Operation and maintenance method and operation and maintenance system

Through the design of operation and maintenance methods and systems, the request forwarding mechanism between the first platform, the first service and the second service, combined with proxy nodes and permission verification, the problems of low operation and maintenance efficiency and limited resource management in the existing technology are solved, and convenient and efficient K8S cluster management is achieved.

CN119966841AActive Publication Date: 2025-05-09CHINA MOBILE (SUZHOU) SOFTWARE TECH CO LTD +1
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
CN202510020653.4
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-01-02
Publication Date
2025-05-09
Estimated Expiration
2045-01-02

AI Technical Summary

Technical Problem

The existing operation and maintenance system has low operation efficiency in large-scale K8S cluster scenarios, cumbersome operations, and limited cluster resources to support management.

Method used

An operation and maintenance method and system are designed to analyze instructions input by the user through the first platform, send a request to the first service, and the first service forwards the request to the K8S cluster where the second service is located, and the second service communicates with the interface service components of the K8S cluster to perform operation and maintenance operations. The system also includes proxy nodes to communicate across network areas and perform operation and maintenance operations after user permission verification.

Benefits of technology

It realizes that users can easily instruct the operation and maintenance system to manage the K8S cluster, simplify operation and maintenance operations, and has rich cluster resource types that support management. It can still efficiently manage the K8S cluster in large-scale cluster scenarios, improving operation and maintenance efficiency.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN119966841A_ABST
    Figure CN119966841A_ABST
Patent Text Reader

Abstract

The invention discloses an operation and maintenance method and system, and the system comprises a first platform, a first service, and one or more second services. Each second service in the one or more second services is respectively arranged in a K8S cluster; the method comprises the steps that a first platform analyzes a first instruction input by a user into a first request and sends the first request to a first service; the first instruction is used for indicating operation and maintenance operation on a first K8S cluster selected by a user in a first platform; the first request is used for requesting the first service to perform operation and maintenance operation on the first K8S cluster; the first service forwards the first request to a second service in the first K8S cluster; and a second service in the first K8S cluster communicates with an interface service component of the first K8S cluster based on the first request so as to perform operation and maintenance operation on the first K8S cluster.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of computer technology, and in particular to an operation and maintenance method and an operation and maintenance system. Background Art

[0002] In the related technology, the client in the operation and maintenance system directly connects to the Kubernetes (K8S) cluster based on the WebSocket protocol, thereby realizing the operation and maintenance management of the K8S cluster. However, the operation of the operation and maintenance system is relatively cumbersome and the cluster resources supported for management are limited. In large-scale cluster scenarios, the operation and maintenance efficiency is low. Summary of the invention

[0003] In order to solve the related technical problems, the embodiments of the present application provide an operation and maintenance method and an operation and maintenance system.

[0004] The technical solution of the embodiment of the present application is implemented as follows:

[0005] The embodiment of the present application provides an operation and maintenance method, which is applied to an operation and maintenance system, wherein the operation and maintenance system includes: a first platform, a first service, and one or more second services; each of the one or more second services is respectively set in a K8S cluster; the method includes:

[0006] The first platform parses the first instruction input by the user into a first request, and sends the first request to the first service; the first instruction is used to instruct to perform operation and maintenance operations on the first K8S cluster selected by the user in the first platform; the first request is used to request the first service to perform operation and maintenance operations on the first K8S cluster;

[0007] The first service forwards the first request to the second service in the first K8S cluster;

[0008] The second service in the first K8S cluster communicates with the interface service component of the first K8S cluster based on the first request to perform operation and maintenance operations on the first K8S cluster.

[0009] In the above scheme, the method further comprises:

[0010] The second service sends a second request to the first service; the second request is used to request to register the cluster where the second service is located with the first service.

[0011] In the above solution, the operation and maintenance system further includes: one or more proxy nodes; each of the one or more proxy nodes corresponds to a network area;

[0012] Correspondingly, when the first service and the first K8S cluster are deployed in different network areas, the first service forwards the first request to the second service in the first K8S cluster, including:

[0013] The first service forwards the first request to a proxy node corresponding to the network area where the first K8S cluster is located;

[0014] The proxy node corresponding to the network area where the first K8S cluster is located forwards the first request to the second service in the first K8S cluster.

[0015] In the above solution, the first service forwards the first request to the second service in the first K8S cluster, including:

[0016] The first service determines whether the user has execution authority for the operation and maintenance operation corresponding to the first instruction based on the setting service and the first request; the setting service is used to perform authority verification on the user;

[0017] In a case where the user has execution authority for the operation and maintenance corresponding to the first instruction, the first service forwards the first request to the second service in the first K8S cluster.

[0018] In the above solution, the first service determines whether the user has the execution authority of the operation and maintenance operation corresponding to the first instruction based on the setting service and the first request, including:

[0019] The first service parses, based on the first request, a target object of the operation and maintenance operation corresponding to the first instruction;

[0020] The first service sends a third request to the setting service, and determines, based on a response returned by the setting service according to the third request, whether the user has execution authority to perform an operation and maintenance operation on a target object of the operation and maintenance operation corresponding to the first instruction.

[0021] In the above solution, the category of the target object of the operation and maintenance operation includes one of the following: project, cluster, business, and namespace.

[0022] In the above solution, one or more K8S clusters are displayed in the visualization interface of the first platform, and the method further includes:

[0023] The first platform determines the first K8S cluster from the one or more K8S clusters based on the selection operation of the user in the visualization interface.

[0024] The embodiment of the present application also provides an operation and maintenance system, including: a first platform, a first service, and one or more second services; each of the one or more second services is respectively set in a K8S cluster; wherein,

[0025] The first platform is used to parse the first instruction input by the user into a first request, and send the first request to the first service; the first instruction is used to instruct to perform operation and maintenance operations on the first K8S cluster selected by the user in the first platform; the first request is used to request the first service to perform operation and maintenance operations on the first K8S cluster;

[0026] The first service is used to forward the first request to the second service in the first K8S cluster;

[0027] The second service in the first K8S cluster is used to communicate with the interface service component of the first K8S cluster based on the first request to perform operation and maintenance operations on the first K8S cluster.

[0028] In the above solution, the second service is also used for:

[0029] The second service sends a second request to the first service; the second request is used to request to register the cluster where the second service is located with the first service.

[0030] In the above solution, the operation and maintenance system further includes: one or more proxy nodes; each of the one or more proxy nodes corresponds to a network area;

[0031] Correspondingly, when the first service and the first K8S cluster are deployed in different network areas, the first service forwards the first request to the second service in the first K8S cluster, including:

[0032] The first service forwards the first request to a proxy node corresponding to the network area where the first K8S cluster is located;

[0033] The proxy node corresponding to the network area where the first K8S cluster is located forwards the first request to the second service in the first K8S cluster.

[0034] In the above solution, the first service forwards the first request to the second service in the first K8S cluster, including:

[0035] The first service determines whether the user has execution authority for the operation and maintenance operation corresponding to the first instruction based on the setting service and the first request; the setting service is used to perform authority verification on the user;

[0036] In a case where the user has execution authority for the operation and maintenance corresponding to the first instruction, the first service forwards the first request to the second service in the first K8S cluster.

[0037] In the above solution, the first service determines whether the user has the execution authority of the operation and maintenance operation corresponding to the first instruction based on the setting service and the first request, including:

[0038] The first service parses, based on the first request, a target object of the operation and maintenance operation corresponding to the first instruction;

[0039] The first service sends a third request to the setting service, and determines, based on a response returned by the setting service according to the third request, whether the user has execution authority to perform an operation and maintenance operation on a target object of the operation and maintenance operation corresponding to the first instruction.

