Multi-cloud cluster security group configuration method, device, equipment and medium

By obtaining the IP information to be updated and quickly updating it when external visiting IP addresses or nodes change, the problem of inefficient security group configuration and difficult to ensure consistency in multi-cloud environments is solved, and efficient security group rules updates and configuration consistency is achieved.

CN120017501APending Publication Date: 2025-05-16E FUND MANAGEMENT CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510284501.5
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-03-11
Publication Date
2025-05-16

AI Technical Summary

Technical Problem

When the external environment or cluster information changes in existing security group configuration schemes in multi-cloud environments, it is inefficient to locate and update security group rules, and it is difficult to ensure the consistency of configurations.

Method used

By obtaining the IP information to be updated, when external visiting IP addresses or nodes change, the corresponding security group rules and IP collections are quickly updated to achieve batch updates, improve configuration efficiency and ensure consistency.

Benefits of technology

Improves the efficiency and consistency of security group configuration, and reduces complex search and update operations on multi-cloud environments by quickly positioning and updating security group rules.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120017501A_ABST
    Figure CN120017501A_ABST
Patent Text Reader

Abstract

The invention discloses a multi-cloud cluster security group configuration method and device, equipment and a medium. The method comprises the following steps: when a security group configuration condition is met, acquiring to-be-updated IP information; wherein each security group corresponds to one IP set, and each security group comprises a plurality of security group rules; each security group rule quotes a plurality of I P sets corresponding to other security groups; the security group configuration condition comprises one or more combinations of the following conditions: an external visiting I P address changes or any node changes; when the security group configuration condition is that the external visiting IP address changes, updating the external visiting IP address in the corresponding security group rule according to the to-be-updated IP information; and when the security group configuration condition is that any node is changed, updating the IP set corresponding to the corresponding security group according to the to-be-updated IP information. According to the invention, the security group configuration efficiency in the multi-cloud environment can be improved, and the configuration consistency can be ensured.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present application relates to the field of network security, and in particular to a multi-cloud cluster security group configuration method, device, equipment and medium. Background Art

[0002] Security groups are one of the key components of cloud security management, which can protect resources in multi-cloud environments from unauthorized access. Security groups usually support fine-grained configuration of access control rules by IP address, port, protocol, etc.

[0003] The existing multi-cloud environment security group configuration scheme usually first searches and locates the security group rules globally when the external environment or cluster information changes, causing the source and destination information to change, and then updates the security group rules one by one. In a multi-cloud environment, each cloud environment includes multiple clusters, and each cluster includes multiple nodes, and each node is associated with multiple security group rules. Therefore, the existing multi-cloud environment security group configuration scheme, especially in the scenario where there is no need to configure security groups across clusters, has low efficiency in locating and updating security group rules, and it is difficult to ensure the consistency of security group configuration.

[0004] Therefore, how to improve the efficiency of security group configuration in a multi-cloud environment is the main technical problem that needs to be solved at present. Summary of the invention

[0005] The present application provides a multi-cloud cluster security group configuration method, apparatus, device and medium to solve the technical problem of how to improve the efficiency of security group configuration in a multi-cloud environment.

[0006] In order to solve the above technical problems, in a first aspect, an embodiment of the present application provides a multi-cloud cluster security group configuration method, including:

[0007] When the security group configuration conditions are met, the IP information to be updated is obtained; each security group corresponds to an IP set, and each security group includes several security group rules; each security group rule references several IP sets corresponding to other security groups; the security group configuration conditions include one or more combinations of the following: the external visiting IP address changes or any node changes;

[0008] When the security group configuration condition is that the external visiting IP address changes, the external visiting IP address in the corresponding security group rule is updated according to the IP information to be updated;

[0009] When the security group configuration condition is that any node changes, the IP set corresponding to the corresponding security group is updated according to the IP information to be updated.

