-domain clusters. In the case where the first request is used to request to manage the permissions of one or more cross-domain clusters, the third information represents the relevant information and related parameters of the first interface corresponding to the first request in the setting components of one or more cross-domain clusters.

[0046] It should be noted that the cluster identifier uniquely indicates the cluster, which can be the name or number of the cluster; similarly, the resource pool identifier uniquely indicates the resource pool, which can be the name or number of the resource pool. The permission operation of the cluster can be for different objects, and the objects for permission operations can include services, policies and users. The permission operation types of clusters for different objects can include viewing, creating, modifying and deleting; for example, viewing services, viewing policies and viewing users. Services can refer to services and / or resources that the cluster can provide. Policies can include reading, writing and access. Users can be reflected as user names, user numbers and user identities. Permissions can also be understood as permission policies or permission information, indicating that a user is allowed or prohibited to read, write or access rights to a service. The interface on the setting component of the cluster can be understood as the native interface of the ranger admin deployed on the cluster, that is, the interface called when performing permission management on a single cluster, which corresponds to the permission operation type of the cluster. One or more interfaces can exist on a setting component; for example, the permission operation type of the cluster is viewing services, and the corresponding interface on the setting component is the interface for viewing services.

[0047] In order to accurately locate the first interface of the setting component of one or more cross-domain clusters corresponding to the first request, in one embodiment, determining the third information based on the first information and the second information includes:

[0048] Determine fourth information based on the first information, the fourth information including deployment nodes, access ports, and version numbers of setting components of the one or more cross-domain clusters;

[0049] The third information is determined based on the second information and the fourth information.

[0050] Here, in the case where the first information represents the identification of one or more cross-domain clusters, the one or more cross-domain clusters corresponding to the first request are determined based on the first information, thereby determining the deployment nodes, access ports and version numbers of the one or more cross-domain clusters, that is, determining the fourth information. The third information is determined based on the second information and the fourth information; specifically, the third information is determined based on the second information and the version number of the setting component of one or more cross-domain clusters. The first node can obtain and store information such as deployment nodes, access ports and version numbers from the setting components of each cluster, or obtain and store information such as deployment nodes, access ports and version numbers by receiving information reported by the setting components of each cluster.

[0051] In order to accurately determine the first interface corresponding to the first request in the setting components of one or more cross-domain clusters, in one embodiment, determining the third information based on the second information and the fourth information includes:

[0052] Based on the second information and the version numbers of the one or more cross-domain cluster setting components, fifth information is determined, where the fifth information represents relevant information of the first interface corresponding to the first request in the one or more cross-domain cluster setting components.

[0053] Here, the relevant information of the interface of the setting component of the cluster corresponds to the permission operation type and the version number of the setting component, so the relevant information of the first interface of the setting component of the one or more cross-domain clusters can be determined based on the second information and the version number of the setting component of the one or more cross-domain clusters. The first interface of the setting component of the one or more cross-domain clusters can represent the interface corresponding to the first request in the setting component of the one or more cross-domain clusters.

[0054] After determining the fifth information, if the setting operation corresponding to the first request is to view, the first interface of the setting component of one or more cross-domain clusters can be directly called based on the fifth information, and the relevant permission information can be obtained from the second node of one or more cross-domain clusters, so that the permission information can be displayed on the page for the administrator to view, and the second node is the node where the setting component of the cluster is located. In the case where the setting operation corresponding to the first request is to delete, the first interface of the setting component of one or more cross-domain clusters can also be directly called based on the fifth information, and the relevant permission information can be deleted in the second node of one or more cross-domain clusters. The permission information after deletion can also be obtained from the second node of one or more cross-domain clusters, so that the permission information after deletion is displayed on the page for the administrator to view. In the case where the setting operation corresponding to the first request is to create, the permission information entered by the administrator can be obtained first, and then the first interface of the setting component of one or more cross-domain clusters can be called based on the fifth information, and the relevant permission information can be created and stored in the second node of one or more cross-domain clusters. In the case where the setting operation corresponding to the first request is to modify, the first interface can be called directly, or the information entered by the administrator can be obtained first, and then the first interface of the setting component of one or more cross-domain clusters can be called to modify the relevant permission information in the second node of one or more cross-domain clusters.

[0055] In order to conveniently and accurately call the first interface, in one embodiment, the relevant information of the first interface includes the following items:

[0056] The calling path of the first interface;

[0057] The calling method of the first interface;

[0058] Manage and / or view the parameter list corresponding to the operation;

[0059] Manage and / or view a list of parameter types corresponding to an operation.

[0060] Here, in the case where the setting operation corresponding to the first request is to view or delete, the relevant information of the first interface may include the calling path and calling method of the first interface, that is, directly obtaining or deleting all permission information for the setting component management of one or more cross-domain clusters; in this case, the relevant information of the first interface may also include the parameter list and parameter type list corresponding to the management and / or viewing operation, that is, based on the parameter list and parameter type list, obtaining or deleting the permission information for the setting component management of one or more cross-domain clusters. In the case where the setting operation corresponding to the first request is to create or modify, the relevant information of the first interface may include the calling path and calling method of the first interface, as well as the parameter list and parameter type list corresponding to the management and / or viewing operation. The calling path of the first interface is used to call the first interface based on the calling path under the setting components of one or more cross-domain clusters; the calling methods of the first interface include GET (view), POST (create or modify), PUT (modify), and DELETE (delete); manage and / or view the parameter list and parameter type list corresponding to the operation, which are used to render the second user interface. The parameter type list may include one or more of the parameter types such as string (String), integer (int), long integer (long), single-precision floating point type (float), double-precision floating point type (double), file type (file), date type (date), and Boolean (boolean).

