Public network access method and device, electronic equipment, medium and program product

Through the automated access link generation method, the problem of inefficient visits to the public network in the cloud-native network architecture is solved, and efficient public network access is achieved without manual configuration.

CN120358274APending Publication Date: 2025-07-22中移信息技术有限公司 +1
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202510682709.2
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2025-05-23
Publication Date
2025-07-22

AI Technical Summary

Technical Problem

In the cloud native network architecture, business parties need to manually set up visit policies and proxy configurations when visiting the public network, resulting in inefficiency and easy configuration errors.

Method used

By receiving the access link request from the service party, the preset access proxy, the access configuration dictionary and the cluster domain name are automatically determined, the target access configuration dictionary is updated, the access link is automatically generated, and the domain name mapping relationship in the preset proxy service cluster is used to achieve public network access.

Benefits of technology

No manual configuration is required, which improves the efficiency of public network access, reduces configuration errors, simplifies the visit process, and improves the access success rate.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120358274A_ABST
    Figure CN120358274A_ABST
Patent Text Reader

Abstract

The invention discloses a public network access method and device, electronic equipment, a medium and a program product, and relates to the technical field of communication, and the method comprises the steps: receiving an access link application request initiated by a service party, and determining a preset access agent, a preset access configuration dictionary, a cluster domain name and a public network address range from the access link application request; according to a preset access agent and a public network address range, updating the preset access configuration dictionary to obtain a target access configuration dictionary; searching an access agent address corresponding to the preset access agent in a preset agent service cluster, and associating the access agent address with the cluster domain name to obtain an intra-cluster domain name mapping relationship of the preset agent service cluster; and generating an access link of the target public network according to the intra-group domain name mapping relationship, a preset access agent and a target access configuration dictionary, so as to access the target public network through the access link. The technical problem that the efficiency of visiting the public network is low is solved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] Embodiments of the present application relate to the field of communication technologies, and in particular, to a public network access method, apparatus, electronic device, medium, and program product. Background Art

[0002] In a cloud-native network architecture, the architecture includes a public network infrastructure layer, a security layer, a load balancing network layer, a bearer network layer, and a service core layer. Among them, the services of the service provider are usually deployed in the service core layer cluster. Due to security control requirements, the service provider usually cannot directly access the public network and needs to achieve public network access through the middle network layer for transit.

[0003] Currently, when the service provider applies to access the public network, it is necessary to manually set the access policy, manually configure the access proxy, etc., and rely on the operation and maintenance personnel to perform transit in the middle network layer. However, manual setting is not only troublesome but also prone to configuration errors, which in turn leads to low efficiency in accessing the public network.

[0004] The above content is only used to assist in understanding the technical solution of the embodiments of the present application, and does not represent an admission that the above content is prior art. Summary of the Invention

[0005] The main purpose of the embodiments of the present application is to provide a public network access method, apparatus, electronic device, medium, and program product, aiming to solve the technical problem of low efficiency in accessing the public network.

[0006] To achieve the above object, an embodiment of the present application provides a public network access method, and the method includes:

[0007] Receiving an access link application request initiated by a service provider, and determining a preset access proxy, a preset access configuration dictionary associated with the preset access proxy, a cluster domain name of the preset access proxy in a preset proxy service cluster, and a public network address range of a target public network to be accessed by the service provider from the access link application request;

[0008] Updating the preset access configuration dictionary according to the preset access proxy and the public network address range to obtain a target access configuration dictionary;

[0009] Searching for an access proxy address corresponding to the preset access proxy in the preset proxy service cluster, and associating the access proxy address with the cluster domain name to obtain an in-cluster domain name mapping relationship of the preset proxy service cluster;

[0010] Generating an access link to the target public network according to the in-cluster domain name mapping relationship, the preset access proxy, and the target access configuration dictionary, so as to access the target public network through the access link.

[0011] In a feasible embodiment, the step of updating the preset access configuration dictionary according to the preset access proxy and the public network address range to obtain a target access configuration dictionary includes: in the case that there is no configuration item corresponding to the preset access proxy in the preset access configuration dictionary, querying an access routing template corresponding to the proxy mode according to the proxy mode of the preset access proxy;

[0012] Determining a public network address set of the public network address range, and updating a preset address mapping template according to the public network address set and the public network port of the obtained target public network to obtain a target address mapping relationship;

[0013] Replacing a preset routing address placeholder in the access routing template with the target address mapping relationship, and replacing a preset proxy parameter placeholder in the access routing template with a proxy parameter corresponding to the obtained preset access proxy to obtain a target access configuration dictionary;

[0014] Wherein, the proxy parameter includes at least one of a node port of the preset access proxy, a proxy protocol, a cluster domain name, and a cluster identifier of a preset proxy service cluster.

[0015] In a feasible embodiment, the step of determining the public network address set of the public network address range includes: determining a public network start address and a public network end address from the public network address range;

[0016] Converting the public network start address into a start long integer, and converting the public network end address into an end long integer;

[0017] For each intermediate long integer between the start long integer and the end long integer, converting the intermediate long integer into an intermediate address;

[0018] Determining a public network address set constructed by the public network start address, the public network end address, and each intermediate address corresponding to each intermediate long integer.

[0019] In a feasible embodiment, the step of converting the public network start address into a start long integer and converting the public network end address into an end long integer includes: for any target address, sequentially determining a first target byte, a second target byte, a third target byte, and a fourth target byte from the target address;

[0020] Calculating a product of the cube of a preset value and the first target byte to obtain a first integer, calculating a product of the square of the preset value and the second target byte to obtain a second integer, calculating a product of the preset value and the third target byte to obtain a third integer, and calculating a product of the zero power of the preset value and the fourth target byte to obtain a fourth integer;

[0021] Accumulate the first integer, the second integer, the third integer, and the fourth integer to obtain the target long integer of the target address;

[0022] Wherein, when the target address is the public network start address, the target long integer is the start long integer, and when the target address is the public network end address, the target long integer is the end long integer.

[0023] In a feasible embodiment, the step of converting each intermediate long integer between the start long integer and the end long integer into an intermediate address includes: determining any one of the intermediate long integers as the target long integer among the intermediate long integers, and for each target long integer, taking the remainder of the target long integer by a preset value to obtain a byte;

[0024] Right-shift the target long integer by a preset number of shift bits to obtain a target right-shifted long integer, update the target long integer to the target right-shifted long integer, and return the step of taking the remainder of the target long integer by the preset value to obtain a byte until a preset number of bytes are obtained;

[0025] Sort the bytes in sequence according to the order of taking the remainder of each byte to obtain a sorting result, wherein the order of taking the remainder of the byte sorted earlier is earlier than the order of taking the remainder of the byte sorted later;

[0026] Concatenate the bytes in sequence in the order from large to small in the sorting result to obtain the intermediate address of the target long integer.

[0027] In a feasible embodiment, the access proxy address includes multiple container addresses, and the step of finding the access proxy address corresponding to the preset access proxy in the preset proxy service cluster includes: when receiving the approval result of the access work order by the operation and maintenance personnel and the approval result passes, finding the preset service resource corresponding to the preset access proxy in the preset proxy service cluster, wherein the access work order is generated based on the access link application request and the target access configuration dictionary;

[0028] Obtain the service container set of the preset access proxy from the preset service resource, and extract the container address of each service container in the service container set.

[0029] In a feasible embodiment, both the preset access proxy and the preset access configuration dictionary are deployed in a preset namespace of the preset proxy service cluster; the step of generating the access link of the target public network according to the in-cluster domain name mapping relationship, the preset access proxy, and the target access configuration dictionary includes:

[0030] After receiving the confirmation configuration instruction of the target access configuration dictionary from the service party, update the configuration item identifier of the configuration item in the target access configuration dictionary according to the cluster domain name corresponding to the preset access proxy;

[0031] Under the preset namespace of the preset proxy service cluster, update the preset access configuration dictionary under the preset namespace to the target access configuration dictionary, and adjust the configuration status of the target access configuration dictionary to the published state. The published state indicates that the target access configuration dictionary has been configured in the preset proxy service cluster;

[0032] When the configuration status of the target access configuration dictionary is the published state, execute a preset test reload command in the service container under the preset namespace to perform a test reload on the target access configuration dictionary;

[0033] After a preset duration, obtain the reload result after the test reload of the target access configuration dictionary. When the reload result includes a successful reload, determine the access link of the target public network composed of the intranet domain name mapping relationship, the preset access proxy, and the target access configuration dictionary;

[0034] Wherein, the successful reload indicates that the target access configuration dictionary is correctly configured.

[0035] In a feasible embodiment, the public network access method further includes: receiving an access proxy deployment request initiated by the service party, and determining deployment parameters from the access proxy deployment request;

[0036] Deploy a preset access proxy according to the deployment parameters;

[0037] Wherein, the deployment parameters include: the preset proxy service cluster where the preset access proxy is located, the preset namespace and node port of the preset access proxy in the preset proxy service cluster, the proxy mode of the preset access proxy, the proxy identifier, the image version parameter, the storage parameter, the number of proxy instances, and the number of worker threads.

[0038] In a feasible embodiment, the step of deploying a preset access proxy according to the deployment parameters includes: querying a proxy template corresponding to the proxy mode in a preset database according to the proxy mode;

[0039] Deploy the proxy environment variables of the preset access proxy according to the proxy template and the number of worker threads;

[0040] Configure the initial access configuration object of the preset access proxy within the preset namespace. Configure preset default startup configuration items in the initial access configuration object to support the first startup of the preset access proxy, and determine the configuration value template corresponding to the initial access configuration object according to the proxy template. Update the configuration value template according to the node port in the deployment parameters to obtain the preset access configuration dictionary after the initial access configuration object is configured, so as to deploy the preset access configuration dictionary of the preset access proxy;

[0041] Deploy the log storage unit of the preset access proxy according to the storage parameters, where the log storage unit includes an error log storage unit and a correct log storage unit;

[0042] Deploy the preset service resources of the preset access proxy in the preset namespace according to the proxy identifier, the number of proxy instances, the image version parameter, the node port, the proxy template, and the proxy environment variables;

[0043] Deploy the preset service exposure data of the preset access proxy in the preset namespace according to the proxy identifier and the node port.

[0044] In a feasible embodiment, the step of deploying the preset service resources of the preset access proxy in the preset namespace according to the proxy identifier, the number of proxy instances, the image version parameter, the node port, the proxy template, and the proxy environment variables includes:

[0045] Configure an initial service resource object within the preset namespace, and perform configuration operations on the initial service resource object to obtain the preset service resources deployed in the preset namespace;

[0046] Among them, the configuration operations include: using the proxy identifier as the service resource identifier of the initial service resource object; configuring the number of service replicas corresponding to the initial service resource object according to the number of proxy instances; configuring a service container in the initial service resource, and configuring the container image of the service container according to the image version parameter;

[0047] The configuration operations further include: configuring the container port of the service container according to the node port; configuring the container resources of the service container according to the proxy template, and configuring the container environment variables of the service container according to the proxy environment variables; configuring a preset anti-affinity rule for the initial service resource object; where the preset anti-affinity rule includes that in the case where there are multiple service containers in the preset service resources, each service container is allocated to a different host node.

[0048] In a feasible embodiment, the step of deploying the preset service exposure data of the preset access proxy in the preset namespace according to the proxy identifier and the node port includes:

[0049] Deploy an initial service exposure object in the preset namespace, configure the service exposure identifier of the initial service exposure object according to the proxy identifier, and configure the service exposure port of the initial service exposure object according to the node port, where the service exposure port is the entry for accessing the preset access proxy;

[0050] Associate the service exposure port with the container port in the preset service resource to obtain the exposure port mapping relationship of the initial service exposure object, and deploy a preset label selector in the initial service exposure object, where the preset label selector is used to associate the service container corresponding to the initial service exposure object;

[0051] Use the initial service exposure object configured with the service exposure identifier, the service exposure port, the exposure port mapping relationship, and the preset label selector as the preset service exposure data.