[0010] Compared with the prior art, the embodiments of the present application have the following beneficial effects: when the external visiting IP address changes, the security group that needs to be changed can be quickly determined based on the access port accessed by the current external visiting IP address and the accessed cluster, and the relevant security group rules can be quickly located in the security group, thereby improving the efficiency of the security group configuration. In addition, when a node change causes the security group rules in the security group corresponding to the cluster corresponding to the changed node to need to be changed, the cluster can be quickly located based on the node first, and the security group that needs to be changed can be further quickly determined through the cluster. Since internal node communication does not require access to ports, an IP set can be set for each security group. By updating the IP set instead of changing the data in each security group rule one by one, batch updates of all security group rules in the security group can be achieved, thereby improving the efficiency of security group rule updates and ensuring the consistency of security group rule configuration in a multi-cloud environment.

[0011] In some embodiments of the first aspect of the present application, when the security group configuration condition is met, obtaining the IP information to be updated includes:

[0012] Each node is associated with several clusters; each cluster corresponds to a security group;

[0013] When the security group configuration condition is that the external visiting IP address changes, the first external visiting IP address is used as the IP information to be updated; the first external visiting IP address is the changed external visiting IP address;

[0014] When the security group configuration condition is that any node changes, the first node IP address is used as the IP information to be updated; the first node IP address is the node IP address after the node changes.

[0015] Compared with the prior art, the above embodiment has the following beneficial effects: when the external visiting IP address changes, it is necessary to update the relevant security group rules in the security group to determine whether the external visiting IP address is allowed to access the internal nodes of the cluster. Therefore, it is necessary to use the changed external visiting IP address as the IP information to be updated to update the corresponding security group rules, thereby ensuring the effectiveness of the security group rule update. When any node in the cluster changes, it not only means that the node that can provide services has changed, but also means that the number of nodes that can communicate with each other in the cluster has changed. Therefore, the node IP address after the node changes is used as the IP information to be updated to update the IP set, which can ensure the effectiveness of the subsequent security group rules.

[0016] In some embodiments of the first aspect of the present application, when the security group configuration condition is that the external visiting IP address changes, updating the external visiting IP address in the corresponding security group rule according to the IP information to be updated includes:

[0017] The elements in each of the security group rules include at least: a first IP address and an access port;

[0018] Locate a first security group rule based on a first access port accessed by the first external visiting IP address and a first cluster;

[0019] Update the first IP address in the first security group rule according to the first external visiting IP address.

[0020] Compared with the prior art, the above embodiment has the following beneficial effects: since external access to nodes within the cluster requires the use of a specified access port to call related node resources, the security group rules need to record the corresponding external access IP address and access port to enable external calls to cluster internal resources. At the same time, because each cluster corresponds to a security group, when the first access port and the first cluster that the currently changed external access IP address (i.e., the first external access IP address) needs to access are known, the first security group rule that needs to be updated can be quickly located, thereby improving the efficiency of security group rule updates.

[0021] In some embodiments of the first aspect of the present application, locating the first security group rule according to the first access port accessed by the first external visiting IP address and the first cluster includes:

[0022] Determine a first security group corresponding to the first cluster accessed by the first external visiting IP address;

[0023] The first security group rule is determined from all the security group rules of the first security group according to the first access port accessed by the first external visiting IP address.

[0024] Compared with the prior art, the above embodiment has the following beneficial effects: since each cluster corresponds to a security group, the first security group that needs to be updated can be quickly located based on the first cluster; further, since the elements of each security group rule include an access port, and the change of the first IP address does not affect the change of the access port, the first security group rule can be quickly located from the first security group through the first access port, thereby improving the efficiency of security group rule updating.

[0025] In some embodiments of the first aspect of the present application, when the security group configuration condition is that the external visiting IP address changes and the corresponding security group rule is not found according to the IP information to be updated, a corresponding second security group rule is established based on the first external visiting IP address, the first access port and the first cluster.

[0026] Compared with the prior art, the above embodiment has the following beneficial effects: since some external visiting IP addresses access the node resources of the cluster through the designated access port for the first time, there is no relevant security group rule with the designated access port as an element in the current security group. At this time, the validity of the security group is guaranteed by establishing the corresponding second security group rule.

[0027] In some embodiments of the first aspect of the present application, when the security group configuration condition is that any node changes, updating the IP set corresponding to the corresponding security group according to the IP information to be updated includes:

[0028] Determine a number of second clusters according to the changed nodes;

[0029] Determine a corresponding second security group according to the second cluster;

[0030] According to the first node IP address, update the IP set corresponding to each second security group.

