Network creation method based on cloud management platform and cloud management platform
By creating a virtual gateway on the cloud management platform and building a branch network exclusive to tenants, the problem of high communication delay in the cloud backbone network is solved and more efficient inter-cluster communication is achieved.
Patent Information
- Application Number
- CN202410231518.X
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Priority Date
- 2023-12-22
- Filing Date
- 2024-02-29
- Publication Date
- 2025-06-24
AI Technical Summary
When communicating between tenant clusters, existing cloud backbone networks need to bypass the geographical area, resulting in a higher communication delay.
Through the cloud management platform, create a virtual gateway on the tenant's own access point and build a tenant-only branch network so that the cluster's traffic does not need to bypass the geographical area.
Improve communication delay between tenant clusters and realize a more intuitive communication path.
Smart Images

Figure CN120201026A_ABST
Abstract
Description
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on December 22, 2023, with application number 202311791810.9 and invention name “A network architecture based on access gateway device”, all contents of which are incorporated by reference in this application. Technical Field
[0002] The embodiments of the present application relate to the field of cloud technology, and in particular to a network creation method based on a cloud management platform and a cloud management platform. Background Art
[0003] With the rapid development of cloud technology, cloud vendors have built cloud backbone networks all over the world for tenants to use. Tenants can use the cloud backbone networks provided by cloud vendors to achieve interoperability between their multiple physical server clusters, making it easier for tenants to build distributed data centers.
[0004] In related technologies, the cloud backbone network built by cloud vendors usually provides multiple parent access points, each of which is connected to multiple sub-access points for tenants. Different parent access points are located in different geographical areas, and different sub-access points are also located in different geographical areas. When a tenant needs to connect two of its clusters, two sub-access points close to the two clusters can be selected from several access points, and the two clusters can be connected to the two sub-access points respectively, so that the two clusters can achieve communication connection through the sub-access points, parent access points and cloud backbone network in sequence.
[0005] In the above process, the traffic of the tenant's cluster first flows into the child access point, then passes through the parent access point of the child access point, and then enters the cloud backbone network. It can be seen that the traffic of the cluster cannot directly enter the cloud backbone network from the child access point, but needs to pass through the parent access point to enter the cloud backbone network, that is, it needs to bypass a certain geographical area, which will cause a high communication delay between tenants' clusters. Summary of the invention
[0006] The embodiments of the present application provide a network creation method based on a cloud management platform and a cloud management platform, which can enable the cluster traffic to not detour through geographical areas when the clusters of tenants communicate with each other, thereby improving the communication latency between the clusters of tenants.
[0007] A first aspect of an embodiment of the present application provides a network creation method based on a cloud management platform, wherein the cloud management platform used to implement the method manages multiple access points that can build a branch network of a tenant, and the multiple access points are located in different geographical areas, and the method includes:
[0008] When a tenant needs to create a branch network for the tenant's first cluster and the tenant's second cluster (both the first cluster and the second cluster contain multiple physical servers), the cloud management platform can provide a network creation interface to the tenant, and the network creation interface can display multiple access points to the tenant. After the tenant browses the multiple access points, since the tenant knows that the first cluster is located in the first geographical area and the second cluster is located in the second geographical area, the tenant can select the first access point also located in the first geographical area and the second access point located in the second geographical area from the multiple access points, and input the configuration information of the branch network to the network creation interface, and the configuration information is used to indicate the first access point and the second access point. In this way, the cloud management platform can receive the configuration information of the branch network through the network creation interface.
[0009] After obtaining the configuration information of the branch network, based on the configuration information, the cloud management platform can determine that the tenant needs to build the branch network between the first access point and the second access point. Then, the cloud management platform can create a first virtual gateway dedicated to the tenant in the first physical gateway of the first access point, and create a second virtual gateway dedicated to the tenant in the second physical gateway of the second access point.
[0010] After obtaining the first virtual gateway and the second virtual gateway, the cloud management platform can build the branch network between the first virtual gateway and the second virtual gateway. Since the first access point where the first virtual gateway is located and the tenant's first cluster are both located in the first geographical area, and the second access point where the second virtual gateway is located and the tenant's second cluster are both located in the second geographical area, the tenant can enable the first cluster to access the branch network through the first virtual gateway, and enable the second cluster to access the branch network through the second virtual gateway. In this way, the first cluster and the second cluster can communicate through the branch network.
[0011] It can be seen from the above method that: the cloud management platform can create virtual gateways (i.e., the aforementioned first virtual gateway and second virtual gateway) at several access points (i.e., the aforementioned first access point and second access point) selected by the tenant himself, so as to build a tenant-specific branch network between the virtual gateways of several access points. Since these several access points are selected by the tenant according to the geographical areas where several clusters (i.e., the aforementioned first cluster and second cluster) to be connected are located, that is to say, the geographical areas where these several access points are located (i.e., the aforementioned first geographical area and second geographical area) coincide with the geographical areas where several clusters of the tenant are located (i.e., the aforementioned first geographical area and second geographical area) respectively. Therefore, after several clusters of the tenant access the tenant's branch network through the virtual gateways of these several access points and communicate with each other, when the clusters of the tenant communicate, the traffic of the clusters does not need to detour around the geographical area, which can improve the communication delay between the clusters of the tenant.
[0012] In a possible implementation, the configuration information includes the identifier of the branch network, the identifier of the first access point, and the identifier of the second access point; the identifier of the branch network includes the identity document (ID) of the branch network and the structure of the branch network; the identifier of the first access point includes the ID of the first geographical area, the ID of the first virtual gateway, and the ID of the first access point; the identifier of the second access point includes the ID of the second geographical area, the ID of the second virtual gateway, and the ID of the second access point. In the foregoing implementation, the configuration information of the tenant's branch network may include the identifier of the tenant's branch network, the identifier of the first access point, and the identifier of the second access point. Among them, the identifier of the branch network may include various information set by the tenant for its branch network. For example, the ID set by the tenant for its branch network and the structure set by the tenant for its branch network. The identifier of the first access point may include various information that can be used to represent the first access point selected by the tenant. For example, the ID of the first geographical area where the first access point is located, the ID of the first virtual gateway that can be created at the first access point, and the ID of the first access point itself, etc. The identifier of the second access point may include various information that can be used to represent the second access point selected by the tenant. For example, the ID of the second geographical area where the second access point is located, the ID of the second virtual gateway that can be created at the second access point, and the ID of the second access point itself, etc. Thus, since the configuration information of the tenant's branch network includes the above various information, the configuration information can be used to indicate the first access point and the second access point selected by the tenant for constructing the tenant's branch network.
[0013] In a possible implementation, the structure of the branch network is an end-to-end structure. The cloud management platform constructs a branch network between the first virtual gateway and the second virtual gateway, including: the cloud management platform constructs a communication connection between the first virtual gateway and the second virtual gateway to obtain the branch network. In the foregoing implementation, if the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is an end-to-end structure, the cloud management platform may use the first virtual gateway and the second virtual gateway as the two endpoints of the tenant's branch network to directly construct a communication connection between the first virtual gateway and the second virtual gateway, thereby obtaining the tenant's branch network. Thus, the tenant can customize its branch network as an end-to-end structure, and the cloud management platform can build the tenant's branch network according to the tenant's needs, so as to meet the tenant's setting requirements for the branch network and adapt to the tenant's needs in different scenarios.
[0014] In a possible implementation, the structure of the branch network is a mesh structure, and the configuration information is further used to indicate the third access point for constructing the branch network. The cloud management platform constructs a branch network between the first virtual gateway and the second virtual gateway, including: the cloud management platform constructs communication connections between the first virtual gateway, the second virtual gateway, and the third virtual gateway of the third access point in pairs to obtain the branch network; wherein, the third virtual gateway is used for the third cluster of the tenant to access the branch network, the third cluster includes multiple physical servers, and the third cluster is located in the third geographical area where the third access point is located. In the foregoing implementation, if the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is a mesh structure, and the configuration information is not only used to indicate the first access point and the second access point selected by the tenant for constructing the branch network, but also used to indicate the third access point selected by the tenant for constructing the branch network, the cloud management platform can also create a third virtual gateway on the third physical gateway of the third access point. Then, the cloud management platform can use the first virtual gateway, the second virtual gateway, and the third virtual gateway as the endpoints that can communicate with each other in pairs in the tenant's branch network to construct communication connections between the first virtual gateway, the second virtual gateway, and the third virtual gateway in pairs, so as to obtain the tenant's branch network. Subsequently, the tenant can enable the first cluster to access the branch network through the first virtual gateway, enable the second cluster to access the branch network through the second virtual gateway, and enable the third cluster to access the branch network through the third virtual gateway. In this way, the first cluster, the second cluster, and the third cluster can communicate through the branch network. It can be seen that the tenant can customize its branch network as a mesh structure, and the cloud management platform can build the tenant's branch network according to the tenant's needs, so as to meet the tenant's settings requirements for the branch network and adapt to the tenant's needs in different scenarios.
