Cloud physical host security group management method, device, equipment and medium
By introducing preset security group service plug-ins and agents into the OpenStack cloud platform to monitor and manage cloud physical host security groups, the problem that the neutron component does not support cloud physical host security group management is solved, achieving a wider application scenario and a better user experience.
Patent Information
- Application Number
- CN202510224826.4
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-02-27
- Publication Date
- 2025-05-13
- Estimated Expiration
- 2045-02-27
AI Technical Summary
In the existing OpenStack cloud platform environment, the neutron component does not support the management and configuration of cloud physical host security groups, which seriously restricts the application scenarios and business intervals of cloud physical host services and reduces the usage experience of cloud platform.
Provide a cloud physical host security group management method, which monitors the first message and the second message through the preset security group service plug-in and the preset security group service agent, obtains target information, and determines the target security group based on this information, and sends it to the physical switch to update the security group rules.
It realizes the management and configuration of cloud physical host security groups, expands the application scenarios and business intervals of cloud physical host services, and improves the user experience of cloud platform.
Smart Images

Figure CN119996020A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the computer field, and in particular to a cloud physical host security group management method, device, equipment and medium. Background Art
[0002] With the development of cloud platform technology, cloud physical host services are becoming more and more popular among users because they can provide users with computing and network resources similar to traditional physical servers. Cloud physical host security groups are also gradually becoming a key security technology in cloud platform security. As a type of cloud platform firewall technology, cloud physical host security groups are used to control network access traffic in and out of cloud physical hosts.
[0003] Nowadays, in the cloud platform environment based on OpenStack (an open source cloud computing management platform project), the functional component neutron responsible for virtual network services does not support the management and configuration of cloud physical host security groups, which seriously restricts the application scenarios and business ranges of cloud physical host services and greatly reduces the user experience of the cloud platform. Summary of the invention
[0004] In view of this, the purpose of this application is to provide a cloud physical host security group management method, device, equipment and medium, which can manage and configure the cloud physical host security group. The specific scheme is as follows: In a first aspect, the present application provides a cloud physical host security group management method, which is applied to a cloud platform, wherein the cloud platform includes a preset security group service plug-in and a preset security group service agent, and the cloud physical host security group management method includes: Based on a preset security group service plug-in and a preset security group service agent, the first message and the second message are monitored respectively; When the preset security group service plug-in detects the first message, the first target information corresponding to the first message is obtained, and the first target information is sent to the preset security group service agent, so that the preset security group service agent determines a first target security group based on the first target information, and sends the first target security group to the physical switch, so that the physical switch updates its own security group rules based on the first target security group, so as to manage the security group of the cloud physical host; When the preset security group service agent detects the second message, it obtains the second target information corresponding to the second message and sends a database information request to the preset security group service plug-in to obtain the database information sent by the preset security group service plug-in, determines the second target security group based on the second target information and the database information, and sends the second target security group to the physical switch, so that the physical switch updates its own security group rules based on the second target security group to manage the security group of the cloud physical host.
[0005] Optionally, the monitoring of the first message and the second message based on the preset security group service plug-in and the preset security group service agent respectively includes: Controlling a preset security group service plug-in and a preset security group service agent to start, and binding the preset security group service plug-in and the preset security group service agent to the first function and the second function respectively; The first message is monitored based on the first function bound to the preset security group service plug-in, and the second message is monitored based on the second function bound to the preset security group service agent.
[0006] Optionally, the first message includes a virtual network card deletion message; the second message includes a virtual network card update message, a security group deletion message, a security group update message, a security group rule deletion message and a security group rule update message.
[0007] Optionally, the first target information includes a port identifier, an Internet Protocol address, a security group identifier and a physical address corresponding to the deleted virtual network card.
