Volume resource relationship creation method, storage cluster, equipment, medium and product
By restricting remote replication to tenant-related resources, the method ensures secure data isolation and privacy in multi-tenant storage systems, addressing the issue of unauthorized access and enhancing data security.
Patent Information
- Application Number
- CN202510457437.6
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-04-11
- Publication Date
- 2025-07-15
AI Technical Summary
The prior art cannot achieve data isolation between tenants and tenants between clusters when creating remote replication relationships, which poses data security risks, which may lead to illegal access or synchronization of tenants' data.
By displaying the remote cluster list and the remote volume resource list, only the volume resources that have a tenant relationship with the first tenant user are displayed, and a remote replication relationship is established in response to the user's selection operation, ensuring that only the volume resources that meet the tenant relationship are displayed and copied.
It realizes data isolation between tenants, reduces the possibility of data being illegally accessed, guarantees data security and privacy, and meets the requirements for data security and privacy.
Smart Images

Figure CN120320993A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the technical field of data storage and management, and particularly to a method for creating a volume resource relationship, a storage cluster, a device, a medium, and a product. Background Art
[0002] In the technical field of data storage and management, the multi-tenant architecture has gradually become the mainstream. It enables the storage services of a cluster to provide services for one or more tenants and realizes resource isolation between tenants. Taking Cluster A as an example, after creating Tenant a and Tenant b, when creating Volume Resource 1 (Vdisk1) for Tenant a, Vdisk1 has the exclusive attributes of Tenant a. For Tenant b, Vdisk1 is invisible and inaccessible, which effectively prevents unauthorized use of resources between tenants.
[0003] However, in the prior art when creating a remote replication relationship, once Cluster A and Cluster B establish a partnership, the volumes in Cluster A can see all the volumes in Cluster B across the cluster, and can create remote replication relationships with all the volumes having the same capacity in Cluster B and perform data synchronization. This results in the inability to achieve data isolation between tenants across clusters, posing a data security risk, and may cause tenant data to be illegally accessed or synchronized, unable to meet application scenarios with high requirements for data security and privacy. Summary of the Invention
[0004] This application provides a method for creating a volume resource relationship, a storage cluster, a device, a medium, and a product, to at least solve the problem in the related art that data isolation between tenants across clusters cannot be achieved when creating a remote replication relationship.
[0005] This application provides a method for creating a volume resource relationship, which is applied to a first storage cluster and includes:
[0006] In response to a remote replication relationship creation operation input by a first tenant user of the first storage cluster for a first volume resource, presenting a list of remote clusters;
[0007] In response to a selection operation by the first tenant user for a second storage cluster in the list of remote clusters, presenting a list of remote volume resources, where the list of remote volume resources consists of volume resources created by tenant users having a tenant relationship with the first tenant user;
[0008] In response to a selection operation by the first tenant user for a second volume resource in the list of remote volume resources, establishing a remote replication relationship between the first volume resource and the second volume resource.
[0009] This application also provides a first storage cluster, including:
[0010] A remote cluster display module, which is used to respond to a remote replication relationship creation operation input by a first tenant user of a storage cluster for a first volume resource, and display a list of remote clusters;
[0011] A remote volume resource display module, which is used to respond to a selection operation of a second storage cluster in the remote cluster list by the first tenant user, and display a list of remote volume resources. The list of remote volume resources consists of volume resources created by tenant users who have a tenant relationship with the first tenant user;
[0012] A relationship creation module, which is used to respond to a selection operation of a second volume resource in the remote volume resource list by the first tenant user, and establish a remote replication relationship between the first volume resource and the second volume resource.
[0013] This application also provides an electronic device, including: a memory for storing a computer program; a processor for implementing the steps of any of the above-mentioned volume resource relationship creation methods when executing the computer program.
[0014] This application also provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the steps of any of the above-mentioned volume resource relationship creation methods are implemented.
[0015] This application also provides a computer program product, including a computer program. When the computer program is executed by a processor, the steps of any of the above-mentioned volume resource relationship creation methods are implemented.
[0016] In this application, when a first tenant user of a first storage cluster performs a remote replication relationship creation operation, a list of remote clusters is displayed in response to the operation, which avoids the first tenant user randomly accessing other irrelevant clusters from the source, reduces the possibility of data being illegally accessed, and guarantees the security of tenant data to a certain extent. After the first tenant user selects a remote cluster, the displayed list of remote volume resources consists of volume resources created by tenant users who have a tenant relationship with the first tenant user. This method realizes the isolation of data between tenants, because only volume resources that meet the tenant relationship conditions will be displayed, thus avoiding the risk of tenant data being illegally accessed and meeting the requirements for data security and privacy. Based on the process of establishing a remote replication relationship under the clear operation of the user and within the limit of the tenant relationship, it is ensured that the data replication operation is carried out within a safe and legal range, further preventing unauthorized data synchronization behavior and guaranteeing the security and privacy of data. BRIEF DESCRIPTION OF THE DRAWINGS
[0017] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the accompanying drawings required in the embodiments. Obviously, the accompanying drawings in the following description are only some embodiments of the present application. For those of ordinary skill in the art, without creative efforts, other accompanying drawings can also be obtained based on these drawings.