[0015] In a possible implementation manner, the structure of the branch network is a hybrid structure, and the configuration information is further used to indicate the third access point for constructing the branch network. The cloud management platform constructs a branch network between the first virtual gateway and the second virtual gateway, including: the cloud management platform constructs a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and the third virtual gateway of the third access point, so as to obtain the branch network; wherein, the third virtual gateway is used for the third cluster of the tenant to access the branch network, the third cluster includes multiple physical servers, and the third cluster is located in the third geographical area where the third access point is located. In the foregoing implementation manner, if the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is a hybrid structure, and the configuration information is not only used to indicate the first access point and the second access point selected by the tenant for constructing the branch network, but also used to indicate the third access point selected by the tenant for constructing the branch network, the cloud management platform can also create a third virtual gateway on the third physical gateway of the third access point. Then, the cloud management platform can use the first virtual gateway, the second virtual gateway, and the third virtual gateway as the endpoints connected in sequence in the tenant's branch network, so as to construct a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and the third virtual gateway, thereby obtaining the tenant's branch network. Subsequently, the tenant can enable the first cluster to access the branch network through the first virtual gateway, enable the second cluster to access the branch network through the second virtual gateway, and enable the third cluster to access the branch network through the third virtual gateway. In this way, the first cluster, the second cluster, and the third cluster can communicate through the branch network. It can be seen that the tenant can customize its branch network as a hybrid structure, and the cloud management platform can build the tenant's branch network according to the tenant's needs, so as to meet the tenant's setting requirements for the branch network and adapt to the tenant's needs in different scenarios.
[0016] In a possible implementation, the structure of the branch network is a star structure, and the configuration information is further used to indicate the third access point for constructing the branch network. The cloud management platform constructs a branch network between the first virtual gateway and the second virtual gateway, including: the cloud management platform constructs a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and the third virtual gateway of the third access point, so as to obtain the branch network; wherein, the third virtual gateway is used for the third cluster of the tenant to access the branch network, the third cluster includes multiple physical servers, and the third cluster is located in the third geographical area where the third access point is located. In the foregoing implementation, if the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is a star structure, and this configuration information is not only used to indicate the first access point and the second access point selected by the tenant for constructing the branch network, but also used to indicate the third access point selected by the tenant for constructing the branch network, the cloud management platform can also create a third virtual gateway on the third physical gateway of the third access point. Then, the cloud management platform can use the first virtual gateway as the center point in the tenant's branch network, and the second virtual gateway and the third virtual gateway as the extension points in the branch network, so as to construct a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and the third virtual gateway, thereby obtaining the tenant's branch network. Subsequently, the tenant can enable the first cluster to access the branch network through the first virtual gateway, enable the second cluster to access the branch network through the second virtual gateway, and enable the third cluster to access the branch network through the third virtual gateway. In this way, the first cluster, the second cluster, and the third cluster can communicate through the branch network. It can be seen that the tenant can customize its branch network as a star structure, and the cloud management platform can build the tenant's branch network according to the tenant's needs, so as to meet the tenant's setting requirements for the branch network and adapt to the tenant's needs in different scenarios.
[0017] In a possible implementation, the communication connections between the first virtual gateway, the second virtual gateway, and the third virtual gateway are all implemented based on the cloud backbone network.
[0018] In a possible implementation, the first access point and the second access point are any one of the following: region, availability zone, data center, and computer room.
[0019] A second aspect of the embodiments of the present application provides a cloud management platform, which is used to manage multiple access points that can build a tenant's branch network. The multiple access points are located in different geographical regions. The cloud management platform includes: a receiving module, configured to receive, through a network creation interface, configuration information of the branch network sent by the tenant. The configuration information is used to indicate a first access point and a second access point selected by the tenant from the multiple access points for building the branch network; a creation module, configured to create a first virtual gateway of the tenant in a first physical gateway of the first access point and create a second virtual gateway of the tenant in a second physical gateway of the second access point based on the configuration information; a construction module, configured to build a branch network between the first virtual gateway and the second virtual gateway; wherein, the first virtual gateway is used for the first cluster of the tenant to access the branch network, the second virtual gateway is used for the second cluster of the tenant to access the branch network, both the first cluster and the second cluster include multiple physical servers, the first cluster is located in a first geographical region where the first access point is located, and the second cluster is located in a second geographical region where the second access point is located.
[0020] In a possible implementation manner, the configuration information includes an identifier of the branch network, an identifier of the first access point, and an identifier of the second access point; the identifier of the branch network includes an identity identification number ID of the branch network and the structure of the branch network; the identifier of the first access point includes an ID of the first geographical region, an ID of the first virtual gateway, and an ID of the first access point; the identifier of the second access point includes an ID of the second geographical region, an ID of the second virtual gateway, and an ID of the second access point.
[0021] In a possible implementation manner, the structure of the branch network is an end-to-end structure. The construction module is configured to build a communication connection between the first virtual gateway and the second virtual gateway to obtain the branch network.
[0022] In a possible implementation manner, the structure of the branch network is a mesh structure. The configuration information is further used to indicate a third access point for building the branch network. The construction module is configured to build communication connections between the first virtual gateway, the second virtual gateway, and a third virtual gateway of the third access point two by two to obtain the branch network; wherein, the third virtual gateway is used for a third cluster of the tenant to access the branch network, the third cluster includes multiple physical servers, and the third cluster is located in a third geographical region where the third access point is located.
[0023] In a possible implementation, the structure of the branch network is a hybrid structure, and the configuration information is further used to indicate a third access point for constructing the branch network. The construction module is used to construct a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and the third virtual gateway of the third access point, so as to obtain the branch network; wherein, the third virtual gateway is used for the third cluster of the tenant to access the branch network. The third cluster includes multiple physical servers, and the third cluster is located in the third geographical area where the third access point is located.
[0024] In a possible implementation, the structure of the branch network is a star structure, and the configuration information is further used to indicate a third access point for constructing the branch network. The construction module is used to construct a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and the third virtual gateway of the third access point, so as to obtain the branch network; wherein, the third virtual gateway is used for the third cluster of the tenant to access the branch network. The third cluster includes multiple physical servers, and the third cluster is located in the third geographical area where the third access point is located.
[0025] In a possible implementation, the communication connection is implemented based on a cloud backbone network.
[0026] In a possible implementation, the first access point and the second access point are any one of the following: region, availability zone, data center, and computer room.
[0027] In the third aspect of the embodiments of the present application, a computing device cluster is provided. The computing device cluster includes at least one computing device, and each computing device includes a processor and a memory: the memory is used to store instructions; the processor is used to execute the method described in the first aspect or any possible implementation manner in the first aspect according to the instructions, so that the computing device cluster performs the method.
[0028] In the fourth aspect of the embodiments of the present application, a computer storage medium is provided. The computer storage medium stores one or more instructions, and when the instructions are executed by one or more computers, the one or more computers are caused to implement the method described in the first aspect or any possible implementation manner in the first aspect.
[0029] In the fifth aspect of the embodiments of the present application, a computer program product is provided. The computer program product stores instructions, and when the instructions are executed by a computer, the computer is caused to implement the method described in the first aspect or any possible implementation manner in the first aspect.