[0040] In the above solution, the category of the target object of the operation and maintenance operation includes one of the following: project, cluster, business, and namespace.

[0041] In the above solution, one or more K8S clusters are displayed in the visualization interface of the first platform, and the first platform is also used for:

[0042] Based on the selection operation of the user in the visualization interface, the first K8S cluster is determined from the one or more K8S clusters.

[0043] In an embodiment of the present application, an operation and maintenance system includes: a first platform, a first service, and one or more second services; wherein each of the one or more second services is respectively set in a K8S cluster; the operation and maintenance method executed by the operation and maintenance system includes: a user inputs a first instruction to instruct to perform an operation and maintenance operation on a first K8S cluster selected by the user in the first platform, the first platform parses the first instruction into a first request, and sends the first request to the first service to request the first service to perform an operation and maintenance operation on the first K8S cluster; then, the first service forwards the first request to the second service in the first K8S cluster; thereafter, the second service in the first K8S cluster communicates with the interface service component of the first K8S cluster based on the first request to perform an operation and maintenance operation on the first K8S cluster. In this way, the user can conveniently instruct the operation and maintenance system to operate and manage the K8S cluster based on the selection operation. The operation and maintenance system can request the first service from the first platform based on the first instruction, and then the first service requests the second service set in the K8S cluster to perform operation and maintenance operations, which is equivalent to realizing the transmission of instructions, thereby enabling diversified management of rich cluster resources. Compared with related technologies, the operation and maintenance system on the user side is easy to operate, and the operation and maintenance system supports rich types of cluster resources to be managed. It can still efficiently manage K8S clusters in large-scale cluster scenarios, thereby improving operation and maintenance efficiency. BRIEF DESCRIPTION OF THE DRAWINGS

[0044] Figure 1 A schematic diagram of the architecture of an operation and maintenance system provided in an embodiment of the present application;

[0045] Figure 2 A schematic diagram of an implementation flow of an operation and maintenance method provided in an embodiment of the present application;

[0046] Figure 3 A schematic diagram of the architecture of an operation and maintenance system provided for an application embodiment of the present application;

[0047] Figure 4 An interactive flow chart of an operation and maintenance method provided for an application embodiment of the present application. DETAILED DESCRIPTION

[0048] Based on the command line management tool kubectl provided by the K8S system, users can perform operation and maintenance management on the K8S cluster. For example, users can be operation and maintenance personnel and R&D personnel. Operation and maintenance management can be to deploy, delete, scale up and down, and check the status of conventional applications, or interact with running containers. However, these operation and maintenance management require users to manually log in to the bastion server and then operate in the command line interface, which is cumbersome.

[0049] With the development of cloud native technology, the related technology has designed an operation and maintenance system. The client in the operation and maintenance system directly connects to the K8S cluster based on the WebSocket protocol, thereby realizing the operation and maintenance management of the K8S cluster. Specifically, the operation and maintenance system includes multiple client pages, each of which is used to manage a cluster. The kubectl command line tool is integrated in the page, and common query statements are provided in the form of fixed rules so that users can select query statements and then instruct the operation and maintenance system to perform operation and maintenance management on the K8S cluster. However, based on the operation and maintenance system in the related technology, each time a user manages a K8S cluster, he needs to open a client page, which is cumbersome and slow to schedule; and the operation and maintenance system only provides query functions, and supports limited management of cluster resources. For interactive session scenarios, such as managing Pod-level container resources, users are still required to manually log in to the bastion server. Therefore, in large-scale cluster scenarios, for example, in cluster scenarios where the cluster scale is expanded to thousands of nodes and spans multiple network areas, the operation and maintenance efficiency is low.

[0050] Based on this, in an embodiment of the present application, the operation and maintenance system includes: a first platform, a first service and one or more second services; wherein each of the one or more second services is respectively set in a K8S cluster; the operation and maintenance method executed by the operation and maintenance system includes: a user inputs a first instruction to instruct to perform an operation and maintenance operation on the first K8S cluster selected by the user in the first platform, the first platform parses the first instruction into a first request, and sends the first request to the first service to request the first service to perform an operation and maintenance operation on the first K8S cluster. Then, the first service forwards the first request to the second service in the first K8S cluster; thereafter, the second service in the first K8S cluster communicates with the interface service component of the first K8S cluster based on the first request to perform an operation and maintenance operation on the first K8S cluster. In this way, the user can conveniently instruct the operation and maintenance system to operate and manage the K8S cluster based on the selection operation. The operation and maintenance system can request the first service from the first platform based on the first instruction, and then the first service requests the second service set in the K8S cluster to perform operation and maintenance operations, which is equivalent to realizing the transmission of instructions, thereby enabling diversified management of rich cluster resources. Compared with related technologies, the operation and maintenance system on the user side is easy to operate, supports rich types of cluster resources for management, and is not limited to query functions. It can still efficiently manage K8S clusters in large-scale cluster scenarios, thereby improving operation and maintenance efficiency.

[0051] The present application is further described in detail below with reference to the accompanying drawings and embodiments.

[0052] The embodiment of the present application provides an operation and maintenance method, which is applied to an operation and maintenance system. Here, Figure 1 The system architecture diagram of the operation and maintenance system is shown in Figure 1The operation and maintenance system includes: a first platform, a first service, and one or more second services. Each of the one or more second services is respectively set in a K8S cluster.

[0053] In actual applications, the operation and maintenance system can be used to operate and manage the K8S cluster, and the K8S cluster can be understood as a cluster service.

[0054] See also Figure 2 , the operation and maintenance method provided in the embodiment of the present application includes:

[0055] Step 201: The first platform parses a first instruction input by a user into a first request, and sends the first request to a first service.

[0056] Among them, the first instruction is used to instruct the operation and maintenance of the first K8S cluster selected by the user in the first platform; the first request is used to request the first service to perform operation and maintenance operations on the first K8S cluster.

[0057] In actual applications, users can be personnel who need to operate and maintain the K8S cluster, such as R&D personnel, testers, and operation and maintenance personnel. Users can operate and maintain the K8S cluster through the operation and maintenance system.

[0058] In actual applications, the first platform can provide an operation interface for users, which can also be expressed as a front-end window. The operation interface of the first platform can display one or more K8S clusters, which can be one or more K8S clusters supported by the first platform for management, or one or more K8S clusters for which users have the authority to perform operation and maintenance operations.

[0059] The first platform can determine the K8S cluster selected by the user, that is, the first K8S cluster, based on the selection operation of the user in the operation interface. The first K8S cluster can be understood as the K8S cluster that the user needs to perform operation and maintenance operations.

[0060] In practical applications, the first platform can be regarded as a client platform of the operation and maintenance system. The first platform can be constructed based on setting specifications and setting styles, so as to support concurrent operations of multiple users and have a faster loading speed.

[0061] In one embodiment, one or more K8S clusters are displayed in the visualization interface of the first platform, and the operation and maintenance method provided in the embodiment of the present application further includes:

[0062] The first platform determines a first K8S cluster from one or more K8S clusters based on a selection operation performed by a user in a visualization interface.

[0063] In actual applications, the operation interface provided by the first platform to the user may be a visual interface. The visual interface may display content through visual elements such as graphics, and the user may operate the content displayed in the visual interface through various types of inputs such as a mouse or keyboard.

