Change control method based on cloud technology, cloud management platform and cluster
By introducing change permission indication information into the cloud management platform, users can set target change permissions, and before sending change operations to the cloud infrastructure, they can determine whether the change permissions of the change operation are within the target change permissions, solve the problem of cloud infrastructure changes oversteps, achieve more refined and reliable change control, and improve the stability and security of cloud infrastructure.
Patent Information
- Application Number
- CN202410107744.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-02
- Filing Date
- 2024-01-25
- Publication Date
- 2025-05-06
AI Technical Summary
Changes in cloud infrastructure may lead to changes that exceed the boundaries and affect the stability and security of cloud infrastructure. It is difficult for existing technologies to achieve fine and reliable change control.
By introducing change permission indication information into the cloud management platform, users can set target change permissions and determine whether the change permissions of the change operation are within the target change permissions before sending the change operation to the cloud infrastructure. If they are not there, they will refuse to send it.
It effectively prevents changes from crossing boundaries, ensures that changes in the cloud infrastructure meet users' expectations, and improves the stability and security of the cloud infrastructure.
Smart Images

Figure CN119946047A_ABST
Abstract
Description
[0001] This application claims the priority of the Chinese patent application filed with the State Intellectual Property Office of China on November 2, 2023, with application number 202311451088.4 and application name “A Method for Changing Scope Management”, all contents of which are incorporated by reference in this application. Technical Field
[0002] The present application relates to the field of cloud computing technology, and in particular to a change control method, a cloud management platform and a cluster based on cloud technology. Background Art
[0003] With the popularization of cloud technology, cloud services have been applied to many fields. Accordingly, cloud infrastructure has also become an important infrastructure that affects many fields. Therefore, the stability and security of cloud infrastructure are of vital importance. The rapid development of cloud computing technology has accelerated the speed of cloud infrastructure updates and iterations. Changes to cloud infrastructure (such as component version upgrades, room expansion, configuration modifications, or patch repairs, etc.) may occur every day.
[0004] Cross-border changes may cause unexpected problems and threaten the stability and security of cloud infrastructure. Therefore, a more sophisticated and reliable change control solution is needed to manage and control changes to cloud infrastructure to prevent cross-border changes. Summary of the invention
[0005] The embodiments of the present application provide a change control method, a cloud management platform and a cluster based on cloud technology, which can effectively prevent changes from crossing boundaries.
[0006] In a first aspect, a change control method is provided, which is applied to a cloud management platform connected to a cloud infrastructure, wherein the cloud infrastructure includes at least one cloud data center, each cloud data center is provided with multiple servers, and some or all of the multiple servers are deployed with services, and the cloud management platform is used to send change operations to the cloud infrastructure, and the change operations are used to change any one or more of the cloud data center, the server, and the services; the method includes: receiving a change request sent by a user device, the change request is used to request the cloud management platform to send a change operation corresponding to the change request to the cloud infrastructure, and the change request includes authority indication information, and the authority indication information is used to indicate a target change authority of the change operation corresponding to the change request; when it is confirmed that a first change operation to be sent to the cloud infrastructure belongs to the change operation corresponding to the change request, based on the authority indication information, judging whether the change authority of the first change operation is within the target change authority; when the change authority of the first change operation is within the target change authority, sending the first change operation to the cloud infrastructure to execute the first change operation in the cloud infrastructure.
[0007] Among them, the target change permission is the change permission set by the user and in line with the user's expectations. Through this method, when a user initiates a change to the cloud infrastructure, the target change permission of this change can be set, and a change request can be sent to the cloud management platform through the user device to request the cloud management platform to send a change operation for implementing the change (i.e., the change operation corresponding to the change request) to the cloud infrastructure, wherein the change request includes indication information of the target change permission, so that the cloud management platform can obtain the indication information of the target change permission. Before sending the change operation corresponding to the change request to the cloud infrastructure, the cloud management platform can determine whether the change permission of the change operation is within the target change permission based on the permission indication information. If the change permission of the change operation is within the target change permission, the cloud management platform sends the change operation to the cloud infrastructure. In this way, it is ensured that the change permissions of the change operations sent to the cloud infrastructure are in line with the user's expectations, thereby ensuring that the changes in the cloud infrastructure meet the user's expectations and preventing the changes from crossing the boundary.
[0008] In a possible implementation, when the change permission of the first change operation is outside the target change permission, the first change operation is refused to be sent to the cloud infrastructure.
[0009] In this implementation, when the change authority of a change operation is outside the target change authority, the change operation is not sent to the cloud infrastructure, thereby preventing the change operation whose change authority is outside the target change authority from reaching the cloud infrastructure, thereby avoiding cross-border changes at the source.
[0010] In a possible implementation, the method also includes: responding to a change request, creating a session, and storing permission indication information in the session; based on the permission indication information, determining whether the change permission of the first change operation is within the target change permission, including: based on a session identifier included in the first change operation, obtaining the permission indication information from the session; based on the permission indication information, determining whether the change permission of the first change operation is within the target change permission.
[0011] In this implementation, a session can be created for a change request, and the permission indication information corresponding to the change request can be stored in the session. Whenever it is necessary to determine whether the change permission of the change operation is within the target change permission, the permission indication information corresponding to the change operation can be obtained based on the session identifier included in the change operation, so that the permission indication information can be used to determine whether the change permission of the change operation is within the target change permission. This implementation facilitates the management of permission indication information and change operations by the cloud management platform.
[0012] In a possible implementation manner, the first change operation is sent by a user equipment; the method further includes: sending a session identifier of a session to the user equipment, so that the user equipment includes the session identifier in the first change operation.
[0013] In this implementation, after the cloud management platform creates a session for the change request sent by the user device, the cloud management platform can send the session identifier of the session to the user device. Thereby, when the user device sends a change operation corresponding to the change request, the session identifier can be included in the change operation, so that the cloud management platform can confirm that the change operation belongs to the change operation corresponding to the change request based on the session identifier in the change operation, and obtain the permission indication information corresponding to the change request, and then determine whether the change operation is within the target change authority.
[0014] In a possible implementation, the method further includes: when the second change operation is acquired, generating a linkage operation of the second change operation, the second change operation including a session identifier; including the session identifier in the linkage operation of the second change operation to obtain the first change operation.
