Method for managing edge sites based on public cloud technology and cloud system
Patent Information
- Application Number
- CN202510353378.8
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2025-03-24
- Publication Date
- 2026-09-25
AI Technical Summary
但是,这需要牵扯到本地的管控面和租户面打通的问题、本地鉴权缓存周期性缓存的问题,其实现比较复杂且工作量大,还面临安全风险或者时效性问题,如缓存认证、鉴权等模块,长期缓存存在安全风险,缓存时间过短导致容忍网络故障恢复时长过短等问题,因此无法彻底解决问题
[0026]第五方面,本申请提供了一种计算机可读存储介质,该计算机可读存储介质为非易失性计算机可读存储介质,该计算机可读存储介质包括程序指令,当程序指令在计算设备集群上运行时,使得计算设备集群实现本申请第一方面以及其任一种可能的实现方式中提供的方法。
Smart Images

Figure CN122824734A_ABST
Abstract
Description
Technical Field
[0001] This application relates to the field of cloud service technology, and in particular to a method and cloud system for managing edge sites based on public cloud technology. Background Technology
[0002] In distributed cloud scenarios, the control plane of edge sites is deployed in the central cloud, resulting in a remote control interface. Edge sites connect to the control plane via public networks / dedicated lines. Due to relatively poor network conditions, the network connection between the edge sites and the control plane is unreliable and can be interrupted by factors such as fiber optic cable cuts, unpaid bills, or outgoing switch failures. This scenario is known as a cloud-edge disconnection. In a cloud-edge disconnection scenario, the edge site loses connection with the control plane, making it impossible for the control plane to manage the edge site. This leads to the unavailability of certain business functions and hinders the edge site's operations.
[0003] Currently, solutions include edge computing management components, local authentication systems, and local API gateways. However, these solutions involve issues such as integrating the local control plane and tenant plane, and periodic caching of local authentication. Their implementation is complex and labor-intensive, and they also face security risks and timeliness issues. For example, long-term caching of authentication and authorization modules poses security risks, while short caching times result in insufficient tolerance for network failure recovery time. Therefore, these solutions cannot completely solve the problems. Summary of the Invention
[0004] This application provides a method and cloud system for managing edge sites based on public cloud technology. This application enables control over edge sites even when communication between the edge site and the cloud management platform is impossible. The technical solution provided by this application is as follows:
[0005] Firstly, this application provides a method for managing edge sites based on public cloud technology. The edge site is deployed in the edge cloud of a public cloud. A cloud management platform is deployed in the central cloud of the public cloud. A management component is deployed in the edge cloud. Both the cloud management platform and the management component are used to manage the edge site. The edge site is used to deploy tenant services. The method includes: the cloud management platform obtaining enhanced configuration instructions sent by the tenant, the enhanced configuration instructions indicating target control operations that still need to be performed on the edge site even when communication between the edge site and the cloud management platform is impossible, the target control operations being performed under specified triggering conditions; the cloud management platform providing target configuration information required to perform the target control operations to the management component based on the enhanced configuration instructions; and the management component performing the target control operations on the edge site based on the target configuration information when communication between the edge site and the cloud management platform is impossible and the specified triggering conditions are met.
[0006] In this way, managing edge sites according to the method provided in this application ensures that even when communication between the edge site and the cloud management platform is impossible, the management component can still execute target control operations on the edge site if the specified triggering conditions for performing target control operations are met. This prevents situations where the edge site cannot be controlled due to a communication failure to transmit control commands between the edge site and the cloud management platform. For example, it prevents situations where a cloud desktop that has been shut down cannot be turned on due to a cloud-edge disconnection, thus ensuring the continuity of customer business. This facilitates the promotion of edge sites and reduces the operational burden after their deployment. In addition, this application does not require the separate deployment of edge computing management components, local authentication systems, and local API gateways at the edge site, reducing edge management overhead and security risks.
[0007] In one possible implementation, before performing target control operations on an edge site, the management component needs to detect the status of the edge site. When the edge site's status indicates that target control operations are required, the management component performs the target control operations. Alternatively, if communication between the edge site and the cloud management platform is impossible, and a specified trigger condition is met, the management component performs target control operations on the edge site based on the target configuration information. This includes performing target control operations on the edge site based on the target configuration information when communication between the edge site and the cloud management platform is impossible, a specified trigger condition is met, and the edge site is in a state where no target control operations have been performed.
[0008] In one possible implementation, upon meeting the specified triggering condition, the cloud management platform can first send an instruction to the edge site, based on the target configuration information, to perform the target control operation on the edge site. Alternatively, if the management component cannot communicate between the edge site and the cloud management platform, and the specified triggering condition is met, before performing the target control operation on the edge site based on the target configuration information, the method further includes: configuring the target configuration information in the cloud management platform based on the enhanced configuration instruction; and performing the target control operation on the edge site based on the target configuration information upon meeting the specified triggering condition.
[0009] In one possible implementation, after the cloud management platform sends an instruction to the edge site to perform a target control operation, if communication between the edge site and the cloud management platform fails, the cloud management platform receives a response indicating that communication between the edge site and the cloud management platform is also unavailable. Based on this response, the cloud management platform can determine that communication between the edge site and the cloud management platform is unavailable. However, since the cloud management platform cannot predict when communication between the edge site and the cloud management platform will be restored, to ensure that the target control operation can be performed on the edge site, the cloud management platform can continue to perform the target control operation on the edge site based on the target configuration information according to a specified strategy until the stopping condition is met. The method further includes: when the response to the target control operation indicates that communication between the edge site and the cloud management platform is unavailable, the cloud management platform continues to perform the target control operation on the edge site based on the target configuration information according to a specified strategy until the stopping condition is met.
