Message processing system, proxy server deployment method, electronic device and medium

Through the combination of progressive deployment and message queue replication components, the problems of large failure and explosion radius and large RPO in multi-data center deployment are solved, and a high availability and flexible message processing system is realized, suitable for message services in multi-data centers.

CN120378306APending Publication Date: 2025-07-25HANGZHOU ALICLOUD FEITIAN INFORMATION TECH CO LTD
View PDF 0 Cites 0 Cited by

Patent Information

Application Number
CN202410063204.3
Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-01-16
Publication Date
2025-07-25

AI Technical Summary

Technical Problem

The existing technology has problems such as large failure and explosion radius, one-step planning and layout, large RPOs in off-site disaster preparedness centers, and inability to selectively copy data in multi-data center deployment, resulting in poor executability and scalability of the system during actual implementation.

Method used

The progressive deployment method is adopted, first deploying the first message service cluster in the same city and dual centers, and then deploying the second message service cluster in the remote location. The message queue replication component is used to achieve selective data synchronization. The off-site disaster preparedness center and the same city and dual centers are independent clusters, reducing the fault radius, and high-availability disaster recovery switching is achieved through the majority consensus protocol.

Benefits of technology

It has achieved good executability and scalability in actual implementation, reduced the fault radius, reduced the recovery point target of off-site disaster preparedness centers, and improved the high availability and flexibility of the system.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN120378306A_ABST
    Figure CN120378306A_ABST
Patent Text Reader

Abstract

The invention provides a message processing system, a proxy server deployment method, electronic equipment and a medium, and the system comprises a first main proxy server which is deployed in a first data center; message copies of the first main proxy server and the first standby proxy server are deployed in a second data center, the first data center and the second data center are located in a first service area, and the first main proxy server and the first standby proxy server belong to a first message service cluster; the second proxy server is deployed in a third data center and belongs to a second message service cluster, and the third data center is located in a second service area; the client is used for producing a message and a consumption message based on the first main proxy server in a normal service mode; generating a message and a consumption message based on the first standby proxy server in the city-wide disaster recovery mode; in the remote disaster recovery mode, the message and the consumption message are generated based on the second proxy server, high availability and high reliability can be guaranteed, and meanwhile high flexibility, performability and expansibility are achieved.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] This application relates to the technical field of data centers, and particularly to a message processing system, a method for deploying a proxy server, an electronic device, and a storage medium. Background Art

[0002] In recent years, with the continuous improvement of digital infrastructure and the emphasis on data availability and reliability, multi-computer room, multi-region, multi-data center, etc. have increasingly become the choice solutions for users. By deploying applications in different regions or computer rooms, users can obtain capabilities such as disaster tolerance, data redundancy, and data isolation. Therefore, how to provide highly available message services based on the deployment of multiple data centers is particularly important. Summary of the Invention

[0003] Embodiments of this application provide a message processing system, a method for deploying a proxy server, an electronic device, and a storage medium to alleviate or solve one or more technical problems existing in the prior art.

[0004] In a first aspect, embodiments of this application provide a message processing system, including: a first primary proxy server deployed in a first data center; a first standby proxy server, which is a message copy of the first primary proxy server and is deployed in a second data center, where the first data center and the second data center are both located in a first service area, and the first primary proxy server and the first standby proxy server belong to a first message service cluster; a second proxy server deployed in a third data center and belonging to a second message service cluster, where the third data center is located in a second service area; a client, when the message processing system is in a normal service mode, the client produces and consumes messages based on the first primary proxy server; when the message processing system is in a local disaster tolerance mode, the client produces and consumes messages based on the first standby proxy server; when the message processing system is in a remote disaster tolerance mode, the client produces and consumes messages based on the second proxy server.

[0005] In a second aspect, an embodiment of the present application provides a proxy server deployment method, including: obtaining a deployment status, wherein the deployment status includes a first deployment status and a second deployment status, the first deployment status being that a primary proxy server and a backup proxy server having a primary-backup topology relationship are both deployed in a first data center, and the second deployment status being that a primary proxy server and a backup proxy server having a primary-backup topology relationship are respectively deployed in the first data center and the second data center; in response to a change request for the first deployment status to be changed to the second deployment status, updating the primary proxy server and the backup proxy server in the first data center to be the first primary proxy server, and running multiple proxy servers in the second data center as the first backup proxy server; wherein the first backup proxy server is a message copy of the first primary proxy server, the first data center and the second data center are both located in a first service area, and the first primary proxy server and the first backup proxy server belong to a first message service cluster; in a normal service mode, the client produces and consumes messages based on the first primary proxy server, and in a same-city disaster recovery mode, the client produces and consumes messages based on the first backup proxy server.

[0006] In a third aspect, an embodiment of the present application provides an electronic device, including a memory, a processor, and a computer program stored in the memory, and the processor implements the method provided in any embodiment of the present application when executing the computer program.

[0007] In a fourth aspect, an embodiment of the present application provides a computer-readable storage medium, in which a computer program is stored. When the computer program is executed by a processor, the method provided in any embodiment of the present application is implemented.

[0008] In a fifth aspect, an embodiment of the present application provides a computer program product, including a computer program, which, when executed by a processor, implements the method provided in any embodiment of the present application.

[0009] According to the message processing system of the embodiment of the present application, the dual centers in the same city are the first data center and the second data center, and the first message service cluster (Cluster1) is deployed. The first data center deploys a main proxy server to provide normal services, and the second data center deploys a backup proxy server as the disaster recovery center in the same city. The disaster recovery center in a different place is the third data center, and the second message service cluster (Cluster2) is deployed. Therefore, the first message service cluster (Cluster1) can be built first, and then the second message service cluster (Cluster2) can be built in a progressive manner. The intermediate message service is uninterrupted, and the layout and planning of all components do not need to be completed in advance. It has good executability and scalability in the actual implementation process. In addition, in response to the problem of a large fault explosion radius caused by all components in the same message service cluster, the disaster recovery center in a different place and the dual centers in the same city in the embodiment of the present application are two completely independent message service clusters that do not affect each other. Therefore, the fault radius can be effectively reduced.

[0010] The above summary is for illustrative purposes only and is not intended to be limiting in any way. In addition to the illustrative aspects, embodiments and features described above, further aspects, embodiments and features of the present application will be readily apparent by reference to the accompanying drawings and the following detailed description. BRIEF DESCRIPTION OF THE DRAWINGS

[0011] In the accompanying drawings, unless otherwise specified, the same reference numerals throughout the multiple drawings represent the same or similar parts or elements. These drawings are not necessarily drawn to scale. It should be understood that these drawings only depict some embodiments disclosed in the present application and should not be regarded as limiting the scope of the present application.