[0052] In addition, to achieve the above object, an embodiment of the present application provides a public network access device, which includes:

[0053] A receiving module, configured to receive an access link application request initiated by a service party, and determine a preset access proxy, a preset access configuration dictionary associated with the preset access proxy, a cluster domain name of the preset access proxy in a preset proxy service cluster, and a public network address range of a target public network that the service party needs to access from the access link application request;

[0054] A configuration module, configured to update the preset access configuration dictionary according to the preset access proxy and the public network address range to obtain a target access configuration dictionary;

[0055] A mapping module, configured to find an access proxy address corresponding to the preset access proxy in the preset proxy service cluster, and associate the access proxy address and the cluster domain name to obtain an in-cluster domain name mapping relationship of the preset proxy service cluster;

[0056] A link determination module, configured to generate an access link to the target public network according to the in-cluster domain name mapping relationship, the preset access proxy, and the target access configuration dictionary, so as to access the target public network through the access link.

[0057] In addition, to achieve the above object, an embodiment of the present application further provides an electronic device, where the electronic device includes: a memory, a processor, and a program of the public network access method stored on the memory and executable on the processor. When the program of the public network access method is executed by the processor, the steps of the public network access method as described above can be implemented.

[0058] In addition, to achieve the above object, an embodiment of the present application further provides a computer-readable storage medium, on which a program for implementing the public network access method is stored. When the program of the public network access method is executed by a processor, the steps of the public network access method as described above are implemented.

[0059] In addition, to achieve the above object, an embodiment of the present application further provides a computer program product, including a computer program, and when the computer program is executed by a processor, the steps of the public network access method as described above are implemented.

[0060] One or more technical solutions proposed by the embodiments of the present application have at least the following technical effects: The present application can receive an access link application request initiated by a service party, and can determine from the access link application request the public network address range of the target public network that the service party needs to access, a preset access proxy, a preset access configuration dictionary associated with the preset access proxy, and the cluster domain name of the preset access proxy in a preset proxy service cluster.

[0061] Furthermore, the present application can update the preset access configuration dictionary according to the preset access proxy and the public network address range in the access link application request to obtain a target access configuration dictionary, so as to realize the automatic configuration of the target access configuration dictionary without manual configuration by a person. And because the target access configuration dictionary is updated based on the preset access proxy and the public network address range, the target access configuration dictionary matches both the preset access proxy and the public network address range. Furthermore, it is convenient to subsequently combine the preset access proxy and the target access configuration dictionary to access the target public network. Further, the present application can also find the access proxy address corresponding to the preset access proxy in the preset proxy service cluster, map the access proxy address to the cluster domain name, and automatically construct an in-cluster domain name mapping relationship. Thus, an access link to the target public network can be automatically generated according to the in-cluster domain name mapping relationship, the preset access proxy, and the target access configuration dictionary without manual configuration. Furthermore, when the service party needs to access the target public network, the preset access proxy can be found directly from the access proxy addresses in the preset proxy service cluster through the cluster domain name of the preset proxy service cluster. Furthermore, it is convenient to access the target public network through the preset access proxy and the target access configuration dictionary corresponding to the preset access proxy without manual configuration, improving the access efficiency to the target public network. Description of the Drawings

[0062] The drawings herein are incorporated into and constitute a part of the specification, illustrate embodiments consistent with the embodiments of the present application, and together with the description are used to explain the principles of the embodiments of the present application.

[0063] In order to more clearly illustrate the embodiments of the present application or the technical solutions in the prior art, the drawings required for use in the embodiments or the description of the prior art will be briefly introduced below. Obviously, for ordinary technicians in this field, other drawings can be obtained based on these drawings without paying any creative labor.

[0064] Figure 1 This is a flowchart of an embodiment of a public network access method according to an embodiment of the present application;

[0065] Figure 2 This is a flowchart of an example of a public network access method in an embodiment of the present application;

[0066] Figure 3 This is a schematic diagram of an example module in the public network access method of an embodiment of the present application;

[0067] Figure 4 This is a schematic diagram of the module structure of the public network access device according to an embodiment of the present application;

[0068] Figure 5 This is a schematic diagram of the device structure of the hardware operating environment involved in the public network access method in the embodiment of the present application.

[0069] The purpose, features and advantages of the embodiments of the present application will be further described in conjunction with the embodiments and with reference to the accompanying drawings. DETAILED DESCRIPTION

[0070] It should be understood that the specific embodiments described herein are only used to explain the technical solutions of the embodiments of the present application and are not used to limit the embodiments of the present application.

[0071] In order to better understand the technical solutions of the embodiments of the present application, a detailed description will be given below in conjunction with the accompanying drawings and specific implementation methods.

[0072] The cloud-native network environment usually consists of a public network infrastructure layer, a security layer, a load balancing network layer, a bearer network layer, and a business core layer. The business party's services are usually deployed in the business core layer cluster. If the business party needs to access an address in the public network in the core network, it needs to be transferred through the intermediate network layer. In security management and control, direct access is usually not allowed. The business party needs to apply for the configuration of outbound access policies, organize the outbound access proxy configuration and resources, and manually configure or deploy a proxy in the intermediate layer to forward outbound requests, so as to open up the link to the outbound public network.

[0073] Currently, when the business side applies for accessing the public network, the operation and maintenance personnel need to manually maintain and track the outbound policy process initiated by the business side. However, the outbound policy process has problems such as long process and difficult to track, lack of security supervision, and difficult to trace historical configurations. Secondly, the outbound configurations of the outbound policy need to be carefully sorted out. Especially in the multi-data center and multi-cluster environment with continuous expansion, the complexity of the network environment continues to grow, and there is an increasing problem of difficulty in configuration sorting. Thirdly, during the deployment stage of the outbound proxy, container images, log storage resources, configuration dictionary resources, K8s domain name mapping resources, etc. that support different protocols need to be prepared, and then the deployment operation of the outbound proxy is carried out manually. During the manual deployment process, a series of problems that may occur, such as configuration errors, version mismatches, unavailable ports, and unexpected supported protocols, need to be solved to successfully establish the link to access the public network. Therefore, there is currently a problem of low efficiency in accessing the public network.

[0074] Therefore, this application provides a method for accessing the public network, which receives an access link application request initiated by the business side, and can determine from the access link application request the public network address range of the target public network that the business side needs to access, a preset access proxy, a preset access configuration dictionary associated with the preset access proxy, and the cluster domain name of the preset access proxy within the preset proxy service cluster. The preset access proxy can be used to proxy the business side to access the target public network. The preset access proxy is pre-deployed and does not require the business side to set it manually, so as to improve the access efficiency of the target public network.

[0075] Moreover, in this application, the preset access configuration dictionary can be directly updated based on the preset access proxy and the public network address range to obtain the target access configuration dictionary, so as to realize the automatic configuration of the target access configuration dictionary without manual configuration. Since the target access configuration dictionary is updated based on the preset access proxy and the public network address range, the target access configuration dictionary matches both the preset access proxy and the public network address range. Furthermore, it is convenient to subsequently combine the preset access proxy and the target access configuration dictionary to access the target public network. Further, this application can also find the access proxy address corresponding to the preset access proxy in the preset proxy service cluster, map the access proxy address to the cluster domain name, and automatically construct the in-cluster domain name mapping relationship. Thus, based on the in-cluster domain name mapping relationship, the preset access proxy, and the target access configuration dictionary, the access link to the target public network can be automatically generated without manual configuration. When the business side needs to access the target public network, it can directly find the preset access proxy in the access proxy addresses in the preset proxy service cluster through the cluster domain name of the preset proxy service cluster. Furthermore, it is convenient to access the target public network through the preset access proxy and the target access configuration dictionary corresponding to the preset access proxy without manual configuration, improving the access efficiency of the target public network. It can also reduce the complexity of accessing the public network.

[0076] Based on this, an embodiment of the present application provides a public network access method. Refer to Figure 1 , Figure 1 which is a schematic flowchart of the first embodiment of the public network access method in the embodiment of the present application. The public network access method includes steps S10 to S30:

[0077] Step S10: Receive an access link application request initiated by the service party, and determine a preset access proxy, a preset access configuration dictionary associated with the preset access proxy, a cluster domain name of the preset access proxy in the preset proxy service cluster, and a public network address range of the target public network that the service party needs to access from the access link application request;

[0078] It should be noted that the access link application request is initiated by the service party, and the access link application request indicates that an access link to the target public network needs to be constructed, and the target public network can be accessed through the access link. In this embodiment, the service party can initiate an access application on the access platform. The access platform can be the execution subject in this embodiment or other platforms for accessing the public network, and this embodiment does not make specific limitations on this. Before accessing the target public network, an access link to the target public network needs to be constructed to facilitate accessing the target public network through this access link.

[0079] The target public network is the public network that the service party needs to access. The public network address range indicates the address range that the service party needs to access the target public network, and the public network address range can include the addresses of multiple target public networks. The public network address range of the target public network can be determined based on the public network domain name of the target public network, and different public network domain names can correspond to different public network address ranges.

[0080] The preset access proxy can be determined by the service party in advance in the access proxy library. The access proxy library can store multiple access proxy services, and the preset access proxy is the preset access proxy selected by the service party from each access proxy service. Each access proxy service can proxy the service party to access the public network. For example, the access proxy service can forward the access request of the service party to the target public network. The preset access proxy can be an Nginx proxy.

[0081] The preset access configuration dictionary is the configuration data required when running the preset access proxy. The preset access configuration dictionaries corresponding to different preset access proxies are not necessarily the same, and each preset access proxy has its own corresponding preset access configuration dictionary.

[0082] The cluster domain name is the domain name assigned to a preset access proxy in a preset proxy service cluster, and the cluster domain names corresponding to different preset access proxies are different. The preset proxy service clusters corresponding to different preset access proxies can be the same or different, and this embodiment does not make specific limitations on this. The preset proxy service cluster is the target Kubernetes cluster used to execute the public network access requests of the business party. The Kubernetes cluster is also called K8s, and the Kubernetes cluster (an open-source container orchestration platform).

[0083] In this embodiment, the access link application request can also be divided into a cluster domain name application and an outbound policy application. It can be understood that the business party can initiate the cluster domain name application and the outbound policy application in sequence, and the public network platform can also receive the cluster domain name application and the outbound policy application in sequence. For example, the business party can fill in the key parameters according to the business outbound requirements on the page for adding a cluster domain name on the public network platform to initiate a cluster domain name application: for example, the cluster domain name application can include the preset proxy service cluster specified by the business party, the cluster domain name in the preset proxy service cluster, the name of the target public network system where the target public network is located, the public network domain name of the target public network, and the public network address range corresponding to the public network domain name. Among them, the name of the target public network system is convenient for identifying the target public network system where the target public network is located, so as to access the target public network subsequently. The public network domain name is the address of the target public network, and the public network port is the service entry for accessing the public network domain name.

[0084] The outbound policy application can include: the public network port of the target public network, the preset access proxy used to access the target public network, the proxy mode of the preset access proxy specified by the business party, the application layer protocol corresponding to the proxy mode, the client certificate and certificate chain required by the business party when accessing the target public network, and the usage description of the public network port; among them, the public network port can access the public network domain name of the target public network. The proxy mode can also be specified by the business party. For example, the proxy mode of the preset access proxy can include a four-layer proxy and a seven-layer proxy. Among them, the protocol corresponding to the four-layer proxy can be the TCP protocol (Transmission Control Protocol), and the protocols corresponding to the seven-layer proxy can be HTTP (Hypertext Transfer Protocol mode), HTTPS (Hypertext Transfer Protocol Secure), etc. The client certificate and certificate chain are provided by the business party and can be used to prove the identity of the business party. The business party provides the client certificate and certificate chain to ensure secure communication. When the proxy mode is a seven-layer proxy, it is necessary to specify the application layer protocol. For example, select the protocol of the preset access proxy from the HTTP and HTTPS protocols. The usage description of the public network port is convenient for ensuring the integrity and accuracy during the access to the public network.

[0085] Exemplarily, by receiving a cluster domain name application and an outbound access policy application, the public network address range and the cluster domain name of the target public network that the service party needs to access can be determined from the cluster domain name application; and the preset access proxy and the preset access configuration dictionary can be determined from the outbound access policy application.

[0086] Step S20: Update the preset access configuration dictionary according to the preset access proxy and the public network address range to obtain a target access configuration dictionary.

[0087] It should be noted that the target access configuration dictionary may include each address of the target public network corresponding to the public network address range. The target access configuration dictionary is related to the preset access proxy and also related to the public network address range, so as to facilitate subsequent access to the target public network according to the preset access proxy and the target access configuration dictionary.