[0064] In actual applications, after the visualization interface of the first platform is opened, one or more K8S clusters can be displayed. For example, one or more K8S clusters can be represented in the visualization interface by one or more icons for identifying K8S clusters. Then, the user can perform a selection operation in the visualization interface, for example, by clicking an icon corresponding to a K8S cluster with a mouse to select the K8S cluster. After that, the first platform can determine the K8S cluster selected by the user as the first K8S cluster based on the user's selection operation.

[0065] It should be noted that the visual interface is different from the command line interface in the related art. The command line interface can only display characters and can only operate based on the input provided by the keyboard. In actual applications, no information is displayed after the naming line interface is opened, so the user cannot directly select the K8S cluster through the command line interface. After the user manually enters the command statement through the keyboard in the command line interface, the command line interface can list one or more K8S clusters in the form of characters. When the user indicates a K8S cluster, the corresponding command statement is also required through the keyboard. Obviously, compared with the command line interface, the visual interface simplifies the operation steps and improves the operation efficiency. In actual applications, the command line interface can be described as a black screen interface, and the visual interface can be described as a white screen interface.

[0066] In actual applications, the user can also input an operation instruction on the first platform, and the operation instruction is used to instruct the operation and maintenance system to perform operation and maintenance operations on the K8S cluster. Exemplarily, the operation instruction can be a Linux instruction.

[0067] Here, the first instruction can be understood as an operation instruction input by the user on the first platform for performing operation and maintenance operations on the first K8S cluster.

[0068] In actual applications, after receiving the first instruction, the first platform may parse the first instruction, thereby converting the first instruction into a first request, and send the first request to the first service.

[0069] In actual applications, the first service may expose one or more application programming interfaces (APIs) for operating the first K8S cluster. For example, these APIs may be encapsulated based on the native APIs provided by the K8S system. The first request sent by the first platform may be an interface call request for calling the API provided by the first service.

[0070] Step 202: The first service forwards the first request to the second service in the first K8S cluster.

[0071] In actual applications, the second service is set in the K8S cluster and can communicate with the interface service component of the K8S cluster to realize the operation and maintenance of the K8S cluster.

[0072] In actual applications, after receiving the first request, the first service can forward the first request to the second service to request the second service to perform operation and maintenance operations on the first K8S cluster.

[0073] The second service may expose one or more APIs for operating the first K8S cluster. The first service may send a corresponding interface call request to the second service based on the received first request, and the interface call request may be used to call the API provided by the second service.

[0074] In actual applications, the interface call request sent by the first service to the second service based on the first request and the first request received by the first service are used to request the same operation and maintenance operation on the same K8S cluster. Therefore, the first service sending the interface call request to the second service based on the first request can also be understood as the first service forwarding the first request to the second service.

[0075] It should be noted that although both the first service and the second service can expose one or more APIs for operating the first K8S cluster, the API exposed by the first service is not the same as the API exposed by the second service. After the API exposed by the first service is called, the first service can first perform pre-processing. For example, the pre-processing can include processing such as user permission verification. Then the first service can call the corresponding API exposed by the second service based on its own called API. After the API exposed by the second service is called, the second service can communicate with the interface service component of the cluster based on its own called API.

[0076] Step 203: Based on the first request, the second service in the first K8S cluster communicates with the interface service component of the first K8S cluster to perform operation and maintenance operations on the first K8S cluster.

[0077] In actual applications, the interface service component can be the API Server component of the K8S cluster.

[0078] In actual applications, after receiving the first request forwarded by the first service, the second service can communicate with the interface service component of the K8S cluster based on the first request, thereby controlling the interface service component of the cluster to perform actual operation and maintenance operations, such as querying the resources in the cluster by the interface service component, or conducting an interactive session in the Pod container.

[0079] It can be seen that in the embodiment of the present application, the operation and maintenance system can parse the first instruction input by the user into a first request, and based on the processing of the first request by the first service and the second service, control the interface service component of the first K8S cluster to perform the operation and maintenance operation corresponding to the first instruction, which is equivalent to realizing: passing the first instruction to the K8S cluster and executing the first instruction inside the K8S cluster. It can be understood that the instruction can support various types of operation and maintenance operations, and after the instruction is passed to the K8S cluster, it can actually operate various types of resources in the K8S cluster, for example, managing Pod-level container resources and conducting interactive sessions, etc., so as to manage rich cluster resources in a diversified manner. In addition, in the embodiment of the present application, the user can conveniently indicate the K8S cluster to be operated and managed by the operation and maintenance system based on the selection operation, which simplifies the operation of the operation and maintenance system. Compared with the related art, the operation and maintenance method provided in the embodiment of the present application is relatively simple to operate, and supports a rich type of cluster resources for management. It can still efficiently manage the K8S cluster in a large-scale cluster scenario, thereby improving the operation and maintenance efficiency.

[0080] In actual applications, before the user selects the first K8S cluster on the first platform, the first platform needs to determine the K8S cluster available for the user to select. Based on this, the first service needs to establish an association with the K8S cluster in advance.

[0081] In one embodiment, the operation and maintenance method provided by the embodiment of the present application also includes: the second service sends a second request to the first service; the second request is used to request to register the cluster where the second service is located with the first service.

[0082] In actual applications, the second service can be bound to a K8S service account and a cluster rule, which can give the second service full permissions to operate the K8S cluster. After the second service is set in the cluster, it can log in to the K8S cluster based on the bound K8S service account and cluster rule, so that the second service supports communication with the interface service component of the K8S cluster, which is equivalent to establishing a continuous communication channel between the second service and the K8S cluster.

[0083] In actual applications, the second service after logging in can be understood as a user with full permissions to operate the K8S cluster. Therefore, the second service can also be described as a cluster management client.

[0084] In actual applications, the second service can be compatible with multiple different versions of K8S clusters. For example, the second service can be compatible with multiple versions of K8S clusters such as 1.14, 1.16, 1.18, 1.20, 1.22 and 1.24. In the case where the K8S cluster where the second service is located is a K8S cluster compatible with the second service, the second service can support logging into the K8S cluster and supporting communication with the interface service component in the K8S cluster.

[0085] In actual applications, after logging into the K8S cluster, the second service can actively send a first request to the first service. After receiving the first request, the first service can complete the registration of the K8S cluster based on the first request. The first request can be regarded as a registration request. The first request can carry the registration information of the corresponding K8S cluster. Exemplarily, the registration information may include one or more of the following of the corresponding K8S cluster: identification, access credentials, and deployed network area. The first service can obtain the registration information based on the first request and store the registration information locally in the first service to complete the registration of the K8S cluster.

[0086] In actual applications, after registering the K8S cluster, the first service can actively initiate a request to the second service set in the K8S cluster, which is equivalent to establishing a long connection channel between the first service and the second service corresponding to the K8S cluster, and can also be regarded as establishing an association between the first service and the K8S cluster. In this way, the first service can actively send a request to the second service to perform operation and maintenance operations on the K8S cluster where the second service is located.

[0087] In actual applications, the first platform can determine the registered K8S cluster as the K8S cluster available for user selection. Exemplarily, the first platform can actively call the relevant interface of the first service to obtain the registered K8S cluster, and then display the obtained K8S cluster in the interface.

[0088] In the related art, the K8S service account is stored separately from the K8S cluster, for example, in a server deployed in a different network area from the K8S cluster. In this way, the configuration information corresponding to the K8S service account, such as the kube-config file, needs to be stored in plain text in the server, which reduces the security of operation and maintenance. In addition, the user needs to actively execute instructions related to logging into the K8S cluster and control the server to send a login request to the K8S cluster to establish an association between the server and the K8S cluster. The operation is relatively cumbersome and reduces the efficiency of operation and maintenance.