[0012] Figure 1 An architectural diagram showing a distributed message processing system;

[0013] Figure 2 An architectural diagram showing another distributed message processing system;

[0014] Figure 3 An architecture diagram of a message processing system provided by an embodiment of the present application is shown;

[0015] Figure 4 An architecture diagram of another message processing system provided by an embodiment of the present application is shown;

[0016] Figure 5 A schematic diagram showing the state switching of a replica replication state machine record;

[0017] Figure 6 A schematic diagram showing the working status of the message queue replication component;

[0018] Figure 7 A schematic diagram showing off-site disaster tolerance switching of a message processing system according to an embodiment of the present application;

[0019] Figure 8 A flowchart showing a proxy server deployment method provided by an embodiment of the present application;

[0020] Figure 9 A schematic diagram showing a deployment status change according to an embodiment of the present application;

[0021] Figure 10 An architecture diagram of a deployment system provided by an embodiment of the present application;

[0022] Figure 11 An example diagram showing a first primary and standby topology information table;

[0023] Figure 12 An example diagram showing a second primary and standby topology information table;

[0024] Figure 13 A block diagram of an electronic device provided by an embodiment of the present application. Detailed implementation manners

[0025] In the following, only some exemplary embodiments are simply described. As those skilled in the art can recognize, the described embodiments can be modified in various different ways without departing from the spirit or scope of the present application. Therefore, the drawings and the description are considered to be exemplary in nature rather than restrictive.

[0026] To facilitate understanding of the technical solutions of the embodiments of the present application, the related technologies of the embodiments of the present application are described below. The following related technologies can be arbitrarily combined with the technical solutions of the embodiments of the present application as optional solutions, and they all fall within the protection scope of the embodiments of the present application.

[0027] A distributed message processing system is a system for asynchronous communication in a distributed environment. It uses middleware technology to allow different components of a distributed system or application to exchange information through messages without directly connecting or knowing each other, thereby decoupling different components and improving the scalability, elasticity, and maintainability of the system. The following will introduce the terms to be used in the embodiments of the present application in conjunction with Figure 1 the distributed message processing system shown.

[0028] Message: A message is a data unit transmitted between different components. It can contain text, binary data, or information in other formats. Messages are usually used for communication between different components of a distributed system or application, mainly including the combination of data and (optional) attributes sent by a producer to a topic and finally transmitted to a consumer.

[0029] Topic: A topic is a logical classification or namespace for messages. Messages are published to specific topics, and receivers (consumers) subscribed to those topics will receive the relevant messages. Topics provide a way to organize and filter messages, enabling different components to send and receive specific types of messages independently.

[0030] Produce Message: Producing a message refers to the process of creating and sending a message.

[0031] Producer: The party that produces and sends messages, also known as the message publisher. The producer publishes messages to one or more topics so that other components (consumers) can receive and process these messages. In a distributed message processing system, the producer randomly establishes a long connection with a name server to obtain the routing information of the broker server where the topic of the message to be published is located, and then establishes a long connection with it to publish the message.

[0032] Consume Message: Consuming a message refers to the process of receiving and processing a message.

[0033] Consumer: The party that consumes messages, used to process messages synchronously or asynchronously. The consumer is the receiver of messages, subscribes to one or more topics, and receives messages from these topics. In a distributed message system, the consumer also randomly establishes a long connection with a name server to obtain the routing information of the broker server where the subscribed topic is located, and then establishes a long connection with it. Once a new message is published to the subscribed topic, the consumer will receive the message and perform corresponding operations.

[0034] Source Topic: The topic of the message queue from which data is sourced in a synchronization task. The producer publishes messages to the source topic, and the message queue routes these messages elsewhere according to certain rules and configurations.

[0035] Target Topic: The topic of the message queue to which data is targeted in a synchronization task. The consumer subscribes to the target topic to receive messages passed from the source topic. The target topic determines where the messages are ultimately delivered.

[0036] Source Message Queue: The queue to which messages are sent from the source topic. In a distributed message processing system, messages usually first enter a queue and then are routed from the queue to the corresponding topic. Queues can be used to buffer messages, provide ordered delivery, or serve as an intermediate step in routing.

[0037] Target Message Queue: The target message queue is the queue to which the message passing system routes messages. Once a message reaches the target topic, the system may place it in one or more target message queues for waiting to be processed by consumers.

[0038] Name Server: A routing discovery server in a distributed message processing system, used to provide routing information of the proxy server where the topic is located for producers and consumers.

[0039] Broker Server: Exposes the message sending interface and consumption interface externally. Producers and consumers of messages interact with it to complete the core message sending and receiving logic.

[0040] Master Broker: Undertakes the function of providing message services externally under normal circumstances.

[0041] Slave Broker: In a distributed message processing system, the slave broker is a message copy of the master broker and has the full amount of data of the master broker.

[0042] Recovery Time Objective (RTO): Measured in time, that is, after a disaster occurs, the time requirement for an information system or service function to recover from being stopped.

[0043] Recovery Point Object (RPO): Refers to a past point in time to which data can be restored when a disaster or emergency occurs, and it is the amount of data loss that the system can tolerate.

[0044] Cluster: A group of independent computers interconnected by a high-speed computer network. They form a group and are managed in the mode of a single system. Computers or servers in a cluster are usually connected together through a high-speed network and share storage, software, or other resources. A cluster can exist within a data center or span multiple data centers. In a cluster, each computing resource can share the workload to improve overall performance and scalability. Broker servers are usually deployed in a cluster form. A broker server cluster includes at least one Master Broker and at least one Slave Broker. The master broker and the slave broker with a master-slave topological relationship can be called a group of broker servers. In a distributed message processing system, the slave broker is a message copy of the master broker and has the full amount of data of the master broker.

[0045] In recent years, with the continuous improvement of digital infrastructure and the emphasis on data availability and reliability, multiple computer rooms, multiple regions, and multiple data centers have increasingly become the options of users. Users can deploy applications in different regions or computer rooms to obtain disaster recovery, data redundancy, latency reduction, and data isolation capabilities. Among them, disaster recovery capabilities can ensure that when a region fails, failover can be performed, that is, switching to another region, thereby reducing fault recovery time and data loss. Data redundancy capabilities can ensure that multiple copies of data are distributed in different regions, further ensuring data security. The ability to reduce latency refers to reducing latency by deploying data closer to the user's geographic location. Data isolation capabilities can ensure that data in different regions is isolated from each other. For example, some data must be stored in a certain area or needs to be encrypted before it can be transmitted, while some data can be synchronized to other regions.

[0046] Two-site three-center is a common disaster recovery deployment method with high data availability and reliability. Two-site three-center generally includes three data centers, two of which are physically close and deployed in the same service area, forming a dual center in the same city, and the other data center is physically far away from the other two data centers and deployed in other service areas, serving as a remote disaster recovery center.

[0047] It should be noted that in the embodiments of the present application, "Region" refers to a physical area, that is, a geographically divided area, such as different computer rooms (different data centers) deployed in different Regions; "Service area" refers to an area with the same or similar management in infrastructure such as power systems or network systems, such as the same city or neighboring cities. When a power system or network system in a service area fails due to natural disasters or other reasons, multiple computer rooms (multiple data centers) in the service area may fail.

