Storage node cluster access method and cloud management platform
By creating a binding relationship between applications, computing nodes and storage space in the cloud management platform and deploying the binding relationship in the proxy node, the data security problem when multiple applications share storage pools in the cloud service system is solved, and efficient storage management and security guarantees are achieved.
Patent Information
- Application Number
- CN202410095068.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-11-24
- Filing Date
- 2024-01-23
- Publication Date
- 2025-05-27
AI Technical Summary
In a cloud service system based on a separate storage architecture, in order to provide secure and stable storage services, cloud vendors need to build an exclusive storage pool for each application, resulting in high hardware costs, large storage scale and low processing efficiency; at the same time, sharing storage pools for multiple applications may lead to data security problems.
Create a binding relationship between applications, computing nodes and storage space through the cloud management platform, and deploy the binding relationship in the proxy node. The proxy node creates an exclusive storage space in the storage node cluster and performs security detection of access requests to ensure that only access requests that meet the binding relationship can access the corresponding storage space.
While multiple applications share the same storage pool, it ensures data security between each application, avoiding the high hardware cost and inefficient processing of a separate storage pool.
Smart Images

Figure CN120050282A_ABST
Abstract
Description
[0001] This application claims the priority of a Chinese patent application with the application number 202311585043.6 and the invention title "A Method, Apparatus and Other Devices for Data Processing" filed with the National Intellectual Property Administration on November 24, 2023, the entire content of which is incorporated herein by reference. Technical Field
[0002] Embodiments of this application relate to the field of cloud technology, and in particular, to a method for accessing a storage node cluster based on a cloud management platform and a cloud management platform. Background Art
[0003] With the rapid development of cloud technology, cloud providers can offer cloud service systems built on a separated computing and storage architecture. In this architecture, tenants' applications can run in a computing pool, and the data required by the applications can be stored in a storage pool. There is physical isolation between the computing pool and the storage pool, but they are communicatively connected. Therefore, when an application in the computing pool needs to process data, it can call data from the storage pool to fulfill business requirements.
[0004] Currently, in a cloud service system built on a separated computing and storage architecture, for different applications of the same tenant or applications of different tenants, cloud providers need to separately build exclusive storage pools for each application to provide secure and stable storage services for each application. However, this approach incurs extremely high hardware costs and makes the scale on the storage side too large, resulting in low processing efficiency when processing data.
[0005] Based on this, cloud providers have tried to enable multiple applications to share a storage pool. However, this approach may cause an application to erroneously access the data of other applications when accessing the storage pool, leading to a series of data security issues. Summary of the Invention
[0006] Embodiments of this application provide a method for accessing a storage node cluster based on a cloud management platform and a cloud management platform, which can not only enable multiple applications to share the same storage pool but also ensure data security between applications.
[0007] In a first aspect of the embodiments of this application, a method for accessing a storage node cluster based on a cloud management platform is provided. The cloud management platform for implementing this method can manage the infrastructure that provides cloud services, and these infrastructures may include computing nodes purchased by tenants, proxy nodes located between the computing nodes and the storage node cluster, and a storage node cluster that can provide storage space. The method includes:
[0008] When a tenant needs to bind the tenant's application and the computing nodes specified by the tenant for running the application, the cloud management platform can provide a binding interface to the tenant. Therefore, the tenant can send the identifier of the application and the identifier of the computing node to the binding interface, so that the cloud management platform can receive the identifier of the application and the identifier of the computing node through the binding interface.
[0009] After obtaining the identifier of the application and the identifier of the computing node, the cloud management platform can generate an identifier for the storage space serving the application (the storage space can be used to store the data of the application), and create a binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space, and deploy the application on the computing node so that the computing node runs the application.
[0010] After obtaining the binding relationship, the cloud management platform can deploy the binding relationship on the proxy node. When the application has a data processing requirement, the computing node running the application can send an access request to the proxy node. After receiving the access request from the computing node, the proxy node can detect the information included in the access request based on the binding relationship. If the access request includes the identifier of the computing node and the identifier of the storage space, it means that the information included in the access request conforms to the binding relationship. The proxy node then creates the storage space in the storage node cluster or completes data processing in the storage space to meet the data processing requirements of the application.
[0011] As can be seen from the above method: The cloud management platform can, upon the request of a tenant, create a binding relationship between the identifier of the tenant's application, the identifier of the computing node running the application, and the identifier of the storage space serving the application, and deploy the binding relationship in the proxy node. When the computing node running the application sends an access request to the proxy node, the proxy node can perform a security check on the access request based on the binding relationship. If the access request passes the security check, it indicates that the information carried by the access request conforms to the binding relationship. Therefore, the proxy node can create a storage space serving the application or access the storage space in the storage node cluster (i.e., the storage pool) on behalf of the computing node running the application to complete data processing, thereby meeting the data processing requirements of the application. Thus, it can be seen that the cloud management platform can utilize the binding relationship between the application, the computing node, and the storage space to instruct the proxy node to create a storage space dedicated to the tenant's application in the storage pool. When the computing node running the application needs to access the storage space, the proxy node can perform a security check on it. After passing the security check, the proxy node will replace the computing node to access the storage space to complete data processing. In this way, even if there are multiple applications, the proxy node can create a dedicated storage space for each application in the storage pool, enabling multiple applications to share the same storage pool. When the computing nodes running each application need to access the corresponding storage space, the proxy node can perform a security check on them in real time. Only after passing the security check will it be allowed to access the corresponding storage space, which can ensure data security between applications.
[0012] In a possible implementation manner, the identifier of the storage space includes the namespace of the storage space. In the foregoing implementation manner, the identifier of the application can be used to represent the application, such as the universal unique identifier of the application, etc. Similarly, the identifier of the computing node can be used to represent the application, such as the universal unique identifier of the computing node, etc. Similarly, the identifier of the storage space can be used as the metadata of the storage space, such as the command space of the storage space, etc.
[0013] In a possible implementation manner, the method further includes: The cloud management platform receives a creation request for the identifier of the application from the tenant through a creation interface; the cloud management platform creates the identifier of the application based on the identifier creation request and provides the identifier of the application to the tenant through the creation interface. In the foregoing implementation manner, when the tenant needs to create the identifier of the application, the cloud management platform can provide the creation interface to the tenant. Therefore, the tenant can send a creation request for the identifier of the application to the creation interface, so that the cloud management platform receives the creation request for the identifier of the application through the creation interface. After receiving the creation request for the identifier of the application, the cloud management platform can create an identifier representing the application according to the indication of the identifier creation request and return the identifier of the application to the tenant's client through the creation interface for the tenant's subsequent use.
[0014] In a possible implementation manner, the storage node cluster includes multiple storage nodes and a management node for managing the multiple storage nodes. The cloud management platform deploys the binding relationship in the proxy node, including: the cloud management platform sends the binding relationship to the management node, so that the management node deploys the binding relationship in the proxy node. In the foregoing implementation manner, the storage node cluster includes multiple storage nodes and a management node for managing the multiple storage nodes, and three ends of the management node are respectively communicatively connected to the cloud management platform, the proxy node, and the multiple storage nodes. Based on this, after obtaining the binding relationship among the identifier of the application, the identifier of the computing node, and the identifier of the storage space, the cloud management platform can directly send the binding relationship to the management node. After obtaining the binding relationship, the management node can store the binding relationship and send the binding relationship to the proxy node, so that the proxy node stores the binding relationship. In this way, with the cooperation of the management node, the cloud management platform successfully deploys the binding relationship in the proxy node.
[0015] In a possible implementation manner, the method further includes: the cloud management platform notifies the tenant through the binding interface that the application has been bound to the computing node. In the foregoing implementation manner, after the management node sends the binding relationship to the proxy node, it can notify the cloud management platform that the binding relationship has been successfully processed. That is to say, the cloud management platform, the proxy node, the management node, and the computing node have all successfully obtained the binding relationship, which is equivalent to synchronizing that the application, the computing node, and the storage space have been bound. Therefore, the cloud management platform can display through the binding interface to the tenant that the application has been bound to the computing node (the tenant side does not need to perceive the storage space), which is equivalent to notifying the tenant that the application has been successfully bound to the computing node.