[0018] Figure 1 It is a schematic flowchart of a method for creating a volume resource relationship provided by an embodiment of the present application;
[0019] Figure 2 It is a timing diagram of a method for creating a volume resource relationship provided by an embodiment of the present application;
[0020] Figure 3 It is a schematic structural diagram of a storage cluster provided by an embodiment of the present application;
[0021] Figure 4 It is a schematic structural diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners
[0022] The following will clearly and completely describe the technical solutions in the embodiments of the present application with reference to the accompanying drawings in the embodiments of the present application. Obviously, the described embodiments are only some embodiments of the present application, rather than all embodiments. Based on the embodiments in the present application, all other embodiments obtained by those of ordinary skill in the art without creative efforts belong to the protection scope of the present application.
[0023] It should be noted that in the description of the present application, the terms "include", "comprise" or any other variant thereof are intended to cover non-exclusive inclusion, so that a process, method, article or device including a series of elements not only includes those elements, but also includes other elements not explicitly listed, or further includes elements inherent to such process, method, article or device. The terms "first", "second", etc. in the present application are used to distinguish similar objects, rather than to describe a specific order or sequence.
[0024] To more clearly illustrate the embodiments of the present application, the following will briefly introduce the technical terms required in the embodiments:
[0025] In the storage data backup function, a cluster refers to one or more storage devices that form a relatively large computer service system using a high-speed communication network, and they provide storage services to users as a whole.
[0026] A partnership is an inter-cluster relationship formed by two or more clusters through a high-speed communication network, usually used to create inter-cluster remote replication relationships, active-active between clusters, etc. to provide disaster recovery replication services externally.
[0027] In the storage data backup function, a remote cluster refers to another cluster that has formed a partnership with the local cluster.
[0028] A tenant is a collection of various accessible resources in a cluster, and the resources in the collection are limited to being used by users belonging to that tenant.
[0029] A tenant user is a consumption entity with authentication information. After the user is created, it can be used for tenant binding and create corresponding resources such as volumes and snapshots. The volumes created based on this tenant are only visible after the user corresponding to this tenant logs in and are invisible to users of other tenants.
[0030] A tenant pair is a relationship between tenants created by the tenants between two clusters that have already formed a partnership.
[0031] A super user is a consumption entity with authentication information. It is the user created by default after the system is created. This user is the system administrator and can manage all resources in the system, including tenant resources, user resources, volume resources, etc.
[0032] Volume resources (Vdisk) are mapped to the host as disks for use.
[0033] A remote replication relationship is a replication relationship created by the volumes between two clusters that have already formed a partnership, providing data replication services externally.
[0034] The primary volume of the remote replication relationship: In the remote replication relationship, it is the source volume for data replication, and data is read from this volume.
[0035] The secondary volume of the remote replication relationship: In the remote replication relationship, it is the target volume for data replication, and the data read from the primary volume of the remote replication relationship is written to this volume.
[0036] To enable those skilled in the art of this technology to better understand the solution of this application, the following further detailed description of this application will be given in combination with the accompanying drawings and specific implementation manners.
[0037] Combined with the specific application environment architecture or specific hardware architecture on which the execution of the method for creating the volume resource relationship depends, the specific application environment architecture or specific hardware architecture will be described here.
[0038] The specific application environment architecture consists of a first storage cluster, a second storage cluster, and a management control module.
[0039] Among them, the first storage cluster: is the source that initiates the creation operation of the remote replication relationship and stores the first volume resources of the first tenant user. It has the ability to communicate with the management control module, can receive and respond to the operation instructions of the first tenant user, and transfer these operation information to the management control module.
[0040] The second storage cluster: serves as the target cluster of the remote replication relationship and stores the second volume resources created by the tenant users who have a tenant relationship with the first tenant user. It can interact with the management control module and receive the instructions of the management control module regarding resource display and relationship establishment.
[0041] The management control module: is the core of the entire architecture and is responsible for coordinating the interaction between the first storage cluster and the second storage cluster. It stores the tenant relationship information, filters and provides the first storage cluster with a list of remote clusters and a list of remote volume resources that can be displayed based on this information. At the same time, after the first tenant user completes the selection operation, it controls the first storage cluster and the second storage cluster to establish a remote replication relationship.
[0042] The specific hardware architecture includes storage devices, servers, and network devices.
[0043] Among them, storage devices: Both the first storage cluster and the second storage cluster are equipped with high-performance storage devices, such as disk arrays, solid-state drives (Solid State Disk, SSD), etc., for storing volume resource data. These storage devices have the characteristics of high capacity, high read and write speed, and high reliability to meet the data storage needs of tenants.
[0044] Servers: In each storage cluster, the servers are responsible for managing the storage devices and processing user requests. The servers have powerful computing capabilities and memory to ensure that they can quickly respond to the operation of the first tenant user and efficiently process tasks such as data display and relationship establishment.
[0045] Network devices: Include switches, routers, etc., and are used to connect the first storage cluster, the second storage cluster, and the management control module. The network devices need to have high-speed and stable transmission capabilities to ensure the fast and accurate transmission of data between different clusters and modules and ensure the smooth progress of the remote replication relationship creation process.
[0046] The embodiments of the present application provide a method for creating a volume resource relationship. Combining the execution process of the method for creating a volume resource relationship, the method is described in detail. The method for creating a volume resource relationship mainly includes the following steps S101 to S103:
[0047] S101. In response to the remote replication relationship creation operation input by the first tenant user of the first storage cluster for the first volume resource, display the list of remote clusters.
[0048] The first tenant user is the user who logs in to the first tenant on the first storage cluster. The first volume resource is the volume resource created by the first tenant user. The list of remote clusters consists of storage clusters that have a partnership with the first storage cluster, including the second storage cluster.
