Server cluster management method and device, computer equipment and storage medium
Through a unified trust library and thread pool mechanism, arbitration services are provided for multiple clusters, solving the problems of complex resource waste and operation and maintenance under traditional deployment methods, and achieving efficient and scalable arbitration service management.
Patent Information
- Application Number
- CN202510098387.7
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-22
- Publication Date
- 2025-05-30
AI Technical Summary
The traditional arbitration service deployment method requires the deployment of IP arbitration procedures for each cluster separately, resulting in waste of hardware resources, high operation and maintenance complexity and difficulty in scaling.
Through a unified trust database, arbitration services are provided to multiple clusters, and arbitration procedures are centrally deployed to achieve multi-cluster arbitration service management.
Improve resource utilization, reduce operation and maintenance costs, simplify certificate management and configuration, and facilitate the expansion of arbitration services to meet the growing demand.
Smart Images

Figure CN120075025A_ABST
Abstract
Description
Technical Field
[0001] The present application relates to the technical field of distributed systems, and particularly to a server cluster management method, apparatus, computer device, and storage medium. Background Art
[0002] In a distributed system, a cluster arbitration service ensures the high availability and data consistency of the cluster. The traditional arbitration service deployment method is to deploy one or more IP arbitration programs separately for each multi-control cluster that requires the arbitration service to perform arbitration determination when nodes compete for arbitration and prevent the occurrence of split-brain phenomena.
[0003] Although this method realizes the independence of the IP arbitration program, with the expansion of the scale of the distributed system and technological progress, deploying IP arbitration programs separately for each cluster will occupy a large amount of hardware resources, resulting in waste of computing and storage resources. Especially in a large-scale distributed environment, as the number of clusters increases, the number of required IP arbitration programs grows exponentially, making it more difficult to manage and allocate resources. Secondly, since each IP arbitration program needs to be independently configured, monitored, and maintained, when a new cluster is added, new IP arbitration programs must be added, significantly increasing the operation and maintenance complexity. Summary of the Invention
[0004] Based on this, it is necessary to provide a server cluster management method, apparatus, computer device, and storage medium that can provide arbitration services for multiple clusters through a unified trust library for the above technical problems.
[0005] On the one hand, a server cluster management method is provided, and the method includes:
[0006] Obtain cluster information of multiple clusters by reading a configuration file, where the cluster information includes a cluster identifier and node addresses of multiple nodes in the cluster;
[0007] Obtain certificate files of the multiple clusters and add the certificate files to a trust library;
[0008] Create a thread pool corresponding to the cluster according to the cluster identifier, where the thread pool is used to receive arbitration requests of the cluster and provide arbitration services;
[0009] Send connection requests to the node addresses through threads in the thread pool and perform identity authentication through the trust library to establish communication connections between the multiple clusters and the corresponding thread pools.
[0010] In one embodiment, the method further includes:
[0011] Deploy an arbitration program on an arbitration server, where the arbitration program includes thread pools corresponding to the multiple clusters, where the thread pools correspond to the clusters one by one, and resources between the thread pools are isolated;
[0012] Obtain certificate files of the multiple clusters and store the certificate files in a specified directory of the arbitration program.
[0013] In one embodiment, there are one or more arbitration programs, and deploying the arbitration program on the arbitration server further includes:
[0014] In response to there being multiple arbitration programs, determine a primary arbitration program from the arbitration programs, and use other arbitration programs as standby arbitration programs;
[0015] In response to the primary arbitration program failing, select one of the standby arbitration programs to take over the primary arbitration program for cluster arbitration.
[0016] In one embodiment, obtaining the certificate files of the multiple clusters and adding the certificate files to a trust store includes:
[0017] Create corresponding key stores for the multiple clusters respectively;
[0018] Obtain verification information according to the certificate files of the clusters and load the verification information into the key stores corresponding to the clusters, where the verification information includes an alias, a certificate, and a key;
[0019] Traverse the aliases in the key stores to obtain the corresponding certificates and keys, and add the certificates and keys to the trust store;
[0020] Create a first factory class and set the trust store as the trust source of the first factory class, where the first factory class is used to create a trust manager;
[0021] Create a security context and initialize the security context through the first factory class, where the security context is used to manage security protocols;
[0022] Obtain a second factory class through the security context and create and manage secure sockets through the second factory class, where the secure sockets are used to encrypt data for communication connections between the multiple nodes and the corresponding thread pools.
[0023] In one embodiment, sending a connection request to the node address through a thread in the thread pool and performing authentication through the trust store to establish a communication connection between the multiple clusters and the corresponding thread pools includes:
[0024] Establish socket connections with the multiple nodes through the threads in the thread pool, and perform authentication and data encryption using the verification information in the trust store and the secure socket;
[0025] Obtain the cluster identifier of the cluster where the node is located, and send a connection request to the cluster based on the cluster identifier to establish a communication connection between the arbitration program and the multiple clusters.
[0026] In one embodiment, after establishing the communication connection between the multiple clusters and the corresponding thread pools, it further includes:
[0027] Regularly send heartbeat message requests to the multiple clusters through the arbitration program;
[0028] Receive the heartbeat message responses sent by the multiple clusters based on the heartbeat message requests;
[0029] Monitor the network communication connection status of the multiple clusters according to the heartbeat message responses, and determine whether to perform cluster arbitration based on the monitoring results.