[0010] In one possible implementation, the stopping conditions include one or more of the following: the cloud management platform receives a specified number of responses indicating that the edge site and the cloud management platform cannot communicate; or the cloud management platform obtains that the edge site is in a state where target control operations have been performed.
[0011] In one possible implementation, before performing target control operations on an edge site, the cloud management platform may optionally detect the status of the edge site. If the status of the edge site indicates that target control operations are required, then the target control operations are performed on the edge site; if the status indicates that target control operations are not required, then no target control operations are performed on the edge site. Then, under specified trigger conditions, the cloud management platform performs target control operations on the edge site based on target configuration information, including: when the specified trigger conditions are met and the edge site is in a state where no target control operations have been performed, the cloud management platform performs target control operations on the edge site based on target configuration information.
[0012] In one possible implementation, the method further includes: the management component sending an indication to the cloud management platform that the target control operation has been performed on the edge site, even when the cloud management platform is still instructing the edge site to perform the target control operation. This avoids the cloud management platform performing duplicate operations.
[0013] In one possible implementation, when the state of an edge site changes, the management component also needs to update the target configuration information required for performing target control operations to ensure consistency in performing target control operations on the edge site based on the target configuration information. Therefore, the method includes: the management component updating the target configuration information required for performing target control operations when the state of the edge site changes.
[0014] In one possible implementation, the target management operations include one or more of the following: managing the lifecycle of the edge site, migrating the edge site, deleting the edge site, releasing the resources used by the edge site, or elastically scaling the resources used by the edge site.
[0015] Secondly, this application provides a cloud system for managing edge sites based on public cloud technology. The edge sites are deployed in the edge cloud of a public cloud. A cloud management platform is deployed in the central cloud of the public cloud. Management components are deployed in the edge cloud. Both the cloud management platform and the management components are used to manage the edge sites. The edge sites are used to deploy tenant services. The cloud system includes: a cloud management platform, used to obtain enhanced configuration instructions sent by tenants, which instruct the execution of target control operations on the edge sites even when communication between the edge sites and the cloud management platform is impossible; the target control operations are executed under specified triggering conditions; the cloud management platform is also used to provide the management components with target configuration information required to execute the target control operations based on the enhanced configuration instructions; and a management component, used to execute target control operations on the edge sites based on the target configuration information when communication between the edge sites and the cloud management platform is impossible and specified triggering conditions are met.
[0016] In one possible implementation, the management component is specifically used to perform target management operations on the edge site based on the target configuration information when communication between the edge site and the cloud management platform fails, a specified trigger condition is met, and the edge site is in a state where no target management operation has been performed.
[0017] In one possible implementation, before performing target control operations on the edge site based on the target configuration information, when the management component cannot communicate between the edge site and the cloud management platform and a specified triggering condition is met, the cloud system is also used to: configure target configuration information in the cloud management platform based on enhanced configuration instructions; and perform target control operations on the edge site based on the target configuration information when the specified triggering condition is met.
[0018] In one possible implementation, the cloud system is also used to: continue to perform target control operations on the edge site based on the target configuration information according to a specified policy, in the event that the response indication of the target control operation indicates that communication between the edge site and the cloud management platform is impossible, until the stopping condition is met.
[0019] In one possible implementation, the stopping conditions include one or more of the following: the cloud management platform receives a specified number of responses indicating that the edge site and the cloud management platform cannot communicate; or the cloud management platform obtains that the edge site is in a state where target control operations have been performed.
[0020] In one possible implementation, the cloud management platform is specifically used to perform target control operations on the edge site based on the target configuration information when a specified triggering condition is met and the edge site is in a state where no target control operation has been performed.
[0021] In one possible implementation, the management component is also used to send an instruction to the cloud management platform indicating that a target control operation has been performed on the edge site, even when the target control operation has already been performed on the edge site and the cloud management platform is still instructing the target control operation to be performed on the edge site.
[0022] In one possible implementation, the management component is also used to update the target configuration information required to perform target control operations when the state of the edge site changes.
[0023] In one possible implementation, the target management operations include one or more of the following: managing the lifecycle of edge sites, migrating edge sites, deleting edge sites, releasing resources used by edge sites, or elastically scaling the resources used by edge sites.
[0024] Thirdly, this application provides a computing device including a memory and a processor, wherein the memory stores program instructions and the processor executes the program instructions to implement the methods provided in the first aspect of this application and any of its possible implementations.
[0025] Fourthly, this application provides a computing device cluster, including multiple computing devices, each computing device including multiple processors and multiple memories, the multiple memories storing program instructions, and the multiple processors executing the program instructions, so that the computing device cluster implements the method provided in the first aspect of this application and any possible implementation thereof.
[0026] Fifthly, this application provides a computer-readable storage medium that is a non-volatile computer-readable storage medium, which includes program instructions that, when executed on a computing device cluster, cause the computing device cluster to implement the methods provided in the first aspect of this application and any of its possible implementations.
[0027] Sixthly, this application provides a computer program product containing instructions that, when run on a computer, cause the computer to implement the methods provided in the first aspect of this application and any of its possible implementations. Attached Figure Description
[0028] Figure 1 This is a schematic diagram illustrating the implementation scenario of a method for managing edge sites based on public cloud technology provided in this application embodiment;
[0029] Figure 2 This is a schematic diagram illustrating the deployment of basic resources in a data center, provided in an embodiment of this application.
[0030] Figure 3 This is a flowchart illustrating a method for managing edge sites based on public cloud technology, as provided in an embodiment of this application.
