Cloud resource changing method and electronic equipment
By judging whether the cloud resource change request will cause the upper-level resources to be unavailable and output prompt information, the problem of users accidentally deleting cloud resources is solved, and the security and business continuity of cloud resource changes are achieved.
Patent Information
- Application Number
- CN202410164397.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-02-02
- Publication Date
- 2025-08-05
AI Technical Summary
When users change cloud resources, it is easy to accidentally delete cloud resources, resulting in resource losses and resource waste, especially in batch operation scenarios.
By judging whether the cloud resource change request will cause the upper-level resource to be unavailable, the prompt information is output to prevent the error deletion, especially for the last cloud resource in the topological relationship, a high-risk interception strategy is provided to flexibly respond to different application scenarios.
It effectively avoids the mistaken deletion of cloud resources when cloud resource changes, protects business continuity, and avoids resource losses and waste.
Smart Images

Figure CN120434205A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of computer technology, and particularly to a method for changing cloud resources and an electronic device. Background Art
[0002] Cloud services are an increasing, usage, and interaction model of Internet-related services, usually involving providing dynamically scalable and often virtualized cloud resources over the Internet. During the process of a user using cloud services provided by a cloud service provider, due to changes in user requirements, the user needs to change the cloud resources they use.
[0003] When a user changes cloud resources, there are many high-risk operations. For example, unbinding an Elastic IP address (EIP), deleting an Elastic Compute Service (ECS), etc. Especially in the scenario of batch operations, it is easier to trigger such high-risk operations, which may cause the customer's resources to be accidentally deleted, resulting in the user losing resources and wasting the time for re-applying and setting up resources.
[0004] Therefore, a method for changing cloud resources is needed to prevent users from accidentally deleting cloud resources when changing cloud resources. Summary of the Invention
[0005] Aiming at the problem of how to prevent users from accidentally deleting cloud resources when changing cloud resources, this application provides a method for changing cloud resources and an electronic device, and this application also provides a computer-readable storage medium.
[0006] The embodiments of this application adopt the following technical solutions:
[0007] In a first aspect, this application provides a method for changing cloud resources, and the method includes:
[0008] According to a cloud resource change request, determine whether unbinding or deleting a first cloud resource will cause the upper-layer resources of the first cloud resource to be unavailable, where the cloud resource change request corresponds to unbinding or deleting the first cloud resource;
[0009] In the case where unbinding or deleting the first cloud resource will cause the upper-layer resources to be unavailable, output a prompt message.
[0010] According to the method of the first aspect, it is possible to remind the user when unbinding or deleting cloud resources will cause the upper-layer resources to be unavailable, thereby effectively preventing accidental deletion of cloud resources during cloud resource changes and avoiding business damage.
[0011] In one implementation manner of the first aspect, the determining whether unbinding or deleting a first cloud resource will cause the upper-layer resources of the first cloud resource to be unavailable according to the cloud resource change request includes:
[0012] Determine whether the first cloud resource is the last cloud resource under the cloud resource topology relationship according to the cloud resource change request, where:
[0013] The cloud resource topology relationship includes the topology relationship between the first cloud resource and the upper-layer resource;
[0014] In the case where the first cloud resource is the last cloud resource under the cloud resource topology relationship, unbinding or deleting the first cloud resource will cause the upper-layer resource to be unavailable.
[0015] According to the method of the above implementation, when a user attempts to unbind or delete the last cloud resource under the topology relationship, the user can be reminded, so as to effectively avoid accidentally deleting the last cloud resource under the topology relationship during cloud resource change and avoid business damage.
[0016] In an implementation of the first aspect, the first cloud resource is an Elastic Public IP Address (EIP), and the upper-layer resource of the first cloud resource is the domain name to which the EIP belongs.
[0017] In an implementation of the first aspect, the first cloud resource is an Elastic Compute Service (ECS), and the upper-layer resource of the first cloud resource is the cloud server middleware to which the ECS belongs.
[0018] In an implementation of the first aspect, the method further includes creating one or more high-risk interception policies, where the one or more high-risk interception policies at least include the first policy, and the first policy is used to determine whether the first cloud resource is the last cloud resource under the cloud resource topology relationship according to the request parameters of the cloud resource change request;
[0019] Determining whether the first cloud resource is the last cloud resource under the cloud resource topology relationship according to the cloud resource change request includes querying, from the one or more high-risk interception policies, a high-risk interception policy that matches the request parameters according to the request parameters of the cloud resource change request.
[0020] According to the method of the above implementation, creating multiple high-risk interception policies can flexibly implement the interception of cloud resource change operations for different application scenarios.
[0021] In an implementation of the first aspect, determining whether the first cloud resource is the last cloud resource under the cloud resource topology relationship according to the cloud resource change request further includes:
[0022] When a first policy that matches the request parameters is queried, call the first policy;
[0023] Based on the request parameters and the first policy, determine whether the first cloud resource is the last cloud resource under the cloud resource topological relationship.
[0024] In an implementation manner of the first aspect:
[0025] The request parameters include the interface characteristics of the first cloud resource, and the interface characteristics include any one or more combinations of the startup path, basic path, path, and interface name;
[0026] The policy script of the high-risk interception policy includes interface attributes, and the interface attributes include any one or more combinations of the startup path, basic path, path, and interface name. Among them, the interface attributes of the first policy match the interface characteristics of the first cloud resource;
[0027] Querying the high-risk interception policy that matches the request parameters includes: querying the high-risk interception policy that matches the interface characteristics in the request parameters according to the interface characteristics in the request parameters.
[0028] In an implementation manner of the first aspect, the first cloud resource is an EIP, the upper-layer resource of the first cloud resource is the domain name to which the EIP belongs, and the policy script of the first policy includes:
[0029] An extraction attribute, which is used to call the topological relationship to which the first cloud resource belongs according to the request parameters, and obtain the domain name to which the first cloud resource belongs according to the topological relationship of the first cloud resource;
[0030] A rule attribute, which is used to call the topological relationship to which the first cloud resource belongs according to the request parameters, and determine whether the domain name to which the first cloud resource belongs only includes the first cloud resource according to the domain name to which the first cloud resource belongs and the topological relationship of the first cloud resource.
[0031] In an implementation manner of the first aspect, after creating one or more high-risk interception policies, the method includes enabling or disabling one or more high-risk interception policies among the one or more high-risk interception policies;
[0032] Querying the high-risk interception policy that matches the request parameters includes querying the high-risk interception policy that matches the request parameters from one or more enabled high-risk interception policies.
[0033] According to the method of the above implementation manner, configuring the enabling and disabling of the high-risk interception policy can flexibly implement the interception of cloud resource change operations for different application scenarios.
[0034] In an implementation manner of the first aspect, the method further includes:
[0035] When no high-risk interception policy matching the request parameters is found from one or more enabled high-risk interception policies, the first cloud resource is unbound or deleted based on the cloud resource change request.
[0036] According to the above implementation method, whether to intercept the cloud resource change operation is determined by judging whether there is a corresponding high-risk interception strategy, which simplifies the judgment logic and makes the interception of the cloud resource change operation easier to implement.
[0037] In a second aspect, the present application provides an electronic device, comprising a memory for storing computer program instructions and a processor for executing computer program instructions, wherein when the computer program instructions are executed by the processor, the electronic device is triggered to execute the method steps described in the first aspect.