[0030] In one embodiment, the monitoring the network communication connection status of the multiple clusters according to the heartbeat message responses and determining whether to perform cluster arbitration includes:
[0031] In response to not receiving the heartbeat message response within a preset time, perform cluster arbitration, causing the multiple nodes to send arbitration requests to the corresponding thread pools. The arbitration requests include arbitration information, and the arbitration information includes the cluster identifier corresponding to the node;
[0032] In response to the thread pool receiving the arbitration request, find the corresponding cluster according to the cluster identifier and perform arbitration determination.
[0033] On the other hand, a server cluster management device is provided. The device includes:
[0034] An acquisition module for acquiring the cluster information of multiple clusters by reading a configuration file. The clusters include multiple nodes, and the cluster information includes the cluster identifier and the node addresses of the multiple nodes;
[0035] A loading module for loading the certificate files of the multiple clusters and adding the certificate files to the trust store;
[0036] A creation module for creating a thread pool corresponding to the cluster according to the cluster identifier. The thread pool is used to receive the arbitration requests of the cluster and provide arbitration services;
[0037] A communication module, which is used to send a connection request to the node address through a thread in the thread pool and perform authentication through the trust store to establish a communication connection between the multiple nodes and the corresponding thread pool.
[0038] In another aspect, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:
[0039] Obtain the cluster information of multiple clusters by reading a configuration file, where the cluster information includes a cluster identifier and the node addresses of multiple nodes within the cluster;
[0040] Obtain the certificate files of the multiple clusters and add the certificate files to the trust store;
[0041] Create a thread pool corresponding to the cluster according to the cluster identifier, where the thread pool is used to receive arbitration requests of the cluster and provide arbitration services;
[0042] Send a connection request to the node address through a thread in the thread pool and perform authentication through the trust store to establish a communication connection between the multiple clusters and the corresponding thread pools.
[0043] In yet another aspect, a computer-readable storage medium is provided, on which a computer program is stored. When the computer program is executed by a processor, the following steps are implemented:
[0044] Obtain the cluster information of multiple clusters by reading a configuration file, where the cluster information includes a cluster identifier and the node addresses of multiple nodes within the cluster;
[0045] Obtain the certificate files of the multiple clusters and add the certificate files to the trust store;
[0046] Create a thread pool corresponding to the cluster according to the cluster identifier, where the thread pool is used to receive arbitration requests of the cluster and provide arbitration services;
[0047] Send a connection request to the node address through a thread in the thread pool and perform authentication through the trust store to establish a communication connection between the multiple clusters and the corresponding thread pools.
[0048] The above server cluster management method, device, computer device and storage medium add the certificate files of all clusters to the trust store to form a unified trust source instance, providing necessary authentication information for subsequent socket connections. And a thread pool is created according to the cluster identifier, and the threads in each thread pool are responsible for processing arbitration requests from the corresponding cluster. By deploying a single instance centrally to provide arbitration services for different clusters, the utilization rate of resources is improved and the operation and maintenance cost is reduced. At the same time, as the scale of the distributed system expands, the number of threads in the thread pool or the hardware resources of the arbitration instance can be easily increased to meet the growing arbitration service requirements. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] Figure 1 is a structural block diagram of deployment methods of multiple arbitration services in the traditional solution;
[0050] Figure 2 is a structural block diagram of a deployment method of a single arbitration service in an embodiment;
[0051] Figure 3 is a schematic flowchart of a server cluster management method in an embodiment;
[0052] Figure 4 is a schematic flowchart of a server cluster management method in another embodiment;
[0053] Figure 5 is a structural block diagram of a server cluster management device in an embodiment;
[0054] Figure 6 is an internal structure diagram of a computer device in an embodiment. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0055] In order to make the objectives, technical solutions and advantages of the present application clearer, the present application will be further described in detail below with reference to the accompanying drawings and embodiments. It should be understood that the specific embodiments described herein are only used to explain the present application and are not used to limit the present application.
[0056] As Figure 1 shown, in order to provide arbitration services, an IP arbitration program is configured for each multi-control cluster. Since each cluster needs to deploy and maintain an arbitration instance separately, a large amount of hardware resources are occupied, and the complexity and cost of operation and maintenance are increased. At the same time, as the number of clusters increases, the expansion of arbitration instances becomes extremely difficult.
[0057] Therefore, to solve the problem of arbitration service deployment in a distributed system, this application proposes a method in which a single-IP arbitration program provides arbitration services for multiple clusters. By centrally deploying an instance of the IP arbitration program and utilizing multi-threading technology and resource isolation mechanisms, efficient and reliable arbitration services are provided for multiple clusters.
[0058] In one embodiment, as Figures 2 - 4 shown, a server cluster management method is provided, including the following steps:
[0059] Step S1, obtain the cluster information of multiple clusters by reading a configuration file, where the cluster information includes a cluster identifier and the node addresses of multiple nodes within the cluster.
[0060] It should be noted that, in order to distinguish different clusters and provide personalized arbitration services for them, this embodiment records the cluster ID and node IP information of each cluster in the configuration file (config.xml). Among them, the cluster ID is the unique identifier of the cluster, used to distinguish different clusters and create corresponding thread pools, and the node IP is the IP address of the arbitration service in the cluster, used to initiate socket connections to the corresponding nodes through the threads in the thread pool.