[0049] S102. In response to the selection operation of the second storage cluster in the list of remote clusters by the first tenant user, display the list of remote volume resources.
[0050] The list of remote volume resources consists of volume resources created by tenant users who have a tenant relationship with the first tenant user, including the second volume resource. When the first tenant user selects the second storage cluster, the list of remote volume resources is composed of volume resources on the second storage cluster that have a tenant relationship with the first tenant. For example, if the second tenant on the second storage cluster has established a tenant relationship with the first tenant on the first storage cluster, the volume resources of the second tenant will be displayed in the list of remote volume resources.
[0051] After the first tenant user selects a remote cluster (such as the second storage cluster), the list of remote volume resources displayed by the system consists of volume resources created by tenant users who have a tenant relationship with the first tenant user. This means that the first tenant user can only see the volume resources created by other tenants who have a specific tenant relationship with themselves, and cannot see the volume resources of tenants without a tenant relationship. This method realizes the isolation of data between tenants because only volume resources that meet the tenant relationship conditions will be displayed, thus avoiding the risk of illegal access to tenant data and meeting the requirements for data security and privacy.
[0052] S103. In response to the selection operation of the second volume resource in the list of remote volume resources by the first tenant user, establish a remote replication relationship between the first volume resource and the second volume resource.
[0053] The first tenant user selects the second volume resource in the list of remote volume resources to create a remote replication relationship. In response to this selection operation, establish a remote replication relationship between the first volume resource on the first storage cluster and the second volume resource on the second storage cluster.
[0054] After the first tenant user has successively completed the selection of the remote cluster (selecting the second storage cluster) and the selection of the remote volume resource (selecting the second volume resource), a remote replication relationship is established between the first volume resource and the second volume resource. This process of establishing a remote replication relationship based on the user's explicit operation and within the limits of the tenant relationship ensures that the data replication operation is carried out within a safe and legal scope, further preventing unauthorized data synchronization behavior and guaranteeing the security and privacy of data.
[0055] Based on the established tenant relationship, the first tenant user selects to create a remote replication relationship between the first volume resource and the second volume resource. This means that the remote replication relationship between volume resources is established on the basis of a specific tenant relationship, rather than randomly establishing a relationship with any volume of the same capacity in other clusters, thus effectively avoiding the situation of illegal access or synchronization of data of other tenants and realizing data isolation between tenants in different clusters.
[0056] The above steps realize data isolation between tenants in different clusters by restricting the display of volume resources based on the tenant relationship and standardizing the process of establishing the remote replication relationship, effectively reducing the data security risk and meeting the requirements of application scenarios with high requirements for data security and privacy.
[0057] In some embodiments, before executing step S101, the following steps S201 to S203 are further included:
[0058] S201. In response to the partnership creation operation input by the first administrator user of the first storage cluster, display a list of clusters to be associated.
[0059] Among them, the first administrator user is the system administrator user of the first storage cluster. The list of clusters to be associated includes storage clusters that can establish a partnership with the first storage cluster.
[0060] S202. In response to the selection operation of the first administrator user on at least one storage cluster in the list of clusters to be associated, establish a partnership between the first storage cluster and at least one storage cluster.
[0061] Exemplarily, the first administrator user selects the second storage cluster from the list of clusters to be associated. In response to this selection operation, the first storage cluster sends a partnership creation request to the second storage cluster, and identity authentication and authorization are carried out between the clusters. After passing the identity authentication, select and configure an appropriate inter-cluster communication protocol. Then, add the relevant information of the second storage cluster to the management system of the first storage cluster, and at the same time, the second storage cluster also makes corresponding configurations in the management system. After completing the above configurations, perform a connectivity test and function verification to check whether the two storage clusters can communicate normally until the partnership between the two storage clusters can be established stably and reliably.
[0062] In the above embodiments, the administrator user creates the partnership between storage clusters, realizes the communication and cooperation between storage clusters, ensures the system security, facilitates the management and maintenance of storage clusters, and also ensures the availability and reliability of the partnership.
[0063] In some embodiments, before step S201, it further includes: creating a first tenant in response to the tenant creation operation of the first administrator user of the first storage cluster.
[0064] As Figure 2 shown, the first storage cluster creates at least one tenant in response to the tenant creation operation of the first administrator user. It can be understood that the present application does not limit the specific number of the first tenant. For example, the first tenant may include TenantA-1, TenantA-2, and TenantA-3. At the same time, on the side of the second storage cluster, at least one tenant is created in response to the tenant creation operation of the second administrator user. The specific number of the second tenant is not specifically limited either. For example, the second tenant includes TenantB-1, TenantB-2, and TenantB-3.
[0065] For the convenience of explanation, hereinafter, the first storage cluster will be used as the local cluster and the second storage cluster will be used as the remote cluster to illustrate the method for creating the volume resource relationship provided by the present application.
[0066] S203. In response to the tenant relationship creation operation input by the first administrator user for the first tenant, display a list of tenants to be associated.
[0067] Among them, the list of tenants to be associated is composed of the tenants of the storage cluster (such as the second storage cluster) that has a partnership with the first storage cluster.
[0068] In some embodiments, the list of tenants to be associated contains the tenants for which the tenant relationship has not been created. Exemplarily, for the first storage cluster, the tenants for which the tenant relationship has been established on the second storage cluster are invisible. Assume that TenantB-1 among the multiple tenants on the second storage cluster has already created a tenant relationship with the tenants on other clusters. The list of tenants to be associated includes TenantB-2 and TenantB-3.