[0088] Exemplarily, the routing configuration of the preset access configuration dictionary can be updated according to the preset access proxy and the public network address range to obtain a target access configuration dictionary, so that the target public network can be routed through the target access configuration dictionary to realize the automatic configuration of the target access configuration dictionary of the preset access proxy.

[0089] In a feasible embodiment, step S20 further includes steps S21 to S23:

[0090] Step S21: When there is no configuration item corresponding to the preset access proxy in the preset access configuration dictionary, query the access routing template corresponding to the proxy mode according to the proxy mode of the preset access proxy.

[0091] It should be noted that the configuration item is a necessary configuration for the preset access proxy to proxy access to the target public network, and each public network address of the target public network is included in the configuration item. If there is a configuration item in the preset access configuration dictionary, it means that the preset access configuration dictionary corresponding to the preset access proxy has been updated. For example, the preset access proxy may have been used to access the target public network historically, then the preset access configuration dictionary can be directly used as the target access configuration dictionary. If there is no configuration item corresponding to the preset access proxy in the preset access configuration dictionary, the preset access configuration dictionary needs to be updated to obtain the target access configuration dictionary. The proxy mode is specified by the service party when initiating the outbound access policy application, and the access routing templates corresponding to different proxy modes are different, and the access routing template can represent the routing rule.

[0092] Exemplarily, check whether there is a configuration item named after the cluster domain name in the preset access configuration dictionary. If there is a configuration item named after the cluster domain name in the preset access configuration dictionary, it is determined that there is a configuration item corresponding to the preset access proxy; if there is no configuration item named after the cluster domain name in the preset access configuration dictionary, it is determined that there is no configuration item corresponding to the preset access proxy. In the case where there is no configuration item named after the cluster domain name in the preset access configuration dictionary, query the access routing template corresponding to the proxy mode according to the proxy mode of the preset access proxy.

[0093] Step S22: Determine the public network address set within the public network address range, and update the preset address mapping template based on the public network address set and the public network port of the obtained target public network to obtain the target address mapping relationship.

[0094] It should be noted that the public network address set represents the set of each public network address within the public network address range. The public network address range includes a public network start address and a public network end address, so that the public network address range of the target public network can be described by the public network start address and the public network end address. The public network port is the entry for accessing the target public network. The public network port is also specified by the service provider when initiating a cluster domain name request.

[0095] The preset address mapping template includes multiple sub-address mapping templates, and each sub-address mapping template is the same. Each sub-address mapping template can be an upstream (upstream mapping template) mapping template; each public network address in the public network address set can be substituted into an upstream mapping template, and the public network port can be substituted into each upstream mapping template. For each upstream mapping template, substituting the public network address and the public network port into the upstream mapping template can obtain the upstream mapping relationship; thus, the target address mapping relationship can be obtained. The target address mapping relationship includes multiple upstream mapping relationships, and each upstream mapping relationship includes a public network address and a public network port. The public network addresses corresponding to different upstream mapping relationships are different, but the public network ports are the same.

[0096] Exemplarily, determine the public network address set based on the public network start address and the public network end address within the public network address range, and fill each public network address in the public network address set into the corresponding upstream mapping template. One public network address corresponds to one upstream mapping template, and each upstream mapping template is filled with the public network address to obtain the target address mapping relationship.

[0097] Step S23: Replace the preset routing address placeholder in the access routing template with the target routing address mapping relationship, and replace the preset proxy parameter placeholder in the access routing template with the proxy parameters corresponding to the obtained preset access proxy, to obtain a target access configuration dictionary;

[0098] Among them, the proxy parameters include at least one of the node port, proxy protocol, cluster domain name of the preset access proxy, and the cluster identifier of the preset proxy service cluster.

[0099] It should be noted that both the preset routing address placeholder and the preset proxy parameter placeholder are variables in the access routing template. The target routing address mapping relationship can replace the preset routing address placeholder, and the proxy parameters can replace the preset proxy parameter placeholder. The node port is the port of the preset access proxy in the preset proxy service cluster, the proxy protocol is the communication protocol required for the preset access proxy to access the target public network, and the cluster identifier is the identifier of the preset proxy service cluster. The cluster identifier can be used to distinguish different preset proxy service clusters. There are respective placeholders for the node port, proxy protocol, cluster domain name, and cluster identifier in the access routing template, and the preset access configuration dictionary can be updated according to the respective placeholders of the node port, proxy protocol, cluster domain name, and cluster identifier in the access routing template to obtain the target access configuration dictionary.

[0100] Exemplarily, replace the preset routing address placeholder in the access routing template with the target address mapping relationship, and replace the preset proxy parameter placeholder in the access routing template with the proxy parameters corresponding to the obtained preset access proxy, to obtain a target access configuration dictionary. Thus, the target access configuration dictionary can include the public network addresses of the target public network, and can also include the public network ports, as well as the node port, proxy protocol, cluster domain name, and cluster identifier corresponding to the preset access proxy. Thus, it is convenient to subsequently access the target public network through the preset access proxy and the target access configuration dictionary. There is no need to manually configure the target access configuration dictionary, so as to improve the access efficiency of the target public network.

[0101] In other embodiments, the target access configuration dictionary can also be stored in a preset database, and the configuration status of the target access configuration dictionary in the preset database can be updated but not published. Updated but not published indicates that the target access configuration dictionary has been updated, but the target access configuration dictionary has not been published to the preset proxy service cluster yet. If the target access configuration dictionary is published to the preset proxy service cluster, it means that the preset proxy service can access the target public network in the preset proxy service cluster according to the target access configuration dictionary.

[0102] In a feasible embodiment, step S22 further includes steps S221 to S224:

[0103] Step S221: Determine the public network start address and the public network end address from the public network address range;

[0104] Step S222: Convert the public network start address into a start long integer and convert the public network end address into an end long integer;

[0105] It should be noted that usually it is a continuous IP address segment. The public network start address represents the starting IP in the public network address range, and the public network end address represents the ending IP in the public network address range. The address types of both the public network start address and the public network end address can be IPv4 (Internet Protocol version 4 Address) addresses. The start long integer is the public network start address replaced by a numerical value, and the end long integer is the public network end address replaced by a numerical value.

[0106] Exemplarily, the public network start address can be divided into 4 sub-addresses. Numerical conversion is performed on each sub-address in the public network start address, and the results after numerical conversion are added to obtain the start long integer. The public network end address is divided into 4 sub-addresses. Numerical conversion is performed on each sub-address in the public network end address, and the results after numerical conversion are added to obtain the end long integer.

[0107] In a feasible embodiment, step S222 further includes steps S2221 to S2223:

[0108] Step S2221: For any target address, sequentially determine the first target byte, the second target byte, the third target byte, and the fourth target byte from the target address;

[0109] Step S2222: Calculate the product of the cube of a preset value and the first target byte to obtain the first integer, calculate the product of the square of the preset value and the second target byte to obtain the second integer, calculate the product of the preset value and the third target byte to obtain the third integer, and calculate the product of the zero power of the preset value and the fourth target byte to obtain the fourth integer;

[0110] Step S2223: Accumulate the first integer, the second integer, the third integer, and the fourth integer to obtain the target long integer of the target address;

[0111] Wherein, when the target address is the public network start address, the target long integer is the start long integer, and when the target address is the public network end address, the target long integer is the end long integer.

[0112] It should be noted that the methods for converting the public network start address and the public network end address into their respective corresponding long integers are the same. The target address can be the public network start address or the public network end address. When the target address is the public network start address, the target long integer is the start long integer, and when the target address is the public network end address, the target long integer is the end long integer.

[0113] The address type of the target address is an IPv4 address. An IPv4 address can be divided into four parts. For example, the target address can be 192.168.1.1, and the target address is split into 4 parts by "." The first target byte, the second target byte, the third target byte, and the fourth target byte are concatenated in sequence to obtain the target address. For example, when the target address is 192.168.1.1, the first target byte can be 192, the second target byte can be 168, the third target byte can be 1, and the fourth target byte can be 1.

[0114] The preset value can be 256. The first integer is the integer after numerical conversion of the first target byte, the second integer is the integer after numerical conversion of the second target byte, the third integer is the integer after numerical conversion of the third target byte, and the fourth integer is the integer after numerical conversion of the fourth target byte.

[0115] Exemplarily, the formula for determining the target long integer of the target address can be:

[0116] Number=Z1×a^3+Z2×a^2+Z3×a^1+Z4×a^0 (Formula 1);

[0117] Where, Number is the target long integer, Z1 is the first target byte, Z2 is the second target byte, Z3 is the third target byte, Z4 is the fourth target byte. a is the preset value, and the preset value can be 256.

[0118] In this embodiment, by converting the public network start address into the start long integer and converting the public network end address into the end long integer, it is convenient to subsequently determine all the public network addresses within the public network address range through the variable start long integer to the end long integer, and further facilitate subsequent access to the target public network.

[0119] Step S223, for each intermediate long integer between the start long integer and the end long integer, convert the intermediate long integer into an intermediate address;

[0120] Step S224, determine the public network address set constructed by the public network start address, the public network end address, and the intermediate address corresponding to each intermediate long integer.

[0121] It should be noted that the intermediate long integer is the long integer between the starting long integer and the ending long integer. There are multiple intermediate long integers between the starting long integer and the ending long integer. All intermediate long integers can be converted into intermediate addresses, so that each public network address in the public network address range can be obtained. The public network address set includes each public network address from the public network starting address to the public network ending address. The public network address range includes the public network starting address and the public network ending address. The intermediate address is the public network address between the public network starting address and the public network ending address.

[0122] Exemplarily, each intermediate long integer can be converted back to the corresponding intermediate address, and the intermediate addresses are sequentially added to the public network address set. The public network address set includes the public network addresses from the public network starting address to the public network ending address in sequence.

[0123] In a feasible embodiment, step S223 further includes steps S2231 to S2233:

[0124] Step S2231, determine any one of the intermediate long integers as the target long integer among the intermediate long integers. For each target long integer, take the remainder of the target long integer with a preset value to obtain a byte.

[0125] Step S2232, shift the target long integer to the right by a preset number of shift bits to obtain the target right-shifted long integer. Update the target long integer to the target right-shifted long integer, and return to the step of taking the remainder of the target long integer with a preset value to obtain a byte until a preset number of bytes are obtained.

[0126] Step S2233, sort each byte in sequence according to the order of taking the remainder of each byte to obtain a sorting result, where the order of taking the remainder of the byte sorted earlier is earlier than the order of taking the remainder of the byte sorted later.

[0127] Step S2234, splice each byte in sequence in the order from large to small in the sorting result to obtain the intermediate address of the target long integer.

[0128] It should be noted that the method of converting each intermediate long integer back to the intermediate address is the same. The target long integer can be any intermediate long integer, and the preset value can be 256. The remainder can be taken for each intermediate long integer. The preset number of shift bits can be 8. For each intermediate long integer, each intermediate long integer will take the remainder 4 times, so that 4 bytes can be obtained, and then the intermediate address corresponding to the intermediate long integer can be spliced.

[0129] The preset number can be 4. After each remainder is taken for the target long integer, it will be shifted 8 bits to the right and then take the remainder until 4 bytes are obtained. For the target long integer, the byte obtained by the first remainder is the last byte of the intermediate address, and the byte obtained by the last remainder of the target long integer is the first byte of the intermediate address.

[0130] Sort each byte in sequence according to the order of taking the remainder of each byte to obtain a sorting result. Then, splice each byte in sequence in descending order in the sorting result to obtain the intermediate address of the target long integer. The address type of the intermediate address is also in the IPv4 format, and the two adjacent bytes in the intermediate address can be separated by a "."

[0131] For example, the order of taking the remainder of the byte obtained by the target long integer for the first time is 1, and the order of taking the remainder of the byte obtained by the target long integer for the fourth time is 4. Therefore, in the sorting result, the order of taking the remainder of the byte sorted earlier is earlier than the order of taking the remainder of the byte sorted later. When the target long integer obtains a preset number of bytes, the remainder-taking will no longer continue.

[0132] For example, if the byte obtained by the target long integer for the first time is 1, the byte obtained by the second time is 1, the byte obtained by the third time is 168, and the byte obtained by the fourth time is 192, then the intermediate address corresponding to the target long integer is 192.168.1.1.

[0133] In this embodiment, through the correspondence between the long integer and the address, all public network addresses can be determined, which is convenient for the subsequent preset access proxy to access the target public network.