[0061] Exemplarily, assume there are two clusters, named Cluster 1 and Cluster 2 respectively. The config file records the clusterid and serviceip information of each cluster, and the content example is as follows:
[0062] <config>
[0063] <cluster>
[0064] <clusterid>cluster1< / clusterid>
[0065] <serviceip> 192.168.1.10< / serviceip>
[0066] < / cluster>
[0067] <cluster>
[0068] <clusterid>cluster2< / clusterid>
[0069] <serviceip> 192.168.1.11< / serviceip>
[0070] < / cluster>
[0071] <!--More clusters can be added-->[[]]END]]
[0072] < / config>
[0073] Based on the above steps, the IP arbitration program can accurately read the cluster information in the configuration file for subsequent creation of thread pools and initiation of socket connections.
[0074] In an alternative embodiment, it further includes: deploying an arbitration program on an arbitration server, where the arbitration program includes thread pools corresponding to multiple clusters, and the thread pools are in one-to-one correspondence with the clusters, and the resources between the thread pools are isolated; obtaining the certificate files of multiple clusters and storing the certificate files in a specified directory of the arbitration program.
[0075] Specifically, in order to ensure that the arbitration services between different clusters do not interfere with each other, complete isolation of resources is implemented in each thread pool, including memory isolation, context isolation, and network connection isolation between threads, etc. Through the resource isolation mechanism, it can be ensured that the arbitration services provided by each thread pool are independent and reliable, and will not be affected by other clusters, so that each cluster has an independent thread pool to handle its arbitration requests.
[0076] In an alternative embodiment, there is one or more arbitration procedures, and the arbitration procedures are deployed on an arbitration server, further including: in response to there being multiple arbitration procedures, determining a primary arbitration procedure from the arbitration procedures, and using other arbitration procedures as standby arbitration procedures; in response to the primary arbitration procedure failing, selecting a standby arbitration procedure to take over the primary arbitration procedure for cluster arbitration.
[0077] Specifically, IP arbitration procedures can be deployed on multiple servers to serve as redundancy for the arbitration service. Only one arbitration service is effective for storage at the same time, that is, the primary arbitration procedure. When the server where the primary arbitration procedure is located fails, one can be selected from the standby arbitration procedures to serve as the effective arbitration to take over the primary arbitration procedure and continue to provide the arbitration service, avoiding the loss of the arbitration service.
[0078] Step S2: Obtain the certificate files of multiple clusters and add the certificate files to the trust store.
[0079] It should be noted that in a distributed system, to ensure the security of communication, each cluster uses the SSL (Secure Socket Layer) / TLS (Transport Layer Security) protocol for encrypted communication. Therefore, each cluster has its own certificate file. For example, the certificate files of cluster 1 and cluster 2 are named cert1.pfx and cert2.pfx respectively, and these certificate files are centrally stored in the specified directory of the IP arbitration procedure for subsequent establishment of a secure communication connection.
[0080] In an alternative embodiment, obtaining the certificate files of multiple clusters and adding the certificate files to the trust store includes:
[0081] Step S201: Create corresponding key stores for multiple clusters respectively.
[0082] Specifically, to manage the certificates and keys of each cluster, an independent key store (KeyStore) needs to be created for each cluster. For example, for cluster 1 and cluster 2, two KeyStore instances are created respectively, named ks_cluster1 and ks_cluster2. Each KeyStore is used to store aliases, certificates, and keys, where the alias is the unique identifier of the certificate and key.
[0083] Step S202: Obtain verification information according to the certificate file of the cluster and load the verification information into the key store corresponding to the cluster. The verification information includes an alias, a certificate, and a key.
[0084] By reading the certificate files of each cluster (such as cert1.pfx and cert2.pfx), use the load method to load the certificate files into the corresponding KeyStore instance.
[0085] Step S203, traverse the aliases in the key store to obtain the corresponding certificates and keys, and add the certificates and keys to the trust store.
[0086] To centrally manage and use the certificate files of all clusters, create an empty KeyStore instance as the trust store, named ks_merge. Then traverse the aliases in ks_cluster1 and ks_cluster2 to obtain the corresponding certificates and keys, and add the certificates and keys to the ks_merge instance. In this way, ks_merge combines the trust source content from ks_cluster1 and ks_cluster2 to form a unified trust store.
[0087] Step S204, create the first factory class and set the trust store as the trust source of the first factory class, where the first factory class is used to create a trust manager.
[0088] Among them, in Java, the factory class is a design class that follows the factory pattern. The factory pattern aims to encapsulate the object creation process, reducing the code's dependence on the specific implementation class, thereby improving the flexibility, maintainability, and scalability of the system. Therefore, the factory class is like an object manufacturing factory that produces different types of object instances according to different requirements (input parameters, etc.).
[0089] Specifically, create a TrustManagerFactory instance, that is, the first factory class, named tmf, and set the merged ks_merge instance as its trust source. Among them, TrustManagerFactory is a class in the Java Secure Sockets Extension (JSSE), which acts as a factory for trust managers based on the trust source. In this way, it can ensure the correct verification of the peer identity during the SSL / TLS handshake process.
[0090] Step S205, create a security context and initialize the security context through the first factory class, where the security context is used to manage the security protocol.