[0038] In a third aspect, the present application provides a computer-readable storage medium, wherein the computer-readable storage medium stores a computer program, which, when executed on a computer, enables the computer to execute the method described in the first aspect. BRIEF DESCRIPTION OF THE DRAWINGS
[0039] Figure 1 Shown is a flow chart of a method for changing cloud resources according to an embodiment of the present application;
[0040] Figure 2 Shown is a simplified diagram of the cloud service system architecture according to an embodiment of the present application;
[0041] Figure 3 FIG2 is a timing diagram of a method for changing cloud resources according to an embodiment of the present application;
[0042] Figure 4 FIG2 is a timing diagram of a method for changing cloud resources according to an embodiment of the present application;
[0043] Figure 5 Shown is a simplified diagram of the cloud service system architecture according to an embodiment of the present application;
[0044] Figure 6 FIG2 is a timing diagram of a method for changing cloud resources according to an embodiment of the present application;
[0045] Figure 7 Shown is a partial flow chart of a method for changing cloud resources according to an embodiment of the present application;
[0046] Figure 8 FIG. 1 is a schematic structural diagram of an electronic device according to an embodiment of the present application. DETAILED DESCRIPTION
[0047] To make the purpose, technical solutions, and advantages of this application more clear, the technical solutions of this application will be clearly and completely described below in conjunction with the specific embodiments of this application and the corresponding drawings. Obviously, the embodiments described are only part of the embodiments of this application, not all of them. Based on the embodiments in this application, all other embodiments obtained by ordinary technicians in this field without making creative efforts are within the scope of protection of this application.
[0048] The terms used in the implementation section of this application are only used to explain the specific embodiments of this application and are not intended to limit this application.
[0049] To prevent users from accidentally deleting cloud resources when changing them, one feasible solution is to implement traffic control for cloud resource changes. This prevents large-scale changes in a short period of time, which could lead to accidental deletion of cloud resources. For example, a limit of three EIPs can be set within 30 minutes. If a business unbinds more than three EIPs within 30 minutes, this change will be identified as a high-risk change and traffic control will be triggered, preventing the high-risk EIP unbinding operation from continuing. This prevents EIPs from being accidentally bound.
[0050] While implementing traffic control on cloud resource changes can prevent abnormal batch changes to a certain extent, it cannot guarantee service integrity. For cloud resources with topological relationships, unbinding or deleting a cloud resource may also cause its upper-layer resources to be unbound or deleted.
[0051] For example, consider the relationship between domain names and EIPs. Users access corresponding business services through domain names, and domain names, in turn, request backend services through their associated EIPs. To ensure service availability, at least one EIP must be bound to the domain name. Unbinding the last EIP from a domain will render the domain unavailable. While rate limiting can help prevent EIP unbindings from becoming too rapid, it cannot guarantee that the last EIP will not be unbound.
[0052] For example, if a domain A is associated with five EIPs, and a user mistakenly binds an EIP to domain A, after unbinding three, they are blocked when attempting to unbind the fourth, leaving only two. If the user has already noticed the misbinding, the current policy successfully prevents this misoperation. If not, and they continue to unbind the EIPs under domain A within the next 30 minutes, unbinding the remaining two EIPs will not trigger a block. At this point, all five EIPs under domain A are unbound, causing service disruption.
[0053] In view of the above situation, an embodiment of the present application provides a method for changing cloud resources. In the method of an embodiment of the present application, when a user changes cloud resources, the cloud resource change request of the user is not immediately responded to. Instead, it is determined whether the cloud resource change request corresponds to unbinding or deleting cloud resources. When the cloud resource change request corresponds to unbinding or deleting cloud resources, it is verified whether unbinding or deleting the cloud resources will cause the upper-layer resources of the cloud resources to be unavailable. If unbinding or deleting the cloud resources will cause the upper-layer resources of the cloud resources to be unavailable, the cloud resource change request is intercepted. If unbinding or deleting the cloud resources will not cause the upper-layer resources of the cloud resources to be unavailable, the cloud resource change request is released.
[0054] According to the method of the embodiment of the present application, when unbinding or deleting cloud resources by the user will cause the upper-layer resources to be unavailable, the user can be reminded, so as to effectively avoid accidentally deleting cloud resources during cloud resource change and avoid business damage.
[0055] Specifically, in one embodiment, it is verified whether the cloud resource to be unbound or deleted is the last cloud resource under the corresponding topology (TOPO) relationship; if the cloud resource is the last cloud resource under the corresponding topology relationship, it is determined that unbinding or deleting the cloud resource will cause the upper-layer resources of the cloud resource to be unavailable. At this time, unbinding the cloud resource is temporarily blocked, and the user is prompted to confirm whether to continue unbinding or deleting the cloud resource, so as to avoid misunbinding the last cloud resource under the topology relationship and avoid business damage.
[0056] Figure 1 The figure shows a flowchart of a method for changing cloud resources according to an embodiment of the present application.
[0057] In one embodiment, the following process shown in Figure 1 is executed to change cloud resources.
[0058] S100, Receive a cloud resource change request.
[0059] In the case where the cloud resource change request corresponds to unbinding or deleting cloud resources, S101 is executed.
[0060] S101, Determine the first cloud resource that the user attempts to unbind or delete according to the cloud resource change request.
[0061] In the embodiment of the present application, the first cloud resource can be any type of resource provided by a cloud service provider. For example, EIP, ECS, etc.
[0062] S110, Query the topology relationship (cloud resource topology relationship) of the first cloud resource.
[0063] S120, Determine whether the first cloud resource is the last cloud resource under its corresponding topology relationship according to the topology relationship of the first cloud resource.
[0064] Specifically, in this embodiment of the present application, the first cloud resource is the last cloud resource in its corresponding topological relationship. This means that if the first cloud resource is deleted, no cloud resources will exist in its corresponding topological relationship, and the topological relationship will not be supported. In other words, when the first cloud resource is deleted, the resources corresponding to the topological relationship to which the first cloud resource corresponds will also be deleted.
[0065] If the first cloud resource is not the last cloud resource in its corresponding topological relationship, execute S121.
[0066] S121: Respond to the cloud resource change request and unbind or delete the first cloud resource.
[0067] If the first cloud resource is the last cloud resource in its corresponding topological relationship, execute S122.
[0068] S122: Output a prompt message to the user, prompting that the first cloud resource currently being attempted to be unbound or deleted is the last cloud resource in its corresponding topological relationship.
[0069] S130: Request the user to confirm whether to continue unbinding or deleting the first cloud resource.
[0070] S131: Confirm whether to continue unbinding or deleting the first cloud resource according to user input.
[0071] If the user cancels the unbinding or deletion of the first cloud resource, execute S141.
[0072] S141: Abandon the cloud resource change request.
[0073] If the user confirms to continue unbinding or deleting the first cloud resource, execute S142.
[0074] S142: In response to the cloud resource change request, unbind or delete the first cloud resource.
[0075] For example, in one application scenario, a user attempts to unbind EIP1. EIP1's topology is as follows: EIP1 belongs to domain A, which contains only EIP1. According to the method of an embodiment of the present application, when the user attempts to unbind EIP1, the system recognizes that EIP1 is the last EIP under domain A. Therefore, the unbinding of EIP1 is temporarily suspended, and a reminder is displayed to the user, asking them to confirm whether to continue unbinding EIP1. This prevents the last EIP under domain A from being unbound due to user error.