[0008] Optionally, the preset security group service agent determines a first target security group based on the first target information, and sends the first target security group to the physical switch, including: The preset security group service agent determines, based on the first target information, whether the virtual network card corresponding to the first target information is a network card of the cloud physical host; If the virtual network card is a network card of a cloud physical host, a first target security group is determined, and the first target security group is sent to the physical switch; the first target security group is a security group after clearing the security group rules corresponding to the virtual network card in the physical switch; If the virtual network card is not the network card of the cloud physical host, the preset security group service agent sends a target database information request to the preset security group service plug-in based on the remote control call operation, so as to redetermine the third target security group corresponding to the cloud physical host according to the database information obtained from the preset security group service plug-in, and send the third target security group to the physical switch, so that the physical switch updates its own security group rules based on the third target security group.
[0009] Optionally, the cloud physical host security group management method further includes: The preset security group service agent is connected to the physical switch based on the secure shell protocol, and sends the determined target security group to the physical switch to update the security group rules in the physical switch; The target security group and the security group rule in the physical switch are both in the form of an access control list that can be understood and executed by the physical switch.
[0010] Optionally, the preset security group service plug-in and the preset security group service agent are both located on a control node in the cloud platform; Accordingly, the method further includes: Based on the control node, the preset security group service plug-in and the preset security group service agent are controlled to obtain target information, so that the preset security group service agent converts the security group rules corresponding to the current cloud platform obtained based on the target information into the form of security group rules that can be executed by the physical switch, and sends the converted security group rules to the physical switch.
[0011] In a second aspect, the present application provides a cloud physical host security group management device, which is applied to a cloud platform, wherein the cloud platform includes a preset security group service plug-in and a preset security group service agent, and the cloud physical host security group management device includes: A message monitoring module, used to monitor the first message and the second message respectively based on a preset security group service plug-in and a preset security group service agent; a first management module, configured to obtain first target information corresponding to the first message when the preset security group service plug-in detects the first message, and send the first target information to the preset security group service agent, so that the preset security group service agent determines a first target security group based on the first target information, and sends the first target security group to the physical switch, so that the physical switch updates its own security group rules based on the first target security group, so as to manage the security group of the cloud physical host; A second management module is used to obtain second target information corresponding to the second message and send a database information request to the preset security group service plug-in to obtain the database information sent by the preset security group service plug-in when the preset security group service agent monitors the second message, determine a second target security group based on the second target information and the database information, and send the second target security group to the physical switch, so that the physical switch updates its own security group rules based on the second target security group to manage the security group of the cloud physical host.
[0012] In a third aspect, the present application provides an electronic device, including: Memory, used to store computer programs; The processor is used to execute the computer program to implement the aforementioned cloud physical host security group management method.
[0013] In a fourth aspect, the present application provides a computer-readable storage medium for storing a computer program, wherein the computer program implements the aforementioned cloud physical host security group management method when executed by a processor.
[0014] In the present application, the first message and the second message are monitored respectively based on the preset security group service plug-in and the preset security group service agent; when the preset security group service plug-in monitors the first message, the first target information corresponding to the first message is obtained, and the first target information is sent to the preset security group service agent, so that the preset security group service agent determines the first target security group based on the first target information, and sends the first target security group to the physical switch, so that the physical switch updates its own security group rules based on the first target security group to manage the security group of the cloud physical host; when the preset security group service agent monitors the second message, the second target information corresponding to the second message is obtained and a database information request is sent to the preset security group service plug-in to obtain the database information sent by the preset security group service plug-in, the second target security group is determined based on the second target information and the database information, and the second target security group is sent to the physical switch, so that the physical switch updates its own security group rules based on the second target security group to manage the security group of the cloud physical host. As can be seen from the above, the present application monitors the messages in the cloud platform through the preset security group service plug-in and the preset security group service agent to obtain the corresponding target information, controls the preset security group service agent to determine the target security group corresponding to the current cloud platform based on the target information, and sends the target security group to the physical switch, so that the physical switch updates its own security group rules based on the target security group to manage the security group corresponding to the cloud physical host. BRIEF DESCRIPTION OF THE DRAWINGS
[0015] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, the drawings described below are only embodiments of the present application. For ordinary technicians in this field, other drawings can be obtained based on the provided drawings without paying any creative work.