[0089] In the embodiment of the present application, the second service is set in the K8S cluster, so that the K8S service account can be stored in the K8S cluster and is not easily stolen, thereby improving the security of operation and maintenance. In addition, after being set in the K8S cluster, the second service actively logs in to the K8S cluster and then actively sends a registration request to the first service, without the need for the user to control the second service to send a login request to the K8S cluster, which simplifies the operation and improves the efficiency of operation and maintenance.

[0090] In actual applications, the first service and the K8S cluster may be deployed in different network areas. For security reasons, there is network isolation between services deployed in different network areas, that is, they cannot communicate directly.

[0091] In one embodiment, the operation and maintenance system further includes: one or more proxy nodes; each of the one or more proxy nodes corresponds to a network area;

[0092] Correspondingly, when the first service and the first K8S cluster are deployed in different network areas, the first service forwards the first request to the second service in the first K8S cluster, including:

[0093] The first service forwards the first request to the proxy node corresponding to the network area where the first K8S cluster is located;

[0094] The proxy node corresponding to the network area where the first K8S cluster is located forwards the first request to the second service in the first K8S cluster.

[0095] In actual applications, after receiving the first request sent by the first platform, the first service can determine the network area where the first K8S cluster is located based on the registration information of the first K8S cluster stored locally, and then determine whether the first service is deployed in a different network area from the first K8S cluster.

[0096] In actual applications, each K8S cluster deployed in a different network area from the first service can have a proxy node, which can be used to forward requests from the external network area to the corresponding K8S cluster, and forward requests from the corresponding K8S cluster to the service deployed in the external network area, thereby realizing communication between services across network areas. Here, the external network area can be understood as a network area different from the network area where the corresponding K8S cluster is located. In this way, based on the forwarding of the proxy node, the first service can achieve unified management of multiple K8S clusters.

[0097] In actual applications, during the forwarding process, the proxy node can perform encrypted forwarding based on the Secure Sockets Layer (SSL) protocol or the Transport Layer Security (TLS) protocol, thereby protecting data transmission and further improving the security of operation and maintenance.

[0098] In actual applications, when the first service and the first K8S cluster are deployed in different network areas, the first service and the first K8S cluster are in a cross-network relationship, that is, there is network isolation. Based on the forwarding of the proxy node corresponding to the first K8S cluster, communication between the first service and the first K8S cluster can be achieved, so that the second service in the first K8S cluster can receive the first request forwarded by the first service.

[0099] In actual applications, when the first service and the first K8S cluster are deployed in the same network area, there is a direct connection between the first service and the first K8S cluster, that is, there is no network isolation. The second service in the first K8S cluster can directly receive the first request forwarded by the first service, and does not require forwarding based on a proxy node.

[0100] In actual applications, in order to further improve the security of operation and maintenance, the first service can perform permission verification on the user when forwarding the first request to the second service, that is, perform authentication.

[0101] In one embodiment, the first service forwards the first request to the second service in the first K8S cluster, including:

[0102] The first service determines whether the user has the execution authority of the operation and maintenance operation corresponding to the first instruction based on the setting service and the first request; the setting service is used to verify the authority of the user;

[0103] When the user has the execution authority of the operation and maintenance operation corresponding to the first instruction, the first service forwards the first request to the second service in the first K8S cluster.

[0104] In actual applications, the setting service can also be called the permission center, which can be used to verify the permissions of users.

[0105] In actual applications, after receiving the first request sent by the first platform, the first service can parse the target verification information based on the first request. Exemplarily, the target verification information may include one or more of the following: the operation and maintenance operation corresponding to the first instruction, the user identifier, and the cluster information of the first K8S cluster. Then the first service can send an authentication request to the setting service, that is, call the setting service, and determine whether the user has the execution authority of the operation and maintenance operation corresponding to the first instruction based on the response returned by the setting service based on the authentication request. Among them, the target verification information can be carried in the authentication request. In the case where the user has the execution authority of the operation and maintenance operation corresponding to the first instruction, it can be regarded as the authentication of the user passed, and the first service is allowed to forward the first request to the second service in the first K8S cluster. In the case where the user does not have the execution authority of the operation and maintenance operation corresponding to the first instruction, it can be regarded as the authentication of the user failed, and the first service is not allowed to forward the first request to the second service in the first K8S cluster.

[0106] In actual applications, the first request forwarded by the first service to the second service in the first K8S cluster may carry the access credentials of the first K8S cluster.

[0107] In one embodiment, the first service determines whether the user has execution authority for the operation and maintenance operation corresponding to the first instruction based on the setting service and the first request, including:

[0108] The first service parses the target object of the operation and maintenance operation corresponding to the first instruction based on the first request;

[0109] The first service sends a third request to the setting service, and determines, based on a response returned by the setting service according to the third request, whether the user has execution authority to perform the operation and maintenance operation on the target object of the operation and maintenance operation corresponding to the first instruction.

[0110] In practical applications, the third request can be understood as an authentication request, and the third request can carry the target object of the operation and maintenance operation corresponding to the first instruction.

[0111] In actual applications, after receiving the third request, the setting service can determine based on the third request: the execution permission that the user needs to have in order to perform the operation and maintenance operation on the target object of the operation and maintenance operation corresponding to the first instruction, and then compare the permission that the user already has with the determined execution permission that needs to be possessed to determine whether the user has the execution permission to perform the operation and maintenance operation on the target object of the operation and maintenance operation corresponding to the first instruction, and obtain a judgment result. Then, the setting server carries the judgment result in the returned response.

[0112] In actual applications, the first service may first determine, based on the target object of the operation and maintenance operation corresponding to the first instruction, the execution permission that the user needs to have in order to perform the operation and maintenance operation on the target object. Then, after receiving the third request, the setting service may determine whether the user has the determined execution permission, obtain a determination result, and carry the determination result in the returned response.

[0113] In actual applications, the first service can forward the first request to the second service in the first K8S cluster if the user has the execution authority to perform the operation and maintenance operation on the target object of the operation and maintenance operation corresponding to the first instruction.

[0114] In one embodiment, the category of the target object of the operation and maintenance operation includes one of the following: project, cluster, business, and namespace.

[0115] In practical applications, the type of the target object of the operation and maintenance operation can also be expressed as the dimension of the operation and maintenance operation.

[0116] In actual applications, a project can correspond to one or more clusters. For example, project 1 can correspond to two clusters, namely cluster 1 and cluster 2. When the category of the target object of the operation and maintenance operation is a project, a single operation and maintenance operation can perform batch processing on all clusters corresponding to the project, that is, batch processing on cluster resources in all clusters corresponding to the project. For example, when the target object of the operation and maintenance operation is project 1 in the previous example, a single operation and maintenance operation can perform batch processing on cluster 1 and cluster 2.

[0117] A cluster can correspond to one or more businesses, and each business corresponds to corresponding cluster resources. For example, cluster 1 can correspond to two businesses, namely business 1 and business 2, where business 1 can correspond to containers 1 to 5 in cluster 1, and business 2 can correspond to containers 6 to 9 in cluster 1. In the case where the category of the target object of the operation and maintenance operation is a cluster, a single operation and maintenance operation can batch process the cluster resources corresponding to all businesses corresponding to the cluster. For example, in the case where the target object of the operation and maintenance operation is cluster 1 in the previous example, a single operation and maintenance operation can batch process the cluster resources corresponding to business 1 and business 2, namely containers 1 to 9.