[0016] In a possible implementation manner, the binding relationship is further used to instruct the proxy node to detect an initialization request from the computing node. If the initialization request includes the identifier of the application and the identifier of the computing node, the identifier of the storage space is sent to the computing node. In the foregoing implementation manner, when the application needs to complete initialization, the computing node running the application can send the initialization request generated by the application to the proxy node. After obtaining the initialization request from the computing node, the proxy node can detect the information included in the initialization request based on the binding relationship to determine whether the access request includes both the identifier of the application and the identifier of the computing node. If the initialization request includes the identifier of the application and the identifier of the computing node, it indicates that the information included in the initialization request conforms to the binding relationship. The proxy node then finds the identifier of the storage space serving the application from the binding relationship and sends it to the computing node, so that the application stores the identifier of the storage space and thus successfully completes the initialization.
[0017] In a possible implementation, the proxy node creating a storage space in the storage node cluster or processing data in the storage space includes: The proxy node sends an access request to the management node. The access request is used to instruct the management node to detect the access request. If the access request contains the identifier of the storage space, a storage space is created in any one of the multiple storage nodes; or, the proxy node sends the access request to the storage node. The access request is used to instruct the storage node to detect the access request. If the access request contains the identifier of the storage space, data is processed in the storage space. In the foregoing implementation, after receiving the access request from the computing node running the application, the proxy node can perform a security check on the access request. If the security check is passed, the proxy node can perform different operations based on the type of the access request. If the access request is a creation request for the storage space, the proxy node can send the access request to the management node so that the management node detects the access request. If the access request contains the identifier of the storage space, it indicates that the information contained in the access request is legal. Therefore, the management node selects a certain storage node among the multiple storage nodes and creates the storage space in the storage node. The identifier of the storage space can be used as the metadata of the storage space. If the access request is a data processing request for the storage space, the proxy node can send the access request to the storage node so that the storage node detects the access request. If the access request contains the identifier of the storage space, it indicates that the access request is legal. Therefore, the storage node can find the storage space based on the identifier of the storage space and process data in the storage space, thereby meeting the data processing requirements of the application.
[0018] In a possible implementation, the storage node cluster is located in the same site, and the site includes any one of the following: cabinet, computer room, data center, region, and availability zone.
[0019] In a possible implementation, the computing node includes any one of the following: physical server, bare metal server, virtual machine, and container.
[0020] The second aspect of the embodiments of the present application provides a method for accessing a storage node cluster based on a proxy node. The proxy node is set in the infrastructure that provides cloud services. The infrastructure is managed by a cloud management platform and also includes computing nodes and a storage node cluster. The method includes: The proxy node receives the binding relationship between the identifier of an application, the identifier of a computing node, and the identifier of a storage space from the cloud management platform. The identifier of the application and the identifier of the computing node are obtained by the cloud management platform from a tenant. The computing node runs the application, and the identifier of the storage space is generated by the cloud management platform. The storage space is used to store the data of the application; The proxy node receives an access request from the computing node and detects the access request based on the binding relationship. If the access request includes the identifier of the computing node and the identifier of the storage space, a storage space is created in the storage node cluster or data is processed in the storage space.
[0021] In a possible implementation, the identifier of the storage space includes the namespace of the storage space.
[0022] In a possible implementation, the storage node cluster includes multiple storage nodes and a management node that manages the multiple storage nodes. The proxy node receiving the binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space from the cloud management platform includes: The proxy node directly receives the binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space from the management node. The binding relationship is obtained by the management node from the cloud management platform.
[0023] In a possible implementation, the method further includes: The proxy node detects an initialization request from the computing node. If the initialization request includes the identifier of the application and the identifier of the computing node, the identifier of the storage space is sent to the computing node.
[0024] In a possible implementation, the proxy node detects the access request based on the binding relationship. If the access request includes the identifier of the computing node and the identifier of the storage space, creating a storage space in the storage node cluster or processing data in the storage space includes: Sending the access request to the management node. The access request is used to instruct the management node to detect the access request. If the access request includes the identifier of the storage space, a storage space is created in any one of the multiple storage nodes; Or, sending the access request to the storage node. The access request is used to instruct the storage node to detect the access request. If the access request includes the identifier of the storage space, data is processed in the storage space.
[0025] In a possible implementation, the storage node cluster is located in the same site. The site includes any one of the following: a cabinet, a computer room, a data center, a region, and an availability zone.
[0026] In a possible implementation, the computing node includes any one of the following: physical server, bare metal server, virtual machine, and container.
[0027] The third aspect of the embodiments of the present application provides a cloud management platform, which is used to manage the infrastructure that provides cloud services. The infrastructure includes computing nodes, proxy nodes, and a storage node cluster. The cloud management platform includes: a first receiving module, configured to receive the identifier of the application from the tenant and the identifier of the computing node through a binding interface; a first creating module, configured to create a binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space, and deploy the application in the computing node, where the storage space is used to store the data of the application; a deployment module, configured to deploy the binding relationship in the proxy node, and the binding relationship is used to instruct the proxy node to detect the access request from the computing node. If the access request includes the identifier of the computing node and the identifier of the storage space, create a storage space in the storage node cluster or process the data in the storage space.
[0028] In a possible implementation, the identifier of the storage space includes the namespace of the storage space.
[0029] In a possible implementation, the cloud management platform further includes: a second receiving module, configured to receive an identifier creation request for the application from the tenant through a creation interface; a second creating module, configured to create the identifier of the application based on the identifier creation request, and provide the identifier of the application to the tenant through the creation interface.
[0030] In a possible implementation, the cloud management platform further includes: a notification module, configured to notify the tenant through the binding interface that the application has been bound to the computing node.
[0031] In a possible implementation, the storage node cluster includes multiple storage nodes and a management node for managing the multiple storage nodes. The deployment module is configured to send the binding relationship to the management node, so as to deploy the binding relationship in the proxy node through the management node.
[0032] In a possible implementation, the binding relationship is further used to instruct the proxy node to detect the initialization request from the computing node. If the initialization request includes the identifier of the application and the identifier of the computing node, send the identifier of the storage space to the computing node.
[0033] In a possible implementation manner, the proxy node creating a storage space in the storage node cluster or processing data in the storage space includes: The proxy node sends an access request to the management node, where the access request is used to instruct the management node to detect the access request. If the access request contains the identifier of the storage space, a storage space is created in any one of the multiple storage nodes; or, the proxy node sends an access request to the storage node, where the access request is used to instruct the storage node to detect the access request. If the access request contains the identifier of the storage space, data is processed in the storage space.
[0034] In a possible implementation manner, the storage node cluster is located in the same site, and the site includes any one of the following: cabinet, computer room, data center, region, and availability zone.
[0035] In a possible implementation manner, the computing node includes any one of the following: physical server, bare metal server, virtual machine, and container.
[0036] A fourth aspect of the embodiments of the present application provides a proxy node. The proxy node is set in the infrastructure that provides cloud services. The infrastructure is managed by a cloud management platform and further includes computing nodes and a storage node cluster. The proxy node includes: a receiving module, configured to receive the binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space from the cloud management platform. The identifier of the application and the identifier of the computing node are obtained by the cloud management platform from the tenant. The computing node runs the application, and the identifier of the storage space is generated by the cloud management platform. The storage space is used to store the data of the application; a processing module, configured to receive an access request from the computing node and detect the access request based on the binding relationship. If the access request contains the identifier of the computing node and the identifier of the storage space, a storage space is created in the storage node cluster or data is processed in the storage space.
[0037] In a possible implementation manner, the identifier of the storage space includes the namespace of the storage space.
[0038] In a possible implementation manner, the storage node cluster includes multiple storage nodes and a management node for managing the multiple storage nodes. The receiving module is further configured to directly receive the binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space from the management node. The binding relationship is obtained by the management node from the cloud management platform.