[0048] For example, in the two-site three-center deployment mode, the dual centers in the same city are two data centers that can independently undertake the operation of key systems in the same service area (such as the same city or a neighboring city). The dual centers have basically equivalent data processing capabilities and synchronize data in real time through high-speed links. Under normal circumstances, they can share the operation of services and management systems at the same time and can switch operations. The off-site disaster recovery center is a backup disaster recovery center established in another service area (such as a city in another place) for data backup of the dual centers. When the dual centers fail due to natural disasters or other reasons, the off-site disaster recovery center can use the backup data to restore services.

[0049] In a specific implementation, a two-site three-center architecture can be implemented based on a cluster internal replica synchronization mechanism. Figure 2The following is an architecture diagram of a two-site three-center message processing system based on a cluster internal replica synchronization mechanism.

[0050] like Figure 2 In the message processing system shown, data center 1 and data center 2 are physically close and serve the same service area, while data center 3 is another service area and is physically far away from the other two. Data center 1 deploys a primary proxy server, which is responsible for providing external message services under normal circumstances; data center 2 deploys a backup proxy server, and the primary proxy server of data center 1 and the backup proxy server of data center 2 enter the synchronous replication state after the replication state machine flows. When a failure occurs in data center 1, the backup proxy server of data center 2 will be elected as the new primary proxy server to provide message services. As an off-site disaster recovery center, data center 3 also deploys a backup proxy server, which has always been in an asynchronous replication state as a backup proxy server, that is, it will not enter the state machine to become the primary proxy server and will not participate in the election. This ensures data redundancy and does not affect the delay in sending application messages.

[0051] The above-mentioned two-site three-center architecture based on the cluster internal copy synchronization mechanism has the following disadvantages: (1) Once the two centers in the same city fail at the same time, even if the backup proxy server in the remote disaster recovery center is promoted to provide services to the main proxy server through manual intervention, since the message copy in the cluster synchronizes the commit log (commitlog) of the proxy server, that is, the message log that has been successfully sent by the producer, once data center 3 has external data flowing in, the commit log of the proxy server in data center 1 and data center 2 will be forked (remote disaster recovery is asynchronous replication, and its own RPO>0), and due to the strict consistency requirements of the commit log data, when the failure is restored, there is almost no way to complete the data re-entry; (2) Since the three data centers are in the same cluster, the actual The construction process basically needs to be completed in one step, but in the actual construction process, many construction processes are expanded according to the actual disaster recovery needs. The system expands from a single computer room to two computer rooms, and finally to two centers in two places, rather than in one step; (3) Since the components of the three data centers are in the same cluster, any problem with the components of any data center will expand the explosion radius of the failure; (4) Due to the internal replica synchronization mechanism of the cluster, all data will be replicated in full, and selective replication cannot be performed (such as selecting the topics that need to be disaster-tolerant for replication). Therefore, if the bandwidth is limited or the inflow traffic is large, the gap in asynchronous replication is relatively large, and the RPO of the off-site disaster recovery center (data center 3) and the dual centers in the same city (data center 1 and data center 2) will also be larger.

[0052] Figure 3 The following is an architecture diagram of the message processing system provided by the embodiment of the present application. Figure 3As shown in the figure, the message processing system includes: a first primary proxy server 311, a first standby proxy server 312, a second proxy server 320, and a client 303.

[0053] Among them, the first primary proxy server 311 and the first standby proxy server 312 belong to the first message service cluster (Cluster1). The first primary proxy server 311 and the first standby proxy server 312 can be multiple. The first primary proxy server and the first standby proxy server with a primary-standby topology relationship are the same group of proxy servers. In the same group of proxy servers, the first standby proxy server 312 is a message copy of the first primary proxy server 311 and receives the data synchronized by the first primary proxy server 311, so as to have the same data as the first primary proxy server 311.

[0054] The first primary proxy server 311 is deployed in the first data center (Region1), and the first standby proxy server 312 is deployed in the second data center (Region2). Both the first data center and the second data center are located in the first service area. The second proxy server 320 is deployed in the third data center (Region3) and belongs to the second message service cluster (Cluster2). The third data center is located in the second service area.

[0055] Exemplarily, the first service area can be the same city or adjacent cities, so that the first data center (Region1) and the second data center (Region2) have the same service infrastructure (such as power facilities or network facilities). The second service area is different from the first service area, so that the second service area and the first service area have different service infrastructures (such as power facilities or network facilities). That is to say, the physical distance between the first data center (Region1) and the second data center (Region2) is relatively close, while the physical distance between the third data center (Region3) and the first data center and the second data center is relatively far. When a failure occurs in the first service area, the probability of a failure in the second service area is relatively small, that is, the first service area and the second service area usually do not fail at the same time.

[0056] The client 303 can be either a producer or a consumer. The producer realizes message production through interaction with a proxy server (the first primary proxy server 311, the first standby proxy server 312, or the second proxy server 320), and the consumer realizes message consumption through interaction with the proxy server. Specifically, when the message processing system is in the normal service mode, the client 303 produces and consumes messages based on the first primary proxy server 311; when the message processing system is in the same-city disaster recovery mode, the client 303 produces and consumes messages based on the first standby proxy server 312; when the message processing system is in the off-site disaster recovery mode, the client 303 produces and consumes messages based on the second proxy server 320. Among them, in the normal service mode, the first data center is in a normal working state without faults; in the same-city disaster recovery mode, the first data center fails and the second data center does not fail; in the off-site disaster recovery mode, both the first data center and the second data center fail.

[0057] Exemplarily, the message processing system of the embodiments of the present application further includes: at least one first name server 301 deployed in the first message service cluster (Cluster1); at least one second name server 302 deployed in the second message service cluster (Cluster2).

[0058] In the normal service mode, the producer (client 303) randomly establishes a long connection with a first name server 301, obtains the routing information of the first primary proxy server 311 where the topic of the message to be published is located, then establishes a long connection with it, and publishes the message to realize message production; the consumer (client 303) also randomly establishes a long connection with a first name server 301, obtains the routing information of the first primary proxy server 311 where the subscribed topic is located, then establishes a long connection with it. Once a new message is published to the subscribed topic, the consumer will receive the message and perform corresponding operations.

[0059] In the same-city disaster recovery mode, the producer (client 303) obtains the routing information of the first standby proxy server 312 where the topic of the message to be published is located based on the first name server 301, and then realizes message production based on the first standby proxy server 312; the consumer (client 303) obtains the routing information of the first standby proxy server 312 where the subscribed topic is located based on the first name server 301, and then realizes message consumption based on the first standby proxy server 312.

[0060] In the off-site disaster recovery mode, the producer or consumer (client 303) obtains the routing information of the second proxy server 320 based on the first name server 301, and then realizes message production or consumption based on the second proxy server 320.