[0016] Figure 1 A flow chart of a cloud physical host security group management method disclosed in this application; Figure 2 A schematic diagram of a specific cloud physical host security group management method disclosed in this application; Figure 3 A schematic diagram of a first message processing disclosed in this application; Figure 4 A schematic diagram of a second message processing disclosed in this application; Figure 5 A schematic diagram of a device structure disclosed in this application; Figure 6 This is a schematic diagram of the structure of an electronic device disclosed in this application. DETAILED DESCRIPTION
[0017] The following will be combined with the drawings in the embodiments of the present application to clearly and completely describe the technical solutions in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.
[0018] With the development of cloud platform technology, cloud physical host services are becoming more and more popular among users because they can provide users with computing and network resources similar to traditional physical servers. Cloud physical host security groups have gradually become a key security technology in cloud platform security. As a type of cloud platform firewall technology, it is used to control network access traffic in and out of cloud physical hosts. Nowadays, in the cloud platform environment with OpenStack (an open source cloud computing management platform project) as the technical base, the functional component neutron responsible for virtual network services does not support the management and configuration of cloud physical host security groups, which seriously restricts the application scenarios and business ranges of cloud physical host services, and greatly reduces the user experience of the cloud platform. To this end, the present application provides a cloud physical host security group management method that can manage and configure the security groups corresponding to the cloud physical hosts.
[0019] See also Figure 1 As shown, the embodiment of the present application discloses a cloud physical host security group management method, including: Step S11: monitor the first message and the second message respectively based on the preset security group service plug-in and the preset security group service agent.
[0020] In this embodiment, a preset security group service plug-in and a preset security group service agent are first deployed on a control node in a cloud platform environment, and then the first message and the second message are monitored based on the preset security group service plug-in and the preset security group service agent. Specifically, the preset security group service plug-in and the preset security group service agent are first controlled to be turned on, and the preset security group service plug-in and the preset security group service agent are respectively bound to the first function and the second function; then the first message is monitored based on the first function bound to the preset security group service plug-in, and the second message is monitored based on the second function bound to the preset security group service agent.
[0021] The first message includes but is not limited to a virtual network card deletion message; the second message includes but is not limited to a virtual network card update message, a security group deletion message, a security group update message, a security group rule deletion message, and a security group rule update message. The first function and the second function can be hook functions. When a virtual network card deletion operation occurs on the cloud platform, the preset security group service plug-in can perceive the virtual network card deletion message through the first function; or when a virtual network card update operation occurs on the cloud platform, the preset security group service agent can perceive the virtual network card update message through the second function.
[0022] Through the above method, different types of messages in the cloud platform can be accurately perceived by the corresponding components, laying the foundation for further processing and response to these messages.
[0023] Step S12: When the preset security group service plug-in detects the first message, it obtains the first target information corresponding to the first message, and sends the first target information to the preset security group service agent, so that the preset security group service agent determines the first target security group based on the first target information, and sends the first target security group to the physical switch, so that the physical switch updates its own security group rules based on the first target security group to manage the security group of the cloud physical host.
[0024] In this embodiment, when the preset security group service plug-in detects the first message, the first target information corresponding to the first message is first obtained, wherein the first target information includes but is not limited to the port identifier, Internet Protocol address, security group identifier and physical address corresponding to the deleted virtual network card. For example, if the preset security group service plug-in detects the virtual network card deletion message, the port identifier, Internet Protocol address, security group identifier and physical address corresponding to the deleted virtual network card are obtained as the first target information, and then the first target information is sent to the preset security group service agent based on the remote control call (RPC, Remote Procedure Call) operation.