[0030] In the embodiments of the present application, when a tenant needs to create a branch network for the tenant's first cluster and the tenant's second cluster, the tenant can input the configuration information of the branch network into the network creation interface provided by the cloud management platform, so that the cloud management platform can receive the configuration information of the branch network through the network creation interface. The configuration information is used to indicate the first access point and the second access point selected by the tenant from multiple access points. Then, based on the configuration information, the cloud management platform can create a first virtual gateway dedicated to the tenant in the first physical gateway of the first access point, and create a second virtual gateway dedicated to the tenant in the second physical gateway of the second access point. Then, the cloud management platform can build a tenant-specific branch network between the first virtual gateway and the second virtual gateway. Since the first access point where the first virtual gateway is located and the tenant's first cluster are both in the first geographical area, and the second access point where the second virtual gateway is located and the tenant's second cluster are both in the second geographical area, the tenant can make the first cluster access the branch network through the first virtual gateway, and make the second cluster access the branch network through the second virtual gateway. In this way, the first cluster and the second cluster can communicate through the branch network. In the foregoing process, the cloud management platform can create virtual gateways (i.e., the foregoing first virtual gateway and second virtual gateway) at several access points (i.e., the foregoing first access point and second access point) selected by the tenant itself, so as to build a tenant-specific branch network between the virtual gateways of several access points. Since these several access points are selected by the tenant according to the geographical areas where several clusters (i.e., the foregoing first cluster and second cluster) to be connected are located, that is to say, the geographical areas where these several access points are located (i.e., the foregoing first geographical area and second geographical area) coincide with the geographical areas where several clusters of the tenant are located (i.e., the foregoing first geographical area and second geographical area) respectively. Therefore, after several clusters of the tenant access the tenant's branch network through the virtual gateways of these several access points and communicate with each other, when the clusters of the tenant communicate, the traffic of the clusters does not need to detour around the geographical area, which can reduce the communication delay between the clusters of the tenant. BRIEF DESCRIPTION OF THE DRAWINGS
[0031] Figure 1 FIG. is a schematic structural diagram of a cloud service system provided by an embodiment of the present application;
[0032] Figure 2 FIG. is a schematic diagram of multiple access points provided by an embodiment of the present application;
[0033] Figure 3 FIG. is another schematic structural diagram of a cloud service system provided by an embodiment of the present application;
[0034] Figure 4 FIG. is a schematic flowchart of a network creation method based on a cloud management platform provided by an embodiment of the present application;
[0035] Figure 5 A schematic diagram of the tenant interface provided by an embodiment of the present application;
[0036] Figure 6 Another schematic diagram of the tenant interface provided by an embodiment of the present application;
[0037] Figure 7 Another schematic diagram of the tenant interface provided by an embodiment of the present application;
[0038] Figure 8 Another schematic diagram of the tenant interface provided by an embodiment of the present application;
[0039] Figure 9 A schematic diagram of the branch network provided by an embodiment of the present application;
[0040] Figure 10 Another schematic diagram of the branch network provided by an embodiment of the present application;
[0041] Figure 11 Another schematic diagram of the branch network provided by an embodiment of the present application;
[0042] Figure 12 Another schematic diagram of the branch network provided by an embodiment of the present application;
[0043] Figure 13 A schematic structural diagram of the cloud management platform provided by an embodiment of the present application;
[0044] Figure 14 A schematic structural diagram of the computing device provided by an embodiment of the present application;
[0045] Figure 15 A schematic structural diagram of the computing device cluster provided by an embodiment of the present application;
[0046] Figure 16 A schematic diagram of the computer devices in the computer cluster provided by an embodiment of the present application being connected through a network. Detailed implementation manners
[0047] The embodiments of the present application provide a network creation method based on a cloud management platform and the cloud management platform, which can enable the traffic of the clusters of tenants not to bypass geographical regions when communicating between the clusters, and can improve the communication delay between the clusters of tenants.
[0048] In the description, claims and above-mentioned drawings of this application, terms such as "first" and "second" are used to distinguish similar objects, and do not necessarily describe a specific order or sequence. It should be understood that such terms can be interchanged under appropriate circumstances, which is only a way of distinguishing objects with the same attributes when describing the embodiments of this application. In addition, the terms "comprising" and "having" and any variations thereof are intended to cover non-exclusive inclusion, so that a process, method, system, product or device comprising a series of units does not have to be limited to those units, but may include other units not clearly listed or inherent to these processes, methods, products or devices.
[0049] With the rapid development of cloud technology, cloud providers build a backbone network covering the globe for tenants to use, enabling tenants to utilize the backbone network provided by cloud providers to achieve interconnection between their multiple physical server clusters, facilitating the construction of distributed data centers for tenants.
[0050] In the related art, the cloud backbone network independently built by cloud providers usually provides multiple parent access points, each parent access point is connected to multiple child access points for tenants, different parent access points are located in different geographical regions, and different child access points are also located in different geographical regions. When a tenant needs to connect two of its clusters, it can select two child access points close to these two clusters among several access points, and connect these two clusters to these two child access points respectively, so that these two clusters can communicate with each other through the child access points, parent access points and the cloud backbone network in sequence. For example, assume that the backbone network has a parent access point A in Guangzhou and a parent access point B in Hong Kong. The parent access point A is connected to a child access point A1 in Tianhe District and a child access point A2 in Yuexiu District, and the parent access point B is connected to a child access point B1 in the New Territories and a child access point B2 in Kowloon. The tenant's cluster 1 is close to the child access point A1, and the cluster 2 is close to the child access point B2. It can connect the cluster 1 to the child access point A1 and connect the cluster 2 to the child access point B2. In this way, the cluster 1 communicates with the cluster 2 through the child access point A2, the parent access point A, the backbone network, the parent access point B and the child access point B2 in sequence.
[0051] In the above process, the traffic of the tenant's cluster first flows into the child access point, then through the parent access point of the child access point, and then enters the cloud backbone network. It can be seen that the traffic of this cluster cannot directly enter the cloud backbone network from the child access point and needs to pass through the parent access point to enter the cloud backbone network, that is, it needs to detour a certain geographical area, which will result in a relatively high communication delay between the tenant's clusters.
[0052] To solve the above problems, the embodiments of this application provide a network creation method based on a cloud management platform, which can be implemented through a cloud service system. Figure 1This is a schematic structural diagram of the cloud service system provided by the embodiments of the present application. As Figure 1 shown, the cloud service system includes the infrastructure that can provide cloud services and the cloud management platform that manages these infrastructures. The cloud management platform and the infrastructure will be introduced separately below:
[0053] The cloud management platform can overall manage the infrastructures in the entire cloud service system (for example, among multiple access points included in the infrastructure, select several access points from multiple access points according to the instructions of the tenant to build a tenant-specific branch network (site network), etc.), and can also be open to tenants outside the cloud service system and respond to their requests. For example, the cloud management platform can provide various interfaces such as a login interface and a network creation interface for the tenant's client (for example, the terminal device used by the tenant or the browser on the terminal device, etc.) to access. Among them, the cloud management platform can authenticate the tenant's client through the login interface, and after successful authentication, allow the tenant's client to log in to the cloud management platform. Another example is that the cloud management platform can also provide multiple access points for building the tenant's branch network to the tenant's client through the network creation interface, so that the tenant's client can display these multiple access points to the tenant for viewing and selection, where these multiple access points are located in different geographical regions. Another example is that the cloud management platform can also allow the tenant's client to send the configuration information of the tenant's branch network to the cloud management platform through the network creation interface. Then, the cloud management platform can determine several access points selected by the tenant from multiple access points based on this configuration information, and build the tenant's branch network among these several access points. In this way, several clusters of the tenant located in different geographical regions can respectively access the branch network through these several access points to achieve communication between clusters in different locations.
[0054] The infrastructure includes multiple access points (which can also be called access sites) directly accessing the cloud backbone network, and these multiple access points can be used to build the tenant's branch network. It should be noted that these multiple access points are usually located in different geographical regions. For any one of these multiple access points, the geographical region where the access point is located can be a certain plate, or a certain city under a certain plate, or a certain district or county or town under a certain city, etc. The size of the geographical region where the access point is located can be set according to actual needs and is not limited here. Since these multiple access points are all directly accessing the cloud backbone network, there is no longer a distinction between a parent access point and a child access point formed according to the subordinate relationship of geographical regions. That is to say, the cloud backbone network directly opens a larger number of access points to tenants, and the relationship between these multiple access points is peer-to-peer. For example, as Figure 2 shown ( Figure 2A schematic diagram of multiple access points provided by an embodiment of this application. The cloud backbone network spread across the globe can provide a large number of access points in various locations. For example, the access point located in Huaxin Garden, Guangzhou, the access point located in Qili Lake, Guiyang, the access point located in Tseung Kwan O, Hong Kong, and so on.
[0055] The following introduces multiple access points from the perspectives of physical hardware and virtual software respectively. Figure 3 Another structural schematic diagram of the cloud service system provided by an embodiment of this application, as Figure 3 shown. For any one of the multiple access points, this access point can include multiple physical gateways, and each physical gateway has been connected to the cloud backbone network. That is to say, a physical tunnel (which can also be called a physical communication channel) has been established between each physical gateway and the cloud backbone network. Then, when a tenant needs to create its exclusive branch network, the cloud management platform can, according to the tenant's instructions, create a certain virtual gateway of the tenant on the physical gateway of an access point selected by the tenant, create another virtual gateway of the tenant on the physical gateway of another access point selected by the tenant, and build a virtual tunnel (which can also be called a virtual communication channel) that connects these two virtual gateways between these two virtual gateways. This virtual tunnel is built based on the physical tunnels between the physical gateways where these two virtual gateways are located and the cloud backbone network. That is to say, this virtual tunnel passes through the cloud backbone network. Due to the existence of this virtual tunnel, it can be regarded that a communication connection has been established between these two virtual gateways. In this way, the cloud management platform creates the tenant's branch network, and these two virtual gateways can be accessed by two clusters of the tenant (these two clusters are respectively located in the geographical regions where the two access points selected by the tenant are located) to enable the clusters of the tenant to communicate with each other through the tenant's branch network (it should be understood that the foregoing example only uses the tenant's selection of two access points to construct its branch network for illustrative purposes. In actual applications, the tenant can also select a larger number of access points to construct its branch network, which will not be elaborated here).