[0061] In order to dynamically generate a visualization page and obtain administrator input parameters, in one embodiment, a second user interface is rendered based on the first request and the fifth information;

[0062] The information input through the second user interface is obtained to obtain relevant parameters of the first interface corresponding to the first request in the setting components of the one or more cross-domain clusters.

[0063] Here, when the fifth information is determined and the setting operation corresponding to the first request is creation or modification, based on the setting operation (creation or modification) corresponding to the first request, the user interface to be displayed (creation interface or modification interface) is determined, and based on the parameter list and parameter type list corresponding to the management and / or viewing operations included in the fifth information, the fill-in fields are rendered to generate a second user interface; the information input on the second user interface can be obtained through a second request, and the second request can be triggered on the second user interface, thereby obtaining the relevant parameters of the first interface of the setting component of one or more cross-domain clusters, that is, determining the third information; based on the third information, the first interface of the setting component of one or more cross-domain clusters is called, and the setting operation (creation or modification) corresponding to the first request is performed on one or more cross-domain clusters.

[0064] It should be noted that, when the setting operation corresponding to the first request is viewing or deleting, the first interface of one or more cross-domain cluster setting components can be directly called to obtain relevant permission information and generate a third user interface; or the page can be based on the parameter list and parameter type list corresponding to the management and / or viewing operations included in the fifth information, call the first interface of one or more cross-domain cluster setting components, obtain the data corresponding to the parameter list, and generate a third user interface.

[0065] In this embodiment, a visualization interface can be dynamically generated based on the first request and the fifth information to achieve a unified view of dynamic visualization; the cross-domain multi-cluster unified authority management visualization method based on the dynamic visualization mechanism can improve the flexibility and operability of cluster authority operation and maintenance, and reduce operation and maintenance costs and complexity.

[0066] In order to determine the fourth information and implement unified authority management across multiple domains and clusters, in one embodiment, determining the fourth information based on the first information includes:

[0067] The fourth information is determined based on the first information and a first relationship, wherein the first relationship includes:

[0068] a correspondence between the cluster and the second node, the access port, and the version number, the second node being used to deploy the setting component; and / or

[0069] The correspondence between resource pools and clusters.

[0070] Here, the first relationship may include a correspondence between the cluster and the second node, the access port, and the version number, specifically, may include a correspondence between the cluster identifier and the second node, the access port, and the version number, the cluster identifier may be the name of the cluster; considering that unified authority management may also be performed on clusters under the resource pool, the first information may represent the identifier of the resource pool, and the first relationship may also include a correspondence between the resource pool and the cluster. The first relationship may be stored in a storage module of the first node.

[0071] In the case where the first information represents the identifier of one or more cross-domain clusters, the second node, access port and version number corresponding to the first information can be directly found in the first relationship to determine the fourth information. In the case where the first information represents the identifier of the resource pool, based on the first information and the correspondence between the resource pool and the cluster in the first relationship, all clusters under the resource pool corresponding to the first information are found, and then based on all clusters under the resource pool corresponding to the found first information, and the correspondence between the cluster and the second node, access port and version number in the first relationship, the second nodes, access ports and version numbers corresponding to all clusters under the resource pool corresponding to the first information are found to determine the fourth information.

[0072] For example, the first relationship can be stored in the database in the form of a data table, and the data table may include: a first data table, a second data table, and a third data table. For example, in the first data table shown in Table 1, each record corresponds to a primary key, and the primary key is used to uniquely identify each record in the table, that is, a primary key of the first data table corresponds to the deployment address of the second node of a cluster, the access port and version number of the setting component of the second node; the fields in the first data table include the primary key, the second node, the access port and the version number; for example, the primary key corresponding to the first record in Table 1 is A_1, and the first record includes the deployment address of the second node 10.172.162.19, and the access port 6080 of the setting component on the second node. Version number 0.5.3. The first data table can be understood as a ranger deployment information table, which can be obtained by storing the sixth information reported by the second nodes of different clusters.

[0073] Table 1 First data table

[0074]

[0075]

[0076] In the second data table shown in Table 2, each record also corresponds to a primary key, which is used to uniquely identify each record in the table, that is, a primary key in the second data table corresponds to a corresponding relationship between a resource pool and a cluster; the fields in the second data table include the primary key, the resource pool name, and the cluster name; for example, the primary key corresponding to the first record in Table 2 is B_1, and the first record includes the corresponding relationship between the Suzhou resource pool and the Suzhou hadoop cluster; the second data table can be understood as a virtual hierarchical table, which is used to maintain the hierarchical relationship between the resource pool and the cluster, to identify the information of each cluster, and to indicate the resource pool information where each cluster is located.