[0069] S204. In response to the selection operation of the first management user for the second tenant in the list of tenants to be associated, establish a tenant relationship between the first tenant and the second tenant.
[0070] After the partnership between the first storage cluster and the second storage cluster is created, in response to the selection operation of the first administrator user to select the second tenant from the list of tenants to be associated, create a tenant relationship between the first tenant and the second tenant.
[0071] AsFigure 2 As shown, the first administrator user can specify that a first tenant on the first storage cluster establishes a tenant relationship with a tenant on the second storage cluster. At the request of the first administrator user, the second tenant is selected from the displayed list of tenants to be associated, and a tenant relationship between the first tenant and the second tenant is created.
[0072] In the above embodiment, the first storage cluster can query and display the information of the tenants to be associated on the second storage cluster, which is convenient for the administrator to select, so that a tenant relationship can be created between the first tenant and the second tenant in a targeted manner, improving the accuracy and efficiency of the association. The tenants with established tenant relationships on the second storage cluster are invisible to the first storage cluster, which further strengthens the data isolation between tenants, prevents information leakage and interference between different tenant relationships, and improves the data security of the entire system.
[0073] In some embodiments, when performing step S204, in response to the selection operation of the first administrator user on the second tenant in the list of tenants to be associated, first add a data structure related to the tenant relationship, and then determine that the remote tenant identifier in the data structure is the identifier of the second tenant, and the remote cluster identifier is the identifier of the storage cluster to which the second tenant belongs; further, create a tenant relationship between the first tenant and the second tenant, and determine that the local tenant identifier in the data structure is the identifier of the first tenant, and determine the tenant relationship identifier.
[0074] Specifically, when creating a tenant relationship between the first tenant and the second tenant on the first storage cluster and the second storage cluster, at the Cluster System Management (CSM) end, add a data structure related to the tenant relationship, including the local tenant identifier, the remote tenant identifier, the remote cluster identifier, and the tenant relationship identifier; the tenant relationship identifier (partner_ref) represents the tenant relationship ID corresponding to a certain tenant relationship on another cluster; the local tenant identifier (local_tenant_id) represents the local tenant of a certain tenant relationship; the remote tenant identifier (remote_tenant_id) represents the remote tenant of a certain tenant relationship; the remote cluster identifier (remote_cluster_id) represents the peer cluster of a certain tenant relationship.
[0075] Exemplarily, assume that the selection operation of the first administrator user indicates that the first tenant is the local tenant TenantA-1 and the second tenant is the remote tenant TenantB-2. After creating the tenant relationship on the first storage cluster A, the data structure related to the tenant relationship contains the fields shown in Table 1.
[0076] Table 1
[0077] Field Tenant relationship identifier partner_ref 2 Local tenant identifier local_tenant_id ID1 Remote tenant identifier remote_tenant_id ID2 Remote cluster identifier remote_cluster_id B
[0078] Correspondingly, after creating the tenant relationship, on the second storage cluster B, the data structure related to the tenant relationship includes the fields shown in Table 2.
[0079] Table 2
[0080] Field Tenant relationship identifier partner_ref 1 Local tenant identifier local_tenant_id ID2 Remote tenant identifier remote_tenant_id ID1 Remote cluster identifier remote_cluster_id A
[0081] In the above embodiments, by adding a data structure related to the tenant relationship, a standardized storage and management framework is provided for subsequent operations, ensuring the consistency and integrity of tenant relationship data. This can avoid data chaos and inconsistency, improve the quality and reliability of data, and facilitate the system to uniformly manage and maintain tenant relationships. The remote cluster identifier, remote tenant identifier, local tenant identifier, and tenant relationship identifier in the data structure can accurately identify the clusters and tenants involved in different tenant relationships, realizing the precise association of the relationship between the first tenant and the second tenant. This helps the system quickly and accurately locate and query relevant tenant relationship information, providing an accurate basis for subsequent operations such as resource allocation and data access control. The above embodiments clarify the operation process of creating a tenant relationship, first determining the relevant identifiers and then creating the relationship, making the whole process logical and the steps clear. This not only facilitates the operation of the administrator, reduces the complexity and error probability of the operation, but also is conducive to the system to monitor and manage the operation process, improving the maintainability and stability of the system.
[0082] To create a tenant relationship between the first tenant TenantA-1 and the second tenant TenantB-2, the tenant relationship can be named tenant_pair_AB.
[0083] In some embodiments, after the execution of step S204, when the creation of the tenant relationship is completed, the visible permission of the tenant relationship is opened to the first administrator user and the first tenant user, the tenant users of the second tenant, and the second administrator user of the second tenant storage cluster. And, the visible permission of the tenant relationship for other administrator users and other tenant users is closed, where other administrator users are administrator users other than the first administrator user and the second administrator user, and other tenants are tenant users other than the first tenant user and the tenant users of the second tenant.
[0084] It can be understood that the visible permission of the tenant relationship is opened to the first administrator user, the second administrator user, the first tenant user, and the second tenant user. The visible permission of the tenant relationship for other administrator users other than the first administrator user and the second administrator user, and other tenant users other than the first tenant user and the second tenant user is closed.