[0056] In addition, in any physical gateway in any access point, the cloud management platform can create multiple virtual gateways for the clusters of multiple tenants. These virtual gateways have the following multiple characteristics: (1) Among the multiple virtual gateways in this access point, one virtual gateway can serve the cluster of one tenant, so as to achieve isolation between multiple tenants on different virtual gateways in the same access point. (2) Among the multiple virtual gateways in this access point, each virtual gateway has an exclusive virtual tunnel to access the cloud backbone network, so that isolation between multiple tenants can be achieved on the virtual tunnel. (3) For any one of the multiple virtual gateways in this access point, any physical server in the cluster accessing this virtual gateway can have two border gateway protocol (BGP) modules. These two BGP modules (which can also be called BGP peers) can enable this physical server to access this virtual gateway with different network segments (for example, two network segments that are mutually primary and standby, etc.), so that the cluster accessing the virtual gateway has line disaster tolerance capabilities. Further, the cloud management platform can make this virtual gateway learn the network segment (route) of any physical server in the cluster accessing this virtual gateway to achieve communication with any physical server in this cluster. (4) For any one of the multiple virtual gateways in this access point, the cloud management platform can also make this virtual gateway have traffic collection and traffic rate limiting capabilities, so that it can perform traffic metering and billing for the tenant's cluster, etc.
[0057] Furthermore, the physical gateway is essentially a physical instance in the cloud service system. The physical instance can be presented in multiple ways. For example, the physical instance can be a physical server selected by the cloud management platform. Another example is that the physical instance can also be a bare metal server selected by the cloud management platform, etc. The virtual gateway on the physical gateway can also be called a global dedicated gateway (GDGW), and it can also be called a virtual routing forwarding (VRF) instance on the physical gateway. That is to say, the virtual gateway is essentially a virtual instance in the cloud service system. The virtual instance can be presented in multiple ways. For example, the virtual instance can be a virtual machine (VM) created by the cloud management platform on the physical server through virtualization technology. Another example is that the virtual instance can also be a container (docker) created by the cloud management platform on the physical server through virtualization technology. Another example is that the virtual instance can also be a micro virtual machine (microVM) created by the cloud management platform on the physical server through virtualization technology, etc.
[0058] Furthermore, for multiple access points, the multiple access points can be presented in various forms. For example, the multiple access points can be multiple regions in the infrastructure, or the multiple access points can be multiple availability zones in the infrastructure, or the multiple access points can be multiple data centers (DCs) in the infrastructure, or the multiple access points can be multiple rooms in the infrastructure, and so on.
[0059] Based on the above cloud service system, for a tenant, the tenant usually has multiple clusters (which can also be called multiple branches), each cluster can contain multiple physical servers, and the multiple clusters of the tenant are usually located in different geographical regions. When the tenant needs to connect these multiple clusters, the cloud management platform can be used to select several access points from multiple access points to create a tenant-specific branch network. Since this branch network is built based on the virtual gateways of several access points located in different geographical regions, the multiple clusters of the tenant can access this branch network through the virtual gateway closest to them, thereby realizing the interconnection between these multiple clusters. In this way, the clusters of the tenant can directly access the tenant's branch network from the closest access point to directly communicate through the branch network. In this way, the traffic of the clusters no longer needs to detour around a certain geographical region, which can reduce the communication delay between the clusters of the tenant. To further understand the foregoing process, the following will further introduce the process in combination with Figure 3 to further introduce this process. Figure 4 is a schematic flowchart of a network creation method based on a cloud management platform provided by an embodiment of the present application. As Figure 4 shown, this method can be implemented through the Figure 1 shown cloud service system. The cloud service system includes an infrastructure for providing cloud services and a cloud management platform for managing these infrastructures. These infrastructures include multiple access points that can build a tenant's branch network. The multiple access points are located in different geographical regions. This method includes:
[0060] 401. The cloud management platform receives, through a network creation interface, configuration information of a branch network sent by a tenant. The configuration information is used to indicate a first access point and a second access point selected by the tenant from multiple access points for building the branch network.
[0061] In this embodiment, when a tenant needs to create a branch network for the tenant's first cluster and the tenant's second cluster, the cloud management platform can provide a network creation interface to the tenant's client (for example, the branch network name input field, the branch network structure input field, and the access point information input field of the tenant interface, etc.). The network creation interface can display multiple access points for the tenant to select. After the tenant browses the multiple access points displayed by the network creation interface through the tenant's client, since the tenant knows that the first cluster is located in the first geographical area and the second cluster is located in the second geographical area, the tenant can select the first access point also located in the first geographical area and the second access point located in the second geographical area from the multiple access points, and input the configuration information of the tenant's branch network through the tenant's client to the network creation interface. This configuration information is used to indicate the first access point and the second access point. In this way, the cloud management platform can receive the configuration information of the tenant's branch network through the network creation interface.
[0062] Specifically, the configuration information of the tenant's branch network can be presented in the following multiple ways:
[0063] (1) The configuration information of the tenant's branch network can include the identifier of the tenant's branch network, the identifier of the first access point, and the identifier of the second access point. It should be noted that the identifier of the tenant's branch network is usually defined and input by the tenant to the network creation interface, and the network creation interface can provide the identifiers of multiple access points to the tenant. The tenant can select and input the identifier of the first access point and the identifier of the second access point from the identifiers of the multiple access points displayed by the network creation interface. Therefore, the network creation interface can generate the configuration information of the tenant's branch network based on the identifier of the branch network, the identifier of the first access point, and the identifier of the second access point input by the tenant, and send it to the cloud management platform.
[0064] Among them, the identifier of the branch network can include various information set by the tenant for its branch network. For example, the identity document (ID) set by the tenant for its branch network and the structure set by the tenant for its branch network (such as the end-to-end structure, etc.). The identifier of the first access point can include various information that can be used to represent the first access point selected by the tenant. For example, the ID of the first geographical area where the first access point is located, the ID of the first virtual gateway that can be created at the first access point, and the ID of the first access point itself, etc. The identifier of the second access point can include various information that can be used to represent the second access point selected by the tenant. For example, the ID of the second geographical area where the second access point is located, the ID of the second virtual gateway that can be created at the second access point, and the ID of the second access point itself, etc.
[0065] For example, as Figure 5 shown ( Figure 5This is a schematic diagram of the tenant interface provided by the embodiments of the present application. When a tenant needs to build its exclusive branch network, it can log in to the cloud management platform. The cloud management platform can provide a tenant interface for the tenant. The tenant can enter the ID of the branch network, which is site-work-fc25, in the branch network name input field of the tenant interface. Suppose the tenant needs to connect Cluster 1 and Cluster 2. Cluster 1 is located in Qili Lake, Guiyang, and Cluster 2 is located in Runze, Beijing. And the tenant wants to form an end-to-end network between these two clusters. Therefore, the tenant can select and enter the structure of the branch network as the end-to-end structure from the various structures provided in the branch network structure input field. At this time, the access point information input field of the branch network can include two input fields. The tenant can select and enter the ID of the geographical area where Access Point 1 is located, which is Southwest-Guiyang-Qili Lake, from the relevant information of the multiple access points provided in the first input field, and select and enter the ID of the virtual gateway 1 that can be created at Access Point 1, which is er-0818-1, in the first input field. At this time, the ID of Access Point 1, which is Guiyang 61238, will be automatically generated in the first input field (of course, it can also be set and entered by the tenant himself). Similarly, the tenant can select and enter the ID of the geographical area where Access Point 2 is located, which is North China-Beijing-Runze, from the relevant information of the multiple access points provided in the second input field, and select and enter the ID of the virtual gateway 2 that can be created at Access Point 2, which is er-0818-2, in the second input field. At this time, the ID of Access Point 2, which is Beijing 64512, will be automatically generated in the second input field. Then, the information entered by the tenant in each input field can be aggregated into the configuration information of the tenant's branch network and sent to the cloud management platform through these input fields.
[0066] (2) If the tenant needs to build a branch network for the tenant's first cluster, second cluster, and third cluster (located in the third geographical area), the tenant can select the first access point located in the first geographical area, the second access point located in the second geographical area, and the third access point located in the third geographical area from the multiple access points provided by the network creation interface, and send the configuration information of the branch network to the cloud management platform through the network creation interface. It can be seen that the configuration information of the branch network can not only include the identifier of the tenant's branch network, the identifier of the first access point, and the identifier of the second access point, but also include the identifier of the third access point. It should be noted that the identifier of the tenant's branch network is usually defined by the tenant himself and entered into the network creation interface. And the network creation interface can provide the identifiers of multiple access points for the tenant. The tenant can select and enter the identifier of the first access point, the identifier of the second access point, and the identifier of the third access point from the identifiers of the multiple access points displayed by the network creation interface. Therefore, the network creation interface can generate the configuration information of the tenant's branch network based on the identifier of the branch network, the identifier of the first access point, the identifier of the second access point, and the identifier of the third access point entered by the tenant, and send it to the cloud management platform.
[0067] Among them, the identifier of the branch network may include various information set by the tenant for its branch network. For example, the ID set by the tenant for its branch network and the structure set by the tenant for its branch network (such as a mesh structure, a hybrid structure, a star structure, etc.). The identifier of the first access point may include various information that can be used to represent the first access point selected by the tenant. For example, the ID of the first geographical area where the first access point is located, the ID of the first virtual gateway that can be created at the first access point, and the ID of the first access point itself, etc. The identifier of the second access point may include various information that can be used to represent the second access point selected by the tenant. For example, the ID of the second geographical area where the second access point is located, the ID of the second virtual gateway that can be created at the second access point, and the ID of the second access point itself, etc. The identifier of the third access point may include various information that can be used to represent the third access point selected by the tenant. For example, the ID of the third geographical area where the third access point is located, the ID of the third virtual gateway that can be created at the third access point, and the ID of the third access point itself, etc.