[0091] Create an SSLContext instance, that is, a security context, and initialize this instance using the TrustManagerFactory. Among them, SSLContext represents the implementation of the secure socket protocol and is used as a factory to create SSLSocketFactory, SSLServerSocketFactory, and SSLEngine. This step ensures that all communications between cluster nodes are encrypted and authenticated, improving the security of the communication.
[0092] Step S206: Obtain the second factory class through the security context, and create and manage secure sockets through the second factory class. The secure sockets are used to encrypt the data for the communication connections between multiple nodes and the corresponding thread pools.
[0093] Use the getSocketFactory method of SSLContext to obtain the SSLSocketFactory instance, that is, the second factory class. SSLSocketFactory is a factory class provided by Java. It is used to create and manage SSL sockets. SSL is a security protocol used to establish encrypted connections on the Internet to ensure the integrity and confidentiality of data. The secure sockets created through SSLSocketFactory can use the correct trust certificates during the SSL / TLS handshake process to ensure the encryption of the communication connections between multiple nodes and the corresponding thread pools.
[0094] Based on the above steps, the IP arbitration program can effectively obtain the certificate files of multiple clusters and merge and add them to a unified trust store, thus ensuring that the communications with each cluster are both secure and reliable. This method not only simplifies the certificate management and configuration but also improves the overall security of the system.
[0095] Step S3: Create a thread pool corresponding to the cluster according to the cluster identifier. The thread pool is used to receive the arbitration requests of the cluster and provide arbitration services.
[0096] It should be noted that in the IP arbitration program, in order to effectively manage and process the arbitration requests from different clusters, a corresponding thread pool is created for each cluster to ensure that each cluster has the corresponding thread pool resources to process its arbitration requests, avoiding task interference between different clusters.
[0097] In an alternative embodiment, a connection request is sent to the node address by a thread in the thread pool, and authentication is performed through the trust store to establish a communication connection between multiple clusters and the corresponding thread pools, including: establishing socket connections with multiple nodes by threads in the thread pool, and performing authentication and data encryption using the authentication information in the trust store and secure sockets; obtaining the cluster identifier of the cluster where the node is located, and sending a connection request to the cluster according to the cluster identifier to establish a communication connection between the arbitration program and multiple clusters.
[0098] Specifically, when establishing communication between the IP arbitration program and all nodes in the cluster, a socket connection is initiated to the node address by a thread in the corresponding thread pool of the cluster. Moreover, during the connection establishment process, the thread authenticates the remote node using the authentication information in the unified trust store to ensure that it is a legitimate cluster member. Meanwhile, two-way authentication is completed during the handshake using secure sockets to ensure the trustworthiness of the identities of both communication parties and the confidentiality of the transmitted data.
[0099] Step S4, a connection request is sent to the node address by a thread in the thread pool, and authentication is performed through the trust store to establish a communication connection between multiple clusters and the corresponding thread pools.
[0100] Exemplarily, for Cluster 1 and Cluster 2, thread pools named Thread Pool 1 and Thread Pool 2 are respectively created for the two clusters according to the cluster ID. During the connection process, the threads in Thread Pool 1 initiate a socket connection to 192.168.1.10, and the threads in Thread Pool 2 initiate a socket connection to 192.168.1.11. Among them, the socket connection is a communication protocol, which is the interface between the application layer and the transport layer and is used to achieve communication between processes on the network.
[0101] In an alternative embodiment, after establishing the communication connection between multiple clusters and the corresponding thread pools, it further includes: sending heartbeat message requests to multiple clusters regularly through the arbitration program; receiving the heartbeat message responses sent by multiple clusters based on the heartbeat message requests; monitoring the network communication connection status of multiple clusters according to the heartbeat message responses, and determining whether to perform cluster arbitration according to the monitoring results.
[0102] It should be noted that in a distributed system, when nodes in the cluster are invisible to each other due to network partitioning or other reasons, independent operations of the invisible nodes will cause data inconsistency. Therefore, in order to effectively monitor and prevent split-brain, heartbeat monitoring can be performed between nodes, or heartbeat monitoring can be performed on each node through the IP arbitration program.
[0103] Specifically, after establishing secure communication connections between multiple clusters and corresponding thread pools, a heartbeat message mechanism is introduced to monitor the network communication status between the IP arbitration program and each cluster, and based on this, it is determined whether to initiate the cluster arbitration process. If all clusters respond to the heartbeat message in a timely and correct manner, the network communication connection is considered stable and no additional operations are required.
[0104] In an alternative embodiment, monitoring the network communication connection status of multiple clusters based on the heartbeat message response and determining whether to perform cluster arbitration according to the monitoring result includes: obtaining the time interval between the heartbeat message response and the heartbeat message request; in response to the time interval being within a preset time range, determining that the network communication connection status with the cluster is a normal connection status; in response to the time interval exceeding the preset time range, determining that the network communication connection status with the cluster is a disconnected status; taking the cluster in the disconnected status as the target cluster and sending a reconnect request to the target cluster to re - establish a network communication connection with the target cluster; in response to the failure of re - establishing the network communication connection, recording the number of reconnection attempts, and determining a time period based on the number of reconnection attempts, and sending subsequent reconnect requests to the target cluster according to the time period; in response to a change in the view of the target cluster, receiving an arbitration request sent by a node in the target cluster and performing cluster arbitration.