[0031] Figure 4 This is a schematic diagram illustrating how the functions of a cloud management platform and management components are implemented through multiple functional components, as provided in an embodiment of this application.
[0032] Figure 5 This is a schematic diagram of the structure of a cloud system for managing edge sites based on public cloud technology, provided in an embodiment of this application.
[0033] Figure 6 This is a schematic diagram of the structure of a computing device provided in an embodiment of this application;
[0034] Figure 7 This is a schematic diagram of the structure of a computing device cluster provided in an embodiment of this application;
[0035] Figure 8 This is a schematic diagram of another computing device cluster structure provided in an embodiment of this application. Detailed Implementation
[0036] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0037] To facilitate understanding, the technologies and background involved in the embodiments of this application will be introduced below.
[0038] Cloud computing is a type of distributed computing that refers to a network that centrally manages and schedules a large number of computing and storage resources to provide on-demand services to users. These computing and storage resources are provided through clusters of computing devices located in data centers. Furthermore, cloud computing can provide users with various types of services, such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Infrastructure as a Service provides virtual machines or other resources as a service to tenants. Platform as a Service provides a development platform as a service to tenants. Software as a Service provides applications (Apps) as a service to customers.
[0039] An Internet Data Center (IDC) is a facility and related service system that provides operation and maintenance for equipment that centrally collects, stores, processes, and transmits data, based on the Internet. Conceptually, it can be understood as a public, commercial Internet "server room," and it is also a professional IT service and a crucial infrastructure for the IT industry. IDC is not only a service concept but also a network concept; it constitutes part of the network infrastructure resources, like backbone networks and access networks, providing high-end data delivery and high-speed access services. Generally, a tenant's on-premises IDC can be understood as their physical server room, where the tenant utilizes existing Internet communication lines and bandwidth resources to establish a standardized, telecommunications-grade server room environment to provide comprehensive services such as server hosting, leasing, and related value-added services. A cloud data center is an Internet data center deployed using the infrastructure resources owned by cloud vendors.
[0040] A resource pool is a collection of various hardware and software resources involved in a cloud data center. Typically, resources in a resource pool can be categorized by type, such as computing resources, storage resources, and network resources.
[0041] A physical machine (PM) is the physical resource used to host virtualization technology. It is also called a physical server. Typically, a physical machine is used to deploy virtual instances. A physical machine has multiple physical devices. For example, a physical server has physical devices such as processors and memory. Multiple virtual instances can be deployed on a single physical machine, sharing the machine's physical resources. Depending on the use case, multiple virtual instances deployed on a single physical machine can belong to the same tenant or to different tenants.
[0042] Virtualization is a resource management technology. Virtualization abstracts and transforms various physical resources of a host, such as computing, network, and storage resources, breaking down the indivisible barriers between the host's physical structures. This allows tenants to utilize these resources in a better way than the original configuration. Resources obtained through virtualization are called virtualized resources, and virtualized resources are not limited by the existing physical resource deployment methods, geographical location, or physical configuration.
[0043] Virtualized resources are typically provided to tenants in the form of virtual instances. Virtual instances utilize the host's hardware resources and run on the host's operating system (OS). Applications run within the virtual instance to implement the tenant's business logic. The host's hardware resources can be allocated to one or more tenants at the virtual instance level. Different virtual instances are isolated from each other, allowing tenants to use physical resources conveniently and flexibly while maintaining security and isolation, and significantly improving the utilization of physical resources. Typically, virtual instances can be virtual machines, containers, or independent processes (such as functions). Virtual instances can also be called Elastic Compute Service (ECS) or Elastic Instances (different cloud service providers may use different names).
[0044] A virtual machine (VM) is a complete computer system with full hardware system functionality, simulated using virtualization technology and running in a completely isolated environment. A subset of the instructions in a VM can be processed on the host machine, while other instructions can be executed in a simulated manner. A VM is also called a virtual server. A VM can be viewed as a collection of virtual devices, which possess full hardware system functionality and run in a completely isolated environment. Virtual devices are created by virtualizing physical devices that can share resources. For example, a virtual processor, created by virtualizing a processor, is a virtual device. Similarly, a training card, created by virtualizing a field-programmable gate array (FPGA), is also a virtual device. For instance, the VM in this application can be a kernel-based virtual machine (KVM). Any task that can be performed on a server can also be performed in a VM. When creating a virtual machine on a server, a portion of the physical machine's hard drive and memory capacity is used as the virtual machine's hard drive and memory capacity. Each virtual machine has its own independent hard drive and operating system, and virtual machine tenants can operate the virtual machine as if it were a server. The runtime environments (such as virtual machine applications, operating systems, and virtual hardware) in different virtual machines are completely isolated, and communication between different virtual machines requires the virtual machine manager to forward network packets.
[0045] Containers utilize the namespace and cgroup technologies supported by the Linux kernel to isolate application processes and their dependencies (the runtime environment's bins / libs, specifically all files required to run the application) within an independent runtime environment. Containers provide a lightweight virtual runtime environment. Containers are created by packaging all the code, libraries, and dependencies of a tenant's application into an image. When the image is executed, it runs in a virtual runtime environment. At this point, the container is a runtime instance of the image, similar to a lightweight sandbox, which can be started, stopped, and deleted. The infrastructure for containers can be server hardware or virtual machines in the cloud (i.e., containers can also be deployed within virtual machines). The operating system uses the Linux kernel and supports namespaces and cgroups. Namespaces are used to isolate processes, while cgroups are used to allocate process resources, specifically virtual processors and memory allocated to the process. The container engine, similar to a virtual machine manager, runs within the operating system and is used to manage containers. Compared to virtual machines, which come with their own operating system, containers do not have an operating system. Instead, containers run as processes within the host machine's operating system. As a result, containers start up faster than virtual machines, making them particularly suitable for lightweight applications. Furthermore, a single host machine can run thousands of containers (processes) simultaneously.