[0076] For another example, in an application scenario, a user attempts to delete ECS1 (primary). The topological relationship of ECS1 (primary) is as follows: ECS1 (primary) belongs to middleware B, and under middleware B, there are ECS1 (primary), ECS2 (primary), ECS3 (standby), and ECS1 (standby). According to the method of the embodiment of the present application, when the user attempts to delete ECS1 (primary), it is recognized that deleting ECS1 (primary) is not the last ECS under middleware B. Therefore, ECS1 (primary) is deleted.
[0077] According to the method of the embodiment of the present application, when a user attempts to unbind or delete the last cloud resource under a topological relationship, the user can be reminded, thereby effectively avoiding accidentally deleting the last cloud resource under the topological relationship during cloud resource changes and avoiding business damage.
[0078] In one embodiment, the method for changing cloud resources provided by the present application is executed by a cloud server that provides cloud services.
[0079] In an actual application scenario, those skilled in the art can configure the cloud server in various different ways to implement the method for changing cloud resources proposed in the embodiment of the present application. The present application does not make specific limitations on this.
[0080] For example, Figure 2 Shown is a schematic diagram of the cloud service system architecture according to an embodiment of the present application.
[0081] The user's terminal device 200 is connected to the cloud server 210 that provides cloud services through a network. The cloud server 210 includes a cloud control platform 211, an Application Programming Interface (API) gateway 212, a cloud resource change evaluation service 213, and cloud services 214.
[0082] The cloud control platform 211 is used to provide a management interface for the user to apply for and change cloud resources. The cloud control platform 211 is used to generate a cloud resource change request based on the user operation input of the terminal device 200 and send the cloud resource change request to the API gateway 212.
[0083] The cloud resource change evaluation service 213 is loaded with a high-risk interception policy. The cloud resource change evaluation service 213 is used to evaluate whether the current cloud resource change triggers high-risk interception based on the high-risk interception policy. Specifically, in one embodiment, the high-risk interception policy loaded by the cloud resource change evaluation service 213 at least includes a first policy. The first policy is to determine whether the cloud resource that the user attempts to unbind or delete is the last cloud resource under the topological relationship. If the cloud resource that the user attempts to unbind or delete is the last cloud resource under the topological relationship, high-risk interception is triggered.
[0084] The API gateway 212 bears functions such as cloud resource registration, forwarding, and management of various control policies. The API gateway 212 is also used to intercept cloud resource change requests when the cloud resource change assessment service 213 determines that the current cloud resource change triggers a high-risk interception.
[0085] The cloud service 214 is used to provide cloud services for users. The cloud service 214 includes a business as a service (BaaS) service 215 and a resource TOPO service 216.
[0086] The BaaS service 215 is used to manage the cloud resources of cloud services, and it provides functions for creating, modifying, deleting, and querying cloud resources. The BaaS service 215 is used to implement corresponding cloud resource changes according to cloud resource change requests.
[0087] The resource TOPO service 216 is used to save the TOPO relationship of cloud resources, and it provides a cloud resource TOPO query interface.
[0088] The following is based on Figure 2 the shown cloud service system architecture, and the implementation process of the method for changing cloud resources according to an embodiment of the present application is described in detail through specific embodiments.
[0089] Figure 3 The shown is a timing diagram of the method for changing cloud resources according to an embodiment of the present application.
[0090] S310, the terminal device 200 accesses the cloud server 210 and calls the cloud control platform 211 to perform cloud resource change operations for cloud services.
[0091] S311, the cloud control platform 211 generates a cloud resource change request and sends the cloud resource change request to the API gateway 212.
[0092] S321, when the cloud resource change request does not correspond to unbinding or deleting cloud resources, the API gateway 212 forwards the cloud resource change request to the BaaS service 215.
[0093] S330, the BaaS service 215 implements the cloud resource change corresponding to the cloud resource change request.
[0094] Optionally, after the cloud resource change is successful, the cloud resource feeds back the change success information to the BaaS service 215, the BaaS service 215 feeds back the change success information to the API gateway 212, the API gateway 212 feeds back the change success information to the cloud control platform 211, and the cloud control platform 211 feeds back the change success information to the terminal device 200, and the terminal device 200 displays the change success information to the user.
[0095] S322, when the cloud resource change request corresponds to unbinding or deleting a cloud resource, the API gateway 212 intercepts the cloud resource change request and sends the request parameters of the cloud resource change request to the cloud resource change evaluation service 213.
[0096] S340, the cloud resource change evaluation service 213 calls the resource TOPO service 216 and queries the TOPO relationship of the first cloud resource through the cloud resource TOPO query interface.
[0097] S350, the resource TOPO service 216 feeds back the TOPO relationship of the first cloud resource to the cloud resource change evaluation service 213.
[0098] S341, the cloud resource change evaluation service 213 determines whether the first cloud resource is the last cloud resource under the topological relationship according to the TOPO relationship of the first cloud resource, and returns the judgment result to the API gateway 212.
[0099] In S341, if the first cloud resource is not the last cloud resource under the topological relationship, the cloud resource change evaluation service 213 returns a pass message to the API gateway 212.
[0100] S323, after receiving the pass message, the API gateway 212 forwards the cloud resource change request to the BaaS service 215.
[0101] S331, the BaaS service 215 implements the cloud resource change operation corresponding to the cloud resource change request (unbind or delete the first cloud resource).
[0102] After the cloud resource change is successful, the cloud resource feeds back the change success information to the BaaS service 215, the BaaS service 215 feeds back the change success information to the API gateway 212, the API gateway 212 feeds back the change success information to the cloud control platform 211, and the cloud control platform 211 feeds back the change success information to the terminal device 200, and the terminal device 200 displays the change success information to the user.
[0103] In S341, if the first cloud resource is the last cloud resource under the topological relationship, the cloud resource change evaluation service 213 returns a reject message to the API gateway 212.
[0104] S324, after receiving the reject message, the API gateway 212 feeds back an error prompt message (for example, 401 error code) to the cloud control platform 211.
[0105] S312, after receiving the error prompt message, the cloud control platform 211 sends a prompt message and a confirmation request to the terminal device 200.
[0106] S313, the terminal device 200 displays a prompt message to notify the user that the first cloud resource currently attempted to be unbound or deleted is the last cloud resource under the topological relationship.
[0107] S314, the terminal device 200 requests the user to confirm whether to continue to unbind or delete the first cloud resource based on the confirmation request.
[0108] S315, when the user cancels the execution of unbinding or deleting the first cloud resource, the terminal device 200 sends a cancellation execution instruction to the cloud control platform 211.
[0109] S316, the cloud control platform 211 issues a cancellation execution instruction to the API gateway 212.
[0110] S325, the API gateway 212 discards the cloud resource change request.
[0111] S317, when the user determines to continue to unbind or delete the first cloud resource, the terminal device 200 sends a continue execution instruction to the cloud control platform 211.
[0112] S318, the cloud control platform 211 issues a continue execution instruction to the API gateway 212.
[0113] [[ID=2|1]]S326, the API gateway 212 forwards the cloud resource change request to the BaaS service 215.