[0031] Compared with the prior art, the above embodiment has the following beneficial effects: since each node is associated with several clusters, when the node changes, it is necessary to determine all affected second clusters. At the same time, since each cluster corresponds to a security group, the corresponding second security group is located according to the second cluster, so that the new first node IP address is updated to the IP set corresponding to each second security group, thereby realizing the update of batch security group rules and improving the efficiency of security group rule updates.

[0032] In some embodiments of the first aspect of the present application, it also includes: aggregating the security group rules that reference the updated IP set, the first security group rules, and the second security group rules to perform unified view analysis and query or assist in troubleshooting access control issues.

[0033] Compared with the prior art, the above embodiment has the following beneficial effects: when updated security group rules appear, a unified management view is achieved by aggregating security group rules in a multi-cloud environment, thereby improving the efficiency of locating network control problems.

[0034] In a second aspect, an embodiment of the present application further provides a multi-cloud cluster security group configuration device, including: an IP information acquisition module, a first update module, and a second update module;

[0035] The IP information acquisition module is used to acquire the IP information to be updated when the security group configuration conditions are met; wherein each security group corresponds to an IP set, and each security group includes several security group rules; each security group rule references several IP sets corresponding to other security groups; the security group configuration conditions include one or more combinations of the following: the external visiting IP address changes or any node changes;

[0036] The first update module is used to update the external visiting IP address in the corresponding security group rule according to the IP information to be updated when the security group configuration condition is that the external visiting IP address changes;

[0037] The second updating module is used to update the IP set corresponding to the corresponding security group according to the IP information to be updated when the security group configuration condition is that any node changes.

[0038] In a third aspect, the present application also provides a terminal device, comprising a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein the processor implements the above-mentioned multi-cloud cluster security group configuration method when executing the computer program.

[0039] In a fourth aspect, the present application also provides a computer-readable storage medium, which includes a stored computer program, wherein when the computer program is running, the device where the computer-readable storage medium is located is controlled to execute the above-mentioned multi-cloud cluster security group configuration method. BRIEF DESCRIPTION OF THE DRAWINGS

[0040] Figure 1 A flowchart of a multi-cloud cluster security group configuration method provided in some embodiments of the present application;

[0041] Figure 2 Another flowchart of a multi-cloud cluster security group configuration method provided in some embodiments of the present application;

[0042] Figure 3 A schematic diagram of the structure of a multi-cloud cluster security group configuration device provided in some embodiments of the present application. DETAILED DESCRIPTION

[0043] The existing multi-cloud environment security group configuration scheme usually first searches and locates the security group rules globally when the external environment or cluster information changes, causing the source and destination information to change, and then updates the security group rules one by one. In a multi-cloud environment, each cloud environment includes multiple clusters, and each cluster includes multiple nodes, and each node is associated with multiple security group rules. Therefore, the existing multi-cloud environment security group configuration scheme, especially in the scenario where there is no need to configure security groups across clusters, has low efficiency in locating and updating security group rules, and it is difficult to ensure the consistency of security group configuration.

[0044] In order to solve the above technical problems, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are only part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by ordinary technicians in this field without creative work are within the scope of protection of this application.

[0045] First, some explanations are given for the technical terms in this article.

[0046] Multi-cloud: Multi-cloud refers to a multi-cloud environment consisting of multiple complete and independent cloud environments, each of which includes one or more clusters.

[0047] Cluster: A collection of one or more hosts with the same purpose is defined as a cluster (for example, all machines under an application system are an application cluster).

[0048] Security group: A virtual firewall that is equivalent to a security access policy for one or more host resources, thereby defining which machines can access what services on the local machine; each host is associated with multiple security groups.

[0049] Embodiment 1

[0050] Please refer to Figure 1 , a multi-cloud cluster security group configuration method provided in an embodiment of the present application, including S10 to S30, specifically:

[0051] S10: When the security group configuration conditions are met, obtain the IP information to be updated; wherein each security group corresponds to an IP set, and each security group includes several security group rules; each security group rule references several IP sets corresponding to other security groups; the security group configuration conditions include one or more combinations of the following: the external visiting IP address changes or any node changes.