[0118] A business can correspond to one or more namespaces, and each namespace corresponds to corresponding cluster resources. Exemplarily, business 1 in cluster 1 can correspond to two namespaces, namely namespace 1 and namespace 2, wherein namespace 1 can correspond to container 1 in cluster 1, and namespace 2 can correspond to containers 2 to 5 in cluster 1. In the case where the category of the target object of the operation and maintenance operation is business, a single operation and maintenance operation can perform batch processing on the cluster resources corresponding to all namespaces corresponding to the business. Exemplarily, in the case where the target object of the operation and maintenance operation is business 1 in the previous example, a single operation and maintenance operation can perform batch processing on the cluster resources corresponding to all namespaces corresponding to business 1, namely containers 1 to 5.

[0119] When the target object of the operation is a namespace, a single operation can perform batch processing on all cluster resources corresponding to the namespace. For example, namespace 2 can correspond to containers 2 to 5 in cluster 1. When the target object of the operation is namespace 2, a single operation can perform batch processing on all cluster resources corresponding to namespace 2, i.e., containers 2 to 5.

[0120] In practical applications, the type of the target object of the operation and maintenance operation can also be expressed as the dimension of the operation and maintenance operation.

[0121] In the related technology, operation and maintenance operations can only be performed on a single cluster, that is, operation and maintenance operations can only be performed in the cluster dimension, and complex permission control scenarios cannot be implemented. For example, a permission control scenario that cannot be implemented by the related technology may be: the operation object of a single operation and maintenance operation by the R&D personnel can only be a single cluster, and the operation object of a single operation and maintenance operation by the operation and maintenance personnel may include: multiple clusters corresponding to the same project.

[0122] In the embodiment of the present application, the first service forwards or does not forward the first request to the second service based on the authentication result of the user's execution authority to perform the operation and maintenance operation on the target object of the operation and maintenance operation corresponding to the first instruction. That is, the user is authenticated based on the dimension of the operation and maintenance operation corresponding to the first instruction, thereby realizing complex permission control scenarios, increasing the security of operation and maintenance, and improving operation and maintenance efficiency.

[0123] Based on the operation and maintenance method in the above embodiment, the embodiment of the present application also provides an operation and maintenance system. Figure 1 The system architecture diagram of the operation and maintenance system shown is as follows:

[0124] The first platform is used to parse the first instruction input by the user into a first request, and send the first request to the first service; the first instruction is used to instruct to perform operation and maintenance operations on the first K8S cluster selected by the user in the first platform; the first request is used to request the first service to perform operation and maintenance operations on the first K8S cluster;

[0125] The first service is used to forward the first request to the second service in the first K8S cluster;

[0126] The second service in the first K8S cluster is used to communicate with the interface service component of the first K8S cluster based on the first request to perform operation and maintenance operations on the first K8S cluster.

[0127] In actual applications, users can be personnel who need to operate and maintain the K8S cluster, such as R&D personnel, testers, and operation and maintenance personnel. Users can operate and maintain the K8S cluster through the operation and maintenance system.

[0128] In actual applications, the first platform can provide an operation interface for users, which can also be expressed as a front-end window. The operation interface of the first platform can display one or more K8S clusters, which can be one or more K8S clusters supported by the first platform for management, or one or more K8S clusters for which users have the authority to perform operation and maintenance operations.

[0129] The first platform can determine the K8S cluster selected by the user, that is, the first K8S cluster, based on the selection operation of the user in the operation interface. The first K8S cluster can be understood as the K8S cluster that the user needs to perform operation and maintenance operations.

[0130] In practical applications, the first platform can be regarded as a client platform of the operation and maintenance system. The first platform can be constructed based on setting specifications and setting styles, so as to support concurrent operations of multiple users and have a faster loading speed.

[0131] In one embodiment, one or more K8S clusters are displayed in the visualization interface of the first platform, and the first platform is further used to:

[0132] Based on the selection operation of the user in the visualization interface, a first K8S cluster is determined from one or more K8S clusters.

[0133] In actual applications, the operation interface provided by the first platform to the user may be a visual interface. The visual interface may display content through visual elements such as graphics, and the user may operate the content displayed in the visual interface through various types of inputs such as a mouse or keyboard.

[0134] In actual applications, after the visualization interface of the first platform is opened, one or more K8S clusters can be displayed. For example, one or more K8S clusters can be represented in the visualization interface by one or more icons for identifying K8S clusters. Then, the user can perform a selection operation in the visualization interface, for example, by clicking an icon corresponding to a K8S cluster with a mouse to select the K8S cluster. After that, the first platform can determine the K8S cluster selected by the user as the first K8S cluster based on the user's selection operation.

[0135] It should be noted that the visual interface is different from the command line interface in the related art. The command line interface can only display characters and can only operate based on the input provided by the keyboard. In actual applications, no information is displayed after the naming line interface is opened, so the user cannot directly select the K8S cluster through the command line interface. After the user manually enters the command statement through the keyboard in the command line interface, the command line interface can list one or more K8S clusters in the form of characters. When the user indicates a K8S cluster, the corresponding command statement is also required through the keyboard. Obviously, compared with the command line interface, the visual interface simplifies the operation steps and improves the operation efficiency. In actual applications, the command line interface can be described as a black screen interface, and the visual interface can be described as a white screen interface.

[0136] In actual applications, the user can also input an operation instruction on the first platform, and the operation instruction is used to instruct the operation and maintenance system to perform operation and maintenance operations on the K8S cluster. Exemplarily, the operation instruction can be a Linux instruction.

[0137] Here, the first instruction can be understood as an operation instruction input by the user on the first platform for performing operation and maintenance operations on the first K8S cluster.

[0138] In actual applications, after receiving the first instruction, the first platform may parse the first instruction, thereby converting the first instruction into a first request, and send the first request to the first service.

[0139] In actual applications, the first service may expose one or more APIs for operating the first K8S cluster. For example, these APIs may be encapsulated based on the native APIs provided by the K8S system. The first request sent by the first platform may be an interface call request for calling the API provided by the first service.

[0140] In actual applications, the second service is set in the K8S cluster and can communicate with the interface service component of the K8S cluster to realize the operation and maintenance of the K8S cluster.

[0141] In actual applications, after receiving the first request, the first service can forward the first request to the second service to request the second service to perform operation and maintenance operations on the first K8S cluster.

[0142] The second service may expose one or more APIs for operating the first K8S cluster. The first service may send a corresponding interface call request to the second service based on the received first request, and the interface call request may be used to call the API provided by the second service.

[0143] In actual applications, the interface call request sent by the first service to the second service based on the first request and the first request received by the first service are used to request the same operation and maintenance operation on the same K8S cluster. Therefore, the first service sending the interface call request to the second service based on the first request can also be understood as the first service forwarding the first request to the second service.

[0144] It should be noted that although both the first service and the second service can expose one or more APIs for operating the first K8S cluster, the API exposed by the first service is not the same as the API exposed by the second service. After the API exposed by the first service is called, the first service can first perform pre-processing. For example, the pre-processing can include processing such as user permission verification. Then the first service can call the corresponding API exposed by the second service based on its own called API. After the API exposed by the second service is called, the second service can communicate with the interface service component of the cluster based on its own called API.

[0145] In actual applications, the interface service component can be the API Server component of the K8S cluster.