[0134] Step S30: Search for the access proxy address corresponding to the preset access proxy in the preset proxy service cluster, and associate the access proxy address with the cluster domain name to obtain the in-cluster domain name mapping relationship of the preset proxy service cluster;

[0135] It should be noted that the preset access proxy accesses the target public network based on the preset proxy service cluster, and the access proxy address is the address allocated to the preset access proxy in the preset proxy service cluster. The mapping relationship between the cluster domain name and the access proxy address can be automatically constructed, and the in-cluster domain name mapping relationship is the mapping relationship between the cluster domain name and the access proxy address, so that the preset proxy service and the outside of the preset proxy service cluster can communicate through the domain name instead of through hard-coded IP. The access proxy address is the address where the preset access proxy runs.

[0136] Exemplarily, the access address corresponding to the preset access proxy can be searched in the preset proxy service cluster, and the mapping relationship between the access proxy address and the cluster domain name can be constructed to obtain the in-cluster domain name mapping relationship.

[0137] In a feasible embodiment, the access proxy address includes multiple container addresses, and step S30 further includes steps S31 to S32:

[0138] Step S31, when receiving the approval result of the operation and maintenance personnel for the access work order and the approval result is passed, search for the preset service resources corresponding to the preset access proxy in the preset proxy service cluster, where the access work order is generated based on the access link application request and the target access configuration dictionary;

[0139] Step S32, obtain the service container set of the preset access proxy from the preset service resources, and extract the container address of each service container from the service container set.

[0140] It should be noted that the access work order is automatically generated based on the access link application request and the target access configuration dictionary, and the access work order can be saved in the preset database.

[0141] The operation and maintenance personnel can initiate a review request for the access work order. After receiving the review request, the access work order can be retrieved from the preset database and pushed to the operation and maintenance personnel for review. The operation and maintenance personnel can review the rationality, security, and necessity of the access link application request and the target access configuration dictionary in the access work order. After the review, the operation and maintenance personnel can fill in the approval result. If the approval result includes approval, the access work order can also be sent to the security control department for the security control department to perform release processing on the target address mapping relationship involved in the access work order, that is, to allow the use of the addresses involved in the target address mapping relationship. If the approval result is not passed, the business party can be prompted that the approval is not passed, and at the same time, the access work order does not need to be sent to the security control department.

[0142] The preset access proxy is pre-deployed, and the preset service resources are deployed during the deployment of the preset access proxy. Each preset access proxy has its own corresponding preset service resources. Different preset access proxies may have different corresponding preset service resources. Each preset service resource has a service container set, and the service container set includes multiple service containers. Each service container has its own corresponding container address, and the access proxy address includes multiple container addresses. The preset access proxy can run in each container address. The preset service resource can be a Deployment (stateless service) resource, and the service container is a POD (container group). The Deployment resource can include multiple PODs, and multiple real-time PODs can be obtained under the preset service resource.

[0143] Exemplarily, an access work order is automatically generated based on the access link application request and the target access configuration dictionary, and the access work order is pushed to the operation and maintenance personnel. The approval result based on the access work order is received. In the case where the approval result is not passed, the business party is prompted that the approval is not passed, and the construction of the access link is stopped. In the case where the approval result is passed, the preset service resource corresponding to the preset access proxy is searched for in the preset proxy service cluster; the service container set of the preset access proxy is obtained from the preset service resource, and the container address of each service container is extracted from the service container set. Further, in the case where the approval is passed, the statuses of the public network port and the client certificate can be marked as valid in the preset database, so as to facilitate subsequent access to the target public network by calling the public network port and the client certificate with valid statuses, ensuring the security of the access.

[0144] In this embodiment, the access proxy address is determined only when the approval is passed, which is convenient for ensuring the security and accuracy of the subsequent access link, and thus facilitating the subsequent successful access to the target public network, and preventing the situation of failure to access the target public network due to configuration errors or other situations.

[0145] Step S40: Generate an access link to the target public network according to the in-group domain name mapping relationship, the preset access proxy, and the target access configuration dictionary, so as to access the target public network through the access link.

[0146] It should be noted that the access link is a link used to access the target public network. The access proxy address where the preset access proxy is located can be found through the cluster domain name of the preset proxy service cluster. Thus, the target public network can be accessed through the preset access proxy and the target access configuration dictionary in the access proxy address, without manual setting, improving the access efficiency of the target public network access, and at the same time reducing the situation of failure to access the target public network caused by manual configuration errors.

[0147] Exemplarily, the target access configuration dictionary can be tested. After the target access configuration dictionary test is successful, the access link to the target public network generated by the in-group domain name mapping relationship, the preset access proxy, and the target access configuration dictionary can be determined.

[0148] The embodiments of the present application can receive an access link application request initiated by a service party, and can determine from the access link application request the public network address range of the target public network that the service party needs to access, the preset access proxy determined by the service party in a pre-deployed access proxy library for proxying access to the target public network, the preset access configuration dictionary associated with the preset access proxy, and the cluster domain name of the preset access proxy within the preset proxy service cluster; since the preset access proxy is determined by the service party in a pre-deployed access proxy library, the preset access proxy for proxying the service party to access the target public network does not need to be manually set by the service party, so as to improve the access efficiency of the target public network.

[0149] Moreover, in the embodiments of the present application, the preset access configuration dictionary can be directly updated based on the preset access proxy and the public network address range to obtain a target access configuration dictionary, so that the automatic configuration of the target access configuration dictionary can be realized without manual configuration. And since the target access configuration dictionary is updated based on the preset access proxy and the public network address range, the target access configuration dictionary matches both the preset access proxy and the public network address range. Furthermore, it is convenient to subsequently combine the preset access proxy and the target access configuration dictionary to realize the access to the target public network. Further, the embodiments of the present application can also find the access proxy address corresponding to the preset access proxy in the preset proxy service cluster, map the access proxy address to the cluster domain name, and automatically construct an intra-cluster domain name mapping relationship. Thus, based on the intra-cluster domain name mapping relationship, the preset access proxy, and the target access configuration dictionary, the access link to the target public network can be automatically generated without manual configuration. Moreover, when the service party needs to access the target public network, the preset access proxy can be directly found among the access proxy addresses in the preset proxy service cluster through the cluster domain name of the preset proxy service cluster. Furthermore, it is convenient to access the target public network through the preset access proxy and the target access configuration dictionary corresponding to the preset access proxy without manual configuration, which improves the access efficiency of the target public network.

[0150] In a feasible embodiment, step S40 further includes steps S41 to S44:

[0151] Step S41, after receiving the confirmation configuration instruction of the service party for the target access configuration dictionary, update the configuration item identifier of the configuration item in the target access configuration dictionary according to the cluster domain name corresponding to the preset access proxy;

[0152] It should be noted that the target access configuration dictionary can be pushed to the service party for viewing, and the service party can adjust the target access configuration dictionary based on actual access requirements, so that the target access configuration dictionary better meets the actual access requirements.

[0153] When the business party adjusts the target access configuration dictionary, the confirmation configuration instruction triggered by the business party includes the adjustment operation on the target access configuration dictionary. Thus, the target access configuration dictionary can be updated based on the adjustment operation, and it can be confirmed that the updated target access configuration dictionary can be used for accessing the target public network. When the confirmation configuration instruction triggered by the business party does not include the adjustment operation on the target access configuration dictionary, it indicates that the business party has not adjusted the target access configuration dictionary, and it can be determined that the target access configuration dictionary can be used for accessing the target public network.

[0154] The confirmation configuration instruction indicates that the final target access configuration dictionary can be used as the configuration of the preset access proxy, which means that the target access configuration dictionary can participate in the access to the target public network. The final target access configuration dictionary can refer to the target access configuration dictionary adjusted by the business party. When the business party does not adjust the target access configuration dictionary, the final target access configuration dictionary is the data after the update of the preset access configuration dictionary. After receiving the target access configuration dictionary, the configuration item identifier in the target access configuration dictionary can be updated according to the cluster domain name corresponding to the preset access proxy, so as to mark that there is a configuration item corresponding to the preset access proxy in the target access configuration dictionary. Furthermore, when the preset access proxy is used subsequently, if there is a configuration item of the cluster domain name in the access configuration dictionary corresponding to the preset access proxy, the proxy parameters and address mapping relationship in the access configuration dictionary of the preset access proxy do not need to be updated. For example, steps S21 to S23 of querying the access routing template are not required.

[0155] Exemplarily, the target access configuration dictionary is pushed to the business party, and the confirmation configuration instruction of the business party for the target access configuration dictionary is received. According to the cluster domain name corresponding to the preset access proxy, the configuration item identifier of the configuration item in the target access configuration dictionary is updated. For example, the cluster domain name can be used as the prefix name of the configuration item in the target access configuration dictionary. For example, the configuration item identifier can be {cluster domain name}.conf (configuration file), where conf is the suffix identifier of the configuration item in the target access configuration dictionary.

[0156] Step S42, in the preset namespace of the preset proxy service cluster, update the preset access configuration dictionary in the preset namespace to the target access configuration dictionary, and adjust the configuration status of the target access configuration dictionary to the published state. The published state indicates that the target access configuration dictionary has been configured in the preset proxy service cluster;

[0157] It should be noted that the preset namespace is the namespace determined when the preset access proxy is pre-deployed. The preset namespace is within the preset proxy service cluster. Under the preset namespace, relevant parameters such as the preset access proxy and the preset access configuration dictionary of the preset access proxy can be stored. The original preset access configuration dictionary stored under the preset namespace can be replaced with the target access configuration dictionary, so as to facilitate accessing the target public network in the preset proxy service cluster using the preset access proxy and the target access configuration dictionary associated with the concept.

[0158] The configuration status can reflect the configuration situation of the target access configuration dictionary. The configuration status can include the published status, the updated but unpublished status, and the unupdated status. Among them, the updated but unpublished status indicates that it has been updated to the target access configuration dictionary but has not been configured in the preset proxy service cluster, and the unupdated status indicates that the preset access configuration dictionary has not been updated to the target access configuration dictionary.

[0159] The published status means that the target access configuration dictionary has been configured in the preset proxy service cluster, so that subsequently the preset access proxy can use the target access configuration dictionary to access the target public network in the preset proxy service cluster. In other embodiments, the published status of the target access configuration dictionary can also be stored in the preset database, so as to facilitate tracking the target access configuration dictionary and understanding the status of the target access configuration dictionary in the preset database.

[0160] Exemplarily, under the preset namespace of the preset proxy service cluster, the preset access configuration dictionary under the preset namespace is replaced with the target access configuration dictionary, and the configuration status of the target access configuration dictionary is adjusted to the published status. The published status means that the target access configuration dictionary has been configured in the preset proxy service cluster, which further facilitates subsequent testing of the target access configuration dictionary in the preset proxy service cluster to test whether the target access configuration dictionary is correct, so as to successfully access the target public network subsequently.

[0161] Step S43, when the configuration status of the target access configuration dictionary is the published status, execute a preset test reload command in the service container under the preset namespace to perform a test reload on the target access configuration dictionary;

[0162] Step S44, obtain the reload result after the test reload of the target access configuration dictionary after a preset duration. When the reload result includes a successful reload, determine the access link of the target public network composed of the in-group domain name mapping relationship, the preset access proxy, and the target access configuration dictionary;

[0163] Among them, a successful reload means that the target access configuration dictionary is correctly configured.

[0164] It should be noted that when the configuration status of the target access configuration dictionary is published, it means that the target access configuration dictionary has been configured in the preset proxy service cluster, and then the target access configuration dictionary can be reloaded in the preset proxy service cluster. Reload testing means testing the target access configuration dictionary to test whether the target access configuration dictionary is accurate and can run successfully.

[0165] The preset test reload command can be pre-set, and the preset test reload command can be used to test whether the target access configuration dictionary is correct. For example, the preset test reload command can be "sh -c 'nginx -t; echo "nginx-tresult:$?"; nginx -s reload; echo "nginx -s reload result:$?"; '" This command means: check the grammatical correctness of the target access configuration dictionary corresponding to Nginx and output the grammar check result; detect whether the configuration of the target access configuration dictionary is correct. If the configuration of the target access configuration dictionary is correct, reload the target access configuration dictionary of Nginx and output the reloaded reload result. It can be understood that the preset test reload command can detect whether the syntax of the target access configuration dictionary is correct, and can also detect whether the configuration is correct. At the same time, it can test whether the target access configuration dictionary can be reloaded and run, and then it can test whether the target access configuration dictionary can be run, so as to detect whether the target public network can be accessed in combination with the target access configuration dictionary.

