General computing power management method and device, equipment, medium and program product
By configuring the event flow sequence of virtual control nodes and hook functions, the problems of insufficient flexibility and security in traditional computing power management methods are solved, flexible scheduling and safe management of computing power resources are achieved, and resource utilization is improved.
Patent Information
- Application Number
- CN202510599916.1
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-05-09
- Publication Date
- 2025-10-10
AI Technical Summary
Traditional general computing power management methods have poor flexibility and make it difficult to achieve flexible scheduling and secure management of computing power resources.
By pre-configuring control items and standard template files, using virtual control nodes and hook functions, and combining event flow sequences to perform control operations, including access permission verification, computing power quota deduction, and resource pool information matching, precise control of target tenants can be achieved.
It improves the security and utilization of computing resources, ensures the rational allocation of resources among different tenants, reduces the risk of resource abuse, adapts to different computing resource architectures and business scenarios, and achieves the coexistence of flexibility and security.
Smart Images

Figure CN120762874A_ABST
Abstract
Description
TECHNICAL FIELD
[0001] The present application relates to the technical field of cloud computing, in particular to a general computing power management method and device, equipment, medium and program product. BACKGROUND
[0002] With the rapid development of cloud computing technology, computing power demand is increasing and diversifying. Efficient management and flexible scheduling of general computing power have become a key problem. The traditional management method of general computing power has poor flexibility. Therefore, there is an urgent need for a computing power resource management method with high flexibility. SUMMARY
[0003] Therefore, the embodiments of the present application provide a general computing power management method, device, equipment, medium and program product.
[0004] In a first aspect, the embodiments of the present application provide a general computing power management method, which comprises:
[0005] Preconfigured control items and standard template files; the control items include resource pool information, computing power quota and access rights of ordinary tenants; the standard template file is configured with a virtual control node, and the virtual control node is associated with a corresponding hook function;
[0006] Obtain the resource pool information selected by the target tenant, and write the resource pool information into a control context;
[0007] Determine a target template file, parse the target template file to obtain a virtual control node and an event flow sequence, the event flow sequence defines the execution order of the hook function associated with the virtual control node, and the target template file is a standard template file corresponding to the resource pool information selected by the target tenant;
[0008] According to the event flow sequence, trigger the hook function corresponding to the virtual control node in order to perform a control operation, and obtain a return result; store the return result in the control context;
[0009] According to the control context, determine resource creation information recognizable by a computing power provider, so that the computing power provider performs a resource creation operation according to the resource creation information.
[0010] In an optional implementation, the parsing of the target template file to obtain the virtual control node and the event flow sequence comprises:
[0011] Parse the target template file to identify the definition of the virtual control node and the description of the event flow sequence, and obtain the virtual control node and the event flow sequence.
[0012] In an optional implementation, determining resource creation information recognizable to a computing power provider based on the management and control context includes:
[0013] Target control information is extracted from the control context according to a preset grammar, and the target control information is written into the target template file to achieve rendering of the target template file; and resource creation information that can be identified by the computing power provider is obtained.
[0014] In an optional embodiment, after determining the resource creation information identifiable by the computing power provider according to the control context, the method further includes:
[0015] Distribute the resource creation information to the corresponding computing power provider.
[0016] In an optional implementation, the resource pool information includes: a unique identifier of the resource pool; the computing power quota includes an upper limit on the computing power resource usage of common tenants; and the access rights of common tenants include: resource pools that common tenants are allowed to access.
[0017] In an optional implementation, the control items are stored in a structured data format.
[0018] In a second aspect, the present application provides a general computing power management device, the general computing power management device comprising:
[0019] The first processing module is used to pre-configure control items and standard template files; the control items include: resource pool information, computing power quotas, and access rights of ordinary tenants; the standard template files are configured with virtual control nodes, and the virtual control nodes are associated with corresponding hook functions;
[0020] The second processing module is configured to obtain the resource pool information selected by the target tenant and write the resource pool information into the management and control context;
[0021] The third processing module is used to determine the target template file; parse the target template file to obtain the virtual control node and event flow sequence; the event flow sequence defines the execution order of the hook functions associated with the virtual control node; the target template file is a standard template file corresponding to the resource pool information selected by the target tenant;
[0022] A fourth processing module is used to trigger the hook function corresponding to the virtual control node in sequence according to the event flow sequence to perform the control operation and obtain a return result; and store the return result in the control context;
[0023] The fifth processing module is used to determine resource creation information that can be identified by the computing power provider based on the management and control context, so that the computing power provider can perform resource creation operations based on the resource creation information.
[0024] In a third aspect, the present application provides a computer device comprising: a memory and a processor, the memory and the processor being communicatively connected to each other, computer instructions being stored in the memory, and the processor executing the general computing power management method of the above-mentioned first aspect or any corresponding embodiment thereof by executing the computer instructions.
[0025] In a fourth aspect, the present application provides a computer-readable storage medium, on which a single computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the general computing power management method of the above-mentioned first aspect or any corresponding embodiment thereof.
[0026] In a fifth aspect, the present application provides a computer program product, comprising computer instructions, which are used to enable a computer to execute the general computing power management method of the above-mentioned first aspect or any corresponding embodiment thereof.