[0046] Resource pooling refers to integrating various computing and storage resources into a unified resource pool for unified dynamic allocation and management. Resource pooling enables high resource sharing, improves resource utilization, simplifies resource management, and provides users with flexible on-demand allocation services.
[0047] In the field of computer science, orchestration refers to the automated arrangement, coordination, and management of complex computer systems, middleware, and business processes. Orchestration typically involves three aspects: 1) resource orchestration, responsible for resource allocation; 2) workload orchestration, responsible for sharing workloads among resources and managing their lifecycles; and 3) service orchestration, responsible for service discovery and high availability, etc.
[0048] Network interface card (NIC): also known as network interface controller, network adapter, or local area network receiver, is a type of computer hardware designed to allow hosts or computing devices to communicate over a network.
[0049] Memory (RAM): Also known as internal memory or main memory, its function is to temporarily store the data processed by the CPU, as well as the data exchanged with external storage devices such as hard drives.
[0050] Distributed cloud includes clouds distributed across different physical locations. Cloud service providers (CSPs) distribute public cloud services to different physical locations, and the CSPs are responsible for the unified operation, governance, updates, and evolution of the cloud services. Distributed cloud is mainly divided into central cloud and edge cloud. Edge cloud is a cloud computing platform distributed at the network edge, built on edge infrastructure (i.e., infrastructure deployed at the network edge) based on the core and edge computing capabilities of cloud computing technology. Instances built on edge infrastructure are called edge sites, which are used to provide computing and storage capabilities to users closer to users or terminal devices. For example, edge sites are distributed cloud sites, distributed cloud hosts, or distributed cloud mini-sites. This application does not specifically limit the form of edge sites. For example, since 1U / 2U cloud hosts occupy less space, distributed cloud hosts can be selected in miniaturized forms such as 1U / 2U.
[0051] The control plane of edge sites is deployed in the central cloud, resulting in a remote control interface. Edge sites connect to the control plane via public networks / dedicated lines. Due to relatively poor network conditions, the network connection between the edge sites and the control plane is unreliable and can be interrupted by factors such as fiber optic cable cuts, unpaid bills, or outgoing switch failures. This scenario is known as a cloud-edge disconnection. In a cloud-edge disconnection scenario, the edge site loses connection with the control plane, making it impossible for the control plane to manage the edge site. This leads to the unavailability of certain business functions and hinders the edge site's operations.
[0052] For example, when the edge site loses connection with the control plane, the cloud desktop functionality implemented at the edge site will have significant vulnerabilities. In typical cloud desktop usage scenarios, employees usually shut down their cloud desktops when they leave work and turn them back on the next day. If a cloud-edge outage occurs, the already shut-down cloud desktops cannot be powered on because their Elastic Cloud Server (ECS) application program interface (API) gateway is located in the cloud. This prevents customers from using their cloud desktops for work until the cloud-edge connection is restored. The recovery time often far exceeds the customer's acceptable level of work interruption, which hinders the adoption of cloud desktop functionality and poses significant operational risks to the edge site after deployment.
[0053] Therefore, there is an urgent need to propose a solution that allows continued control over edge sites even in scenarios where cloud-edge connectivity is lost. For example, a solution that allows customers to control cloud desktop startup locally in emergencies without affecting cloud desktop access. While solutions such as edge computing management components, local authentication systems, and local API gateways exist, these involve complex implementations and large workloads, including issues with connecting the local control plane and tenant plane, and the periodic caching of local authentication. These solutions also face security risks and timeliness issues, such as long-term caching of authentication and authorization modules posing security risks, and short caching times leading to insufficient tolerance for network failure recovery time. Therefore, they cannot completely solve the problem.
[0054] In view of this, this application provides a method for managing edge sites based on public cloud technology. The edge site is deployed in the edge cloud of a public cloud. A cloud management platform is deployed in the central cloud of the public cloud. A management component is deployed in the edge cloud. Both the cloud management platform and the management component are used to manage the edge site. The edge site is used to deploy tenant services. In this method, after receiving an enhanced configuration instruction sent by the tenant, the cloud management platform provides the management component with the target configuration information required to perform the target control operation based on the enhanced configuration instruction. The enhanced configuration instruction indicates the target control operation that still needs to be performed on the edge site even when communication between the edge site and the cloud management platform is impossible. The target control operation is executed under specified triggering conditions. Then, when communication between the edge site and the cloud management platform is impossible and the specified triggering conditions are met, the management component can perform the target control operation on the edge site based on the target configuration information.
[0055] In this way, managing edge sites according to the method provided in this application ensures that even when communication between the edge site and the cloud management platform is impossible, the management component can still perform target control operations on the edge site if the specified triggering conditions for target control operations are met. This allows for continued control of the edge site even when communication between the management component and the edge site is unavailable, preventing situations where control of the edge site is impossible due to a lack of communication between the edge site and the cloud management platform. For example, it prevents situations where a disconnected cloud-edge connection prevents a powered-off cloud desktop from powering on, thus preventing customers from using the cloud desktop for work. This facilitates the promotion of edge sites and reduces the operational burden after their deployment.
[0056] This article provides a detailed introduction to the technical solution of this application from multiple perspectives, including implementation scenarios, methods and processes, hardware devices, and software devices.
[0057] The following are examples illustrating the implementation scenarios of the embodiments of this application.