[0061] Compared to Figure 2 The two-site three-center message processing system based on the cluster internal copy synchronization mechanism shown has the disadvantage that the components need to be planned and laid out in advance for the same cluster deployment and cannot be expanded. In the message processing system of the embodiment of the present application, the dual centers in the same city are the first data center and the second data center, and the first message service cluster (Cluster1) is deployed. The remote disaster recovery center is the third data center, and the second message service cluster (Cluster2) is deployed. The first message service cluster (Cluster1) can be built first, and then the second message service cluster (Cluster2) can be built. The progressive deployment is realized, and the intermediate message service is uninterrupted, and the layout and planning of all components do not need to be completed in advance. It has good executability and scalability in the actual implementation process. In addition, in view of the problem that the failure explosion radius is large when all components are in the same message service cluster, the remote disaster recovery center and the dual centers in the same city in the embodiment of the present application are two completely independent message service clusters that do not affect each other. Therefore, the failure radius can be effectively reduced.

[0062] In one embodiment, Figure 4 As shown, the second proxy server 320 includes a second main proxy server 321 and a second backup proxy server 322 as a copy of the message of the second main proxy server 321. When the message processing system is in a remote disaster recovery mode, the client 303 produces and consumes messages based on the second main proxy server 321 or the second backup proxy server 321. In other words, during the deployment of the second message service cluster, the data of the first message service cluster can be copied, and the master-slave topology relationship in the second message service cluster can be synchronized, so as to achieve rapid deployment without interrupting the service process of the first message service cluster, and has better executability and scalability.

[0063] The following is a detailed introduction to the implementation of the same-city disaster recovery mode. In the same message service cluster, the data consistency between the primary proxy server and the backup proxy server can rely on the internal replica synchronization mechanism of the message service cluster (also called the message replica replication mechanism) to achieve high availability. In one implementation, Figure 4 As shown, the first data center, the second data center and the third data center are all deployed with state switching control components (Controller), and each state switching control component (Controller) controls the switching of the message copy replication state of the proxy server in the first message service cluster or the second message service cluster based on the majority consensus protocol among multiple state switching control components.

[0064] Among them, the state switching control component (Controller) is also called the master selection component. Each Controller can start multiple replica replication state machines, each replica replication state machine corresponds to a group of proxy servers (such as the first master proxy server 311 and the first standby proxy server 312 with a master-standby topology relationship, or the second master proxy server 321 and the second standby proxy server 322 with a master-standby topology relationship), and controls the state switching of message replication between the two proxy servers in the group. In the first message service cluster, after the flow of the replica replication state machine, the first master proxy server 311 and the first standby proxy server 312 eventually enter the synchronous replication state; in the second message service cluster, after the flow of the replica replication state machine, the second master proxy server 321 and the second standby proxy server 322 eventually enter the synchronous replication state.

[0065] The message processing system of the embodiment of the present application makes full use of the fact that the two centers (the first data center and the second data center) in the same city are close to each other. Disaster recovery in the same city can be achieved by relying on the internal replica synchronization mechanism of the message service cluster, and high-availability disaster recovery switching is achieved through the conversion of the replica state machine. The RPO is 0, ensuring high reliability and low latency of the two centers in the same city.

[0066] Figure 5 A master proxy server in a set of proxy servers is shown for a replica replication state machine record ( Figure 5 Master) and backup proxy server ( Figure 5 When the first proxy server ( Figure 5 When the first broker (shown as Broker) is started, the proxy server group switches from the initial state to the single-master state, that is, the Broker started at this time acts as the Master; when the second Broker is started, the proxy server group switches from the single-master state to the asynchronous replication state, and the second Broker acts as the Slave, and starts asynchronous replication of the master-slave data with the Master; when the asynchronous replication of the master-slave data is in progress, the proxy server group switches to the semi-synchronous state; when the Slave site (the Slave's message synchronization site) catches up with the Master, the proxy server group switches to the synchronous replication state. During this period, if the Master goes down, the system will issue an alarm to prompt the operation and maintenance personnel to handle it. It can be seen that the metadata or state switching of each group of proxy servers will not affect each other. Therefore, the metadata and switching states of the first message service cluster (Cluster1) and the second message service cluster (Cluster2) will not affect each other, so that data management can be isolated according to the message service cluster.

[0067] In a disaster recovery scenario, the Controller calculates the replica replication state machine and relies on the majority consensus protocol to reach a consensus to determine whether an agent server is the primary agent server or the standby agent server. Among them, the majority consensus protocol (Raft) is a consensus algorithm, which is a strongly consistent, decentralized, and highly available distributed protocol widely used in engineering and can be used for leader election, that is, to select the primary agent server that provides message services externally. That is to say, when the replica replication state machine controls the state transition of message replication among a group of agent servers, for each state transition step, it is necessary to reach a majority consensus protocol, that is, each state transition step must conform to the majority consensus among multiple replica replication state machines. Since the Controller is deployed in the first data center, the second data center, and the third data center, that is, two Controllers are deployed in the same city (the first service area), and one Controller is deployed in a different location (the second service area). If any one of the data centers fails, the other two data centers can still reach a majority consensus, and the primary and standby state transition can be completed without manual intervention. The RTO is the election time plus the routing awareness time, which can be within one minute.

[0068] Based on this, when any one of the data centers (the first data center or the second data center) in the same city (the first service area) fails, it can immediately enter the disaster recovery state, and the RPO is 0. The replica replication state machine also ensures that when the first primary agent server 311 in the first data center fails, the first standby agent server 312 in the second data center, which is the disaster recovery center in the same city, can be elected as the primary agent server and enter the disaster recovery mode in the same city. The client 303 produces and consumes messages based on the first standby agent server 312.

[0069] The implementation of the disaster recovery mode in a different location is specifically introduced below. In one implementation, as Figure 4 shown, the message processing system of the embodiment of the present application further includes a message queue replication component (MQ Replicator) 304, which is used to configure the first replication link for replicating messages from the first message service cluster to the second message service cluster. That is to say, based on the first replication link configured by the message queue replication component 304, asynchronous message replication from the dual data centers in the same city (the first data center and the second data center) to the disaster recovery center in a different location (the third data center) can be realized, and the data of the cluster (the first message service cluster Cluster1) in the dual data centers in the same city can be backed up in real time to the cluster (the second message service cluster Cluster2) in the disaster recovery center in a different location.

[0070] Exemplarily, as Figure 6As shown, the message queue replication component 304 consumes the messages of the target topic from the first message service cluster (Cluster1) based on the first replication link, and sends the messages of the target topic to the second message service cluster (Cluster2). For example, the target topic can be determined according to the topic level according to the actual disaster recovery needs, and the message queue replication component 304 is used to establish a synchronization link (first replication link) that consumes the source topic message and sends it to the target topic to complete data synchronization. In other words, the remote disaster recovery center and the dual centers in the same city can selectively replicate data based on the topic level without full replication, thereby reducing the risk of excessive RPO caused by bandwidth limitations or excessive full data volume.