[0114] S332, the BaaS service 215 implements the cloud resource change corresponding to the cloud resource change request (unbinding or deleting the first cloud resource).
[0115] After the cloud resource change is successful, the cloud resource feeds back the change success information to the BaaS service 215, the BaaS service 215 feeds back the change success information to the API gateway 212, the API gateway 212 feeds back the change success information to the cloud control platform 211, the cloud control platform 211 feeds back the change success information to the terminal device 200, and the terminal device 200 displays the change success information to the user.
[0116] [[ID=3|0]]In an actual application scenario, those skilled in the art can configure the API gateway 212 and the cloud resource change evaluation service 213 in various different ways to implement the method for changing cloud resources proposed in the embodiments of the present application, and the present application does not make specific limitations thereto.
[0117] For example, Figure 4 The figure shows a timing diagram of the method for changing cloud resources according to an embodiment of the present application.
[0118] Before executing the Figure 3 shown process, execute the Figure 4 shown process.
[0119] In S400, register the cloud resource change interface of the cloud resource change request involving high-risk cloud resource changes with the API gateway 212.
[0120] In one embodiment, the cloud resource change request involving high-risk cloud resource changes refers to that the cloud resource change operation corresponding to the cloud resource change request is a high-risk operation and may cause resource loss. The cloud resource change request involving high-risk cloud resource changes at least includes the cloud resource change request for unbinding or deleting cloud resources.
[0121] In S400, the registered cloud resource change interface at least includes a first interface, and the first interface corresponds to the cloud resource change request for unbinding or deleting cloud resources. Based on the execution of S400, in S311, the cloud control platform 211 calls the corresponding cloud resource change interface of the API gateway 212 and issues a cloud resource change request.
[0122] For example, register cloud resource change interface 1 and cloud resource change interface 2 with the API gateway 212 (cloud resource change interface 1 is the first interface). Cloud resource change interface 1 corresponds to the cloud resource change request for unbinding or deleting cloud resources, and cloud resource change interface 2 corresponds to the cloud resource change request that does not include unbinding or deleting cloud resources. In S311, the cloud control platform 211 calls the corresponding cloud resource change interface of the API gateway 212 according to the specific content of the cloud resource change request. For example, if the cloud resource change request is to unbind the EIP, the cloud control platform 211 calls cloud resource change interface 1 of the API gateway 212. Another example, if the cloud resource change request is to add an ECS, the cloud control platform 211 calls cloud resource change interface 2 of the API gateway 212.
[0123] Another example, register cloud resource change interface 3 with the API gateway 212, and cloud resource change interface 3 corresponds to unbinding the EIP; register cloud resource change interface 4 with the API gateway 212, and cloud resource change interface 4 corresponds to binding a new EIP; register cloud resource change interface 5 with the API gateway 212, and cloud resource change interface 5 corresponds to deleting an ECS (the first interface can be cloud resource change interface 3 and / or cloud resource change interface 5). In S311, the cloud control platform 211 calls the corresponding cloud resource change interface of the API gateway 212 according to the specific content of the cloud resource change request. For example, if the cloud resource change request is to unbind the EIP, the cloud control platform 211 calls cloud resource change interface 3 of the API gateway 212.
[0124] For example, in an application scenario, define the interface name of cloud resource change interface 3 as PUT, and the path where cloud resource change interface 3 is registered with the API gateway 212 is: PUT / {region} / huaweicloud / v1 / {project_id} / publicips / {publicip_id}.
[0125] Optionally, in S400, an evaluation interface is also registered in the cloud resource change evaluation service 211. When evaluating a cloud resource change request, the cloud resource change interface calls the evaluation interface and sends the request parameters of the cloud resource change request to the evaluation interface.
[0126] For example, the evaluation interface: POST / api / high_risk_control / v1 / api / evaluation /
[0127] The body parameters of the evaluation interface are defined as shown in Table 1 below.
[0128] Table 1
[0129] Parameter Name Type Description requestId string Request ID apiName string API Name apiRootPath string API Gateway Registration Interface rootPath apiBasePath string API Gateway Registration Interface basePath apiPath string API Gateway Registration Interface path method string Request Method requestPath string Actual Request Path serviceId string Service to Which the Request Belongs header object Original Request Header body string Original Request Body query object Query Parameter pathParam object Path Parameter
[0130] The response of the evaluation interface is: Pass / Reject.
[0131] S410, create a high-risk interception policy.
[0132] In S410, the high-risk interception policy at least includes a first policy. The first policy is to determine whether the cloud resource that the user attempts to unbind or delete is the last cloud resource under the topological relationship. If the cloud resource that the user attempts to unbind or delete is the last cloud resource under the topological relationship, high-risk interception is triggered.
[0133] S411, save the high-risk interception policy to the cloud resource change evaluation service 213.
[0134] Further, after S411 (or, in S410 or S411), configure the high-risk interception policy for the cloud resource change interface of the API gateway 212. One cloud resource change interface can correspond to one or more high-risk interception policies. Optionally, different cloud resource change interfaces can respectively correspond to different high-risk interception policies, and multiple cloud resource change interfaces can also correspond to the same high-risk interception policy.
[0135] According to the method of the embodiment of the present application, creating multiple high-risk interception policies can flexibly implement the interception of cloud resource change operations for different application scenarios.
[0136] Specifically, after the cloud control platform 211 invokes the corresponding cloud resource change interface of the API gateway 212 and sends the cloud resource change request to the API gateway 212, the API gateway 212 queries whether there is a corresponding high-risk interception policy for this cloud resource change interface. If not, it forwards the cloud resource change request to the BaaS service 215, and the BaaS service 215 implements the cloud resource change corresponding to the cloud resource change request (S321 - S330). If so, it invokes the cloud resource change assessment service 213, and the cloud resource change assessment service 213 invokes the high-risk interception policy of the corresponding cloud resource change interface to evaluate whether the cloud resource change request triggers high-risk interception.
[0137] According to the method of the embodiment of the present application, by determining whether there is a corresponding high-risk interception policy to confirm whether to intercept the cloud resource change operation, the judgment logic is simplified, making it easier to implement the interception of the cloud resource change operation.
[0138] Further, in an embodiment, an evaluation interface is registered in the cloud resource change assessment service 213. After the cloud control platform 211 invokes the corresponding cloud resource change interface of the API gateway 212 and sends the cloud resource change request to the API gateway 212, the API gateway 212 queries whether there is a corresponding high-risk interception policy for this cloud resource change interface. If so, it invokes the evaluation interface of the cloud resource change assessment service 213. After receiving the call to the evaluation interface, the cloud resource change assessment service 213 queries the high-risk interception policy of the corresponding cloud resource change interface and evaluates whether the cloud resource change request triggers high-risk interception.
[0139] Furthermore, in an embodiment, it can be configured on the API gateway 212 to enable or disable the created high-risk interception policy; or, for a certain cloud resource change interface, enable or disable the high-risk interception policy corresponding to this cloud resource change interface. After the cloud control platform 211 invokes the corresponding cloud resource change interface of the API gateway 212 and sends the cloud resource change request to the API gateway 212, the API gateway 212 queries whether there is an enabled high-risk interception policy corresponding to this cloud resource change interface. If not, it forwards the cloud resource change request to the BaaS service 215, and the BaaS service 215 implements the cloud resource change corresponding to the cloud resource change request (S321 - S330). If so, it invokes the cloud resource change assessment service 213, and the cloud resource change assessment service 213 invokes the high-risk interception policy of the corresponding cloud resource change interface to evaluate whether the cloud resource change request triggers high-risk interception.
