Cluster access method and device, equipment, storage medium and computer program product
By using an algorithm based on probability density function in the K8s cluster to obtain the endpoint status of the service cluster server and dynamically manage access certificates through the API proxy device, the load problem and certificate update problem of the K8s cluster access in the service cluster in the prior art is solved, and efficient and reliable cluster access is achieved.
Patent Information
- Application Number
- CN202510125464.3
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-01-26
- Publication Date
- 2025-05-30
AI Technical Summary
When the existing technology accesses a business cluster in a K8s cluster, the direct connection method and the Tower Agent method will increase the load of the apiserver, and it is impossible to quickly and actively sense whether the apiserver's endpoints are alive, and it cannot be updated in real time when the access certificate of the business cluster expires, resulting in access failure.
Using an algorithm based on probability density function, we actively obtain the endpoint status of the service cluster server, and dynamically register and discover the routing information in K8s through the API proxy device, listen to the CRD resource information and encrypted files of the service cluster, and automatically update the access certificate to ensure the completeness of access requests and reduce the failure rate.
Effectively reduces the time when services are unavailable, ensures that traffic data will not be distributed to invalid servers, ensures the completeness of access requests, reduces the failure rate, and simplifies the way to access business clusters.
Smart Images

Figure CN120075301A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud computing technology, and in particular, to a cluster access method, apparatus, device, storage medium, and computer program product. Background Art
[0002] Kubernetes (hereinafter referred to as K8s) has currently become the distributed operating system kernel in the container era. With the continuous development of microservices, more and more applications have been migrated to K8s. However, due to various reasons, a single-cluster K8s can no longer meet the business requirements. For example, a set of K8s clusters is required for development environments, test environments, production environments, etc. Different manufacturers have different implementation solutions for how to simply manage multiple clusters.
[0003] Generally, public cloud providers use a set of management clusters to deploy multiple business clusters. Among them, the deployed K8s cluster is called a business cluster, and the deployed K8s cluster is called a management cluster. Figure 1 For the architecture schematic diagram of deploying multiple business clusters by a set of management clusters in the related technology, as Figure 1 shown, a set of management clusters (i.e., one or more management clusters) deploy multiple business clusters, such as dedicated cluster - Cluster A, Cluster B, Cluster C. The management cluster accesses the application programming interface server (apiserver) of the business cluster through a load balancer (Loadbalance). Among them, the business cluster is a complete cluster. After the user selects the business cluster configuration information, the management cluster will generate a custom resource component - the definition of the Cluster custom resource (CRD, Custom Resource Definition) with the corresponding configuration. The Cluster control manager in the management cluster directly creates the corresponding dedicated cluster according to the definition of the CRD. The management nodes (i.e., Master nodes) in the dedicated cluster include information such as apiserver and etcd, which are mainly used to manage and schedule cluster resources; the worker nodes (i.e., worker nodes) in the dedicated cluster are mainly used to provide resources, that is, to provide Pods for the K8s cloud platform.
[0004] Currently, in the related art, the application-centered multi-tenant container platform (i.e., Kubesphere) built on K8s accesses the business cluster in a direct connection manner when the network is reachable, and accesses the business cluster in a way of proxy connection through the Tower Agent component when the network is unreachable. However, all operation processes of the direct connection method need to directly operate the apiserver, which will increase the load of the apiserver of the business cluster, increase the response time of requests, and cannot quickly and actively sense whether the endpoint of the apiserver is alive; the Tower Agent method connects by creating a network proxy between the management cluster and the business cluster, and still operates the apiserver essentially, and the above problems also exist. Summary of the Invention
[0005] To solve the technical problems existing in the related art, an embodiment of the present application provides a cluster access method, device, equipment, storage medium and computer program product.
[0006] To achieve the above object, the technical solution of the embodiment of the present application is realized as follows:
[0007] In a first aspect, an embodiment of the present application provides a cluster access method, which is applied to an Application Programming Interface (API) proxy device component, and the method includes:
[0008] Receiving a first request sent by a management cluster; the first request represents an access request for requesting to access a server of a target business cluster, the server is an apiserver, the target business cluster is one of one or more business clusters managed by the management cluster, and the first request includes traffic data;
[0009] In response to the first request, based on the algorithm of the probability density function, determining the endpoint status corresponding to the server of the one or more business clusters;
[0010] Based on the endpoint status corresponding to the server of the one or more business clusters, determining the server of the target business cluster, and sending the traffic data to the server of the target business cluster.
[0011] In a second aspect, an embodiment of the present application further provides a cluster access device, which is applied to an API proxy device component, and the device includes:
[0012] A receiving unit, configured to receive a first request sent by a management cluster; the first request represents an access request for requesting to access a server of a target service cluster, the server being an application programming interface server (apiserver), and the target service cluster being one of one or more service clusters controlled by the management cluster, and the first request includes traffic data;
[0013] A first determining unit, configured to, in response to the first request, determine an endpoint state corresponding to a server of the one or more service clusters based on an algorithm of a probability density function;
[0014] A second determining unit, configured to determine a server of the target service cluster based on the endpoint state corresponding to the server of the one or more service clusters;
[0015] A sending unit, configured to send the traffic data to the server of the target service cluster.
[0016] In a third aspect, an embodiment of the present application further provides a cluster access device, including: a processor and a memory for storing a computer program that can run on the processor;
[0017] Wherein, when the processor is used to run the computer program, the steps of the cluster access method described in the embodiment of the present application are executed.
[0018] In a fourth aspect, an embodiment of the present application further provides a storage medium, on which a computer program is stored, and when the computer program is executed by a processor, the steps of the cluster access method described in the embodiment of the present application are implemented.
[0019] In a fifth aspect, an embodiment of the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the cluster access method described in the embodiment of the present application are implemented.