[0027] The technical solution provided by this application has the following technical effects:
[0028] The technical solution of the embodiment of the present application sets the access rights of ordinary tenants when pre-configuring the control items, effectively preventing illegal access, ensuring the security of computing resources, and reducing the risk of resource abuse. According to the event flow sequence, the hook function corresponding to the virtual control node is triggered in sequence to perform control operations. Control operations such as access right verification, computing quota deduction, and resource pool information matching can be performed. The access rights of the target tenant can be verified and the target tenant's use of computing resources can be accurately controlled. It avoids some tenants from excessively occupying computing resources, ensures that resources are reasonably allocated among different tenants, improves overall resource utilization, and enables limited computing resources to meet the needs of more tenants. By pre-configuring standard template files, it can adapt to different computing resource architectures and business scenarios. The control operations are abstracted into virtual control nodes and hook functions, and are triggered in an orderly manner through event flow sequences. It can achieve control over the flexibility of standard template files, while ensuring flexibility, improving the security of general computing power management, and achieving the coexistence of flexibility and security. BRIEF DESCRIPTION OF THE DRAWINGS
[0029] In order to more clearly illustrate the specific implementation methods of this application or the technical solutions in related technologies, the following is a brief introduction to the drawings required for use in the specific implementation methods or related technical descriptions. Obviously, the drawings described below are some implementation methods of this application. For ordinary technicians in this field, other drawings can be obtained based on these drawings without any creative work.
[0030] Figure 1 1 is a flowchart of a method for managing general computing power according to an embodiment of the present application;
[0031] Figure 2 This is a schematic diagram of an embodiment of the present application regarding the application of TOSCA in multi-cloud management;
[0032] Figure 3 It is a flowchart of the technical solution of this application;
[0033] Figure 4 This is a schematic diagram of the structure of a general computing power management device according to an embodiment of the present application;
[0034] Figure 5 It is a schematic diagram of the hardware structure of the computer device of an embodiment of the present application. DETAILED DESCRIPTION
[0035] To make the purpose, technical solutions, and advantages of the embodiments of the present application more clear, the technical solutions in the embodiments of the present application will be clearly and completely described below in conjunction with the drawings in the embodiments of the present application. Obviously, the described embodiments are part of the embodiments of the present application, not all of the embodiments. Based on the embodiments in the present application, all other embodiments obtained by those skilled in the art without making creative efforts shall fall within the scope of protection of this application.
[0036] Computing power distribution network: A platform that can convert the needs of computing power users (ordinary tenants) into corresponding computing power requirements and perform scheduling. It can access a variety of computing power.
[0037] General computing power: computing power provided by computing power providers, including but not limited to virtual machines, bare metal, elastic public IP (Elastic IP Address, EIP), virtual private cloud (Virtual Private Cloud, VPC), etc.
[0038] The Topology and Orchestration Specification for Cloud Applications (TOSCA) document, developed by the Organization for the Advancement of Structured Information Standards (OASIS), defines the topology and orchestration specifications for cloud applications. In layman's terms, it establishes a standard for describing the topology of applications on cloud platforms.
[0039] Virtual control node: In order to adapt to the TOSCA concept, a virtual execution node is generated to meet the control behavior in this application.
[0040] Computing power provider: A computing power service provider that provides a variety of computing power resources.
[0041] The use of TOSCA enables highly flexible computing power distribution networks, enabling them to translate into language understood by cloud vendors based on the needs of computing power providers. This high flexibility allows for unlimited expansion of computing power within the computing power distribution network. However, flexibility alone is not enough for a computing power distribution network platform. Platform-side control is essential for platform security. Furthermore, absolute control is essential for the coordinated and dispatchable computing power of the computing power distribution network.
[0042] The main purpose of this application is to solve the problem that the flexibility of TOSCA in the current computing power distribution network cannot be controlled. To solve this problem, the embodiment of this application injects the control items into the TOSCA parser through the hook function in the form of virtual control nodes. It can not only maintain the flexibility of the TOSCA definition language, but also control the security of the computing power distribution network platform. It can improve the security of the computing power distribution network while ensuring its flexibility.
[0043] An embodiment of the present application provides a method for managing general computing power. It should be noted that the steps shown in the flowchart of the accompanying drawings can be executed in a computer device such as a set of computer-executable instructions, and although a logical order is shown in the flowchart, in some cases, the steps shown or described can be executed in an order different from that shown here.
[0044] Figure 1 It is a flowchart of the general computing power management method of the embodiment of the present application.
[0045] like Figure 1 As shown, an embodiment of the present application provides a method for managing general computing power, which includes:
[0046] S101: Pre-configure control items and standard template files.
[0047] In this embodiment, control items include resource pool information, computing power quotas, and access rights for common tenants. Resource pool information includes a unique identifier for the resource pool, such as the resource pool ID, and may also include information such as geographic location, available computing power resources, and computing power resource types. Computing power quotas include the upper limit of computing power usage for common tenants. Common tenant access rights include the resource pools to which they are permitted to access, and may also include information such as the computing power resource types they are permitted to access. Control items are stored in a structured data format, such as JSON. The standard template file is specifically a cloud application topology and orchestration specification file (TOSCA file), which describes the topology and orchestration rules of a cloud application. Virtual control nodes are configured within the standard template file, and these virtual control nodes are associated with corresponding hook functions. There is a corresponding relationship between virtual control nodes and control items. It can be considered that one virtual control node corresponds to one control item. Control items are abstract concepts used to implement management and control logic, not actual physical resources. By associating hook functions, they implement functions such as permission control and resource allocation management.