[0071] Figure 7 FIG. 1 is a schematic diagram showing a remote disaster recovery switching of a message processing system according to an embodiment of the present application. Figure 7 As shown, before disaster recovery occurs, the message processing system is in normal service mode, the first message service cluster (Cluster1) is in normal operation (Active), and the second message service cluster (Cluster2) is in standby (Standby), that is, the client 303 produces and consumes messages based on Cluster1, and all service requests are completed by Cluster1, and Cluster2 does not provide message services to the outside. Based on the first replication link configured by the message queue replication component 304, the data of the dual centers in the same city (the first data center and the second data center) is backed up in real time (message replication) to the off-site disaster recovery center (the third data center). Here, the target topic can be selected according to the topic level for data synchronization according to the actual disaster recovery needs.

[0072] If a disaster occurs in the dual centers in the same city and remote disaster recovery occurs, the message processing system switches to remote disaster recovery mode. In remote disaster recovery mode, Cluster1 enters the standby state, Cluster2 is in the normal operating Active state, and the message service logic switches to Cluster2. That is, client 303 produces and consumes messages based on Cluster2, and all service requests are completed by Cluster2. It can be seen that the uplink (consumption link of client 303) can be switched seamlessly.

[0073] In one embodiment, the message queue replication component 304 synchronizes the message consumption site of Cluster 1 to Cluster 2 according to the preset time conditions. For example, the message queue replication component 304 can periodically synchronize the message consumption sites (timestamps) of the dual centers in the same city to the off-site disaster recovery center. When the message processing system switches to the off-site disaster recovery mode, the downlink (the production link of the client 303) needs to reset the message consumption site once after switching to Cluster 2 in order to minimize the loss of messages. That is, the client 303 can query the message consumption site last submitted by the client 303 before the off-site disaster recovery occurs through the application programming interface (Application Programming Interface, API), and continue to consume from the message consumption site.

[0074] When the message processing system switches from the normal service mode to the remote disaster recovery mode, due to the asynchronous replication characteristics of the message queue replication component 304, RPO>0 at this time. When the dual centers in the same city are restored, the data that has not been synchronized to the remote disaster recovery center in time and RPO>0 will continue to be synchronized to the remote disaster recovery center, and the remote disaster recovery center will also process this part of the data. If you do not need to resume the breakpoint transmission of this part of the data, you can stop the replication task of the message queue replication component 304.

[0075] If it is necessary to restore Cluster1 to the Active state at this time, data re-recording can be done as needed. Re-record the new data generated in Cluster2 after the disaster recovery occurs. Specifically, in response to the message processing system switching from the off-site disaster recovery mode to the normal service mode, the message queue replication component 304 configures a second replication link for message replication from Cluster2 to Cluster1. The starting point of the second replication link for message replication corresponds to the time when the message processing system switches to the off-site disaster recovery mode, that is, the message queue replication component 304 will start a unidirectional synchronization link (second replication link) from Cluster2 to Cluster1, and the synchronization start point time is when the disaster recovery occurs.

[0076] exist Figure 2In the message processing system shown, in view of the shortcoming that it is difficult to complete data re-recording after switching caused by bifurcation due to its commit log (commitlog) level replication, in the technical solution of the embodiment of the present application, the remote disaster recovery center and the dual centers in the same city rely on the message queue replication component 304 to complete the data synchronization at the topic level. Its essence is to establish a synchronization link (first replication link) that consumes the source topic message and sends it to the target topic. Therefore, when the dual centers in the same city are restored, once the first replication link is re-established, the part of the data that has not been synchronized to the remote disaster recovery center in time when RPO>0 will continue to be synchronized to the remote disaster recovery center. In addition, the data can also be synchronized on demand by establishing a reverse synchronization link (second replication link), and the start point time of the synchronization is when disaster recovery occurs. Therefore, the technical solution of the embodiment of the present application can better complete the data re-recording.

[0077] The following introduces the progressive deployment scheme of the message processing system of the embodiment of the present application. The progressive deployment scheme expands from the single computer room (single data center) stage to the dual computer room (dual data center) stage, and then to the final state of two locations and three centers. Among them, the single computer room stage corresponds to the first deployment state of the message processing system, that is, the main proxy server and the backup proxy server with the main and backup topology relationship are deployed in the first data center; the dual computer room stage corresponds to the second deployment state, that is, the main proxy server and the backup proxy server with the main and backup topology relationship are deployed in the first data center and the second data center respectively.

[0078] Since the name server is stateless, it can be expanded directly from the first deployment state to the second deployment state. The proxy server is a stateful application, which needs to be changed from the master-slave state in a single computer room (the first deployment state) to two replicas across two computer rooms (the second deployment state), that is, the master and backup proxy servers in a group of proxy servers are deployed one in each data center, so a conversion plan is needed, which is described in detail below. Figure 8 A flowchart showing a proxy server deployment method provided in an embodiment of the present application is shown as follows: Figure 8 As shown, the method includes:

[0079] Step S801: acquiring a deployment state, wherein the deployment state includes a first deployment state and a second deployment state, the first deployment state is that the primary proxy server and the backup proxy server having a primary-backup topology relationship are both deployed in the first data center, and the second deployment state is that the primary proxy server and the backup proxy server having a primary-backup topology relationship are respectively deployed in the first data center and the second data center;

[0080] Step S802: In response to a change request from the first deployment state to the second deployment state, the primary proxy server and the backup proxy server in the first data center are updated to be the first primary proxy server, and multiple proxy servers are run in the second data center as the first backup proxy server; wherein the first backup proxy server is a message copy of the first primary proxy server, the first data center and the second data center are both located in the first service area, and the first primary proxy server and the first backup proxy server belong to the first message service cluster; in normal service mode, the client produces and consumes messages based on the first primary proxy server, and in same-city disaster recovery mode, the client produces and consumes messages based on the first backup proxy server.

[0081] Take room A as the first data center and room B as the second data center. Figure 9 As shown, in the first deployment state, multiple groups of proxy servers are deployed in computer room A, each group of proxy servers includes a primary proxy server and a backup proxy server, and the two have a primary-backup topology relationship, that is, the backup proxy server can serve as a message copy of the primary proxy server. In the second deployment state, the primary proxy server and the backup proxy server in computer room A both operate as primary proxy servers, that is, they can serve as the first primary proxy server 311, and the proxy server in computer room B operates as a backup proxy server, that is, it can serve as the first backup proxy server 312. Specifically, in response to a change request from the first deployment state to the second deployment state, the primary proxy server and the backup proxy server in computer room A are updated to the first primary proxy server 311, and multiple proxy servers are operated in computer room B as the first backup proxy server 312.

