Disaster recovery methods, products, equipment, and media for cloud environment VPN services
By synchronizing the control plane data of the cloud management and backup environment in the cloud management platform, the technical problems of VPN services are solved, the disaster recovery capability of VPN services in cloud environments is achieved, the service interruption problem of VPN services in cloud environments during switching is solved, and the continuity and recovery efficiency of VPN services are ensured.
Patent Information
- Application Number
- CN202510838393.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Patents(China)
- Current Assignee / Owner
- Filing Date
- 2025-06-23
- Publication Date
- 2025-09-19
- Estimated Expiration
- 2045-06-23
AI Technical Summary
In the existing technology, when the cloud environment VPN service is switched, the gateway node cannot adapt to the change of the cloud environment address. The technical problem of the cloud environment VPN service is that the disaster recovery capability of the cloud environment VPN service is insufficient, resulting in the VPN service being unable to be used normally when the cloud management environment is switched.
By periodically synchronizing the control plane data of the cloud management primary environment in the cloud management platform to the cloud management backup environment, and initiating the disaster recovery switching process when the preset conditions are met, the primary environment services are destroyed, the backup environment services are started, and the address mapping relationship of the VPN gateway node is updated to adapt it to the new cloud management primary environment, thereby ensuring the continuity of VPN services.
This enables normal communication between the VPN gateway node and the new cloud management master environment when the cloud management environment is switched, reducing data synchronization time during switching and improving recovery efficiency and VPN service continuity.
Smart Images

Figure CN120358242B_ABST
Abstract
Description
Technical Field
[0001] The present invention relates to the technical field of cloud computing, and in particular to a disaster recovery method, product, device and medium for a cloud environment VPN service. Background Art
[0002] With the development of cloud computing, enterprises are increasingly demanding cloud VPN services. However, cloud VPN (Virtual Private Network) services—a technology that uses public networks to establish dedicated data communication networks—face numerous challenges, including network failures, data loss, and security threats. To address these challenges, cloud VPN services require robust disaster recovery capabilities to ensure service reliability and security.
[0003] When the cloud management environment is switched, the cloud management address cannot change, so the address of the cloud management platform message queue and the OVN-SBVPN gateway node also changes. The VPN gateway node will not be able to use the VPN service normally due to the change of the environment address.
[0004] It can be seen that how to make the VPN gateway node adapt to the change of the cloud management environment address when the cloud management environment switches so that VPN services can still be provided between the VPN gateway node and the new cloud management main environment is a problem that technical personnel in this field need to solve. Summary of the Invention
[0005] The purpose of the embodiments of the present invention is to provide a disaster recovery method, apparatus, device, and medium for cloud environment VPN services. When a cloud management environment switches, VPN gateway nodes can adapt to changes in the cloud management environment address, ensuring that VPN services can continue to be provided between the VPN gateway node and the new cloud management environment. The specific solution is as follows:
[0006] In a first aspect, the present invention discloses a disaster recovery method for a cloud environment VPN service, comprising:
[0007] Periodically synchronize the control plane data of the cloud management primary environment in the cloud management platform to the cloud management backup environment;
[0008] When the cloud management platform currently meets the preset cloud environment switching conditions, the disaster recovery switching process of the cloud management platform is started;
[0009] Destroy the cloud management service of the primary cloud management environment and start the cloud management service of the backup cloud management environment to switch the backup cloud management environment to the new primary cloud management environment;
[0010] Drift the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management environment, and update the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management environment;
[0011] The VPN gateway node is controlled to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set, so that VPN service is provided between the VPN gateway node and the new cloud management environment.
[0012] Optionally, the cloud environment VPN service disaster recovery method further includes:
[0013] Deploy a primary cloud management environment and a backup cloud management environment on the cloud management platform; wherein the primary cloud management environment and the backup cloud management environment have the same number of nodes, operating system, and hardware configuration;
[0014] Configure the physical address, secure shell protocol port, and login credentials of the cloud management primary environment and the cloud management backup environment.
[0015] Optionally, the cloud environment VPN service disaster recovery method further includes:
[0016] When a cloud environment switching instruction is obtained through a preset user instruction issuing interface, or when the operating status of the cloud management main environment is monitored to be abnormal, it is determined that the cloud management platform currently meets the preset cloud environment switching conditions.
[0017] Optionally, starting the cloud management service of the cloud management standby environment to switch the cloud management standby environment to a new cloud management primary environment includes:
[0018] If there are multiple cloud management standby environments, select a target cloud management standby environment from the multiple cloud management standby environments, and start the cloud management service of the target cloud management standby environment to switch the target cloud management standby environment to the new cloud management primary environment;
[0019] The target cloud management standby environment corresponds to the standby environment instruction obtained through the preset user instruction issuing interface, or the target cloud management standby environment is a cloud management standby environment selected according to the load status of each of the cloud management standby environments.
[0020] Optionally, the drifting of the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management primary environment includes:
[0021] The mapping relationship between the logical address of the message queue in the cloud management platform and the original physical address is drifted based on the physical address of the new cloud management main environment through the underlying network component of the cloud management platform; wherein, the underlying network component is any one of the load balancer, virtual router and floating logical address manager.
[0022] Optionally, the drifting of the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management primary environment by the underlying network component of the cloud management platform includes:
[0023] Through the underlying network components of the cloud management platform, the first mapping relationship between the logical address of the message queue in the cloud management platform and the physical address of the original cloud management main environment is changed to a second mapping relationship between the logical address of the message queue and the physical address of the new cloud management main environment.
[0024] Optionally, updating the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management environment includes:
[0025] Querying the currently managed VPN gateway node in the virtual switch database of the new cloud management environment; wherein the VPN gateway node includes a VPN proxy component of the Neutron virtual network;
[0026] The OVN-SB physical address set recorded in the VPN proxy component is changed to the physical address set of each management node in the new cloud management environment through the disaster recovery service in the new cloud management environment.
[0027] Optionally, controlling the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set includes:
[0028] Control the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management environment through the OVN-SB physical address set;
[0029] If the identification information of the VPN proxy component is found in the Neutron component of the new cloud management environment, the VPN gateway node is controlled to communicate with the new cloud management environment through the logical address of the message queue.
[0030] Optionally, if the identification information of the VPN proxy component is queried in the Neutron component of the new cloud management environment, controlling the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue includes:
[0031] Querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management environment;
[0032] If the identification information of the VPN proxy component exists in the Neutron component, controlling the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue;
[0033] If the identification information of the VPN proxy component does not exist in the Neutron component, the current retry count is determined. If the current retry count is less than the first preset threshold, the process jumps back to the step of querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management environment based on the delayed retry mechanism, and updates the current retry count.
[0034] Optionally, controlling the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue includes:
[0035] Control the VPN gateway node to obtain the VPN configuration information sent by the new cloud management environment through the logical address of the message queue, so that the VPN gateway node forwards the VPN configuration information to the IPsec component; wherein, the VPN configuration information is the configuration information generated by the Neutron component in the new cloud management environment.