[0048] In this embodiment, the platform administrator can pre-configure control items and standard template files on the computing power network distribution platform. Control items defined for the computing power network distribution platform, such as resource pool information, computing power quotas, and access rights for common tenants, are also written into the control context. This information can only be configured by high-authorized platform administrators. Considering that different computing power providers may use different languages, standard template files recognizable to each computing power provider can be configured for each provider. Different computing power providers can configure different control items. The platform administrator performs configuration tasks related to operations and maintenance management, specifically including: 1) Configuring standard template files corresponding to each computing power provider. 2) Configuring control items and associating them with computing power provider information (e.g., the computing power provider's name, unique identifier, etc.) to ensure that management configurations are accurately applied to the corresponding computing power resources, achieving effective management of computing power resources. 3) Defining hook functions for control edges. Control edges are essentially logical connections used to link different virtual control nodes in the TOSCA topology. 4) Configure control items to constrain the behavior of ordinary tenants, configure resource pool information, computing power quotas, and access rights of ordinary tenants, etc.
[0049] As an example, a standard template file includes the following:
[0050] tosca definitions version:cpdn evm_2_0
[0051] Description: Open virtual machine
[0052] Serwice_template.
[0053] #Define template input
[0054] inputs:
[0055] node_templates:
[0056] disk:
[0057] type:
[0058] metadata
[0059] properties:
[0060] flawor:{$get ctx:[sale,id]}
[0061] requirements:
[0062] -dependency:evm
[0063] -dependency:quota
[0064] evm:
[0065] type:
[0066] metadata
[0067] properties:
[0068] requirements:
[0069] -dependency:quota
[0070] -dependency:region
[0071] sale:
[0072] type:virtual
[0073] code:xxx.py
[0074] region:
[0075] type:virtual
[0076] In the standard template file in the above example, "xxx.py" is an executable script, a hook function corresponding to the virtual control node, and a script that implements the control logic. In this embodiment, in addition to directly running local Python scripts such as "xxx.py", two other methods can be used to execute the script that implements the control logic:
[0077] 1) HTTP-based script execution: Scripts are triggered and executed via the HTTP protocol. The script is deployed on a remote server, and the local platform initiates the script by sending a request to a specific HTTP endpoint. The request can carry the parameters required to execute the script. After the script is executed, the result is returned to the requester via an HTTP response. For example, a resource pool quota verification script can be deployed on a dedicated server. When the quota needs to be verified, the platform sends a request containing tenant information and resource request details to the server's specific HTTP interface. The server executes the script and returns the verification result.
[0078] 2) Use other dynamic languages to execute scripts: In addition to Python, you can also use other programming languages with dynamic features to write and execute scripts, such as JavaScript, Ruby, PHP, etc.
[0079] S102: Obtain the resource pool information selected by the target tenant, and write the resource pool information into the management and control context.
[0080] S103: Determine the target template file, parse the target template file, and obtain the virtual control node and event flow sequence.
[0081] In this embodiment, the event flow sequence defines the execution order of the hook functions corresponding to the virtual control nodes. The target template file is a standard template file corresponding to the resource pool information selected by the target tenant. The target template file can be parsed using a TOSCA parser to obtain the virtual control nodes and event flow sequence.
[0082] In this embodiment, a common tenant chooses to purchase computing resources provided by a computing power provider. After purchasing computing resources, the resource pool information (resource pool ID) selected by the common tenant (target tenant) is obtained and written into the management and control context.
[0083] Parse the target template file to obtain the virtual control nodes and event flow sequence, including:
[0084] The target template file is parsed to identify the definition of the virtual control node and the description of the event flow sequence, and the virtual control node and event flow sequence are obtained.
[0085] In this embodiment, as an example, the cloud application topology orchestration template file may include the following virtual management and control nodes:
[0086] A permission control node used to verify user access rights.
[0087] A quota control node used to deduct computing resource quotas.
[0088] Resource pool control node used to match resource pool region information.
[0089] In this embodiment, as an example, the event flow sequence can be specifically represented by a directed acyclic graph (DAG), and the order can be the authority management node, the quota management node, and the resource pool management node, and the corresponding hook functions of the authority management node, the quota management node, and the resource pool management node can be triggered in sequence.
[0090] Taking the standard template file of the above example as an example, the definition of the virtual management node and the description of the event flow sequence are identified, and the virtual management node and the event flow sequence are obtained, which can be specifically:
[0091] 1) Lexical analysis:
[0092] The TOSCA parser first performs lexical analysis on the target template file, and decomposes the content into individual lexical units. For example:
[0093] “tosca_definitions_version” will be identified as a keyword type lexical unit.
[0094] “cpdn”, “evm”, “2”, “0”, etc. will be identified as identifier type lexical units.
[0095] “description”, “service_template”, “inputs”, “node_templates”, etc. will also be identified as keyword type lexical units.
[0096] “disk”, “type”, “metadata”, “properties”, “flavor”, “sale”, “id”, “dependency”, “evm”, “quota”, “region”, etc. are also identifier type lexical units.