[0105] Among them, after the IP arbitration program initiates a heartbeat message request, it is possible that due to network instability, the heartbeat message response from the node is not received, which will cause the network communication connection between the IP arbitration program and each node to be disconnected. After the connection is disconnected, the IP arbitration program will sleep according to a preset time period, and then send a reconnect request to the target cluster. If a reconnect response sent by the target cluster is received, it is determined that the reconnection is successful.
[0106] In an alternative embodiment, monitoring the network communication connection status of multiple clusters based on the heartbeat message response and determining whether to perform cluster arbitration according to the monitoring result includes: in response to not receiving a heartbeat message response within a preset time, performing cluster arbitration, causing multiple nodes to send arbitration requests to the corresponding thread pools, where the arbitration request includes arbitration information, and the arbitration information includes the cluster identifier corresponding to the node; in response to the thread pool receiving the arbitration request, looking up the corresponding cluster according to the cluster identifier and performing arbitration determination.
[0107] It should be understood that although Figures 3 - 4 the steps in the flowchart Figures 3 - 4At least some of the steps may include multiple sub-steps or multiple phases, and these sub-steps or phases do not necessarily need to be executed and completed at the same time, but can be executed at different times. The execution order of these sub-steps or phases does not necessarily need to be sequential, but can be executed alternately or in turns with at least some of the sub-steps or phases of other steps or other steps.
[0108] In one embodiment, as Figure 5 shown, a server cluster management device is provided, including: an acquisition module, a loading module, a creation module, and a communication module, where:
[0109] The acquisition module is used to obtain the cluster information of multiple clusters by reading the configuration file. The cluster includes multiple nodes, and the cluster information includes the cluster identifier and the node addresses of multiple nodes;
[0110] The loading module is used to load the certificate files of multiple clusters and add the certificate files to the trust store;
[0111] The creation module is used to create a thread pool corresponding to the cluster according to the cluster identifier. The thread pool is used to receive arbitration requests of the cluster and provide arbitration services;
[0112] The communication module is used to send connection requests to the node addresses through the threads in the thread pool and perform authentication through the trust store to establish communication connections between multiple nodes and the corresponding thread pools.
[0113] In one embodiment, it further includes a deployment module, which is used to deploy an arbitration program on the arbitration server. The arbitration program includes thread pools corresponding to multiple clusters, where the thread pools are in one-to-one correspondence with the clusters and the resources between the thread pools are isolated; obtain the certificate files of multiple clusters and store the certificate files in the specified directory of the arbitration program.
[0114] In one embodiment, the deployment module is further used to, in response to there being multiple arbitration programs, determine the primary arbitration program from the arbitration programs, and use other arbitration programs as standby arbitration programs; in response to the primary arbitration program failing, select a standby arbitration program to take over the primary arbitration program for cluster arbitration.
[0115] In one embodiment, the loading module is further configured to create corresponding key stores for multiple clusters respectively; obtain verification information according to the certificate files of the clusters, and load the verification information into the key stores corresponding to the clusters, where the verification information includes aliases, certificates, and keys; traverse the aliases in the key stores to obtain the corresponding certificates and keys, and add the certificates and keys to the trust store; create a first factory class, and set the trust store as the trust source of the first factory class, where the first factory class is used to create a trust manager; create a security context, and initialize the security context through the first factory class, where the security context is used to manage security protocols; obtain a second factory class through the security context, and create and manage a secure socket through the second factory class, where the secure socket is used to encrypt data for the communication connections between multiple nodes and the corresponding thread pools.
[0116] In one embodiment, the communication module is further configured to establish socket connections with multiple nodes through the threads in the thread pool, and perform authentication and data encryption by using the verification information in the trust store and the secure socket; obtain the cluster identifier of the cluster where the node is located, and send a connection request to the cluster according to the cluster identifier to establish a communication connection between the arbitration program and multiple clusters.
[0117] In one embodiment, a monitoring module is further included, which is configured to send heartbeat message requests to multiple clusters regularly through the arbitration program; receive the heartbeat message responses sent by multiple clusters based on the heartbeat message requests; monitor the network communication connection status of multiple clusters according to the heartbeat message responses, and determine whether to perform cluster arbitration according to the monitoring results.
[0118] In one embodiment, an arbitration module is further included, which is configured to perform cluster arbitration in response to not receiving a heartbeat message response within a preset time, so that multiple nodes send arbitration requests to the corresponding thread pools, where the arbitration requests include arbitration information, and the arbitration information includes the cluster identifier corresponding to the node; in response to the thread pool receiving the arbitration request, find the corresponding cluster according to the cluster identifier, and perform an arbitration determination.
[0119] For the specific limitations of the server cluster management device, reference can be made to the limitations of the server cluster management method in the above text, which will not be elaborated here. Each module in the above server cluster management device can be implemented in whole or in part by software, hardware, and their combinations. The above modules can be embedded in the processor of the computer device in hardware form or be independent of it, or can be stored in the memory of the computer device in software form, so that the processor can call and execute the operations corresponding to the above modules.
[0120] In one embodiment, a computer device is provided. The computer device can be a server, and its internal structure diagram can be as Figure 6As shown in the figure. The computer device includes a processor, a memory, a network interface, and a database connected through a system bus. Among them, the processor of the computer device is used to provide computing and control capabilities. The memory of the computer device includes a non-volatile storage medium and an internal memory. The non-volatile storage medium stores an operating system, a computer program, and a database. The internal memory provides an environment for the operation of the operating system and the computer program in the non-volatile storage medium. The database of the computer device is used to store verification information data of multiple clusters. The network interface of the computer device is used to communicate with an external terminal through a network connection. When the computer program is executed by the processor, it implements a server cluster management method.