[0036] Optionally, controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management environment through the OVN-SB physical address set includes:
[0037] Control the VPN gateway node to establish a communication link with the OVN-SB in the new cloud management environment through the OVN-SB physical address set, and control the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link.
[0038] Optionally, controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link includes:
[0039] Query whether the chassis_private table exists in the OVN-SB; wherein the chassis_private table is used to store private configuration information related to the physical host;
[0040] If the chassis_private table does not exist in the OVN-SB and the current query count is not greater than a second preset threshold, then jump back to the step of querying whether the chassis_private table exists in the OVN-SB based on a delayed retry mechanism until the current query count is greater than the second preset threshold;
[0041] If the chassis_private table exists in the OVN-SB, the communication link of the VPN proxy component in the VPN gateway node is controlled to add identification information of the VPN proxy component to the chassis_private table.
[0042] In a second aspect, the present invention discloses a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the disaster recovery method for the cloud environment VPN service disclosed above.
[0043] In a third aspect, the present invention discloses an electronic device, comprising:
[0044] Memory, used to store computer programs;
[0045] The processor is configured to execute a computer program to implement the steps of the aforementioned disclosed method for disaster recovery of a cloud environment VPN service.
[0046] In a fourth aspect, the present invention discloses a computer-readable storage medium for storing a computer program; wherein, when the computer program is executed by a processor, the steps of the disaster recovery method for the cloud environment VPN service disclosed above are implemented.
[0047] It can be seen that the present invention periodically synchronizes the control plane data of the cloud management main environment in the cloud management platform to the cloud management backup environment; when the cloud management platform currently meets the preset cloud environment switching conditions, the disaster recovery switching process of the cloud management platform is started; the cloud management service of the cloud management main environment is destroyed, and the cloud management service of the cloud management backup environment is started to switch the cloud management backup environment to the new cloud management main environment; based on the physical address of the new cloud management main environment, the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform is drifted, and based on the physical address set of each management node in the new cloud management main environment, the OVN-SB physical address set recorded in the VPN gateway node is updated; the VPN gateway node is controlled to communicate with the new cloud management main environment through the logical address of the message queue and the OVN-SB physical address set, so that VPN service is performed between the VPN gateway node and the new cloud management main environment.
[0048] The beneficial effect is that the present invention periodically synchronizes the control plane data of the cloud management master environment in the cloud management platform to the cloud management backup environment, so that the cloud management backup environment obtains the control plane data of the management master environment in advance. When the master-slave environment needs to be switched subsequently, the data synchronization time during the switch can be reduced, the recovery efficiency is improved, and the continuity of the VPN service can be guaranteed. Furthermore, if the cloud management platform currently meets the preset cloud environment switching conditions, it means that the cloud management master-slave environment needs to be switched, that is, the original cloud management backup environment becomes the new cloud management master environment. Next, it is necessary to update the address of the message queue in the cloud management platform and the OVN-SB physical address set recorded in the VPN gateway node. Specifically, the logical address of the message queue is kept unchanged, but the mapping relationship between the logical address and the physical address is changed. This makes the VPN gateway node unaware that the physical address of the message queue has changed, and the OVN-SB physical address set recorded in the VPN gateway node is updated based on the physical address set of each management node in the new cloud management environment to adapt to the control plane of the new cloud management environment. After completing the modification of the VPN gateway node configuration, the VPN gateway node can be controlled to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set, so that VPN services can be provided between the VPN gateway node and the new cloud management environment. In other words, when the cloud management environment is switched, the VPN gateway node can adapt to the changes in the cloud management environment address, so that VPN services can still be provided between the VPN gateway node and the new cloud management environment. BRIEF DESCRIPTION OF THE DRAWINGS
[0049] In order to more clearly illustrate the embodiments of the present invention, the following is a brief introduction to the drawings required for use in the embodiments. Obviously, the drawings described below are only some embodiments of the present invention. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0050] Figure 1 A flow chart of a disaster recovery method for a cloud environment VPN service provided by an embodiment of the present invention;
[0051] Figure 2 A specific VPN control plane disaster recovery architecture diagram provided by an embodiment of the present invention;
[0052] Figure 3 A schematic diagram of a specific disaster recovery switching process provided by an embodiment of the present invention;
[0053] Figure 4 A flowchart of a specific disaster recovery method for a cloud environment VPN service provided by an embodiment of the present invention;
[0054] Figure 5A schematic diagram of the structure of a disaster recovery device for a cloud environment VPN service provided by an embodiment of the present invention;
[0055] Figure 6 A structural diagram of an electronic device provided by an embodiment of the present invention. DETAILED DESCRIPTION
[0056] The following will clearly and completely describe the technical solutions in the embodiments of the present invention in conjunction with the accompanying drawings. Obviously, the described embodiments are only part of the embodiments of the present invention, not all of them. Based on the embodiments of the present invention, all other embodiments obtained by ordinary technicians in this field without making any creative efforts shall fall within the scope of protection of the present invention.
[0057] With the development of cloud computing, enterprises are increasingly demanding cloud VPN services. However, cloud VPN services face numerous challenges, including network failures, data loss, and security threats. To address these challenges, cloud VPN services require robust disaster recovery capabilities to ensure service reliability and security.
[0058] When the cloud management environment is switched, the cloud management address cannot change, so the address of the cloud management platform message queue and the OVN-SBVPN gateway node also changes. The VPN gateway node will not be able to use the VPN service normally due to the change of the environment address.
[0059] The terms "including" and "having," as used in the present description and accompanying drawings, and any variations thereof, are intended to cover non-exclusive inclusions. For example, a process, method, system, product, or apparatus comprising a series of steps or elements is not limited to the listed steps or elements and may include steps or elements that are not listed.
[0060] In order to enable those skilled in the art to better understand the present invention, the present invention will be further described in detail below with reference to the accompanying drawings and specific implementation methods.
[0061] Next, a disaster recovery solution for a cloud environment VPN service provided by an embodiment of the present invention is described in detail. Figure 1 A disaster recovery method for a cloud environment VPN service provided by an embodiment of the present invention includes:
[0062] Step S11: Periodically synchronize the control plane data of the cloud management primary environment in the cloud management platform to the cloud management backup environment.
[0063] In this embodiment, it also includes: deploying a cloud management main environment and a cloud management backup environment in the cloud management platform; wherein the number of nodes, operating system and hardware configuration of the cloud management main environment and the cloud management backup environment are the same; configuring the physical address, secure shell protocol port and login credentials of the cloud management main environment and the cloud management backup environment.
[0064] It is understandable that several cloud management environments are deployed in the cloud management platform, and the roles of each cloud management environment are set, that is, one cloud management master environment is deployed, that is, only one environment provides services to the outside world at the same time, and the remaining cloud management environments are deployed as cloud management backup environments. The number of cloud management backup environments can be deployed according to actual scenario needs, and the number of nodes, operating system and hardware configuration of the cloud management master environment and the cloud management backup environment are the same. After completing the basic network configuration and hardware configuration, it is also necessary to configure the physical address (IP), Secure Shell (SSH) port and login credentials of the cloud management master environment and the cloud management backup environment. The login credentials include the login username and password and are used to access the node and remotely execute deployment commands during the deployment process. After the disaster recovery configuration is completed, the cloud management service is deployed in the master environment, and the backup environment only deploys disaster recovery services and related basic services.