[0068] For example, as Figure 6 shown ( Figure 6Another schematic diagram of the tenant interface provided by the embodiments of the present application. When a tenant needs to build its exclusive branch network, it can log in to the cloud management platform. The cloud management platform can provide a tenant interface for the tenant. The tenant can enter the ID of the branch network, which is site-work-fc25, in the branch network name input field of the tenant interface. Suppose the tenant needs to connect Cluster 1, Cluster 2, Cluster 3, and Cluster 4. Cluster 1 is located in Qili Lake, Guiyang, Cluster 2 is located in Runze, Beijing, Cluster 3 is located in XX, Ulanqab, and Cluster 4 is located in Huaxin Garden, Guangzhou. And the tenant wants to form a mesh network among these four clusters. Therefore, the tenant can select and enter the structure of the branch network as a mesh structure from the various structures provided in the branch network structure input field. At this time, the access point information input field of the branch network can include four input fields. The tenant can, from the relevant information of multiple access points provided in the first input field, select and enter in the first input field the ID of the geographical area where Access Point 1 is located, which is Southwest-Guiyang-Qili Lake, and select and enter in the first input field the ID of Virtual Gateway 1 that can be created at Access Point 1, which is er-0818-1. At this time, the first input field will automatically generate the ID of Access Point 1, which is Guiyang 61238. Similarly, the tenant can, from the relevant information of multiple access points provided in the second input field, select and enter in the second input field the ID of the geographical area where Access Point 2 is located, which is North China-Beijing-Runze, and select and enter in the second input field the ID of Virtual Gateway 2 that can be created at Access Point 2, which is er-0818-2. At this time, the second input field will automatically generate the ID of Access Point 2, which is Beijing 64512. Similarly, the tenant can, from the relevant information of multiple access points provided in the third input field, select and enter in the third input field the ID of the geographical area where Access Point 3 is located, which is North China-Ulanqab-XX, and select and enter in the third input field the ID of Virtual Gateway 3 that can be created at Access Point 3, which is er-0818-3. At this time, the third input field will automatically generate the ID of Access Point 3, which is Ulanqab 67892. Similarly, the tenant can, from the relevant information of multiple access points provided in the fourth input field, select and enter in the fourth input field the ID of the geographical area where Access Point 4 is located, which is South China-Guangzhou-Huaxin Garden, and select and enter in the fourth input field the ID of Virtual Gateway 4 that can be created at Access Point 4, which is er-0818-4. At this time, the fourth input field will automatically generate the ID of Access Point 4, which is Guangzhou 67788. Then, the information entered by the tenant in each input field can be aggregated into the configuration information of the tenant's branch network and sent to the cloud management platform through these input fields.
[0069] For another example, as Figure 7 shown ( Figure 7Another schematic diagram of the tenant interface provided by the embodiments of the present application. When a tenant needs to build its exclusive branch network, it can log in to the cloud management platform. The cloud management platform can provide a tenant interface for the tenant. The tenant can enter the ID of the branch network, which is site-work-fc25, in the branch network name input field of the tenant interface. Suppose the tenant needs to connect to Cluster 1, Cluster 2, Cluster 3, and Cluster 4. Cluster 1 is located in Qili Lake, Guiyang, Cluster 2 is located in Runze, Beijing, Cluster 3 is located in XX, Ulanqab, and Cluster 4 is located in Huaxin Garden, Guangzhou. And the tenant wants to form a mixed network among these four clusters. Therefore, the tenant can select and enter the structure of the branch network as a mixed structure from the various structures provided in the branch network structure input field. At this time, the access point information input field of the branch network can include six pairs of input fields. The first input field and the second input field are a pair (indicating that the access points of these two input fields are connected), the third input field and the fourth input field are a pair (indicating that the access points in these two input fields are connected), and the fifth input field and the sixth input field are a pair (indicating that the access points of these two input fields are connected). Among the relevant information of the multiple access points provided in the first input field, the tenant can select and enter the ID of the geographical area where Access Point 1 is located, which is Southwest-Guiyang-Qili Lake, in the first input field, and select and enter the ID of Virtual Gateway 1 that can be created at Access Point 1, which is er-0818-1, in the first input field. At this time, the ID of Access Point 1, which is Guiyang 61238, will be automatically generated in the first input field. Similarly, among the relevant information of the multiple access points provided in the second input field, the tenant can select and enter the ID of the geographical area where Access Point 2 is located, which is North China-Beijing-Runze, in the second input field, and select and enter the ID of Virtual Gateway 2 that can be created at Access Point 2, which is er-0818-2, in the second input field. At this time, the ID of Access Point 2, which is Beijing 64512, will be automatically generated in the second input field. It should be noted that the information in the third input field is the same as that in the second input field, which will not be elaborated here. Similarly, among the relevant information of the multiple access points provided in the fourth input field, the tenant can select and enter the ID of the geographical area where Access Point 3 is located, which is North China-Ulanqab-XX, in the fourth input field, and select and enter the ID of Virtual Gateway 3 that can be created at Access Point 3, which is er-0818-3, in the fourth input field. At this time, the ID of Access Point 3, which is Ulanqab 67892, will be automatically generated in the fourth input field. It should be noted that the information in the fifth input field is the same as that in the fourth input field, which will not be elaborated here. Similarly, among the relevant information of the multiple access points provided in the sixth input field, the tenant can select and enter the ID of the geographical area where Access Point 4 is located, which is South China-Guangzhou-Huaxin Garden, in the sixth input field, and select and enter the ID of Virtual Gateway 4 that can be created at Access Point 4, which is er-0818-4, in the sixth input field. At this time, the ID of Access Point 4, which is Guangzhou 67788, will be automatically generated in the sixth input field.Then, the information entered by the tenant in each input field can be aggregated into the configuration information of the tenant's branch network and sent to the cloud management platform through these input fields.
[0070] For another example, as Figure 8 shown ( Figure 8 which is another schematic diagram of the tenant interface provided by the embodiments of the present application), when the tenant needs to build its exclusive branch network, the tenant can log in to the cloud management platform. The cloud management platform can provide a tenant interface for the tenant. The tenant can enter the ID of the branch network, i.e., site-work-fc25, in the branch network name input field of the tenant interface. Suppose the tenant needs to connect Cluster 1, Cluster 2, and Cluster 4. Cluster 1 is located in Qili Lake, Guiyang, Cluster 2 is located in Runze, Beijing, Cluster 3 is located in XX, Wulanchabu, and the tenant wants to form a star network among these three clusters. Therefore, the tenant can select and enter the structure of the branch network as the star structure from the various structures provided in the branch network structure input field. At this time, the access point information input field of the branch network can include three input fields. The first input field is the central input field of the star structure, and the second and third input fields are the radiation input fields of the star structure. Therefore, the tenant can select and enter, in the first input field, the ID of the geographical area where Access Point 1 is located, i.e., Southwest-Guiyang-Qili Lake, from the relevant information of multiple access points provided in the first input field, and select and enter, in the first input field, the ID of Virtual Gateway 1 that can be created at Access Point 1, i.e., er-0818-1. At this time, the ID of Access Point 1, i.e., Guiyang 61238, will be automatically generated in the first input field. Similarly, the tenant can select and enter, in the second input field, the ID of the geographical area where Access Point 2 is located, i.e., North China-Beijing-Runze, from the relevant information of multiple access points provided in the second input field, and select and enter, in the second input field, the ID of Virtual Gateway 2 that can be created at Access Point 2, i.e., er-0818-2. At this time, the ID of Access Point 2, i.e., Beijing 64512, will be automatically generated in the second input field. Similarly, the tenant can select and enter, in the third input field, the ID of the geographical area where Access Point 3 is located, i.e., North China-Wulanchabu-XX, from the relevant information of multiple access points provided in the third input field, and select and enter, in the third input field, the ID of Virtual Gateway 3 that can be created at Access Point 3, i.e., er-0818-3. At this time, the ID of Access Point 3, i.e., Wulanchabu 67892, will be automatically generated in the third input field. Then, the information entered by the tenant in each input field can be aggregated into the configuration information of the tenant's branch network and sent to the cloud management platform through these input fields.
[0071] 402. The cloud management platform creates the tenant's first virtual gateway in the first physical gateway of the first access point and creates the tenant's second virtual gateway in the second physical gateway of the second access point based on the configuration information.
[0072] After obtaining the configuration information of the tenant's branch network, based on this configuration information, the cloud management platform can determine that the tenant needs to build a tenant-specific branch network between the first access point and the second access point. Then, the cloud management platform can find the first access point and the second access point from multiple access points, create a first virtual gateway dedicated to the tenant in the first physical gateway of the first access point, and create a second virtual gateway dedicated to the tenant in the second physical gateway of the second access point.