[0058] Figure 1 This is a structural diagram illustrating an implementation scenario of a method for managing edge sites based on public cloud technology provided in this application embodiment. For example... Figure 1 As shown, the implementation scenario includes a cloud system 1 and a client 2. The cloud system 1 and client 2 can establish a communication connection via a network. Optionally, this network can be the Internet, or other networks; this embodiment does not limit the specific network used. Tenants can interact with the cloud system 1 through client 2. For example, a tenant can send cloud service requests and other information to the cloud system 1 through client 2. The cloud system 1 responds based on the information sent by client 2.
[0059] like Figure 1 As shown, cloud system 1 includes a cloud management platform and infrastructure. The cloud management platform and infrastructure are connected via an internal network of the cloud system. In another implementation, the cloud management platform may optionally be located within the infrastructure. The cloud management platform is used to manage the infrastructure. The infrastructure is used to provide public cloud services. The infrastructure includes at least one data center (DC). The cloud management platform can connect to this at least one data center. In this case, the cloud management platform is used to manage this at least one data center. The data center deploys a large number of cloud resources owned by the cloud service provider, such as computing resources, storage resources, and network resources. Computing resources can be computing devices (such as servers) capable of providing computing power. For example, as... Figure 1 As shown, multiple servers are deployed in the data center. Cloud services are optionally deployed on these servers. Cloud services are implemented by running virtual instances, hence the term "virtual instances deployed on servers to implement tenant services." Tenants can send cloud service requests and related information to the servers through their client 2. The servers can process these requests and information and provide cloud services to the tenants based on the processed requests and information.
[0060] The cloud management platform can be logically divided into: tenant console, compute management service, network management service, storage management service, authentication service, and image management service. The tenant console provides a user interface or application programming interface (API) for interaction with tenants. The compute management service manages servers running virtual instances and bare metal servers. The network management service manages network services (such as gateways and firewalls). The storage management service manages storage services (such as data bucket services). The authentication service manages tenant accounts and passwords. The image management service manages virtual instance images.
[0061] exist Figure 1In the illustrated implementation scenario, a data center contains multiple servers. The servers consist of a hardware layer and a software layer. The hardware layer comprises the standard server configuration, including processors, memory, network interface cards (NICs), disks, and buses. The software layer includes the operating system installed and running on the server. This operating system, relative to the virtual machine, can be called the host operating system. The host operating system runs a virtual machine manager (also known as a hypervisor). The hypervisor's role is to implement compute virtualization, network virtualization, and storage virtualization, and to manage the virtual machines.
[0062] The virtual machine manager runs a cloud management platform client. This client receives control plane commands from the cloud management platform, creates virtual instances on the server based on these commands, and manages the virtual instances throughout their lifecycle. For example, the client can monitor the hardware resource usage of the server in real time and report it to the cloud management platform. When the cloud management platform confirms that a virtual instance needs to be created on a specific server, it sends a virtual instance creation command to the client on that server. Upon receiving the command, the client creates the virtual instance on that server. In this way, tenants can create, manage, log in to, and operate virtual instances through the cloud management platform.
[0063] Servers can run virtual machines of different specifications. Virtual machine specifications are categorized as: general-purpose computing, memory-optimized, ultra-large memory, etc., with specific specifications under each type. After a tenant selects a virtual machine specification, the cloud management platform selects a server in the data center that supports that specification and ensures sufficient idle hardware resources on that server. Then, it creates and configures the virtual machine with that specification on that server. Configuring servers through the cloud management platform allows for the analysis and planning of server hardware resources. Based on the server's hardware performance, it plans the corresponding computing products for the physical hardware, such as planning virtual machines of different specifications, to meet the diverse needs of different tenants. Furthermore, differentiated pricing strategies can be implemented based on the performance differences of virtual machines of different specifications. For example, high-performance virtual instances can be sold at a higher price, while ordinary performance virtual instances can be sold at a lower price, allowing tenants to purchase virtual instances as needed.
[0064] In one implementation, such as Figure 2As shown, the location of infrastructure can be described using cloud resource deployment regions (regions) and availability zones (AZs). Tenants can choose to deploy cloud services based on resources within specific regions and AZs. Regions are defined by geographical location and network latency. Using the same resource pool within the same region can be understood as sharing public services such as elastic computing, block storage, object storage, virtual private cloud (VPC) networks, elastic internet protocol (EIP) addresses, and images. Regions are divided into general-purpose regions and dedicated regions. General-purpose regions provide general cloud services to public tenants. Dedicated regions are dedicated regions that host the same type of business or provide business services to specific tenants. A region typically includes multiple AZs. Multiple AZs within a region are connected via high-speed fiber optic cables to meet the needs of tenants building high-availability systems across AZs. Computing, network, and storage resources within an AZ are logically divided into multiple clusters.
[0065] Tenants can send instructions to the cloud management platform through their client 2 to create, manage, log in to, and operate virtual instances on the server, and use the cloud services provided by these virtual instances. For example, the cloud management platform can provide an access interface. This interface can be provided either as a user interface or an API. Tenants can operate their client to remotely access the access interface to register a cloud account and password on the cloud management platform, and then log in using these accounts and passwords. The cloud management platform can also authenticate the cloud account and password. After successful authentication, the tenant can further select and purchase a virtual instance with specific specifications (processor, memory, disk) on the cloud management platform. After the tenant successfully purchases the virtual instance, the cloud management platform provides the tenant with a remote login account and password for the purchased virtual instance. The tenant can use the remote login account and password to remotely log in to the virtual instance on their client, install and run their application within the virtual instance, and use the application to implement their business operations.
[0066] Client 2 can be selected from computers, personal computers, laptops, mobile phones, smartphones, tablets, cloud servers, portable mobile terminals, multimedia players, e-book readers, wearable devices, smart home appliances, artificial intelligence devices, smart wearable devices, smart in-vehicle devices, or Internet of Things devices, etc.