[0065] For example Figure 2The following diagram shows a specific VPN control plane disaster recovery architecture. The cloud management platform deploys a primary cloud management environment and a backup cloud management environment. Both environments include disaster recovery services (DR), a control plane, a virtual machine switch database (DB), and a message queue. The control plane includes multiple nodes, each of which includes Neutron and OVN-SB. OpenStack is an open source cloud computing infrastructure project. Neutron is the component responsible for network functions within the OpenStack project, supporting network, subnet, security groups, firewall, VPN, and other functions. Neutron-ovn-vpn-agent (the VPN agent component of the Neutron virtual network) is responsible for receiving control node configurations on compute nodes and distributing them to the IPsec component when Neutron is connected to OVN. VPN is a technology that uses public networks (such as the Internet) to establish a dedicated data communication network. VPN uses tunneling technology to create a logically dedicated channel on the public network, thereby achieving the same communication functions as a private network. IPsec is a collection of protocols and services that provide security for IP networks and is a commonly used technology in VPNs. A network is a network resource on the cloud platform. A network can have multiple subnets. A subnet is a separate network island on the cloud platform. A port is a network resource on the cloud platform. Multiple ports can be created under a subnet. A port contains IP address information, and the virtual network attached to the port can use the corresponding IP address. OVN (Open Virtual Network) is a distributed controller, primarily consisting of processes such as ovn-controller and ovn-northd that perform translation work, as well as processes such as ovn-nb-db and ovn-sb-db that provide database-server services. Each process can exist in a cluster to ensure high availability. A database is a "warehouse that organizes, stores, and manages data according to data structures." It is a collection of large amounts of data stored on a computer in an organized, shareable, and uniformly managed manner for a long period of time. It exists as a service provider in the product, providing data storage, query, update, and delete operations. Different modules may use different database types, for example, Octavia uses the mysql database, and ovn uses the ovsdb database.
[0066] Neutron-ovn-vpn-agent is a proxy service deployed on compute nodes in Neutron-OVN scenarios. It is the actual execution component that implements VPN functionality. Neutron-ovn-vpn-agent is responsible for receiving VPN configurations issued by Neutron through a message queue, distributing the configurations to IPsec, implementing VPN services through IPsec, and synchronizing the status of currently created VPN services with Neutron. In addition to interacting with Neutron, Neutron-ovn-vpn-agent also connects to the ovs-db server on the local node and OVN-SB on the control node to monitor relevant database events. As mentioned above, Neutron-ovn-vpn-agent communicates with Neutron, ovs-db, and OVN-SB based on message queues and Transmission Control Protocol (TCP) connections, respectively. Therefore, for Neutron-ovn-vpn-agent to function properly, it must know the communication addresses of the cloud management platform message queue and OVN-SB. If the cloud management platform migrates, the cloud management address will change, and the addresses of the message queue and OVN-SB will also change.
[0067] The disaster recovery architecture of the cloud management platform described above shows that the primary and backup cloud management platforms have different exposed addresses. This means that the service addresses of Neutron, OVN-SB, and the message queue on the management plane are also different. When a primary / backup switch occurs on the cloud management platform, the Neutron-ovn-vpn-agent running on the VPN gateway node cannot automatically sense and switch, resulting in unavailability of the VPN service.
[0068] The control plane data of the cloud management primary environment in the cloud management platform is periodically synchronized to the cloud management backup environment. The control plane data includes VPN configuration data and network status data. In this way, data synchronization between the cloud management primary environment and the cloud management backup environment can be completed before the cloud environment is switched, so that the cloud management backup environment can serve as the new cloud management primary environment and ensure business continuity. In addition, the backup environment periodically synchronizes control plane data from the primary environment to ensure data consistency between the primary and backup environments, and the multi-copy mechanism ensures data security.
[0069] Step S12: When the cloud management platform currently meets the preset cloud environment switching conditions, the disaster recovery switching process of the cloud management platform is started.
[0070] In this embodiment, it also includes: when a cloud environment switching instruction is obtained through a preset user instruction issuing interface, or when the operating status of the cloud management main environment is monitored to be abnormal, it is determined that the cloud management platform currently meets the preset cloud environment switching conditions.
[0071] There are two specific preset cloud environment switching conditions. The first is that when there is an abnormality in the main environment, the cloud environment is forced to switch, that is, the operating status of the cloud management main environment is periodically checked. If a service abnormality is detected, that is, it is in an abnormal state, the service is migrated to the backup environment. In other words, the preset cloud environment switching conditions are met at this time. In this case, the cloud environment switching can be completed automatically, and the VPN service can be guaranteed to operate normally; the second is to actively switch the cloud environment, and obtain the cloud environment switching instruction through the preset user instruction issuing interface. The instruction is issued by the user through the preset user instruction issuing interface. At this time, the disaster recovery switching process of the cloud management platform is actively started. In this case, the situation where the cloud environment switching cannot be performed because the operating status is normal but the business scenario requires it is avoided. After the user issues the instruction, the cloud environment switching can be actively performed.
[0072] Step S13: Destroy the cloud management service of the cloud management primary environment, and start the cloud management service of the cloud management backup environment to switch the cloud management backup environment to the new cloud management primary environment.
[0073] For example Figure 3 The diagram shows a specific disaster recovery switching process. First, the cloud management service of the cloud management primary environment is destroyed, and then the cloud management service of the cloud management backup environment is started. In this way, the cloud management backup environment is switched to the new cloud management primary environment, and the original cloud management primary environment is no longer responsible for the VPN service. The original cloud management primary environment is switched to the new cloud management backup environment.
[0074] In this embodiment, starting the cloud management service of the cloud management standby environment to switch the cloud management standby environment to the new cloud management primary environment includes: if there are multiple cloud management standby environments, selecting a target cloud management standby environment from the multiple cloud management standby environments, and starting the cloud management service of the target cloud management standby environment to switch the target cloud management standby environment to the new cloud management primary environment; wherein, the target cloud management standby environment corresponds to the standby environment instruction obtained through the preset user instruction issuing interface, or the target cloud management standby environment is a cloud management standby environment selected according to the load status of each of the cloud management standby environments.
[0075] It can be understood that if there are multiple cloud management and standby environments, then when selecting the target cloud management and standby environment from multiple cloud management and standby environments, the load status of each cloud management and standby environment can be considered, that is, a suitable target cloud management and standby environment can be selected from each cloud management and standby environment based on the load status of each cloud management and standby environment. For example, the target cloud management and standby environment is the standby environment with the smallest load, or it can be directly specified by the user, that is, the standby environment instruction obtained through the preset user instruction issuing interface carries the standby environment identification information, so that the cloud management and standby environment corresponding to the standby environment identification information is determined as the target cloud management and standby environment.