[0052] Further, in some embodiments of the present application, when the security group configuration condition is met, obtaining the IP information to be updated includes:

[0053] Each node is associated with several clusters; each cluster corresponds to a security group;

[0054] When the security group configuration condition is that the external visiting IP address changes, the first external visiting IP address is used as the IP information to be updated; the first external visiting IP address is the changed external visiting IP address;

[0055] When the security group configuration condition is that any node changes, the first node IP address is used as the IP information to be updated; the first node IP address is the node IP address after the node changes.

[0056] It should be noted that in the embodiments of the present application, there is a one-to-one correspondence between clusters and security groups, which is equivalent to locating the corresponding security group with the cluster as a label, or locating the corresponding cluster with the security group as a label. At the same time, the security group will not be set across clusters, that is, a security group will not be effective for two or more clusters, and there is only one security group in a cluster to control node resource access.

[0057] Preferably, in some embodiments of the present application, the IP set is a set of IP addresses of the internal nodes of the cluster corresponding to the corresponding security group. Here, the IP set is equivalent to being referenced by security group rules in several other security groups. Since each security group rule implements access control by limiting the source and destination addresses of node resource access behaviors, the referenced IP set can be used as the source and destination addresses required to be limited by the security group rules in the corresponding security group. In order to better explain the principle of IP set reference, the following example is given: When the source and destination addresses of security group rule B under a security group A directly reference a certain IP set C, IP set C is an IP set composed of the IP addresses of all nodes under set D. If the nodes in set D change, at this time, you only need to pay attention to updating the IP set C maintained by set D. There is no need to locate security group A and the corresponding security group rule B, and batch update of security group rules can be achieved.

[0058] It can be seen from the above preferred embodiments that when the external visiting IP address changes, it is necessary to update the relevant security group rules in the security group to determine whether the external visiting IP address is allowed to access the internal nodes of the cluster. Therefore, it is necessary to use the changed external visiting IP address as the IP information to be updated to update the corresponding security group rules, thereby ensuring the effectiveness of the security group rule update. When any node in the cluster changes, it not only means that the node that can provide services has changed, but also means that the number of nodes that can communicate with each other in the cluster has changed. Therefore, the node IP address after the node changes is used as the IP information to be updated to update the IP set, which can ensure the effectiveness of the subsequent security group rules.

[0059] S20: When the security group configuration condition is that the external visiting IP address changes, the external visiting IP address in the corresponding security group rule is updated according to the IP information to be updated.

[0060] Further, in some embodiments of the present application, when the security group configuration condition is that the external visiting IP address changes, updating the external visiting IP address in the corresponding security group rule according to the IP information to be updated includes:

[0061] The elements in each of the security group rules include at least: a first IP address and an access port;

[0062] Locate a first security group rule based on a first access port accessed by the first external visiting IP address and a first cluster;

[0063] Update the first IP address in the first security group rule according to the first external visiting IP address.

[0064] Preferably, in some embodiments of the present application, a security group rule can be abstracted into a dictionary, for example {first IP address (which can be understood as the source address): 192.168.1; access port: 22; second IP address (which can be understood as the destination address): 192.168.2}. The first IP address can be a specific external visiting IP address, or a set of multiple external visiting IP addresses, or it can directly reference the IP set corresponding to other security groups. The second IP address can directly reference the IP set. The external visiting IP address is the source address in the security group rule, and the access port needs to be specified to access the node resources. Therefore, when the external visiting IP address changes, it is necessary to determine the first IP address of a specific security group rule that needs to be updated based on the access port.

[0065] Furthermore, in some embodiments of the present application, the first access port and the first cluster refer to the access port and the cluster requested to be accessed by the currently changed external visiting IP address, respectively.

[0066] Further, in some embodiments of the present application, the first security group rule refers to the corresponding security group rule that needs to be updated in S20.

[0067] Since external access to nodes within the cluster requires access to the specified access port to call related node resources, the security group rules need to include the corresponding external access IP address and access port to enable external calls to cluster internal resources. At the same time, because each cluster corresponds to a security group, when the first access port and the first cluster that the currently changed external access IP address (i.e., the first external access IP address) needs to access are known, the first security group rule that needs to be updated can be quickly located, thereby improving the efficiency of security group rule updates.