[0025] After receiving the first target information, the preset security group service agent determines the first target security group based on the first target information, and sends the first target security group to the physical switch. Specifically, the preset security group service agent determines whether the virtual network card corresponding to the first target information is the network card of the cloud physical host based on the first target information; if the virtual network card is the network card of the cloud physical host, the first target security group is determined, and the first target security group is sent to the physical switch; wherein, the first target security group is the security group after the security group rules corresponding to the virtual network card in the physical switch are cleared; if the virtual network card is not the network card of the cloud physical host, the preset security group service agent sends a target database information request to the preset security group service plug-in based on the remote control call operation, so as to re-determine the third target security group corresponding to the cloud physical host according to the database information obtained from the preset security group service plug-in, and send the third target security group to the physical switch, so that the physical switch updates its own security group rules based on the third target security group.
[0026] It should be noted that the virtual network card corresponding to the first target information can be the network card of the cloud physical host or the virtual network card of the virtual machine. If the virtual network card is the network card of the cloud physical host, then deleting the virtual network card may indicate that the cloud physical host needs to make major adjustments to the network architecture, migrate to a new network environment, or the security policy of the host is about to undergo fundamental changes. In these cases, clearing the original security group rules can avoid the interference of the old rules with the new operations and ensure that the new security policy or network configuration can be implemented smoothly. If the virtual network card is not the network card of the cloud physical host, although the operation of the non-cloud physical host network card seems to have no direct connection with the cloud physical host, there may be indirect network relationships and dependencies in the complex network environment of the cloud platform. For example, a change in the virtual network card configuration of a virtual machine may affect the topology of the entire virtual network, and thus affect the network access path and security policy of the cloud physical host. Therefore, it is necessary to use the preset security group service agent to send a target database information request to the preset security group service plug-in based on the remote control call operation to obtain relevant database information, such as security group association, cloud physical host information, virtual network card information, network topology and environment information, etc., in order to re-evaluate and determine the security group rules corresponding to the cloud physical host.
[0027] Step S13: When the preset security group service agent detects the second message, it obtains the second target information corresponding to the second message and sends a database information request to the preset security group service plug-in to obtain the database information sent by the preset security group service plug-in, determines the second target security group based on the second target information and the database information, and sends the second target security group to the physical switch, so that the physical switch updates its own security group rules based on the second target security group to manage the security group of the cloud physical host.
[0028] In this embodiment, when the preset security group service agent obtains the second target information, in order to more comprehensively and accurately determine the security group rules, a database information request can be sent to the preset security group service plug-in based on the remote control call operation, and database information related to security group management can be obtained from the database to determine the second target security group based on the second target information and the database information. The second target security group can meet the security requirements of the cloud physical host and adapt to the entire network environment. After determining the second target security group, the preset security group service agent sends the second target security group to the physical switch.
[0029] It should be noted that the physical switch is a key device in the network, responsible for actual network data forwarding and traffic control. The preset security group service agent can connect to the physical switch based on the Secure Shell (SSH) protocol and send the determined target security group to the physical switch to update the security group rules in the physical switch. The target security group and the security group rule in the physical switch are both in the form of access control lists (ACLs) that can be understood and executed by the physical switch.
[0030] It can be understood that this embodiment controls the preset security group service plug-in and the preset security group service agent to obtain target information based on the control node, so that the preset security group service agent converts the security group rules corresponding to the current cloud platform obtained based on the target information into the form of security group rules that can be executed by the physical switch, and sends the converted security group rules to the physical switch, so that the physical switch updates its own security group rules to manage the security group of the cloud physical host.
[0031] As can be seen from the above, this embodiment monitors the messages in the cloud platform through the preset security group service plug-in and the preset security group service agent to obtain the corresponding target information, controls the preset security group service agent to determine the target security group corresponding to the current cloud platform based on the target information, and sends the target security group to the physical switch, so that the physical switch updates its own security group rules based on the target security group to manage the security group corresponding to the cloud physical host. The application scenarios and business ranges of the cloud physical host service are expanded, and the user experience of the cloud platform is improved.