[0085] The first tenant user is the user who logs in to the first tenant on the first storage cluster and can be represented as user_A_T_1. The second tenant user is the user who logs in to the second tenant on the second storage cluster and can be represented as user_B_T_2.
[0086] After the tenant relationship tenant_pair_AB is created, only the first administrator user and the first tenant user user_A_T_1 on the first storage cluster A, and the second administrator user and the second tenant user user_B_T_2 on the second storage cluster B can see the tenant relationship tenant_pair_AB. Other tenant users on the first storage cluster A and the second storage cluster B cannot see this tenant relationship tenant_pair_AB. The administrator users and tenant users of other storage clusters also cannot see this tenant relationship tenant_pair_AB.
[0087] In the above embodiments, by precisely setting the visible permissions of different user roles for the tenant relationship, it is ensured that only the administrator users (the first administrator user and the second administrator user) and tenant users (the first tenant user and the second tenant user) related to a specific tenant relationship can view the tenant relationship information. This avoids unnecessary access to the tenant relationship by irrelevant personnel, improves the confidentiality and security of information. Closing the visible permissions of other administrator users and other tenant users realizes data isolation between different tenant relationships. It prevents the leakage of information among unrelated user groups, protects the privacy and business secrets of tenants, and maintains the integrity and accuracy of data in the system. Opening the visible permissions for relevant users (the first administrator user, the second administrator user, the first tenant user, and the second tenant user) facilitates them to quickly obtain tenant relationship information when needed for corresponding management and operations, improving work efficiency and the usability of the system. At the same time, restricting access by other users reduces the waste of system resources and optimizes system performance.
[0088] In some embodiments, after executing step S204, in response to the login operation of the first tenant, the first tenant user is determined; in response to the volume resource creation operation of the first tenant user, the volume resource corresponding to the first tenant is created.
[0089] Storage cluster users include administrator users and tenant users. As Figure 2As shown, the first tenant user user_A_T_1 can operate to create at least one volume resource, which includes the first volume resource (VdiskA_T_1). The first volume resource has tenant attributes corresponding to the first tenant TenantA-1. At the same time, the second tenant user user_B_T_2 can operate to create at least one volume resource, which includes the second volume resource (VdiskB_T_2). The second volume resource has tenant attributes corresponding to the second tenant TenantB-2.
[0090] In this application, tenants are created by the administrator user, and volume resources are created by the tenant users. This ensures clear operation permissions and responsibilities, further ensuring that only authorized users can operate within the scope of the corresponding tenant, enhancing data security and isolation.
[0091] In some embodiments, based on the tenant relationship between the first tenant and the second tenant, the visibility permission of the second tenant user to the volume resources of the first tenant is opened. Correspondingly, on the side of the second storage cluster, based on this tenant relationship, the visibility permission of the first tenant user to the volume resources of the second tenant is opened.
[0092] Therefore, the first tenant user can see all the volume resources with the tenant attribute of the first tenant on the first storage cluster, and based on the tenant relationship between the first tenant and the second tenant, the first tenant user can also see the volume resources of the second tenant. Correspondingly, the second tenant user can see all the volume resources with the tenant attribute of the second tenant on the second storage cluster, and can also see the volume resources of the first tenant based on the created tenant relationship.
[0093] Exemplarily, the first tenant user user_A_T_1 of the first tenant TenantA-1 can see the volume resources with the tenant attribute of the first tenant on the first storage cluster A, such as the first volume resource VdiskA_T_1, and the volume resources of the second tenant TenantB-2 with the tenant relationship tenant_pair_AB, such as the second volume resource VdiskB_T_2.
[0094] In the above embodiments, by opening the visibility of the first tenant's volume resources to the second tenant user and the visibility of the second tenant's volume resources to the first tenant user, cross-cluster volume resource sharing is achieved based on the tenant relationship. This enables different tenants to access each other's volume resources under certain conditions, promotes resource interaction and collaborative use, helps improve resource utilization, and meets the complex business requirements in a multi-tenant environment. This setting of resource visibility enhances business flexibility. Users of different tenants can conveniently access each other's volume resources according to actual business needs, thus being able to cooperate more flexibly, share data, or collaborate. Setting the visibility of volume resources based on the tenant relationship between two storage clusters helps break down the resource barriers between clusters, improve the integrity and coordination of the entire system. It enables each tenant and storage cluster in the system to work better together, forming an organic whole, enhancing the overall performance and service quality of the system, and providing more powerful support for complex business scenarios in a multi-tenant environment.
[0095] In some embodiments, when performing step S102, in response to the selection operation of the second storage cluster in the remote cluster list by the first tenant user, based on the tenant relationship between the first tenant and the second tenant, the volume resources to be associated with the second tenant are queried to display the remote resource list. Among them, the volume resources to be associated with the second tenant are the volume resources for which no remote replication relationship has been created. The volume resources of the second tenant for which a remote replication relationship has been established are invisible to the first tenant.
[0096] In some embodiments, when performing step S103, in response to the selection operation of the second volume resource in the remote volume resource list by the first tenant user, a remote replication relationship is established between the first volume resource and the second volume resource. Among them, the first volume resource and the second volume resource have the same capacity. It can be understood that the first tenant user designates the first volume resource and the second volume resource with the same capacity to create a remote replication relationship based on the tenant relationship.
[0097] Exemplarily, as Figure 2 shown, the first tenant user user_A_T_1 can select the second volume resource VdiskB_T_2 from the remote volume resource list. The first volume resource VdiskA_T_1 and the second volume resource VdiskB_T_2 have the same capacity. A remote replication relationship (rcrel_AB) is created between the first volume resource VdiskA_T_1 and the second volume resource VdiskB_T_2.