[0068] Further, in some embodiments of the present application, locating the first security group rule according to the first access port accessed by the first external visiting IP address and the first cluster includes:

[0069] Determine a first security group corresponding to the first cluster accessed by the first external visiting IP address;

[0070] The first security group rule is determined from all the security group rules of the first security group according to the first access port accessed by the first external visiting IP address.

[0071] Further, in some embodiments of the present application, the first security group refers to the security group corresponding to the first cluster.

[0072] Since each cluster corresponds to a security group, the first security group that needs to be updated can be quickly located based on the first cluster. Furthermore, since the elements of each security group rule include the access port, and the change of the first IP address does not affect the change of the access port, the first security group rule can be quickly located from the first security group through the first access port, thereby improving the efficiency of security group rule update.

[0073] Furthermore, in some embodiments of the present application, when the security group configuration condition is that the external visiting IP address changes and no corresponding security group rule is found according to the IP information to be updated, a corresponding second security group rule is established according to the first external visiting IP address, the first access port and the first cluster.

[0074] Further, in some embodiments of the present application, the second security group rule refers to a new security group rule established through the external visiting IP address, the first access port and the first cluster.

[0075] Since some external visiting IP addresses access the node resources of the cluster for the first time through the specified access port, there is no relevant security group rule with the specified access port as an element in the current security group. At this time, the corresponding second security group rule is established to ensure the validity of the security group.

[0076] Preferably, reference Figure 2 The left branch process of the shown process, S20, can also be automatically executed based on the automation platform, specifically: when the external visiting IP address changes and the security group rules need to be updated, first quickly locate or create a new security group rule through the access port and cluster accessed by the external visiting IP address (that is, the first step is to locate the label through the cluster, locate the corresponding security group, and obtain the name or label of the security group. The second step is to locate the corresponding security group rule through the access port in the located security group, and then obtain the ID of the security group rule); then, the external visiting IP address, the name of the security group, the ID of the security group rule, and the name of the cloud environment where the cluster is located are passed as parameters to the automatic task platform; finally, the automation platform automatically creates a multi-cloud security group update plan according to the parameters. When the update plan is generated, it will be automatically scheduled for execution by the automation platform, so that the batch update of the multi-cloud security group rules takes effect.

[0077] S30: When the security group configuration condition is that any node changes, the IP set corresponding to the corresponding security group is updated according to the IP information to be updated.

[0078] Further, in some embodiments of the present application, when the security group configuration condition is that any node changes, updating the IP set corresponding to the corresponding security group according to the IP information to be updated includes:

[0079] Determine a number of second clusters according to the changed nodes;

[0080] Determine a corresponding second security group according to the second cluster;

[0081] According to the first node IP address, update the IP set corresponding to each second security group.

[0082] Furthermore, in some embodiments of the present application, since each node is associated with one or more clusters, when a node within a cluster changes, it means that the nodes within other clusters will also undergo the same change, so the above-mentioned second cluster is the cluster associated with the changed node.

[0083] Furthermore, in some embodiments of the present application, the second security group is a security group corresponding to the second cluster.

[0084] Preferably, in some embodiments of the present application, a change in any node refers to a change in a node within the cluster, including but not limited to creating a new node, shrinking or expanding capacity within the cluster, and any cluster node information change operation that may cause the security group rules to need to be updated.

[0085] Since each node is associated with several clusters, when the node changes, it is necessary to determine all affected second clusters. At the same time, because each cluster corresponds to a security group, the corresponding second security group is located according to the second cluster, so as to update the new first node IP address to the IP set corresponding to each second security group, thereby realizing the update of batch security group rules and improving the efficiency of security group rule updates.

[0086] Furthermore, in some embodiments of the present application, it also includes: aggregating the security group rules that reference the updated IP set, the first security group rules, and the second security group rules to perform unified view analysis and query or assist in troubleshooting access control issues.

[0087] When updated security group rules appear, a unified management view is achieved by aggregating security group rules in multi-cloud environments, thereby improving the efficiency of locating network control problems.

[0088] Preferably, in some embodiments of the present application, S30 can be performed by Figure 2 The branch process shown on the right is executed as follows: When the cluster's own nodes change and the security group rules need to be updated, the cluster with the node changes is located to the IP set composed of the IP addresses of all nodes under the cluster, and the located IP set and the new node IP address are passed to the automated execution platform to create a multi-cloud cluster IP set update plan, and execute a multi-cloud cluster IP combined batch update. When the multi-cloud cluster IP is combined in batches, the multi-cloud security group rules are also updated and take effect synchronously.