[0020] The cluster access method, device, equipment, storage medium and computer program product provided by the embodiments of the present application. The API proxy device component receives a first request sent by the management cluster; the first request represents an access request for requesting to access a server of a target service cluster, the server is an apiserver, the target service cluster is one of one or more service clusters controlled by the management cluster, and the first request includes traffic data; in response to the first request, based on the algorithm of the probability density function, determine the endpoint status corresponding to the servers of the one or more service clusters; based on the endpoint status corresponding to the servers of the one or more service clusters, determine the server of the target service cluster, and send the traffic data to the server of the target service cluster. By adopting the technical solution of the embodiments of the present application, through the algorithm based on the probability density function, obtain the endpoint status corresponding to the servers of the service cluster, that is, the endpoint survival status, and then based on the endpoint status corresponding to the servers of the service cluster, determine the server of the target service cluster, and send the traffic data in the access request to the server of the target service cluster. In this way, the time when the service is unavailable can be effectively reduced, it is ensured that the traffic data will not be distributed to invalid servers, the completeness of the access request is guaranteed, and the failure rate is reduced. BRIEF DESCRIPTION OF THE DRAWINGS
[0021] Figure 1 It is a schematic diagram of the architecture for deploying multiple service clusters by a set of management clusters in the related art;
[0022] Figure 2 It is a flowchart of the cluster access method according to the embodiments of the present application Figure 1 ;
[0023] Figure 3 It is a flowchart of the cluster access method according to the embodiments of the present application Figure 2 ;
[0024] Figure 4 It is a flowchart of the cluster access method according to the embodiments of the present application Figure 3 ;
[0025] Figure 5 It is a flowchart of the operations related to the change of the CRD resource information according to the embodiments of the present application;
[0026] Figure 6 It is a schematic diagram of the composition structure of the cluster access device according to the embodiments of the present application;
[0027] Figure 7 It is a schematic diagram of the hardware composition structure of the cluster access device according to the embodiments of the present application. DETAILED DESCRIPTION OF THE EMBODIMENTS
[0028] The present application will be further described in detail below with reference to the drawings and embodiments.
[0029] Unless otherwise defined, all technical and scientific terms used herein have the same meaning as commonly understood by one of ordinary skill in the technical field to which this application belongs. The terms used in the specification of this application are only for the purpose of describing specific embodiments and are not intended to limit this application.
[0030] An embodiment of this application provides a cluster access method, which is applied to a cluster access device, and the cluster access device can be an API proxy device component. Figure 2 It is a schematic flow of the cluster access method according to the embodiment of this application. Figure 1 ; As Figure 2 shown, the cluster access method includes:
[0031] Step 201: Receive a first request sent by the management cluster.
[0032] In the embodiment of this application, the first request represents an access request for requesting to access a server of a target service cluster, the server is an apiserver, the target service cluster is one of one or more service clusters managed by the management cluster, and the first request includes traffic data.
[0033] Here, the cluster access method of the embodiment of this application is applied to a cluster management scenario. In actual application, a set of management clusters can deploy a group of service clusters, that is, a group of service clusters are managed by the management cluster. This group of service clusters includes one or more service clusters. Among them, the management cluster can be understood as a deployed K8s cluster, and the service cluster can be understood as a deployed K8s cluster.
[0034] It should be noted that in the embodiment of this application, one or more service clusters managed by the management cluster can be K8s multi-clusters under public cloud; that is to say, the cluster access method of the embodiment of this application can be specifically applied to the cluster management scenario under public cloud in the field of cloud computing technology.
[0035] Step 202: In response to the first request, determine the endpoint status corresponding to the servers of one or more service clusters based on the algorithm of the probability density function.
[0036] In the embodiments of the present application, the endpoint state includes an endpoint reachable state and an endpoint unreachable state. Among them, the endpoint reachable state can be understood as that the endpoint corresponding to the server of the service cluster, such as the apiserver of the service cluster, is in a live state, and at this time the endpoint corresponding to the apiserver of the service cluster is available; the endpoint unreachable state can be understood as that the endpoint corresponding to the apiserver of the service cluster is not in a live state, and at this time the endpoint corresponding to the apiserver of the service cluster is unavailable.
[0037] Here, the API proxy device component can also be referred to as an API proxy device or an API gateway device. As the proxy entry of the service cluster gateway, the API proxy device component forwards requests for different service cluster resources to the corresponding service cluster with the cluster as the boundary.
[0038] Here, the API proxy device component in the embodiments of the present application is an API proxy device for K8s multi-clusters. This API proxy device can dynamically register and discover routing information in K8s, record service cluster access information by defining a VirtualService, and proxy the real service cluster for the management cluster to access, which simplifies the way to access the service cluster. It should be noted that the API proxy device component is responsible for providing the full life cycle proxy of the K8s resources of the service cluster, including the creation, deletion, modification, and query of K8s API object resources.
[0039] In practical applications, since server detection is all processed in the form of heartbeat packets, and the Transmission Control Protocol (TCP) is a connection-oriented protocol. When the peer, that is, the receiving end, has no response, in the related art, it can only judge whether the application is reachable according to the set timeout time, and cannot quickly judge whether the endpoint is abnormal. Therefore, the embodiments of the present application adopt an algorithm based on the probability density function to judge whether the endpoint is alive through the survival probability of the corresponding endpoint.
[0040] Based on this, in one embodiment, the algorithm based on the probability density function for determining the endpoint state corresponding to the servers of the one or more service clusters includes:
[0041] Based on the algorithm of the probability density function, determine the survival probability of the endpoints corresponding to the servers of the one or more service clusters; based on the survival probability of the endpoints corresponding to the servers of the one or more service clusters, determine the endpoint state corresponding to the servers of the one or more service clusters.
[0042] Here, in probability theory and statistics, the exponential distribution is a continuous probability distribution that can be used to represent the time intervals between independent random events. Therefore, in the embodiments of the present application, the algorithm for detecting whether an endpoint is alive, that is, the algorithm of the probability density function, can be the exponential distribution function algorithm based on the exponential distribution.
[0043] Based on this, in one embodiment, the algorithm of the probability density function includes the exponential distribution function algorithm based on the exponential distribution.
[0044] The algorithm based on the probability density function to determine the survival probability of the endpoints corresponding to the servers of the one or more service clusters includes:
[0045] Based on the exponential distribution function algorithm, determine the target time interval; the target time interval represents the time interval between the first time and the second time, the first time represents the time when the current data sample sampling in the target sequence is successful, and the second time represents the time when the last data sample sampling in the target sequence is successful.
[0046] Based on the target time interval, determine the survival probability of the endpoints corresponding to the servers of the one or more service clusters.
[0047] Here, the API proxy device component can determine the time interval between the time when the current data sample sampling is successful and the time when the last data sample sampling is successful through the continuous probability distribution represented by the exponential distribution function algorithm. Among them, the exponential distribution function algorithm uses the time interval of data sample sampling success as the algorithm sample within a sequence of finite length (i.e., the target sequence), and performs probability calculation through the nearest N data samples to obtain the survival probability of the endpoints corresponding to the servers of the one or more service clusters. Among them, the survival probability of the endpoint can be understood as the probability of endpoint failure.