[0098] In the above embodiments, it is possible to accurately view the resources to be associated with the second tenant based on the tenant relationship, and select a second volume resource with the same capacity as the first volume resource to create a remote replication relationship, ensuring the accuracy and rationality of establishing the replication relationship, ensuring that data replication is carried out between appropriate resources, and avoiding problems that may be caused by resource mismatch. Selecting and replicating resources according to the tenant relationship helps to rationally utilize the resources in the system. It avoids waste or overuse of resources, enabling resources to be effectively allocated and shared among different tenants according to actual needs, and improving the resource utilization efficiency of the entire system. Responding to the selection operation of the first tenant user to execute the entire process makes the operation have a clear trigger mechanism and a standardized process.
[0099] In some embodiments, after creating a remote replication relationship between the first volume resource and the second volume resource, it further includes: opening the visibility permission of the remote replication relationship to the first management user of the first storage cluster, the second administrator user of the second storage cluster, the first tenant user, and the second tenant user corresponding to the second volume resource; and closing the visibility permission of the remote replication relationship to other administrator users and other tenant users; where other administrator users are administrator users other than the first administrator user and the second administrator user, and other tenant users are tenant users other than the first tenant user and the second tenant user.
[0100] It can be understood that the visibility permission of the first administrator user, the second administrator user, the first tenant user, and the second tenant user to the remote replication relationship is opened. And the visibility permission of other administrator users other than the first administrator user and the second administrator user, and other tenant users other than the first tenant user and the second tenant user to the remote replication relationship is closed.
[0101] After the remote replication relationship rcrel_AB is created, only the first administrator user and the first tenant user user_A_T_1 of the first storage cluster A, and the second administrator user and the second tenant user user_B_T_2 of the second storage cluster B can see this remote replication relationship rcrel_AB based on the tenant relationship tenant_pair_AB. Other tenant users on the first storage cluster A and the second storage cluster B cannot see this remote replication relationship rcrel_AB. Administrator users and tenant users of other clusters also cannot see this remote replication relationship rcrel_AB.
[0102] In the above embodiments, it is clearly stipulated that only the first administrator user, the second administrator user, the first tenant user, and the second tenant user can view the remote replication relationship between the first volume resource and the second volume resource, ensuring that the information related to this replication relationship is only visible within a specific user scope, achieving precise access control and preventing information leakage to unauthorized personnel. Closing the visibility permissions of other administrator users and tenant users further enhances the security and isolation of the data. The data between different tenants and administrators is strictly isolated, avoiding the risk of data leakage caused by permission chaos and protecting the privacy and data security of each tenant. Relevant users can conveniently view the remote replication relationship, which helps them promptly understand the replication status and perform necessary management and maintenance operations. At the same time, restricting access by non-relevant users reduces unnecessary interference and incorrect operations, improving the convenience and efficiency of system management.
[0103] By creating a remote replication relationship based on the tenant relationship in the above steps, a data replica of the first volume resource is provided in a different location. In the event of local failures, disasters, or data loss, etc., data can be restored from the second volume resource, enhancing the data security and the disaster tolerance ability of the system and improving the business continuity.
[0104] In summary, the embodiments of the present application provide a method for creating a volume resource relationship, which generates the following
[0105] Beneficial effects:
[0106] (1) The first administrator user and the second administrator user respectively create the first tenant and the second tenant on different storage clusters, clarifying the belonging relationship between the tenant and the storage cluster where it is located. The method of first establishing the partnership between storage clusters and then establishing the tenant relationship provides a clear architecture and logical basis for subsequent operations, clearly defining the relationship between tenants on different storage clusters and laying a foundation for realizing data isolation. The entire process of creating the volume resource relationship has a clear operation sequence and responsible entity. A series of operation processes from tenant creation, tenant relationship establishment, resource creation to remote replication relationship creation and permission control make the whole process logically clear and steps explicit, facilitating system management and maintenance and reducing the complexity of operations and the possibility of errors.
[0107] (2) The first tenant user creates the first volume resource, and the second tenant user creates the second volume resource on the second storage cluster, clarifying the ownership relationship between the resource and the tenant. This ensures that the resources of each tenant are associated with a specific tenant, avoiding confusion in resource ownership and providing a prerequisite for realizing data isolation. It realizes the effective isolation of tenant-to-tenant data between storage clusters, ensuring that the data of each tenant is strictly protected, avoiding the risks of data leakage and illegal access, and improving the security and confidentiality of the data.
[0108] (3) In response to the selection operation of the first tenant user, based on the established tenant relationship, select to create a remote replication relationship between the first volume resource and the second volume resource. This operation tightly binds the remote replication relationship with the tenant relationship. Only between volume resources with a specific tenant relationship can a remote replication relationship be established, enabling resources to be reasonably allocated and shared among tenants in different storage clusters according to actual needs, improving the resource utilization efficiency. At the same time, at the data replication level, data isolation between tenants is achieved, ensuring data security and isolation, and meeting the complex business requirements in a multi-tenant environment. Because the replication relationship is established based on the tenant relationship, data of different tenants will not be confused or wrongly shared during the replication process.