[0076] Step S14: Drift the mapping relationship between the logical address of the message queue in the cloud management platform and the original physical address based on the physical address of the new cloud management environment, and update the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management environment.
[0077] It should be noted that, for the VPN gateway node, no matter how the cloud management environment switches, the logical address of the message queue will not change. That is to say, there is no need for the VPN gateway node to perceive that the physical address of the message queue is changing. It can be understood that because of the switching of the cloud management environment, the physical address of the message queue is actually changing. Therefore, in this embodiment, the logical address of the message queue is kept unchanged, but the mapping relationship between the logical address and the physical address is changed. That is, during the switching process, there is a mapping relationship between the logical address and the physical address of the original cloud management main environment, that is, there is a mapping relationship between the logical address of the message queue and the original physical address. After the switching, the mapping relationship between the logical address of the message queue and the original physical address needs to be updated to the mapping relationship between the logical address of the message queue and the physical address of the new cloud management main environment, thereby completing the drift of the mapping relationship, and the VPN gateway node will not perceive that the physical address of the message queue is changing.
[0078] In this embodiment, the updating of the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management environment includes: querying the currently managed VPN gateway node in the virtual switch database of the new cloud management environment; wherein the VPN gateway node includes a VPN proxy component of the Neutron virtual network; and changing the OVN-SB physical address set recorded in the VPN proxy component to the physical address set of each management node in the new cloud management environment through the disaster recovery service in the new cloud management environment.
[0079] Check the VPN gateway nodes among the nodes managed by the new cloud management environment and modify the service configuration of each VPN gateway node. That is, query the virtual switch database of the new cloud management environment for the currently managed VPN gateway nodes. The VPN gateway nodes include the VPN agent component of the Neutron virtual network (i.e., Neutron-ovn-vpn-agent). The disaster recovery service in the new cloud management environment changes the OVN-SB physical address set recorded in the VPN agent component to the physical address set of each management node in the new cloud management environment.
[0080] Step S15: Control the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set, so that VPN service is performed between the VPN gateway node and the new cloud management environment.
[0081] After changing the address configuration of the message queue and the OVN-SB physical address set, start the Neutron-ovn-vpn-agent service on the VPN gateway node.
[0082] In this embodiment, controlling the VPN gateway node to communicate with the new cloud management primary environment through the logical address of the message queue and the OVN-SB physical address set includes: controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management primary environment through the OVN-SB physical address set; if the identification information of the VPN proxy component is queried in the Neutron component of the new cloud management primary environment, controlling the VPN gateway node to communicate with the new cloud management primary environment through the logical address of the message queue.
[0083] During the Neutron-ovn-vpn-agent service restart and registration process, you must first register the agent information with OVN-SB and then restart the Neutron-ovn-vpn-agent service. This allows Neutron-ovn-vpn-agent to synchronize the VPN service configuration with Neutron. The registration process involves the VPN gateway node registering the VPN agent component's identification information with OVN-SB in the new cloud management environment using the OVN-SB physical address set. If the VPN agent component's identification information can be found in the Neutron component of the new cloud management environment, registration is successful. The VPN gateway node can then be controlled to communicate with the new cloud management environment using the logical address of the message queue, completing the synchronization of the VPN service configuration with Neutron.
[0084] In this embodiment, if the identification information of the VPN proxy component is queried in the Neutron component of the new cloud management main environment, the VPN gateway node is controlled to communicate with the new cloud management main environment through the logical address of the message queue, including: querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management main environment; if the identification information of the VPN proxy component exists in the Neutron component, the VPN gateway node is controlled to communicate with the new cloud management main environment through the logical address of the message queue; if the identification information of the VPN proxy component does not exist in the Neutron component, the current number of retries is determined, and if the current number of retries is less than the first preset threshold, the process jumps again to the step of querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management main environment based on the delayed retry mechanism, and updates the current number of retries.
[0085] It is understandable that only after Neutron-ovn-vpn-agent registers with OVN-SB will Neutron have the identification information of the corresponding VPN proxy component. However, since there is a certain delay in the synchronization of the identification information of the VPN proxy component, this may cause Neutron-ovn-vpn-agent to be unable to find the identification information of the VPN proxy component when querying the VPN service associated with the current VPN-agent, resulting in the VPN service not being able to be synchronized to the current node normally. Therefore, it is necessary to query whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management environment; if the identification information of the VPN proxy component exists in the Neutron component, the VPN gateway node is controlled to communicate with the new cloud management environment through the logical address of the message queue; if the Neutron component If there is no identification information of the VPN proxy component, the current retry count is determined. If the current retry count is less than the first preset threshold, the process jumps back to the step of querying whether there is identification information of the VPN proxy component in the Neutron component of the new cloud management master environment based on the delayed retry mechanism, and updates the current retry count, that is, setting a delayed retry mechanism. If the query fails, a delayed retry is performed. The number of retries and the retry interval can be configured by the user. The default interval is 5 seconds, and 60 retries are made, that is, every 5 seconds, an attempt is made to query again whether there is identification information of the VPN proxy component in the Neutron component of the new cloud management master environment until the retry count reaches 60 times. In this way, the situation where the VPN proxy component successfully registers the Agent information to OVN-SB but the subsequent configuration information synchronization cannot be performed due to the delay in VPN service information synchronization can be avoided.
[0086] In this embodiment, controlling the VPN gateway node to communicate with the new cloud management main environment through the logical address of the message queue includes: controlling the VPN gateway node to obtain the VPN configuration information sent by the new cloud management main environment through the logical address of the message queue, so that the VPN gateway node forwards the VPN configuration information to the IPsec component; wherein, the VPN configuration information is configuration information generated by the Neutron component in the new cloud management main environment.
[0087] The process of completing configuration information synchronization by communicating with the VPN gateway node and the new cloud management environment is as follows: the new cloud management environment sends the configuration information generated by the Neutron component to the message queue, and the VPN gateway node obtains the VPN configuration information from the message queue through the logical address of the message queue. Then, the VPN gateway node converts the VPN configuration information into a target instruction that meets the preset identification requirements of the IPsec component. Next, the VPN gateway node forwards the target instruction to the IPsec component so that the IPsec component can recognize the target instruction and implement the VPN service.
[0088] In this embodiment, controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management primary environment through the OVN-SB physical address set includes: controlling the VPN gateway node to establish a communication link with the OVN-SB in the new cloud management primary environment through the OVN-SB physical address set, and controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link.