[0089] In summary, a multi-cloud cluster security group configuration method provided by an embodiment of the present application has the following beneficial effects: when the external visiting IP address changes, the security group that needs to be changed can be quickly determined based on the access port accessed by the current external visiting IP address and the accessed cluster, and the relevant security group rules can be quickly located in the security group, thereby improving the efficiency of security group configuration. At the same time, the same cluster nodes distributed in the multi-cloud environment are defined as an IP set, and the IP set is used as rule information in the security group rules. When the node changes dynamically, the IP set is automatically updated synchronously, and the security group rules take effect synchronously. There is no need to perform complex global rule search, positioning and update according to the node, thereby improving the efficiency of security group rule updates and ensuring the consistency of security group rule configuration in the multi-cloud environment. The automation platform automatically identifies the multi-cloud environment that needs to be operated, issues update tasks in parallel, ensures configuration consistency, aggregates multi-cloud environment security group rules, unifies management views, and improves the efficiency of locating network control problems.

[0090] Embodiment 2

[0091] refer to Figure 3, a multi-cloud cluster security group configuration device provided in an embodiment of the present application, includes: an IP information acquisition module 11, a first update module 12 and a second update module 13.

[0092] Furthermore, in some embodiments of the present application, the IP information acquisition module 11 is used to obtain the IP information to be updated when the security group configuration conditions are met; wherein, each security group corresponds to an IP set, and each security group includes several security group rules; each security group rule references several IP sets corresponding to other security groups; the security group configuration conditions include one or more combinations of the following: the external visiting IP address changes or any node changes; the first update module 12 is used to update the external visiting IP address in the corresponding security group rule according to the IP information to be updated when the security group configuration condition is that the external visiting IP address changes; the second update module 13 is used to update the IP set corresponding to the corresponding security group according to the IP information to be updated when the security group configuration condition is that any node changes.

[0093] Furthermore, in some embodiments of the present application, when the security group configuration condition is met, the IP information to be updated is obtained, including: each node is associated with several clusters; each cluster corresponds to a security group; when the security group configuration condition is that the external visiting IP address changes, the first external visiting IP address is used as the IP information to be updated; the first external visiting IP address is the external visiting IP address after the change; when the security group configuration condition is that any node changes, the first node IP address is used as the IP information to be updated; the first node IP address is the node IP address after the node changes.

[0094] Furthermore, in some embodiments of the present application, when the security group configuration condition is that the external visiting IP address changes, the external visiting IP address in the corresponding security group rule is updated according to the IP information to be updated, including: each element in the security group rule includes at least: a first IP address and an access port; locating the first security group rule according to the first access port accessed by the first external visiting IP address and the first cluster; and updating the first IP address in the first security group rule according to the first external visiting IP address.

[0095] Further, in some embodiments of the present application, the first security group rule is located according to the first access port accessed by the first external visiting IP address and the first cluster, including: determining the corresponding first security group according to the first cluster accessed by the first external visiting IP address; and determining the first security group rule from all the security group rules of the first security group according to the first access port accessed by the first external visiting IP address.

[0096] Furthermore, in some embodiments of the present application, when the security group configuration condition is that the external visiting IP address changes and no corresponding security group rule is found according to the IP information to be updated, a corresponding second security group rule is established according to the first external visiting IP address, the first access port and the first cluster.

[0097] Furthermore, in some embodiments of the present application, when the security group configuration condition changes for any node, the IP set corresponding to the corresponding security group is updated according to the IP information to be updated, including: determining several second clusters according to the changed nodes; determining the corresponding second security group according to the second clusters; and updating the IP set corresponding to each second security group according to the IP address of the first node.

[0098] Furthermore, in some embodiments of the present application, it also includes: aggregating the security group rules that reference the updated IP set, the first security group rules, and the second security group rules to perform unified view analysis and query or assist in troubleshooting access control issues.