[0039] In a possible implementation manner, the proxy node further includes: a feedback module, configured to detect an initialization request from the computing node. If the initialization request contains the identifier of the application and the identifier of the computing node, the identifier of the storage space is sent to the computing node.
[0040] In a possible implementation manner, a processing module is configured to: send an access request to a management node, where the access request is used to instruct the management node to detect the access request, and if the access request includes an identifier of a storage space, create a storage space in any one of a plurality of storage nodes; or send the access request to a storage node, where the access request is used to instruct the storage node to detect the access request, and if the access request includes an identifier of a storage space, process data in the storage space.
[0041] In a possible implementation manner, a storage node cluster is located in the same site, and the site includes any one of the following: a cabinet, a computer room, a data center, a region, and an availability zone.
[0042] In a possible implementation manner, a computing node includes any one of the following: a physical server, a bare metal server, a virtual machine, and a container.
[0043] A fifth aspect of the embodiments of the present application provides a computing device cluster, which includes at least one computing device, and each computing device includes a processor and a memory: the memory is used to store instructions; the processor is used to execute the method described in the first aspect, any possible implementation manner in the first aspect, the second aspect, or any possible implementation manner in the second aspect according to the instructions.
[0044] A sixth aspect of the embodiments of the present application provides a computer storage medium, which stores one or more instructions, and when the instructions are executed by one or more computers, the one or more computers are caused to implement the method described in the first aspect, any possible implementation manner in the first aspect, the second aspect, or any possible implementation manner in the second aspect.
[0045] A seventh aspect of the embodiments of the present application provides a computer program product, which stores instructions, and when the instructions are executed by a computer, the computer is caused to implement the method described in the first aspect, any possible implementation manner in the first aspect, the second aspect, or any possible implementation manner in the second aspect.
[0046] In the embodiments of the present application, when a tenant needs to bind the tenant's application and the tenant's computing node together, the tenant can input the identifier of the application and the identifier of the computing node to the binding interface provided by the cloud management platform. Then, the cloud management platform can determine the information of the storage space (for storing the data of the application) serving the application, so as to create a binding relationship among the identifier of the application, the identifier of the computing node, and the identifier of the storage space, and make the computing node run the application. Then, the cloud management platform can deploy the binding relationship in the proxy node. Since the proxy node is located between the computing node and the storage node cluster, when the proxy node receives an access request from the computing node, the proxy node can detect the access request based on the binding relationship. If the access request contains the identifier of the mutually bound computing node and the identifier of the storage space, the proxy node can create a storage space in the storage node cluster or complete data processing in the storage space. In the foregoing process, the cloud management platform can, at the request of the tenant, create a binding relationship indicating the identifier of the tenant's application, the identifier of the computing node running the application, and the identifier of the storage space serving the application, and deploy the binding relationship in the proxy node. When the computing node running the application sends an access request to the proxy node, the proxy node can perform a security check on the access request based on the binding relationship. If the access request passes the security check, it means that the information carried by the access request conforms to the binding relationship. Therefore, the proxy node can replace the computing node running the application to create a storage space serving the application in the storage node cluster (i.e., the storage pool) or access the storage space to complete data processing, so as to meet the data processing requirements of the application. Thus, it can be seen that the cloud management platform can use the binding relationship among the application, the computing node, and the storage space to instruct the proxy node to create a storage space dedicated to the tenant's application in the storage pool. When the computing node running the application needs to access the storage space, the proxy node can perform a security check on it. After passing the security check, the proxy node will replace the computing node to access the storage space to complete data processing. In this way, even if there are multiple applications, the proxy node can create a dedicated storage space for each application in the storage pool, so that multiple applications can share the same storage pool. When the computing nodes running each application need to access the corresponding storage spaces, the proxy node can perform a security check on them in real time. Only after passing the security check will it be allowed to access the corresponding storage space, which can ensure the data security among various applications. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] Figure 1 It is a schematic structural diagram of a cloud service system provided by an embodiment of the present application;
[0048] Figure 2 It is a schematic flowchart of a method for accessing a storage node cluster based on a cloud management platform provided by an embodiment of the present application;
[0049] Figure 3 A schematic diagram for obtaining application information provided by an embodiment of the present application;
[0050] Figure 4 A schematic diagram for binding an application to a virtual machine provided by an embodiment of the present application;
[0051] Figure 5 A schematic diagram for a virtual machine to access a storage pool provided by an embodiment of the present application;
[0052] Figure 6 A schematic structural diagram of a cloud management platform provided by an embodiment of the present application;
[0053] Figure 7 A schematic structural diagram of an agent node provided by an embodiment of the present application;
[0054] Figure 8 A schematic structural diagram of a computing device provided by an embodiment of the present application;
[0055] Figure 9 A schematic structural diagram of a computing device cluster provided by an embodiment of the present application;
[0056] Figure 10 A schematic diagram of computer devices in a computer cluster of the present application connected through a network. Detailed implementation manners
[0057] The embodiments of the present application provide a method for accessing a storage node cluster based on a cloud management platform and the cloud management platform, which can not only enable multiple applications to share the same storage pool, but also ensure data security between applications.
[0058] Terms such as "first" and "second" in the specification, claims and above-mentioned drawings of the present application are used to distinguish similar objects, and do not have to be used to describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing embodiments of the present application. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device including a series of units does not have to be limited to those units, but may include other units not clearly listed or inherent to these processes, methods, products or devices.
[0059] With the rapid development of cloud technology, cloud providers can offer cloud service systems built on a separated storage and computing architecture. In this architecture, a tenant's application can run in a computing pool, and the data required by the application can be stored in a storage pool. There is physical isolation between the computing pool and the storage pool, but they are communicatively connected. Therefore, when the application in the computing pool needs to process data, it can call data from the storage pool to meet the business requirements.
[0060] Currently, in the cloud service system built on the separated storage and computing architecture, for different applications of the same tenant or applications of different tenants, cloud providers need to separately build exclusive storage pools for each application to provide secure and stable storage services for each application. However, since there are usually multiple computing nodes for running an application, correspondingly, the storage pool set up for it usually can also include multiple storage nodes. Therefore, once the number of applications increases, the number of storage pools also increases, which will not only lead to extremely high hardware costs for building the cloud service system, but also make the scale on the storage side too large, resulting in low processing efficiency when processing data.
[0061] Based on this, cloud providers have tried to make multiple applications share a storage pool. However, this way may cause an application to incorrectly access the data of other applications when accessing the storage pool, resulting in a series of data security problems. Therefore, how to ensure data security between multiple applications when they share the same storage pool has become an urgent problem to be solved.
[0062] To solve the above problems, the embodiments of this application provide a method for accessing a storage node cluster based on a cloud management platform. This method can be implemented through a cloud service system. Figure 1 A schematic structural diagram of the cloud service system provided by the embodiments of this application is shown in Figure 1 As shown, the cloud service system includes the infrastructure that can provide cloud services and the cloud management platform that manages these infrastructures. The cloud management platform and the infrastructure will be introduced separately below:
[0063] A cloud management platform can overall manage the infrastructure in the entire cloud service system (for example, select specific computing nodes for a tenant from the computing node cluster included in the infrastructure; bind the tenant's application to the tenant's computing nodes so that these computing nodes run the tenant's application; allocate exclusive storage space for the tenant's computing nodes in the storage node cluster to store the data of the tenant's application, etc.). It can also be open to tenants outside the cloud service system and respond to their requests. For example, the cloud management platform can provide various interfaces such as login interfaces, creation interfaces, purchase interfaces, and binding interfaces for the tenants' clients (such as the terminal devices used by the tenants or the browsers on the terminal devices, etc.) to access. Among them, the cloud management platform can authenticate the tenants' clients through the login interface. After successful authentication, it can allow the tenants' clients to log in to the cloud management platform. For another example, the cloud management platform can also allow the tenants' clients to send cloud resource purchase requests of the tenants to the cloud management platform through the purchase interface. The cloud management platform can select exclusive computing nodes for the tenants in the computing node cluster of the infrastructure based on the cloud resource purchase requests and provide the identifiers of these computing nodes to the tenants to provide cloud services for the tenants through these computing nodes. For another example, the cloud management platform can also allow the tenants' clients to send tenant's application identifier creation requests to the cloud management platform through the creation interface. This request is used to indicate the tenant's application. Then, the cloud management platform can create the identifier of the tenant's application based on the identifier creation request and provide the identifier of the tenant's application to the tenant. For another example, the cloud management platform can also allow the tenants' clients to send the identifier of the tenant's application and the identifier of the tenant's computing nodes to the cloud management platform through the binding interface. Then, the cloud management platform can create a binding relationship among the identifier of the tenant's application, the identifier of the tenant's computing nodes, and the identifier of the storage space serving this application, make the tenant's computing nodes run this application, and send the binding relationship to the proxy node so that the proxy node creates a storage space serving this application in the storage node cluster to store the data of this application. In this way, the tenant's computing nodes, the tenant's application, and the storage space serving this application are bound together. Once this application needs to process data, the computing node running this application can send an access request for this storage space to the proxy node so that the proxy node completes data processing in this storage space. This will not be elaborated here for the time being.