[0140] According to the method of the embodiment of the present application, by configuring the enabling and disabling of the high-risk interception policy, the interception of the cloud resource change operation can be flexibly implemented for different application scenarios.
[0141] Further, in one embodiment, the above interface registration, policy creation, and policy configuration operations are performed by the maintenance personnel of the cloud service. Specifically, a terminal device (other than the terminal device 200) used to maintain the cloud service can access the cloud server 210, and the maintenance personnel can operate the terminal device to implement interface registration, policy creation, and policy configuration. In another embodiment, the user can also operate the terminal device 200 to access the cloud server 210, and the user can operate the terminal device 200 to implement interface registration, policy creation, and policy configuration.
[0142] Optionally, in one embodiment, a policy script for the high-risk interception policy is developed based on declarative code (e.g., yaml) and a data query language (e.g., jq, yaql, etc.). The policy script is published through an IAC tool, and the policy development is flexible, efficient, and low-cost.
[0143] Specifically, in one embodiment, the input of the high-risk interception policy is the parameters of the cloud resource change request to be evaluated (or, the cloud resource change interface called for the cloud resource change request). For example, the path parameter, data header parameter, query parameter, and body parameter of the cloud resource change interface.
[0144] The properties of the policy script of the high-risk interception policy include the interface (api) property, extraction (extract) property, aggregation (aggregate) property, and rule (rule) property.
[0145] The api property is used to describe the interface characteristics corresponding to the current high-risk interception policy. Based on the api property, it is possible to match the corresponding high-risk interception policy according to the request parameters of the cloud resource change request.
[0146] Specifically, the api property includes a combination of any one or more of the startup path (rootPath), base path (basePath), path, and interface name (method). The rootPath, basePath, path, and method in the api property are indexes of the cloud resource change interface registered with the API gateway 212. According to a combination of one or more of the rootPath, basePath, path, and method of the cloud resource change interface, search for the api property that contains a match for one or more of the rootPath, basePath, path, and method, so as to determine the high-risk interception policy that contains the api property.
[0147] Optionally, in one embodiment, the properties of the policy script of the high-risk interception policy do not include the api property. Outside the high-risk interception policy, a correspondence table is created, which is used to save the correspondence between the high-risk interception policy and the cloud resource change interface.
[0148] The extract property is used to extract the input for subsequent rule analysis from the request parameters of the cloud resource change request.
[0149] The aggregate property is used to aggregate the extraction results of the extract property of multiple cloud resource change requests. The configuration scenario of the aggregate property is the scenario where multiple cloud resource change requests need to be aggregated, and the evaluation scenario of whether to trigger high-risk interception is performed on the aggregated result. For the evaluation scenario where only a single cloud resource change request needs to be evaluated for whether to trigger high-risk interception, the aggregate property can be not set, or the aggregate property can be set to null (for example, configure aggregate: null).
[0150] In one embodiment, the aggregate property includes three properties:
[0151] a) groupBy: The dimension of aggregation, which takes values based on the jq expression. The input is the extraction result of the extract property. Leave it blank or set a fixed value all, indicating the entire network;
[0152] b) when: The condition for triggering aggregation, based on the jq expression;
[0153] c) ttl: The expiration time of each element in the queue used for aggregation.
[0154] The rule property is used to evaluate based on the input.
[0155] In one embodiment, the rule property includes three properties:
[0156] a) when: The trigger condition for interception, based on the jq expression. The input is divided into the following two scenarios:
[0157] Scenario 1: The scenario that needs to be aggregated, that is, the policy script is configured with the aggregate property and the aggregate property is not null.
[0158] The input is the queue aggregated in the aggregate step plus the current extract result. For example:
[0159] {
[0160] "exract": {},
[0161] "aggregate": [{extract result 1}, {extract result 2}, {extract result 3}……]
[0162] }
[0163] Scenario 2: Scenarios where aggregation is not required, the policy script does not configure the aggregate attribute or the aggregate attribute is empty.
[0164] The input is the extraction result of the extract attribute of the current cloud resource change request.
[0165] b) then: Set the evaluation result returned to the API gateway 212 after evaluation.
[0166] For example, the evaluation result value can be: reject / alarm / approve, etc.
[0167] c) message: The text description of the high-risk interception policy.
[0168] Furthermore, in one embodiment, implement a topology query function in the policy script of the first policy. In this function, request the topology service open interface to query topology data. When the user performs a high-risk change, if the high-risk interception policy is triggered, this function will be called to query the corresponding topology data, and the query topology data will be used in the policy to analyze whether interception is required.
[0169] Specifically, in one embodiment, define a topology query function (query_topo_data). This topology query function is a jq function, which needs to be implemented in the service code. Its main function is to query the required topo data from the topo service according to the input parameters.
[0170] Implement domain name (domain) query in the policy script of the first policy through the topology query function (jq function).
[0171] For example, define a topology query function (query_topo_data):
[0172] / **
[0173] * Query topology data
[0174] * @param viewName View name
[0175] * @param condition Query condition
[0176] * @return Queried data
[0177] * /
[0178] Object query_top_data(String viewName, String condition)
[0179] Alternatively, define the topology query function (query_topo_data):
[0180] List <object>query_topo_data(String viewName, String filter).
[0181] In the policy script of the first policy, the domain name query is implemented through the topology query function (jq function). Specifically, the topology query function is called in the extract attribute to extract the domain data.
[0182] For example:
[0183] extract:
[0184] domain: query_topo_data("eipDomainView”, ”eip = ” +.request.body.publicip.ip).
[0185] For example, in an embodiment, the attribution types of the high-risk interception policy include: Guided Cloud Service (WiseCloud), Policy, and Interface Request (APIRequest).
[0186] In an embodiment, the first policy is named prevent-unbind-the-last-eip-in-the-domain.
[0187] The policy script of the first policy is as follows:
[0188]
[0189]
[0190] Optionally, in S410, the high-risk interception policy further includes policies other than the first policy.
[0191] For example, the high-risk interception policy further includes a second policy.
[0192] The second policy is named prevent-concurrent-unbind-eip-at-the-same-time.
[0193] The policy script of the second policy is as follows:
[0194]
[0195] For another example, the high-risk interception policy further includes a third policy (flow limiting policy). The third policy is to determine whether the number of the same type of cloud resources that the user has unbound or deleted within a preset duration (e.g., 30 minutes) starting from the current moment reaches a preset value (e.g., 3). The same type of cloud resources refers to the cloud resources of the same type as the cloud resources that the user is currently attempting to unbind or delete. If the number of the same type of cloud resources that the user has unbound or deleted within the preset duration starting from the current moment reaches the preset value, high-risk interception is triggered.