[0097] “{”, “}”, “[”, “]”, “:”, “-”, etc. symbols will be identified as corresponding symbol type lexical units.
[0098] 2) Syntax analysis:
[0099] On the basis of lexical analysis, syntax analysis is performed to construct an abstract syntax tree.
[0100] For the “node_templates” part, the parser will identify that this is the area of defining a virtual management node.
[0101] For the “disk” node template:
[0102] Identify that "disk" is the name of the virtual control node.
[0103] "type", "metadata", "properties", etc. are attributes of a node.
[0104] "flavor:{$get_ctx:[sale,id]}" is a specific property value in the "properties" attribute, where "$get_ctx:[sale,id]" is a specific expression. The parser will recognize its structure, but the specific meaning may need to be determined in subsequent semantic analysis.
[0105] The "requirements" section lists the dependencies of the virtual control node, such as "dependency:evm" and "dependency:quota". The parser will recognize them as dependency requirements of the virtual control node.
[0106] For the "evm" node template:
[0107] Also identify the name of the virtual control node "evm" and its attributes "type", "metadata", "properties" and "requirements".
[0108] "dependency:quota" and "dependency:region" in "requirements" are recognized as dependency requirements.
[0109] For the "sale" node template:
[0110] Identify the name "sale" and type "virtual" of the virtual control node, as well as the associated hook function "code:xxx.py".
[0111] For the "region" node template:
[0112] Identify the name "region" and type "virtual" of the virtual control node.
[0113] 3) Identify virtual control nodes:
[0114] The parser can identify virtual control nodes based on the definition and type identifier of the virtual control node in the target template file. In this example, the "sale" and "region" nodes are defined as "type:virtual", so the parser will identify them as virtual control nodes.
[0115] For each virtual control node, the parser extracts relevant information, such as the name of the virtual control node ("sale" or "region"), type ("virtual"), and associated hook function ("xxx.py").
[0116] 4) Identify event flow sequences:
[0117] In this example, the target template file does not explicitly give a direct description of the event flow sequence. Usually, if an event flow sequence exists, it may be represented by a specific grammatical structure or keyword.
[0118] For example, if there is a statement like "execution_order:[sale,region]", the parser will recognize that this is an event flow sequence, which stipulates that the hook function corresponding to the "sale" virtual control node is executed first, and then the hook function corresponding to the "region" virtual control node is executed.
[0119] However, in the current example, since there is no such explicit description, the parser may not be able to directly identify the event flow sequence. In actual applications, if the event flow sequence needs to be defined, it should be explicitly configured according to the requirements of the TOSCA specification.
[0120] 5) Information verification and integration
[0121] The parser verifies the identified virtual control nodes and event flow sequence information to ensure that they comply with the TOSCA specification requirements.
[0122] For example, check whether the name of the virtual control node is unique, whether the definition of the virtual control node is correct, whether all virtual control points in the event flow sequence exist in the target template file, etc.
[0123] It should be noted that the above parsing process is based on a general understanding of the TOSCA specification and common parsing methods. TOSCA parsers may be more complex and need to handle more details and possible grammatical variations.
[0124] S104: triggering the hook function corresponding to the virtual control node in sequence according to the event flow sequence to perform the control operation, obtain the return result, and store the return result in the control context.
[0125] In this embodiment, as an example, the management and control operations may include: access permission verification, computing power quota deduction, and resource pool information matching.
[0126] S105: Determine resource creation information that is recognizable by the computing power provider based on the management and control context, so that the computing power provider can perform a resource creation operation based on the resource creation information.
[0127] In this embodiment, according to the management context, the resource creation information identifiable by the computing power provider is determined, specifically including:
[0128] According to the preset syntax, the target management information is extracted from the management context, and the target management information is written into the target template file to realize rendering of the target template file. The resource creation information identifiable by the computing power provider is obtained.
[0129] In this embodiment, the return result is stored to the management context, and the management context can be a JSON string.
[0130] As an example, according to the preset syntax, the target management information is extracted from the management context, and the target management information is written into the target template file to realize rendering of the target template file. The implementation process of obtaining the resource creation information identifiable by the computing power provider can be specifically as follows:
[0131] Extract the target management information:
[0132] The preset syntax rule is determined: in the TOSCA template, a syntax such as {$get_ctx:{region,rz}} is used to obtain information from the management context. The rule is that the $get_ctx function is used to extract data from the management context in which the return result is stored, and region and rz are specified keys to be obtained.
[0133] Extract information from the JSON string: the JSON string is {"rz":"AAAA-1"}. According to the above syntax rule,
[0134] The $get_ctx function will find the value of the rz key in this JSON string (i.e., the context). In this example, the value corresponding to rz is successfully found as "AAAA-1", which is the extracted target management information, representing specific resource pool region information.
[0135] Write the target management information into the target template file:
[0136] Determine the template file position: in the TOSCA template file, there is a part specially used to describe the virtual machine region attribute, for example, when describing the attribute of the evm node, there is a region attribute field.
[0137] Write information: write the extracted target management information "AAAA-1" into the region attribute field, that is, through the syntax region:{$get_ctx:{region,rz}}, "AAAA-1" is assigned to region during template rendering, and the writing operation of the target management information in the target template file is completed.