[0067] In one implementation, the method for managing edge sites based on public cloud technology provided in this application embodiment can be implemented by running an executable program on a computing device in cloud system 1. When the method for managing edge sites based on public cloud technology provided in this application embodiment is applied to a cloud management platform, the server used to implement the cloud management platform can implement the method for managing edge sites based on public cloud technology provided in this application embodiment by running the executable program of the method for managing edge sites based on public cloud technology provided in this application embodiment. Furthermore, the executable program for implementing the method for managing edge sites based on public cloud technology can optionally be presented in the form of an application installation package. After the server installs the application installation package, it can implement the method for managing edge sites based on public cloud technology provided in this application embodiment by running the executable program therein.
[0068] It should be understood that the above content is an exemplary description of the implementation scenarios of the method for managing edge sites based on public cloud technology provided in the embodiments of this application, and does not constitute a limitation on the implementation scenarios of the method for managing edge sites based on public cloud technology. Those skilled in the art will understand that, as business needs change, the implementation scenarios can be adjusted according to application requirements, and the embodiments of this application do not specifically limit them. Furthermore, when the method for managing edge sites based on public cloud technology provided in the embodiments of this application is applied to other scenarios, the executable program of the method can also be presented in the form of an application installation package or in other ways, and the embodiments of this application do not list them all.
[0069] The implementation process of the method for managing edge sites based on public cloud technology provided in this application embodiment is described below. The edge site is deployed in the edge cloud of a public cloud. A cloud management platform is deployed in the central cloud of the public cloud. Management components are deployed in the edge cloud. Both the cloud management platform and the management components are used to manage the edge site. The edge site is used to deploy tenant services. Figure 3 This is a flowchart illustrating a method for managing edge sites based on public cloud technology, as provided in an embodiment of this application. Figure 3 As shown, its implementation process includes the following steps.
[0070] Step 301: The cloud management platform obtains the enhanced configuration instruction sent by the tenant. The enhanced configuration instruction is used to indicate the target control operation that still needs to be performed on the edge site when the edge site and the cloud management platform cannot communicate. The target control operation is executed under specified trigger conditions.
[0071] When a tenant needs to perform a target control operation on an edge site even when it cannot communicate with the cloud management platform, they can execute a specified operation on their client to trigger an enhanced configuration command. This command allows the cloud management platform to obtain the required information. The enhanced configuration command carries the edge site's identifier and the target control operation's instructions, enabling the cloud management platform to identify the edge site requiring the operation despite the communication barrier and the specific target control operation to be performed. In one possible implementation, the cloud management platform can provide an interface to the tenant to trigger the enhanced configuration command. After triggering the command, the cloud management platform can obtain the command through the interface and extract the target control operation from it.
[0072] In one possible implementation, the interaction interface of this application is implemented through one or more of the following: an application programming interface (API), an interaction template, and a configuration interface. The interaction template is a template provided by the cloud management platform to the tenant to implement different functions. When a tenant needs to use a certain function, the tenant can download the template to implement that function, add its relevant information to the template, and then send the template with the added tenant information back to the cloud management platform. After receiving the template with the added tenant information, the cloud management platform can obtain the function that the template needs to implement and customize the implementation of that function according to the tenant's information. The configuration interface allows the tenant to operate within the configuration interface to indicate the function that the tenant needs to implement. The configuration interface is, for example, a user interface (UI).
[0073] Optionally, the timing of sending the enhanced configuration command can be determined based on application requirements. That is, the tenant can send the enhanced configuration command to the cloud management platform whenever needed. For example, when instructing the cloud management platform to create an edge site, the tenant may also instruct the cloud management platform to perform target control operations on the edge site even if the edge site cannot communicate with the cloud management platform. In this case, the enhanced configuration command can be sent to the cloud management platform as a separate command; that is, the tenant sends the enhanced configuration command to the cloud management platform along with the edge site creation command. The edge site creation command is used to instruct the cloud management platform to create the edge site. Alternatively, the enhanced configuration command can be sent as an optional feature of the edge site creation command. For example, the enhanced configuration command can be configured by the tenant as an optional function of the edge site creation command. When the tenant needs to configure this function indicated by the enhanced configuration command for the edge site to be created, the tenant can configure this function in the edge site creation interface. When the tenant does not need to configure this function indicated by the enhanced configuration command for the edge site to be created, the tenant does not need to configure this function in the edge site creation interface. For example, after the cloud management platform has created an edge site for the tenant, the tenant sends this enhanced configuration command to the cloud management platform.
[0074] The target management operation can be any management operation that the cloud management platform can perform on the edge site. For example, the target management operation includes one or more of the following: managing the lifecycle of the edge site, migrating the edge site, deleting the edge site, releasing resources used by the edge site, or elastically scaling the resources used by the edge site. Furthermore, the resources targeted by the target management operation can be any resources used by the edge site, such as computing resources, storage resources, and network resources.
[0075] In addition, to help tenants understand the functionality of this enhanced configuration command, the cloud management platform can also display its functionality in interfaces such as the configuration interface. For example, the cloud management platform can display the enhanced configuration command's functionality on the user interface (UI) for managing edge sites displayed in the tenant's client. For instance, displaying the enhanced configuration command to support edge remote / edge site scenarios ensures that the enhanced configuration command will still function normally even if the cloud-edge connection is lost. For example, assuming the enhanced configuration command indicates that edge site 'aa' supports a specified policy: scheduled power-on at 9:00 AM every day, then even if the cloud-edge connection is lost, edge site 'aa' will automatically power on at 9:00 AM every day, unaffected by the cloud-edge connection loss.