[0121] Those skilled in the art can understand that Figure 6 the structure shown in the figure is only a block diagram of some structures related to the solution of the present application, and does not constitute a limitation on the computer device to which the solution of the present application is applied. The specific computer device may include more or fewer components than those shown in the figure, or combine some components, or have a different component layout.
[0122] In one embodiment, a computer device is provided, including a memory, a processor, and a computer program stored on the memory and executable on the processor. When the processor executes the computer program, the following steps are implemented:
[0123] Obtain the cluster information of multiple clusters by reading the configuration file, where the cluster information includes the cluster identifier and the node addresses of multiple nodes in the cluster;
[0124] Obtain the certificate files of multiple clusters and add the certificate files to the trust store;
[0125] Create a thread pool corresponding to the cluster according to the cluster identifier, where the thread pool is used to receive arbitration requests of the cluster and provide arbitration services;
[0126] Send connection requests to the node addresses through the threads in the thread pool and perform identity authentication through the trust store to establish communication connections between multiple clusters and the corresponding thread pools.
[0127] In one embodiment, when the processor executes the computer program, the following steps are also implemented: Deploy an arbitration program on the arbitration server, where the arbitration program includes thread pools corresponding to multiple clusters, where the thread pools are in one-to-one correspondence with the clusters and the resources between the thread pools are isolated; Obtain the certificate files of multiple clusters and store the certificate files in the specified directory of the arbitration program.
[0128] In one embodiment, when the processor executes the computer program, the following steps are further implemented: in response to there being multiple arbitration programs, determine the primary arbitration program from the arbitration programs, and use the other arbitration programs as backup arbitration programs; in response to a failure of the primary arbitration program, select a backup arbitration program to take over the primary arbitration program for cluster arbitration.
[0129] In one embodiment, when the processor executes the computer program, the following steps are further implemented: create corresponding key stores for multiple clusters respectively; obtain verification information according to the certificate files of the clusters, and load the verification information into the key stores corresponding to the clusters, where the verification information includes aliases, certificates, and keys; traverse the aliases in the key stores to obtain the corresponding certificates and keys, and add the certificates and keys to the trust store; create a first factory class, and set the trust store as the trust source of the first factory class, where the first factory class is used to create a trust manager; create a security context, and initialize the security context through the first factory class, where the security context is used to manage security protocols; obtain a second factory class through the security context, and create and manage secure sockets through the second factory class, where the secure sockets are used to encrypt data for the communication connections between multiple nodes and the corresponding thread pools.
[0130] In one embodiment, when the processor executes the computer program, the following steps are further implemented: establish socket connections with multiple nodes through the threads in the thread pool, and perform authentication and data encryption using the verification information in the trust store and the secure sockets; obtain the cluster identifier of the cluster where the node is located, and send a connection request to the cluster according to the cluster identifier to establish a communication connection between the arbitration program and multiple clusters.
[0131] In one embodiment, when the processor executes the computer program, the following steps are further implemented: regularly send heartbeat message requests to multiple clusters through the arbitration program; receive the heartbeat message responses sent by multiple clusters based on the heartbeat message requests; monitor the network communication connection status of multiple clusters according to the heartbeat message responses, and determine whether to perform cluster arbitration according to the monitoring results.
[0132] In one embodiment, when the processor executes the computer program, the following steps are further implemented: in response to not receiving a heartbeat message response within a preset time, perform cluster arbitration, causing multiple nodes to send arbitration requests to the corresponding thread pools, where the arbitration requests include arbitration information, and the arbitration information includes the cluster identifier corresponding to the node; in response to the thread pool receiving the arbitration request, find the corresponding cluster according to the cluster identifier and perform arbitration determination.
[0133] In one embodiment, a computer-readable storage medium is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0134] Obtain the cluster information of multiple clusters by reading the configuration file. The cluster information includes the cluster identifier and the node addresses of multiple nodes within the cluster;
[0135] Obtain the certificate files of multiple clusters and add the certificate files to the trust store;
[0136] Create a thread pool corresponding to the cluster according to the cluster identifier. The thread pool is used to receive arbitration requests of the cluster and provide arbitration services;
[0137] Send connection requests to the node addresses through the threads in the thread pool and perform identity authentication through the trust store to establish communication connections between multiple clusters and the corresponding thread pools.
[0138] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: Deploy an arbitration program on the arbitration server. The arbitration program includes thread pools corresponding to multiple clusters, where the thread pools correspond to the clusters one by one and the resources between the thread pools are isolated; Obtain the certificate files of multiple clusters and store the certificate files in the specified directory of the arbitration program.
[0139] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: In response to multiple arbitration programs, determine the main arbitration program from the arbitration programs, and use other arbitration programs as standby arbitration programs; In response to the failure of the main arbitration program, select a standby arbitration program to take over the main arbitration program for cluster arbitration.