[0082] In one embodiment, in step S802, the main proxy server and the standby proxy server in the first data center are updated to be the first main proxy server, and multiple proxy servers are run in the second data center as the first standby proxy server, including: deleting a first main-standby topology information table, wherein the first main-standby topology information table is used to record the identification information and the main-standby topology relationship of the main proxy server and the standby proxy server in the first data center in the first deployment state; updating the running status of the main proxy server and the standby proxy server in the first data center to be the running status of the main proxy server, running multiple proxy servers in the second data center as the first standby proxy server, and generating a second main-standby topology information table, wherein the second main-standby topology information table includes information for recording the identification information of the first main proxy server, the identification information of the first standby proxy server, and the main-standby topology relationship between the first main proxy server and the first standby proxy server.

[0083] For example, in order to realize the deployment from a single computer room to a dual computer room, that is, to realize the change from the first deployment state to the second deployment state, the embodiment of the present application provides a deployment system architecture, such as Figure 10As shown, the deployment system includes a control center, a topology relationship storage center, and agents deployed on each proxy server. An agent is deployed on each proxy server to communicate with the control center and the topology relationship storage center. The computer room conversion control center can be implemented using a distributed coordination component, which controls the progress during the deployment state transition. The agent on the proxy server listens for the deployment state information of the control center. Once the deployment state changes, such as changing from the first deployment state to the second deployment state, the primary and standby topology relationship conversion begins. The topology relationship storage center stores the primary and standby topology relationships, which can be implemented using a database.

[0084] Progressive deployment mainly includes three stages: the single computer room (SINGLE) state, which is the first deployment state; the transition (TRANSITION) state, which is the intermediate stage of the transition from the first deployment state to the second deployment state; and the dual computer room (DUAL) state, which is the second deployment state.

[0085] In the single computer room (SINGLE) state, that is, when the first data center (such as computer room A) is established, after each proxy server starts, it will automatically apply for unique identification information from the topology relationship storage center and complete the construction of the primary and standby topology relationships with other agents, generate the first primary and standby topology information table, generate the corresponding configuration information at the same time, record the metadata as the application metadata table for storage, and then go online to complete the single computer room automated deployment.

[0086] Figure 11 The example diagram of the first primary and standby topology information table is shown. When each proxy server starts, its agent inserts a record into the topology relationship storage center. Each record has the identification information (id) and server information (such as ip) of the proxy server. Each time the id is inserted, it will increment automatically. The primary and standby topology relationship is characterized by the id sequence number. Exemplarily, adjacent even numbers are paired to form the primary and standby topology relationship, and adjacent odd numbers are paired to form the primary and standby topology relationship. For each even id, divide it by 2. If it is odd, look up the first adjacent id above to form the primary and standby topology relationship. If it is even, look down for the first adjacent id to form the primary and standby topology relationship. For each odd id, divide it by 2 after subtracting 1. If it is odd, look up the first adjacent id above to form the primary and standby topology relationship. If it is even, look down for the first adjacent id to form the primary and standby topology relationship. As Figure 11 shown, the proxy servers with id 0 and 2 form the primary and standby topology relationship, 1 and 3 form the primary and standby topology relationship, 4 and 6 form the primary and standby topology relationship, 5 and 7 form the primary and standby topology relationship, and so on.

[0087] In the TRANSITION state, the proxy server (including the main proxy server and the backup proxy server) will monitor the information from the control center that the first deployment state has changed to the second deployment state. Specifically, the main proxy server inserts its own record (including id and ip) into the topology relationship table of computer room A, and downgrades the copy operation mechanism to single copy operation. After completion, the stage information (stage) in the record of the topology relationship table of computer room A is set to 1; the backup proxy server will go offline first, clean up the storage data, and then re-apply for a new server name, and insert its own record (including id and ip) into the topology relationship table of computer room A, enter the main proxy server operation state, and after completion, the stage in the record of the topology relationship table of computer room A is set to 1, thereby realizing the automatic deployment of the first main proxy server, the automatic deletion of the first main and backup topology information tables, and the automatic generation of a subtable (computer room A topology relationship table) in the second main and backup topology information tables. In addition, in the TRANSITION state, multiple proxy servers are run in the second data center (eg, computer room B) as first backup proxy servers, and another subtable (computer room B topology relationship table) in the second primary and backup topology information table is automatically generated.

[0088] Exemplarily, once the conversion state is entered, the first master-slave topology information table will be automatically deleted, and the proxy server of each computer room will insert records into the topology relationship table of its computer room. Each record has an id, and each insertion of the id will be automatically incremented. The proxy servers with the same id in the topology relationship table of the last two computer rooms constitute a master-slave topology relationship, that is, the same group of proxy servers. Specifically, the proxy server in computer room B inserts its own record (including id and ip) into the topology relationship table of computer room B, and completes the construction of the master-slave topology relationship with the proxy server in computer room A according to the id. For example, the proxy servers with the same id in the topology relationship table of computer room A and the topology relationship table of computer room B constitute a master-slave topology relationship. The proxy server in computer room B polls until the stage of its paired proxy server (with a master-slave topology relationship) is 1, and then starts to go online. After the online completion, the stage in the record in the topology relationship table of computer room A is set to 1. Then, the control center will check whether the topology relationship table of computer room B contains all the planned proxy servers and the stage is 1. If so, the control center will set the current deployment state to DUAL, that is, the second deployment state, thereby completing the automatic generation of the second active-standby topology information table and the automatic deployment of dual centers in the same city. The second active-standby topology information table includes the topology relationship table of the first data center (for example, computer room A) and the topology relationship table of the second data center (for example, computer room B). Figure 12 shown.

[0089] Furthermore, the method of the embodiment of the present application may also include: running a second proxy server in a third data center, wherein the third data center is located in a second service area and belongs to a second message service cluster, and in a remote disaster recovery mode, the client produces and consumes messages based on the second proxy server; based on the message queue replication component, messages are replicated from the first message service cluster to the second message service cluster.

[0090] In other words, from dual centers (dual computer rooms) in the same city to three centers in two locations, it is only necessary to deploy an additional message service cluster in the off-site disaster recovery center (third data center) and use the message queue replication component to establish a data synchronization link (first replication link) for message replication. The service progress of the dual centers in the same city will not be affected at all during the process.

[0091] Furthermore, the deployment and expansion of the Controller cluster can utilize Raft's member change solution. After the network is connected, one Controller can be expanded to a remote disaster recovery center (third data center), and the service process will not be affected during the process.

[0092] According to the deployment scheme of the embodiment of the present application, the progressive deployment is completed by gradually converting the deployment from a single computer room (one data center) to a dual computer room (dual centers in the same city), and then expanding the first message service area cluster of the dual centers in the same city (the first data center and the second data center) to the second message service cluster of the off-site disaster recovery center. The service process is uninterrupted during the deployment process, and there is no need to complete the layout and planning of all components in advance. Therefore, it has good executability and scalability.