[0076] Step 302: Based on the enhanced configuration instructions, the cloud management platform configures the target configuration information in the cloud management platform.
[0077] Upon receiving an enhanced configuration command, the cloud management platform can determine that even if the edge site indicated by the command cannot communicate with the cloud management platform, the target control operation still needs to be performed on that edge site. Therefore, upon receiving the enhanced configuration command, the cloud management platform needs to perform relevant preparatory operations beforehand. These preparatory operations mainly include: configuring the target configuration information necessary for performing the target control operation on the edge site, recording the scheduled task used to perform the target control operation, and configuring the triggering mechanism of the scheduled task, so that it can be triggered based on the specified triggering conditions of the target control operation. Configuring the target configuration information mainly includes obtaining and saving the target configuration information. For example, when the target control operation is to control the boot of a virtual machine, the target configuration information necessary for performing this operation includes: the virtual machine's Extensible Markup Language (XML) file, flow table, and storage unique identifier, etc. Therefore, configuring the target configuration information in the cloud management platform includes: obtaining and saving the virtual machine's XML file, flow table, and storage unique identifier, etc.
[0078] It should be noted that the target configuration information required for different control operations may be different, and the preparatory operations required are also different. This application does not list them one by one.
[0079] Step 303: The cloud management platform provides the management components with the target configuration information required to perform the target control operations based on the enhanced configuration instructions.
[0080] As described above, after receiving an enhanced configuration command, the cloud management platform needs to pre-configure the target configuration information for that command. After configuring the target configuration information, the cloud management platform also needs to provide this target configuration information to the management component. Once the cloud management platform provides this target configuration information to the management component, if the edge site meets the triggering conditions for a target control operation when the cloud management platform and the management component cannot communicate, the management component, possessing this target configuration information, can then perform the target control operation on the edge site based on that target configuration.
[0081] In one possible implementation, the cloud management platform may provide the target configuration information to the management component immediately after obtaining it. Alternatively, the cloud management platform may send a request notification to the management component after obtaining the target configuration information, and the management component may retrieve the target configuration information from the cloud management platform upon receiving the notification. For example, the management component may pull the target configuration information from the cloud management platform based on the request notification. Here, "the cloud management platform providing the target configuration information to the management component" means that the cloud management platform provides the target configuration information to the management component when communication between the cloud management platform and the management component is possible.
[0082] Step 304: When the specified triggering conditions are met, the cloud management platform performs target control operations on the edge site based on the target configuration information.
[0083] After receiving the enhanced configuration command, the cloud management platform can determine the specified triggering conditions for executing the target control operation. When these conditions are met, the cloud management platform can first send an instruction to the edge site, based on the target configuration information, to perform the target control operation. For example, assuming the target control operation is to control the edge site to power on at a specified time, the cloud management platform can first send an instruction to the edge site to power on at the specified time, based on the target configuration information.
[0084] In one possible implementation, before performing target control operations on an edge site, the cloud management platform may optionally detect the status of the edge site. If the status of the edge site indicates that target control operations are required, then the target control operations are performed on the edge site; if the status indicates that target control operations are not required, then no target control operations are performed on the edge site. Therefore, the implementation process of step 303 includes: when a specified trigger condition is met and the edge site is in a state where no target control operation has been performed, the cloud management platform performs target control operations on the edge site based on target configuration information. For example, assuming the target control operation is to control the edge site to power on at a specified time, the cloud management platform, upon reaching the specified time, can first detect whether the edge site is already powered on. If the edge site is not powered on, the cloud management platform sends a command to the edge site instructing it to power on based on the target configuration information.
[0085] Whether an edge site is in a state where a target control operation has been performed can be determined by the cloud management platform, which obtains this information from the management component, provided the management component and management platform can communicate with each other. For example, a mechanism exists between the cloud management platform and management component to communicate the edge site's state. When an operation by one party causes a change in the edge site's state, the other party is notified of this change. For instance, if shared memory is used in the edge cloud, after the management component performs a target control operation on an edge site, causing a change in the edge site's state, the management component writes an indication to the shared memory that the edge site's state is the state after the target control operation. For example, after meeting a specified triggering condition for a target control operation, if the edge site detects a communication breakdown with the cloud management platform, it performs the target control operation on the edge site, placing it in a state where the target control operation has been performed. In this case, the management component writes an indication to the shared memory that the edge site's state is the state after the target control operation. When the cloud management platform needs to obtain the edge site's state, it can do so by accessing the shared memory or by accessing the management component. The management component then provides the cloud management platform with the edge site's state based on the result of accessing the shared memory.
[0086] Step 305: If the cloud management platform indicates that the edge site and the cloud management platform cannot communicate in response to the target control operation, it shall continue to perform the target control operation on the edge site based on the target configuration information according to the specified policy until the stopping condition is met.
[0087] After the cloud management platform sends an instruction to the edge site to perform a target control operation, if communication between the edge site and the cloud management platform fails, the cloud management platform will receive a response indicating that communication between the edge site and the cloud management platform is unavailable. Based on this response, the cloud management platform can determine that communication between the edge site and the cloud management platform is unavailable. However, since the cloud management platform cannot predict when communication between the edge site and the cloud management platform will be restored, in order to ensure that the target control operation can be performed on the edge site, the cloud management platform can continue to perform the target control operation on the edge site based on the target configuration information according to a specified strategy until the stopping condition is met.