[0064] The infrastructure may include a cluster of computing nodes, proxy nodes (which may also be referred to as data processing units (DPUs)), and a cluster of storage nodes. These three concepts are introduced separately below: (1) The cluster of computing nodes may also be referred to as a computing pool. The computing pool may include multiple computing nodes, and multiple computing nodes are available for selection by the cloud management platform. Thus, upon the request of a tenant, a tenant-exclusive computing node can be selected from multiple computing nodes to run the tenant's application. (2) The proxy node can not only serve as an intermediate medium between the cluster of computing nodes and the cluster of storage nodes, but also be connected to the cloud management platform (directly or indirectly), thereby (directly or indirectly) receiving the binding relationship between the identifier of the tenant's application, the identifier of the tenant's computing node, and the identifier of the storage space serving the application from the cloud management platform. And based on this binding relationship, a primary security check is performed on the initialization request and access request from the computing node. Only when the security check is passed will the proxy node respond to the initialization request (for example, return the identifier of the storage space serving the application to the computing node) and the access request (for example, forward the access request to the cluster of storage nodes for processing to create a storage space serving the application in the cluster of storage nodes or complete data processing in the storage space, etc.). (3) The cluster of storage nodes may also be referred to as a storage pool. The storage pool may include multiple storage nodes and a management node for managing multiple storage nodes. Among them, the management node can directly receive the binding relationship between the identifier of the tenant's application, the identifier of the tenant's computing node, and the identifier of the storage space serving the application from the cloud management platform, and set this binding relationship in the proxy node. Moreover, the management node can also receive the access request (such as a storage space creation request) from the tenant's computing node forwarded by the proxy node, and perform a secondary security check on the access request. When the security check is passed, a certain (or some) storage node can be selected and a storage space serving the tenant's application is created in this storage node. The selected storage node can receive the access request (such as a data processing request) from the tenant's computing node forwarded by the proxy node, and perform a secondary security check on the access request. When the security check is passed, data processing can be completed in the storage space serving the tenant's application.
[0065] Furthermore, the above-mentioned computing nodes, proxy nodes, storage nodes, and management nodes can all be regarded as cloud instances in the cloud service system. Cloud instances can be presented in various ways. For example, a cloud instance can be a physical server selected by the cloud management platform. Another example is that a cloud instance can also be a virtual machine (VM) created by the cloud management platform on a physical server through virtualization technology. Another example is that a cloud instance can also be a container (docker) created by the cloud management platform on a physical server through virtualization technology. Another example is that a cloud instance can also be a micro virtual machine (microVM) created by the cloud management platform on a physical server through virtualization technology. Another example is that a cloud instance can also be a bare metal server selected by the cloud management platform, and so on.
[0066] Furthermore, the above-mentioned storage node cluster is usually set in the same site, and this site can be presented in various forms. For example, this site can be a certain cabinet (rack) in the infrastructure. Another example is that this site can be a certain computer room (room) in the infrastructure. Another example is that this site can be a certain data center (data center, DC) in the infrastructure. Another example is that this site can be a certain region (region) in the infrastructure. Another example is that this site can be a certain availability zone (availability zone, AZ) in the infrastructure, and so on.
[0067] Furthermore, the above-mentioned computing node cluster, proxy node, and storage node cluster can be deployed in the same site or in different sites respectively, without any restrictions here, and can be set according to actual needs.
[0068] Based on the above cloud service system, it can be known that at the request of the tenant, the cloud management platform can run the tenant's application on the tenant's exclusive computing node, and (through the proxy node) allocate exclusive storage space for the tenant's application (that is, the tenant's computing node) in the storage node cluster to store the data of the tenant's application, and provide access and invocation for the tenant's application (that is, the tenant's computing node) to complete data processing. Thus, it can be seen that the cloud management platform can bind the tenant's application, the computing node running the application, and the storage space serving the application together. No matter how many applications there are, exclusive storage space is set in the storage node cluster for them to access. Therefore, multiple applications can share the same storage node cluster (storage pool), and the occurrence of data security problems can be avoided. To further understand the foregoing process, the following will be combined with Figure 2 to further introduce this process. Figure 2 This is a schematic flowchart of a method for accessing a storage node cluster based on a cloud management platform provided by an embodiment of this application. As Figure 2 shown, this method can be passed through as Figure 1The implementation of the cloud service system shown, the cloud service system includes a cloud management platform and the infrastructure for providing cloud services. These infrastructures include those allocated to a computing node cluster, a proxy node, and a storage node cluster. The computing node cluster includes computing nodes allocated to tenants. The method includes:
[0069] Step 201, the cloud management platform receives the identifier of the application from the tenant and the identifier of the computing node through the binding interface.
[0070] In this embodiment, when a tenant needs to bind the tenant's application and the computing node specified by the tenant for running the application, the cloud management platform can provide a binding interface to the client used by the tenant (for example, the binding relationship input field and the reminder window, etc. on the tenant interface). Therefore, the tenant can send the identifier of the tenant's application and the identifier of the computing node specified by the tenant for running the application to the binding interface through the client, so that the cloud management platform receives the identifier of the application (for example, the unique identifier of the application, etc.) and the identifier of the computing node (for example, the unique identifier of the computing node, etc.) through the binding interface.
[0071] Specifically, before the tenant sends the identifier of the application and the identifier of the computing node to the cloud management platform, the tenant can obtain the identifier of the application in the following ways:
[0072] When the tenant needs to create the identifier of the application, the cloud management platform can provide a creation interface to the client used by the tenant (for example, the application information application field on the tenant interface, etc.). Therefore, the tenant can send a creation request for the identifier of the application to the creation interface through the client, so that the cloud management platform receives the creation request for the identifier of the application through the creation interface. After receiving the creation request for the identifier of the application, the cloud management platform can parse the identifier creation request, thereby determining that it is necessary to create the identifier of the application for the tenant. Therefore, the cloud management platform can create an identifier representing the application and return the identifier of the application to the tenant's client through the creation interface for the tenant to use.
[0073] For example, as Figure 3 shown ( Figure 3 is a schematic diagram of obtaining application information provided by an embodiment of the present application), when the tenant needs to create a universally unique identifier (UUID) for application (data service) 1, the tenant can enter a creation request for the identifier of application 1 in the application information application field in the tenant interface provided by the cloud management platform. Therefore, the cloud management platform can receive the identifier creation request through the application information application field. Then, the cloud management platform can create a dedicated UUID for application 1 based on the identifier creation request and return the UUID of application 1 to the tenant.