[0015] In this implementation, the cloud management platform includes the session identifier of the change operation in the linkage operation of the change operation. Therefore, before sending the linkage operation to the cloud infrastructure, the permission indication information can be obtained based on the session identifier, and based on the permission indication information, it can be determined whether the change permission of the linkage operation is within the target change permission of the permission indication information. In this way, it can be ensured that the change permission of the linkage operation sent to the cloud infrastructure also meets the user's expectations, preventing the change from crossing the boundary.
[0016] In a possible implementation, the change permission includes a change scope and / or a change object.
[0017] In this implementation, it can be ensured that the change scope of the change operation sent to the cloud infrastructure meets the user's expectations, avoiding changes to the scope beyond the user's expectations. In this implementation, it can also be ensured that the change object of the change operation sent to the cloud infrastructure meets the user's expectations, avoiding changes to the object beyond the user's expectations.
[0018] In a second aspect, a cloud management platform is provided, which is connected to a cloud infrastructure, wherein the cloud infrastructure includes at least one cloud data center, each cloud data center is provided with multiple servers, and some or all of the multiple servers are deployed with services. The cloud management platform is used to send change operations to the cloud infrastructure, and the change operations are used to change any one or more of the cloud data center, servers, and services; the cloud management platform includes: a receiving module, which is used to receive a change request sent by a user device, and the change request is used to request the cloud management platform to send a change operation corresponding to the change request to the cloud infrastructure, and the change request includes authority indication information, and the authority indication information is used to indicate a target change authority of the change operation corresponding to the change request; a judging module, which is used to, when confirming that a first change operation to be sent to the cloud infrastructure belongs to the change operation corresponding to the change request, determine whether the change authority of the first change operation is within the target change authority based on the authority indication information; and a sending module, which is used to send the first change operation to the cloud infrastructure when the change authority of the first change operation is within the target change authority, so as to execute the first change operation in the cloud infrastructure.
[0019] In a possible implementation, the sending module is further configured to: when the change permission of the first change operation is outside the target change permission, refuse to send the first change operation to the cloud infrastructure.
[0020] In a possible implementation, the cloud management platform further includes: a creation module;
[0021] The creation module is used to: respond to the change request, create a session, and store the permission indication information in the session;
[0022] The judgment module is used to:
[0023] Based on the session identifier included in the first change operation, obtaining permission indication information from the session;
[0024] Based on the authority indication information, it is determined whether the change authority of the first change operation is within the target change authority.
[0025] In a possible implementation manner, the first change operation is sent by a user equipment;
[0026] The sending module is further used for sending a session identifier of the session to the user equipment, so that the user equipment includes the session identifier in the first change operation.
[0027] In a possible implementation, the cloud management platform further includes:
[0028] A generating module, configured to generate a linkage operation of the second change operation when a second change operation is acquired, wherein the second change operation includes a session identifier;
[0029] The session identifier is included in the linkage operation of the second change operation to obtain the first change operation.
[0030] In a possible implementation, the change permission includes a change scope and / or a change object.
[0031] In a third aspect, a computing device cluster is provided, comprising at least one computing device, each computing device comprising a processor and a memory; the processor of at least one computing device is used to execute instructions stored in the memory of at least one computing device, so that the computing device cluster executes the method provided in the first aspect.
[0032] In a fourth aspect, a computer-readable storage medium is provided, comprising computer program instructions. When the computer program instructions are executed by a computing device cluster, the computing device cluster executes the method provided in the first aspect.
[0033] In a fifth aspect, a computer program product comprising instructions is provided. When the instructions are executed by a computer device cluster, the computer device cluster executes the method provided in the first aspect.
[0034] The beneficial effects of the second to fifth aspects can be referred to the above introduction to the beneficial effects of the first aspect, and will not be repeated here. BRIEF DESCRIPTION OF THE DRAWINGS
[0035] Figure 1 A schematic diagram of a system architecture provided for an embodiment of the present application;
[0036] Figure 2 A functional schematic diagram of a cloud management platform provided in an embodiment of the present application;
[0037] Figure 3 A schematic diagram of the structure of a cloud management platform provided in an embodiment of the present application;
[0038] Figure 4 A flow chart of a change control method provided in an embodiment of the present application;
[0039] Figure 5 A schematic diagram of the structure of a cloud management platform provided in an embodiment of the present application;
[0040] Figure 6 A schematic diagram of the structure of a computing device provided in an embodiment of the present application;
[0041] Figure 7 A schematic diagram of the structure of a computing device cluster provided in an embodiment of the present application;
[0042] Figure 8 A schematic diagram of a structure of a computing device cluster connected via a network provided in an embodiment of the present application. DETAILED DESCRIPTION
[0043] The scheme provided by the embodiment of the present application will be described below in conjunction with the accompanying drawings. In the embodiment of the present application, "plurality" refers to two or more than two. "First", "second", etc. are only used to distinguish similar objects and are not necessarily used to describe a specific order or number of objects.
[0044] The embodiments of the present application may involve the following technical terms.
[0045] Cloud technology refers to a hosting service that unifies hardware, software, network and other resources within a wide area network or local area network to achieve data computing, storage, processing and sharing.
[0046] Cloud infrastructure: facilities that support cloud computing services, including at least one data center, each of which includes multiple servers. The servers can be used to deploy services and provide cloud computing services. Specifically, computing instances such as virtual machines (VMs) or containers run on the servers to deploy services and provide cloud computing services. For example, in the case where the cloud infrastructure includes multiple data centers, the multiple data centers can be distributed in different geographical areas, and the data centers can be remotely connected through a backbone network.
[0047] Region: A cloud computing unit in cloud infrastructure, which is divided into cloud computing units based on geographical location and network latency. Public services such as elastic computing, block storage, object storage, VPC network, elastic public IP, and mirroring are shared within the same region.
[0048] Availability zone (AZ): A cloud computing unit in cloud infrastructure. An AZ is a collection of one or more physical data centers with independent wind, fire, water, and electricity. An AZ includes one data center or multiple geographically close data centers. A region can include multiple AZs.
[0049] Cell: A cloud computing unit in the cloud infrastructure, also called a deployment unit, a cloud computing unit under an AZ. Usually, an AZ includes multiple cells.