[0109] (4) By opening and closing the visible permissions of different users to the tenant relationship and the remote replication relationship, data isolation is further strengthened. Only the first administrator user, the second administrator user, the first tenant user, and the second tenant user have visible permissions to the relevant relationships, and other users are restricted from accessing. This ensures that only personnel related to specific tenant relationships and remote replication relationships can obtain relevant information, preventing illegal access to data by other tenants or administrators, and achieving strict data isolation from the perspective of permission management.
[0110] Through the description of the above implementation manners, those skilled in the art can clearly understand that the method according to the above embodiments can be implemented by means of software plus a necessary general hardware platform. Of course, it can also be implemented by hardware, but in many cases, the former is a better implementation manner.
[0111] As Figure 3 shown, the embodiment of the present application provides a storage cluster, including:
[0112] A remote cluster display module 301, configured to display a list of remote clusters in response to a remote replication relationship creation operation input by a first tenant user of the storage cluster for a first volume resource;
[0113] A remote volume resource display module 302, configured to display a list of remote volume resources in response to a selection operation of the first tenant user for a second storage cluster in the list of remote clusters. The list of remote volume resources consists of volume resources created by tenant users having a tenant relationship with the first tenant user;
[0114] A relationship creation module 303, configured to establish a remote replication relationship between the first volume resource and the second volume resource in response to a selection operation of the first tenant user for a second volume resource in the list of remote volume resources.
[0115] As an optional implementation manner provided by the embodiments of the present application, the storage cluster further includes a partnership creation module, which is configured to: in response to a partnership creation operation input by a first administrator user of a first storage cluster, display a list of clusters to be associated; in response to a selection operation of at least one storage cluster in the list of clusters to be associated by the first administrator user, establish a partnership between the first storage cluster and the at least one storage cluster.
[0116] The storage cluster further includes a tenant relationship creation module, which is configured to: in response to a tenant relationship creation operation input by the first administrator user for a first tenant, display a list of tenants to be associated, where the list of tenants to be associated consists of tenants of storage clusters that have a partnership with the first storage cluster; in response to a selection operation of a second tenant in the list of tenants to be associated by the first administrator user, establish a tenant relationship between the first tenant and the second tenant.
[0117] As an optional implementation manner provided by the embodiments of the present application, the tenant relationship creation module is specifically configured to: in response to a selection operation of a second tenant in the list of tenants to be associated by the first administrator user, add a data structure related to the tenant relationship; determine that the remote tenant identifier in the data structure is the identifier of the second tenant, and the remote cluster identifier is the identifier of the storage cluster to which the second tenant belongs; establish a tenant relationship between the first tenant and the second tenant, and determine that the local tenant identifier in the data structure is the identifier of the first tenant, and determine the tenant relationship identifier.
[0118] As an optional implementation manner provided by the embodiments of the present application, the storage cluster further includes a volume resource creation module, which is configured to: in response to a login operation of a first tenant, determine the first tenant user; in response to a volume resource creation operation of the first tenant user, create a volume resource corresponding to the first tenant.
[0119] As an optional implementation manner provided by the embodiments of the present application, the storage cluster further includes a tenant relationship permission management module, which is configured to: after the tenant relationship is created, open the visible permission of the tenant relationship to the first administrator user, the first tenant user, the tenant users of the second tenant, and the second administrator user of the storage cluster to which the second tenant belongs; close the visible permission of the tenant relationship to other administrator users and other tenant users, where the other administrator users are administrator users other than the first administrator user and the second administrator user, and the other tenants are tenant users other than the first tenant user and the tenant users of the second tenant.
[0120] As an alternative implementation provided by the embodiments of the present application, the storage cluster further includes a remote replication relationship permission management module, which is used to: after the creation of the remote replication relationship is completed, open the visible permission of the remote replication relationship to the first administrator user of the first storage cluster, the second administrator user of the second storage cluster, the first tenant user, and the second tenant user corresponding to the second volume resource; close the visible permission of the remote replication relationship to other administrator users and other tenant users; where the other administrator users are administrator users other than the first administrator user and the second administrator user, and the other tenant users are tenant users other than the first tenant user and the second tenant user.
[0121] It should be noted that the structure of the second storage cluster mentioned in the embodiments of the present application is similar to that of the first storage cluster, and will not be elaborated here.
[0122] For the description of the features in the embodiments corresponding to the storage cluster, reference can be made to the relevant descriptions in the embodiments corresponding to the creation method of the volume resource relationship, and will not be elaborated one by one here.
[0123] As Figure 4 shown, the embodiments of the present application further provide an electronic device, including a memory 401 and a processor 402. A computer program is stored in the memory 401, and the processor 402 is configured to run the computer program to execute the steps in any of the above embodiments of the creation method of the volume resource relationship.
[0124] The embodiments of the present application further provide a computer-readable storage medium, in which a computer program is stored, where the computer program is configured to execute the steps in any of the above embodiments of the creation method of the volume resource relationship when running.
[0125] In an exemplary embodiment, the above computer-readable storage medium may include, but is not limited to: various media such as a USB flash drive, a read-only memory (ROM for short), a random access memory (RAM for short), a mobile hard disk, a magnetic disk, or an optical disc that can store a computer program.
[0126] The embodiments of the present application further provide a computer program product, the above computer program product includes a computer program, and the steps in any of the above embodiments of the creation method of the volume resource relationship are implemented when the computer program is executed by a processor.
[0127] The embodiments of the present application further provide another computer program product, including a non-volatile computer-readable storage medium, the non-volatile computer-readable storage medium stores a computer program, and the steps in any of the above embodiments of the creation method of the volume resource relationship are implemented when the computer program is executed by a processor.