[0138] Implement rendering of target template file:
[0139] Template rendering process: When processing a template file, the TOSCA parser renders the template according to pre-set syntax rules and the target control information it obtains. In this example, when the parser encounters region:{$get_ctx:{region,rz}}, it knows to retrieve data from the control context and replace the expression. After obtaining "AAAA-1", it replaces it with the region attribute, transforming the template containing the expression into a specific and explicit configuration, such as region:"AAAA-1". This is the template rendering process.
[0140] Get resource creation information that can be identified by the computing power provider:
[0141] Resource creation information composition: After the previous steps, the target template file's VM region information has been clearly defined as "AAAA-1." At this point, the target template file contains key information necessary for computing power providers to create resources, such as the VM type (evm) and region (AAAA-1). This target management information is presented in a format that complies with the TOSCA specification, allowing computing power providers to parse and identify this information.
[0142] Guiding resource creation: Computing power providers can extract complete and accurate resource creation information from the rendered target template file. For example, knowing that they want to create an EVM-type virtual machine in the "AAAA-1" resource pool, they can then perform actual resource creation operations based on this information, including allocating the corresponding computing resources, storage resources, and configuring the network. Target control information can be understood as a series of discrete data fragments, such as single parameter values or simple data structures. For example, a resource pool ID might be a string. Resource creation information can be understood as a complete, structured data set generated based on target control information. It can be considered a data set that can be recognized by computing power providers and used for resource creation operations.
[0143] In this embodiment, as an example, the resource creation information is:
[0144]
[0145] "xxxx" can represent other attributes not shown. Resource creation information can include the virtual machine type (evm), the geographic location (the resource pool's geographic location is in region 1, AAAA (which can be a place name), and the model (s6.small.1). This resource creation information indicates the creation of a virtual machine of the s6.small.1 model in region AAAA-1.
[0146] In this embodiment, the control context collects and integrates information generated at each stage, such as the target tenant's selected resource pool and the return results from hook function execution. It acts as an information hub, providing the necessary data support for control operations at different stages, ensuring consistent decision-making and execution throughout the control process. Once the target tenant's selected resource pool information is obtained, it is written to the control context. Subsequently, when the target template file is parsed and the hook function is triggered, the return result from the hook function execution is stored in the control context. The target control information is extracted from the control context, and resource creation information is generated based on this information.
[0147] In this embodiment, the computing power providers corresponding to the control items defined by the computing power network distribution platform may be different. In this embodiment, the return result can be obtained through a public interface, and the hook function can return a json string after execution and save it to the control context. The control context can be understood as a series of environmental information and condition sets related to control during the platform management and operation and maintenance process, which can be understood as an abstract concept. In the computing power management scenario, it includes resource pool information (resource pool ID, geographic location, available computing power resources, computing power resource type, etc.), computing power quota (the upper limit of computing power resource usage for ordinary tenants), ordinary tenant access rights (resource pools allowed to be accessed, computing power resource types allowed to be accessed, etc.). This information is the basis for the platform to perform control operations such as resource allocation and permission control. It is configured by high-authority platform administrators and stored in a structured data format (such as JSON).
[0148] As an example, the schematic diagram of TOSCA application in multi-cloud management is as follows: Figure 2 The figure below shows the logical relationships between control items and different resource nodes (disks, VMs, and VPCs). In multi-cloud management scenarios, parsing TOSCA templates ultimately enables the execution and management of these nodes and control relationships, ensuring that all types of resources in cloud applications are orchestrated, deployed, and managed according to pre-defined rules.
[0149] In cloud computing, resource nodes disk, VM, and VPC represent:
[0150] Disk: A storage resource node provides persistent storage services for data in cloud environments. It can be used to store virtual machine images, application-generated data, and user-uploaded data. For example, when building a database application, database files are stored on disk. Different types of disks, such as regular hard drives and solid-state drives, vary in read and write speed, performance stability, and cost. The choice depends on your business needs.
[0151] VM (Virtual Machine): It is a computing resource node that can be divided into multiple isolated virtual computer environments on a physical server through virtualization technology. Each VM can independently install an operating system and application program, and has independent CPU, memory, storage, and network configuration, etc. For example, enterprises can deploy web application servers on VMs to carry website business and achieve flexible allocation and efficient use of resources. Different configurations of VMs can meet the business requirements of different scales and performance.
[0152] VPC (Virtual Private Cloud): It is a network resource node that can build a logically isolated network space in a public cloud environment. Users can customize the topology of the network, including subnet division, configuration of routing table, and setting of network access control rules, etc. For example, enterprises can isolate different business systems using VPC to ensure data security, and achieve communication with public network and internal and external access management of resources by configuring elastic public IP, NAT gateway, etc.
[0153] Control item: an abstract concept for implementing management and control logic, not an actual physical resource. It realizes functions such as permission control and resource allocation management by associating with hook functions.
[0154] Control edge: represented by a line, it is a logical connection used to associate different nodes in the TOSCA topology and transfer management and control information to realize functions such as permission control, resource allocation management, and process control. For example, the control edge can set the access permission of a specific user to the VM resource, or specify the rules for allocating storage resources from the disk to the VM.