[0077] Table 2 Second data table

[0078] Primary Key Resource pool name Cluster name B_1 Suzhou Resource Pool Suzhou Hadoop Cluster B_2 Suzhou Resource Pool Suzhou Kafka Cluster B_3 Wuxi Resource Pool Wuxi HBase Cluster B_4 Changzhou Resource Pool Changzhou Kafka Cluster

[0079] In the third data table shown in Table 3, each record also corresponds to a primary key, which is used to uniquely identify each record in the table, that is, a primary key of the third data table corresponds to a correspondence between a primary key of the first data table and a primary key of the second data table; the fields in the third data table include the primary key, the primary key of the second data table, and the primary key of the first data table; for example, the primary key corresponding to the first record in Table 3 is C_1, and the first record includes the correspondence between the primary key A_1 of the first data table and the primary key B_1 of the second data table. The third data table can be understood as a ranger and hierarchical association table, which is used to associate the first data table with the second data table, indicating the ranger authority management address corresponding to each cluster.

[0080] Table 3 The third data table

[0081]

[0082]

[0083] Based on the first information and the first relationship represented in the form of the above three data tables, the process of determining the fourth information is as follows: Figure 4 As shown; specifically, based on the first information, the primary keys of one or more second data tables corresponding to the first information are determined from the second data table; for example, in the case where the first information represents the names of one or more cross-domain clusters, the primary keys of one or more records corresponding to the names of the one or more cross-domain clusters are determined from the second data table; in the case where the first information represents the name of a resource pool, the names of one or more cross-domain clusters corresponding to the name of the resource pool are determined from the second data table, and then based on the names of the one or more cross-domain clusters, the primary keys of one or more records corresponding to the names of the one or more cross-domain clusters are determined from the second data table, and then based on the primary keys of one or more second data tables corresponding to the first information, the primary keys of one or more first data tables corresponding to the primary keys of the one or more second data tables are determined from the third data table, and finally, based on the primary keys of one or more first data tables, one or more records corresponding to the primary keys of the one or more first data tables are determined from the first data table, that is, the fourth information is determined.

[0084] In order to improve the scalability and fault tolerance of unified management of permissions of big data components across multiple domains and clusters, in one embodiment, the method further includes:

[0085] receiving sixth information reported by one or more second nodes, where the sixth information includes an access port and a version number of a setting component deployed by the second node;

[0086] The first relationship is established based on the received sixth information, or the first relationship is established based on the received sixth information and the resource pool where the cluster is located.

[0087] Here, receiving the sixth information reported by one or more second nodes may be receiving the sixth information reported by a reporting module in one or more second nodes; for example, Figure 5As shown, the first node receives the sixth information reported by the reporting module of the second node of cluster 1, the sixth information reported by the reporting module of the second node of cluster 2, and the sixth information reported by the reporting module of the second node of cluster 3; based on the received sixth information reported by the second nodes of each cluster, a corresponding relationship between each cluster and the sixth information is established, that is, a first relationship is established; or, based on the received sixth information of each cluster and the resource pool where each cluster is located, a corresponding relationship between each cluster and the sixth information, as well as a corresponding relationship between each cluster and the resource pool is established, thereby establishing a first relationship; and the established first relationship is stored in the storage module.

[0088] In order to perform unified authority management based on the authority management framework of each cluster, so as to improve the scalability and fault tolerance of unified authority management of big data components across multiple domains and clusters, and reduce operation and maintenance costs and difficulties, in one embodiment, the fifth information is determined based on the second information and the version number of the setting component of the one or more cross-domain clusters, including:

[0089] Based on the second information, the version numbers of the setting components of the one or more cross-domain clusters, and the second relationship, fifth information is determined; the second relationship includes:

[0090] The corresponding relationship between the interface related information and the version number and the interface of the setting component; or

[0091] The correspondence between the version number and the interface of the setting component, and the correspondence between the interface of the setting component and the related information of the interface.

[0092] Here, in the case where the second relationship includes the corresponding relationship between the relevant information of the interface and the version number and the interface of the setting component, the fifth information can be directly found from the second relationship based on the version number included in the second information and the fourth information. In the case where the second relationship includes the corresponding relationship between the version number and the interface of the setting component, and the corresponding relationship between the interface of the setting component and the relevant information of the interface, the first interface corresponding to the permission operation type indicated by the second information in the setting component corresponding to the version number can be determined based on the version number of the setting component of one or more cross-domain clusters and the corresponding relationship between the version number and the interface of the setting component in the second relationship. This process can be understood as determining the first interface corresponding to the second information from the interface of the setting component under the permission management framework version corresponding to the version number of the setting component of the cluster; based on the determined first interface, and the corresponding relationship between the interface of the setting component in the second relationship and the relevant information of the interface, the relevant information of the first interface is determined, that is, the fifth information is determined. The interface of the setting component can be represented by an interface code or an interface name. The corresponding relationship between the version number and the interface of the setting component can be understood as the hierarchical relationship between the version number and the interface of the setting component.

[0093] For example, among one or more cross-domain clusters, there is a cluster whose setting component version is v1, and the first node indicates in the second information obtained from the first request that the permission operation type of the cluster is to create a policy; based on the second information and the version number of the setting component of the cluster, and the second relationship, the calling path of the first interface included in the fifth information is determined to be " / ranger / api / v1 / createpolicy", the calling method of the first interface is "post", the parameter list corresponding to the creation operation includes user ID (userId), service ID (serviceId), policy ID (policyId) and policy name (policyName), and the parameter type list corresponding to the creation operation includes string (String), string, string, and string.