[0146] In actual applications, after receiving the first request forwarded by the first service, the second service can communicate with the interface service component of the K8S cluster based on the first request, thereby controlling the interface service component of the cluster to perform actual operation and maintenance operations, such as querying the resources in the cluster by the interface service component, or conducting an interactive session in the Pod container.

[0147] It can be seen that in the embodiment of the present application, the operation and maintenance system can parse the first instruction input by the user into a first request, and based on the processing of the first request by the first service and the second service, control the interface service component of the first K8S cluster to perform the operation and maintenance operation corresponding to the first instruction, which is equivalent to realizing: passing the first instruction to the K8S cluster and executing the first instruction inside the K8S cluster. It can be understood that the instruction can support various types of operation and maintenance operations, and after the instruction is passed to the K8S cluster, it can actually operate various types of resources in the K8S cluster, for example, managing Pod-level container resources and conducting interactive sessions, etc., so as to manage rich cluster resources in a diversified manner. In addition, in the embodiment of the present application, the user can conveniently indicate the K8S cluster to be operated and managed by the operation and maintenance system based on the selection operation, which simplifies the operation of the operation and maintenance system. Compared with the related art, the operation and maintenance system provided in the embodiment of the present application is relatively simple to operate, and supports a rich type of cluster resources for management. It can still efficiently manage the K8S cluster in a large-scale cluster scenario, thereby improving the operation and maintenance efficiency.

[0148] In actual applications, before the user selects the first K8S cluster on the first platform, the first platform needs to determine the K8S cluster available for the user to select. Based on this, the first service needs to establish an association with the K8S cluster in advance.

[0149] In one embodiment, the second service is further used to:

[0150] The second service sends a second request to the first service; the second request is used to request to register the cluster where the second service is located with the first service.

[0151] In actual applications, the second service can be bound to a K8S service account and cluster rules, which can give the second service full permissions to operate the K8S cluster. After the second service is set up in the cluster, it can log in to the K8S cluster based on the bound K8S service account and cluster rules, so that the second service supports communication with the interface service component of the K8S cluster, which is equivalent to establishing a continuous communication channel between the second service and the K8S cluster.

[0152] In actual applications, the second service after logging in can be understood as a user with full permissions to operate the K8S cluster. Therefore, the second service can also be described as a cluster management client.

[0153] In actual applications, the second service can be compatible with multiple different versions of K8S clusters. For example, the second service can be compatible with multiple versions of K8S clusters such as 1.14, 1.16, 1.18, 1.20, 1.22 and 1.24. In the case where the K8S cluster where the second service is located is a K8S cluster compatible with the second service, the second service can support logging into the K8S cluster and supporting communication with the interface service component in the K8S cluster.

[0154] In actual applications, after logging into the K8S cluster, the second service can actively send a first request to the first service. After receiving the first request, the first service can complete the registration of the K8S cluster based on the first request. The first request can be regarded as a registration request. The first request can carry the registration information of the corresponding K8S cluster. Exemplarily, the registration information may include one or more of the following of the corresponding K8S cluster: identification, access credentials, and deployed network area. The first service can obtain the registration information based on the first request and store the registration information locally in the first service to complete the registration of the K8S cluster.

[0155] In actual applications, after registering the K8S cluster, the first service can actively initiate a request to the second service set in the K8S cluster, which is equivalent to establishing a long connection channel between the first service and the second service corresponding to the K8S cluster, and can also be regarded as establishing an association between the first service and the K8S cluster. In this way, the first service can actively send a request to the second service to perform operation and maintenance operations on the K8S cluster where the second service is located.

[0156] In actual applications, the first platform can determine the registered K8S cluster as the K8S cluster available for user selection. Exemplarily, the first platform can actively call the relevant interface of the first service to obtain the registered K8S cluster, and then display the obtained K8S cluster in the interface.

[0157] In the related art, the K8S service account is stored separately from the K8S cluster, for example, in a server deployed in a different network area from the K8S cluster. In this way, the configuration information corresponding to the K8S service account, such as the kube-config file, needs to be stored in plain text in the server, which reduces the security of operation and maintenance. In addition, the user needs to actively execute instructions related to logging into the K8S cluster and control the server to send a login request to the K8S cluster to establish an association between the server and the K8S cluster. The operation is relatively cumbersome and reduces the efficiency of operation and maintenance.

[0158] In the embodiment of the present application, the second service is set in the K8S cluster, so that the K8S service account can be stored in the K8S cluster and is not easily stolen, thereby improving the security of operation and maintenance. In addition, after being set in the K8S cluster, the second service actively logs in to the K8S cluster and then actively sends a registration request to the first service, without the need for the user to control the second service to send a login request to the K8S cluster, which simplifies the operation and improves the efficiency of operation and maintenance.

[0159] In actual applications, the first service and the K8S cluster may be deployed in different network areas. For security reasons, there is network isolation between services deployed in different network areas, that is, they cannot communicate directly.

[0160] In one embodiment, the operation and maintenance system further includes: one or more proxy nodes; each of the one or more proxy nodes corresponds to a network area;

[0161] Correspondingly, when the first service and the first K8S cluster are deployed in different network areas, the first service forwards the first request to the second service in the first K8S cluster, including:

[0162] The first service forwards the first request to the proxy node corresponding to the network area where the first K8S cluster is located;

[0163] The proxy node corresponding to the network area where the first K8S cluster is located forwards the first request to the second service in the first K8S cluster.

[0164] In actual applications, after receiving the first request sent by the first platform, the first service can determine the network area where the first K8S cluster is located based on the registration information of the first K8S cluster stored locally, and then determine whether the first service is deployed in a different network area from the first K8S cluster.

[0165] In actual applications, each K8S cluster deployed in a different network area from the first service can have a proxy node, which can be used to forward requests from the external network area to the corresponding K8S cluster, and forward requests from the corresponding K8S cluster to the service deployed in the external network area, thereby realizing communication between services across network areas. Here, the external network area can be understood as a network area different from the network area where the corresponding K8S cluster is located. In this way, based on the forwarding of the proxy node, the first service can achieve unified management of multiple K8S clusters.

[0166] In actual applications, the proxy node can perform encrypted forwarding based on the SSL protocol or TLS protocol during the forwarding process, thereby protecting data transmission and further improving the security of operation and maintenance.

[0167] In actual applications, when the first service and the first K8S cluster are deployed in different network areas, the first service and the first K8S cluster are in a cross-network relationship, that is, there is network isolation. Based on the forwarding of the proxy node corresponding to the first K8S cluster, communication between the first service and the first K8S cluster can be achieved, so that the second service in the first K8S cluster can receive the first request forwarded by the first service.

[0168] In actual applications, when the first service and the first K8S cluster are deployed in the same network area, there is a direct connection between the first service and the first K8S cluster, that is, there is no network isolation. The second service in the first K8S cluster can directly receive the first request forwarded by the first service, and does not require forwarding based on a proxy node.

[0169] In actual applications, in order to further improve the security of operation and maintenance, the first service can perform permission verification on the user when forwarding the first request to the second service, that is, perform authentication.

[0170] In one embodiment, the first service forwards the first request to the second service in the first K8S cluster, including:

[0171] The first service determines whether the user has the execution authority of the operation and maintenance operation corresponding to the first instruction based on the setting service and the first request; the setting service is used to verify the authority of the user;

[0172] When the user has the execution authority of the operation and maintenance operation corresponding to the first instruction, the first service forwards the first request to the second service in the first K8S cluster.