[0050] Cloud management platform: a platform provided by cloud service providers for interacting with users. Users can register accounts on the cloud management platform and rent cloud services with their accounts, thereby becoming tenants of cloud services. The cloud management platform is also used to manage cloud infrastructure and to isolate computing, network, and / or storage resources rented by different tenants based on their accounts.
[0051] Tenant: refers to the person who rents cloud infrastructure. Tenants can register accounts on the cloud management platform operated by the cloud service provider through a browser or other client. The cloud service provider will record the accounts of different tenants, isolate the cloud services of different tenants based on the accounts, and have full access to the resources and cloud services they own.
[0052] User: An operator of a cloud infrastructure. After being authorized by a tenant, the user can operate the cloud infrastructure leased by the tenant through the cloud management platform, such as making changes to the cloud infrastructure through the cloud management platform.
[0053] Computing instance: also known as a virtual computing device or virtual computing instance, refers to a complete computer system with a complete hardware system that is simulated by software and runs in a completely isolated environment. Among them, the hardware system of the computing instance is a virtual hardware system obtained by virtualizing the physical hardware. A complete computing instance has an independent virtual computing system (such as a central processing unit (CPU) and a virtual disk. Among them, the computing instance that needs to communicate with the outside world also has an independent virtual network card. Typical computing instances include virtual machines (VM) and containers.
[0054] Change task: also called change activity or change, is a task created to achieve a certain change purpose. Change tasks are completed by one or more change operations to achieve the change purpose. Common changes include component version upgrades, room expansion, configuration modifications, patch problem repairs, business expansion, etc.
[0055] Change operation: also known as change instruction, is a specific change operation on cloud infrastructure. Taking component version upgrade as an example, the change operation refers to the operation to be performed to complete the component version upgrade, such as the installation of new version components and the uninstallation of old version components. Change operations are performed in cloud infrastructure to change data centers (such as room expansion, etc.), servers (such as component version upgrades, configuration modifications, etc.) or services (such as patch problem repairs, business expansion, etc.) in the cloud infrastructure. More specifically, the change operation can be performed by a server or computing instance in the cloud infrastructure, where the server or computing instance that performs the change operation is a server or computing instance within the change scope of the change operation.
[0056] Linkage operation: refers to an operation triggered by a change operation. For example, the installation operation of a new version of component A1 may trigger the installation operation of component A2, which is a companion component of component A1. The installation operation of component A2 is a linkage operation of the installation operation of the new version of component A1.
[0057] Change scope (scope): refers to the scope of a change task or change operation. The scope of a change task refers to the scope affected by the change task or the scope of the change task. The scope of a change operation refers to the scope affected by the change operation or the scope of the operation activity. Common change scopes can be one or more cloud data centers (such as one or more regions, one or more AZs, etc.), one or more servers, one or more businesses, etc. Among them, the change scope can be divided into a target change scope and an actual change scope. Among them, the target change scope refers to the change scope set by the user and in line with the user's expectations. The actual change scope refers to the actual change object of the change operation. Due to factors such as user operation errors, defects or loopholes in the change operation interpretation function of the cloud management platform, the actual change scope of the change operation under the change task may be inconsistent with the target change scope of the change task, resulting in an out-of-bounds change. In addition, the target change scope of the change operation and the actual change scope of the linkage operation of the change operation may also be inconsistent.
[0058] Change object: The object operated by the change task and the change operation. Common change objects include servers, computing instances, components, operating systems or applications. More specifically, taking the change task of component version upgrade as an example, its change object is the server for component version upgrade, the component to be upgraded, etc. Taking the change operation of new version component installation as an example, its change object is the server for installing the new version component, the new version component to be installed, etc. The change object can be divided into the target change object and the actual change object. Among them, the target change object refers to the change object set by the user and meets the user's expectations. The actual change object refers to the actual change object of the change operation. Due to factors such as user operation errors, defects or loopholes in the change operation interpretation function of the cloud management platform, the actual change object of the change operation under the change task may be inconsistent with the target change object of the change task, resulting in cross-border changes. In addition, the target change object of the change operation and the actual change object of the linkage operation of the change operation may also be inconsistent.
[0059] Change authority: a general term for the scope and object of change.
[0060] Session: A special object created by a computing device (such as a server) to save user status. It is essentially an area in memory that is used to store information such as user status. Usually, when a client such as a browser accesses a service for the first time, the server creates a session. The session has a session identifier (identifier, ID), and the server sends the session identifier to the browser. The client's subsequent access to the server will carry the session identifier, and the server can query the corresponding session of the client based on the session identifier. Among them, in an embodiment of the present application, the cloud management platform creates a session for a change request and stores the permission indication information carried by the change request in the session.
[0061] In the relevant scheme, in order to prevent the change from crossing the boundary, the role-based access control (RBAC) mechanism is used to control the change permissions of the change operation issued by the user. Specifically, the change permission is assigned to the user, such as the permission to change objects B1, B2, and B3, and the change operation issued by the user can only change the objects in objects B1, B2, and B3. In this scheme, the user and the change permission are bound, and the different change activities initiated by the user may be for different change scopes or change objects. Therefore, although the change permission of the change operation issued by the user can be prevented from exceeding the change permission bound by the user, it cannot prevent the change from crossing the boundary within the change permission bound by the user. For example, the user's expected change objects this time are objects B1 and B2, but due to user operation errors, defects or loopholes in the change operation interpretation function of the cloud management platform, etc., the actual change object includes object B3, and an erroneous change to object B3 occurs, that is, a change crossing the boundary occurs. In addition, the change object of the linkage operation of the change operation may also include object B3, which may also cause the change crossing the boundary.
[0062] The embodiment of the present application provides a change control method based on cloud technology. In this method, when a change is made to a cloud infrastructure, a user can request a cloud management platform to send a change operation to a cloud computing device through a user device, and set a target change permission for the change operation. The cloud management platform can record the target change permission. Before sending a change operation to the cloud infrastructure, the cloud management platform determines whether the change permission of the change operation is within the target change permission. If the change permission of the change operation is within the change permission of the change task, the cloud management platform sends the change operation to the cloud infrastructure to execute the change operation in the cloud infrastructure, and the change operation is used to make changes under the corresponding change permission in the cloud infrastructure. Among them, the corresponding change permission is the change permission of the change operation, which may include a change scope and / or a change object, such as one or more data centers (such as one or more regions, one or more AZs, etc.), one or more servers (such as some or all servers in the same region, AZ or deployment unit), business, etc. One or more. The change permission of the change operation is within the target change permission, which ensures that the changes made by the change operation are within the user's expectations and prevents the changes from crossing the boundary.