[0196] Optionally, the high-risk interception policy further includes a fourth policy (list policy). The fourth policy is to determine whether the cloud resources that the user is currently attempting to unbind or delete are on the pre-stored resource list. If the cloud resources that the user is currently attempting to unbind or delete are on the pre-stored first resource list, high-risk interception is triggered; or, to determine whether the cloud resources that the user is currently attempting to unbind or delete are on the pre-stored second resource list. If the cloud resources that the user is currently attempting to unbind or delete are not on the pre-stored resource list, high-risk interception is triggered.
[0197] Figure 5 Shown is a schematic diagram of the cloud service system architecture according to an embodiment of the present application.
[0198] The user's terminal device 500 is connected to the cloud server 501 that provides cloud services. The cloud server 501 includes a cloud control platform 510, an API gateway 520, a cloud resource change evaluation service 530, and a cloud service 540.
[0199] The cloud control platform 510 is used to provide a management interface for the user to apply for and change cloud resources.
[0200] The API gateway 520 includes an interface module 521 and a policy management module 522.
[0201] The cloud resource change evaluation service 530 includes an interface module 531, a policy management module 532, and a resource topology cache 533.
[0202] The cloud service 540 is used to provide cloud services for the user. The cloud service 540 includes a BaaS service 541 and a resource TOPO service 542.
[0203] Figure 6 Shown is a timing diagram of the method for changing cloud resources according to an embodiment of the present application.
[0204] S600, register the cloud resource change interface of the cloud resource change request involving high-risk cloud resource changes to the interface module 521 of the API gateway 520.
[0205] Specifically, in S500, the registered cloud resource change interfaces at least include the interface PUT, and the interface PUT corresponds to the cloud resource change request for unbinding the EIP. The path where the interface PUT is registered on the API gateway 520 is:
[0206] PUT / {region} / huaweicloud / v1 / {project_id} / publicips / {publicip_id}.
[0207] S601, register the evaluation interface in the interface module 531 of the cloud resource change evaluation service 213.
[0208] For example, the evaluation interface: POST / api / high_risk_control / v1 / api / evaluation /
[0209] The definition of the body parameters of the evaluation interface is shown in Table 1. The response of the evaluation interface is: Pass / reject.
[0210] S602, create a high-risk interception policy.
[0211] Specifically, referring to S410, in S601, create the first policy, the second policy, the third policy, and the fourth policy. Further, register the first policy, the second policy, and the third policy in the policy management module 522, and register that the first policy corresponds to the interface PUT.
[0212] Based on the policy script of the above first policy, when the first policy is called for evaluation, judge the currently unbound
[0213] S603, save the high-risk interception policy to the policy management module 532 of the cloud resource change evaluation service 530.
[0214] S604, configure the enabling and / or disabling of the high-risk interception policy in the policy management module 522. For example, enable the first policy and disable the second policy, the third policy, and the fourth policy.
[0215] S610, the terminal device 200 accesses the cloud server 210 and calls the cloud control platform 211 to perform the operation of unbinding the EIP.
[0216] For example, the user submits the EIP to be unbound (assumed to be: 192.168.1.100) and the corresponding port number (port_id) (assumed to be: "") on the cloud control platform 211.
[0217] S611, the cloud control platform 211 generates a cloud resource change request (EIP unbinding request), invokes the corresponding EIP unbinding interface PUT (PUT / {region} / huaweicloud / v1 / {project_id} / publicips / {publicip_id}), and issues the cloud resource change request to the interface module 521.
[0218] S620, after receiving the interface PUT call, the interface module 521 invokes the policy management module 522 to query whether there is an enabled high-risk interception policy configured for the corresponding interface PUT.
[0219] In S620, the interface module 521 queries that there is an enabled high-risk interception policy (the first policy) configured for the corresponding interface PUT.
[0220] S622, the interface module 521 invokes the evaluation interface registered in the interface module 531 and passes the request parameters of the EIP unbinding request to the evaluation interface.
[0221] For example, in S622, the interface module 521 invokes the evaluation interface, and the request parameters passed are:
[0222]
[0223]
[0224] S630, after receiving the evaluation interface call, the interface module 531 invokes the policy management module 532 to query the high-risk interception policy (the first policy) for the corresponding EIP unbinding request.
[0225] For example, in one embodiment, the policy management module 532 searches for a high-risk interception policy with a matching api attribute from the saved high-risk interception policies according to the rootPath, path, and method in the parameters of the EIP unbinding request passed to the evaluation interface in S622. The policy management module 532 finds that the api attribute of the first policy matches the rootPath, path, and method in the parameters of the EIP unbinding request passed to the evaluation interface in S622.
[0226] S631, the evaluation interface of the interface module 531 generates an evaluation result (Pass or reject) based on the first policy and the request parameters received in S622.
[0227] Figure 7 Shown is a partial method flowchart for changing cloud resources according to an embodiment of the present application.
[0228] As Figure 7 shown, S631 includes:
[0229] S701, according to the extract attribute of the first policy, extract data from the request parameters received in S622 as the input of the rule attribute.
[0230] Specifically, S701 includes:
[0231] a) Extract the port number (port_id), execute the jq expression.request.body.publicip.port_id, and extract the port_id field under the publicip object from the body parameter in the evaluation interface ("body":"{\"publicip\":{\"ip\":\"192.168.1.100\",\"port_id\":\"\"}}",), and the result obtained is "";
[0232] b) Extract the domain name (domain), call the query_topo_data jq function, and execute the jq expression:
[0233] query_topo_data("eipDomainView","eip="+.request.body.publicip.ip),
[0234] Suppose the extracted domain name is: xxx.huaweicloud.com.
[0235] Finally, the output of the extract attribute obtained by S701 is:
[0236] {"extract”:{
[0237] "port_id”:"",
[0238] "domain”:"xxx.huaweicloud.com”
[0239] }}
[0240] S702, according to the rule attribute of the first policy, generate an evaluation result based on the output of the extract attribute.
[0241] Specifically, in S702, execute the jq expression:
[0242] when:(query_topo_data("eipDomainView","domain="+.extract.doamin)|length)<=1
[0243] then:reject.
[0244] That is, call the query_topo_data jq function, query the EIP list under the xxx.huaweicloud.com domain from the eipDomainView according to the "domain": "xxx.huaweicloud.com" output by the extract attribute, and calculate the number of EIPs. If the number of EIPs <= 1 (meeting the when condition), generate an evaluation result of reject (indicating that the EIP to be unbound currently is the last EIP under this domain and it is not allowed to unbind the EIP). If the when condition is not met, generate an evaluation result of pass.
[0245] In S701 and S702, the evaluation interface requests the TOPO relationship from the resource TOPO service 542 through the resource topology cache 533 to achieve the extraction of the domain name and the acquisition of the EIP list under the domain name.
[0246] Suppose the final evaluation result obtained in S702 is pass. After S702, S632 is executed.
[0247] S632, the evaluation interface of the interface module 531 feeds back the evaluation result of pass to the interface PUT of the interface module 521.
[0248] S640, after the evaluation interface of the interface module 531 receives the evaluation result of pass, it forwards the EIP unbinding request to the BaaS service 541.
[0249] S650, the BaaS service 541 performs the EIP unbinding operation corresponding to the EIP unbinding request.
[0250] In the description of the embodiments of the present application, for the convenience of description, when describing the device, it is divided into various modules according to functions and described separately. The division of each module is only a logical function division. When implementing the embodiments of the present application, the functions of each module can be implemented in the same or multiple software and / or hardware.