[0048] Specifically, after obtaining the time interval of data sample sampling success, the survival probability of the endpoint can be calculated through the following formula (1):
[0049]
[0050] Among them, f(x) represents the survival probability of the endpoint, x represents the time interval between the time when the current data sample sampling in the target sequence is successful and the time when the last data sample sampling is successful, and the value of λ is 1 / average data sample.
[0051] Here, in one embodiment, the determining the endpoint status corresponding to the servers of the one or more service clusters based on the survival probability of the endpoints corresponding to the servers of the one or more service clusters includes:
[0052] Compare the survival probability of the endpoints corresponding to the servers of the one or more service clusters with a probability threshold to obtain a comparison result;
[0053] When the comparison result indicates that the survival probability of the endpoint is greater than the probability threshold, determine that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint reachable status;
[0054] When the comparison result indicates that the survival probability of the endpoint is less than or equal to the probability threshold, determine that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint unreachable status.
[0055] It should be noted that the probability threshold can be preset according to actual needs, and the embodiments of the present application do not limit this here.
[0056] In practical applications, the API proxy device component can store the detected normal endpoint data of the endpoints through the created queue.
[0057] Based on this, in one embodiment, the method further includes: creating a storage queue;
[0058] After determining that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint reachable status, the method further includes:
[0059] Store the endpoint data in the endpoint reachable status into the storage queue; the stored data of the storage queue can be dynamically adjusted, and the length of the storage queue does not exceed a length threshold.
[0060] Here, the API proxy device component will create a storage queue for storing the endpoint data in the endpoint reachable status. However, the storage queue is represented in the form of a stack, that is to say, the storage queue has a first-in-first-out (FIFO) data structure. Exemplarily, assume that the length of the storage queue is 10. In practical applications, when new data needs to be stored in the storage queue, the previously stored data in the storage queue will be deleted. Therefore, the length of this storage queue will always remain 10. It can be seen that the data stored in the storage queue created by the embodiments of the present application can be dynamically adjusted according to actual needs, but the length of the storage queue does not exceed the length threshold, that is, the length of the storage queue does not exceed 10.
[0061] In one embodiment, after determining that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint unreachable status, the method further includes: determining whether the endpoint unreachable status meets a set condition; when it is determined that the endpoint unreachable status meets the set condition, set the weight of the endpoint in the endpoint unreachable status to zero.
[0062] Here, after the API proxy device component determines that the endpoint status corresponding to the servers of one or more service clusters is the endpoint unreachable status, it is also necessary to further determine whether the endpoint unreachable status of the endpoint meets the set conditions. Among them, the set condition is the number threshold of endpoint unreachability detected within the target time. In practical applications, the number threshold is a constant value set. For example, the target time is set to 1 minute and the number threshold is 3. Assuming that the number of times the endpoint unreachability of a certain endpoint is detected within 1 minute is 3 times or more, it is considered that the endpoint unreachable status of the endpoint meets the set conditions. At this time, the weight of the endpoint will be set to 0 to prevent the inflow of access traffic data. Assuming that the number of times the endpoint unreachability of a certain endpoint is detected within 1 minute is 1 time or 2 times, it is considered that the endpoint unreachable status of the endpoint does not meet the set conditions. This is very likely caused by reasons such as network jitter. Therefore, only the number of times the endpoint unreachability of the endpoint is recorded, and the weight of the endpoint is not set temporarily.
[0063] In practical applications, in one embodiment, after the API proxy device component determines that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint unreachable status, the method may further include: determining whether the endpoint unreachable status meets the set conditions; and in the case where it is determined that the endpoint unreachable status meets the set conditions, removing the endpoint in the endpoint unreachable status.
[0064] Here, the set condition is the number threshold of endpoint unreachability detected within the target time. In practical applications, the number threshold is a constant value set. For example, the target time is set to 1 minute and the number threshold is 3. Assuming that the number of times the endpoint unreachability of a certain endpoint is detected within 1 minute is 3 times or more, it is considered that the endpoint unreachable status of the endpoint meets the set conditions. At this time, the endpoint in the endpoint unreachable status is removed, so that the service unavailable time can be effectively reduced, ensuring that traffic data will not be distributed to invalid apiservers, guaranteeing the completeness of access requests, and reducing the failure rate.
[0065] It should be noted that in the embodiments of the present application, setting the weight of the endpoint in the endpoint unreachable status to zero, or removing the endpoint in the endpoint unreachable status can both make the endpoint unavailable. However, the difference between these two processing methods is that: when the endpoint in the endpoint unreachable status is removed, after the endpoint is repaired, it needs to be re-added to the endpoint, and parameters such as the health detection path, detection method, and weight of the endpoint need to be reset, and the operation is relatively cumbersome; while when the weight of the endpoint in the endpoint unreachable status is set to zero, after the endpoint is repaired, the weight value of the endpoint can be directly modified, and other parameters of the endpoint can be retained, and this processing method is more lightweight.
[0066] Step 203: Determine the servers of the target service cluster based on the endpoint statuses of the servers corresponding to the one or more service clusters, and send traffic data to the servers of the target service cluster.
[0067] In the embodiments of the present application, the traffic data can be understood as the traffic data related to the access carried in the access request, and can also be referred to as access traffic data.
[0068] In one embodiment, the determining the servers of the target service cluster based on the endpoint statuses of the servers corresponding to the one or more service clusters includes:
[0069] In the case that the endpoint statuses of the servers corresponding to the one or more service clusters are endpoint reachable statuses, determine that the endpoints are alive endpoints; determine the servers of the service cluster corresponding to the alive endpoints as the servers of the target service cluster.
[0070] In practical applications, the API proxy device component serves as the proxy entry of the service cluster gateway. When starting up, it will listen to the Cluster CRD resource information of the service cluster, and when the Cluster CRD resource information of the service cluster changes, perform K8s client-related operations.
[0071] Based on this, in one embodiment, the method further includes: when the API proxy device component starts up, listen to the definition CRD resource information of the custom resources of the one or more service clusters; when it is monitored that the CRD resource information of the one or more service clusters changes, perform operations related to the change of the CRD resource information.
[0072] Here, the API proxy device component provides a unified interface such as a rest access interface for the management cluster. When the management cluster needs to operate on the service cluster, it only needs to access the API proxy device component through the rest access interface.
[0073] Here, the operations related to the change of the CRD resource information include operations such as creation, deletion, and query. For the case of performing operations related to the change of the CRD resource information when it is monitored that the CRD resource information of the one or more service clusters changes, for example, when creating a service cluster (Cluster) resource, the API proxy device component obtains the routing information and certificate file of the service cluster from the registered information. If the routing information does not exist, wait for retry until the routing information of the service cluster and the corresponding certificate file are obtained, generate client information for accessing the service cluster, and establish an index according to the name and namespace, and cache the client information in a local multiple index such as a database of an index of the cache class.