[0094] It should be noted that, when the interface of the setting component is represented by an interface code, one interface code indicates one permission operation type, and the interface codes of the same permission operation type corresponding to different version numbers may be the same or different; when the interface codes of the same permission operation type corresponding to different version numbers are the same, the second relationship may include: the corresponding relationship between the relevant information of the interface and the version number and the interface code. Figure 6 As shown, the interface of the setting component corresponding to a version number targets objects including services, policies and users, and the permission operation types corresponding to each object include creation, modification, deletion and viewing, that is, the interface of the setting component corresponding to each object includes creation interface, modification interface, deletion interface and viewing interface, and an interface code is generated for each permission operation type. For example, the interface code of the policy creation interface for the policy is create_policy.

[0095] When different version numbers correspond to different interface codes of the same permission operation type, that is, each interface code can uniquely correspond to a version number and a permission operation type, the second relationship may include: a corresponding relationship between the interface code and related information of the interface.

[0096] In order to collect relevant information of the native interfaces of the setting components of each version, and to call the underlying native interfaces to implement unified management of cluster permissions, thereby reducing operation and maintenance costs and difficulties, in one embodiment, the method further includes:

[0097] Receive ninth information reported by the second nodes of each version, where the ninth information includes relevant information of an interface of a setting component deployed by the second nodes of each version, or a correspondence between an interface of a setting component deployed by the second nodes of each version and relevant information of the interface;

[0098] The second relationship is established based on the received ninth information.

[0099] Here, receiving the ninth information reported by the second node of each version may be receiving the ninth information reported by the tracking module of the second node of each cluster; the tracking module is used to intercept interface call requests and obtain interface-related information of the setting component, and the tracking module is deployed in the second node of each version.

[0100] In the case where the ninth information includes the relevant information of each interface of the setting component deployed by the second node of each version, the version number can be determined based on the calling path of the interface in the relevant information of the interface, and the permission operation type can be determined based on the calling method of the interface in the relevant information of the interface, so as to establish the second relationship based on the determined version number and permission operation type and the received ninth information. In the case where the ninth information includes the corresponding relationship between the interface of the setting component deployed by the second node of each version and the relevant information of the interface, the second relationship can be established directly based on the received ninth information.

[0101] It should be noted that, before receiving the ninth information reported by the second node of each version, the native interfaces of the setting components of each version may be sorted and stored respectively; for example, the native interfaces of the setting components of each version may be packaged and stored.

[0102] In this embodiment, the process of receiving the ninth information reported by the second node of each version and establishing the second relationship based on the received ninth information can be understood as the collection process or collection mechanism of the native interface of the setting component of each version. Based on the second relationship, the differentiated call of the interface of the setting component of the cluster using different versions of the permission management framework can be realized. The collection process of the native interface of the setting component of different versions can be triggered simultaneously, or it can be triggered separately for each version.

[0103] The present application is described in further detail below in conjunction with application examples.

[0104] It should be noted that before cluster permission management is performed, the first relationship and the second relationship need to be established in advance. Taking triggering an interface call in the setting component of version 0.5.3 as an example, the specific method of establishing the second relationship is as follows: Figure 7 As shown, Figure 7 The tracking module is deployed on the second node in the cluster using the ranger0.5.3 version of the permission management framework, and the management module and storage module are deployed on the first node. The specific steps for establishing the second relationship include:

[0105] Step 1: The administrator triggers the interface call in the permission management interface corresponding to each version.

[0106] Here, the administrator triggers interface calls on the permission management interface corresponding to each version, including triggering interface calls for different objects (such as services, policies, and users); the permission management interface corresponding to each version is the original ranger web page, that is, the interface for permission management of a single cluster; for example, click "Create Policy" on the permission management interface.

[0107] Step 2: The tracking module of the second node intercepts the interface call request.

[0108] Here, the administrator triggers an interface call on the authority management interface, generates an interface call request and sends it to the setting component of the second node. The tracking module deployed on the second node intercepts the interface call request sent to the setting component of the second node, and parses the interface call request to obtain the relevant information of the interface corresponding to the interface call request; the relevant information of the interface includes the calling path and calling method of the interface, and / or the parameter list and parameter type list corresponding to the operation executed by the interface. The tracking module is an interception filter implemented by modifying the ranger source code, which is used to intercept the interface call request sent to the setting component of the second node and obtain the relevant information of the interface.

[0109] Step 3: The tracking module of the second node sends an interface trigger message to the management module of the first node.

[0110] Here, the tracking module of the second node sends an interface trigger message to the management module of the first node to obtain the interface code or transmit the relevant information of the interface to the first node; that is, the interface trigger message may include the relevant information of the interface parsed by the tracking module of the second node (the ninth information), or at least include the permission operation or permission operation type corresponding to the interface call request.

[0111] When the interface trigger message includes relevant information of the interface parsed by the tracking module of the second node (the ninth information), execute step 5; when the interface trigger message includes at least the permission operation or permission operation type corresponding to the interface call request, execute step 4.

[0112] Step 4: The management module of the first node returns the interface code corresponding to the interface call request.

[0113] Here, the management module of the first node determines the interface code corresponding to the interface trigger message based on the received interface trigger message, that is, the interface code corresponding to the interface call request, and returns the interface code corresponding to the interface call request to the tracking module of the second node. For example, the interface call request is used to call the create policy interface, and the interface code corresponding to the interface call request determined by the management module of the first node is create_policy. The tracking module of the second node matches the received interface code with the relevant information of the interface parsed from the interface call request to obtain the corresponding relationship between the interface code and the relevant information of the interface; and sends the corresponding relationship between the interface code and the relevant information of the interface to the storage module of the first node (the ninth information).