[0128] Those skilled in the art may further realize that the units and algorithm steps of each example described in combination with the embodiments disclosed herein can be implemented by electronic hardware, computer software, or a combination of both. To clearly illustrate the interchangeability of hardware and software, the composition and steps of each example have been generally described according to functions in the above description. Whether these functions are executed in a hardware or software manner depends on the specific application and design constraints of the technical solution. Those skilled in the art can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of this application.
[0129] The above has introduced in detail a method for creating a volume resource relationship provided by this application. Specific examples are used herein to elaborate on the principle and implementation manner of this application. The description of the above embodiments is only used to help understand the method and its core idea of this application. It should be noted that for those of ordinary skill in the art in this technical field, without departing from the principle of this application, several improvements and modifications can still be made to this application, and these improvements and modifications also fall within the protection scope of the claims of this application.
Claims
1. A method for creating a volume resource relationship, characterized in that Applied to the first storage cluster, including: In response to a remote replication relationship creation operation input by a first tenant user of the first storage cluster for a first volume resource, display a list of remote clusters; In response to a selection operation by the first tenant user on a second storage cluster in the list of remote clusters, display a list of remote volume resources, where the list of remote volume resources consists of volume resources created by tenant users who have a tenant relationship with the first tenant user; In response to a selection operation by the first tenant user on a second volume resource in the list of remote volume resources, establish a remote replication relationship between the first volume resource and the second volume resource.
2. The method according to claim 1, wherein Before the step of displaying the list of remote clusters in response to a remote replication relationship creation operation input by a first tenant user of the first storage cluster for a first volume resource, the method further includes: In response to a partnership creation operation input by a first administrator user of the first storage cluster, display a list of clusters to be associated; In response to a selection operation by the first administrator user on at least one storage cluster in the list of clusters to be associated, establish a partnership between the first storage cluster and the at least one storage cluster; In response to a tenant relationship creation operation input by the first administrator user for a first tenant, display a list of tenants to be associated, where the list of tenants to be associated consists of tenants of storage clusters that have a partnership with the first storage cluster; In response to a selection operation by the first administrator user on a second tenant in the list of tenants to be associated, establish a tenant relationship between the first tenant and the second tenant.
3. The method according to claim 2, wherein The step of establishing a tenant relationship between the first tenant and the second tenant in response to a selection operation by the first administrator user on the first tenant in the list of tenants to be associated includes: In response to a selection operation by the first administrator user on a second tenant in the list of tenants to be associated, add a data structure related to the tenant relationship; Determine that the remote tenant identifier in the data structure is the identifier of the second tenant, and the remote cluster identifier is the identifier of the storage cluster to which the second tenant belongs; Establish a tenant relationship between the first tenant and the second tenant, and determine that the local tenant identifier in the data structure is the identifier of the first tenant, and determine the tenant relationship identifier.
4. The method according to claim 2, characterized in that, After the step of establishing a tenant relationship between the first tenant and the second tenant in response to a selection operation by the first administrator user on a second tenant in the list of tenants to be associated, the method further includes: In response to a login operation of the first tenant, determine the first tenant user; In response to a volume resource creation operation by the first tenant user, create a volume resource corresponding to the first tenant.
5. The method according to claim 2, wherein The method further includes: After the tenant relationship is created, open the visible permission of the tenant relationship to the first administrator user, the first tenant user, the tenant users of the second tenant, and the second administrator user of the storage cluster to which the second tenant belongs; Close the visibility permissions of the tenant relationship for other administrator users and other tenant users, where the other administrator users are administrator users other than the first administrator user and the second administrator user, and the other tenants are tenant users other than the first tenant user and the second tenant user.
6. The method according to claim 1, wherein The method further includes: After the remote replication relationship is created, open the visibility permissions of the remote replication relationship to the first administrator user of the first storage cluster, the second administrator user of the second storage cluster, the first tenant user, and the second tenant user corresponding to the second volume resource; Close the visibility permissions of the remote replication relationship for other administrator users and other tenant users; where the other administrator users are administrator users other than the first administrator user and the second administrator user, and the other tenant users are tenant users other than the first tenant user and the second tenant user.
7. A storage cluster, characterized in that, Includes: A remote cluster display module for displaying a list of remote clusters in response to a remote replication relationship creation operation input by a first tenant user of the storage cluster to a first volume resource; A remote volume resource display module for displaying a list of remote volume resources in response to a selection operation of a second storage cluster in the list of remote clusters by the first tenant user, where the list of remote volume resources consists of volume resources created by tenant users who have a tenant relationship with the first tenant user; A relationship creation module for establishing a remote replication relationship between the first volume resource and the second volume resource in response to a selection operation of a second volume resource in the list of remote volume resources by the first tenant user.
8. An electronic device, characterized in that, Includes: A memory for storing a computer program; A processor for implementing the steps of the method for creating a volume resource relationship as described in any one of claims 1 to 6 when executing the computer program.
9. A computer-readable storage medium, characterized in that, A computer program is stored in the computer-readable storage medium, where the computer program implements the steps of the method for creating a volume resource relationship as described in any one of claims 1 to 6 when executed by a processor.
10. A computer program product, comprising a computer program, characterized in that, The computer program implements the steps of the method for creating a volume resource relationship as described in any one of claims 1 to 6 when executed by a processor.