[0140] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: Create corresponding key stores for multiple clusters respectively; Obtain verification information according to the certificate files of the clusters and load the verification information into the key stores corresponding to the clusters. The verification information includes aliases, certificates, and keys; Traverse the aliases in the key store to obtain the corresponding certificates and keys, and add the certificates and keys to the trust store; Create a first factory class and set the trust store as the trust source of the first factory class, where the first factory class is used to create a trust manager; Create a security context and initialize the security context through the first factory class, where the security context is used to manage security protocols; Obtain a second factory class through the security context and create and manage secure sockets through the second factory class. The secure sockets are used to encrypt data for the communication connections between multiple nodes and the corresponding thread pools.
[0141] In one embodiment, when the computer program is executed by the processor, the following steps are further implemented: Establish socket connections with multiple nodes through the threads in the thread pool, and perform identity authentication and data encryption using the verification information in the trust store and the secure sockets; Obtain the cluster identifier of the cluster where the node is located, and send a connection request to the cluster according to the cluster identifier to establish a communication connection between the arbitration program and multiple clusters.
[0142] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: periodically send heartbeat message requests to multiple clusters through an arbitration program; receive heartbeat message responses sent by the multiple clusters based on the heartbeat message requests; monitor the network communication connection status of the multiple clusters according to the heartbeat message responses, and determine whether to perform cluster arbitration based on the monitoring results.
[0143] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: in response to not receiving a heartbeat message response within a preset time, perform cluster arbitration, causing multiple nodes to send arbitration requests to the corresponding thread pools, where the arbitration requests include arbitration information, and the arbitration information includes the cluster identifier corresponding to the node; in response to the thread pool receiving the arbitration request, find the corresponding cluster according to the cluster identifier and perform arbitration determination.
[0144] In one embodiment, a computer product is provided, on which a computer program is stored, and when the computer program is executed by a processor, the following steps are implemented:
[0145] Obtain the cluster information of multiple clusters by reading a configuration file, where the cluster information includes the cluster identifier and the node addresses of multiple nodes within the cluster;
[0146] Obtain the certificate files of multiple clusters and add the certificate files to the trust store;
[0147] Create a thread pool corresponding to the cluster according to the cluster identifier, where the thread pool is used to receive arbitration requests of the cluster and provide arbitration services;
[0148] Send connection requests to the node addresses through the threads in the thread pool and perform authentication through the trust store to establish communication connections between multiple clusters and the corresponding thread pools.
[0149] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: deploy an arbitration program on an arbitration server, where the arbitration program includes thread pools corresponding to multiple clusters, where the thread pools correspond to the clusters one by one and the resources between the thread pools are isolated; obtain the certificate files of multiple clusters and store the certificate files in a specified directory of the arbitration program.
[0150] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: in response to there being multiple arbitration programs, determine the main arbitration program from the arbitration programs, and use other arbitration programs as standby arbitration programs; in response to the main arbitration program failing, select a standby arbitration program to take over the main arbitration program for cluster arbitration.
[0151] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: creating corresponding key stores for multiple clusters respectively; obtaining verification information according to the certificate files of the clusters and loading the verification information into the key stores corresponding to the clusters, where the verification information includes aliases, certificates, and keys; traversing the aliases in the key stores to obtain the corresponding certificates and keys and adding the certificates and keys to the trust store; creating a first factory class and setting the trust store as the trust source of the first factory class, where the first factory class is used to create a trust manager; creating a security context and initializing the security context through the first factory class, where the security context is used to manage security protocols; obtaining a second factory class through the security context and creating and managing secure sockets through the second factory class, where the secure sockets are used to encrypt data for communication connections between multiple nodes and corresponding thread pools.
[0152] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: establishing socket connections with multiple nodes through threads in the thread pool and performing authentication and data encryption using the verification information in the trust store and the secure sockets; obtaining the cluster identifier of the cluster where the node is located and sending a connection request to the cluster according to the cluster identifier to establish a communication connection between the arbitration program and multiple clusters.
[0153] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: periodically sending heartbeat message requests to multiple clusters through the arbitration program; receiving heartbeat message responses sent by multiple clusters based on the heartbeat message requests; monitoring the network communication connection status of multiple clusters according to the heartbeat message responses and determining whether to perform cluster arbitration according to the monitoring results.
[0154] In one embodiment, when the computer program is executed by a processor, the following steps are further implemented: in response to not receiving a heartbeat message response within a preset time, performing cluster arbitration to cause multiple nodes to send arbitration requests to the corresponding thread pools, where the arbitration requests include arbitration information, and the arbitration information includes the cluster identifier corresponding to the node; in response to the thread pool receiving the arbitration request, looking up the corresponding cluster according to the cluster identifier and performing arbitration determination.
[0155] Those of ordinary skill in the art can understand that all or part of the processes in the methods of the above embodiments can be completed by instructing relevant hardware through a computer program. The computer program can be stored in a non-volatile computer-readable storage medium. When the computer program is executed, it can include the processes of the embodiments of the above methods. Among them, any reference to a memory, storage, database, or other medium used in the various embodiments provided in the present application can include non-volatile and / or volatile memories. Non-volatile memory can include read-only memory (ROM), programmable ROM (PROM), electrically programmable ROM (EPROM), electrically erasable programmable ROM (EEPROM), or flash memory. Volatile memory can include random access memory (RAM) or external cache memory. By way of illustration and not limitation, RAM is available in many forms, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchronous link DRAM (SLDRAM), Rambus direct RAM (RDRAM), direct memory bus dynamic RAM (DRDRAM), and Rambus dynamic RAM (RDRAM), etc.