[0093] It should be noted that the embodiments of the present application do not specifically limit the application scenarios of the technical solution. In addition, the user information (including but not limited to user device information, user personal information, etc.) and data (including but not limited to data used for analysis, stored data, displayed data, etc.) involved in this application are all information and data authorized by the user or fully authorized by all parties, and the collection, use and processing of relevant data need to comply with the relevant laws, regulations and standards of relevant countries and regions, and provide corresponding operation entrances for users to select or edit authorization or rejection.

[0094] The embodiment of the present application also provides a proxy server deployment device, including: a deployment status acquisition module, used to acquire the deployment status, wherein the deployment status includes a first deployment status and a second deployment status, the first deployment status is that the primary proxy server and the backup proxy server with a primary-backup topology relationship are both deployed in the first data center, and the second deployment status is that the primary proxy server and the backup proxy server with a primary-backup topology relationship are respectively deployed in the first data center and the second data center; an update module, used to respond to a change request for the first deployment status to be changed to the second deployment status, update the primary proxy server and the backup proxy server in the first data center to be the first primary proxy server, and run multiple proxy servers in the second data center as the first backup proxy server; wherein the first backup proxy server is a message copy of the first primary proxy server, the first data center and the second data center are both located in the first service area, and the first primary proxy server and the first backup proxy server belong to the first message service cluster; in the normal service mode, the client produces and consumes messages based on the first primary proxy server, and in the same-city disaster recovery mode, the client produces and consumes messages based on the first backup proxy server.

[0095] In one embodiment, the update module is specifically used to: delete a first master-slave topology information table, wherein the first master-slave topology information table is used to record the identification information and master-slave topology relationship of the primary proxy server and the backup proxy server in the first data center under the first deployment state; update the operating status of the primary proxy server and the backup proxy server in the first data center to the operating status of the primary proxy server, run multiple proxy servers in the second data center as the first backup proxy server, and generate a second master-slave topology information table, wherein the second master-slave topology information table includes information for recording the identification information of the first primary proxy server, the identification information of the first backup proxy server, and the master-slave topology relationship between the first primary proxy server and the first backup proxy server.

[0096] In one embodiment, the proxy server deployment device also includes an operation module for running a second proxy server in a third data center, wherein the third data center is located in a second service area, and the second proxy server belongs to a second message service cluster. In a remote disaster recovery mode, the client produces and consumes messages based on the second proxy server; based on a message queue replication component, messages are replicated from the first message service cluster to the second message service cluster.

[0097] The functions of each module in each device in the embodiments of the present application can be found in the corresponding description in the above method, and have corresponding beneficial effects, which will not be repeated here.

[0098] Figure 13 This is a block diagram of an electronic device for implementing the embodiments of the present application. As Figure 13 shown, the electronic device includes: a memory 1301 and a processor 1302. The memory 1301 stores a computer program that can run on the processor 1302. When the processor 1302 executes the computer program, the methods in the above embodiments are implemented. The number of the memory 1301 and the processor 1302 can be one or more.

[0099] The electronic device further includes: a communication interface 1303, which is used to communicate with external devices and perform data interaction and transmission.

[0100] If the memory 1301, the processor 1302, and the communication interface 1303 are implemented independently, the memory 1301, the processor 1302, and the communication interface 1303 can be interconnected through a bus and complete communication with each other. The bus can be an Industry Standard Architecture (ISA) bus, a Peripheral Component Interconnect (PCI) bus, an Extended Industry Standard Architecture (EISA) bus, etc. The bus can be divided into an address bus, a data bus, a control bus, etc. For the sake of convenience of representation, Figure 13 only a thick line is used to represent it in the figure, but it does not mean that there is only one bus or one type of bus.

[0101] Optionally, in a specific implementation, if the memory 1301, the processor 1302, and the communication interface 1303 are integrated on a chip, the memory 1301, the processor 1302, and the communication interface 1303 can complete communication with each other through an internal interface.

[0102] The embodiments of the present application provide a computer-readable storage medium that stores a computer program, and when the program is executed by a processor, the methods provided in any embodiment of the present application are implemented.

[0103] The embodiments of the present application further provide a chip, which includes a processor for calling and running an instruction stored in a memory, so that a communication device installed with the chip executes the methods provided in any embodiment of the present application.

[0104] The embodiments of the present application further provide a chip, including: an input interface, an output interface, a processor, and a memory. The input interface, the output interface, the processor, and the memory are connected through an internal connection path. The processor is used to execute the code in the memory, and when the code is executed, the processor is used to execute the methods provided in any embodiment of the application.

[0105] It should be understood that the above-mentioned processor may be a Central Processing Unit (CPU), or may also be other general-purpose processors, Digital Signal Processors (DSPs), Application Specific Integrated Circuits (ASICs), Field Programmable Gate Arrays (FPGAs), or other programmable logic devices, discrete gate or transistor logic devices, discrete hardware components, etc. The general-purpose processor may be a microprocessor or any conventional processor, etc. It is worth noting that the processor may be a processor that supports the Advanced RISC Machines (ARM) architecture.

[0106] Optionally, the above-mentioned memory may include a read-only memory and a random access memory, and may also include a non-volatile random access memory. The memory may be a volatile memory or a non-volatile memory, or may include both volatile and non-volatile memories. Among them, the non-volatile memory may include a Read-Only Memory (ROM), a Programmable ROM (PROM), an Erasable Programmable ROM (EPROM), an Electrically Erasable Programmable ROM (EEPROM), or a flash memory. The volatile memory may include a Random Access Memory (RAM), which is used as an external cache. By way of example but not limitation, many forms of RAM are available. For example: Static Random Access Memory (SRAM), Dynamic Random Access Memory (DRAM), Synchronous Dynamic Random Access Memory (SDRAM), Double Data Rate SDRAM (DDR SDRAM), Enhanced SDRAM (ESDRAM), Sync Link DRAM (SLDRAM), and Direct Rambus RAM (DRRAM).

[0107] In the above embodiments, it can be implemented in whole or in part by software, hardware, firmware, or any combination thereof. When implemented using software, it can be implemented in whole or in part in the form of a computer program product. The computer program product includes one or more computer instructions. When the computer program instructions are loaded and executed on a computer, the processes or functions according to the present application are generated in whole or in part. The computer can be a general-purpose computer, a special-purpose computer, a computer network, or other programmable devices. The computer instructions can be stored in a computer-readable storage medium or transmitted from one computer-readable storage medium to another computer-readable storage medium.

[0108] In the description of this specification, the descriptions referring to terms such as "one embodiment", "some embodiments", "example", "specific example", or "some examples" mean that the specific features, structures, materials, or characteristics described in connection with the embodiment or example are included in at least one embodiment or example of the present application. Moreover, the specific features, structures, materials, or characteristics described can be combined in a suitable manner in any one or more embodiments or examples. In addition, without contradiction, those skilled in the art can combine and combine the different embodiments or examples described in this specification and the features of different embodiments or examples.