[0114] Step 5: The first node receives the ninth information.

[0115] Here, in the case where the ninth information is relevant information of the interface, the first node determines the version number and the interface corresponding to the interface call request based on the relevant information of the interface, establishes a second relationship based on the relevant information of the interface, the version number and the interface corresponding to the interface call request, and stores the second relationship in the storage module; in the case where the ninth information is the correspondence between the interface code and the relevant information of the interface, the ninth information is directly stored in the storage module.

[0116] The first node can be based on Figure 7 In the step of establishing a second relationship of an interface, a second relationship of each interface of each version is established.

[0117] like Figure 8 As shown, taking the creation of policies under resource pool A and resource pool B as an example, the cluster permission management method includes the following steps:

[0118] Step 801: The administrator clicks “Create Policy” in the first user interface.

[0119] Here, the administrator can select resource pool A and resource pool B in the first user interface, and then click the "Create Policy" button to generate a first request; the first user interface is a unified permission management interface for one or more cross-domain clusters or resource pools; the first request is used to request management and / or viewing of permissions for all clusters under resource pool A and resource pool B; the first request includes at least first information and second information, the first information represents the identifiers of resource pool A and resource pool B, and the second information indicates that the permission operation type for all clusters under resource pool A and resource pool B is to create a policy (that is, the permission operation is for the policy, and the operation performed is to create).

[0120] Step 802: The first node receives a first request, and obtains first information and second information from the first request.

[0121] Here, the specific implementation process of step 802 please refer to the relevant description above, which will not be repeated here.

[0122] Step 803: The first node determines fourth information based on the first information and the first relationship.

[0123] Here, the first relationship can be stored in the database in the form of a data table, such as the first data table, the second data table, and the third data table. The first node can sequentially query the data tables in the first relationship based on the first information to determine the fourth information. For example, Fig. 9 As shown, the management module of the first node obtains the first information, queries the second data table based on the first information, and obtains the primary key of the second data table corresponding to the records of all clusters under resource pool A and resource pool B. The clusters under resource pool A include cluster 1, cluster 2 and cluster 3, and the clusters under resource pool B include cluster 4 and cluster 5; queries the third data table based on the primary key of the second data table to obtain the primary key of the first data table corresponding to the primary key of the second data table; queries the first data table based on the primary key of the first data table to obtain fourth information, and the fourth information includes the deployment node, access port and version number of the setting component of all clusters under resource pool A and resource pool B.

[0124] Step 804: The first node determines fifth information based on the second information and version numbers of the setting components of one or more cross-domain clusters, and the second relationship.

[0125] Here, for the specific implementation process of step 804, please refer to the relevant description above, which will not be repeated here.

[0126] Step 805: The first node renders a second user interface based on the first request and the fifth information.

[0127] Here, the first node renders the second user interface based on the first request and the fifth information. Specifically, the first node determines the specific function type of the second user interface (such as creating a policy function) based on the first request, and renders the second user interface based on the parameter list and parameter type list corresponding to the management and / or viewing operations in the fifth information; for example, the parameter list includes a service name (serviceName), a user name (userName), a policy name (policyName), and whether it is authorized (isPublish), and the parameter type list includes a string (String), a string, a string, a string or an integer (int), and a Boolean (boolean) respectively. The second user interface is as follows: Fig.10 shown.

[0128] Step 806: The administrator enters information in the second user interface.

[0129] Here, the administrator can enter relevant information for creating a policy in the second user interface, create the user's permission to read, write or access the policy for the service (including permission or prohibition), and click the "Save" button.

[0130] Step 807: The first node obtains information input through the second user interface, and obtains relevant parameters of the first interface corresponding to the first request in the setting components of one or more cross-domain clusters.

[0131] Here, when the administrator clicks the "Save" button, the information entered by the administrator can be transmitted to the first node, so that the first node obtains the relevant parameters of the first interface corresponding to the first request in the setting components of one or more cross-domain clusters, and determines the third information, so that it can call the first interface of the setting components of one or more cross-domain clusters based on the third information to complete the permission management operation corresponding to the first request.

[0132] Step 808: The first node calls the first interface of the setting component of one or more cross-domain clusters based on the fourth information and the third information, and performs the setting operation corresponding to the first request on the one or more cross-domain clusters.

[0133] Here, the first node can obtain the access path of the first interface of the setting component of one or more cross-domain clusters based on the fourth information and the third information, generate a create policy request based on the information input by the administrator in the second user interface, call the first interface under the access path of the first interface of the setting component of each cluster in the one or more cross-domain clusters, initiate the same create policy request for the setting component of each cluster, and complete the unified creation or addition of permission policies. Specifically, the "Save" button can be linked to "http: / / rangerIp:rangerPort / rangerApi" to call the first interface of the setting component of one or more cross-domain clusters; wherein rangerIp represents the address of the second node, rangerPort represents the access port of the setting component of the second node, and rangerApi represents the call path of the first interface (such as / ranger / api / v1 / createpolicy). For example, the first node can form an access path to the first interface of the setting component of all clusters under resource pool A and resource pool B based on the fourth information and the third information, and when rendering the second user interface based on the first request and the fifth information, link the "Save" button to the access path to the first interface of the setting component of all clusters under resource pool A and resource pool B; the administrator enters information on the second user interface and clicks the "Save" button; the first node generates a create policy request based on the information entered by the administrator, calls the first interface under the access path of the first interface of the setting component of each cluster under resource pool A and resource pool B, initiates the same create policy request for the setting component of each cluster, and completes the unified creation or addition of permission policies.