[0156] The technical features of the above embodiments can be combined arbitrarily. For the sake of brevity of description, not all possible combinations of the technical features in the above embodiments are described. However, as long as there is no contradiction in the combination of these technical features, it should be considered as the scope described in this specification.
[0157] The above-described embodiments merely represent several implementation manners of the present application. The description thereof is relatively specific and detailed, but it should not be construed as a limitation on the scope of the invention patent. It should be noted that for those of ordinary skill in the art, without departing from the concept of the present application, several modifications and improvements can still be made, and these all belong to the protection scope of the present application. Therefore, the protection scope of the patent of the present application shall be subject to the appended claims.
Claims
1. A server cluster management method, characterized in that: include: Acquire cluster information of multiple clusters, the cluster information including cluster identifiers and node addresses of multiple nodes in the clusters; Obtain certificate files of the multiple clusters, and add the certificate files to a trust store; Creating a thread pool corresponding to the cluster according to the cluster identifier, wherein the thread pool is used to receive an arbitration request from the cluster and provide arbitration services; A connection request is sent to the node address through a thread in the thread pool, and identity authentication is performed through the trust store to establish a communication connection between the multiple clusters and the corresponding thread pools.
2. The server cluster management method according to claim 1, characterized in that: The method further comprises: Deploy an arbitration program on the arbitration server, wherein the arbitration program includes thread pools corresponding to the multiple clusters, wherein the thread pools correspond to the clusters one by one, and resources are isolated between the thread pools; The certificate files of the plurality of clusters are obtained, and the certificate files are stored in a designated directory of the arbitration program.
3. The server cluster management method according to claim 2, characterized in that: The arbitration program may be one or more, and the deploying of the arbitration program on the arbitration server further includes: In response to the number of arbitration procedures being multiple, determining a main arbitration procedure from the arbitration procedures, and using the other arbitration procedures as backup arbitration procedures; In response to a failure of the main arbitration program, one of the backup arbitration programs is selected to take over the main arbitration program for cluster arbitration.
4. The server cluster management method according to claim 2, characterized in that: The obtaining of the certificate files of the multiple clusters and adding the certificate files to the trust store includes: Creating corresponding key libraries for the multiple clusters respectively; Acquire verification information according to the certificate file of the cluster, and load the verification information into the key library corresponding to the cluster, the verification information including the alias, certificate and key; Traversing the aliases in the keystore to obtain corresponding certificates and keys, and adding the certificates and keys to the truststore; Creating a first factory class, and setting the trust store as a trust source of the first factory class, wherein the first factory class is used to create a trust manager; Creating a security context and initializing the security context through the first factory class, wherein the security context is used to manage a security protocol; A second factory class is obtained through the security context, and a secure socket is created and managed through the second factory class, where the secure socket is used to encrypt data for communication connections between the multiple nodes and the corresponding thread pools.
5. The server cluster management method according to claim 4, characterized in that: The sending of a connection request to the node address through a thread in the thread pool and performing identity authentication through the trust store to establish a communication connection between the multiple clusters and the corresponding thread pools includes: Establishing socket connections with the multiple nodes through threads in the thread pool, and performing identity authentication and data encryption using the verification information in the trust store and the secure socket; A cluster identifier of the cluster where the node is located is obtained, and a connection request is sent to the cluster according to the cluster identifier, so as to establish a communication connection between the arbitration program and the multiple clusters.
6. The server cluster management method according to claim 2, characterized in that: After establishing the communication connection between the plurality of clusters and the corresponding thread pools, the method further includes: Sending heartbeat message requests to the multiple clusters regularly through the arbitration procedure; Receiving heartbeat message responses sent by the multiple clusters based on the heartbeat message request; The network communication connection status of the plurality of clusters is monitored according to the heartbeat message response, and it is determined whether cluster arbitration is to be performed according to the monitoring result.
7. The server cluster management method according to claim 6, characterized in that: The monitoring of the network communication connection status of the plurality of clusters according to the heartbeat message response, and determining whether to perform cluster arbitration according to the monitoring result, includes: In response to not receiving the heartbeat message response within a preset time, performing cluster arbitration, so that the multiple nodes send arbitration requests to the corresponding thread pool, the arbitration request includes arbitration information, and the arbitration information includes the cluster identifier corresponding to the node; In response to the thread pool receiving the arbitration request, the corresponding cluster is searched according to the cluster identifier, and an arbitration decision is performed.
8. A server cluster management device, characterized in that: The device comprises: An acquisition module, used to acquire cluster information of a plurality of clusters, wherein the cluster includes a plurality of nodes, and the cluster information includes a cluster identifier and node addresses of the plurality of nodes; A loading module, used to load the certificate files of the multiple clusters and add the certificate files to the trust store; A creation module, used to create a thread pool corresponding to the cluster according to the cluster identifier, and the thread pool is used to receive an arbitration request from the cluster and provide arbitration services; A communication module is used to send a connection request to the node address through a thread in the thread pool, and perform identity authentication through the trust store to establish a communication connection between the multiple nodes and the corresponding thread pool.
9. A computer device comprising a memory, a processor and a computer program stored in the memory and executable on the processor, characterized in that: When the processor executes the computer program, the steps of the method according to any one of claims 1 to 7 are implemented.
10. A computer-readable storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 7 are implemented.