[0251] Specifically, the device proposed in the embodiments of the present application can be fully or partially integrated into a physical entity in actual implementation, or physically separated. And these modules can all be implemented in the form of software called by processing elements; they can also all be implemented in the form of hardware; or some modules can be implemented in the form of software called by processing elements, and some modules can be implemented in the form of hardware. For example, the detection module can be a separately established processing element or can be integrated in a certain chip of an electronic device. The implementation of other modules is similar. In addition, these modules can be fully or partially integrated together or can be independently implemented. In the implementation process, each step of the above method or each of the above modules can be completed by the integrated logic circuit in the processor element or the instruction in the form of software.
[0252] For example, these modules above can be one or more integrated circuits configured to implement the above method, such as: one or more Application Specific Integrated Circuits (ASICs), or, one or more Digital Signal Processors (DSPs), or, one or more Field Programmable Gate Arrays (FPGAs), etc. Again, these modules can be integrated together and implemented in the form of a System-On-a-Chip (SOC).
[0253] An embodiment of the present application also proposes an electronic device. This electronic device is used to execute the method process or part of the method process described in the embodiments of the present application. The electronic device can be the terminal device or cloud server described in the embodiments of the present application.
[0254] Figure 8 It is a schematic structural diagram of an electronic device according to an embodiment of the present application.
[0255] As Figure 8 shown, the electronic device 2500 includes a memory 2502 for storing computer program instructions and a processor 2501 for executing the program instructions. Among them, when the computer program instructions are executed by the processor 2501, the electronic device 2500 is triggered to execute the method steps described in the embodiments of the present application.
[0256] Specifically, in an embodiment of the present application, the above one or more computer programs are stored in the above memory 2502. The above one or more computer programs include instructions. When the above instructions are executed by the electronic device 2500, the electronic device 2500 is made to execute the method steps described in the embodiments of the present application.
[0257] It can be understood that the structural description of the electronic device 2500 in the embodiments of the present application does not constitute a specific limitation on the electronic device 2500. In other embodiments of the present application, the electronic device 2500 may include other components in addition to the processor 2501 and the memory 2502.
[0258] The processor 2501 can be a System-On-a-Chip (SOC). The processor 2501 may include a Central Processing Unit (CPU) and may further include other types of processors.
[0259] The processor involved in processor 2501 may, for example, include a CPU, a DSP, a microcontroller, or a digital signal processor, and may also include a GPU, an embedded neural-network processor (NPU), and an image signal processor (ISP). The processor may further include necessary hardware accelerators or logic processing hardware circuits, such as an ASIC, or one or more integrated circuits for controlling the execution of the technical solution program of this application. In addition, the processor may have the function of operating one or more software programs, and the software programs may be stored in a storage medium.
[0260] Processor 2501 may include one or more processing units. For example, the processor may include an application processor (AP), a modem processor, a graphics processing unit (GPU), an image signal processor (ISP), a controller, a video codec, a digital signal processor (DSP), a baseband processor, and / or a neural-network processing unit (NPU), etc. Among them, different processing units may be independent components or integrated in one or more processors. In some embodiments, the electronic device 2500 may also include one or more processors 2501. Among them, the controller may generate an operation control signal according to the instruction opcode and timing signal to complete the control of fetching and executing instructions.
[0261] In some embodiments, the processor 2501 may include one or more interfaces. The interfaces may include an inter-integrated circuit (I2C) interface, an integrated circuit sound (I2S) interface, a pulse code modulation (PCM) interface, a universal asynchronous receiver / transmitter (UART) interface, a mobile industry processor interface (MIPI), a general-purpose input / output (GPIO) interface, a SIM card interface, and / or a USB interface, etc. Among them, the USB interface is an interface that complies with the USB standard specification, and specifically may be a Mini USB interface, a Micro USB interface, a USB Type C interface, etc. The USB interface can be used to connect a charger to charge the electronic device, and can also be used to transfer data between the electronic device and peripheral devices.
[0262] The electronic device 2500 may further include an external memory interface, which is used to connect an external memory card, such as a Micro SD card, to implement the storage capacity expansion of the electronic device. The external memory card communicates with the processor 2501 through the external memory interface to implement the data storage function. For example, files such as music and videos are saved in the external memory card.
[0263] The memory 2502 may include a code storage area and a data storage area. Among them, the code storage area can store the operating system. The data storage area can store the data created during the use of the electronic device 2500, etc. In addition, the memory 2502 may include a high-speed random access memory, and may also include a non-volatile memory, such as one or more disk storage components, flash memory components, universal flash storage (UFS), etc.
[0264] The memory 2502 can be a read-only memory (ROM), other types of static storage devices that can store static information and instructions, a random access memory (RAM), or other types of dynamic storage devices that can store information and instructions. It can also be an electrically erasable programmable read-only memory (EEPROM), a compact disc read-only memory (CD-ROM), or other optical disc storage, optical disc storage (including compact discs, laser discs, optical discs, digital versatile discs, Blu-ray discs, etc.), magnetic disk storage media, or other magnetic storage devices. Or it can also be any computer-readable medium that can be used to carry or store the desired program code in the form of instructions or data structures and can be accessed by a computer.
[0265] The processor 250 and the memory 2502 can be integrated into a processing device, but more commonly they are independent components of each other.
[0266] Optionally, the devices, apparatuses, and modules illustrated in the embodiments of the present application can be specifically implemented by computer chips or entities, or by products with certain functions.
[0267] Those skilled in the art should understand that the embodiments of the present application can be provided as a method, an apparatus, or a computer program product. Therefore, the present invention can take the form of a complete hardware embodiment, a complete software embodiment, or an embodiment combining software and hardware aspects. Moreover, the present invention can take the form of a computer program product implemented on one or more computer-usable storage media that contain computer-usable program code.
[0268] In several embodiments provided by the present application, if any function is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application, in essence, or the part that contributes to the prior art, or a part of this technical solution, can be embodied in the form of a software product. This computer software product is stored in a storage medium and includes several instructions for causing a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the methods described in the various embodiments of the present application.
[0269] Specifically, in an embodiment of the present application, a computer-readable storage medium is further provided. The computer-readable storage medium stores a computer program. When it runs on a computer, it causes the computer to execute the method provided by the embodiment of the present application.
[0270] An embodiment of the present application further provides a computer program product, which includes a computer program. When it runs on a computer, it causes the computer to execute the method provided by the embodiment of the present application.
[0271] The embodiments described in the present application are described by referring to the flowcharts and / or block diagrams of the methods, devices (apparatuses), and computer program products according to the embodiments of the present application. It should be understood that each process and / or block in the flowchart and / or block diagram, and the combination of processes and / or blocks in the flowchart and / or block diagram can be implemented by computer program instructions. These computer program instructions can be provided to the processor of a general-purpose computer, a special-purpose computer, an embedded processor, or other programmable data processing devices to generate a machine, so that the instructions executed by the processor of the computer or other programmable data processing devices generate means for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0272] These computer program instructions can also be stored in a computer-readable memory that can guide a computer or other programmable data processing devices to work in a specific manner, so that the instructions stored in the computer-readable memory generate a manufactured product including instruction means, and the instruction means implements the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0273] These computer program instructions can also be loaded onto a computer or other programmable data processing devices, so that a series of operation steps are executed on the computer or other programmable devices to generate a computer-implemented process. Thus, the instructions executed on the computer or other programmable devices provide steps for implementing the functions specified in Figure 1 one process or multiple processes and / or blocks Figure 1 one block or multiple blocks.