[0134] In order to implement the method on the first node side of the embodiment of the present application, the embodiment of the present application also provides a cluster authority management device, which is set on the first node, such as Fig.11 As shown, the device comprises:

[0135] A first receiving unit 1101 is configured to receive a first request, where the first request is triggered in a first user interface of the first node and is configured to request management and / or viewing of permissions of one or more cross-domain clusters;

[0136] The calling unit 1102 is configured to perform a setting operation corresponding to the first request on each cluster corresponding to the first request by calling a setting component of each cluster corresponding to the first request.

[0137] In one embodiment, the calling unit 1102 is specifically configured to obtain first information and second information from the first request, wherein the first information represents an identifier of the one or more cross-domain clusters or an identifier of a resource pool in which the clusters are located, and the second information indicates a permission operation type for the one or more cross-domain clusters;

[0138] Determine third information based on the first information and the second information, where the third information represents relevant information and / or relevant parameters of a first interface corresponding to the first request in a setting component of the one or more cross-domain clusters;

[0139] Based on the third information, a first interface of a setting component of the one or more cross-domain clusters is called to perform a setting operation corresponding to the first request on the one or more cross-domain clusters.

[0140] In one embodiment, the calling unit 1102 is specifically used to determine fourth information based on the first information, and the fourth information includes the deployment node, access port and version number of the setting component of the one or more cross-domain clusters; and determine the third information based on the second information and the fourth information.

[0141] In one embodiment, the calling unit 1102 is specifically used to determine fifth information based on the second information and the version number of the setting component of the one or more cross-domain clusters, and the fifth information represents the relevant information of the first interface corresponding to the first request in the setting component of the one or more cross-domain clusters.

[0142] In one embodiment, the device further comprises:

[0143] a rendering unit, configured to render a second user interface based on the first request and the fifth information;

[0144] An acquisition unit is used to acquire information input through the second user interface, and obtain relevant parameters of the first interface corresponding to the first request in the setting components of the one or more cross-domain clusters.

[0145] In one embodiment, the calling unit 1102 is further configured to determine the fourth information based on the first information and a first relationship, where the first relationship includes:

[0146] The correspondence between the cluster and the second node, the access port and the version number, the second node is used to deploy the setting component; and / or the correspondence between the resource pool and the cluster.

[0147] In one embodiment, the device further comprises:

[0148] A second receiving unit, configured to receive sixth information reported by one or more second nodes, where the sixth information includes an access port and a version number of a setting component deployed by the second node;

[0149] The first establishing unit is configured to establish the first relationship based on the received sixth information, or to establish the first relationship based on the received sixth information and a resource pool where the cluster is located.

[0150] In one embodiment, the relevant information of the first interface includes the following items:

[0151] The calling path of the first interface;

[0152] The calling method of the first interface;

[0153] Manage and / or view the parameter list corresponding to the operation;

[0154] Manage and / or view a list of parameter types corresponding to an operation.

[0155] In one embodiment, the calling unit 1102 is specifically configured to determine the fifth information based on the second information and the version number of the setting component of the one or more cross-domain clusters, and the second relationship; the second relationship includes:

[0156] The corresponding relationship between the interface related information and the version number and the interface of the setting component; or

[0157] The correspondence between the version number and the interface of the setting component, and the correspondence between the interface of the setting component and the related information of the interface.

[0158] In one embodiment, the device further comprises:

[0159] A third receiving unit is used to receive ninth information reported by the second nodes of each version, where the ninth information includes relevant information of the interface of the setting component deployed by the second nodes of each version, or a correspondence between the interface of the setting component deployed by the second nodes of each version and the relevant information of the interface;

[0160] The second establishing unit is used to establish the second relationship based on the received ninth information.

[0161] In actual applications, the first receiving unit 1101, the second receiving unit and the third receiving unit can be implemented by a processor in the cluster authority management device in combination with a communication interface; the calling unit 1102, the rendering unit, the acquisition unit, the first establishing unit and the second establishing unit can be implemented by a processor in the cluster authority management device.

[0162] It should be noted that: the above embodiment provides a cluster authority management device, and when performing cluster authority management, only the division of the above program modules is used as an example. In actual applications, the above processing can be assigned to different program modules as needed, that is, the internal structure of the device is divided into different program modules to complete all or part of the processing described above. In addition, the cluster authority management device and the cluster authority management method embodiment provided in the above embodiment belong to the same concept. The specific implementation process is detailed in the method embodiment, which will not be repeated here.

[0163] Based on the hardware implementation of the above program module, and in order to implement the method of the first node side of the embodiment of the present application, the embodiment of the present application also provides a first node, such as Fig.12 As shown, the first node 1200 includes:

[0164] The communication interface 1201 can exchange information with other network nodes.

[0165] The processor 1202 is connected to the communication interface 1201 to implement information interaction with other network nodes, and is used to execute the methods provided by one or more technical solutions on the first node side when running a computer program.

[0166] The memory 1203 is used to store computer programs that can be executed on the processor 1202 .