[0089] The VPN gateway node registers with the OVN-SB in the new cloud management environment: first, establish a communication connection. Specifically, after Neutron-ovn-vpn-agent obtains the updated OVN-SB physical address set, it uses the address set to try to establish a TCP connection with the OVN-SB in the new cloud management environment. Since OVN-SB is provided by multiple management nodes, Neutron-ovn-vpn-agent will try to connect to each address in the address set in turn until it successfully connects to an available OVN-SB management node, that is, it determines the current OVN-SB physical address from the OVN-SB physical address set, and controls the VPN gateway node to try to connect to the current OVN-SB. The OVN-SB management node corresponding to the physical address establishes a communication link. If the OVN-SB management node corresponding to the current OVN-SB physical address is available, the communication link is determined to be successfully established. If the OVN-SB management node corresponding to the current OVN-SB physical address is not available, the communication link is determined to have failed to be established, and a new current OVN-SB physical address is determined from the OVN-SB physical address set. The control VPN gateway node is redirected to try to establish the current communication link with the OVN-SB management node corresponding to the current OVN-SB physical address; secondly, registration is performed, specifically, the control VPN gateway node registers the identification information of the VPN proxy component to OVN-SB through the successfully established communication link.
[0090] In this embodiment, controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link includes: querying whether a chassis_private table exists in the OVN-SB; wherein the chassis_private table is used to store private configuration information related to the physical host; if the chassis_private table does not exist in the OVN-SB and the current query number is not greater than a second preset threshold, then jumping back to the step of querying whether the chassis_private table exists in the OVN-SB based on a delayed retry mechanism until the current query number is greater than the second preset threshold; if the chassis_private table exists in the OVN-SB, controlling the communication link of the VPN proxy component in the VPN gateway node to add the identification information of the VPN proxy component to the chassis_private table.
[0091] The specific process of controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link is:
[0092] 1) Check whether the chassis_private table exists in the OVN-SB; wherein the chassis_private table is used to store private configuration information related to the physical host.
[0093] 2) If the chassis_private table does not exist in the OVN-SB and the current query count is not greater than a second preset threshold, then based on a delayed retry mechanism, jump back to the step of querying whether the chassis_private table exists in the OVN-SB until the current query count is greater than the second preset threshold.
[0094] 3) If the chassis_private table exists in the OVN-SB, the communication link of the VPN agent component in the VPN gateway node is controlled to add the identification information of the VPN agent component to the chassis_private table, that is, the vpn-agent-id (that is, the identification information of the VPN agent component) is added to the table entry of the corresponding VPN gateway node in the chassis_private table.
[0095] The entries of the VPN gateway node in chassis_private are registered by the ovn-controller on the VPN gateway node. Therefore, it is possible that when Neutron-ovn-vpn-agent is registered, there is no corresponding chassis_private entry, resulting in registration failure. Therefore, for the disaster recovery environment, a delayed retry mechanism is used to register the vpn-agent. Specifically, before registration, it first checks whether there is a corresponding chassis_private entry. If not, a delayed retry is performed. The number of retries and the retry interval can be configured by the user. The default interval is 5 seconds, and 60 retries are selected.
[0096] It can be seen that the present invention periodically synchronizes the control plane data of the cloud management main environment in the cloud management platform to the cloud management backup environment; when the cloud management platform currently meets the preset cloud environment switching conditions, the disaster recovery switching process of the cloud management platform is started; the cloud management service of the cloud management main environment is destroyed, and the cloud management service of the cloud management backup environment is started to switch the cloud management backup environment to the new cloud management main environment; based on the physical address of the new cloud management main environment, the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform is drifted, and based on the physical address set of each management node in the new cloud management main environment, the OVN-SB physical address set recorded in the VPN gateway node is updated; the VPN gateway node is controlled to communicate with the new cloud management main environment through the logical address of the message queue and the OVN-SB physical address set, so that VPN service is performed between the VPN gateway node and the new cloud management main environment.
[0097] The beneficial effect is that the present invention periodically synchronizes the control plane data of the cloud management master environment in the cloud management platform to the cloud management backup environment, so that the cloud management backup environment obtains the control plane data of the management master environment in advance. When the master-slave environment needs to be switched subsequently, the data synchronization time during the switch can be reduced, the recovery efficiency is improved, and the continuity of the VPN service can be guaranteed. Furthermore, if the cloud management platform currently meets the preset cloud environment switching conditions, it means that the cloud management master-slave environment needs to be switched, that is, the original cloud management backup environment becomes the new cloud management master environment. Next, it is necessary to update the address of the message queue in the cloud management platform and the OVN-SB physical address set recorded in the VPN gateway node. Specifically, the logical address of the message queue is kept unchanged, but the mapping relationship between the logical address and the physical address is changed. This makes the VPN gateway node unaware that the physical address of the message queue has changed, and the OVN-SB physical address set recorded in the VPN gateway node is updated based on the physical address set of each management node in the new cloud management environment to adapt to the control plane of the new cloud management environment. After completing the modification of the VPN gateway node configuration, the VPN gateway node can be controlled to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set, so that VPN services can be provided between the VPN gateway node and the new cloud management environment. In other words, when the cloud management environment is switched, the VPN gateway node can adapt to the changes in the cloud management environment address, so that VPN services can still be provided between the VPN gateway node and the new cloud management environment.
[0098] See also Figure 4 This embodiment of the present invention discloses a specific disaster recovery method for a cloud environment VPN service. Compared with the previous embodiment, this embodiment further illustrates and optimizes the technical solution. It includes:
[0099] Step S21: Periodically synchronize the control plane data of the cloud management primary environment in the cloud management platform to the cloud management backup environment.
[0100] After the disaster recovery service of the cloud-managed backup environment is started, control plane data, such as VPN configuration and network status, will be periodically synchronized from the primary environment. A multi-copy mechanism is used to ensure data consistency and security, preparing for rapid switching.
[0101] Step S22: When the cloud management platform currently meets the preset cloud environment switching conditions, the disaster recovery switching process of the cloud management platform is started.
[0102] The disaster recovery service periodically checks the cloud management services of the primary environment, such as Neutron, message queues, and OVN-SB. If an abnormal state is found, such as a failure or performance bottleneck, the disaster recovery switching process is triggered. It also supports manual active switching for scenarios such as environment upgrades. Specifically, cloud environment switching instructions can be obtained through the preset user command issuance interface.
[0103] Step S23: Destroy the cloud management service of the cloud management primary environment, and start the cloud management service of the cloud management backup environment to switch the cloud management backup environment to the new cloud management primary environment.
[0104] Step S24: Drift the mapping relationship between the logical address of the message queue in the cloud management platform and the original physical address based on the physical address of the new cloud management main environment through the underlying network component of the cloud management platform; wherein the underlying network component is any one of the load balancer, virtual router and floating logical address manager.
[0105] VIP (virtual IP, i.e., logical address) serves as the logical entry point for the message queue and has two characteristics. The first is the logical address characteristic: VIP is a virtual address that is not bound to a specific physical node and is dynamically mapped to the message queue node of the current primary environment through the network layer of the cloud management platform (load balancer, virtual router, and floating logical address manager). The second is the immutability: regardless of the switch between the primary and backup environments, the VIP of the message queue remains unchanged. For example, if the VIP of the primary environment's message queue is 10.0.0.1, after switching to the backup environment, the VIP automatically drifts to the message queue node of the new primary environment, but its address 10.0.0.1 is always visible to the VPN gateway node (Neutron-ovn-vpn-agent).