[0166] If the reload result includes reload success, it means that the target access configuration dictionary is accurate, which may include that the target access configuration dictionary is correctly configured and the syntax of the target access configuration dictionary is also correct, and thus can be used to access the target public network.

[0167] The preset duration can be set based on actual conditions, and this embodiment does not make any specific limitation on this. The preset reload command takes time to execute, so the reload result can be obtained after the preset duration.

[0168] In this embodiment, the preset service resources of the preset access proxy are also deployed under the preset namespace. The preset service resources include multiple service containers. The service container can be a POD. The preset reload command can be executed in the Container under the POD. The Container can refer to the sub-working container in the service container, and then the POD can be tested to see whether the target access configuration dictionary can be reloaded. If the target access configuration dictionary can be successfully reloaded in the POD, it also means that the preset access proxy can subsequently use the target access configuration dictionary in the POD to access the target public network. When the reload result includes a successful reload, it also means that the access link to the target public network is open, and then the access link can be used to access the target public network.

[0169] Exemplarily, when the configuration state of the target access configuration dictionary is in the published state, the Kubernetes interface of the preset proxy service cluster can be called, and the preset test reload command can be executed in the service container under the preset namespace to test the target access configuration dictionary to test the grammatical correctness and configuration correctness of the target access configuration dictionary and whether the target access configuration dictionary can be loaded and run; the preset test reload command can be executed in all service containers, or in any service container. This embodiment does not make specific restrictions on this. The Kubernetes interface can manage the resources in the preset proxy service cluster, so the Kubernetes interface of the preset proxy service cluster can be called to execute the preset test reload command in the corresponding service container. After the preset time, the reload result after the target access configuration dictionary test reload is obtained. When the reload result includes a successful reload, the access link of the target public network composed of the domain name mapping relationship within the group, the preset access proxy and the target access configuration dictionary is determined, and then the access link is opened, which is convenient for subsequent access to the target public network and improves the access efficiency of the target public network. At the same time, it is also convenient to ensure the success rate of target public network access.

[0170] After the target access configuration dictionary is successfully reloaded, a reload success prompt may also be output to prompt the business party that the target access configuration dictionary is successfully reloaded in the preset proxy service cluster.

[0171] When the access link is connected, the business party can access the external system through the cluster domain name in the business service. The external system can be, for example, the system where the target public network is located. Alternatively, the business party's access request can be simulated through curl, and the entire access link can be judged based on whether the simulated access request meets expectations. For example, after initiating a test request, the response result of the test request can be obtained, and the entire path from the client where the business party is located to the target public network can be determined from the response result. Whether it is working properly.

[0172] In a feasible embodiment, the public network access method further includes steps A10 to A20:

[0173] Step A10, receiving an access proxy deployment request initiated by a business party, and determining deployment parameters from the access proxy deployment request;

[0174] Step A20, deploying a preset access proxy according to the deployment parameters;

[0175] Among them, the deployment parameters include: the preset proxy service cluster where the preset access proxy is located, the preset namespace and node port of the preset access proxy in the preset proxy service cluster, the proxy mode of the preset access proxy, the proxy identifier, the image version parameters, the storage parameters, the number of proxy instances, and the number of working threads.

[0176] It should be noted that the preset access proxy can be pre-deployed. The business party can initiate an access proxy deployment request to deploy the preset access proxy. The business party can deploy multiple access proxies. For example, the business party can initiate multiple access proxy deployment requests, and each access proxy deployment request can deploy a new access proxy. Each deployed access proxy can be stored in the access proxy library, which is a database for storing multiple access proxies. The deployment parameters are the parameters input by the business party for deploying the preset access proxy. For example, the business party can select and fill in the necessary deployment parameters on the proxy deployment page of the access platform according to the outbound requirements of the business to initiate an access proxy deployment request.

[0177] The deployment parameters include the preset proxy service cluster specified by the business party. For example, the cluster identifier of the preset proxy service cluster can be input, and the required preset proxy service cluster for access can be determined through the cluster identifier. The preset namespace can also be specified by the business party. The preset namespace can be, for example, namespace, the preset access configuration parameters for deploying the preset access proxy under the preset namespace, the preset service resources, etc. The node port is the node port of the preset access proxy in the preset proxy service cluster, and the internal traffic in the preset proxy service cluster K8s can access the preset access proxy through the node port. The proxy identifier is the identifier of the preset access proxy, and the proxy identifier can be generated based on the node port. For example, the node port can be used as the identifier of the preset access proxy. The proxy mode is the proxy mode of the preset access proxy, and the proxy mode can be a 7-layer proxy (HTTP protocol) or a 4-layer proxy (TCP / IP protocol (Transmission Control Protocol / Internet Protocol mode)). The image version parameters include the image name and the corresponding image version corresponding to the proxy mode of the preset access proxy. Different image versions can be used to deploy the corresponding service containers of the preset access proxy with different proxy modes. The storage parameters are the parameters defined by the business party for storage. The storage parameters can include error log storage parameters and correct log storage parameters for persistently storing the logs of the preset access proxy.

[0178] The number of proxy instances is the number of replicas of the preset access proxy specified by the business party to control the load balancing during the access process. The number of worker threads represents the number of worker threads of the preset access proxy, which can be set according to the CPU resource amount of the host where the preset access proxy is located.

[0179] In other embodiments, the deployment parameters further include: the enabled state of the host network mode (host_network). The service provider can determine whether to enable the host network mode based on its own business needs. The enabled state indicates whether the host network mode is enabled. The enabled state can include enabled and can also include disabled, which determines the network configuration of the Nginx proxy. For example, when the host network mode is disabled, the network isolation of the preset access proxy is better. When the host network mode is enabled, the network isolation of the preset access proxy is reduced, but the network performance is better.

[0180] Exemplarily, receive the access proxy deployment request initiated by the service provider, determine the deployment parameters from the access proxy deployment request, and deploy the preset access proxy according to the deployment parameters. The service provider can initiate an access proxy deployment request on the access platform to deploy the preset access proxy. The preset access proxy can be deployed in the preset proxy service cluster.

[0181] In this embodiment, by receiving the access proxy deployment request initiated by the service provider, it is convenient to deploy the preset access proxy according to the needs of the service provider, so that the preset access proxy can be flexibly deployed. And during the deployment process, only the service provider needs to input the necessary deployment parameters, and then the preset access proxy can be directly and automatically deployed based on the deployment parameters, improving the efficiency of the preset access proxy deployment.

[0182] In a feasible embodiment, step A20 further includes steps A21 to A26:

[0183] Step A21, query the proxy template corresponding to the proxy mode in the preset database according to the proxy mode;

[0184] It should be noted that there are multiple proxy templates in the preset database of the access platform. The access platform can search for the proxy template corresponding to the proxy mode in the preset database according to the proxy mode in the deployment parameters. For example, the proxy template can include a seven-layer proxy template and a four-layer proxy template. The proxy template can be used to define the working mode of the preset access proxy. The working mode includes the HTTP mode and the TCP / IP mode. Among them, the HTTP mode can be used to process HTTP requests and responses and is applicable to the seven-layer proxy (Layer 7Proxy, L7). The TCP / IP mode can be used to process TCP / IP traffic forwarding and is applicable to the four-layer proxy (Layer 4Proxy, L4).

[0185] Exemplarily, when the proxy mode is the four-layer proxy mode, the four-layer proxy template can be searched for in the preset database. When the proxy mode is the seven-layer proxy mode, the seven-layer proxy template can be searched for in the preset database.

[0186] Step A22, deploy the proxy environment variables of the preset access proxy according to the proxy template and the number of working threads;

[0187] It should be noted that the proxy environment variables are used to pass necessary parameters during the operation of the preset access proxy. For example, they are used to pass necessary parameters when the POD corresponding to the preset access proxy is started. The proxy environment variables include container group parameters and the number of worker processes. The container group parameter (POD_NAME) can be used to dynamically obtain the current instance name. The number of worker processes (WORKER_PROCESSES) determines the concurrent operation ability of the preset access proxy. The proxy environment variables can be substituted into the proxy template so that when the preset access proxy runs subsequently, the proxy environment variables can be directly used in the proxy template.

[0188] Exemplarily, the number of worker processes in the proxy environment variables can be deployed according to the number of worker threads, and at the same time, the container group parameters can be deployed in the proxy environment variables, and the deployed proxy environment variables are substituted into the proxy template to support the normal operation of the preset access proxy subsequently.

[0189] Step A23, configure the initial access configuration object of the preset access proxy in the preset namespace. Configure the preset default startup configuration item in the initial access configuration object to support the first startup of the preset access proxy, and determine the configuration value template corresponding to the initial access configuration object according to the proxy template. Update the configuration value template according to the node port in the deployment parameters to obtain the preset access configuration dictionary after the initial access configuration object is configured, so as to deploy the preset access configuration dictionary of the preset access proxy.

[0190] It should be noted that the initial access configuration object is a newly created access configuration object under the preset namespace, and the initial access configuration object can be configured to obtain the preset access configuration dictionary under the preset namespace. The preset default startup configuration item is used to support the first startup of the preset access proxy. For example, the preset default startup configuration item can be default.conf. The configuration value template is a predefined configuration file containing placeholders. The configuration value template provides a default configuration framework to ensure that Nginx can start normally. Different proxy modes correspond to different configuration value templates. The configuration value template corresponding to the proxy mode can also be found in the preset database, and the preset database stores the configuration value templates corresponding to different proxy modes in advance.

[0191] The placeholder of the node port in the configuration value template can be replaced with the node port in the deployment parameters, so as to facilitate the preset access proxy to listen to the node port. After configuring the preset default startup configuration item of the initial access configuration object and updating the configuration value template corresponding to the initial access configuration, the preset access configuration dictionary can be obtained, so that the preset access configuration dictionary can also be configured under the preset namespace.

[0192] Exemplarily, an initial access configuration object of a preset access proxy is configured under a preset namespace, and the initial access configuration object is configured to obtain a preset access configuration dictionary under the preset namespace. The steps of configuring the initial access configuration object include: configuring a preset default startup configuration item in the initial access configuration object, determining a configuration value template of the initial access configuration object according to a proxy template, and updating the configuration value template according to a node port. In other embodiments, the configured preset access configuration dictionary can also be stored in a preset database. When configuring the initial access configuration object under the preset namespace, the Kubernetes interface of a preset proxy service cluster can be called to configure the initial access object under the preset namespace.

[0193] In this embodiment, by automatically deploying the preset access configuration dictionary of the preset access proxy under the preset namespace according to the deployment parameters, the automatic configuration of the preset access configuration dictionary is realized, without manually configuring each configuration item in the preset access configuration dictionary, improving the configuration efficiency, and thus facilitating the subsequent improvement of the access efficiency of public network access.

[0194] Step A24: Deploy a log storage unit of the preset access proxy according to the storage parameters, where the log storage unit includes an error log storage unit and a correct log storage unit;

[0195] It should be noted that the storage parameters include error log storage parameters and correct log storage parameters. The error log storage parameters are used to deploy the error log storage unit, and the correct log storage parameters are used to deploy the correct log storage unit. The error log storage unit can be a PVC (Persistent Volume Claim) unit for storing error logs, and the correct log storage unit can be a PVC unit for storing correct logs.

[0196] Exemplarily, the corresponding error log PVC template can be queried according to the error log parameters, and the placeholder of the proxy mode and the node port can be replaced in the error log PCV template, so that the error log storage unit can be obtained. The corresponding correct log PVC template can be queried according to the correct log parameters, and the placeholder of the proxy mode and the node port can be replaced in the correct log PCV template, so that the correct log storage unit can be obtained. As a result, both the correct log storage unit and the error log storage unit are used to store the logs of the preset access proxy. Further, the Kubernetes interface of the preset proxy service cluster can be called to deploy both the correct log storage unit and the error log storage unit under the preset namespace. At the same time, the correct log storage unit and the error log storage unit can be associated with the preset access proxy and stored in the preset database, so that the storage unit corresponding to the preset access proxy can be found in the preset database subsequently. In this embodiment, by deploying the correct log storage unit and the error log storage unit under the preset namespace, the error logs and correct logs generated during the operation of the preset access proxy can be recorded, so that the access process of the preset access proxy can be traced subsequently, and it is also convenient to locate the error in time when the preset access proxy goes wrong, so as to improve the access efficiency.