[0155] In an optional embodiment, the management method of the general computing power further includes: after determining the resource creation information recognizable by the computing power provider according to the control context, distributing the resource creation information to the corresponding computing power provider. The computing power provider creates the computing power resource required by the target tenant according to the resource creation information, such as a virtual machine. In this embodiment, the corresponding computing power provider is controlled by the multi-cloud manager to perform services to create the computing power resource required by the target tenant according to the resource creation information. As an example, the flowchart of the technical solution of the present application is shown in Figure 3 The input information generated by the tenant through the interface is the starting point of the process, representing the demand or operation instruction of the tenant for the computing power resource. For example, the target tenant purchases the computing power resource on the interface, and the input information generated is the resource pool information selected by the target tenant.
[0156] Parser processing: the generated input information enters the parser, which parses the input information and processes it in combination with the control items (pre-set management and control elements such as resource quota and access permission) to prepare for the subsequent steps.
[0157] Generate / obtain target template file: After parsing by the parser, generate / obtain target template file to convert tenant requirements into a form that complies with the TOSCA specification.
[0158] Segmentation step: Parse the target template file to obtain virtual control nodes and event flow sequences, and divide the entire control process into multiple steps to make the operation more organized and manageable.
[0159] Idempotent execution and control: Idempotent (multiple executions have the same effect) executes the script code specified by the control item (the corresponding hook function associated with the virtual control node), and returns the result and injects it into the Tosca control context. At the same time, the database records the control item status to ensure the consistency and traceability of operations.
[0160] Generate a control context and a complete target template file: Through the above steps, a legal control context is generated. Combined with the complete target template file, it provides comprehensive and accurate information for final resource management.
[0161] Multi-cloud manager processing: The generated control context and complete target template file are passed to the multi-cloud manager, which manages and allocates computing resources based on this information to complete the entire process.
[0162] In an embodiment of the present application, the administrator configures the control items. For example, the computing power distribution network platform is concerned with quotas, resource pool restrictions, user access resource restrictions, sales configuration, etc. This part is relatively fixed and should be carried out with iterative development. It is an in-tree method for continuous follow-up maintenance. In the TOSCA template file, a virtual control node still needs to be constructed, but the code (hook function) executed by the virtual control node is written in advance by the computing power distribution network platform. Triggering the hook function corresponding to the virtual control node in sequence according to the event flow sequence indicates executing the hook function corresponding to the virtual control node, and executing the control operation is achieved by executing the hook function corresponding to the virtual control node.
[0163] The executed code is platform-defined. For example, if you need to query the database, obtain the resource pool, and inject the JSON string in the resource pool into the control context, the computing power quota will be deducted, and the deduction result will be written to the control context.
[0164] As an example, computing power quota as a control item can be understood as a fixed execution process, an execution program with fixed input and output defined by the computing power distribution network platform, and the execution program is the hook function corresponding to the virtual control node.
[0165] In the embodiment of the present application, the following is an example of the resource pool information of a control item:
[0166] 1) The control item has been bound to a resource pool, and the resource pool information is a JSON string (resource pool ID), for example: {"rz":"AAAA-1"}.
[0167] 2) After purchasing resources, the computing power user, that is, the target tenant, will pass the resource pool ID defined by the platform into the control context.
[0168] When a computing power user (target tenant) purchases resources, the following series of operations and data flows occur: The platform predefines different resource pools and assigns each a unique identifier (resource pool ID). These resource pools contain different types and quantities of computing resources, such as virtual machines of varying specifications and storage capacity. When the target tenant purchases resources, the platform passes the resource pool ID corresponding to the purchased resources to the control context. This resource pool ID is crucial information, identifying the specific resource pool from which the purchased resources come. The control context is an environment that stores relevant data and information, allowing each node to access and use this data during the execution of the TOSCA template file. In the TOSCA template file, the virtual control node can obtain information such as the resource pool ID from the control context using a specific syntax (such as $get_ctx). This allows the virtual control node to determine the specific resource pool from which to obtain the required resources based on the obtained resource pool ID, thereby ensuring the correct allocation and use of resources.
[0169] The platform will first obtain n virtual nodes based on the target template file and generate n control items, corresponding to n defined execution methods, that is, hook functions. If the virtual node is bound to an executable script, the executable script can be executed (it is necessary to ensure that the executable script is executed without causing a security incident, and usually encryption authentication is required before execution). For example, if there is a virtual control node in the target template file, a control item will be generated, and the code for the control item in the in-tree (hook function) will be executed. The code interface is as follows: "func()context String{}." Considering that due to various factors, the code may be called repeatedly, in order to solve the problem of repeated quota deduction / repeated deduction, it is necessary to ensure that the return result of each hook function is the same after repeated execution.
[0170] 4) Return result: A JSON string, such as {"rz":"AAAA-1"}. In the TOSCA template file, when executing on the virtual control node (evm), the rendered template can correctly pass the platform-side control information to the computing power provider using preset syntax, such as region:{$get_ctx:{region,rz}}.
[0171] 5) Ultimately, the information the hashrate provider sees is:
[0172]
[0173] When the computing power provider sees the semantically clear resource creation information, it will know that a virtual machine with the specification of s6.small.1 and the region of AAAA-1 is to be created.