[0106] In this embodiment, the mapping relationship between the logical address of the message queue in the cloud management platform and the original physical address is drifted based on the physical address of the new cloud management main environment through the underlying network component of the cloud management platform, including: changing the first mapping relationship between the logical address of the message queue in the cloud management platform and the physical address of the original cloud management main environment to the second mapping relationship between the logical address of the message queue and the physical address of the new cloud management main environment through the underlying network component of the cloud management platform.
[0107] The underlying network components of the cloud management platform change the first mapping relationship between the logical address of the message queue in the cloud management platform and the physical address of the original cloud management environment to a second mapping relationship between the logical address of the message queue and the physical address of the new cloud management environment. In this way, after the switch, the VIP points to the physical node of the message queue in the new cloud management environment, ensuring that Neutron-ovn-vpn-agent continues to receive configurations through the original VIP.
[0108] Step S25: Update the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management environment.
[0109] In the process of updating the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management environment, the logical structure of the address set remains unchanged (always representing "all management nodes"). Only the physical IP list in the set needs to be updated during the switch, and the VPN gateway nodes only need to be connected according to the "set" logic. After the standby environment is activated, the system batch modifies the configuration of the VPN gateway nodes and updates the OVN-SB address set to ["192.168.1.202", "192.168.1.203"] (new physical address list), but logically it still represents "all management nodes".
[0110] All management nodes include Neutron component-related nodes and OVN-related nodes. Among them, Neutron component-related nodes are the components responsible for network functions in the OpenStack project. They support network, subnet, security group, firewall, VPN and other functions. In the cloud management environment, Neutron-related nodes are responsible for processing and managing network-related configuration and operations. They are an important part of the management level of the cloud management platform. When configuring VPN services, Neutron sends VPN configurations to Neutron-ovn-vpn-agent through the message queue, and its related nodes participate in the management and control process of VPN services. In terms of OVN-related nodes, OVN is a distributed controller, which mainly includes processes such as ovn-controller and ovn-northd that perform translation work, as well as processes such as ovn-nb-db and ovn-sb-db that provide db-server services. Each process can exist in the form of a cluster to provide high availability. Among them, the node where ovn-sb-db is located and the nodes where related processes such as ovn-controller run are all management nodes. Neutron-ovn-vpn-agent needs to connect to the ovn-sb of the control node to monitor related database events. The control nodes where these OVN-SBs are located are part of "all management nodes".
[0111] Step S26: Control the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set, so that VPN service is provided between the VPN gateway node and the new cloud management environment.
[0112] Communication is reestablished via the logical address. The restarted Neutron-ovn-vpn-agent connects to the message queue using the original logical address. The cloud management platform's network layer has mapped the logical address to the physical address of the message queue in the new primary environment. Therefore, the agent does not need to be aware of the physical address change and can communicate directly with the Neutron components in the new primary environment. For configuration synchronization and service recovery, the agent receives VPN configurations (such as IPsec policies) issued by Neutron through the message queue, performs OVN-SB registration and Neutron data synchronization (using a timeout retry mechanism to ensure success), and ultimately restores VPN service through IPsec.
[0113] Neutron components generate configurations: In the new cloud management environment, Neutron components generate VPN configurations based on system settings and user requirements, including key information such as tunnel parameters and security policies. Configurations are distributed via message queues: Neutron components send the generated VPN configurations via the message queue's VIP. Message queues use a publish-subscribe model, ensuring reliable message delivery. VPN gateway nodes receive configurations: Neutron-ovn-vpn-agent on VPN gateway nodes receives configurations via the message queue's VIP. Because the VIP is a fixed logical address, the underlying network components map it to the new environment's message queue's physical node. This allows Neutron-ovn-vpn-agent to stably receive configurations without having to worry about physical address changes.
[0114] Configuration processing and execution: After receiving the configuration, Neutron-ovn-vpn-agent sends it to the IPsec component. IPsec establishes a secure tunnel through encryption, authentication, and other operations to implement VPN services. Registration and synchronization operations: During the startup of Neutron-ovn-vpn-agent, it will register agent information with OVN-SB and query Neutron for the associated VPN service for configuration synchronization. If the registration or query fails, a timeout retry mechanism is used to ensure successful configuration synchronization. Feedback on configuration status: After Neutron-ovn-vpn-agent completes configuration processing, it synchronizes the current VPN service status, such as connection status and configuration execution results, to Neutron through the message queue, so that the cloud management platform can monitor and manage the VPN service.
[0115] The monitoring data collection tools deployed in each VPN gateway node are used to collect various monitoring data, including real-time bandwidth, packet rate, number of concurrent connections, and node resource utilization. The node load status of each VPN gateway node is determined based on the weighted results of various monitoring data. The priority of each VPN gateway node for VPN service is determined based on the node load status of each VPN gateway node. Based on the priority, each VPN gateway node is controlled to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set. In this way, dynamic load balancing of VPN connections is achieved, effectively avoiding overloading of a single node. Through real-time monitoring and accurate load assessment, resource utilization is improved, and the overall stability, reliability, and intelligent management level of the system are enhanced, supporting efficient and flexible management of large-scale concurrent VPN connections.
[0116] The beneficial effect of this application is that, by updating the OVN-SB physical address set recorded in the VPN gateway node, it is ensured that the VPN gateway node can establish a reliable communication connection with each management node in the new cloud management environment based on the accurate physical address, laying the foundation for the subsequent Neutron-ovn-vpn-agent to register with OVN-SB and synchronize configurations; when Neutron-ovn-vpn-agent registers agent information with the chassis_private table of OVN-SB, it uses the delayed retry mechanism (default 5 seconds interval, 60 retries) to solve the registration failure problem caused by the ovn-controller's failure to create table entries in time or data synchronization delay, ensuring that the agent identity is correctly identified and recorded by OVN-SB; when querying Neutron for the associated VPN service for configuration synchronization, it first confirms the configuration by querying the agent. The agent's registration status in Neutron is verified. If it is not found due to synchronization delay, a delayed retry is triggered to ensure that Neutron can perceive the existence of the agent, so that VPN configuration information (such as IPsec policy, etc.) can be accurately delivered to Neutron-ovn-vpn-agent through the message queue. This solution uses the OVN-SB physical address set as the communication entry, the message queue as the configuration transmission channel, and combines it with a timeout retry mechanism. This solution effectively solves the configuration failure problem caused by data synchronization delay between components in the cloud management environment, realizes stable communication between the VPN gateway node and the new cloud management master environment, ensures the automatic synchronization and implementation of VPN service configuration, improves the reliability, robustness and management efficiency of the entire system, avoids errors caused by manual intervention, adapts to the dynamically changing network requirements in the cloud management environment, and ensures the continuity and stability of VPN services.