[0063] In addition, if the change permission of the change operation is not within the change permission of the change task, that is, the change permission of the change operation is outside the change permission of the change task, then the change operation is refused to be sent to the cloud infrastructure, that is, the change operation is not sent to the cloud infrastructure, thereby avoiding the change operation from being executed in the cloud infrastructure and avoiding the change from crossing the boundary.
[0064] Next, the change control method provided in the embodiment of the present application is described.
[0065] Figure 1 A system architecture 100 is shown. The system architecture 100 can be used to implement the change control method provided in the embodiment of the present application. Figure 1 As shown, the system architecture 100 includes a user device 110 , a cloud management platform 120 , and a cloud infrastructure 130 .
[0066] The user device 110 refers to a device located locally on the user's premises. The user may be a tenant who rents the cloud infrastructure, or an operation and maintenance personnel or manager of the cloud infrastructure. The user device may be a terminal device, such as a mobile phone, a tablet, a smart wearable device, a vehicle terminal, etc. The user device 110 is connected to the cloud management platform 120 via a network, and the user may use the user device 110 to interact with the cloud management platform 120 through an interface or interface provided by the cloud management platform 120.
[0067] The cloud management platform 120 is connected to the cloud infrastructure 130. The cloud management platform 120 and the cloud infrastructure 130 may be connected via a network. The cloud management platform 120 is used to manage the cloud infrastructure 130. For example, the cloud management platform 120 may send a change operation to the cloud infrastructure 130. The change operation may be a change operation to change any one or more of the cloud data center, server, and business in the cloud infrastructure 130.
[0068] The cloud infrastructure 130 includes at least one cloud data center, each cloud data center is provided with multiple servers, and some or all of the multiple servers are deployed with services (such as live broadcast services, image rendering services, etc.). In some embodiments, the cloud infrastructure 130 may be a cloud infrastructure for providing public cloud services, or a cloud infrastructure for providing private cloud services, or a cloud infrastructure for providing hybrid cloud services, or a cloud infrastructure for providing infrastructure as code (IaC) services.
[0069] In the embodiment of the present application, the user uses the user device 110 to initiate changes to the cloud infrastructure 130 through the cloud management platform 120. Specifically, Figure 1 As shown, under the operation of the user, the user device 110 can send a change request to the cloud management platform 120, and the change request is used to request a change to the cloud infrastructure 130, that is, to perform a change task, such as upgrading a component version.
[0070] The change request may specifically request the cloud management platform 120 to send a change operation corresponding to the change request to the cloud infrastructure 130, so as to complete the change task through the change operation. The change operation corresponding to the change request refers to a change operation used to execute or complete the change task requested by the change request. The change operation corresponding to the change request may include a change operation sent by the user device that sends the change request, and a linkage operation of the change operation sent by the user device that sends the change request. The change operation sent by the user device that sends the change request may be a change operation carried in the change request, or may be a change operation sent by the user device after sending the change request.
[0071] The change request includes permission indication information. The permission indication information indicates the target change permission of the change operation corresponding to the change request, and the target change permission can also be called the target change permission of the change task requested by the change request. The target change permission is the change permission set by the user and meets the user's expectations.
[0072] Under the operation of the user, the user device 110 can send a change operation to the cloud management platform 120, so that the change operation is sent to the cloud infrastructure 130 through the cloud management platform 120. The change operation is used to execute or complete the change task requested by the change request. Before sending the change operation, the cloud management platform 120 can determine whether the change authority of the change operation is within the target change authority based on the authority indication information. If the change authority of the change operation is within the target change authority, the cloud management platform 120 sends the change operation to the cloud infrastructure 130 to execute the change operation on the cloud infrastructure 130 to achieve the change of the cloud infrastructure 130. The change authority of the change operation is within the target change authority, so the change of the cloud infrastructure 130 by the change operation does not exceed the target change authority, thereby avoiding problems such as cross-border changes.
[0073] In some embodiments, Figure 2 As shown, when the cloud management platform 120 receives the change request sent by the user device 110, it can respond to the change request, create a session, and store the permission indication information in the change request in the session. When there is a change operation that needs to be sent to the cloud infrastructure 130, that is, when there is a change operation to be sent to the cloud infrastructure 130, the cloud management platform 120 verifies the change operation. Specifically, the permission indication information is obtained from the session, and based on the permission indication information, it is determined whether the change permission of the change operation is within the target change permission indicated by the permission indication information. If so, the cloud management platform 120 sends the change operation to the cloud infrastructure 130. If not, that is, the change permission of the change operation is outside the target change permission indicated by the permission indication information, the cloud management platform 120 does not send the change operation to the cloud infrastructure 130, that is, the cloud management platform 130 refuses to send the operation request to the cloud infrastructure 130.
[0074] The target change permission may be a target change scope, and accordingly, the permission indication information is change scope indication information. The target change permission may be a target change object, and accordingly, the permission indication information is change object indication information. The target change permission may include both the target change scope and the target change object, and accordingly, the permission indication information includes both the target change scope indication information and the target change object indication information.
[0075] In some embodiments, Figure 3As shown, the receiving module of the cloud management platform 120 can receive multiple change requests such as change request A1 and change request A2. Among them, different change requests can be issued by the same user device (such as user device 110) or by different user devices. Whenever the receiving module receives a change request, it can create a session for the change request. For example, when change request A1 is received, session B1 is created for change request A1. For another example, when change request A2 is received, session B2 is created for change request A2.
[0076] The change request includes permission indication information, which indicates the target change permission of the change task requested by the change request, that is, the target change permission of the change operation corresponding to the change request. Among them, the change operation corresponding to the change request refers to the operation used to execute or complete the change task requested by the change request. After the receiving module creates a session for the change request, the permission indication information included in the change request can be stored in the session. For example, the permission indication information A11 included in the change request A1 is stored in the session B1, and the permission indication information A21 included in the change request A2 is stored in the session B2.