[0073] It should be noted that if the cloud management platform determines, based on this configuration information, that the tenant needs to build a tenant-specific branch network between the first access point, the second access point, and the third access point, that is, the configuration information is used not only to indicate the first access point and the second access point but also to indicate the third access point, the cloud management platform can find the first access point, the second access point, and the third access point from multiple access points, create a first virtual gateway dedicated to the tenant in the first physical gateway of the first access point, create a second virtual gateway dedicated to the tenant in the second physical gateway of the second access point, and create a third virtual gateway dedicated to the tenant in the third physical gateway of the third access point.
[0074] 403. The cloud management platform builds a branch network between the first virtual gateway and the second virtual gateway. Among them, the first virtual gateway is used for the first cluster of the tenant to access the branch network, and the second virtual gateway is used for the second cluster of the tenant to access the branch network. Both the first cluster and the second cluster contain multiple physical servers. The first cluster is located in the first geographical area where the first access point is located, and the second cluster is located in the second geographical area where the second access point is located.
[0075] After obtaining the first virtual gateway and the second virtual gateway, the cloud management platform can build a tenant-specific branch network between the first virtual gateway and the second virtual gateway. Since both the first virtual gateway (the first access point where it is located) and the first cluster of the tenant are in the first geographical area, and both the second virtual gateway (the second access point where it is located) and the second cluster of the tenant are in the second geographical area, the tenant can connect the first cluster to the first virtual gateway so that the first cluster can access the tenant's branch network through the first virtual gateway, and connect the second cluster to the second virtual gateway so that the second cluster can access the tenant's branch network through the second virtual gateway. In this way, the first cluster and the second cluster can communicate through the tenant's branch network.
[0076] Specifically, the cloud management platform can create the tenant's branch network between the first virtual gateway and the second virtual gateway in the following multiple ways:
[0077] (1) If the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is an end-to-end structure (which can also be called a point-to-point structure), the cloud management platform can use the first virtual gateway and the second virtual gateway as the two endpoints of the tenant's branch network to directly establish a communication connection between the first virtual gateway and the second virtual gateway, thereby obtaining the tenant's branch network.
[0078] Still as Figure 5 shown in the example, after receiving the configuration information, since the configuration information indicates that the structure of the tenant's branch network is an end-to-end structure, the cloud management platform can create virtual gateway 1 on a certain physical gateway of access point 1 indicated by the configuration information, create virtual gateway 2 on a certain physical gateway of access point 2 indicated by the configuration information, and establish a communication connection between virtual gateway 1 and virtual gateway 2, thereby building a branch network as Figure 9 shown, Figure 9 which is a schematic diagram of the branch network provided by the embodiment of the present application. Then, the tenant can make cluster 1 access the branch network through virtual gateway 1 and make cluster 2 access the branch network through virtual gateway 2, so that cluster 1 and cluster 2 can communicate with each other through the branch network.
[0079] (2) If the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is a mesh structure, the cloud management platform can use the first virtual gateway, the second virtual gateway, and the third virtual gateway as the endpoints that can communicate with each other pairwise in the tenant's branch network to establish communication connections between the first virtual gateway, the second virtual gateway, and the third virtual gateway pairwise, thereby obtaining the tenant's branch network.
[0080] Since the first virtual gateway and the tenant's first cluster are both located in the first geographical area, the second virtual gateway and the tenant's second cluster are both located in the second geographical area, and the third virtual gateway and the tenant's third cluster are both located in the third geographical area, the tenant can connect the first cluster to the first virtual gateway so that the first cluster accesses the branch network through the first virtual gateway, connect the second cluster to the second virtual gateway so that the second cluster accesses the branch network through the second virtual gateway, and connect the third cluster to the third virtual gateway so that the third cluster accesses the branch network through the third virtual gateway. In this way, the first cluster, the second cluster, and the third cluster can communicate through the branch network.
[0081] Still as Figure 6In the example shown, after receiving the configuration information, since the configuration information indicates that the structure of the tenant's branch network is a mesh structure, the cloud management platform can create virtual gateway 1 on a certain physical gateway of access point 1 indicated by the configuration information, create virtual gateway 2 on a certain physical gateway of access point 2 indicated by the configuration information, create virtual gateway 3 on a certain physical gateway of access point 3 indicated by the configuration information, create virtual gateway 4 on a certain physical gateway of access point 4 indicated by the configuration information, and construct communication connections between virtual gateway 1, virtual gateway 2, virtual gateway 3, and virtual gateway 4 pairwise, so as to set up a branch network as shown in Figure 10 The branch network shown Figure 10 is another schematic diagram of the branch network provided by the embodiment of the present application. Then, the tenant can make cluster 1 access the branch network through virtual gateway 1, make cluster 2 access the branch network through virtual gateway 2, make cluster 3 access the branch network through virtual gateway 3, and make cluster 4 access the branch network through virtual gateway 4, so that cluster 1, cluster 2, cluster 3, and cluster 4 can communicate with each other through the branch network.
[0082] (3) If the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is a hybrid structure, the cloud management platform can use the first virtual gateway, the second virtual gateway, and the third virtual gateway as the sequentially connected endpoints in the tenant's branch network to construct a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and the third virtual gateway, so as to obtain the tenant's branch network.
[0083] Still as in Figure 7 In the example shown, after receiving the configuration information, since the configuration information indicates that the structure of the tenant's branch network is a mesh structure, the cloud management platform can create virtual gateway 1 on a certain physical gateway of access point 1 indicated by the configuration information, create virtual gateway 2 on a certain physical gateway of access point 2 indicated by the configuration information, create virtual gateway 3 on a certain physical gateway of access point 3 indicated by the configuration information, create virtual gateway 4 on a certain physical gateway of access point 4 indicated by the configuration information, and sequentially construct communication connections between virtual gateway 1, virtual gateway 2, virtual gateway 3, and virtual gateway 4, so as to set up a branch network as shown in Figure 11 The branch network shown Figure 11Another schematic diagram of the branch network provided by the embodiment of the present application. Then, the tenant can enable Cluster 1 to access the branch network through Virtual Gateway 1, enable Cluster 2 to access the branch network through Virtual Gateway 2, enable Cluster 3 to access the branch network through Virtual Gateway 3, and enable Cluster 4 to access the branch network through Virtual Gateway 4, so that Cluster 1, Cluster 2, Cluster 3, and Cluster 4 can communicate with each other through the branch network.
[0084] (4) If the configuration information of the tenant's branch network is used to indicate that the structure of the tenant's branch network is a star structure, the cloud management platform can use the first virtual gateway as the center point in the tenant's branch network and the second virtual gateway and the third virtual gateway as the extension points in the branch network to establish a communication connection between the first virtual gateway and the second virtual gateway and a communication connection between the first virtual gateway and the third virtual gateway, thereby obtaining the tenant's branch network.
[0085] Still as Figure 8 shown in the example, after receiving the configuration information, since the configuration information indicates that the structure of the tenant's branch network is a star structure, the cloud management platform can create Virtual Gateway 1 on a certain physical gateway of Access Point 1 indicated by the configuration information, create Virtual Gateway 2 on a certain physical gateway of Access Point 2 indicated by the configuration information, create Virtual Gateway 3 on a certain physical gateway of Access Point 3 indicated by the configuration information, and use Virtual Gateway 1 as the center of the branch network and Virtual Gateway 2 and Virtual Gateway 3 as the extensions of the branch network to establish a communication connection between Virtual Gateway 1 and Virtual Gateway 2 and a communication connection between Virtual Gateway 1 and Virtual Gateway 3, thereby building a branch network as Figure 12 shown, Figure 12 Another schematic diagram of the branch network provided by the embodiment of the present application. Then, the tenant can enable Cluster 1 to access the branch network through Virtual Gateway 1, enable Cluster 2 to access the branch network through Virtual Gateway 2, and enable Cluster 3 to access the branch network through Virtual Gateway 3, so that Cluster 1, Cluster 2, and Cluster 3 can communicate with each other through the branch network.