[0032] join Figure 2 As shown below, the technical solution in this application is explained by taking the cloud platform with OpenStack as the technical base as an example. Among them, Neutron components are used to be responsible for virtual network services, and a cloud physical host security group service plug-in (bmsg_plugin) is developed on the extended architecture provided by Neutron to provide security group management functions for cloud physical hosts, and bmsg_plugin is deployed on the control node in the cloud platform environment; a cloud physical host security group service agent (bmsg_agent) is developed on the extended architecture provided by Neutron to actually issue and configure cloud physical host security group rules to physical switches, and bmsg_agent is also deployed on the control node of the cloud platform, and the bmsg_plugin plug-in interacts with the bmsg_agent agent through the RPC message mechanism.
[0033] Furthermore, the neutron-server process is the most important service process of the Neutron component. It is essentially a web-server process that runs on the control node and is responsible for starting and managing the bmsg_plugin service plug-in. MessageQueue provides RPC communication services between the plugin and the agent. The L2_Agent process runs on the control node and is responsible for receiving and processing RPC messages from the plugin. At the same time, L2_Agent is responsible for starting and managing the agent.
[0034] There are six main messages that affect the cloud physical host security group rules from the cloud platform, namely, virtual network card deletion message (port_delete); virtual network card update message (port_update); security group deletion message (security_group_delete); security group update message (security_group_update); security group rule deletion message (security_group_rule_delete); and security group rule update message (security_group_rule_update). The bmsg_plugin on the plugin side is responsible for sensing and processing the port_delete message, and the other five messages are sensed and processed by the bmsg_agent.
[0035] For example, see Figure 3 As shown, the processing of the port_delete message is as follows: The neutron-server process on the cloud platform plugin side deploys and starts the bmsg_plugin plug-in. The L2_agent on the cloud platform agent side deploys and starts the bmsg_agent agent. The cloud physical host instance has been normally opened and connected to the cloud platform network through the physical switch (UNIX switch).
[0036] bmsg_plugin starts and registers the port_delete message. Registering the port_delete message means that when a virtual network card is deleted on the cloud platform, bmsg_plugin can sense the virtual network card deletion message through the hook function and obtain the port identifier (port_id), Internet Protocol address (port_ipaddr), security group identifier (port_sgid) and physical address (port_mac) of the virtual network card. The bmsg_plugin then sends the port_id, port_ipaddr, port_sgid and port_mac to the bmsg_agent agent through the RPC message. After receiving the message, bmsg_agent first determines whether the port_id corresponds to the network address of the cloud physical host. card, if so, it is concluded that the security group of the network card is empty and the first target security group is determined; bmsg_agent connects to the physical switch through the SSH protocol and sends the first target security group to the physical switch to update the security group rules corresponding to the cloud physical host network card in the physical switch, which is essentially to clear the ACL rules configured on the physical switch; if port_id is not a cloud physical host network card, the security group rules corresponding to the cloud physical host are recalculated, wherein during the recalculation process, bmsg_agent needs to request relevant database information from bmsg_plugin through the RPC mechanism in reverse, and after the calculation is completed, bmsg_agent connects to the physical switch through the SSH protocol and sends the recalculated third target security group to the physical switch to configure the corresponding ACL rules for the physical switch.
[0037] For example, see Figure 4 As shown in the figure, the processing of security_group_delete, security_group_update, security_group_rule_delete, security_group_rule_update, and port_update messages is as follows: The neutron-server process on the cloud platform plugin side deploys and starts the bmsg_plugin plug-in. The L2_agent on the cloud platform agent side deploys and starts the bmsg_agent agent. The cloud physical host instance has been normally opened and connected to the cloud platform network through the physical switch.
[0038] The bmsg_agent agent starts and registers security_group_delete, security_group_update, security_group_rule_delete, security_group_rule_update, and port_update messages. When the cloud platform performs corresponding operations, the bmsg_agent can perceive the message through the hook function and obtain detailed information of the message; then the bmsg_agent recalculates the security group rules corresponding to the cloud physical host based on the above detailed information. During the recalculation process, the bmsg_agent needs to request the relevant database information from the bmsg_plugin through the RPC mechanism. After the calculation is completed, the bmsg_agent connects to the physical switch through the SSH protocol and sends the recalculated second target security group to the physical switch to configure the corresponding ACL rules for the physical switch.