[0077] In some embodiments, after creating a session for a change request, the receiving module may send a session identifier of the session to a user device that sends the change request, so that the user device can include the session identifier in the change request when sending a change operation corresponding to the change request.
[0078] In some embodiments, the change request also includes one or more change operations, and the one or more change operations are used to execute or complete the change task requested by the change request, that is, the one or more change operations belong to the change operation corresponding to the change request. After the receiving module creates a session for the change request, the session identifier of the session can be included in the one or more change operations.
[0079] Thus, through the above method, the session identifier can be included in the change operation.
[0080] Before sending a change operation to the cloud infrastructure 130, the cloud management platform 120 may perform a change permission check on the change operation to be sent to the cloud infrastructure 130. The change operation to be sent to the cloud infrastructure 130 may also be referred to as a change operation to be sent to the cloud infrastructure 130. The verification module in the cloud management platform 120 may obtain the change operation to be sent to the cloud infrastructure 130, and perform a change permission check on the change operation to be sent to the cloud infrastructure 130. The details are as follows.
[0081] In some embodiments, the change operation to be sent to the cloud infrastructure 130 may include a change operation sent by a user device. The change operation sent by the user device may be a change operation included in a change request, or may be a change operation sent by the user device after sending a change request. In one example, after receiving the change operation sent by the user device or obtaining the change operation from the change request, the receiving module may send the change operation as the change operation to be sent to the cloud infrastructure 130 to the verification module, so that the verification module obtains the change operation to be sent to the cloud infrastructure 130. In another example, after receiving the change operation sent by the user device or obtaining the change operation from the change request, if the change operation is not a change operation that can be directly executed in the cloud infrastructure 130, the receiving module may interpret, convert, etc. the change operation to convert the change operation into a change operation that can be directly executed in the cloud infrastructure 130. Then, the receiving module sends the change operation that can be directly executed in the cloud infrastructure 130 as the change operation to be sent to the cloud infrastructure 130 to the verification module, so that the verification module obtains the change operation to be sent to the cloud infrastructure 130.
[0082] In some embodiments, the change operation to be sent to the cloud infrastructure 130 may include a linkage operation of the change operation sent by the user device. After the receiving module receives the change operation sent by the user device or obtains the change operation from the change request, if the change operation requires a linkage operation, the receiving module may generate the linkage operation and send the linkage operation as the change operation to be sent to the cloud infrastructure 130 to the verification module, so that the verification module obtains the change operation to be sent to the cloud infrastructure 130. When generating the linkage operation of the change operation, the receiving module includes the session identifier in the change operation in the linkage operation.
[0083] When the verification module obtains the change operation to be sent to the cloud infrastructure 130, it can obtain the permission indication information corresponding to the change operation, and based on the permission indication information, verify whether the change permission of the change operation is within the target change permission indicated by the permission indication information. Among them, the permission indication information corresponding to the change operation refers to the permission indication information included in the change request corresponding to the change operation. As described above, the change operation to be sent to the cloud infrastructure 130 includes a session identifier, and the verification module can obtain the session identifier from the change operation to be sent to the cloud infrastructure 130, and query the session in the memory based on the session identifier, and obtain the permission indication information from the queried session. The obtained permission indication information is the permission indication information corresponding to the change operation. The permission indication information indicates the target change permission, and the verification module can determine whether the change permission of the change operation is within the target change permission. For example, the change permission is specifically the change range, and the target change permission can be set to region C1, and the change permission of the change operation is available zone D1. If available zone D1 is an available zone in region C1, then the change permission of the change operation is within the target change permission. If the availability zone D1 is not an availability zone in region C1, the change permission of the change operation is outside the target change permission. For another example, the change permission is specifically the change object, and the target change permission can be set to include component 1 and component 2. If the change permission of the change operation is component 1 and / or component 2, the change permission of the change operation is within the target change permission; if the change permission of the change operation is component 3, and component 3 is not a component included in the target change permission, the change permission of the change operation is outside the target change permission.
[0084] In addition, the change authority within the target change authority includes the change authority being equal to the target change authority. For example, if the target change authority is region C1 and the change authority of the change operation is also region C1, then the change authority of the change operation is within the target change authority.
[0085] If the change permission of the change operation is within the target change permission, the change operation passes the change permission check. The check module can send the change operation that passes the check to the cloud infrastructure 130. Specifically, the check module can send the change operation that passes the check to the sending module in the cloud management platform 120. The sending module can send the change operation that passes the check to the cloud infrastructure 130 to make the change in the cloud infrastructure 130 and complete all or part of the change task.
[0086] If the change permission of the change operation is outside the target change permission, the change operation fails to pass the change permission check. The verification module refuses to send the change operation to the cloud infrastructure 130. The verification module does not send the change operation to the sending module; or the verification module notifies the sending module of the verification result indicating that the change operation fails to pass the change permission check, and the sending module refuses to send the change operation to the cloud infrastructure 130 based on the verification result. As a result, the change operation is prevented from reaching the cloud infrastructure 130, thereby preventing the change operation with change permission outside the target change permission from reaching the cloud infrastructure, thereby preventing the change from crossing the boundary.
[0087] The above describes the system architecture 100 provided by the embodiment of the present application. Next, in conjunction with the system architecture 100, the change control method provided by the embodiment of the present application is described.
[0088] The method may be executed by the cloud management platform 120, such as Figure 4 As shown, the method includes the following steps.
[0089] In step 401, the cloud management platform 120 receives a change request sent by the user device 110, wherein the change request is used to request the cloud management platform 120 to send a change operation corresponding to the change request to the cloud infrastructure 130, and the change request includes permission indication information, wherein the permission indication information is used to indicate a target change permission of the change operation corresponding to the change request.
[0090] When a user needs to make changes to the cloud infrastructure 130, the user can send a change operation to the cloud management platform 120 through the user device 110 to change the cloud infrastructure 130, so as to change the cloud infrastructure 130 through the change operation. In other words, the change request is used to request the cloud management platform 120 to perform a change task for the cloud infrastructure 130, and request the cloud management platform 130 to send a change operation for executing or completing the change task to the cloud infrastructure 130, that is, the change operation corresponding to the change request.