[0274] It should also be noted that in the embodiments of the present application, "at least one" means one or more, and "multiple" means two or more. "And / or" describes the association relationship of associated objects and indicates that three relationships can exist. For example, A and / or B can represent the situation where A exists alone, A and B exist simultaneously, and B exists alone. Among them, A and B can be singular or plural. The character " / " generally represents an "or" relationship between the associated objects before and after. "At least one of the following" and its similar expressions refer to any combination of these items, including any combination of single items or plural items. For example, at least one of a, b, and c can represent: a, b, c, a and b, a and c, b and c, or a and b and c, where a, b, and c can be single or multiple.
[0275] In the embodiments of the present application, the terms "comprising", "including" or any other variant thereof are intended to cover non-exclusive inclusion, such that a process, method, commodity or device comprising a series of elements includes not only those elements but also other elements not expressly listed, or elements inherent to such process, method, commodity or device. Without further limitation, an element defined by the statement "comprising an..." does not exclude the presence of additional identical elements in the process, method, commodity or device comprising the element.
[0276] The present application may be described in the general context of computer-executable instructions executed by a computer, such as program modules. Generally, program modules include routines, programs, objects, components, data structures, etc. that perform specific tasks or implement specific abstract data types. The present application may also be practiced in a distributed computing environment where tasks are performed by remote processing devices connected through a communication network. In a distributed computing environment, program modules may be located in local and remote computer storage media including storage devices.
[0277] The various embodiments in the present application are described in a progressive manner. For the parts that are the same or similar among the various embodiments, reference may be made to each other. Each embodiment focuses on the differences from other embodiments. In particular, for the apparatus embodiments, since they are basically similar to the method embodiments, the description is relatively simple. For the relevant parts, reference may be made to the corresponding descriptions in the method embodiments.
[0278] Those of ordinary skill in the art can realize that the units and algorithm steps described in the embodiments of the present application can be implemented by electronic hardware, computer software, or a combination of electronic hardware. Whether these functions are executed in hardware or software depends on the specific application and design constraints of the technical solution. Professionals can use different methods to implement the described functions for each specific application, but such implementation should not be considered to exceed the scope of the present application.
[0279] Those skilled in the art can clearly understand that for the convenience and conciseness of description, the specific working processes of the above-described apparatus, device and unit can refer to the corresponding processes in the foregoing method embodiments and will not be elaborated herein.
[0280] The above are only the specific embodiments of the present application. Any person skilled in the art can easily think of changes or substitutions within the technical scope disclosed in the present application, and all such changes or substitutions should be covered within the protection scope of the present application. The protection scope of the present application shall be subject to the protection scope of the claims.< / object>
Claims
1. A method for changing cloud resources, characterized in that: The method comprises: Determining, based on a cloud resource change request, whether unbinding or deleting a first cloud resource causes upper-layer resources of the first cloud resource to be unavailable, wherein the cloud resource change request corresponds to unbinding or deleting the first cloud resource; In the case that unbinding or deleting the first cloud resource will cause the upper-layer resource to be unavailable, a prompt message is output.
2. The method according to claim 1, characterized in that The determining, according to the cloud resource change request, whether unbinding or deleting the first cloud resource causes upper-layer resources of the first cloud resource to be unavailable includes: Determine, according to the cloud resource change request, whether the first cloud resource is the last cloud resource in a cloud resource topology relationship, wherein: The cloud resource topology relationship includes a topology relationship between the first cloud resource and the upper layer resource; In the case where the first cloud resource is the last cloud resource in the cloud resource topology relationship, unbinding or deleting the first cloud resource will cause the upper-layer resource to be unavailable.
3. The method according to claim 2, characterized in that The first cloud resource is an elastic public IP address (EIP), and the upper-layer resource of the first cloud resource is the domain name to which the EIP belongs.
4. The method according to claim 2, characterized in that The first cloud resource is a cloud server (ECS), and the upper-layer resource of the first cloud resource is a cloud server middleware to which the ECS belongs.
5. The method according to any one of claims 2 to 4, characterized in that The method further includes creating one or more high-risk interception policies, wherein the one or more high-risk interception policies include at least a first policy, the first policy being configured to determine, based on request parameters of the cloud resource change request, whether the first cloud resource is the last cloud resource in a cloud resource topology relationship; The determining, based on the cloud resource change request, whether the first cloud resource is the last cloud resource in the cloud resource topology relationship includes, based on the request parameters of the cloud resource change request, querying a high-risk interception policy that matches the request parameters from the one or more high-risk interception policies.
6. The method according to claim 5, characterized in that The determining, according to the cloud resource change request, whether the first cloud resource is the last cloud resource in a cloud resource topology relationship further includes: When a first policy matching the request parameters is found, calling the first policy; According to the request parameters and based on the first policy, it is determined whether the first cloud resource is the last cloud resource in the cloud resource topology relationship.
7. The method according to claim 6, characterized in that: The request parameters include interface characteristics of the first cloud resource, and the interface characteristics include any one or more combinations of a startup path, a basic path, a path, and an interface name; The policy script of the high-risk interception policy includes interface attributes, wherein the interface attributes include any one or more combinations of a startup path, a base path, a path, and an interface name, wherein the interface attributes of the first policy match the interface characteristics of the first cloud resource; The querying for a high-risk interception policy that matches the request parameter includes: querying for a high-risk interception policy that matches the interface feature in the request parameter according to the interface feature in the request parameter.
8. The method according to claim 6, characterized in that The first cloud resource is an EIP, the upper-layer resource of the first cloud resource is the domain name to which the EIP belongs, and the policy script of the first policy includes: Extracting attributes, which are used to call the topological relationship to which the first cloud resource belongs according to the request parameter, and obtain the domain name to which the first cloud resource belongs according to the topological relationship of the first cloud resource; A rule attribute is used to call the topological relationship to which the first cloud resource belongs according to the request parameter, and determine whether the domain name to which the first cloud resource belongs only contains the first cloud resource according to the domain name to which the first cloud resource belongs and the topological relationship to which the first cloud resource belongs.
9. The method according to claim 5, characterized in that After said creating one or more high-risk interception strategies, said method includes turning on or off one or more high-risk interception strategies of said one or more high-risk interception strategies; The query matches the high-risk interception policy of the request parameter. This includes searching for a high-risk interception policy that matches the request parameters from one or more enabled high-risk interception policies.
10. The method according to claim 9, characterized in that The method further comprises: When no high-risk interception policy matching the request parameters is found from one or more enabled high-risk interception policies, the first cloud resource is unbound or deleted based on the cloud resource change request.
11. An electronic device, characterized in that: The electronic device comprises a memory for storing computer program instructions and a processor for executing the computer program instructions, wherein when the computer program instructions are executed by the processor, the electronic device is triggered to perform the method steps according to any one of claims 1 to 10.
12. A computer-readable storage medium, characterized in that The computer-readable storage medium stores a computer program, which, when executed on a computer, enables the computer to execute the method according to any one of claims 1 to 10.