[0074] When deleting the business Cluster resources, the API proxy device component listens for the deletion information of the resources, queries the client cache information of the business cluster from the database of the local multi-index cache, and deletes the client cache information.
[0075] When receiving a query request for full data acquisition (list) or acquisition (get) of the management cluster, the API proxy device component obtains the data and puts it into the database of the cached multi-index cache, and returns the corresponding data to the management cluster. When the management cluster accesses the business cluster again, it can directly obtain the corresponding data from the database of the cached multi-index cache and return it to the management cluster.
[0076] When receiving operations such as creation (post) and deletion (delete) of the management cluster, the API proxy device component obtains the connected clients of the cluster, constructs a forwarding path prefixed with the current cluster identifier (Clusterid), and uses the clients to call the apiserver of the business cluster for resource processing.
[0077] In one embodiment, the method further includes: listening for the encrypted files corresponding to the Custom Resource Definitions (CRDs) of the one or more business clusters; and updating the access certificate files in the API proxy device component when it is detected that the encrypted files corresponding to the CRDs of the one or more business clusters have changed.
[0078] Here, the encrypted file is a secret file, which is a resource object stored in an encrypted manner and is used to store sensitive information, such as sensitive data like passwords, tokens, and keys.
[0079] Specifically, in one embodiment, the updating of the access certificate files in the API proxy device component includes: obtaining the target access certificate files; the target access certificate files are generated by the registration component and sent to the API proxy device component; and updating the access certificate files in the API proxy device component based on the target access certificate files.
[0080] Here, in the related art, in the direct connection method and the Tower Agent method, after the access certificate of the business cluster expires, the certificate information of the business cluster cannot be updated in real time, resulting in access failures. To solve this problem, in the embodiments of the present application, the API proxy device component listens for the encrypted files corresponding to the CRDs of one or more business clusters, automatically proxies the access certificate files of the business cluster through the API proxy device component. The management cluster does not need to directly connect and authenticate with the business cluster, and only needs to access the API proxy device component to request access to the business cluster, simplifying the request method.
[0081] Here, when it is monitored that the encrypted file corresponding to the CRD of one or more business clusters changes, that is, when the business cluster access certificate is updated, the API proxy device component will receive the target access certificate file sent by the registration component (i.e., the Register component). The target access certificate file is a new access certificate file generated by the registration component, and the target access certificate file is used to replace the access certificate file in the API proxy device component, so as to update the access certificate file in the API proxy device component and avoid the failure of the gateway to access the apiserver of the business cluster after the business cluster access certificate expires.
[0082] An embodiment of the present application also provides another cluster access method. This method is applied to a cluster access device, and the cluster access device can be an API proxy device component. Figure 3 Schematic flow of the cluster access method according to the embodiment of the present application Figure 2 ; as Figure 3 shown, the cluster access method includes:
[0083] Step 301: Receive a first request sent by the management cluster.
[0084] In the embodiment of the present application, the first request represents an access request for requesting to access the server of the target business cluster. The server is an apiserver, and the target business cluster is one of one or more business clusters controlled by the management cluster. The first request includes traffic data.
[0085] Step 302: In response to the first request, based on the algorithm of the probability density function, determine the survival probability of the endpoints corresponding to the servers of one or more business clusters.
[0086] In one embodiment, the algorithm of the probability density function includes an exponential distribution function algorithm based on the exponential distribution;
[0087] The algorithm based on the probability density function to determine the survival probability of the endpoints corresponding to the servers of one or more business clusters includes:
[0088] Based on the exponential distribution function algorithm, determine the target time interval. The target time interval represents the time interval between the first time and the second time. The first time represents the time when the current data sample in the target sequence is sampled successfully, and the second time represents the time when the last data sample in the target sequence is sampled successfully;
[0089] Based on the target time interval, determine the survival probability of the endpoints corresponding to the servers of one or more business clusters.
[0090] Step 303: Determine the endpoint status corresponding to the servers of the one or more service clusters based on the survival probability of the endpoints corresponding to the servers of the one or more service clusters.
[0091] In one embodiment, the endpoint status includes an endpoint reachable status and an endpoint unreachable status;
[0092] The determining the endpoint status corresponding to the servers of the one or more service clusters based on the survival probability of the endpoints corresponding to the servers of the one or more service clusters includes:
[0093] Compare the survival probability of the endpoints corresponding to the servers of the one or more service clusters with a probability threshold to obtain a comparison result;
[0094] When the comparison result indicates that the survival probability of the endpoint is greater than the probability threshold, determine that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint reachable status;
[0095] When the comparison result indicates that the survival probability of the endpoint is less than or equal to the probability threshold, determine that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint unreachable status.
[0096] In one embodiment, the method further includes: creating a storage queue;
[0097] After determining that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint reachable status, the method further includes: storing the endpoint data in the endpoint reachable status into the storage queue; the stored data of the storage queue can be dynamically adjusted, and the length of the storage queue does not exceed a length threshold.
[0098] In one embodiment, after determining that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint unreachable status, the method further includes: determining whether the endpoint unreachable status meets a set condition; when it is determined that the endpoint unreachable status meets the set condition, set the weight of the endpoint in the endpoint unreachable status to zero.
[0099] Step 304: When the endpoint status corresponding to the servers of the one or more service clusters is the endpoint reachable status, determine that the endpoint is a surviving endpoint.
[0100] Step 305: Determine the servers of the service clusters corresponding to the surviving endpoints as the servers of the target service clusters.
[0101] Step 306: Send traffic data to the servers of the target service clusters.
[0102] In one embodiment, the method further includes: when the API proxy device component is started, listening for the CRD resource information of the one or more service clusters; and when it is monitored that the CRD resource information of the one or more service clusters changes, performing an operation related to the change in the CRD resource information.
[0103] In one embodiment, the method further includes: listening for the encrypted files corresponding to the CRDs of the one or more service clusters; and when it is monitored that the encrypted files corresponding to the CRDs of the one or more service clusters change, updating the access certificate files in the API proxy device component.
[0104] In one embodiment, the updating of the access certificate files in the API proxy device component includes: obtaining a target access certificate file; the target access certificate file is generated by a registration component and sent to the API proxy device component; and based on the target access certificate file, updating the access certificate files in the API proxy device component.
[0105] It should be noted that the specific processing process of the cluster access device for cluster access has been described in detail above and will not be elaborated here.