[0174] It should be noted that the contents not described in detail in this application specification belong to the common knowledge of those skilled in the art.
[0175] This embodiment also provides a general computing power management device. A single device is used to implement the above-mentioned embodiments and optional implementation methods. Details that have already been described will not be repeated. As used below, the term "module" can refer to a combination of software and / or hardware that implements a predetermined function. Although the devices described in the following embodiments are preferably implemented in software, implementation using hardware, or a combination of software and hardware, is also possible and contemplated.
[0176] Figure 4 It is a structural diagram of the general computing power management device of an embodiment of the present application.
[0177] This application provides a general computing power management device, such as Figure 4 As shown, the general computing power management device includes:
[0178] The first processing module 11 is used to pre-configure control items and standard template files. Control items include resource pool information, computing power quotas, and access rights for common tenants. The standard template files are configured with virtual control nodes, which are associated with corresponding hook functions.
[0179] The second processing module 12 is configured to obtain the resource pool information selected by the target tenant and write the resource pool information into the management and control context.
[0180] The third processing module 13 is used to determine the target template file. The target template file is parsed to obtain the virtual control node and event flow sequence. The event flow sequence defines the execution order of the hook functions associated with the virtual control node. The target template file is a standard template file corresponding to the resource pool information selected by the target tenant.
[0181] The fourth processing module 14 is configured to trigger the hook functions corresponding to the virtual control nodes in sequence according to the event flow sequence to perform control operations and obtain return results, and store the return results in the control context.
[0182] The fifth processing module 15 is used to determine resource creation information that can be identified by the computing power provider based on the management and control context, so that the computing power provider can perform resource creation operations based on the resource creation information.
[0183] In an optional implementation, the third processing module 13 is specifically configured to parse the target template file, identify the definition of the virtual control node and the description of the event flow sequence, and obtain the virtual control node and the event flow sequence.
[0184] In an optional embodiment, the fifth processing module 15 is specifically configured to extract target control information from the control context according to a preset grammar, write the target control information into the target template file, and render the target template file, thereby obtaining resource creation information that is recognizable to the computing power provider.
[0185] In an optional implementation, the general computing power management device further includes: a distribution module.
[0186] The distribution module is used to distribute the resource creation information to the corresponding computing power provider after determining the resource creation information that can be identified by the computing power provider based on the management and control context.
[0187] In an optional embodiment, the resource pool information includes: a unique identifier of the resource pool; a computing power quota including an upper limit on computing power usage of a common tenant; and access rights of a common tenant including: resource pools that the common tenant is allowed to access.
[0188] In an optional implementation, the control items are stored in a structured data format.
[0189] The further functional description of each of the above modules and units is the same as that of the above corresponding embodiments and will not be repeated here.
[0190] The general computing power management device in this embodiment is presented in the form of a functional unit, where the unit refers to an ASIC (Application Specific Integrated Circuit) circuit, a processor and memory that executes one or more software or fixed programs, and / or other devices that can provide the above functions.
[0191] The present application also provides a computer device having the above Figure 4 The general computing power management device shown.
[0192] See also Figure 5 , Figure 5 This is a schematic diagram of the hardware structure of the computer device according to the embodiment of the present application. Figure 5As shown, the computer device includes: one or more processors 10, a memory 20, and interfaces for connecting various components, including high-speed interfaces and low-speed interfaces. Various components utilize different buses to communicate with each other and can be installed on a common mainboard or installed in other ways as needed. The processor can process the instructions executed in the computer device, including instructions stored in or on the memory to display the graphical information of the GUI on an external input / output device (such as, a display device coupled to the interface). In an optional embodiment, if necessary, multiple processors and / or multiple buses can be used together with multiple memories and multiple memories. Equally, multiple computer devices can be connected, and each device provides some necessary operations (for example, as a server array, a group of blade servers, or a multi-processor device). Figure 5 A processor 10 is taken as an example.
[0193] The processor 10 may be a central processing unit, a network processor, or a combination thereof. The processor 10 may further include a hardware chip. The hardware chip may be an application-specific integrated circuit, a programmable logic device, or a combination thereof. The programmable logic device may be a complex programmable logic device, a field programmable gate array, a general purpose array logic, or any combination thereof.
[0194] The memory 20 stores instructions that can be executed by at least one processor 10, so as to enable at least one processor 10 to execute the method shown in the above embodiment.
[0195] The memory 20 may include a program storage area and a data storage area, wherein the program storage area may store an operating device, an application required for at least one function. The data storage area may store data created according to the use of the computer device, etc. In addition, the memory 20 may include a high-speed random access memory, and may also include a non-transient memory, such as at least one disk storage device, a flash memory device, or other non-transient solid-state storage device. In an optional embodiment, the memory 20 may optionally include a memory remotely arranged relative to the processor 10, and these remote memories may be connected to the computer device via a network. Examples of the above-mentioned network include, but are not limited to, the Internet, an intranet, a local area network, a mobile communication network, and combinations thereof.
[0196] The memory 20 may include volatile memory, such as random access memory. The memory may also include non-volatile memory, such as flash memory, a hard disk, or a solid-state drive. The memory 20 may also include a combination of the above types of memory.
[0197] The computer device further includes a communication interface 30 for the computer device to communicate with other devices or a communication network.