[0117] Figure 5 A schematic structural diagram of a disaster recovery device for a cloud environment VPN service provided by an embodiment of the present invention includes:
[0118] The data synchronization module 11 is used to periodically synchronize the control plane data of the cloud management primary environment in the cloud management platform to the cloud management backup environment;
[0119] The disaster recovery switching module 12 is configured to start the disaster recovery switching process of the cloud management platform when the cloud management platform currently meets the preset cloud environment switching conditions;
[0120] An environment switching module 13 is configured to destroy the cloud management service of the cloud management primary environment and start the cloud management service of the cloud management backup environment to switch the cloud management backup environment to the new cloud management primary environment;
[0121] An address updating module 14 is configured to shift the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management environment, and to update the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management environment;
[0122] The service execution module 15 is used to control the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set, so that the VPN service is performed between the VPN gateway node and the new cloud management environment.
[0123] It can be seen that the present invention periodically synchronizes the control plane data of the cloud management main environment in the cloud management platform to the cloud management backup environment; when the cloud management platform currently meets the preset cloud environment switching conditions, the disaster recovery switching process of the cloud management platform is started; the cloud management service of the cloud management main environment is destroyed, and the cloud management service of the cloud management backup environment is started to switch the cloud management backup environment to the new cloud management main environment; based on the physical address of the new cloud management main environment, the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform is drifted, and based on the physical address set of each management node in the new cloud management main environment, the OVN-SB physical address set recorded in the VPN gateway node is updated; the VPN gateway node is controlled to communicate with the new cloud management main environment through the logical address of the message queue and the OVN-SB physical address set, so that VPN service is performed between the VPN gateway node and the new cloud management main environment.
[0124] The beneficial effect is that the present invention periodically synchronizes the control plane data of the cloud management master environment in the cloud management platform to the cloud management backup environment, so that the cloud management backup environment obtains the control plane data of the management master environment in advance. When the master-slave environment needs to be switched subsequently, the data synchronization time during the switch can be reduced, the recovery efficiency is improved, and the continuity of the VPN service can be guaranteed. Furthermore, if the cloud management platform currently meets the preset cloud environment switching conditions, it means that the cloud management master-slave environment needs to be switched, that is, the original cloud management backup environment becomes the new cloud management master environment. Next, it is necessary to update the address of the message queue in the cloud management platform and the OVN-SB physical address set recorded in the VPN gateway node. Specifically, the logical address of the message queue is kept unchanged, but the mapping relationship between the logical address and the physical address is changed. This makes the VPN gateway node unaware that the physical address of the message queue has changed, and the OVN-SB physical address set recorded in the VPN gateway node is updated based on the physical address set of each management node in the new cloud management environment to adapt to the control plane of the new cloud management environment. After completing the modification of the VPN gateway node configuration, the VPN gateway node can be controlled to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set, so that VPN services can be provided between the VPN gateway node and the new cloud management environment. In other words, when the cloud management environment is switched, the VPN gateway node can adapt to the changes in the cloud management environment address, so that VPN services can still be provided between the VPN gateway node and the new cloud management environment.
[0125] Furthermore, the embodiment of the present application also discloses an electronic device, Figure 6 This is a structural diagram of an electronic device according to an exemplary embodiment. The content in the diagram cannot be considered as any limitation on the scope of use of this application. The electronic device may specifically include: at least one processor 21, at least one memory 22, a power supply 23, a communication interface 24, an input / output interface 25, and a communication bus 26. The memory 22 is used to store a computer program, which is loaded and executed by the processor 21 to implement the relevant steps in the disaster recovery method for the cloud environment VPN service disclosed in any of the aforementioned embodiments. In addition, the electronic device in this embodiment may specifically be an electronic computer.
[0126] In this embodiment, the power supply 23 is used to provide operating voltage for various hardware devices on the electronic device; the communication interface 24 can create a data transmission channel between the electronic device and external devices. The communication protocol it follows is any communication protocol that can be applied to the technical solution of this application and is not specifically limited here; the input and output interface 25 is used to obtain external input data or output data to the outside world. Its specific interface type can be selected according to specific application needs and is not specifically limited here.
[0127] In addition, the memory 22, as a carrier for resource storage, can be a read-only memory, random access memory, disk or CD, etc. The resources stored thereon can include an operating system 221, a computer program 222, etc., and the storage method can be temporary storage or permanent storage.
[0128] The operating system 221 is used to manage and control the hardware devices on the electronic device, as well as the computer program 222, which can be Windows Server, NetWare, Unix, Linux, etc. In addition to including a computer program capable of implementing the disaster recovery method for the cloud environment VPN service executed by the electronic device disclosed in any of the aforementioned embodiments, the computer program 222 may further include computer programs capable of performing other specific tasks.
[0129] Furthermore, this application discloses a computer-readable storage medium for storing a computer program. When executed by a processor, the computer program implements the aforementioned cloud environment VPN service disaster recovery method. The specific steps of this method can be found in the corresponding content disclosed in the aforementioned embodiments and will not be further described here.
[0130] Furthermore, an embodiment of the present application also discloses a computer program product, including a computer program / instruction, which, when executed by a processor, implements the steps of the disaster recovery method for the cloud environment VPN service disclosed in any of the aforementioned embodiments.
[0131] The various embodiments in this specification are described in a progressive manner, with each embodiment focusing on its differences from the other embodiments. Reference can be made to the descriptions of the identical or similar parts between the various embodiments. For the devices disclosed in the embodiments, since they correspond to the methods disclosed in the embodiments, the descriptions are relatively simple, and the relevant parts can be referred to the descriptions of the methods.
[0132] Professionals may further appreciate that the units and algorithm steps of each example described in conjunction with the embodiments disclosed herein can be implemented in electronic hardware, computer software, or a combination of the two. In order to clearly illustrate the interchangeability of hardware and software, the above description has generally described the components and steps of each example according to their functions. Whether these functions are performed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals and technicians may use different methods to implement the described functions for each specific application, but such implementation should not be considered beyond the scope of this application.
[0133] The steps of the methods or algorithms described in conjunction with the embodiments disclosed herein may be implemented directly using hardware, a software module executed by a processor, or a combination of the two. The software module may be placed in random access memory (RAM), internal memory, read-only memory (ROM), electrically programmable ROM, electrically erasable programmable ROM, registers, a hard disk, a removable disk, a CD-ROM, or any other form of storage medium known in the art.
[0134] Finally, it should be noted that, in this document, relational terms such as first and second, etc., are used only to distinguish one entity or operation from another entity or operation, and do not necessarily require or imply any actual relationship or order between these entities or operations. Moreover, the terms "comprises," "comprising," or any other variations thereof are intended to cover non-exclusive inclusion, such that a process, method, article, or device comprising a series of elements includes not only those elements, but also other elements not explicitly listed, or elements inherent to such process, method, article, or device. In the absence of further limitations, an element defined by the phrase "comprising a ..." does not exclude the presence of additional identical elements in the process, method, article, or device comprising the element.