[0099] It can be understood that the above-mentioned device item embodiments correspond to the method item embodiments of the present invention. A multi-cloud cluster security group configuration device provided by the embodiment of the present invention can implement any method item embodiment of the present invention, that is, the multi-cloud cluster security group configuration method provided in Embodiment 1.

[0100] In summary, a multi-cloud cluster security group configuration device provided by an embodiment of the present application has the following beneficial effects: when an external visiting IP address changes, the security group that needs to be changed can be quickly determined based on the access port accessed by the current external visiting IP address and the accessed cluster, and the relevant security group rules can be quickly located in the security group, thereby improving the efficiency of security group configuration. At the same time, the same cluster nodes distributed in the multi-cloud environment are defined as an IP set, and the IP set is used as rule information in the security group rules. When the node changes dynamically, the IP set is automatically updated synchronously, and the security group rules take effect synchronously, without the need for complex global rule search, positioning and updating based on the node, thereby improving the efficiency of security group rule updates and ensuring the consistency of security group rule configuration in the multi-cloud environment. The automation platform automatically identifies the multi-cloud environment that needs to be operated, issues update tasks in parallel, ensures configuration consistency, aggregates multi-cloud environment security group rules, unifies management views, and improves the efficiency of locating network control problems.

[0101] Embodiment 3

[0102] Based on the above-mentioned embodiment of the multi-cloud cluster security group configuration method, another embodiment of the present application provides a multi-cloud cluster security group configuration terminal device, which includes a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor. When the processor executes the computer program, the multi-cloud cluster security group configuration method of any embodiment of the present application is implemented.

[0103] Exemplarily, in this embodiment, the computer program may be divided into one or more modules, and the one or more modules are stored in the memory and executed by the processor to complete the present application. The one or more modules may be a series of computer program instruction segments capable of completing specific functions, and the instruction segments are used to describe the execution process of the computer program in the multi-cloud cluster security group configuration device.

[0104] The multi-cloud cluster security group configuration device may be a computing device such as a desktop computer, a notebook, a PDA, a cloud server, etc. The multi-cloud cluster security group configuration terminal device may include, but is not limited to, a processor and a memory.

[0105] The processor may be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field-programmable gate arrays (FPGA) or other programmable logic devices, discrete gates or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or the processor may be any conventional processor, etc. The processor is the control center of the multi-cloud cluster security group configuration device, and uses various interfaces and lines to connect the various parts of the entire multi-cloud cluster security group configuration device. The memory may be used to store the computer program and / or module, and the processor implements various functions of the multi-cloud cluster security group configuration device by running or executing the computer program and / or module stored in the memory, and calling the data stored in the memory. The memory may mainly include a program storage area and a data storage area, wherein the program storage area may store an operating system, an application required for at least one function, etc.; the data storage area may store data created according to the use of the mobile phone, etc. In addition, the memory may include high-speed random access memory and may also include non-volatile memory, such as a hard disk, a memory, a plug-in hard disk, a smart media card (SMC), a secure digital (SD) card, a flash card (Flash Card), at least one disk storage device, a flash memory device, or other volatile solid-state storage devices.

[0106] Embodiment 4

[0107] Based on the above-mentioned embodiment of the multi-cloud cluster security group configuration method, another embodiment of the present application provides a storage medium, wherein the storage medium includes a stored computer program, wherein when the computer program is running, the device where the storage medium is located is controlled to execute the multi-cloud cluster security group configuration method of any embodiment of the present application.

[0108] In this embodiment, the storage medium is a computer-readable storage medium, and the computer program includes computer program code, which may be in source code form, object code form, executable file or some intermediate form, etc. The computer-readable medium may include: any entity or device capable of carrying the computer program code, recording medium, USB flash drive, mobile hard disk, magnetic disk, optical disk, computer memory, read-only memory (ROM), random access memory (RAM), electric carrier signal, telecommunication signal and software distribution medium, etc. It should be noted that the content contained in the computer-readable medium may be appropriately increased or decreased according to the requirements of legislation and patent practice in the jurisdiction. For example, in some jurisdictions, according to legislation and patent practice, computer-readable media do not include electric carrier signals and telecommunication signals.