[0173] In actual applications, the setting service can also be called the permission center, which can be used to verify the permissions of users.

[0174] In actual applications, after receiving the first request sent by the first platform, the first service can parse the target verification information based on the first request. Exemplarily, the target verification information may include one or more of the following: the operation and maintenance operation corresponding to the first instruction, the user identifier, and the cluster information of the first K8S cluster. Then the first service can send an authentication request to the setting service, that is, call the setting service, and determine whether the user has the execution authority of the operation and maintenance operation corresponding to the first instruction based on the response returned by the setting service based on the authentication request. Among them, the target verification information can be carried in the authentication request. In the case where the user has the execution authority of the operation and maintenance operation corresponding to the first instruction, it can be regarded as the authentication of the user passed, and the first service is allowed to forward the first request to the second service in the first K8S cluster. In the case where the user does not have the execution authority of the operation and maintenance operation corresponding to the first instruction, it can be regarded as the authentication of the user failed, and the first service is not allowed to forward the first request to the second service in the first K8S cluster.

[0175] In actual applications, the first request forwarded by the first service to the second service in the first K8S cluster may carry the access credentials of the first K8S cluster.

[0176] In one embodiment, the first service determines whether the user has execution authority for the operation and maintenance operation corresponding to the first instruction based on the setting service and the first request, including:

[0177] The first service parses the target object of the operation and maintenance operation corresponding to the first instruction based on the first request;

[0178] The first service sends a third request to the setting service, and determines, based on a response returned by the setting service according to the third request, whether the user has execution authority to perform the operation and maintenance operation on the target object of the operation and maintenance operation corresponding to the first instruction.

[0179] In actual applications, the third request can be understood as an authentication request, and the third request can carry the target object of the operation and maintenance operation corresponding to the first instruction.

[0180] In actual applications, after receiving the third request, the setting service can determine based on the third request: the execution permission that the user needs to have in order to perform the operation and maintenance operation on the target object of the operation and maintenance operation corresponding to the first instruction, and then compare the permission that the user already has with the determined execution permission that needs to be possessed to determine whether the user has the execution permission to perform the operation and maintenance operation on the target object of the operation and maintenance operation corresponding to the first instruction, and obtain a judgment result. Then, the setting server carries the judgment result in the returned response.

[0181] In actual applications, the first service may first determine, based on the target object of the operation and maintenance operation corresponding to the first instruction, the execution permission that the user needs to have in order to perform the operation and maintenance operation on the target object. Then, after receiving the third request, the setting service may determine whether the user has the determined execution permission, obtain a determination result, and carry the determination result in the returned response.

[0182] In actual applications, the first service can forward the first request to the second service in the first K8S cluster if the user has the execution authority to perform the operation and maintenance operation on the target object of the operation and maintenance operation corresponding to the first instruction.

[0183] In one embodiment, the category of the target object of the operation and maintenance operation includes one of the following: project, cluster, business, and namespace.

[0184] In practical applications, the type of the target object of the operation and maintenance operation can also be expressed as the dimension of the operation and maintenance operation.

[0185] In actual applications, a project can correspond to one or more clusters. For example, project 1 can correspond to two clusters, namely cluster 1 and cluster 2. When the category of the target object of the operation and maintenance operation is a project, a single operation and maintenance operation can perform batch processing on all clusters corresponding to the project, that is, batch processing on cluster resources in all clusters corresponding to the project. For example, when the target object of the operation and maintenance operation is project 1 in the previous example, a single operation and maintenance operation can perform batch processing on cluster 1 and cluster 2.

[0186] A cluster can correspond to one or more businesses, and each business corresponds to corresponding cluster resources. For example, cluster 1 can correspond to two businesses, namely business 1 and business 2, where business 1 can correspond to containers 1 to 5 in cluster 1, and business 2 can correspond to containers 6 to 9 in cluster 1. In the case where the category of the target object of the operation and maintenance operation is a cluster, a single operation and maintenance operation can batch process the cluster resources corresponding to all businesses corresponding to the cluster. For example, in the case where the target object of the operation and maintenance operation is cluster 1 in the previous example, a single operation and maintenance operation can batch process the cluster resources corresponding to business 1 and business 2, namely containers 1 to 9.

[0187] A business can correspond to one or more namespaces, and each namespace corresponds to corresponding cluster resources. Exemplarily, business 1 in cluster 1 can correspond to two namespaces, namely namespace 1 and namespace 2, wherein namespace 1 can correspond to container 1 in cluster 1, and namespace 2 can correspond to containers 2 to 5 in cluster 1. In the case where the category of the target object of the operation and maintenance operation is business, a single operation and maintenance operation can perform batch processing on the cluster resources corresponding to all namespaces corresponding to the business. Exemplarily, in the case where the target object of the operation and maintenance operation is business 1 in the previous example, a single operation and maintenance operation can perform batch processing on the cluster resources corresponding to all namespaces corresponding to business 1, namely containers 1 to 5.

[0188] When the target object of the operation is a namespace, a single operation can perform batch processing on all cluster resources corresponding to the namespace. For example, namespace 2 can correspond to containers 2 to 5 in cluster 1. When the target object of the operation is namespace 2, a single operation can perform batch processing on all cluster resources corresponding to namespace 2, i.e., containers 2 to 5.

[0189] In practical applications, the type of the target object of the operation and maintenance operation can also be expressed as the dimension of the operation and maintenance operation.

[0190] In the related technology, operation and maintenance operations can only be performed on a single cluster, that is, operation and maintenance operations can only be performed in the cluster dimension, and complex permission control scenarios cannot be implemented. For example, a permission control scenario that cannot be implemented by the related technology may be: the operation object of a single operation and maintenance operation by the R&D personnel can only be a single cluster, and the operation object of a single operation and maintenance operation by the operation and maintenance personnel may include: multiple clusters corresponding to the same project.

[0191] In the embodiment of the present application, the first service forwards or does not forward the first request to the second service based on the authentication result of the user's execution authority to perform the operation and maintenance operation on the target object of the operation and maintenance operation corresponding to the first instruction. That is, the user is authenticated based on the dimension of the operation and maintenance operation corresponding to the first instruction, thereby realizing complex permission control scenarios, increasing the security of operation and maintenance, and improving operation and maintenance efficiency.

[0192] The present application is further described in detail below in conjunction with application examples.

[0193] The present application embodiment provides an operation and maintenance system, see Figure 3 , the operation and maintenance system includes: BCS-SaaS, BCS-Service, BCS-Proxy and BCS-Agent. Among them, BCS-SaaS is equivalent to the first platform in the embodiment of the present application, webconsole is equivalent to the operation interface of the first platform; BCS-Service is equivalent to the first service in the embodiment of the present application, bcs-api is equivalent to the module for sending and receiving requests in the first service; BCS-Proxy is equivalent to the proxy node in the embodiment of the present application; BCS-Agent is equivalent to the second service in the embodiment of the present application; API Server is equivalent to the interface service component in the embodiment of the present application.

[0194] See also Figure 4 The interactive process of the operation and maintenance system when performing operation and maintenance based on the operation and maintenance method provided in the embodiment of the present application mainly includes the following steps:

[0195] Step 1: BCS-SaaS parses the first instruction input by the user into a first request and sends the first request to BCS-Service.

[0196] Among them, the first instruction is used to instruct the operation and maintenance of the first K8S cluster selected by the user in BCS-SaaS.

[0197] Step 2: Based on the received first request, BCS-Service sends a third request to the platform authority center to authenticate the user.