[0074] More specifically, before the tenant sends the identifier of the application and the identifier of the computing node to the cloud management platform, the tenant can obtain the identifier of the computing node in the following ways:
[0075] When the tenant needs to purchase a computing node, the cloud management platform can provide a purchase interface to the client used by the tenant (for example, the virtual machine purchase column in the tenant interface, etc.). Therefore, the tenant can send a purchase request for the computing node to the purchase interface through the client, so that the cloud management platform receives the purchase request for the computing node through the creation interface. After receiving the purchase request for the computing node, the cloud management platform can select a tenant-specific computing node from the computing node cluster and return the identifier of the computing node to the tenant's client through the purchase interface to indicate that the computing node has been successfully purchased.
[0076] Still in the above example, when the tenant needs to purchase a virtual machine, the tenant can enter a virtual machine purchase request in the virtual machine purchase column in the tenant interface provided by the cloud management platform. Therefore, the cloud management platform can receive the virtual machine purchase request through the virtual machine purchase column. Then, the cloud management platform can select a dedicated virtual machine 1 for the tenant from the computing pool based on the virtual machine purchase request and return the UUID of the virtual machine 1 to the tenant.
[0077] Step 202: The cloud management platform creates a binding relationship among the identifier of the application, the identifier of the computing node, and the identifier of the storage space, and deploys the application in the computing node. The storage space is used to store the data of the application.
[0078] Step 203: The cloud management platform deploys the binding relationship in the proxy node. The binding relationship is used to instruct the proxy node to detect access requests from the computing node. If the access request contains the identifier of the computing node and the identifier of the storage space, create a storage space in the storage node cluster or process data in the storage space.
[0079] After obtaining the identifier of the application and the identifier of the computing node, the cloud management platform can generate the identifier of the storage space serving the application (for example, the namespace of the storage space), and create a binding relationship among the identifier of the application, the identifier of the computing node, and the identifier of the storage space (which can also be understood as the binding relationship among the application, the computing node, and the storage space), and deploy the application in the computing node so that the computing node runs the application. It can be understood that the storage space can be used to store the data of the application, so the storage space can provide a data storage service for the application.
[0080] Then, the cloud management platform can deploy this binding relationship in the proxy node so that the proxy node stores this binding relationship. Then, when the application has data processing requirements, the computing node running this application can send an access request for the storage node cluster to the proxy node. After receiving the access request from the computing node, the proxy node can detect the information included in the access request based on this binding relationship to determine whether the access request contains both the identifier of the computing node and the identifier of the storage space. If the access request contains the identifier of the computing node and the identifier of the storage space, it indicates that the information included in the access request conforms to this binding relationship, and the proxy node creates the storage space in the storage node cluster or completes data processing in this storage space to meet the data processing requirements of this application. If the access request does not contain the identifier of the computing node or the identifier of the storage space, it indicates that the information included in the access request does not conform to this binding relationship, and the proxy node rejects processing this access request.
[0081] It should be noted that if the identifier of this application has not been bound to the identifier of any storage space, it indicates that this application is an application that binds to a storage space for the first time. Therefore, the cloud management platform can directly generate the identifier of the storage space serving this application and create the binding relationship among the identifier of this application, the identifier of this computing node, and the identifier of this storage space. If the identifier of this application has been bound to the identifier of the remaining storage space, it indicates that this application is an application that is not binding to a storage space for the first time. Therefore, the cloud management platform can directly create the binding relationship among the identifier of this application, the identifier of this computing node, and the identifier of the remaining storage space. The subsequent operations for these two situations are similar and will not be elaborated further below. This embodiment only takes the former as an example for illustrative introduction.
[0082] Specifically, the cloud management platform can deploy this binding relationship in the proxy node in the following manner:
[0083] Since the storage node cluster includes multiple storage nodes and a management node for managing multiple storage nodes, and the first end of the management node is communicatively connected to the cloud management platform, the second end of the management node is communicatively connected to the proxy node, and the third end of the management node is communicatively connected to multiple storage nodes. Therefore, after obtaining the binding relationship among the identifier of this application, the identifier of this computing node, and the identifier of this storage space, the cloud management platform can directly send this binding relationship to the management node. After obtaining this binding relationship, the management node can store this binding relationship and send the binding relationship to the proxy node so that the proxy node stores this binding relationship.
[0084] Still as in the above example, as Figure 4 shown ( Figure 4 This is a schematic diagram for binding an application to a virtual machine provided by an embodiment of this application. Figure 4 It is in Figure 3(drawn on the basis of), when a tenant needs to bind Application 1 and Virtual Machine 1 together, the tenant can input the UUID of Application 1 and the UUID of Virtual Machine 1 in the binding relationship input field in the tenant interface. Therefore, the cloud management platform can receive the UUID of Application 1 and the UUID of Virtual Machine 1 through the binding relationship input field. Next, the cloud management platform can determine whether the UUID of Application 1 has been bound to the UUIDs of other virtual machines. If not, the cloud management platform generates the namespace of Storage Space 1 and creates the binding relationship between the UUID of Application 1, the UUID of Virtual Machine 1, and the namespace of Storage Space 1. (If the UUID of Application 1 has been bound to the UUIDs of other virtual machines, it means that Application 1 has been deployed on other virtual machines. If the tenant needs to add an additional Virtual Machine 1 for running Application 1, in this case, the cloud management platform has already generated the namespaces of other storage spaces for the UUID of Application 1. Therefore, directly obtain the namespaces of other storage spaces and create the binding relationship between the UUID of Application 1, the UUID of Virtual Machine 1, and the namespaces of other storage spaces. The subsequent operations are similar to the previous case and will not be elaborated further.)
[0085] After obtaining the binding relationship between the UUID of Application 1, the UUID of Virtual Machine 1, and the namespace of Storage Space 1, the cloud management platform makes Virtual Machine 1 run Application 1 and sends this binding relationship to the storage management component (i.e., the aforementioned management node) in the storage pool, so that the management component stores this binding relationship and notifies the DPU to store this binding relationship. In this way, this binding relationship is synchronized among the cloud management platform, the storage management component, and the DPU.
[0086] More specifically, after the cloud management platform deploys this binding relationship behind the proxy node, the cloud management platform can also perform the following operations:
[0087] After the management node sends this binding relationship to the proxy node, it can notify the cloud management platform that the binding relationship has been successfully processed. Therefore, the cloud management platform can display to the tenant through the binding interface that this application has been bound to this computing node, which is equivalent to notifying the tenant that this application has been successfully bound to this computing node.
[0088] Still as in the above example, after the management component notifies the DPU to store this binding relationship, it can return to the cloud management platform that the processing of this binding relationship has been successful. Therefore, the cloud management platform can generate a reminder window in the tenant interface. This reminder window contains content such as Application 1 has been successfully bound to Virtual Machine 1. After the tenant browses this reminder window, the tenant can know that Application 1 has been successfully bound to Virtual Machine 1.
[0089] More specifically, before the computing node sends an access request to the proxy node, the computing node may also perform the following operations:
[0090] When the application needs to complete initialization, the computing node running the application may send the initialization request generated by the application to the proxy node. It should be noted that the initialization request may carry the identifier of the application and the identifier of the computing node (for example, the initialization request generated by the application only contains the identifier of the application. When the computing node sends the initialization request to the proxy node through the data channel, the data channel will automatically make the initialization request contain the identifier of the computing node, etc.). After receiving the initialization request from the computing node, the proxy node may detect the information contained in the initialization request based on the binding relationship to determine whether the access request contains both the identifier of the application and the identifier of the computing node. If the initialization request contains the identifier of the application and the identifier of the computing node, it indicates that the information contained in the initialization request conforms to the binding relationship. The proxy node then finds the identifier of the storage space serving the application from the binding relationship and sends it to the computing node so that the application stores the identifier of the storage space (the application can also store the binding relationship between the identifier of the storage space and the identifier of the application, etc.) to complete the initialization. If the initialization request does not contain the identifier of the application or the identifier of the computing node, it indicates that the information contained in the initialization request does not conform to the binding relationship, and the proxy node rejects the initialization request.