[0086] In the embodiments of the present application, when a tenant needs to create a branch network for the tenant's first cluster and the tenant's second cluster, the tenant can input the configuration information of the branch network into the network creation interface provided by the cloud management platform, so that the cloud management platform can receive the configuration information of the branch network through the network creation interface. The configuration information is used to indicate the first access point and the second access point selected by the tenant from multiple access points. Then, based on the configuration information, the cloud management platform can create a first virtual gateway dedicated to the tenant in the first physical gateway of the first access point, and create a second virtual gateway dedicated to the tenant in the second physical gateway of the second access point. Then, the cloud management platform can build a tenant-specific branch network between the first virtual gateway and the second virtual gateway. Since the first access point where the first virtual gateway is located and the tenant's first cluster are both in the first geographical area, and the second access point where the second virtual gateway is located and the tenant's second cluster are both in the second geographical area, the tenant can make the first cluster access the branch network through the first virtual gateway, and make the second cluster access the branch network through the second virtual gateway. In this way, the first cluster and the second cluster can communicate through the branch network. In the foregoing process, the cloud management platform can create virtual gateways (i.e., the foregoing first virtual gateway and second virtual gateway) at several access points (i.e., the foregoing first access point and second access point) selected by the tenant himself, so as to build a tenant-specific branch network between the virtual gateways of several access points. Since these several access points are selected by the tenant according to the geographical areas where several clusters (i.e., the foregoing first cluster and second cluster) to be connected are located, that is to say, the geographical areas where these several access points are located (i.e., the foregoing first geographical area and second geographical area) coincide with the geographical areas where several clusters of the tenant are located (i.e., the foregoing first geographical area and second geographical area) respectively. Therefore, after several clusters of the tenant are interconnected by accessing the tenant's branch network through the virtual gateways of these several access points, when the clusters of the tenant communicate, the traffic of the clusters does not need to detour around the geographical area, which can reduce the communication delay between the clusters of the tenant.
[0087] Further, in the embodiments of the present application, the cloud management platform provides multiple access points for the tenant to choose through the network creation interface. After the tenant selects the access points, the tenant can also define the structure of the branch network at the network creation interface. For example, end-to-end structure, mesh structure, hybrid structure, star structure, etc., which can meet various setting requirements of the tenant for the branch network to adapt to the tenant's needs in different scenarios.
[0088] Further, in the embodiments of the present application, the cloud management platform can also present the tenant's branch network to the tenant for viewing and adjustment in the form of a topology diagram, Json / Yaml template through the network creation interface, which is beneficial to managing the tenant's branch network and improving the tenant's experience.
[0089] The above is a detailed description of the network creation method based on the cloud management platform provided by the embodiments of the present application. The following will introduce the cloud management platform provided by the embodiments of the present application. Figure 13 It is a schematic structural diagram of the cloud management platform provided by the embodiments of the present application. As Figure 13 shown, the cloud management platform is used to manage multiple access points that can build branch networks for tenants. The multiple access points are located in different geographical regions. The cloud management platform includes:
[0090] A receiving module 1301, configured to receive configuration information of a branch network sent by a tenant through a network creation interface. The configuration information is used to indicate a first access point and a second access point selected by the tenant from the multiple access points for building the branch network. For example, the receiving module 1301 is used to implement Figure 4 step 401 in the embodiment shown.
[0091] A creating module 1302, configured to create a first virtual gateway of the tenant in a first physical gateway of the first access point and create a second virtual gateway of the tenant in a second physical gateway of the second access point based on the configuration information. For example, the creating module 1302 is used to implement Figure 4 step 402 in the embodiment shown.
[0092] A building module 1303, configured to build a branch network between the first virtual gateway and the second virtual gateway. For example, the building module 1303 is used to implement Figure 4 step 403 in the embodiment shown.
[0093] Wherein, the first virtual gateway is used for the first cluster of the tenant to access the branch network, and the second virtual gateway is used for the second cluster of the tenant to access the branch network. Both the first cluster and the second cluster include multiple physical servers. The first cluster is located in the first geographical region where the first access point is located, and the second cluster is located in the second geographical region where the second access point is located.
[0094] In a possible implementation manner, the configuration information includes an identifier of the branch network, an identifier of the first access point, and an identifier of the second access point. The identifier of the branch network includes an identity identification number ID of the branch network and the structure of the branch network. The identifier of the first access point includes an ID of the first geographical region, an ID of the first virtual gateway, and an ID of the first access point. The identifier of the second access point includes an ID of the second geographical region, an ID of the second virtual gateway, and an ID of the second access point.
[0095] In a possible implementation manner, the building module 1303 is configured to build a communication connection between the first virtual gateway and the second virtual gateway to obtain the branch network.
[0096] In a possible implementation manner, the structure of the branch network is a mesh structure, and the configuration information is further used to indicate a third access point for constructing the branch network. The construction module 1303 is used to construct communication connections between the first virtual gateway, the second virtual gateway, and the third virtual gateway of the third access point in pairs to obtain the branch network. Among them, the third virtual gateway is used for the third cluster of the tenant to access the branch network. The third cluster includes multiple physical servers, and the third cluster is located in the third geographical area where the third access point is located.
[0097] In a possible implementation manner, the structure of the branch network is a hybrid structure, and the configuration information is further used to indicate a third access point for constructing the branch network. The construction module 1303 is used to construct a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and the third virtual gateway of the third access point to obtain the branch network. Among them, the third virtual gateway is used for the third cluster of the tenant to access the branch network. The third cluster includes multiple physical servers, and the third cluster is located in the third geographical area where the third access point is located.
[0098] In a possible implementation manner, the structure of the branch network is a star structure, and the configuration information is further used to indicate a third access point for constructing the branch network. The construction module 1303 is used to construct a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and the third virtual gateway of the third access point to obtain the branch network. Among them, the third virtual gateway is used for the third cluster of the tenant to access the branch network. The third cluster includes multiple physical servers, and the third cluster is located in the third geographical area where the third access point is located.
[0099] In a possible implementation manner, the communication connection is implemented based on a cloud backbone network.
[0100] In a possible implementation manner, the first access point and the second access point are any one of the following: region, availability zone, data center, and computer room.
[0101] It should be noted that for the information interaction, implementation process, etc. between the above-mentioned device modules / units, since they are based on the same concept as the method embodiment of the present application, the technical effects brought by them are the same as those of the method embodiment of the present application. The specific content can refer to the description in the method embodiment shown in the foregoing of the embodiment of the present application, and will not be elaborated here.
[0102] Please refer to Figure 14 , Figure 14 which is a schematic structural diagram of a computing device provided by an embodiment of the present application. As Figure 14As shown, the computing device 1400 (which can be used to present the aforementioned cloud management platform) includes: a processor 1401, a memory 1402, a communication interface 1403, and a bus 1404. The processor 1401, the memory 1402, and the communication interface 1403 are coupled through a bus (not labeled in the figure). The memory 1402 stores instructions. When the execution instructions in the memory 1402 are executed, the computing device 1400 executes the methods performed by the cloud management platform in the above method embodiments.
[0103] The computing device 1400 can be one or more integrated circuits configured to implement the above methods. For example: one or more application specific integrated circuits (ASICs), or, one or more digital signal processors (DSPs), or, one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. Again, when the units in the device can be implemented in the form of a processing element scheduler, the processing element can be a general-purpose processor, such as a central processing unit (CPU) or other processors that can call programs. Again, these units can be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0104] The processor 1401 can be a central processing unit (CPU), or other general-purpose processors, digital signal processors (DSPs), application specific integrated circuits (ASICs), field programmable gate arrays (FPGAs), or other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor can be a microprocessor or any conventional processor.
[0105] The memory 1402 can be a volatile memory or a non-volatile memory, or can include both volatile and non-volatile memories. Among them, the non-volatile memory can be a read-only memory (ROM), a programmable ROM (PROM), an erasable PROM (EPROM), an electrically erasable PROM (EEPROM), or a flash memory. The volatile memory can be a random access memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic RAM (DRAM), synchronous DRAM (SDRAM), double data rate SDRAM (DDR SDRAM), enhanced SDRAM (ESDRAM), synchlink DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0106] The executable program code is stored in the memory 1402, and the processor 1401 executes the executable program code to respectively implement the functions of the foregoing receiving module, creating module, building module, and other modules, so as to implement the foregoing network creation method based on the cloud management platform. That is to say, the instructions for executing the foregoing network creation method based on the cloud management platform are stored on the memory 1402.
[0107] The communication interface 1403 uses a transceiver module such as, but not limited to, a network interface card, a transceiver, etc., to implement the communication between the computing device 1400 and other devices or communication networks.
[0108] In addition to the data bus, the bus 1404 may further include a power bus, a control bus, a status signal bus, etc. The bus may be a peripheral component interconnect express (PCIe) bus, an extended industry standard architecture (EISA) bus, a unified bus (Ubus or UB), a compute express link (CXL), a cache coherent interconnect for accelerators (CCIX), etc. The bus may be divided into an address bus, a data bus, a control bus, etc.
[0109] Please refer to Figure 15 , Figure 15 which is a schematic structural diagram of a computing device cluster provided by an embodiment of the present application. As Figure 15 shown, the computing device cluster 1500 includes at least one computing device 1400.
[0110] As Figure 15 shown, the computing device cluster 1500 includes at least one computing device 1400. Instructions for executing the above-mentioned network creation method based on the cloud management platform may be stored in the memories 1402 of one or more of the computing devices 1400 in the computing device cluster 1500.
[0111] In some possible implementation manners, partial instructions for executing the above-mentioned network creation method based on the cloud management platform may also be stored separately in the memories 1402 of one or more of the computing devices 1400 in the computing device cluster 1500. In other words, a combination of one or more computing devices 1400 may jointly execute the instructions for executing the above-mentioned network creation method based on the cloud management platform.