[0167] Specifically, the communication interface 1201 is used to receive a first request, where the first request is triggered in a first user interface of the first node and is used to request management and / or viewing of permissions of one or more cross-domain clusters;

[0168] The processor 1202 is configured to perform a setting operation corresponding to the first request on each cluster corresponding to the first request by calling a setting component of each cluster corresponding to the first request.

[0169] In one embodiment, the processor 1202 is specifically configured to obtain first information and second information from the first request, wherein the first information represents an identifier of the one or more cross-domain clusters or an identifier of a resource pool in which the clusters are located, and the second information indicates a permission operation type for the one or more cross-domain clusters;

[0170] Determine third information based on the first information and the second information, where the third information represents relevant information and / or relevant parameters of a first interface corresponding to the first request in a setting component of the one or more cross-domain clusters;

[0171] Based on the third information, a first interface of a setting component of the one or more cross-domain clusters is called to perform a setting operation corresponding to the first request on the one or more cross-domain clusters.

[0172] In one embodiment, the processor 1202 is specifically used to determine fourth information based on the first information, where the fourth information includes the deployment node, access port and version number of the setting components of the one or more cross-domain clusters; and determine the third information based on the second information and the fourth information.

[0173] In one embodiment, the processor 1202 is specifically used to determine fifth information based on the second information and the version number of the setting component of the one or more cross-domain clusters, and the fifth information represents relevant information of the first interface corresponding to the first request in the setting component of the one or more cross-domain clusters.

[0174] In one embodiment, the processor 1202 is also used to render a second user interface based on the first request and the fifth information; obtain information input through the second user interface, and obtain relevant parameters of the first interface corresponding to the first request in the setting component of the one or more cross-domain clusters.

[0175] In one embodiment, the processor 1202 is specifically configured to determine the fourth information based on the first information and a first relationship, where the first relationship includes:

[0176] The correspondence between the cluster and the second node, the access port and the version number, the second node is used to deploy the setting component; and / or the correspondence between the resource pool and the cluster.

[0177] In one embodiment, the communication interface 1201 is further used to receive sixth information reported by one or more second nodes, where the sixth information includes an access port and a version number of a setting component deployed by the second node;

[0178] The processor 1202 is further configured to establish the first relationship based on the received sixth information, or to establish the first relationship based on the received sixth information and a resource pool where the cluster is located.

[0179] In one embodiment, the relevant information of the first interface includes the following items:

[0180] The calling path of the first interface;

[0181] The calling method of the first interface;

[0182] Manage and / or view the parameter list corresponding to the operation;

[0183] Manage and / or view a list of parameter types corresponding to an operation.

[0184] In one embodiment, the processor 1202 is specifically configured to determine fifth information based on the second information and the version number of the setting component of the one or more cross-domain clusters, and the second relationship; the second relationship includes:

[0185] The corresponding relationship between the interface related information and the version number and the interface of the setting component; or

[0186] The correspondence between the version number and the interface of the setting component, and the correspondence between the interface of the setting component and the related information of the interface.

[0187] In one embodiment, the communication interface 1201 is further used to receive ninth information reported by the second nodes of each version, where the ninth information includes relevant information of the interface of the setting component deployed by the second nodes of each version, or the correspondence between the interface of the setting component deployed by the second nodes of each version and the relevant information of the interface;

[0188] The processor 1202 is further configured to establish the second relationship based on the received ninth information.

[0189] It should be noted that the specific processing process of the processor 1202 and the communication interface 1201 can be understood by referring to the above method.

[0190] Of course, in actual application, the various components in the first node 1200 are coupled together through the bus system 1204. It can be understood that the bus system 1204 is used to realize the connection and communication between these components. In addition to the data bus, the bus system 1204 also includes a power bus, a control bus, and a status signal bus. However, for the sake of clarity, Fig.12 Various buses are labeled as bus system 1204.

[0191] The memory 1203 in the embodiment of the present application is used to store various types of data to support the operation of the first node 1200. Examples of such data include: any computer program used to operate on the first node 1200.

[0192] The method disclosed in the above embodiment of the present application can be applied to the processor 1202, or implemented by the processor 1202. The processor 1202 may be an integrated circuit chip with signal processing capabilities. In the implementation process, each step of the above method can be completed by the hardware integrated logic circuit or software instructions in the processor 1202. The above-mentioned processor 1202 may be a general-purpose processor, a digital signal processor (DSP, DigitalSignal Processor), or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The processor 1202 can implement or execute the various methods, steps and logic block diagrams disclosed in the embodiments of the present application. A general-purpose processor may be a microprocessor or any conventional processor, etc. In combination with the steps of the method disclosed in the embodiment of the present application, it can be directly embodied as a hardware decoding processor to execute, or it can be executed by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium, which is located in the memory 1203, and the processor 1202 reads the information in the memory 1203 and completes the steps of the above method in combination with its hardware.

[0193] In an exemplary embodiment, the first node 1200 can be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontrollers (MCUs), microprocessors, or other electronic components to execute the aforementioned method.

[0194] It can be understood that the memory (memory 1203) of the embodiment of the present application can be a volatile memory or a non-volatile memory, and can also include both a volatile memory and a non-volatile memory. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a magnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDRSDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link dynamic random access memory (SLDRAM, SyncLink Dynamic Random Access Memory), and direct RAM bus random access memory (DRRAM, Direct Rambus Random Access Memory).The memory described in the embodiments of the present application is intended to include, but is not limited to, these and any other suitable types of memory.