[0135] The above is a detailed introduction to the technical solution provided by the present application. Specific examples are used herein to illustrate the principles and implementation methods of the present application. The description of the above embodiments is only used to help understand the method of the present application and its core idea. At the same time, for those skilled in the art, according to the ideas of the present application, there may be changes in the specific implementation methods and application scope. In summary, the content of this specification should not be understood as a limitation on the present application.
Claims
1. A disaster recovery method for a cloud environment VPN service, characterized in that: include: Periodically synchronize the control plane data of the cloud management primary environment in the cloud management platform to the cloud management backup environment; When the cloud management platform currently meets the preset cloud environment switching conditions, the disaster recovery switching process of the cloud management platform is started; Destroy the cloud management service of the primary cloud management environment and start the cloud management service of the backup cloud management environment to switch the backup cloud management environment to the new primary cloud management environment; Drift the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management environment, and update the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management environment; Control the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set, so as to provide VPN service between the VPN gateway node and the new cloud management environment; The updating of the OVN-SB physical address set recorded in the VPN gateway node based on the physical address set of each management node in the new cloud management environment includes: Querying the currently managed VPN gateway node in the virtual switch database of the new cloud management environment; wherein the VPN gateway node includes a VPN proxy component of the Neutron virtual network; and changing the OVN-SB physical address set recorded in the VPN proxy component to the physical address set of each management node in the new cloud management environment through the disaster recovery service in the new cloud management environment; The controlling the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set includes: Controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management environment through the OVN-SB physical address set; if the identification information of the VPN proxy component is queried in the Neutron component of the new cloud management environment, controlling the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue; The controlling the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set includes: Various monitoring data are collected using monitoring data collection tools deployed in each VPN gateway node; among them, the various monitoring data specifically include real-time bandwidth, packet rate, number of concurrent connections, and node resource utilization; the node load status of each VPN gateway node is determined based on the weighted results of various monitoring data; the priority of each VPN gateway node for VPN service is determined based on the node load status of each VPN gateway node, and based on the priority, each VPN gateway node is controlled to communicate with the new cloud management environment through the logical address of the message queue and the OVN-SB physical address set.
2. The cloud environment VPN service disaster recovery method according to claim 1, characterized in that: Also includes: Deploy a primary cloud management environment and a backup cloud management environment on the cloud management platform; wherein the primary cloud management environment and the backup cloud management environment have the same number of nodes, operating system, and hardware configuration; Configure the physical address, secure shell protocol port, and login credentials of the cloud management primary environment and the cloud management backup environment.
3. The cloud environment VPN service disaster recovery method according to claim 1, characterized in that: Also includes: When a cloud environment switching instruction is obtained through a preset user instruction issuing interface, or when the operating status of the cloud management main environment is monitored to be abnormal, it is determined that the cloud management platform currently meets the preset cloud environment switching conditions.
4. The cloud environment VPN service disaster recovery method according to claim 3, characterized in that: The starting of the cloud management service of the cloud management standby environment to switch the cloud management standby environment to the new cloud management primary environment includes: If there are multiple cloud management standby environments, select a target cloud management standby environment from the multiple cloud management standby environments, and start the cloud management service of the target cloud management standby environment to switch the target cloud management standby environment to the new cloud management primary environment; The target cloud management standby environment corresponds to the standby environment instruction obtained through the preset user instruction issuing interface, or the target cloud management standby environment is a cloud management standby environment selected according to the load status of each of the cloud management standby environments.
5. The cloud environment VPN service disaster recovery method according to any one of claims 1 to 4, characterized in that: The drifting of the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management master environment includes: The mapping relationship between the logical address of the message queue in the cloud management platform and the original physical address is drifted based on the physical address of the new cloud management main environment through the underlying network component of the cloud management platform; wherein, the underlying network component is any one of the load balancer, virtual router and floating logical address manager.
6. The cloud environment VPN service disaster recovery method according to claim 5, characterized in that: The drifting of the mapping relationship between the logical address and the original physical address of the message queue in the cloud management platform based on the physical address of the new cloud management primary environment by the underlying network component of the cloud management platform includes: Through the underlying network components of the cloud management platform, the first mapping relationship between the logical address of the message queue in the cloud management platform and the physical address of the original cloud management main environment is changed to a second mapping relationship between the logical address of the message queue and the physical address of the new cloud management main environment.
7. The cloud environment VPN service disaster recovery method according to claim 1, characterized in that: If the identification information of the VPN proxy component is queried in the Neutron component of the new cloud management environment, controlling the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue includes: Querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management environment; If the identification information of the VPN proxy component exists in the Neutron component, controlling the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue; If the identification information of the VPN proxy component does not exist in the Neutron component, the current retry count is determined. If the current retry count is less than the first preset threshold, the process jumps back to the step of querying whether the identification information of the VPN proxy component exists in the Neutron component of the new cloud management environment based on the delayed retry mechanism, and updates the current retry count.
8. The cloud environment VPN service disaster recovery method according to claim 1, characterized in that: The controlling the VPN gateway node to communicate with the new cloud management environment through the logical address of the message queue includes: Control the VPN gateway node to obtain the VPN configuration information sent by the new cloud management environment through the logical address of the message queue, so that the VPN gateway node forwards the VPN configuration information to the IPsec component; wherein, the VPN configuration information is the configuration information generated by the Neutron component in the new cloud management environment.
9. The cloud environment VPN service disaster recovery method according to claim 1, characterized in that: The controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB in the new cloud management environment through the OVN-SB physical address set includes: Control the VPN gateway node to establish a communication link with the OVN-SB in the new cloud management environment through the OVN-SB physical address set, and control the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link.
10. The cloud environment VPN service disaster recovery method according to claim 9, characterized in that: The controlling the VPN gateway node to register the identification information of the VPN proxy component with the OVN-SB through the communication link includes: Query whether the chassis_private table exists in the OVN-SB; wherein the chassis_private table is used to store private configuration information related to the physical host; If the chassis_private table does not exist in the OVN-SB and the current query count is not greater than a second preset threshold, then jump back to the step of querying whether the chassis_private table exists in the OVN-SB based on a delayed retry mechanism until the current query count is greater than the second preset threshold; If the chassis_private table exists in the OVN-SB, the communication link of the VPN proxy component in the VPN gateway node is controlled to add identification information of the VPN proxy component to the chassis_private table.
11. A computer program product comprising a computer program / instructions, characterized in that When the computer program / instruction is executed by a processor, the steps of the disaster recovery method for cloud environment VPN service described in any one of claims 1 to 10 are implemented.
12. An electronic device, characterized in that: include: memory for storing computer programs; A processor, configured to execute the computer program to implement the steps of the disaster recovery method for a cloud environment VPN service according to any one of claims 1 to 10.
13. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed by a processor, implements the steps of the disaster recovery method for a cloud environment VPN service according to any one of claims 1 to 10.
Citation Information
Patent Citations
Master-slave service system and master node fault recovery method and device
CN108964948A
Cross-data center intra-city disaster recovery method, device and equipment based on cloud platform
CN113821384A