[0109] In addition, the terms "first" and "second" are only used for descriptive purposes and cannot be understood as indicating or implying relative importance or implicitly specifying the quantity of the indicated technical features. Thus, the features defined with "first" and "second" can explicitly or implicitly include at least one of the features. In the description of the present application, "a plurality of" means two or more unless otherwise specifically defined.

[0110] Any process or method description represented in the flowchart or described in other ways herein can be understood as representing a module, segment, or part of the code of executable instructions including one or more steps for implementing a specific logical function or process. And the scope of the preferred embodiments of the present application includes additional implementations, where the functions can be executed in a substantially simultaneous manner or in the reverse order according to the involved functions, rather than in the order shown or discussed.

[0111] The logic and / or steps represented in the flowchart or described in other ways herein, for example: can be considered as a sequenced list of executable instructions for implementing a logical function, and can be specifically implemented in any computer-readable medium for use by an instruction execution system, apparatus, or device (such as a computer-based system, a system including a processor, or other systems that can fetch and execute instructions from the instruction execution system, apparatus, or device), or in combination with these instruction execution systems, apparatus, or devices.

[0112] It should be understood that each part of the present application can be implemented by hardware, software, firmware, or a combination thereof. In the above embodiments, multiple steps or methods can be implemented by software or firmware stored in a memory and executed by a suitable instruction execution system. All or part of the steps of the above method embodiments can be completed by a program instructing relevant hardware. The program can be stored in a computer-readable storage medium. When the program is executed, it includes one or a combination of the steps of the method embodiments.

[0113] In addition, in each embodiment of the present application, each functional unit can be integrated into a processing module, or each unit can exist physically alone, or two or more units can be integrated into one module. The above integrated module can be implemented in the form of hardware or in the form of a software functional module. If the above integrated module is implemented in the form of a software functional module and sold or used as an independent product, it can also be stored in a computer-readable storage medium. The storage medium can be a read-only memory, a magnetic disk, an optical disk, etc.

[0114] As described above, the above are only specific embodiments of the present application, but the protection scope of the present application is not limited thereto. Any person skilled in the art within the technical scope disclosed in the present application can easily think of various changes or substitutions, and these should all be covered within the protection scope of the present application. Therefore, the protection scope of the present application should be subject to the protection scope of the claims.

Claims

1. A message processing system, comprising: A first primary proxy server, deployed in a first data center; A first standby proxy server, which is a message copy of the first primary proxy server and is deployed in a second data center, wherein both the first data center and the second data center are located in a first service area, and the first primary proxy server and the first standby proxy server belong to a first message service cluster; A second proxy server, deployed in a third data center, belonging to a second message service cluster, wherein the third data center is located in a second service area; A client, in the case where the message processing system is in a normal service mode, the client produces and consumes messages based on the first primary proxy server; in the case where the message processing system is in a local disaster recovery mode, the client produces and consumes messages based on the first standby proxy server; in the case where the message processing system is in a remote disaster recovery mode, the client produces and consumes messages based on the second proxy server.

2. The message processing system according to claim 1, wherein, The second proxy server includes a second primary proxy server and a second standby proxy server that is a message copy of the second primary proxy server. In the case where the message processing system is in the remote disaster recovery mode, the client produces and consumes messages based on the second primary proxy server or the second standby proxy server.

3. The message processing system according to claim 1, wherein, The first data center, the second data center, and the third data center are all deployed with state switching control components, and the state switching control components control the switching of the message copy replication state of the proxy servers in the first message service cluster or the second message service cluster based on the majority consensus protocol among multiple state switching control components.

4. The message processing system according to claim 1, further comprising a message queue replication component for configuring a first replication link for replicating messages from the first message service cluster to the second message service cluster.

5. The message processing system according to claim 4, wherein, Based on the first replication link, the message queue replication component consumes messages of a target topic from the first message service cluster and sends the messages of the target topic to the second message service cluster.

6. The message processing system according to claim 4, wherein, The message queue replication component synchronizes the message consumption positions of the first message service cluster to the second message service cluster according to preset time conditions.

7. The message processing system according to claim 4, wherein, In response to the message processing system switching from the remote disaster recovery mode to the normal service mode, the message queue replication component configures a second replication link for replicating messages from the second message service cluster to the first message service cluster, and the starting position for message replication of the second replication link corresponds to the time when the message processing system switches to the remote disaster recovery mode.

8. A method for deploying a proxy server, comprising: Obtaining a deployment state, wherein the deployment state includes a first deployment state and a second deployment state, the first deployment state is that the primary proxy server and the backup proxy server having a primary-backup topology relationship are both deployed in the first data center, and the second deployment state is that the primary proxy server and the backup proxy server having a primary-backup topology relationship are respectively deployed in the first data center and the second data center; In response to a change request for changing the first deployment state to the second deployment state, updating a primary proxy server and a backup proxy server in the first data center to be a first primary proxy server, and running a plurality of proxy servers in the second data center as first backup proxy servers; Among them, the first backup proxy server is a message copy of the first main proxy server, the first data center and the second data center are both located in the first service area, and the first main proxy server and the first backup proxy server belong to the first message service cluster; in normal service mode, the client produces and consumes messages based on the first main proxy server, and in the same-city disaster recovery mode, the client produces and consumes messages based on the first backup proxy server.

9. The method according to claim 8, wherein, Updating the primary proxy server and the backup proxy server in the first data center to be the first primary proxy server, and running multiple proxy servers in the second data center as the first backup proxy servers, including: Deleting a first master-slave topology information table, wherein the first master-slave topology information table is used to record identification information and a master-slave topology relationship of a master proxy server and a standby proxy server in the first data center in the first deployment state; Update the operating status of the primary proxy server and the backup proxy server in the first data center to the operating status of the primary proxy server, run multiple proxy servers in the second data center as the first backup proxy server, and generate a second primary-backup topology information table, wherein the second primary-backup topology information table includes information for recording the identification information of the first primary proxy server, the identification information of the first backup proxy server, and the primary-backup topology relationship between the first primary proxy server and the first backup proxy server.

10. The method according to claim 8 or 9, further comprising: Running a second proxy server in a third data center, wherein the third data center is located in a second service area, the second proxy server belongs to a second message service cluster, and in a remote disaster recovery mode, the client produces and consumes messages based on the second proxy server; Based on the message queue replication component, messages are replicated from the first message service cluster to the second message service cluster.

11. An electronic device comprising a memory, a processor and a computer program stored in the memory, wherein the processor implements the method according to any one of claims 8 to 10 when executing the computer program.

12. A computer-readable storage medium, wherein a computer program is stored in the computer-readable storage medium, and when the computer program is executed by a processor, the method according to any one of claims 8 to 10 is implemented.

13. A computer program product comprising a computer program which, when executed by a processor, implements the method according to any one of claims 8 to 10.