[0091] Still as the above example, as Figure 5 shown ( Figure 5 is a schematic diagram of a virtual machine accessing a storage pool provided by an embodiment of the present application, Figure 5 is in Figure 4(drawn on the basis of), when Application 1 is initialized, Application 1 can generate an initialization request, where the initialization request carries the UUID of Application 1. The virtual machine 1 running Application 1 can send the initialization request to the DPU through the data channel (i.e., the communication channel between the virtual machine 1 and the DPU). During this process, the data channel will automatically make the initialization request carry the UUID of the virtual machine 1. After receiving the initialization request, the DPU will detect whether the information carried by the initialization request is legal (whether it conforms to the binding relationship) based on the aforementioned binding relationship. If the initialization request contains the UUID of Application 1 and the UUID of the virtual machine 1 that are mutually bound, it indicates that the information carried by the initialization request is legal. The DPU can return the namespace of Storage Space 1 to the virtual machine 1 to be stored in the software development kit (SDK) of Application 1 running on the virtual machine 1. Therefore, the SDK of Application 1 can further store the binding relationship between the UUID of Application 1 and the namespace of Storage Space 1, thereby assisting Application 1 to complete the initialization.
[0092] More specifically, after the computing node sends an access request to the proxy node, the proxy node can process the access request in the following manner:
[0093] When this application needs to process data, since this application has obtained the identifier of the storage space serving this application, this application can generate an access request carrying this storage space. Then, the computing node running this application makes the access request carry the identifier of this application and the identifier of this computing node, and sends the access request to the proxy node (for example, the access request generated by this application only contains the identifier of this storage space. When the computing node sends the initialization request to the proxy node through the data channel, the data channel will automatically make the access request contain the identifier of this computing node, etc.). After receiving the access request, since the proxy node stores the binding relationship between the identifier of this application, the identifier of this computing node, and this storage space, the proxy node can detect the access request based on this binding relationship to determine whether the access request contains both the identifier of this computing node and the identifier of this storage space. If the access request contains the identifier of this computing node and the identifier of this storage space, it indicates that the information contained in the access request conforms to this binding relationship, and the proxy node will perform different processing based on the specific type of the access request.
[0094] If the access request is a creation request for the storage space, the proxy node may send the access request to the management node so that the management node can detect the access request. If the access request contains the identifier of the storage space, it indicates that the information contained in the access request is legal. Therefore, the management node selects a certain storage node among multiple storage nodes and creates the storage space in this storage node. The identifier of the storage space can be used as the metadata (index) of the storage space. If the access request is a data processing request for the storage space, the proxy node may send the access request to this storage node so that this storage node can detect the access request. If the access request contains the identifier of the storage space, it indicates that the access request is legal. Therefore, this storage node can find the storage space based on the identifier of the storage space and process data in this storage space (for example, write data to this storage space, or read data from this storage space, or delete data in this storage space, etc.), so as to meet the data processing requirements of this application.
[0095] Still as in the above example, after Application 1 completes initialization, data processing can be performed. First, the business process of Application 1 can generate an access request, and the access request carries the UUID of Application 1. Then, the business process of Application 1 can send the access request to the SDK of Application 1. The SDK of Application 1 can convert the UUID of Application 1 in the access request into the namespace of Storage Space 1. Therefore, Virtual Machine 1 can send the access request carrying the namespace of Storage Space 1 to the DPU through the data channel. In this process, the data channel will automatically make the access request carry the UUID of Virtual Machine 1. Then, the DPU can detect the information carried by the access request. If the access request contains the information of Virtual Machine 1 and the namespace of Storage Space 1 that are mutually bound, it indicates that the information carried by the access request is legal.
[0096] Then, when the access request is a creation request for Storage Space 1, the DPU can send the access request to the storage management component so that the storage management component creates Storage Space 1 in a certain database node (the aforementioned storage node) and uses the namespace of Storage Space 1 as the metadata of Storage Space 1. When the access request is a data processing request for Storage Space 1, the DPU can send the access request to this database node so that this database node can detect the access request. If the access request carries the namespace of Storage Space 1, it indicates that the access request is legal. Therefore, this database node can find Storage Space 1 and complete operations such as data append, data read, and data delete in Storage Space 1, so as to meet the data processing requirements of Application 1.
[0097] In addition, an embodiment of the present application further provides a method for accessing a storage node cluster based on a proxy node. The method includes: the proxy node receives the binding relationship between the identifier of an application, the identifier of a computing node, and the identifier of a storage space from a cloud management platform. The identifier of the application and the identifier of the computing node are obtained by the cloud management platform from a tenant. The computing node runs the application, and the identifier of the storage space is generated by the cloud management platform. The storage space is used to store the data of the application; the proxy node receives an access request from the computing node, and based on the binding relationship, detects the access request. If the access request includes the identifier of the computing node and the identifier of the storage space, a storage space is created in the storage node cluster or data is processed in the storage space. For the introduction of this method, reference can be made to Figure 2 the relevant description part in the embodiment shown, which will not be elaborated here.
[0098] In the embodiments of the present application, when a tenant needs to bind the tenant's application and the tenant's computing node together, the tenant can input the identifier of the application and the identifier of the computing node to the binding interface provided by the cloud management platform. Then, the cloud management platform can determine the information of the storage space (for storing the data of the application) serving the application, so as to create a binding relationship among the identifier of the application, the identifier of the computing node, and the identifier of the storage space, and make the computing node run the application. Then, the cloud management platform can deploy the binding relationship in the proxy node. Since the proxy node is located between the computing node and the storage node cluster, when the proxy node receives an access request from the computing node, the proxy node can detect the access request based on the binding relationship. If the access request contains the identifier of the mutually bound computing node and the identifier of the storage space, the proxy node creates a storage space in the storage node cluster or processes data in the storage space. In the foregoing process, the cloud management platform can, at the request of the tenant, create a binding relationship indicating the identifier of the tenant's application, the identifier of the computing node running the application, and the identifier of the storage space serving the application, and deploy the binding relationship in the proxy node. When the computing node running the application sends an access request to the proxy node, the proxy node can perform a security check on the access request based on the binding relationship. If the access request passes the security check, it means that the information carried by the access request conforms to the binding relationship. Therefore, the proxy node can replace the computing node running the application to create a storage space serving the application in the storage node cluster (i.e., the storage pool) or access the storage space to complete data processing, so as to meet the data processing requirements of the application. Thus, it can be seen that the cloud management platform can use the binding relationship among the application, the computing node, and the storage space to instruct the proxy node to create a storage space dedicated to the tenant's application in the storage pool. When the computing node running the application needs to access the storage space, the proxy node can perform a security check on it. After passing the security check, the proxy node will replace the computing node to access the storage space to complete data processing. In this way, even if there are multiple applications, the proxy node can create a dedicated storage space for each application in the storage pool, so that multiple applications can share the same storage pool. When the computing nodes running each application need to access the corresponding storage space, the proxy node can perform a security check on them in real time. Only after passing the security check will it be allowed to access the corresponding storage space, which can ensure the data security among applications.
[0099] The above is a detailed description of the storage node cluster access method based on the cloud management platform and the storage node cluster access method based on the proxy node provided in the embodiments of the present application. The cloud management platform and the proxy node provided in the embodiments of the present application will be introduced below. Figure 6 It is a schematic structural diagram of the cloud management platform provided in the embodiments of the present application, asFigure 6 As shown, the cloud management platform is used to manage the infrastructure that provides cloud services. The infrastructure includes computing nodes, proxy nodes, and a storage node cluster. The cloud management platform includes:
[0100] A first receiving module 601, configured to receive the identifier of an application from a tenant and the identifier of a computing node through a binding interface; for example, the first receiving module 601 is used to implement Figure 2 Step 201 of the embodiment shown.
[0101] A first creating module 602, configured to create a binding relationship among the identifier of the application, the identifier of the computing node, and the identifier of the storage space, and deploy the application in the computing node. The storage space is used to store application data; for example, the first creating module 602 is used to implement Figure 2 Step 202 of the embodiment shown.