[0106] By adopting the technical solution of the embodiment of the present application, through an algorithm based on a probability density function, the endpoint status of the server of the service cluster, that is, the endpoint survival status, is obtained. Furthermore, based on the endpoint status of the server of the service cluster, the server of the target service cluster is determined, and the traffic data in the access request is sent to the server of the target service cluster. In this way, the time of service unavailability can be effectively reduced, it is ensured that the traffic data will not be distributed to invalid servers, the completeness of the access request is guaranteed, and the failure rate is reduced.
[0107] The present application will be described below in conjunction with application embodiments.
[0108] Currently, Kubesphere uses a direct connection method to access the service cluster when the network is reachable, and uses the Tower Agent component proxy connection method to access the service cluster when the network is unreachable. However, the following problems exist in these two technical solutions in the related art:
[0109] (1) All operation processes of the direct connection method need to directly operate the apiserver, which will increase the load on the apiserver of the service cluster, increase the response time of requests, and cannot quickly and actively sense whether the endpoint of the apiserver is alive;
[0110] (2) The Tower Agent method connects by creating a network proxy between the management cluster and the business cluster. Essentially, it still operates the apiserver, and the same problems as in (1) above exist.
[0111] (3) Since the apiserver uses certificate authentication, a certificate needs to be constructed to initiate a request during access. However, in both the direct connection method and the Tower Agent method, after the access certificate of the business cluster expires, the certificate information of the business cluster cannot be updated in real time, resulting in access failure. Moreover, the business cluster and the management cluster are highly coupled, which is not conducive to the expansion of components.
[0112] In response to the above problems, the present application proposes a K8s multi-cluster API proxy device for automatic registration and discovery (corresponding to the aforementioned API proxy device component). Using this API proxy device to implement a cluster access method, this method has the following beneficial effects:
[0113] (1) Cache the client information of the business cluster in the API proxy device, and actively obtain the endpoint survival status through the algorithm of the probability density function to reduce unnecessary traffic forwarding.
[0114] (2) The API proxy device listens to the secret file corresponding to the custom cluster (Cluster) CRD (corresponding to the encrypted file corresponding to the CRD of the business cluster). Automatically proxy the access certificate file of the business cluster through the API proxy device. The management cluster does not need to directly connect and authenticate with the business cluster. It only needs to access the gateway (i.e., the API proxy device) to request access to the business cluster, simplifying the access request method.
[0115] (3) The API proxy device listens to the creation of the business Cluster CRD in the management cluster, generates a routing rule based on the cluster identifier (Clusterid) according to the cluster information, and real-time monitors the survival status of the business cluster and the access certificate of the business cluster, realizing the complete decoupling of the management cluster and the business cluster.
[0116] Next, the technical solutions of the API proxy device of the present application and the cluster access method implemented using this API proxy device will be described in detail.
[0117] The present application proposes a K8s multi-cluster API proxy device. Figure 4 For the process schematic of the cluster access method of the embodiment of the present application Figure 3 , as Figure 4As shown in the figure, an API proxy device is set between the management cluster and the business cluster. This API proxy device can dynamically register and discover routing information in K8s, and set the API gateway to monitor the heartbeat of the endpoint. A virtual service is defined to record the access information of the business cluster, and the real business cluster is proxied for the management cluster to access, which simplifies the way to access the business cluster. In this application, first, the user selects the custom configuration information of the business cluster (including node specifications, cluster types, etc.) on the console page of the management cluster to generate a Cluster CRD instance. The controller (Cluster Operator) of the management cluster generates the corresponding business cluster according to the configuration of this instance and updates the cluster creation status in the Cluster CRD. This application also provides a Register component, which is used to monitor the changes of resources in the ClusterCRD and dynamically update the routing rules of the API proxy device by operating the Virtual service.
[0118] Here, the API proxy device is used to provide a full life cycle proxy for the K8s resources of the business cluster, including the creation, deletion, modification, and query of K8s API object resources. The API proxy device takes the cluster as the boundary and forwards the requests for different business cluster resources to the corresponding business cluster.
[0119] When the user creates a business cluster, the corresponding node specifications and cluster types are selected on the page of the management cluster. The management cluster generates a Cluster CRD instance and creates the corresponding business cluster. The Register component monitors the cluster resources (Cluster resources) corresponding to this business cluster. When the Cluster resources change, the Register component makes a series of responses to this change, as described below:
[0120] 1. When a new business cluster resource is created, the Register component obtains the access address endpoint corresponding to the apiserver of the cluster according to the Cluster CRD resource information. The endpoint can be the 6443 port of the nodes in the business cluster. Due to the high availability of the K8s cluster, generally there are three or more nodes providing services. Therefore, there will be multiple endpoints as the access addresses of the business cluster. The Register component takes the address of this endpoint as the upstream address of this dedicated cluster, then obtains the apiserver access certificate information in this business cluster, and generates a route prefixed with Clusterid and stores it in the API proxy device.
[0121] 2. After the business Cluster resources are deleted, the Register component listens for the deletion information of the Cluster, queries whether the API proxy device contains the routing information according to the Clusterid. If the routing information is included, the routing information and access certificate information are deleted, and the corresponding forwarding rules are synchronously deleted.
[0122] 3. When the business Cluster access certificate is updated, the Register component will listen for the corresponding secret change and generate a new access certificate (corresponding to the aforementioned target access certificate file) to replace the access certificate file in the API proxy device, avoiding the problem that the gateway fails to authenticate when accessing the business cluster apiserver after the business cluster access certificate expires.
[0123] 4. After the business Cluster resources are successfully created, the API proxy device will perform a health inspection on the apiserver of the Cluster to determine whether the endpoint status of the endpoint is alive, so as to determine whether to send traffic to the endpoint (also called a node) or remove the node.
[0124] Since server detection is all processed in the form of heartbeat packets, and the TCP protocol is connection-oriented. When the peer has no response, it can only judge whether the application is reachable according to the set timeout, and cannot quickly determine whether the endpoint is abnormal. Therefore, this application adopts an algorithm based on the probability density function to judge whether the node is still alive through the corresponding survival probability.