[0091] The user can set the target change permission through the user device 110. In some embodiments, the target change permission can specifically be a target change scope. The target change scope represents the target scope of the user's change in the cloud infrastructure 130. The target change scope can be one or more data centers, one or more regions, one or more availability zones in a region, one or more deployment units under an availability zone, etc. In some embodiments, the target change permission can specifically be a target change object. The target change object can be a server, a computing instance, a component, an operating system, or an application, etc.
[0092] The user device 110 may generate permission indication information in response to the user's setting of the target change permission. The permission indication information indicates the target change permission indicated by the user. The user device 110 may include the permission indication information in the change request and send the change request to the cloud management platform 120.
[0093] In some embodiments, the cloud management platform 120 may respond to the change request, create a session for the change request, and store the permission indication information included in the change request in the session.
[0094] In some embodiments, step 401 may be performed by a receiving module of the cloud management platform 120 , and step 401 may be implemented with reference to the above description of the functions of the receiving module.
[0095] Step 402: When it is confirmed that the first change operation to be sent to the cloud infrastructure belongs to the change operation corresponding to the change request, based on the permission indication information, it is determined whether the change permission of the first change operation is within the target change permission. The change permission of the change operation here refers to the actual change permission of the change operation. The change permission being within the target change permission includes the case where the change permission is equal to the target change permission.
[0096] When the cloud management platform 120 obtains the change operation to be sent to the cloud infrastructure 130, it performs a change permission check on the change operation. That is, before sending the change operation to the cloud infrastructure 130, the cloud management platform 120 performs a change permission check on the change operation. The cloud management platform 120 obtains the permission indication information included in the change request corresponding to the change operation, and then, based on the permission indication information, determines whether the change permission of the change operation is within the target change permission indicated by the permission indication information.
[0097] In some embodiments, as described above, the cloud management platform 120 creates a session for the change request, and stores the permission indication information included in the change request in the session. When the cloud management platform 120 obtains the change operation to be sent to the cloud infrastructure 130, it can determine whether the change operation includes a session identifier. If the change operation includes a session identifier, the session can be queried based on the session identifier, and the permission indication information included in the change request corresponding to the change operation can be obtained from the queried session. Then, based on the permission indication information obtained from the session, it can be determined whether the change permission of the change operation is within the target change permission indicated by the permission indication information.
[0098] In some embodiments, the first change operation is sent by the user device 110. Specifically, the first change operation is sent by the user device 110 after sending the change request. After creating a session for the change request sent by the user device 110, the cloud management platform 120 may send a session identifier of the session to the user device 110. Thus, when the user device 110 sends a change operation (e.g., the first change operation) corresponding to the change request, the session identifier of the session corresponding to the change request may be included in the change operation. In this way, the change operation may include the session identifier.
[0099] In some embodiments, the first change operation is included in the change request, and the cloud management platform 120 may include the session identifier of the session corresponding to the change request in the first change operation. In this way, the first change operation may include the session identifier.
[0100] In some embodiments, the cloud management platform 120 may obtain a second change operation, where the second change operation includes a session identifier. For example, the second change operation is a change operation sent by the user device 110 and corresponding to a change request, and the user device 110 includes the session identifier of the session corresponding to the change request in the second change operation. For another example, the second change operation belongs to a change operation included in the change request, and the cloud management platform 120 may include the session identifier of the session corresponding to the change request in the second change operation.
[0101] The second change operation can trigger a linkage operation. When the cloud management platform 120 obtains the second change operation, a linkage operation of the second change operation is generated. The cloud management platform 120 can include the session identifier in the second change operation into the linkage operation to obtain the first change operation. In this way, the first change operation can include the session identifier.
[0102] In some embodiments, the target change authority is specifically a target change range. In step 402, it is determined whether the change range of the first change operation is within the target change range. If the change range of the first change operation is within the target change range, it means that the change authority of the first change operation is within the target change authority. If the change range of the first change operation is not within the target change range, it means that the change authority of the first change operation is not within the target change authority, that is, the change authority of the first change operation is outside the target change authority.
[0103] In some embodiments, the target change permission is specifically the target change object. In step 402, it is determined whether the change object of the first change operation is a subset of the target change object. The subset may be a true subset of the target change object or a full set of the target change object. If the change object of the first change operation is a subset of the target change object, it means that the change permission of the first change operation is within the target change permission. If the change object of the first change operation is not a subset of the target change object, it means that the change permission of the first change operation is outside the target change permission.
[0104] In some embodiments, step 402 may be performed by a verification module of the cloud management platform 120 , and step 402 may be implemented with reference to the above description of the functions of the verification module.
[0105] Step 403 : When the change permission of the first change operation is within the target change permission, send the first change operation to the cloud infrastructure 130 to execute the first change operation in the cloud infrastructure 130 .
[0106] When the change permission of the first change operation is outside the target change permission, the first change operation is refused to be sent to the cloud infrastructure 130 to avoid executing the first change operation in the cloud infrastructure 130, thereby avoiding cross-border changes.
[0107] Therefore, through the method provided in the embodiment of the present application, the cloud management platform 130 sends the change operation to the cloud infrastructure 130 when and only when the change authority of the change operation is within the target change authority, so that the change operation can be executed in the cloud infrastructure 130, thereby ensuring that the change authority of the change operation executed in the cloud infrastructure 130 is within the authority set by the user and meets the user's expectations, thereby avoiding changes out of bounds.
[0108] See also Figure 5 , the embodiment of the present application also provides a cloud management platform 500. The cloud management platform 500 is connected to a cloud infrastructure, the cloud infrastructure includes at least one cloud data center, each cloud data center is provided with multiple servers, some or all of the multiple servers are deployed with services, and the cloud management platform 500 is used to send a change operation to the cloud infrastructure, and the change operation is used to change any one or more of the cloud data center, the server, and the service. Figure 5 As shown, the cloud management platform 500 includes:
[0109] The receiving module 510 is used to receive a change request sent by a user device, wherein the change request is used to request the cloud management platform to send a change operation corresponding to the change request to the cloud infrastructure, and the change request includes permission indication information, and the permission indication information is used to indicate a target change permission of the change operation corresponding to the change request;
[0110] A determination module 520 is configured to determine, based on the permission indication information, whether the change permission of the first change operation is within the target change permission when it is confirmed that the first change operation to be sent to the cloud infrastructure belongs to the change operation corresponding to the change request;
[0111] The sending module 530 is configured to send the first change operation to the cloud infrastructure when the change permission of the first change operation is within the target change permission, so as to execute the first change operation in the cloud infrastructure.