[0197] Step A25: According to the proxy identifier, the number of proxy instances, the image version parameter, the node port, the proxy template, and the proxy environment variables, deploy the preset service resources of the preset access proxy in the preset namespace;

[0198] It should be noted that the preset service resource can be a Deployment, the preset service resource can be deployed under the preset namespace, and the preset access proxy can run in the preset service resource.

[0199] In a feasible embodiment, step A25 further includes step A251: Configure the initial service resource object in the preset namespace, and perform configuration operations on the initial service resource object to obtain the preset service resources deployed in the preset namespace;

[0200] Among them, the configuration operations include: Using the proxy identifier as the service resource identifier of the initial service resource object; According to the number of proxy instances, configure the number of service replicas corresponding to the initial service resource object; Configure a service container in the initial service resource, and configure the container image of the service container according to the image version parameter;

[0201] The configuration operations further include: According to the node port, configure the container port of the service container; Configure the container resources of the service container according to the proxy template, and configure the container environment variables of the service container according to the proxy environment variables; Configure the preset anti-affinity rule for the initial service resource object;

[0202] Among them, the preset anti-affinity rule includes that in the case where there are multiple service containers for the preset service resources, each service container is respectively assigned to a different host node.

[0203] It should be noted that the Kubernetes interface in the preset proxy service cluster can be called first to configure the initial service resource object in the preset namespace. The initial service resource object can be configured according to the proxy identifier, the number of proxy instances, the image version parameter, the node port, the proxy template, and the proxy environment variables to obtain the preset service resources deployed in the preset namespace.

[0204] The service resource identifier (metadata.name) is the identifier of the initial service resource object. The proxy identifier can be used as the service resource identifier of the initial service resource object. In other embodiments, the proxy identifier can also be used as the prefix in the service resource identifier of the initial service resource object, and the suffix of the service resource identifier can be the default identifier of the initial service resource object, such as Deployment. In other embodiments, the proxy identifier can be used as the suffix in the service resource identifier, and the prefix of the service resource identifier can be the default identifier of the initial service resource object. At the same time, the service resource label of the service resource identifier is added to the metadata.labels (metadata label) of the initial service resource object, so as to facilitate subsequent matching of the corresponding service container POD through the service resource label. The service resource identifiers of multiple PODs in the same initial service resource object can be the same, and the service resource labels can also be the same.

[0205] The number of proxy instances can be used as the number of service replicas spec.replicas of the initial service resource object. After setting the number of service replicas, the replica update rule of the initial service resource object can also be configured. The replica update rule includes setting the ratio of the maximum number of replicas exceeding the preset service resources (maxSurge, maximum number of replicas) to 25%, and the ratio of the maximum number of unavailable replicas (maxUnavailable, maximum number of unavailable replicas) to 0% to ensure that Nginx is always available during configuration or version changes and avoid service interruption. Service containers can be configured in the initial service resources. Specifically, the sub-worker containers containers of the service containers can be configured. The container image of the sub-worker containers can be configured according to the image version parameter. The service container can represent the environment where the sub-worker containers run. The container image of the sub-worker containers can be configured according to the image version parameter.

[0206] Exemplarily, the mirror repository address of the preset proxy service cluster can be obtained, and the mirror repository address and the mirror version parameter can be concatenated to obtain a mirror value, which can be used as the container image of the sub-worker container. Specifically, the mirror name and the mirror version in the mirror repository address and the mirror version parameter can be concatenated to obtain the mirror value. For example, the concatenated mirror value can be assigned to the field: spec.template.spec.containers.[0].image, so that when the preset proxy service cluster Kubernetes creates and manages service containers, this image can be used to start the sub-worker containers in the POD. To better understand this embodiment, an explanation of spec.template.spec.containers.[0].image is as follows: spec defines the number of replicas of the POD, and template defines the template of the POD. Kubernetes will create and manage the POD based on this template. For example, template includes the labels of the POD. [0] is the index in the POD, indicating the selection of the first sub-worker container in the POD. In Kubernetes, the array index starts from 0. So containers.[0] refers to the first container in the POD, and image is the mirror value.

[0207] The container port is the entry for accessing the sub-worker containers of the service container. Different sub-worker containers have different ports, and a service container can also include multiple sub-worker containers. The container port of each sub-worker container can be configured according to the node port. For example, the format of the container port of the sub-worker container can be: spec.template.spec.containers.[0].ports.[0].containerPort. Among them, spec defines the number of replicas of the POD, template defines the template of the POD, containers.[0] refers to the first sub-worker container in the POD, ports.[0] is the first container port to be exposed inside the sub-worker container, and containerPort is used to tell Kubernetes which port the service container is listening on internally. When creating a service to expose the POD, Kubernetes will forward the traffic in Kubernetes to the corresponding port inside the service container according to the port listened on by containerPort.

[0208] According to the proxy template, set the resource configuration of the service container. Specifically, the resource configuration of the sub-work containers within the service container can be set. The resource configuration of the sub-work containers (containers) can be set according to the proxy template. The resource configuration includes the number of requested CPU (Central Processing Unit) cores, the limited number of CPU cores, the requested memory size, the limited memory size, and the preset default resource quota. Configuring the resource configuration of the service container can facilitate ensuring that the preset access proxy can be started normally and can provide a certain concurrent processing performance for the preset access proxy.

[0209] Since the proxy modes are different, the target values corresponding to the number of requested CPU cores, the limited number of CPU cores, the requested memory size, the limited memory size, and the preset default resource quota in the resource configuration are different. Because different proxy modes consume different resources, the resource configuration of containers (containers) can be set according to the proxy mode. The target values corresponding to the number of requested CPU cores, the limited number of CPU cores, the requested memory size, the limited memory size, and the preset default resource quota in the resource configuration can be determined based on the proxy mode. This embodiment does not make specific limitations on this. For example, the field corresponding to the resource configuration of the containers in the service container can be: spec.template.spec.containers.[0].resources, which represents the resource configuration (resources) of the first sub-work container in the POD. This embodiment automatically determines the corresponding container resources according to the proxy mode, thereby improving the deployment efficiency of the preset access proxy.

[0210] In this embodiment, the container environment variables of the sub-work containers in the service container can also be configured according to the proxy environment variables of the preset access proxy. The container environment variables include: terminal timeout time, time zone, number of working threads, and instance name. Among them, for the terminal where the sub-work container is located, the terminal will be closed when there is no activity within the terminal timeout time. Determining the time zone in the container environment variables is to avoid log time confusion. The number of working threads in the container environment variables can be the number of working threads in the proxy environment variables. The number of threads of the preset access proxy will affect the concurrent processing ability and resource utilization rate of the proxy service. In other embodiments, the number of working threads can also be configured corresponding to the limited number of CPU cores. For example, if the limited number of CPU cores is 2, then the number of working threads can also be 2.

[0211] The instance name in the container environment variables of the sub - working container is used to store the name of the POD where the sub - working container is located, so as to facilitate the real - time acquisition of the POD name within the POD, store the log information generated within the container according to the POD name, and avoid overwriting the same log file when multiple PODs are running. In this embodiment, a preset anti - affinity rule is also configured for the initial service resource object. The preset anti - affinity rule includes that when there are multiple service containers in the preset service resource, each service container is allocated to a different host node respectively, so as to reduce the impact of the single - point failure of the host node and improve the fault - tolerance ability of the preset service resource. Specifically, the preset anti - affinity rule may include a preset scheduling rule, the weight of the preset scheduling rule, the matching conditions of the service container, and the scheduling strategy. Among them, the preset scheduling rule is the preference rule for the preset service resource to schedule PODs. The preset scheduling rule can be expressed as a field: preferredDuringSchedulingIgnoredDuringExecution. The meaning of this field is: try not to deploy multiple PODs of the same application on the same host node (for example, do not deploy multiple PODs with the same service resource identifier and the same service resource label on the same host node), but if resources are insufficient, it may still be deployed on the same host node, and even if there are already the same PODs running on the host node, the existing PODs will not be evicted.

[0212] The weight can represent the priority of the preset scheduling rule. The weight can be 100, indicating that when scheduling PODs, the PODs need to meet the preset scheduling rule. The matching conditions of the service container are: the service resource identifier is the same and the service resource label is the same. If the service resource identifiers and service resource labels of multiple PODs are the same, then the scheduling strategy can be executed on these PODs. The scheduling strategy is to schedule each POD to different host nodes respectively.

[0213] Exemplarily, an initial service resource object is configured within a preset namespace, and the initial service resource object is configured to obtain a preset service resource configured with a service resource identifier, a number of service replicas, a service container, a container image of a sub-worker container in the service container, a container port of the sub-worker container, container environment variables of the sub-worker container, and a preset anti-affinity rule. Further, in this embodiment, a preset access configuration dictionary, an error log storage unit, and a correct log storage unit may also be added to the list of mounted data volumes (spec.template.spec.volumes) of the preset service resource Deployment, including: a volume name and a volume configuration. The volume name is the name of the list of mounted data volumes, and the volume name can be set based on the actual situation. The volume configuration includes the name of the preset access configuration resource, the names of the error log storage unit and the correct log storage unit. Mounting to the list of mounted data volumes of the preset service resource Deployment helps the preset access proxy update the preset access configuration dictionary by mounting it in the list of mounted data volumes to achieve timely update of the preset access configuration dictionary, and also facilitates persistent storage of the error log storage unit and the correct log storage unit to avoid loss of logs after the service container restarts, which may affect the troubleshooting of user business problems.

[0214] It is also possible to set the data volume of the sub-worker container and mount the data volume of the sub-worker container to the preset service resource as well. The data volume of the sub-worker container includes a volume name, a mount path, and a sub-path of the sub-worker container within the service container. Among them, the volume name is the same as the volume name for mounting the preset access configuration dictionary. The mount path is the path where the service container where the sub-worker container is located is mounted to the preset service resource, and the sub-path is the path of the sub-worker container within the service container. Mounting the data volume of the sub-worker container to the preset service resource facilitates writing the running logs of different service containers into their respective corresponding directories in the error log storage unit and the correct log storage unit.

[0215] Step A26, deploy the preset service exposure data of the preset access proxy in the preset namespace according to the proxy identifier and the node port.

[0216] It should be noted that deploying the preset service exposure data facilitates stable external access to the preset access proxy. For example, it facilitates stable access to the preset access proxy by the client where the business party is located, so as to use the preset access proxy to access the target public network. The preset service exposure data is also set in the preset namespace, so that it can be associated with the preset access proxy. For example, the Kubernetes interface of the preset proxy service cluster can be called to deploy the preset service exposure data of the preset access proxy under the preset namespace according to the proxy identifier and the node port. Deploying the preset service exposure data can shield changes in the backend. For example, it can shield changes such as automatic restart of POD failures and service configuration updates.

[0217] In a feasible embodiment, step A26 further includes steps A261 to A263:

[0218] Step A261, deploy an initial service exposure object within a preset namespace, configure the service exposure identifier of the initial service exposure object according to the proxy identifier, and configure the service exposure port of the initial service exposure object according to the node port, where the service exposure port is the entry for accessing the preset access proxy;

[0219] Step A262, associate the service exposure port with the container port in the preset service resource to obtain the exposure port mapping relationship of the initial service exposure object, and deploy a preset label selector in the initial service exposure object, where the preset label selector is used to associate the service container corresponding to the initial service exposure object;

[0220] Step A263, use the initial service exposure object configured with the service exposure identifier, service exposure port, exposure port mapping relationship, and preset label selector as the preset service exposure data.

[0221] It should be noted that the Kubernetes interface of the preset proxy service cluster can be called to first deploy the initial service exposure object under the preset namespace and configure the initial service exposure object, so as to obtain the configured preset service exposure data. For example, the preset service exposure data can be a Service resource.

[0222] The service exposure identifier can be used to distinguish different initial service exposure objects. The proxy identifier can be used as the prefix in the service exposure identifier of the initial service exposure object, and the suffix of the service exposure identifier can be the default identifier of the initial service exposure object, such as service. In other embodiments, the proxy identifier can be used as the suffix in the service exposure identifier, and the prefix of the service exposure identifier can be the default identifier of the initial service exposure object. The node port can be set as the service exposure port of the initial service, so that devices that need to access the Nginx proxy subsequently can access the Nginx proxy through the service exposure port. For example, the client where the business party is located can access the Nginx proxy through the service exposure port and the access proxy address of the Nginx proxy.