[0125] In probability theory and statistics, the exponential distribution is a continuous probability distribution that can be used to represent the time interval between independent random events. Here, the algorithm for detecting whether a node is alive can adopt the exponential distribution algorithm. This algorithm uses the sampling success time interval as the algorithm sample within a finite sequence, and calculates the probability of node failure (corresponding to the survival probability of the aforementioned endpoint) through the nearest N data samples, as shown in the following formula (1):
[0126]
[0127] The probability density function used by the exponential distribution (corresponding to the exponential distribution function based on the exponential distribution mentioned above) is shown in the following formula (2):
[0128]
[0129] Among them, x represents the time interval between the time when the current data sample is successfully sampled and the time when the last data sample is successfully sampled. The value of λ is 1 / sample average. The final actual failure probability distribution function is 1 - F(x; λ). Substituting into the above formula (1) and taking the logarithm, the calculation result is xλ / ln(10). Taking this calculation result as the misjudgment probability of node failure, the larger the value, the smaller the misjudgment probability. This API proxy device uses an algorithm based on the exponential distribution function to determine whether the endpoint corresponding to the service cluster is reachable, and quickly determines whether to set the weight of this endpoint to 0. When it is determined that the endpoint is unreachable, the endpoint is removed in time (or the weight of the endpoint is set to 0) to reduce the unavailable time of the application.
[0130] In this application, the API proxy device creates a queue with a length of 10 (corresponding to the aforementioned length threshold) (corresponding to the aforementioned storage queue), and stores the normal endpoint data of the actively inspected endpoints into the queue. When new data comes in, the old data in the queue will be deleted. Therefore, the data in the queue will always remain 10. After determining that the endpoint is in an unreachable state, it can also be judged whether the number of unreachable times of the endpoint reaches the number threshold (which can be set to 3). If the number of unreachable times of the endpoint reaches the number threshold, the weight of this endpoint will be set to 0 to avoid the inflow of access traffic.
[0131] As the proxy entry of the service cluster gateway, the API proxy device also listens to the Cluster CRD resource information of the service cluster when starting up. When the Cluster CRD resource information of the service cluster changes, it performs relevant operations of the K8s client. Moreover, the API proxy device provides a rest access interface for the management cluster. When the management cluster needs to operate on the service cluster, it only needs to access the API proxy device through the rest access interface. Figure 5 It is a schematic flowchart of the process for handling operations related to changes in CRD resource information in this embodiment of the application, as Figure 5 shown. The specific operations are as follows:
[0132] When a new service Cluster resource is created, the API proxy device obtains the routing information and certificate file of this service cluster from the registered information. If the routing information does not exist, it waits for retry until the routing information of this service cluster and the corresponding certificate file are obtained, generates client information for accessing this service cluster, and indexes the client information according to the name and namespace, and caches it in the local multiple-index cache.
[0133] When deleting the business Cluster resources, the API proxy device listens to the deletion information of the resources, queries the client cache information of the business cluster from the local multi-index cache, and deletes the client cache information.
[0134] When receiving a query request for list or get of the management cluster, the API proxy device obtains the data and puts it into the multi-index cache, and returns the corresponding data to the management cluster. When the management cluster accesses the business cluster again, it directly obtains the corresponding data from the multi-index cache and returns it to the management cluster.
[0135] When receiving operations such as post and delete of the management cluster, the API proxy device obtains the connected clients of the cluster, constructs a forwarding path prefixed with the current cluster Clusterid, and uses the clients to call the apiserver of the business cluster for resource processing.
[0136] This application completes the unified management of dedicated business clusters by automatically listening to the Cluster by the Register component and registering the business clusters to the API proxy device, and automatically listening to the Cluster and caching the clients of the business clusters. The management cluster does not need to construct certificate information, and only needs to construct a request prefixed with the clusterid of the cluster to quickly access the corresponding business cluster. In addition, the API proxy device actively patrols and discovers the survival status of endpoints in the business cluster using the probability density function algorithm based on the exponential distribution, removes unavailable endpoints in a timely manner, effectively reduces the service unavailable time, ensures that traffic data is not distributed to invalid apiservers, guarantees the completeness of requests, and reduces the failure rate.
[0137] This application proposes a multi-cluster API proxy solution based on the probability density function algorithm. Compared with the direct connection or proxy connection methods in the related technologies, the solution of this application shields the inconsistencies of various business cluster access methods, unifies the access methods to business clusters, realizes the dynamic registration and routing of business clusters by listening to the Cluster CRD, and upgrades the management method to the cluster level; uses the API proxy device to listen to the cluster information and create a multi-index cache of the cluster information, increasing the hit rate of business cluster access in multiple dimensions and improving the access speed; uses the algorithm of the probability density function to actively obtain the survival status of endpoints, and determines whether an endpoint needs to be removed according to the set threshold of the number of times the endpoint is unreachable, effectively reducing the service unavailable time, ensuring that traffic data is not distributed to invalid apiservers, guaranteeing the completeness of requests, and reducing the failure rate.
[0138] To implement the cluster access method of the embodiments of the present application, the embodiments of the present application further provide a cluster access device, which is applied to the API proxy device component. Figure 6 It is a schematic structural diagram of the composition of the cluster access device of the embodiments of the present application, as Figure 6 shown. The cluster access device includes:
[0139] A receiving unit 61, configured to receive a first request sent by a management cluster; the first request represents an access request for requesting to access a server of a target service cluster, the server is an apiserver, the target service cluster is one of one or more service clusters controlled by the management cluster, and the first request includes traffic data.
[0140] A first determination unit 62, configured to, in response to the first request, determine the endpoint status corresponding to the servers of the one or more service clusters based on the algorithm of the probability density function.
[0141] A second determination unit 63, configured to determine the server of the target service cluster based on the endpoint status corresponding to the servers of the one or more service clusters.
[0142] A sending unit 64, configured to send the traffic data to the server of the target service cluster.
[0143] In one embodiment, the first determination unit 62 includes a first determination subunit and a second determination subunit; wherein,
[0144] The first determination subunit is configured to determine the survival probability of the endpoints corresponding to the servers of the one or more service clusters based on the algorithm of the probability density function.
[0145] The second determination subunit is configured to determine the endpoint status corresponding to the servers of the one or more service clusters based on the survival probability of the endpoints corresponding to the servers of the one or more service clusters.
[0146] In one embodiment, the algorithm of the probability density function includes an exponential distribution function algorithm based on the exponential distribution.
[0147] The first determination subunit is specifically configured to:
[0148] Based on the exponential distribution function algorithm, determine a target time interval; the target time interval represents the time interval between a first time and a second time, the first time represents the time when the current data sample in the target sequence is sampled successfully, and the second time represents the time when the last data sample in the target sequence is sampled successfully.
[0149] Determine the survival probability of the endpoints corresponding to the servers of the one or more service clusters based on the target time interval.