[0112] In some embodiments, the sending module 530 is further used to: when the change permission of the first change operation is outside the target change permission, refuse to send the first change operation to the cloud infrastructure.
[0113] In some embodiments, the cloud management platform 500 also includes: a creation module (not shown); the creation module is used to: respond to the change request, create a session, and store permission indication information in the session; the judgment module 520 is used to: based on the session identifier included in the first change operation, obtain the permission indication information from the session; based on the permission indication information, judge whether the change permission of the first change operation is within the target change permission.
[0114] In an example of this embodiment, the first change operation is sent by the user equipment; the sending module 530 is further used to: send a session identifier of the session to the user equipment, so that the user equipment includes the session identifier in the first change operation.
[0115] In an example of this embodiment, the cloud management platform 500 also includes: a generation module (not shown), which is used to generate a linkage operation of the second change operation when a second change operation is obtained, and the second change operation includes the session identifier; include the session identifier in the linkage operation of the second change operation to obtain the first change operation.
[0116] In some embodiments, the change permission includes the change scope and / or the change object.
[0117] Among them, the receiving module 510, the judging module 520 and the sending module 530 can all be implemented by software, or can be implemented by hardware. Exemplarily, the following takes the receiving module 510 as an example to introduce the implementation of the receiving module 510. Similarly, the implementation of the judging module 520 and the sending module 530 can refer to the implementation of the receiving module 510.
[0118] As an example of a software functional unit, the receiving module 510 may include code running on a computing instance. Among them, the computing instance may include at least one of a physical host (computing device), a virtual machine, and a container. Further, the above-mentioned computing instance may be one or more. For example, the receiving module 510 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code can be distributed in the same region or in different regions. Furthermore, the multiple hosts / virtual machines / containers used to run the code can be distributed in the same availability zone AZ or in different AZs, and each AZ includes a data center or multiple data centers with close geographical locations. Among them, usually a region can include multiple AZs.
[0119] Similarly, multiple hosts / virtual machines / containers used to run the code can be distributed in the same VPC or in multiple VPCs. Usually, a VPC is set up in a region. For cross-region communication between two VPCs in the same region and between VPCs in different regions, a communication gateway needs to be set up in each VPC to achieve interconnection between VPCs through the communication gateway.
[0120] As an example of a hardware functional unit, the receiving module 510 may include at least one computing device, such as a server, etc. Alternatively, the receiving module 510 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), a generic array logic (GAL) or any combination thereof.
[0121] The multiple computing devices included in the receiving module 510 can be distributed in the same region or in different regions. The multiple computing devices included in the receiving module 510 can be distributed in the same AZ or in different AZs. Similarly, the multiple computing devices included in the receiving module 510 can be distributed in the same VPC or in multiple VPCs. The multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0122] It should be noted that, in other embodiments, the receiving module 510 may be used to execute Figure 4 In any step of the method shown, the determination module 520 can be used to perform Figure 4 For any step in the method shown, the sending module 530 can be used to perform Figure 4 The steps implemented by the receiving module 510, the judging module 520 and the sending module 530 can be specified as needed, and the receiving module 510, the judging module 520 and the sending module 530 can be respectively implemented Figure 4 The different steps in the method shown implement the full functionality of the cloud management platform 500 .
[0123] The present application also provides a computing device 600. Figure 6 As shown, computing device 600 includes: bus 602, processor 604, memory 606 and communication interface 608. Processor 604, memory 606 and communication interface 608 communicate through bus 602. Computing device 600 can be a server or a terminal device. It should be understood that the present application does not limit the number of processors and memories in computing device 600.
[0124] The bus 602 may be a peripheral component interconnect (PCI) bus or an extended industry standard architecture (EISA) bus. The bus may be divided into an address bus, a data bus, a control bus, etc. For ease of representation, Figure 6 The bus 602 may include a path for transmitting information between various components of the computing device 600 (eg, the memory 606, the processor 604, and the communication interface 608).
[0125] The processor 604 may include any one or more of a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0126] The memory 606 may include a volatile memory, such as a random access memory (RAM). The memory 606 may also include a non-volatile memory, such as a read-only memory (ROM), a flash memory, a hard disk drive (HDD), or a solid state drive (SSD).
[0127] The memory 606 stores executable program codes, and the processor 604 executes the executable program codes to respectively implement the functions of the aforementioned receiving module 510, the judging module 520, and the sending module 530, thereby implementing Figure 4 That is, the memory 606 stores the method for executing Figure 4 Instructions for the method shown.
[0128] The communication interface 608 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 600 and other devices or communication networks.
[0129] The embodiment of the present application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smart phone.
[0130] like Figure 7 As shown, the computing device cluster includes at least one computing device 600. The memory 606 in one or more computing devices 600 in the computing device cluster may store the same Figure 4 Instructions for the method shown.
[0131] In some possible implementations, the memory 606 of one or more computing devices 600 in the computing device cluster may also store a program for executing Figure 4In other words, the combination of one or more computing devices 600 can jointly execute instructions for executing Figure 4 Instructions for the method shown.
[0132] It should be noted that the memory 606 in different computing devices 600 in the computing device cluster can store different instructions, which are respectively used to execute part of the functions of the cloud management platform 500. That is, the instructions stored in the memory 606 in different computing devices 600 can implement the functions of one or more modules among the receiving module 510, the judging module 520 and the sending module 530.
[0133] In some possible implementations, one or more computing devices in the computing device cluster may be connected via a network, which may be a wide area network or a local area network. Figure 8 A possible implementation is shown. Figure 8 As shown, two computing devices 600A and 600B are connected via a network. Specifically, the network is connected via a communication interface in each computing device. In this type of possible implementation, the memory 606 in the computing device 600A stores instructions for executing the functions of the receiving module 510. At the same time, the memory 606 in the computing device 600B stores instructions for executing the functions of the judging module 520 and the sending module 530.
[0134] It should be understood that Figure 8 The functions of the computing device 600A shown in FIG. 6A may also be completed by multiple computing devices 600. Similarly, the functions of the computing device 600B may also be completed by multiple computing devices 600.