[0039] As can be seen from the above, this embodiment takes the cloud platform with OpenStack as the technical base as an example, and elaborates on how to manage and configure the cloud physical host security group through the security group service plug-in and the security group service agent. In this way, the cloud platform can directly manage and configure the cloud physical host security group in a unified manner through the Neutron component. The deployment is simple, and there is no need to modify or redevelop the existing network architecture of OpenStack. It only needs to deploy the cloud physical host security group service plug-in and cloud physical host security group service agent developed based on the Neutron component.
[0040] See also Figure 5 As shown, the embodiment of the present application further discloses a cloud physical host security group management device, which is applied to a cloud platform, wherein the cloud platform includes a preset security group service plug-in and a preset security group service agent, and the cloud physical host security group management device includes: A message monitoring module 11, configured to monitor the first message and the second message respectively based on a preset security group service plug-in and a preset security group service agent; A first management module 12 is used for obtaining first target information corresponding to the first message when the preset security group service plug-in detects the first message, and sending the first target information to the preset security group service agent, so that the preset security group service agent determines a first target security group based on the first target information, and sends the first target security group to the physical switch, so that the physical switch updates its own security group rules based on the first target security group, so as to manage the security group of the cloud physical host; The second management module 13 is used to obtain the second target information corresponding to the second message and send a database information request to the preset security group service plug-in to obtain the database information sent by the preset security group service plug-in when the preset security group service agent monitors the second message, determine the second target security group based on the second target information and the database information, and send the second target security group to the physical switch, so that the physical switch updates its own security group rules based on the second target security group to manage the security group of the cloud physical host.
[0041] As can be seen from the above, the present application monitors the messages in the cloud platform through the preset security group service plug-in and the preset security group service agent to obtain the corresponding target information, controls the preset security group service agent to determine the target security group corresponding to the current cloud platform based on the target information, and sends the target security group to the physical switch, so that the physical switch updates its own security group rules based on the target security group to manage the security group corresponding to the cloud physical host.
[0042] In some specific implementations, the message monitoring module 11 includes: A function binding unit, used to control the startup of a preset security group service plug-in and a preset security group service agent, and to bind the preset security group service plug-in and the preset security group service agent to the first function and the second function respectively; A message monitoring unit is used to monitor a first message based on the first function bound to the preset security group service plug-in, and to monitor a second message based on the second function bound to the preset security group service agent.
[0043] In some specific implementations, the first message includes a virtual network card deletion message; the second message includes a virtual network card update message, a security group deletion message, a security group update message, a security group rule deletion message, and a security group rule update message.
[0044] In some specific implementations, the first target information includes a port identifier, an Internet Protocol address, a security group identifier, and a physical address corresponding to the deleted virtual network card.
[0045] In some specific implementations, the first management module 12 includes: A judgment unit, configured to preset a security group service agent to judge, based on the first target information, whether the virtual network card corresponding to the first target information is a network card of a cloud physical host; A first processing unit is configured to determine a first target security group if the virtual network card is a network card of a cloud physical host, and send the first target security group to a physical switch; the first target security group is a security group after clearing the security group rules corresponding to the virtual network card in the physical switch; The second processing unit is used for, if the virtual network card is not the network card of the cloud physical host, the preset security group service agent sends a target database information request to the preset security group service plug-in based on the remote control call operation, so as to redetermine the third target security group corresponding to the cloud physical host according to the database information obtained from the preset security group service plug-in, and send the third target security group to the physical switch, so that the physical switch updates its own security group rules based on the third target security group.
[0046] In some specific implementations, the cloud physical host security group management device further includes: A security group updating unit, configured to preset a security group service agent to connect to a physical switch based on a secure shell protocol, and send the determined target security group to the physical switch to update a security group rule in the physical switch; The target security group and the security group rule in the physical switch are both in the form of an access control list that can be understood and executed by the physical switch.