[0150] In one embodiment, the endpoint status includes an endpoint reachable status and an endpoint unreachable status;
[0151] The second determination subunit includes a comparison unit, a third determination subunit, and a fourth determination subunit; wherein,
[0152] The comparison unit is configured to compare the survival probability of the endpoints corresponding to the servers of the one or more service clusters with a probability threshold to obtain a comparison result;
[0153] The third determination subunit is configured to determine that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint reachable status when the comparison result indicates that the survival probability of the endpoints is greater than the probability threshold;
[0154] The fourth determination subunit is configured to determine that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint unreachable status when the comparison result indicates that the survival probability of the endpoints is less than or equal to the probability threshold.
[0155] In one embodiment, the cluster access device further includes a creation unit; wherein,
[0156] The creation unit is configured to create a storage queue;
[0157] The cluster access device further includes a storage unit; wherein,
[0158] The storage unit is configured to store the endpoint data in the endpoint reachable status into the storage queue after the third determination subunit determines that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint reachable status; the stored data of the storage queue can be dynamically adjusted, and the length of the storage queue does not exceed a length threshold.
[0159] In one embodiment, the cluster access device further includes a judgment unit and a setting unit; wherein,
[0160] The judgment unit is configured to judge whether the endpoint unreachable status meets a set condition after the fourth determination subunit determines that the endpoint status corresponding to the servers of the one or more service clusters is the endpoint unreachable status;
[0161] The setting unit is configured to set the weight of the endpoint in the endpoint unreachable status to zero when the judgment unit judges that the endpoint unreachable status meets the set condition.
[0162] In one embodiment, the second determination unit 63 is specifically configured to:
[0163] When the endpoint status corresponding to the server of the one or more service clusters is the endpoint reachable status, determine that the endpoint is a live endpoint;
[0164] Determine the server of the service cluster corresponding to the live endpoint as the server of the target service cluster.
[0165] In one embodiment, the cluster access device further includes a first monitoring unit and an operation execution unit; wherein,
[0166] The first monitoring unit is configured to monitor the CRD resource information of the one or more service clusters when the API proxy device component is started;
[0167] The operation execution unit is configured to execute an operation related to the change in the CRD resource information when the first monitoring unit monitors that the CRD resource information of the one or more service clusters changes.
[0168] In one embodiment, the cluster access device further includes a second monitoring unit and an update unit; wherein,
[0169] The second monitoring unit is configured to monitor the encrypted file corresponding to the CRD of the one or more service clusters;
[0170] The update unit is configured to update the access certificate file in the API proxy device component when the second monitoring unit monitors that the encrypted file corresponding to the CRD of the one or more service clusters changes.
[0171] In one embodiment, the update unit is specifically configured to:
[0172] Obtain a target access certificate file; the target access certificate file is generated by a registration component and sent to the API proxy device component;
[0173] Update the access certificate file in the API proxy device component based on the target access certificate file.
[0174] In practical applications, the receiving unit 61 and the sending unit 64 can be implemented by a communication interface in the cluster access device; the first determination unit 62 and the second determination unit 63 can be implemented by a processor in the cluster access device.
[0175] It should be noted that: when the cluster access device provided in the above embodiments performs cluster access, only the division of the above program modules is used for illustration. In practical applications, the above processing can be allocated to different program modules according to needs, that is, the internal structure of the device is divided into different program modules to complete all or part of the processing described above. In addition, the cluster access device provided in the above embodiments and the embodiments of the cluster access method belong to the same concept. For the specific implementation process, please refer to the embodiments of the cluster access method, which will not be elaborated here.
[0176] Based on the hardware implementation of the above program modules, and in order to implement the cluster access method of the embodiments of the present application, the embodiments of the present application further provide a cluster access device, which is an API proxy device component. Figure 7 FIG. is a schematic diagram of the hardware composition structure of the cluster access device of the embodiments of the present application. As Figure 7 shown, the cluster access device 70 includes:
[0177] A communication interface 71 capable of interacting with other devices;
[0178] A processor 72, connected to the communication interface 71 to achieve information interaction with other devices, and used to execute the above-provided cluster access method when running a computer program, and the computer program is stored on a memory 73.
[0179] It should be noted that: the specific processing processes of the communication interface 71 and the processor 72 can be understood with reference to the above cluster access method.
[0180] Of course, in practical applications, each component in the cluster access device 70 is coupled together through a bus system 74. It can be understood that the bus system 74 is used to realize the connection and communication between these components. The bus system 74 includes not only a data bus, but also a power bus, a control bus, and a status signal bus. However, for the sake of clarity, in Figure 7 all kinds of buses are labeled as the bus system 74.
[0181] The memory 73 in the embodiments of the present application is used to store various types of data to support the operation of the cluster access device 70. Examples of these data include: any computer program for operating on the cluster access device 70.
[0182] The cluster access method disclosed in the embodiments of the present application can be applied to or implemented by the processor 72. The processor 72 may be an integrated circuit chip with signal processing capabilities. During implementation, the steps of the above cluster access method can be completed through the integrated logic circuit in hardware or instructions in software form in the processor 72. The above processor 72 may be a general-purpose processor, a digital signal processor (DSP), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The processor 72 can implement or execute the various cluster access methods, steps, and logic block diagrams disclosed in the embodiments of the present application. The general-purpose processor may be a microprocessor or any conventional processor, etc. Combining the steps of the cluster access method disclosed in the embodiments of the present application can be directly embodied as being executed and completed by a hardware decoding processor, or by a combination of hardware and software modules in the decoding processor. The software module may be located in a storage medium, and this storage medium is located in the memory 73. The processor 72 reads the information in the memory 73 and combines its hardware to complete the steps of the foregoing cluster access method.
[0183] In an exemplary embodiment, the cluster access device 70 can be implemented by one or more application-specific integrated circuits (ASICs), DSPs, programmable logic devices (PLDs), complex programmable logic devices (CPLDs), field-programmable gate arrays (FPGAs), general-purpose processors, controllers, microcontroller units (MCUs), microprocessors, or other electronic components, and is used to execute the foregoing cluster access method.
[0184] It can be understood that the memory 73 in the embodiments of the present application can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable read-only memory (PROM), an erasable programmable read-only memory (EPROM), an electrically erasable programmable read-only memory (EEPROM), a ferromagnetic random access memory (FRAM), a flash memory, a magnetic surface memory, an optical disc, or a compact disc read-only memory (CD-ROM); the magnetic surface memory can be a disk memory or a tape memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static random access memory (SRAM), synchronous static random access memory (SSRAM), dynamic random access memory (DRAM), synchronous dynamic random access memory (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), sync link dynamic random access memory (SLDRAM), direct rambus random access memory (DRRAM).The memory 73 described in the embodiments of the present application is intended to include, but is not limited to, these and any other suitable types of memories.