[0135] The present application embodiment also provides another computing device cluster. The connection relationship between the computing devices in the computing device cluster can be similar to that of Figure 7 and Figure 8 The difference is that the memory 606 in one or more computing devices 600 in the computing device cluster may store the same memory for executing Figure 4 Instructions for the method shown.
[0136] In some possible implementations, the memory 606 of one or more computing devices 600 in the computing device cluster may also store a program for executing Figure 4 In other words, the combination of one or more computing devices 600 can jointly execute instructions for executing Figure 4 Instructions for the method shown.
[0137] The present application also provides a computer program product including instructions. The computer program product may be software or a program product including instructions that can be run on a computing device or stored in any available medium. When the computer program product is run on at least one computing device, the at least one computing device executes Figure 4 The method shown.
[0138] The present application also provides a computer-readable storage medium. The computer-readable storage medium may be any available medium that can be stored by a computing device or a host migration device such as a data center that includes one or more available media. The available medium may be a magnetic medium (e.g., a floppy disk, a hard disk, a tape), an optical medium (e.g., a DVD), or a semiconductor medium (e.g., a solid-state hard disk). The computer-readable storage medium includes instructions that instruct the computing device to execute Figure 4 The method shown.
[0139] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of the present application, rather than to limit it. Although the present application has been described in detail with reference to the aforementioned embodiments, those skilled in the art should understand that they can still modify the technical solutions described in the aforementioned embodiments, or make equivalent replacements for some of the technical features therein. However, these modifications or replacements do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of the present application.
Claims
1. A change control method, characterized in that: A cloud management platform connected to a cloud infrastructure includes at least one cloud data center, each cloud data center is provided with multiple servers, some or all of the multiple servers are deployed with services, and the cloud management platform is used to send a change operation to the cloud infrastructure, and the change operation is used to change any one or more of the cloud data center, the server, and the service; the method includes: Receiving a change request sent by a user device, the change request is used to request the cloud management platform to send a change operation corresponding to the change request to the cloud infrastructure, and the change request includes authority indication information, and the authority indication information is used to indicate a target change authority of the change operation corresponding to the change request; When it is confirmed that the first change operation to be sent to the cloud infrastructure belongs to the change operation corresponding to the change request, judging whether the change permission of the first change operation is within the target change permission based on the permission indication information; When the change permission of the first change operation is within the target change permission, the first change operation is sent to the cloud infrastructure to execute the first change operation in the cloud infrastructure.
2. The method according to claim 1, characterized in that When the change permission of the first change operation is outside the target change permission, refusing to send the first change operation to the cloud infrastructure.
3. The method according to claim 1 or 2, characterized in that: The method further comprises: creating a session in response to the change request, and storing permission indication information in the session; The determining, based on the permission indication information, whether the change permission of the first change operation is within the target change permission includes: Based on the session identifier included in the first change operation, obtaining the permission indication information from the session; Based on the permission indication information, it is determined whether the change permission of the first change operation is within the target change permission.
4. The method according to claim 3, characterized in that The first change operation is sent by the user equipment; The method further includes: sending a session identifier of the session to the user equipment, so that the user equipment includes the session identifier in the first change operation.
5. The method according to claim 3, characterized in that: The method further comprises: When a second change operation is obtained, a linkage operation of the second change operation is generated, where the second change operation includes the session identifier; The session identifier is included in a linkage operation of the second change operation to obtain the first change operation.
6. The method according to any one of claims 1 to 5, characterized in that The change authority includes the change scope and / or the change object.
7. A cloud management platform, characterized in that: The cloud management platform is connected to a cloud infrastructure, the cloud infrastructure includes at least one cloud data center, each cloud data center is provided with multiple servers, some or all of the multiple servers are deployed with services, the cloud management platform is used to send a change operation to the cloud infrastructure, the change operation is used to change any one or more of the cloud data center, the server, and the service; the cloud management platform includes: A receiving module, configured to receive a change request sent by a user device, wherein the change request is used to request the cloud management platform to send a change operation corresponding to the change request to the cloud infrastructure, and the change request includes permission indication information, wherein the permission indication information is used to indicate a target change permission of the change operation corresponding to the change request; a judgment module, configured to judge, based on the permission indication information, whether the change permission of the first change operation is within the target change permission when confirming that the first change operation to be sent to the cloud infrastructure belongs to the change operation corresponding to the change request; A sending module is used to send the first change operation to the cloud infrastructure when the change permission of the first change operation is within the target change permission, so as to execute the first change operation in the cloud infrastructure.
8. The cloud management platform according to claim 7, characterized in that: The sending module is further used for: when the change authority of the first change operation is outside the target change authority, refusing to send the first change operation to the cloud infrastructure.
9. The cloud management platform according to claim 7 or 8, characterized in that: The cloud management platform also includes: a creation module; The creation module is used to: respond to the change request, create a session, and store the permission indication information in the session; The judging module is used for: Based on the session identifier included in the first change operation, obtaining the permission indication information from the session; Based on the permission indication information, it is determined whether the change permission of the first change operation is within the target change permission.
10. The cloud management platform according to claim 9, characterized in that: The first change operation is sent by the user equipment; The sending module is further used for sending a session identifier of the session to the user equipment, so that the user equipment includes the session identifier in the first change operation.
11. The cloud management platform according to claim 9, characterized in that: The cloud management platform also includes: A generating module, configured to generate a linkage operation of the second change operation when a second change operation is acquired, wherein the second change operation includes the session identifier; The session identifier is included in a linkage operation of the second change operation to obtain the first change operation.
12. The cloud management platform according to any one of claims 6 to 11, characterized in that: The change authority includes the change scope and / or the change object.
13. A computing device cluster, characterized in that: comprising at least one computing device, each computing device comprising a processor and a memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device, so that the computing device cluster executes the method according to any one of claims 1 to 6.
14. A computer-readable storage medium, characterized in that: The method comprises computer program instructions, and when the computer program instructions are executed by a computing device cluster, the computing device cluster performs the method according to any one of claims 1 to 6.
15. A computer program product comprising instructions, characterized in that When the instructions are executed by a computer device cluster, the computer device cluster executes the method according to any one of claims 1 to 6.