[0112] It should be noted that the memories 1402 in different computing devices 1400 in the computing device cluster 1500 may store different instructions, which are respectively used to execute partial functions of the above-mentioned cloud management platform. That is, the instructions stored in the memories 1402 of different computing devices 1400 may implement the functions of one or more modules among the receiving module, the creating module, the constructing module, etc.
[0113] In some possible implementation manners, one or more of the computing devices 1400 in the computing device cluster 1500 may be connected through a network. Among them, the network may be a wide area network, a local area network, etc.
[0114] Please refer toFigure 16 , Figure 16 is a schematic diagram of computer devices in a computer cluster provided by an embodiment of the present application connected through a network. As Figure 16 shown, two computing devices 1400A and 1400B are connected through a network. Specifically, they are connected to the network through communication interfaces in each computing device.
[0115] In a possible implementation, instructions for executing functions of modules such as a receiving module are stored in the memory of computing device 1400A. At the same time, instructions for executing functions of modules such as a creating module and a building module are stored in the memory of computing device 1400B.
[0116] It should be understood that Figure 16 the functions of computing device 1400A shown in
[0117] can also be completed by multiple computing devices. Similarly, the functions of computing device 1400B can also be completed by multiple computing devices. Figure 4 An embodiment of the present application also relates to a computer storage medium. A program for signal processing is stored in the computer-readable storage medium. When it runs on a computer, it causes the computer to execute the steps performed by the cloud management platform in the embodiment as
[0118] shown. An embodiment of the present application also relates to a computer program product. The computer program product stores instructions. When the instructions are executed by a computer, it causes the computer to execute the steps performed by the cloud management platform in the embodiment as Figure 4 shown.
[0119] Those skilled in the art can clearly understand that for the convenience and brevity of description, the specific working processes of the above-described systems, devices, and units can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0120] In several embodiments provided by the present application, it should be understood that the disclosed systems, devices, and methods can be implemented in other ways. For example, the device embodiments described above are merely illustrative. For example, the division of the units is only a logical function division. In actual implementation, there can be other division methods. For example, multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the displayed or discussed mutual coupling or direct coupling or communication connection can be through some interfaces, and the indirect coupling or communication connection of devices or units can be in an electrical, mechanical, or other form.
[0121] The unit described as a separation component may or may not be physically separated. The component displayed as a unit may or may not be a physical unit, that is, it may be located in one place or distributed to multiple network units. Some or all of the units can be selected according to actual needs to achieve the purpose of the solution of this embodiment.
[0122] In addition, each functional unit in various embodiments of the present application may be integrated in a processing unit, may exist separately as individual physical units, or two or more units may be integrated in one unit. The above integrated unit may be implemented in the form of hardware or in the form of a software functional unit.
[0123] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or all or part of the technical solution, can be embodied in the form of a software product. The computer software product is stored in a storage medium and includes several instructions for causing a computer device (which may be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in various embodiments of the present application. The foregoing storage medium includes: various media such as USB flash drives, mobile hard disks, read-only memories (ROM, read-only memory), random access memories (RAM, random access memory), magnetic disks, or optical discs that can store program codes.
Claims
1. A network creation method based on a cloud management platform, characterized in that: The cloud management platform is used to manage multiple access points that can build a branch network of a tenant, and the multiple access points are located in different geographical areas. The method includes: The cloud management platform receives the configuration information of the branch network sent by the tenant through the network creation interface, wherein the configuration information is used to indicate the first access point and the second access point selected by the tenant from the multiple access points for building the branch network; The cloud management platform creates a first virtual gateway of the tenant in a first physical gateway of the first access point based on the configuration information, and creates a second virtual gateway of the tenant in a second physical gateway of the second access point; The cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway; The first virtual gateway is used for the first cluster of the tenant to access the branch network, and the second virtual gateway is used for the second cluster of the tenant to access the branch network. The first cluster and the second cluster both include multiple physical servers. The first cluster is located in a first geographical area where the first access point is located, and the second cluster is located in a second geographical area where the second access point is located.
2. The method according to claim 1, characterized in that The configuration information includes an identifier of the branch network, an identifier of the first access point, and an identifier of the second access point; The identification of the branch network includes the identification number ID of the branch network and the structure of the branch network; The identifier of the first access point includes the ID of the first geographical area, the ID of the first virtual gateway and the ID of the first access point; The identifier of the second access point includes the ID of the second geographical area, the ID of the second virtual gateway, and the ID of the second access point.
3. The method according to claim 2, characterized in that The structure of the branch network is an end-to-end structure, and the cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway, including: The cloud management platform establishes a communication connection between the first virtual gateway and the second virtual gateway to obtain the branch network.
4. The method according to claim 2, characterized in that The structure of the branch network is a mesh structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway, including: The cloud management platform establishes communication connections between the first virtual gateway, the second virtual gateway and the third virtual gateway of the third access point to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.
5. The method according to claim 2, characterized in that: The structure of the branch network is a hybrid structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway, including: The cloud management platform establishes a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and a third virtual gateway of the third access point, so as to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.
6. The method according to claim 2, characterized in that The structure of the branch network is a star structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the cloud management platform constructs the branch network between the first virtual gateway and the second virtual gateway, including: The cloud management platform establishes a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and a third virtual gateway of the third access point, so as to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.
7. The method according to any one of claims 3 to 6, characterized in that: The communication connection is realized based on the cloud backbone network.
8. The method according to any one of claims 1 to 7, characterized in that: The first access point and the second access point are any one of the following: a region, an availability zone, a data center, and a computer room.
9. A cloud management platform, characterized in that: The cloud management platform is used to manage multiple access points that can build a branch network of a tenant, and the multiple access points are located in different geographical areas. The cloud management platform includes: A receiving module, configured to receive the configuration information of the branch network sent by the tenant through a network creation interface, wherein the configuration information is used to indicate a first access point and a second access point selected by the tenant from the plurality of access points for building the branch network; a creation module, configured to create a first virtual gateway of the tenant in a first physical gateway of the first access point based on the configuration information, and to create a second virtual gateway of the tenant in a second physical gateway of the second access point; A construction module, configured to construct the branch network between the first virtual gateway and the second virtual gateway; The first virtual gateway is used for the first cluster of the tenant to access the branch network, and the second virtual gateway is used for the second cluster of the tenant to access the branch network. The first cluster and the second cluster both include multiple physical servers. The first cluster is located in a first geographical area where the first access point is located, and the second cluster is located in a second geographical area where the second access point is located.
10. The cloud management platform according to claim 9, characterized in that: The configuration information includes an identifier of the branch network, an identifier of the first access point, and an identifier of the second access point; The identification of the branch network includes the identification number ID of the branch network and the structure of the branch network; The identifier of the first access point includes the ID of the first geographical area, the ID of the first virtual gateway and the ID of the first access point; The identifier of the second access point includes the ID of the second geographical area, the ID of the second virtual gateway, and the ID of the second access point.
11. The cloud management platform according to claim 10, characterized in that: The construction module is used to construct a communication connection between the first virtual gateway and the second virtual gateway to obtain the branch network.
12. The cloud management platform according to claim 10, characterized in that: The structure of the branch network is a mesh structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the construction module is used to construct a communication connection between the first virtual gateway, the second virtual gateway and the third virtual gateway of the third access point, so as to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.
13. The cloud management platform according to claim 10, characterized in that: The structure of the branch network is a hybrid structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the construction module is used to construct a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the second virtual gateway and a third virtual gateway of the third access point, so as to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.
14. The cloud management platform according to claim 10, characterized in that: The structure of the branch network is a star structure, the configuration information is further used to indicate a third access point for constructing the branch network, and the construction module is used to construct a communication connection between the first virtual gateway and the second virtual gateway, and a communication connection between the first virtual gateway and a third virtual gateway of the third access point, so as to obtain the branch network; The third virtual gateway is used for providing access to the branch network for a third cluster of the tenant, the third cluster includes a plurality of physical servers, and the third cluster is located in a third geographical area where the third access point is located.
15. The cloud management platform according to any one of claims 11 to 14, characterized in that: The communication connection is realized based on the cloud backbone network.
16. The cloud management platform according to any one of claims 9 to 15, characterized in that: The first access point and the second access point are any one of the following: a region, an availability zone, a data center, and a computer room.
17. A computing device cluster, characterized in that: The computing device cluster includes at least one computing device, each computing device including a processor and a memory: The memory is used to store instructions; The processor is configured to cause the computing device cluster to execute the method according to any one of claims 1 to 8 according to the instructions.
18. A computer storage medium, characterized in that: The computer storage medium stores one or more instructions, which, when executed by one or more computers, enable the one or more computers to implement the method of any one of claims 1 to 8.
19. A computer program product, characterized in that The computer program product stores instructions, which, when executed by a computer, enable the computer to implement the method according to any one of claims 1 to 8.
Citation Information
Cited By
Network creation method based on cloud management platform and cloud management platform
WO2025131033A1