[0195] In an exemplary embodiment, the embodiment of the present application further provides a storage medium, namely a computer storage medium, specifically a computer-readable storage medium, for example, including a memory 1203 storing a computer program, and the computer program can be executed by the processor 1202 of the first node 1200 to complete the steps of the first node side method. The computer-readable storage medium can be a memory such as FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface storage, optical disk, or CD-ROM.

[0196] Exemplarily, an embodiment of the present application further provides a computer program product, including a computer program, which can be executed by the processor 1202 of the first node 1200 to complete the steps of any of the aforementioned methods.

[0197] It should be noted that "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence; "multiple" refers to two or more items. The term "and / or" herein is merely a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B may represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the technical solutions described in the embodiments of the present application may be arbitrarily combined without conflict. The above is only a preferred embodiment of the present application and is not intended to limit the scope of protection of the present application.

Claims

1. A cluster rights management method, characterized in that: Applied to the first node, the method comprises: receiving a first request, where the first request is triggered in a first user interface of the first node and is used to request management and / or viewing of permissions of one or more cross-domain clusters; By calling the setting component of each cluster corresponding to the first request, the setting operation corresponding to the first request is performed on each cluster corresponding to the first request.

2. The method according to claim 1, characterized in that: The step of calling the setting component of each cluster corresponding to the first request to perform the setting operation corresponding to the first request on each cluster corresponding to the first request includes: Acquire first information and second information from the first request, the first information representing identifiers of the one or more cross-domain clusters or identifiers of resource pools where the clusters are located, and the second information indicating permission operation types for the one or more cross-domain clusters; Determine third information based on the first information and the second information, where the third information represents relevant information and / or relevant parameters of a first interface corresponding to the first request in a setting component of the one or more cross-domain clusters; Based on the third information, a first interface of a setting component of the one or more cross-domain clusters is called to perform a setting operation corresponding to the first request on the one or more cross-domain clusters.

3. The method according to claim 2, characterized in that The determining the third information based on the first information and the second information includes: Determine fourth information based on the first information, the fourth information including deployment nodes, access ports, and version numbers of setting components of the one or more cross-domain clusters; The third information is determined based on the second information and the fourth information.

4. The method according to claim 3, characterized in that The determining the third information based on the second information and the fourth information includes: Based on the second information and the version numbers of the one or more cross-domain cluster setting components, fifth information is determined, where the fifth information represents relevant information of the first interface corresponding to the first request in the one or more cross-domain cluster setting components.

5. The method according to claim 4, characterized in that The method further comprises: Rendering a second user interface based on the first request and the fifth information; The information input through the second user interface is obtained to obtain relevant parameters of the first interface corresponding to the first request in the setting components of the one or more cross-domain clusters.

6. The method according to claim 3, characterized in that The determining fourth information based on the first information includes: The fourth information is determined based on the first information and a first relationship, wherein the first relationship includes: a correspondence between the cluster and the second node, the access port, and the version number, the second node being used to deploy the setting component; and / or The correspondence between resource pools and clusters.

7. The method according to claim 4, characterized in that The method further comprises: receiving sixth information reported by one or more second nodes, where the sixth information includes an access port and a version number of a setting component deployed by the second node; The first relationship is established based on the received sixth information, or the first relationship is established based on the received sixth information and the resource pool where the cluster is located.

8. The method according to any one of claims 2 to 6, characterized in that: The relevant information of the first interface includes the following items: The calling path of the first interface; The calling method of the first interface; Manage and / or view the parameter list corresponding to the operation; Manage and / or view a list of parameter types corresponding to an operation.

9. The method according to claim 4, characterized in that The determining the fifth information based on the second information and the version numbers of the setting components of the one or more cross-domain clusters includes: Based on the second information, the version numbers of the setting components of the one or more cross-domain clusters, and the second relationship, fifth information is determined; the second relationship includes: The corresponding relationship between the interface related information and the version number and the interface of the setting component; or The correspondence between the version number and the interface of the setting component, and the correspondence between the interface of the setting component and the related information of the interface.

10. The method according to claim 9, characterized in that The method further comprises: Receive ninth information reported by the second nodes of each version, where the ninth information includes relevant information of an interface of a setting component deployed by the second nodes of each version, or a correspondence between an interface of a setting component deployed by the second nodes of each version and relevant information of the interface; The second relationship is established based on the received ninth information.

11. A cluster rights management device, characterized in that: include: A first receiving unit, configured to receive a first request, where the first request is triggered in a first user interface of the first node and is configured to request management and / or viewing of permissions of one or more cross-domain clusters; The calling unit is configured to perform a setting operation corresponding to the first request on each cluster corresponding to the first request by calling a setting component of each cluster corresponding to the first request.

12. A first node, characterized in that: comprising a processor and a memory for storing a computer program capable of being executed on the processor, Wherein, when the processor is used to run the computer program, it executes the steps of the method described in any one of claims 1 to 10.

13. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.

14. A computer program product comprising a computer program, characterized in that The computer program implements the steps of the method according to any one of claims 1 to 10 when executed by a processor.

Citation Information

Cited By

  • Method and apparatus for cluster permission management, and first node, storage medium and computer program product

    WO2026144961A1