[0047] In some specific implementations, the preset security group service plug-in and the preset security group service agent are both located on a control node in the cloud platform; Correspondingly, the cloud physical host security group management device further includes: A security group sending unit is used to control the preset security group service plug-in and the preset security group service agent to obtain target information based on the control node, so that the preset security group service agent converts the form of the security group rules corresponding to the current cloud platform obtained based on the target information into the form of security group rules that can be executed by the physical switch, and sends the converted security group rules to the physical switch.
[0048] Furthermore, the present application also discloses an electronic device. Figure 6 This is a structural diagram of an electronic device 20 according to an exemplary embodiment. The content in the diagram cannot be regarded as any limitation on the scope of use of the present application.
[0049] Figure 6A schematic diagram of the structure of an electronic device 20 provided in an embodiment of the present application. The electronic device 20 may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the cloud physical host security group management method disclosed in any of the aforementioned embodiments. In addition, the electronic device 20 in this embodiment may specifically be an electronic computer.
[0050] In this embodiment, the power supply 23 is used to provide working voltage for each hardware device on the electronic device 20; the communication interface 24 can create a data transmission channel between the electronic device 20 and the external device, and the communication protocol it follows is any communication protocol that can be applied to the technical solution of the present application, and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world, and its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0051] In addition, the memory 22, as a carrier for storing resources, can be a read-only memory, a random access memory, a disk or an optical disk, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0052] The operating system 221 is used to manage and control the hardware devices on the electronic device 20 and the computer program 222, which can be Windows Server, Netware, Unix, Linux, etc. In addition to including a computer program that can be used to complete the cloud physical host security group management method performed by the electronic device 20 disclosed in any of the aforementioned embodiments, the computer program 222 can further include a computer program that can be used to complete other specific tasks.
[0053] Furthermore, the present application also discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the cloud physical host security group management method disclosed above is implemented. For the specific steps of the method, reference may be made to the corresponding contents disclosed in the aforementioned embodiments, and no further description will be given here.
[0054] In this specification, each embodiment is described in a progressive manner, and each embodiment focuses on the differences from other embodiments. The same or similar parts between the embodiments can be referred to each other. For the device disclosed in the embodiment, since it corresponds to the method disclosed in the embodiment, the description is relatively simple, and the relevant parts can be referred to the method part.
[0055] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described in the above description according to function. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered to be beyond the scope of this application.
[0056] The steps of the method or algorithm described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in a random access memory (RAM), a memory, a read-only memory (ROM), an electrically programmable ROM, an electrically erasable programmable ROM, a register, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0057] Finally, it should be noted that, in this article, relational terms such as first and second, etc. are only used to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any such actual relationship or order between these entities or operations. Moreover, the terms "include", "comprise" or any other variants thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements includes not only those elements, but also other elements not explicitly listed, or also includes elements inherent to such process, method, article or device. In the absence of further restrictions, the elements defined by the sentence "comprise a ..." do not exclude the presence of other identical elements in the process, method, article or device including the elements.
[0058] The technical solution provided by the present application is introduced in detail above. Specific examples are used in this article to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for general technicians in this field, according to the idea of the present application, there will be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A cloud physical host security group management method, characterized in that: Applied to a cloud platform, wherein the cloud platform includes a preset security group service plug-in and a preset security group service agent, and the cloud physical host security group management method includes: Based on the preset security group service plug-in and the preset security group service agent, the first message and the second message are monitored respectively; When the preset security group service plug-in detects the first message, the first target information corresponding to the first message is obtained, and the first target information is sent to the preset security group service agent, so that the preset security group service agent determines a first target security group based on the first target information, and sends the first target security group to the physical switch, so that the physical switch updates its own security group rules based on the first target security group, so as to manage the security group of the cloud physical host; When the preset security group service agent detects the second message, it obtains the second target information corresponding to the second message and sends a database information request to the preset security group service plug-in to obtain the database information sent by the preset security group service plug-in, determines the second target security group based on the second target information and the database information, and sends the second target security group to the physical switch, so that the physical switch updates its own security group rules based on the second target security group to manage the security group of the cloud physical host.