[0198] The embodiments of the present application also provide a computer-readable storage medium, and the above-mentioned method according to the embodiment of the present application can be implemented in hardware, firmware, or implemented as a computer code that can be recorded in a storage medium, or implemented as a computer code that is originally stored in a remote storage medium or a non-temporary machine-readable storage medium and will be stored in a local storage medium and downloaded through a network, so that the method described herein can be stored in such software processing on a storage medium using a general-purpose computer, a dedicated processor, or programmable or dedicated hardware. Among them, the storage medium can be a magnetic disk, an optical disk, a read-only storage memory, a random access memory, a flash memory, a hard disk or a solid-state drive, etc. Further, the storage medium can also include a combination of the above-mentioned types of memories. It can be understood that a computer, a processor, a microprocessor controller or programmable hardware includes a storage component that can store or receive software or computer code, and when the software or computer code is accessed and executed by a computer, a processor or hardware, the method shown in the above embodiment is implemented.
[0199] Part of the present application may be applied as a computer program product, such as a computer program instruction, which, when executed by a computer, can call or provide the method and / or technical solution according to the present application through the operation of the computer. Those skilled in the art should understand that the form in which the computer program instruction exists in a computer-readable medium includes but is not limited to a source file, an executable file, an installation package file, etc. Accordingly, the way in which the computer program instruction is executed by the computer includes but is not limited to: the computer directly executes the instruction, or the computer compiles the instruction and then executes the corresponding compiled program, or the computer reads and executes the instruction, or the computer reads and installs the instruction and then executes the corresponding installed program. Here, the computer-readable medium can be any available computer-readable storage medium or communication medium that can be accessed by the computer.
[0200] Although the embodiments of the present application have been described with reference to the accompanying drawings, those skilled in the art may make various modifications and variations without departing from the spirit and scope of the present application, and such modifications and variations shall fall within the scope defined by the appended claims.
Claims
1. A method for managing general computing power, characterized in that: include: Pre-configure control items and standard template files; the control items include: resource pool information, computing power quotas, and access rights of ordinary tenants; the standard template files are configured with virtual control nodes, and the virtual control nodes are associated with corresponding hook functions; Obtain the resource pool information selected by the target tenant and write the resource pool information into the control context; Determine the target template file; parse the target template file to obtain the virtual control node and event flow sequence; the event flow sequence defines the execution order of the hook functions associated with the virtual control node; the target template file is a standard template file corresponding to the resource pool information selected by the target tenant; Triggering the hook functions corresponding to the virtual control nodes in sequence according to the event flow sequence to perform the control operation and obtain the return result; storing the return result in the control context; According to the control context, resource creation information recognizable by the computing power provider is determined, so that the computing power provider can perform a resource creation operation according to the resource creation information.
2. The method according to claim 1, characterized in that The step of parsing the target template file to obtain a virtual control node and an event flow sequence includes: The target template file is parsed to identify the definition of the virtual control node and the description of the event flow sequence, thereby obtaining the virtual control node and the event flow sequence.
3. The method according to claim 1, characterized in that Determining resource creation information recognizable to a computing power provider based on the control context includes: Target control information is extracted from the control context according to a preset grammar, and the target control information is written into the target template file to achieve rendering of the target template file; and resource creation information that can be identified by the computing power provider is obtained.
4. The method according to claim 1, wherein After determining resource creation information identifiable to the computing power provider based on the control context, the method further includes: Distribute the resource creation information to the corresponding computing power provider.
5. The method according to claim 1, wherein The resource pool information includes: a unique identifier of the resource pool; the computing power quota includes the upper limit of computing power resources used by common tenants; the access rights of common tenants include: resource pools that common tenants are allowed to access.
6. The method according to claim 1, characterized in that The control items are stored in a structured data format.
7. A general computing power management device, characterized in that: include: The first processing module is used to pre-configure control items and standard template files; the control items include: resource pool information, computing power quotas, and access rights of ordinary tenants; the standard template files are configured with virtual control nodes, and the virtual control nodes are associated with corresponding hook functions; The second processing module is configured to obtain the resource pool information selected by the target tenant and write the resource pool information into the management and control context; The third processing module is used to determine the target template file; parse the target template file to obtain the virtual control node and event flow sequence; the event flow sequence defines the execution order of the hook functions associated with the virtual control node; the target template file is a standard template file corresponding to the resource pool information selected by the target tenant; A fourth processing module is used to trigger the hook function corresponding to the virtual control node in sequence according to the event flow sequence to perform the control operation and obtain a return result; and store the return result in the control context; The fifth processing module is used to determine resource creation information that can be identified by the computing power provider based on the management and control context, so that the computing power provider can perform resource creation operations based on the resource creation information.
8. A computer device, characterized in that: include: A memory and a processor, wherein the memory and the processor are communicatively connected to each other, the memory stores computer instructions, and the processor executes the general computing power management method according to any one of claims 1 to 6 by executing the computer instructions.
9. A computer-readable storage medium, characterized in that The computer-readable storage medium stores computer instructions, and the computer instructions are used to enable a computer to execute the general computing power management method according to any one of claims 1 to 6.
10. A computer program product, characterized in that The method comprises computer instructions for causing a computer to execute the general computing power management method according to any one of claims 1 to 6.