[0102] A deployment module 603, configured to deploy the binding relationship in the proxy node. The binding relationship is used to instruct the proxy node to detect an access request from the computing node. If the access request includes the identifier of the computing node and the identifier of the storage space, create a storage space in the storage node cluster or process data in the storage space. For example, the deployment module 603 is used to implement Figure 2 Step 203 of the embodiment shown.
[0103] In a possible implementation manner, the identifier of the storage space includes the namespace of the storage space.
[0104] In a possible implementation manner, the cloud management platform further includes: a second receiving module, configured to receive a creation request for the identifier of an application from a tenant through a creation interface; a second creating module, configured to create the identifier of the application based on the identifier creation request and provide the identifier of the application to the tenant through the creation interface.
[0105] In a possible implementation manner, the cloud management platform further includes: a notification module, configured to notify the tenant through the binding interface that the application has been bound to the computing node.
[0106] In a possible implementation manner, the storage node cluster includes multiple storage nodes and a management node for managing the multiple storage nodes. The deployment module is configured to send the binding relationship to the management node to deploy the binding relationship in the proxy node through the management node.
[0107] In a possible implementation manner, the binding relationship is further used to instruct the proxy node to detect an initialization request from the computing node. If the initialization request includes the identifier of the application and the identifier of the computing node, send the identifier of the storage space to the computing node.
[0108] In a possible implementation, the proxy node creating a storage space in the storage node cluster or processing data in the storage space includes: the proxy node sending an access request to the management node, where the access request is used to instruct the management node to detect the access request. If the access request contains the identifier of the storage space, a storage space is created in any one of the multiple storage nodes; or, the proxy node sending the access request to the storage node, where the access request is used to instruct the storage node to detect the access request. If the access request contains the identifier of the storage space, data is processed in the storage space.
[0109] In a possible implementation, the storage node cluster is located in the same site, and the site includes any one of the following: cabinet, computer room, data center, region, and availability zone.
[0110] In a possible implementation, the computing node includes any one of the following: physical server, bare metal server, virtual machine, and container.
[0111] Figure 7 A schematic structural diagram of the proxy node provided by an embodiment of this application is as Figure 7 shown. The proxy node is set in the infrastructure that provides cloud services. The infrastructure is managed by a cloud management platform and further includes computing nodes and a storage node cluster. The proxy node includes:
[0112] A receiving module 701, configured to receive the binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space from the cloud management platform. The identifier of the application and the identifier of the computing node are obtained by the cloud management platform from the tenant. The computing node runs the application, and the identifier of the storage space is generated by the cloud management platform. The storage space is used to store the data of the application. For example, the receiving module 701 can be used to implement the relevant steps of the storage node cluster access method based on the cloud management platform.
[0113] A processing module 702, configured to receive an access request from the computing node and detect the access request based on the binding relationship. If the access request contains the identifier of the computing node and the identifier of the storage space, a storage space is created in the storage node cluster or data is processed in the storage space. For example, the processing module 702 can be used to implement the relevant steps of the storage node cluster access method based on the cloud management platform.
[0114] In a possible implementation, the identifier of the storage space includes the namespace of the storage space.
[0115] In a possible implementation manner, the storage node cluster includes multiple storage nodes and a management node for managing the multiple storage nodes. The receiving module 701 is further configured to directly receive the binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space from the management node, and the binding relationship is obtained by the management node from the cloud management platform.
[0116] In a possible implementation manner, the proxy node further includes: a feedback module, configured to detect the initialization request from the computing node. If the initialization request includes the identifier of the application and the identifier of the computing node, the identifier of the storage space is sent to the computing node.
[0117] In a possible implementation manner, the processing module 702 is configured to: send the access request to the management node, where the access request is used to instruct the management node to detect the access request. If the access request includes the identifier of the storage space, a storage space is created in any one of the multiple storage nodes; or send the access request to the storage node, where the access request is used to instruct the storage node to detect the access request. If the access request includes the identifier of the storage space, data is processed in the storage space.
[0118] In a possible implementation manner, the storage node cluster is located in the same site, and the site includes any one of the following: cabinet, computer room, data center, region, and availability zone.
[0119] In a possible implementation manner, the computing node includes any one of the following: physical server, bare metal server, virtual machine, and container.
[0120] It should be noted that for the information interaction, implementation process, etc. between the above-mentioned device modules / units, since they are based on the same concept as the method embodiment of the present application, the technical effects brought by them are the same as those of the method embodiment of the present application. For the specific content, reference can be made to the description in the method embodiment shown in the foregoing of the embodiment of the present application, and details are not described herein again.
[0121] Please refer to Figure 8 , Figure 8 which is a schematic structural diagram of a computing device provided by an embodiment of the present application. As Figure 8 shown, the computing device 800 (which can be used to present the foregoing cloud management platform or proxy node) includes: a processor 801, a memory 802, a communication interface 803, and a bus 804. The processor 801, the memory 802, and the communication interface 803 are coupled through a bus (not marked in the figure). The memory 802 stores instructions. When the execution instructions in the memory 802 are executed, the computing device 800 executes the method steps executed by the cloud management platform or the proxy node in the above-mentioned method embodiment.
[0122] The computing device 800 may be one or more integrated circuits configured to implement the above methods, such as: one or more application specific integrated circuits (ASICs), or one or more digital signal processors (DSPs), or one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For another example, when the units in the device can be implemented in the form of a processing element scheduler, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call programs. For another example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0123] The processor 801 may be a central processing unit (CPU), or may also be other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0124] The memory 802 can be a volatile memory, a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0125] The executable program code is stored in the memory 802, and the processor 801 executes the executable program code to respectively implement the functions of the first receiving module, the first creating module, and the deployment module (or, the receiving module and the processing module in the proxy node) in the foregoing cloud management platform, so as to implement the above storage node cluster access method based on the cloud management platform (or proxy node). That is to say, the instructions for executing the above storage node cluster access method based on the cloud management platform (or proxy node) are stored on the memory 802.
[0126] The communication interface 803 uses a transceiver module such as, but not limited to, a network interface card and a transceiver to implement the communication between the computing device 800 and other devices or communication networks.
[0127] In addition to including a data bus, the bus 804 may further include a power bus, a control bus, a status signal bus, etc. The bus may be a Peripheral Component Interconnect Express (PCIe) bus, or an Extended Industry Standard Architecture (EISA) bus, a Unified Bus (Ubus or UB), a Compute Express Link (CXL), a Cache Coherent Interconnect for Accelerators (CCIX), etc. The bus may be divided into an address bus, a data bus, a control bus, etc.
[0128] Please refer to Figure 9 , Figure 9 which is a schematic structural diagram of a computing device cluster provided by an embodiment of the present application. As Figure 9 shown, the computing device cluster 900 includes at least one computing device 800.
[0129] As Figure 9 shown, the computing device cluster 900 includes at least one computing device 800. In the memory 802 of one or more of the computing devices 800 in the computing device cluster 900, the same instructions for executing the above-mentioned method for accessing a storage node cluster based on a cloud management platform (or a proxy node) may be stored.
[0130] In some possible implementation manners, in the memory 802 of one or more of the computing devices 800 in the computing device cluster 900, partial instructions for executing the above-mentioned method for accessing a storage node cluster based on a cloud management platform (or a proxy node) may also be stored respectively. In other words, a combination of one or more computing devices 800 may jointly execute the method for accessing a storage node cluster based on a cloud management platform (or a proxy node).
[0131] It should be noted that the memories 802 in different computing devices 800 in the computing device cluster 900 may store different instructions, which are respectively used to execute partial functions of the above-mentioned cloud management platform (or proxy node). That is, the instructions stored in the memories 802 of different computing devices 800 may implement the functions of one or more of the first receiving module, the first creating module, and the deployment module in the cloud management platform (or the receiving module and the processing module in the proxy node).
[0132] In some possible implementations, one or more computing devices 800 in the computing device cluster 900 can be connected via a network. Among them, the network can be a wide area network or a local area network, etc.