[0223] The exposure port mapping relationship is the mapping relationship between the service exposure port and the container port in the preset service resource. If there are multiple container ports in the preset service resource, then multiple container ports are all mapped to the service exposure port correspondingly, so as to facilitate entry through the service exposure port, and then determine the container port corresponding to the service exposure port from the exposure port mapping relationship, so as to access the preset access proxy through the container port.

[0224] The preset label selector can be configured according to the service resource identifier and service resource label in the preset service resources, so that the preset label selector can associate each service container with the same service resource identifier and the same service resource label with the initial service exposure object. For example, these service containers can be added to the Endpoint list of the initial service exposure object, which is convenient for unified management of each service container with the same service resource identifier and the same service resource label. For example, the preset label selector can be spec.selector. Among them, Endpoint can be used to record the IP address and port of the POD actually providing services in the K8s cluster.

[0225] Exemplarily, the initial service exposure object configured with the service exposure identifier, service exposure port, exposure port mapping relationship, and preset label selector can be used as the preset service exposure data. The preset service exposure data is deployed in the preset namespace. Further, the preset service exposure data is associated with the preset access proxy and stored in the preset database. This is convenient for finding the preset service exposure data corresponding to the preset access proxy in the preset database.

[0226] In this embodiment, by deploying the preset service exposure data of the preset access proxy, it is convenient for the external to access the preset access proxy through the service exposure port and the exposure port mapping relationship, so as to facilitate subsequent access to the target public network, and further improve the efficiency of accessing the target public network. For a better understanding of this embodiment, please refer to Figure 2, the process of establishing an access link in this embodiment will be briefly described. The service party can execute step Y10: initiate an access proxy deployment request. The service party can be a user who needs to access the public network. The platform can respond to the access proxy deployment request and execute step Y20: automatically deploy a preset access proxy, including a preset access configuration dictionary, a log storage unit, preset service resources, and a preset service exposure object of the preset access proxy. Among them, the log storage unit includes an error log storage unit and a correct log storage unit. That is, the platform can realize the automatic deployment of the preset access proxy. After the preset access proxy is deployed, the service party can execute step Y30: initiate an access link application request. The platform can respond to the access link application request and execute step Y40: automatically determine the target access configuration dictionary and generate an access work order. For example, the platform can update the preset access configuration dictionary of the preset access proxy to the target access configuration dictionary, and based on the target access configuration dictionary and the access link application request, generate an access work order. The platform can push the access work order to the supervisor for approval. For example, the supervisor can execute step Y50: approve the access work order and determine the approval result; the supervisor can be an operation and maintenance personnel, and the operation and maintenance personnel can approve whether the target access configuration dictionary is reasonable and whether the initiated access link application request is reasonable to confirm whether the access work order is approved. If it is confirmed that the approval is not passed, it can be fed back to the platform, and the platform can feed it back to the service party to prompt the service party that the approval is not passed. If the supervisor determines that the access work order is approved, step Y60 can be executed: confirm that the approval result is passed, and at the same time, the passed approval result can be fed back to the platform so that the platform can execute step Y70: automatically determine the in-group domain name mapping relationship. The service party can execute step Y80: confirm that the target access configuration dictionary can be published to the preset proxy service cluster. That is, the service party can trigger a confirmation configuration instruction for the target access configuration dictionary. When the service party confirms that the target access configuration dictionary is published to the preset proxy service cluster, the service party can trigger a confirmation configuration instruction for the target access configuration dictionary. After the service party confirms that the target access configuration dictionary can be published to the preset proxy service cluster, the platform can execute step Y90: perform a reload test on the target access configuration dictionary. To test whether the syntax and configuration of the target access configuration dictionary are accurate. The platform performs a reload test on the target access configuration dictionary and can generate a reload result. If the reload result includes a successful reload, it can be determined that the reload test is passed. If the reload test is passed, the service party can confirm step Y100: after the reload test is passed, confirm that the target public network can be accessed through the access link. It should be noted that after the reload test is passed, it means that the access link is established, and the target public network can be accessed through the preset access proxy, the target access configuration dictionary, and the in-group mapping relationship. The platform can be an access platform, and the access platform can be the platform where the preset proxy service cluster Kubernetes is located.

[0227] Further, reference can also be made to Figure 3 , and multiple modules can also be involved in the access platform. For example, referring to Figure 3 it can include 6 modules, namely Z10 to Z60. Z10 to Z60 are respectively: Nginx proxy management, preset access configuration dictionary management, access link application, approval management, in-cluster domain name management of K8s, and target access configuration dictionary management. Among them, Nginx proxy management means deploying a preset access proxy based on the deployment parameters of the business party. For example, the error log storage unit, correct log storage unit, preset service resources and preset service exposure data of the deployed preset access proxy, etc. The module of preset access configuration dictionary management means associating the preset access configuration dictionary with the preset access proxy and managing each configuration item in the preset access configuration dictionary, etc. The module of access link application means receiving the access link application initiated by the business party and generating an access work order to be passed to the module of approval management. The module of approval management means pushing the access work order to the regulatory party for approval. The module of in-cluster domain name management of K8s means generating the in-cluster domain name mapping relationship of K8s. The module of target access configuration dictionary management means performing a reload test on the target access configuration dictionary, and after successful reload, publishing the target access configuration dictionary to K8s.

[0228] The embodiment of the present application also provides a public network access device. Please refer to Figure 4 , the device includes:

[0229] A receiving module 10, configured to receive an access link application request initiated by a business party, and determine from the access link application request a preset access proxy, a preset access configuration dictionary associated with the preset access proxy, a cluster domain name of the preset access proxy in a preset proxy service cluster, and a public network address range of the target public network to be accessed by the business party; a configuration module 20, configured to update the preset access configuration dictionary according to the preset access proxy and the public network address range to obtain a target access configuration dictionary; a mapping module 30, configured to find an access proxy address corresponding to the preset access proxy in the preset proxy service cluster and associate the access proxy address with the cluster domain name to obtain an in-cluster domain name mapping relationship of the preset proxy service cluster; a link determination module 40, configured to generate an access link to the target public network according to the in-cluster domain name mapping relationship, the preset access proxy, and the target access configuration dictionary, so as to access the target public network through the access link.

[0230] The public network access device provided by the embodiment of the present application adopts the public network access method in the above embodiment, aiming to solve the technical problem of low efficiency in accessing the public network. Compared with the prior art, the beneficial effects of the public network access method provided by the embodiment of the present application are the same as those of the public network access method provided by the above embodiment, and other technical features in the public network access device are the same as those disclosed in the above embodiment method, which will not be elaborated here.

[0231] The present application provides an electronic device, which includes: at least one processor; and a memory communicatively connected to the at least one processor; wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to execute the public network access method in the first embodiment above.

[0232] Refer to the following Figure 5 , which shows a schematic structural diagram of an electronic device suitable for implementing the embodiment of the present application. The electronic device in the embodiment of the present application may include, but is not limited to, mobile terminals such as mobile phones, laptop computers, digital broadcast receivers, PDAs (Personal Digital Assistants), PADs (Portable Application Descriptions), PMPs (Portable Media Players), vehicle-mounted terminals (such as vehicle-mounted navigation terminals), etc., and fixed terminals such as digital TVs, desktop computers, etc. Figure 5 The electronic device shown is only an example and should not impose any limitation on the functions and usage scope of the embodiment of the present application.

[0233] As shown in Figure 5As shown, the electronic device may include a processing device 1001 (such as a central processing unit, a graphics processing unit, etc.), which may perform various appropriate actions and processes according to the program stored in the read-only memory 1002 or the program loaded from the storage device 1003 into the random access memory 1004. In the random access memory 1004, various programs and data required for the operation of the electronic device are also stored. The processing device 1001, the read-only memory 1002, and the random access memory 1004 are connected to each other through a bus 1005. The input / output interface 1006 is also connected to the bus. Generally, the following systems may be connected to the input / output interface 1006: an input device 1007 including, for example, a touch screen, a touchpad, a keyboard, a mouse, an image sensor, a microphone, an accelerometer, a gyroscope, etc.; an output device 1008 including, for example, a liquid crystal display (LCD: Liquid Crystal Display), a speaker, a vibrator, etc.; a storage device 1003 including, for example, a magnetic tape, a hard disk, etc.; and a communication device 1009. The communication device 1009 may allow the electronic device to communicate with other devices wirelessly or wiredly to exchange data. Although the figure shows an electronic device having various systems, it should be understood that it is not required to implement or have all the systems shown. Instead, more or fewer systems may be implemented or had. In particular, according to the embodiments disclosed in the present application, the processes described above with reference to the flowcharts may be implemented as computer software programs. For example, the embodiments disclosed in the present application include a computer program product, which includes a computer program carried on a computer-readable medium, and the computer program contains program codes for executing the methods shown in the flowcharts. In such an embodiment, the computer program may be downloaded and installed from the network through the communication device, or installed from the storage device 1003, or installed from the read-only memory 1002. When the computer program is executed by the processing device 1001, the above functions defined in the methods of the embodiments disclosed in the present application are executed. The electronic device provided in the present application adopts the public network access method in the above embodiments and can solve the technical problem of low efficiency in accessing the public network. Compared with the prior art, the beneficial effects of the electronic device provided in the present application are the same as those of the public network access method provided in the above embodiments, and other technical features in the electronic device are the same as those disclosed in the previous embodiment method, and will not be elaborated here.

[0234] It should be understood that each part disclosed in this application can be implemented by hardware, software, firmware, or a combination thereof. In the description of the above embodiments, specific features, structures, materials, or characteristics can be combined in a suitable manner in any one or more embodiments or examples. The above is only the specific implementation manner of this application, but the protection scope of this application is not limited thereto. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in this application, and all should be covered by the protection scope of this application. Therefore, the protection scope of this application shall be subject to the protection scope of the claims. This embodiment provides a computer-readable storage medium having computer-readable program instructions stored thereon, and the computer-readable program instructions are used to execute the public network access method in the first embodiment above.

[0235] The computer-readable storage medium provided by the embodiments of this application can be, for example, a USB flash drive, but is not limited to electrical, magnetic, optical, electromagnetic, infrared, or semiconductor devices, apparatuses, or components, or any combination of the above. More specific examples of the computer-readable storage medium may include, but are not limited to: an electrical connection having one or more wires, a portable computer disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable EPROM (Electrical Programmable Read Only Memory), or a flash memory, an optical fiber, a portable compact disk CD-ROM (compact disk read-only memory), an optical storage device, a magnetic storage device, or any suitable combination of the above. In this embodiment, the computer-readable storage medium can be any tangible medium that contains or stores a program, and this program can be used by or combined with an instruction execution device, apparatus, or component. The program code contained on the computer-readable storage medium can be transmitted by any appropriate medium, including but not limited to: wires, optical cables, RF (Radio Frequency), etc., or any suitable combination of the above. The above computer-readable storage medium can be included in an electronic device; or it can exist separately without being assembled into the electronic device.

[0236] The above computer-readable storage medium carries one or more programs, which, when executed by an electronic device, cause the electronic device to: receive an access link application request initiated by a service party, determine from the access link application request a preset access proxy, a preset access configuration dictionary associated with the preset access proxy, a cluster domain name of the preset access proxy within a preset proxy service cluster, and a public network address range of a target public network to be accessed by the service party; update the preset access configuration dictionary according to the preset access proxy and the public network address range to obtain a target access configuration dictionary; find an access proxy address corresponding to the preset access proxy in the preset proxy service cluster, and associate the access proxy address with the cluster domain name to obtain an intra-cluster domain name mapping relationship of the preset proxy service cluster; generate an access link to the target public network according to the intra-cluster domain name mapping relationship, the preset access proxy, and the target access configuration dictionary, so as to access the target public network through the access link.