[0198] In actual applications, the platform authority center is equivalent to the setting service in the embodiment of the present application.

[0199] If the user authentication is successful, proceed to step 3;

[0200] If the user authentication fails, an error indication may be returned to BCS-SaaS.

[0201] Step 3: BCS-Service forwards the first request to BCS-Agent.

[0202] In actual applications, when BCS-Service and the first K8S cluster are deployed in different network areas, BCS-Service forwards the first request to BCS-Proxy, and BCS-Proxy forwards the first request to BCS-Agent in the first K8S cluster; when BCS-Service and the first K8S cluster are deployed in the same network area, BCS-Service forwards the first request directly to BCS-Agent in the first K8S cluster.

[0203] Step 4: Based on the received first request, BCS-Agent communicates with the API Server of the first K8S cluster to perform operation and maintenance operations on the first K8S cluster.

[0204] In the application embodiment of the present application, the user can conveniently instruct the operation and maintenance system to operate and manage the K8S cluster based on the selection operation. The operation and maintenance system can request BCS-Service from BCS-SaaS based on the first instruction, and then request BCS-Agent set in the K8S cluster from BCS-Service to perform operation and maintenance operations, which is equivalent to realizing the transmission of instructions, thereby enabling diversified management of rich cluster resources. Compared with related technologies, the operation and maintenance system is easy to operate, supports rich types of cluster resources to be managed, and can still efficiently manage K8S clusters in large-scale cluster scenarios, thereby improving operation and maintenance efficiency.

[0205] It should be noted that: "first", "second", etc. are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequence.

[0206] The term "and / or" herein is only a description of the association relationship of associated objects, indicating that three relationships may exist. For example, A and / or B can represent: A exists alone, A and B exist at the same time, and B exists alone. In addition, the term "at least one" herein represents any combination of at least two of any one or more of a plurality. For example, at least one of A, B, and C can represent any one or more elements selected from the set consisting of A, B, and C.

[0207] In addition, the technical solutions described in the embodiments of the present application can be combined arbitrarily without conflict.

[0208] The above description is only a preferred embodiment of the present application and is not intended to limit the protection scope of the present application.

Claims

1. An operation and maintenance method, characterized in that: Applied to an operation and maintenance system, the operation and maintenance system includes: a first platform, a first service, and one or more second services; each of the one or more second services is respectively set in a K8S cluster; the method includes: The first platform parses the first instruction input by the user into a first request, and sends the first request to the first service; the first instruction is used to instruct to perform operation and maintenance operations on the first K8S cluster selected by the user in the first platform; the first request is used to request the first service to perform operation and maintenance operations on the first K8S cluster; The first service forwards the first request to the second service in the first K8S cluster; The second service in the first K8S cluster communicates with the interface service component of the first K8S cluster based on the first request to perform operation and maintenance operations on the first K8S cluster.

2. The method according to claim 1, characterized in that The method further comprises: The second service sends a second request to the first service; the second request is used to request to register the cluster where the second service is located with the first service.

3. The method according to claim 1, characterized in that The operation and maintenance system further includes: one or more proxy nodes; each of the one or more proxy nodes corresponds to a network area; Correspondingly, when the first service and the first K8S cluster are deployed in different network areas, the first service forwards the first request to the second service in the first K8S cluster, including: The first service forwards the first request to a proxy node corresponding to the network area where the first K8S cluster is located; The proxy node corresponding to the network area where the first K8S cluster is located forwards the first request to the second service in the first K8S cluster.

4. The method according to claim 1, characterized in that: The first service forwards the first request to the second service in the first K8S cluster, including: The first service determines whether the user has execution authority for the operation and maintenance operation corresponding to the first instruction based on the setting service and the first request; the setting service is used to perform authority verification on the user; In a case where the user has execution authority for the operation and maintenance corresponding to the first instruction, the first service forwards the first request to the second service in the first K8S cluster.

5. The method according to claim 4, characterized in that The first service determines, based on the setting service and the first request, whether the user has execution authority for the operation and maintenance operation corresponding to the first instruction, including: The first service parses, based on the first request, a target object of the operation and maintenance operation corresponding to the first instruction; The first service sends a third request to the setting service, and determines, based on a response returned by the setting service according to the third request, whether the user has execution authority to perform an operation and maintenance operation on a target object of the operation and maintenance operation corresponding to the first instruction.

6. The method according to claim 5, characterized in that The category of the target object of the operation and maintenance operation includes one of the following: project, cluster, business, and namespace.

7. The method according to claim 1, characterized in that One or more K8S clusters are displayed in the visualization interface of the first platform, and the method further includes: The first platform determines the first K8S cluster from the one or more K8S clusters based on the selection operation of the user in the visualization interface.

8. An operation and maintenance system, characterized in that: include: A first platform, a first service, and one or more second services; each of the one or more second services is respectively set in a K8S cluster; wherein, The first platform is used to parse the first instruction input by the user into a first request, and send the first request to the first service; the first instruction is used to instruct to perform operation and maintenance operations on the first K8S cluster selected by the user in the first platform; the first request is used to request the first service to perform operation and maintenance operations on the first K8S cluster; The first service is used to forward the first request to the second service in the first K8S cluster; The second service in the first K8S cluster is used to communicate with the interface service component of the first K8S cluster based on the first request to perform operation and maintenance operations on the first K8S cluster.

9. The method according to claim 8, characterized in that The second service is also used to: The second service sends a second request to the first service; the second request is used to request to register the cluster where the second service is located with the first service.

10. The method according to claim 8, characterized in that The operation and maintenance system further includes: one or more proxy nodes; each of the one or more proxy nodes corresponds to a network area; Correspondingly, when the first service and the first K8S cluster are deployed in different network areas, the first service forwards the first request to the second service in the first K8S cluster, including: The first service forwards the first request to a proxy node corresponding to the network area where the first K8S cluster is located; The proxy node corresponding to the network area where the first K8S cluster is located forwards the first request to the second service in the first K8S cluster.

11. The method according to claim 8, characterized in that The first service forwards the first request to the second service in the first K8S cluster, including: The first service determines whether the user has execution authority for the operation and maintenance operation corresponding to the first instruction based on the setting service and the first request; the setting service is used to perform authority verification on the user; In a case where the user has execution authority for the operation and maintenance corresponding to the first instruction, the first service forwards the first request to the second service in the first K8S cluster.

12. The method according to claim 11, characterized in that The first service determines, based on the setting service and the first request, whether the user has execution authority for the operation and maintenance operation corresponding to the first instruction, including: The first service parses, based on the first request, a target object of the operation and maintenance operation corresponding to the first instruction; The first service sends a third request to the setting service, and determines, based on a response returned by the setting service according to the third request, whether the user has execution authority to perform an operation and maintenance operation on a target object of the operation and maintenance operation corresponding to the first instruction.

13. The method according to claim 12, characterized in that The category of the target object of the operation and maintenance operation includes one of the following: project, cluster, business, and namespace.

14. The method according to claim 8, characterized in that One or more K8S clusters are displayed in the visualization interface of the first platform. The first platform is also used for: Based on the selection operation of the user in the visualization interface, the first K8S cluster is determined from the one or more K8S clusters.

Citation Information

Patent Citations

  • Service invocation request routing methods, service creation methods and devices

    CN114938396A

  • Deployment operation and maintenance method, device and equipment of container cluster and storage medium

    CN117215727A

  • Computing resource management method and apparatus

    WO2024098926A1