[0185] In an exemplary embodiment, the embodiments of the present application further provide a storage medium, specifically a computer storage medium, more specifically a computer-readable storage medium. For example, it includes a memory 73 that stores a computer program. The above computer program can be executed by a processor 72 in the cluster access device 70 to complete the steps of the cluster access method described in the foregoing embodiments of the present application. Among them, the computer-readable storage medium can be a FRAM, ROM, PROM, EPROM, EEPROM, Flash Memory, magnetic surface memory, optical disc, or CD-ROM, etc.
[0186] In an exemplary embodiment, the embodiments of the present application further provide a computer program product, including a computer program. The computer program can be executed by a processor 72 in the cluster access device 70 to complete the steps of the cluster access method described in the foregoing embodiments of the present application.
[0187] It should be noted that: "first", "second", "third", etc. are used to distinguish similar objects and do not necessarily describe a specific order or sequence.
[0188] In addition, the technical solutions described in the embodiments of the present application can be arbitrarily combined without conflict.
[0189] The above is only the specific implementation manner of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed by the present application, and all should be covered by the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.
Claims
1. A cluster access method, characterized in that: Applied to an application program interface (API) proxy device component, the method comprises: Receive a first request sent by the management cluster; the first request represents an access request for requesting access to a server of a target business cluster, the server is an application program interface server apiserver, the target business cluster is one of the one or more business clusters managed by the management cluster, and the first request includes traffic data; In response to the first request, determining, based on an algorithm of a probability density function, endpoint states corresponding to servers of the one or more service clusters; Based on the endpoint states corresponding to the servers of the one or more business clusters, the server of the target business cluster is determined, and the traffic data is sent to the server of the target business cluster.
2. The method according to claim 1, characterized in that The algorithm based on the probability density function determines the endpoint status corresponding to the server of the one or more service clusters, including: Determining the survival probability of the endpoints corresponding to the servers of the one or more service clusters based on the algorithm of the probability density function; Based on the survival probabilities of the endpoints corresponding to the servers of the one or more service clusters, the states of the endpoints corresponding to the servers of the one or more service clusters are determined.
3. The method according to claim 2, characterized in that The algorithm of the probability density function includes an exponential distribution function algorithm based on exponential distribution; The algorithm based on the probability density function determines the survival probability of the endpoints corresponding to the servers of the one or more service clusters, including: Based on the exponential distribution function algorithm, a target time interval is determined; the target time interval represents the time interval between a first time and a second time, the first time represents the time when the current data sample in the target sequence is successfully sampled, and the second time represents the time when the last data sample in the target sequence is successfully sampled; Based on the target time interval, the survival probability of the endpoints corresponding to the servers of the one or more service clusters is determined.
4. The method according to claim 2, characterized in that: The endpoint status includes an endpoint reachable state and an endpoint unreachable state; The determining, based on the survival probabilities of the endpoints corresponding to the servers of the one or more service clusters, the endpoint states corresponding to the servers of the one or more service clusters includes: Comparing the survival probability of the endpoints corresponding to the servers of the one or more service clusters with a probability threshold to obtain a comparison result; When the comparison result indicates that the survival probability of the endpoint is greater than the probability threshold, determining that the endpoint state corresponding to the server of the one or more service clusters is an endpoint reachable state; When the comparison result indicates that the survival probability of the endpoint is less than or equal to the probability threshold, it is determined that the endpoint state corresponding to the server of the one or more service clusters is an endpoint unreachable state.
5. The method according to claim 4, characterized in that The method further comprises: creating a storage queue; After determining that the endpoint status corresponding to the server of the one or more service clusters is an endpoint reachable state, the method further includes: The endpoint data in the endpoint reachable state is stored in the storage queue; the storage data of the storage queue can be adjusted dynamically, and the length of the storage queue does not exceed a length threshold.
6. The method according to claim 4, characterized in that After determining that the endpoint status corresponding to the server of the one or more service clusters is an endpoint unreachable state, the method further includes: Determine whether the endpoint unreachable state meets the set condition; When it is determined that the endpoint unreachable state satisfies a set condition, the weight of the endpoint in the endpoint unreachable state is set to zero.
7. The method according to claim 1, characterized in that The determining the server of the target business cluster based on the endpoint states corresponding to the servers of the one or more business clusters includes: When the endpoint state corresponding to the server of the one or more service clusters is an endpoint reachable state, determining that the endpoint is a surviving endpoint; The server of the service cluster corresponding to the surviving endpoint is determined as the server of the target service cluster.
8. The method according to claim 1, characterized in that The method further comprises: When the API proxy device component is started, monitoring the definition CRD resource information of the custom resources of the one or more business clusters; When a change in the CRD resource information of the one or more service clusters is detected, an operation related to the change in the CRD resource information is performed.
9. The method according to claim 1, characterized in that: The method further comprises: Monitor the encrypted file corresponding to the definition CRD of the custom resource of the one or more business clusters; When it is monitored that the encrypted file corresponding to the CRD of the one or more service clusters changes, the access certificate file in the API proxy device component is updated.
10. The method according to claim 9, characterized in that The updating of the access certificate file in the API proxy device component includes: Obtaining a target access certificate file; the target access certificate file is generated by the registration component and sent to the API proxy device component; Based on the target access certificate file, the access certificate file in the API proxy device component is updated.
11. A cluster access device, characterized in that: Applied to an application program interface API proxy device component, the device includes: A receiving unit, configured to receive a first request sent by a management cluster; the first request represents an access request for requesting access to a server of a target business cluster, the server is an application program interface server apiserver, the target business cluster is one of the one or more business clusters managed by the management cluster, and the first request includes traffic data; A first determining unit, configured to determine, in response to the first request, endpoint states corresponding to the servers of the one or more service clusters based on an algorithm of a probability density function; A second determining unit, configured to determine a server of the target business cluster based on endpoint states corresponding to the servers of the one or more business clusters; A sending unit is used to send the traffic data to the server of the target service cluster.
12. A cluster access device, characterized in that: include: a processor and a memory for storing a computer program capable of running on said processor; Wherein, when the processor is used to run the computer program, it executes the steps of the method described in any one of claims 1 to 10.
13. A storage medium having a computer program stored thereon, characterized in that: When the computer program is executed by a processor, the steps of the method according to any one of claims 1 to 10 are implemented.
14. A computer program product comprising a computer program, characterized in that The computer program implements the steps of the method according to any one of claims 1 to 10 when executed by a processor.