[0109] The specific embodiments described above further describe the purpose, technical solutions and beneficial effects of the present application in detail. It should be understood that the above description is only a specific embodiment of the present application and is not intended to limit the scope of protection of the present application. It is particularly pointed out that for those skilled in the art, any modification, equivalent replacement, improvement, etc. made within the spirit and principle of the present application should be included in the scope of protection of the present application.

Claims

1. A multi-cloud cluster security group configuration method, characterized in that: include: When the security group configuration conditions are met, the IP information to be updated is obtained; each security group corresponds to an IP set, and each security group includes several security group rules; each security group rule references several IP sets corresponding to other security groups; the security group configuration conditions include one or more combinations of the following: the external visiting IP address changes or any node changes; When the security group configuration condition is that the external visiting IP address changes, the external visiting IP address in the corresponding security group rule is updated according to the IP information to be updated; When the security group configuration condition is that any node changes, the IP set corresponding to the corresponding security group is updated according to the IP information to be updated.

2. A multi-cloud cluster security group configuration method as claimed in claim 1, characterized in that: When the security group configuration conditions are met, obtaining the IP information to be updated includes: Each node is associated with several clusters; each cluster corresponds to a security group; When the security group configuration condition is that the external visiting IP address changes, the first external visiting IP address is used as the IP information to be updated; the first external visiting IP address is the changed external visiting IP address; When the security group configuration condition is that any node changes, the first node IP address is used as the IP information to be updated; the first node IP address is the node IP address after the node changes.

3. A multi-cloud cluster security group configuration method as claimed in claim 2, characterized in that: When the security group configuration condition is that the external visiting IP address changes, updating the external visiting IP address in the corresponding security group rule according to the IP information to be updated includes: The elements in each of the security group rules include at least: a first IP address and an access port; Locate a first security group rule based on a first access port accessed by the first external visiting IP address and a first cluster; Update the first IP address in the first security group rule according to the first external visiting IP address.

4. A multi-cloud cluster security group configuration method as claimed in claim 3, characterized in that: The first access port accessed according to the first external visiting IP address and the first cluster positioning the first security group rule include: Determine a first security group corresponding to the first cluster accessed by the first external visiting IP address; The first security group rule is determined from all the security group rules of the first security group according to the first access port accessed by the first external visiting IP address.

5. A multi-cloud cluster security group configuration method as claimed in claim 3, characterized in that: When the security group configuration condition is that the external visiting IP address changes and no corresponding security group rule is found according to the IP information to be updated, a corresponding second security group rule is established according to the first external visiting IP address, the first access port and the first cluster.

6. A multi-cloud cluster security group configuration method as claimed in claim 2, characterized in that: When the security group configuration condition is that any node changes, the IP set corresponding to the corresponding security group is updated according to the IP information to be updated, including: Determine a number of second clusters according to the changed nodes; Determine a corresponding second security group according to the second cluster; According to the first node IP address, update the IP set corresponding to each second security group.

7. A multi-cloud cluster security group configuration method according to any one of claims 4 to 6, characterized in that: Also includes: The security group rules that reference the updated IP set, the first security group rules, and the second security group rules are grouped together to perform unified view analysis and query or assist in troubleshooting access control issues.

8. A multi-cloud cluster security group configuration device, characterized in that: include: IP information acquisition module, first update module and second update module; The IP information acquisition module is used to acquire the IP information to be updated when the security group configuration conditions are met; wherein each security group corresponds to an IP set, and each security group includes several security group rules; each security group rule references several IP sets corresponding to other security groups; the security group configuration conditions include one or more combinations of the following: the external visiting IP address changes or any node changes; The first update module is used to update the external visiting IP address in the corresponding security group rule according to the IP information to be updated when the security group configuration condition is that the external visiting IP address changes; The second updating module is used to update the IP set corresponding to the corresponding security group according to the IP information to be updated when the security group configuration condition is that any node changes.

9. A terminal device, characterized in that: The method comprises a processor, a memory, and a computer program stored in the memory and configured to be executed by the processor, wherein when the processor executes the computer program, a multi-cloud cluster security group configuration method according to any one of claims 1 to 7 is implemented.

10. A computer-readable storage medium, characterized in that: The computer-readable storage medium includes a stored computer program, wherein when the computer program is executed, the device where the computer-readable storage medium is located is controlled to execute a multi-cloud cluster security group configuration method according to any one of claims 1 to 7.