[0237] Computer program code for performing the operations of the present disclosure may be written in one or more programming languages or combinations thereof. The programming languages include object-oriented programming languages such as Java, Smalltalk, C++, and also include conventional procedural programming languages such as the "C" language or similar programming languages. The program code may execute entirely on the user's computer, partially on the user's computer, execute as a stand-alone software package, execute partially on the user's computer and partially on a remote computer, or execute entirely on a remote computer or server. In the case of a remote computer, the remote computer may be connected to the user's computer through any type of network, including a LAN (local area network) or a WAN (Wide Area Network), or may be connected to an external computer (for example, by connecting through an Internet service provider using the Internet). The flowcharts and block diagrams in the accompanying drawings illustrate the possible architectures, functions, and operations of devices, methods, and computer program products according to various embodiments of the present application. In this regard, each block in the flowchart or block diagram may represent a module, a program segment, or a part of code that contains one or more executable instructions for implementing a specified logical function. It should also be noted that, in some alternative implementations, the functions marked in the blocks may occur in a different order than marked in the accompanying drawings. For example, two consecutive blocks shown may actually execute substantially in parallel, and they may sometimes execute in the reverse order, depending on the functions involved. It should also be noted that each block in the block diagram and / or flowchart, and the combinations of blocks in the block diagram and / or flowchart, may be implemented by a dedicated hardware-based device for performing the specified functions or operations, or may be implemented by a combination of dedicated hardware and computer instructions.

[0238] The modules involved in the embodiments of the present disclosure can be implemented in software or in hardware. In some cases, the name of the module does not constitute a limitation on the unit itself. The computer-readable storage medium provided in the embodiments of the present application stores computer-readable program instructions for executing the above-mentioned public network access method, aiming to solve the technical problem of low efficiency in accessing the public network. Compared with the prior art, the beneficial effects of the computer-readable storage medium provided in the embodiments of the present application are the same as those of the public network access method provided in the above embodiments, and will not be elaborated here.

[0239] The embodiments of the present application also provide a computer program product, including a computer program, which implements the steps of the public network access method as described above when executed by a processor. The computer program product provided in the embodiments of the present application aims to solve the technical problem of low efficiency in accessing the public network. Compared with the prior art, the beneficial effects of the computer program product provided in the embodiments of the present application are the same as those of the public network access method provided in the above embodiments, and will not be elaborated here.

[0240] The above are only the preferred embodiments of the embodiments of the present application, and do not limit the patent scope of the embodiments of the present application. Any equivalent structural or equivalent process transformation made by using the description and drawings of the embodiments of the present application, or directly or indirectly applied to other related technical fields, shall be similarly included in the patent scope of the embodiments of the present application.

Claims

1. A public network access method, characterized in that, The method described above includes: Receiving an access link application request initiated by a service provider, and determining from the access link application request a preset access proxy, a preset access configuration dictionary associated with the preset access proxy, a cluster domain name of the preset access proxy within a preset proxy service cluster, and a public network address range of a target public network that the service provider needs to access; Updating the preset access configuration dictionary according to the preset access proxy and the public network address range to obtain a target access configuration dictionary; Searching for an access proxy address corresponding to the preset access proxy in the preset proxy service cluster, and associating the access proxy address with the cluster domain name to obtain an in-cluster domain name mapping relationship of the preset proxy service cluster; Generating an access link to the target public network according to the in-cluster domain name mapping relationship, the preset access proxy, and the target access configuration dictionary, so as to access the target public network through the access link.

2. The public network access method according to claim 1, characterized in that The step of updating the preset access configuration dictionary according to the preset access proxy and the public network address range to obtain a target access configuration dictionary includes: In the case where there is no configuration item corresponding to the preset access proxy in the preset access configuration dictionary, querying an access routing template corresponding to the proxy mode according to the proxy mode of the preset access proxy; Determining a public network address set of the public network address range, and updating a preset address mapping template according to the public network address set and a public network port of the obtained target public network to obtain a target address mapping relationship; Replacing a preset routing address placeholder in the access routing template with the target address mapping relationship, and replacing a preset proxy parameter placeholder in the access routing template with a proxy parameter corresponding to the obtained preset access proxy to obtain a target access configuration dictionary; Wherein, the proxy parameter includes at least one of a node port of the preset access proxy, a proxy protocol, a cluster domain name, and a cluster identifier of the preset proxy service cluster.

3. The public network access method according to claim 2, wherein The step of determining the public network address set of the public network address range includes: Determining a public network start address and a public network end address from the public network address range; Converting the public network start address into a start long integer, and converting the public network end address into an end long integer; For each intermediate long integer between the start long integer and the end long integer, converting the intermediate long integer into an intermediate address; Determining a public network address set constructed by the public network start address, the public network end address, and each intermediate address corresponding to the intermediate long integer.

4. The public network access method according to claim 3, wherein The step of converting the public network start address into a start long integer, and converting the public network end address into an end long integer includes: For any target address, sequentially determining a first target byte, a second target byte, a third target byte, and a fourth target byte from the target address; Calculate the product of the cube of the preset value and the first target byte to obtain a first integer, calculate the product of the square of the preset value and the second target byte to obtain a second integer, calculate the product of the preset value and the third target byte to obtain a third integer, and calculate the product of the zero power of the preset value and the fourth target byte to obtain a fourth integer; Accumulate the first integer, the second integer, the third integer, and the fourth integer to obtain the target long integer of the target address; Wherein, when the target address is the public network start address, the target long integer is the start long integer, and when the target address is the public network end address, the target long integer is the end long integer.

5. The public network access method according to claim 3, characterized in that, The step of converting each intermediate long integer between the start long integer and the end long integer into an intermediate address includes: Determine any one of the intermediate long integers as the target long integer among the intermediate long integers. For each target long integer, take the remainder of the target long integer by the preset value to obtain a byte; Right-shift the target long integer by a preset number of bits to obtain a target right-shifted long integer, update the target long integer to the target right-shifted long integer, and return the step of taking the remainder of the target long integer by the preset value to obtain a byte until a preset number of bytes are obtained; Sort each of the bytes in the order of taking the remainder, and obtain a sorting result, where the order of taking the remainder of the byte sorted earlier is earlier than the order of taking the remainder of the byte sorted later; Concatenate each of the bytes in the order from largest to smallest in the sorting result to obtain the intermediate address of the target long integer.

6. The public network access method according to claim 1, wherein The access proxy address includes a plurality of container addresses. The step of finding the access proxy address corresponding to the preset access proxy in the preset proxy service cluster includes: When receiving the approval result of the access work order by the operation and maintenance personnel and the approval result is passed, find the preset service resource corresponding to the preset access proxy in the preset proxy service cluster, where the access work order is generated based on the access link application request and the target access configuration dictionary; Obtain the service container set of the preset access proxy from the preset service resource, and extract the container address of each service container in the service container set.

7. The public network access method according to claim 1, wherein Both the preset access proxy and the preset access configuration dictionary are deployed in the preset namespace of the preset proxy service cluster; The step of generating the access link of the target public network according to the in-group domain name mapping relationship, the preset access proxy, and the target access configuration dictionary includes: After receiving the confirmation configuration instruction of the business party for the target access configuration dictionary, update the configuration item identifier of the configuration item in the target access configuration dictionary according to the cluster domain name corresponding to the preset access proxy; Under the preset namespace of the preset proxy service cluster, update the preset access configuration dictionary under the preset namespace to the target access configuration dictionary, and adjust the configuration status of the target access configuration dictionary to the published state, where the published state indicates that the target access configuration dictionary has been configured in the preset proxy service cluster; When the configuration status of the target access configuration dictionary is the published status, execute a preset test reload command in the service container under the preset namespace to perform a test reload on the target access configuration dictionary; After a preset duration, obtain the reload result after the test reload of the target access configuration dictionary. When the reload result includes a successful reload, determine the access link of the target public network composed of the in-group domain name mapping relationship, the preset access proxy, and the target access configuration dictionary; Wherein, the successful reload indicates that the target access configuration dictionary is correctly configured.

8. The public network access method according to claim 1, characterized in that, The public network access method further includes: Receive an access proxy deployment request initiated by a business party, and determine deployment parameters from the access proxy deployment request; Deploy a preset access proxy according to the deployment parameters; Wherein, the deployment parameters include: a preset proxy service cluster where the preset access proxy is located, a preset namespace and node port of the preset access proxy in the preset proxy service cluster, a proxy mode of the preset access proxy, a proxy identifier, an image version parameter, a storage parameter, the number of proxy instances, and the number of worker threads.

9. The public network access method according to claim 8, wherein The step of deploying a preset access proxy according to the deployment parameters includes: Query a proxy template corresponding to the proxy mode in a preset database according to the proxy mode; Deploy the proxy environment variables of the preset access proxy according to the proxy template and the number of worker threads; Configure an initial access configuration object of the preset access proxy in a preset namespace, configure a preset default startup configuration item in the initial access configuration object to support the first startup of the preset access proxy, determine a configuration value template corresponding to the initial access configuration object according to the proxy template, and update the configuration value template according to the node port in the deployment parameters to obtain a preset access configuration dictionary after the initial access configuration object is configured, so as to deploy the preset access configuration dictionary of the preset access proxy; Deploy a log storage unit of the preset access proxy according to the storage parameter, wherein the log storage unit includes an error log storage unit and a correct log storage unit; Deploy preset service resources of the preset access proxy in the preset namespace according to the proxy identifier, the number of proxy instances, the image version parameter, the node port, the proxy template, and the proxy environment variables; Deploy preset service exposure data of the preset access proxy in the preset namespace according to the proxy identifier and the node port.

10. The public network access method according to claim 9, wherein, The step of deploying preset service resources of the preset access proxy in the preset namespace according to the proxy identifier, the number of proxy instances, the image version parameter, the node port, the proxy template, and the proxy environment variables includes: Configure an initial service resource object in the preset namespace, and perform a configuration operation on the initial service resource object to obtain preset service resources deployed in the preset namespace; Among them, the configuration operation includes: using the proxy identifier as the service resource identifier of the initial service resource object; configuring the number of service replicas corresponding to the initial service resource object according to the number of proxy instances; configuring a service container in the initial service resource, and configuring the container image of the service container according to the image version parameter; The configuration operation further includes: configuring the container port of the service container according to the node port; configuring the container resources of the service container according to the proxy template, and configuring the container environment variables of the service container according to the proxy environment variables; configuring a preset anti-affinity rule for the initial service resource object; Among them, the preset anti-affinity rule includes that in the case where there are multiple service containers in the preset service resource, each of the service containers is allocated to a different host node.

11. The public network access method according to claim 9, wherein, The step of deploying the preset service exposure data of the preset access proxy in the preset namespace according to the proxy identifier and the node port includes: Deploying an initial service exposure object in the preset namespace, configuring the service exposure identifier of the initial service exposure object according to the proxy identifier, and configuring the service exposure port of the initial service exposure object according to the node port, where the service exposure port is the entry for accessing the preset access proxy; Associating the service exposure port with the container port in the preset service resource to obtain the exposure port mapping relationship of the initial service exposure object, and deploying a preset label selector in the initial service exposure object, where the preset label selector is used to associate the service container corresponding to the initial service exposure object; Using the initial service exposure object configured with the service exposure identifier, the service exposure port, the exposure port mapping relationship, and the preset label selector as the preset service exposure data.

12. A public network access device, characterized in that, The described device includes: A receiving module, configured to receive an access link application request initiated by a service party, and determine a preset access proxy, a preset access configuration dictionary associated with the preset access proxy, a cluster domain name of the preset access proxy in a preset proxy service cluster, and a public network address range of a target public network to be accessed by the service party from the access link application request; A configuration module, configured to update the preset access configuration dictionary according to the preset access proxy and the public network address range to obtain a target access configuration dictionary; A mapping module, configured to find an access proxy address corresponding to the preset access proxy in the preset proxy service cluster, and associate the access proxy address with the cluster domain name to obtain an in-cluster domain name mapping relationship of the preset proxy service cluster; A link determination module, configured to generate an access link to the target public network according to the in-cluster domain name mapping relationship, the preset access proxy, and the target access configuration dictionary, so as to access the target public network through the access link.

13. An electronic device, characterized in that, The electronic device includes: At least one processor; And a memory communicatively connected to the at least one processor; Wherein, the memory stores instructions executable by the at least one processor, and the instructions are executed by the at least one processor to enable the at least one processor to perform the steps of the public network access method according to any one of claims 1 to 11.

14. A storage medium, characterized in that, The storage medium is a computer-readable storage medium, and a program for implementing the public network access method is stored on the computer-readable storage medium. The program for implementing the public network access method is executed by a processor to implement the steps of the public network access method according to any one of claims 1 to 11.

15. A program product, characterized in that, The program product is a computer program product. The computer program product includes a computer program, and when the computer program is executed by a processor, the steps of the public network access method according to any one of claims 1 to 11 are implemented.