[0133] Please refer to Figure 10 , Figure 10 which is a schematic diagram of the connection of computer devices in the computer cluster provided by the embodiments of the present application via a network. As Figure 10 shown, two computing devices 800A and 800B are connected via a network. Specifically, they are connected to the network through the communication interfaces in each computing device.
[0134] In one possible implementation, the memory in computing device 800A stores instructions for executing functions of modules such as the first receiving module (or the receiving module), etc. At the same time, the memory in computing device 800B stores instructions for executing functions of modules such as the first creating module and the deployment module (or the processing module), etc.
[0135] It should be understood that Figure 10 the functions of computing device 800A shown in
[0136] The embodiments of the present application also relate to a computer storage medium, in which a program for signal processing is stored. When it runs on a computer, it causes the computer to execute the steps performed by the cloud management platform or the proxy node in the embodiments as Figure 2 shown.
[0137] The embodiments of the present application also relate to a computer program product, which stores instructions. When the instructions are executed by a computer, they cause the computer to execute the steps performed by the cloud management platform or the proxy node in the embodiments as Figure 2 shown.
[0138] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0139] In several embodiments provided in this application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there may be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed coupling, direct coupling, or communication connection to each other can be through some interfaces, and the indirect coupling or communication connection of the devices or units can be in electrical, mechanical, or other forms.
[0140] The units described as separate components may or may not be physically separated. The components displayed as units may or may not be physical units, that is, they can be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0141] In addition, in each embodiment of this application, the functional units can be integrated in a processing unit, or each unit can exist physically alone, or two or more units can be integrated in one unit. The above-mentioned integrated units can be implemented in the form of hardware or in the form of software functional units.
[0142] If the above-mentioned integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on such an understanding, the technical solution of this application, in essence, or the part that contributes to the prior art, or all or part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions to enable a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in each embodiment of this application. And the aforementioned storage medium includes: USB flash drives, mobile hard disks, read-only memories (ROM, read-only memory), random access memories (RAM, random access memory), magnetic disks, or optical discs, and other various media that can store program codes.
Claims
1. A storage node cluster access method based on a cloud management platform, characterized in that: The cloud management platform is used to manage the infrastructure for providing cloud services, the infrastructure includes computing nodes, proxy nodes and storage node clusters, and the method includes: The cloud management platform receives the identifier of the application and the identifier of the computing node from the tenant through a binding interface; The cloud management platform creates a binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space, and deploys the application in the computing node, and the storage space is used to store data of the application; The cloud management platform deploys the binding relationship in the proxy node, and the binding relationship is used to instruct the proxy node to detect the access request from the computing node. If the access request contains the identifier of the computing node and the identifier of the storage space, the storage space is created in the storage node cluster or the data is processed in the storage space.
2. The method according to claim 1, characterized in that The identifier of the storage space includes a namespace of the storage space.
3. The method according to claim 1 or 2, characterized in that: The method further comprises: The cloud management platform receives an identification creation request for the application from the tenant through a creation interface; The cloud management platform creates an identification of the application based on the identification creation request, and provides the identification of the application to the tenant through the creation interface.
4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: The cloud management platform notifies the tenant through the binding interface that the application has been bound to the computing node.
5. The method according to any one of claims 1 to 4, characterized in that: The storage node cluster includes multiple storage nodes and a management node for managing the multiple storage nodes, and the cloud management platform deploys the binding relationship in the proxy node including: The cloud management platform sends the binding relationship to the management node, so that the binding relationship is deployed in the proxy node through the management node.
6. The method according to any one of claims 1 to 5, characterized in that: The binding relationship is also used to instruct the proxy node to detect the initialization request from the computing node, and if the initialization request includes the identifier of the application and the identifier of the computing node, send the identifier of the storage space to the computing node.
7. The method according to claim 5, characterized in that The proxy node creates the storage space in the storage node cluster or processes the data in the storage space, including: The proxy node sends the access request to the management node, where the access request is used to instruct the management node to detect the access request, and if the access request includes the identifier of the storage space, creates the storage space in any one of the multiple storage nodes; or The proxy node sends the access request to the storage node, where the access request is used to instruct the storage node to detect the access request, and if the access request includes an identifier of the storage space, the data is processed in the storage space.
8. The method according to any one of claims 1 to 7, characterized in that: The storage node cluster is located in the same site, and the site includes any of the following: a cabinet, a computer room, a data center, a region, and an availability zone.
9. The method according to any one of claims 1 to 8, characterized in that: The computing node includes any of the following: a physical server, a bare metal server, a virtual machine, and a container.
10. A cloud management platform, characterized in that: The cloud management platform is used to manage the infrastructure for providing cloud services, the infrastructure includes computing nodes, proxy nodes and storage node clusters, and the cloud management platform includes: A first receiving module, configured to receive an identifier of the application and an identifier of the computing node from the tenant through a binding interface; A first creation module, used to create a binding relationship between the identifier of the application, the identifier of the computing node and the identifier of the storage space, and deploy the application in the computing node, the storage space is used to store data of the application; A deployment module is used to deploy the binding relationship in the proxy node, and the binding relationship is used to instruct the proxy node to detect the access request from the computing node. If the access request contains the identifier of the computing node and the identifier of the storage space, the storage space is created in the storage node cluster or the data is processed in the storage space.
11. The cloud management platform according to claim 10, characterized in that: The identifier of the storage space includes a namespace of the storage space.
12. The cloud management platform according to claim 10 or 11, characterized in that: The cloud management platform also includes: A second receiving module, configured to receive an identification creation request for the application from the tenant through a creation interface; The second creation module is used to create the identification of the application based on the identification creation request, and provide the identification of the application to the tenant through the creation interface.
13. The cloud management platform according to any one of claims 10 to 12, characterized in that: The cloud management platform also includes: A notification module is used to notify the tenant through the binding interface that the application has been bound to the computing node.
14. The cloud management platform according to any one of claims 10 to 13, characterized in that: The storage node cluster includes multiple storage nodes and a management node for managing the multiple storage nodes. The deployment module is used to send the binding relationship to the management node so as to deploy the binding relationship in the proxy node through the management node.
15. The cloud management platform according to any one of claims 10 to 14, characterized in that: The binding relationship is also used to instruct the proxy node to detect the initialization request from the computing node, and if the initialization request includes the identifier of the application and the identifier of the computing node, send the identifier of the storage space to the computing node.
16. The cloud management platform according to claim 14, characterized in that: The proxy node creates the storage space in the storage node cluster or processes the data in the storage space, including: The proxy node sends the access request to the management node, where the access request is used to instruct the management node to detect the access request, and if the access request includes the identifier of the storage space, creates the storage space in any one of the multiple storage nodes; or The proxy node sends the access request to the storage node, where the access request is used to instruct the storage node to detect the access request, and if the access request includes an identifier of the storage space, the data is processed in the storage space.
17. The cloud management platform according to any one of claims 10 to 16, characterized in that: The storage node cluster is located in the same site, and the site includes any of the following: a cabinet, a computer room, a data center, a region, and an availability zone.
18. The cloud management platform according to any one of claims 10 to 17, characterized in that: The computing node includes any of the following: a physical server, a bare metal server, a virtual machine, and a container.
19. A computing device cluster, characterized in that: The computing device cluster includes at least one computing device, each computing device including a processor and a memory: The memory is used to store instructions; The processor is configured to cause the computing device cluster to execute the method according to any one of claims 1 to 9 according to the instructions.
20. A computer storage medium, characterized in that The computer storage medium stores one or more instructions, which, when executed by one or more computers, enable the one or more computers to implement the method of any one of claims 1 to 9.
21. A computer program product, characterized in that The computer program product stores instructions, which, when executed by a computer, enable the computer to implement the method according to any one of claims 1 to 9.
Citation Information
Cited By
Cloud service system and data transmission method
CN121151413A
Storage node cluster access method and cloud management platform
EP4808085A1
Storage node cluster access method and cloud management platform
WO2025108286A1