2. The cloud physical host security group management method according to claim 1, characterized in that: The monitoring of the first message and the second message based on the preset security group service plug-in and the preset security group service agent respectively includes: Controlling a preset security group service plug-in and a preset security group service agent to start, and binding the preset security group service plug-in and the preset security group service agent to the first function and the second function respectively; The first message is monitored based on the first function bound to the preset security group service plug-in, and the second message is monitored based on the second function bound to the preset security group service agent.
3. The cloud physical host security group management method according to claim 2, characterized in that: The first message includes a virtual network card deletion message; the second message includes a virtual network card update message, a security group deletion message, a security group update message, a security group rule deletion message and a security group rule update message.
4. The cloud physical host security group management method according to claim 3, characterized in that: The first target information includes a port identifier, an Internet Protocol address, a security group identifier, and a physical address corresponding to the deleted virtual network card.
5. The cloud physical host security group management method according to claim 1, characterized in that: The preset security group service agent determines a first target security group based on the first target information, and sends the first target security group to the physical switch, including: The preset security group service agent determines, based on the first target information, whether the virtual network card corresponding to the first target information is a network card of the cloud physical host; If the virtual network card is a network card of a cloud physical host, a first target security group is determined, and the first target security group is sent to the physical switch; the first target security group is a security group after clearing the security group rules corresponding to the virtual network card in the physical switch; If the virtual network card is not the network card of the cloud physical host, the preset security group service agent sends a target database information request to the preset security group service plug-in based on the remote control call operation, so as to redetermine the third target security group corresponding to the cloud physical host according to the database information obtained from the preset security group service plug-in, and send the third target security group to the physical switch, so that the physical switch updates its own security group rules based on the third target security group.
6. The cloud physical host security group management method according to any one of claims 1 to 5, characterized in that: Also includes: The preset security group service agent is connected to the physical switch based on the secure shell protocol, and sends the determined target security group to the physical switch to update the security group rules in the physical switch; The target security group and the security group rule in the physical switch are both in the form of an access control list that can be understood and executed by the physical switch.
7. The cloud physical host security group management method according to claim 1, characterized in that: The preset security group service plug-in and the preset security group service agent are both located on the control node in the cloud platform; Accordingly, the method further includes: Based on the control node, the preset security group service plug-in and the preset security group service agent are controlled to obtain target information, so that the preset security group service agent converts the security group rules corresponding to the current cloud platform obtained based on the target information into the form of security group rules that can be executed by the physical switch, and sends the converted security group rules to the physical switch.
8. A cloud physical host security group management device, characterized in that: Applied to a cloud platform, wherein the cloud platform includes a preset security group service plug-in and a preset security group service agent, and the cloud physical host security group management device includes: A message monitoring module, used to monitor the first message and the second message respectively based on a preset security group service plug-in and a preset security group service agent; a first management module, configured to obtain first target information corresponding to the first message when the preset security group service plug-in detects the first message, and send the first target information to the preset security group service agent, so that the preset security group service agent determines a first target security group based on the first target information, and sends the first target security group to the physical switch, so that the physical switch updates its own security group rules based on the first target security group, so as to manage the security group of the cloud physical host; A second management module is used to obtain second target information corresponding to the second message and send a database information request to the preset security group service plug-in to obtain the database information sent by the preset security group service plug-in when the preset security group service agent monitors the second message, determine a second target security group based on the second target information and the database information, and send the second target security group to the physical switch, so that the physical switch updates its own security group rules based on the second target security group to manage the security group of the cloud physical host.
9. An electronic device, characterized in that: include: Memory, used to store computer programs; A processor, configured to execute the computer program to implement the cloud physical host security group management method according to any one of claims 1 to 7.
10. A computer-readable storage medium, characterized in that: Used to store a computer program, which, when executed by a processor, implements the cloud physical host security group management method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Method for configuring template to synchronize default security group rule
CN119094150A
Mapping messages to connection servers between network management system and managed datacenters
EP4407485A1