[0088] The stopping conditions can be configured according to application requirements. In one possible implementation, the stopping conditions include one or more of the following: the cloud management platform receives a specified number of responses indicating that communication between the edge site and the cloud management platform is impossible, or the cloud management platform receives an indication that the edge site has been subjected to target control operations. If the cloud management platform receives a specified number of responses (e.g., 5 times) indicating that communication between the edge site and the cloud management platform is impossible, it means that communication between the cloud management platform and the edge site has not yet been restored. To avoid wasting resources, the cloud management platform can stop performing target control operations on the edge site. During the process of the cloud management platform continuing to perform target control operations on the edge site based on the target configuration information according to the specified strategy, it can also obtain the status of the edge site. If it is found during this process that the edge site is in a state where target control operations have been performed, then there is no need to perform the target control operation on the edge site anymore, and the cloud management platform stops performing target control operations on the edge site. For the implementation method of the cloud management platform receiving the indication that the edge site has been subjected to target control operations, please refer to the relevant description in step 303, which will not be repeated here.
[0089] The specified strategy and the specified number of times can be determined based on application requirements. For example, when the stopping condition includes the cloud management platform receiving a specified number of responses indicating that communication between the edge site and the cloud management platform is impossible, the specified strategy can be that the cloud management platform performs the target control operation on the edge site multiple times at the same time interval (e.g., 2 seconds), or the cloud management platform performs the target control operation on the edge site multiple times according to a specified backoff strategy. For example, when performing the target control operation multiple times, the time interval between the (n+1)th and nth executions of the target control operation is greater than the time interval between the nth and (n-1)th executions of the target control operation.
[0090] It should be noted that after the cloud management platform sends an instruction to the edge site to perform the target control operation, if the cloud management platform receives a response indicating that the target control operation on the edge site has been completed, it means that the task of performing the target control operation on the edge site has been completed, and there is no need to continue to perform subsequent steps.
[0091] Step 306: When the management component cannot communicate between the edge site and the cloud management platform and the specified triggering conditions are met, the target control operation is performed on the edge site based on the target configuration information.
[0092] After the management component obtains the target configuration information required to execute the target control operation, if the edge site and the cloud management platform cannot communicate and the specified triggering conditions are met, the management component will execute the target control operation on the edge site based on the target configuration information. In this case, by having the management component execute the target control operation on the edge site, control over the edge site can continue even when communication between the management component and the edge site is impossible, thus preventing situations where control over the edge site cannot be achieved due to the inability to transmit control commands between the edge site and the cloud management platform via a communication connection.
[0093] Optionally, before performing target control operations on the edge site, the management component also needs to detect the status of the edge site. When the status of the edge site indicates that target control operations need to be performed, the management component performs the target control operations on the edge site. Therefore, the implementation process of step 301 includes: when the edge site and the cloud management platform cannot communicate, a specified triggering condition is met, and the edge site is in a state where no target control operations have been performed, the management component performs target control operations on the edge site based on the target configuration information.
[0094] Since both edge sites and management components are deployed in the edge cloud, the communication status between the edge sites and the cloud management platform can be obtained through the communication status between the management component and the cloud management platform. When the management component detects that it can communicate with the cloud management platform, it determines that communication between the cloud management platform and the edge site is also possible; conversely, when it detects that communication is impossible, it determines that communication between the cloud management platform and the edge site is impossible. The management component can detect its communication status with the cloud management platform in various ways. For example, it can detect the heartbeat between itself and the cloud management platform. If the heartbeat between the management component and the cloud management platform is normal, it indicates that the communication status between them is normal.
[0095] The implementation method of the management component performing target control operations on edge sites based on target configuration information varies depending on the target control operation being performed. The following example illustrates this using controlling the booting of a virtual machine as an example of target control operation.
[0096] After receiving the target configuration information, the management component sets up a scheduled task to execute under specified trigger conditions. For example, this scheduled task might be a script written using the Crontab command, detailing the implementation of triggering virtual machine startup under those conditions. When the specified trigger conditions are met, the scheduled task executes the script, and the management component follows the script to start the virtual machine. For instance, the management component might traverse the locally persisted ` / *** / startvm` directory containing universally unique identifiers (UUIDs) to find the virtual machines that need to be started. Then, the management component checks the heartbeat between itself and the cloud management platform. If the heartbeat is normal, the cloud management platform can trigger the virtual machine startup, and the management component exits the startup process. If the heartbeat is abnormal, the management component calls the virtual machine management API (such as the libvirt interface) to query the virtual machine status. If the virtual machine is already powered on or in the process of starting up, the management component does not trigger startup and continues to the next virtual machine directory to trigger startup for the next virtual machine.
[0097] During the virtual machine startup process triggered by the management component, if the management component detects that the virtual machine does not exist, it means that the virtual machine released its resources after the last shutdown, and the disks it needs are not mounted locally. If the management component detects that the virtual machine is in a shutdown state, it means that the virtual machine did not release its resources after the last shutdown, and the disks it needs are mounted locally. In this case, the management component uses the cached disk identifier to mount the disk and performs registration and reservation checks using the Small Computer System Interface (SCSI)-3 locking mechanism to prevent split-brain. Furthermore, the management component uses cached flow table information to configure the network for the virtual machine and then uses the cached virtual machine XML file to start the virtual machine. The management component can optionally call the distributed storage command-line interface (CLI) to mount devices and load the corresponding device drivers on the edge site, generating local device files for subsequent virtual machine disks. The management component can perform the virtual machine startup operation by accessing APIs for managing virtual machines (such as the libvirt interface). Additionally, since the management component performs the operation that triggers the virtual machine to boot, it also needs to set the virtual machine to a "locally booting" state in shared memory.
[0098] Step 307: If the management component has already performed the target control operation on the edge site and the cloud management platform is still instructing the edge site to perform the target control operation, the management component sends an instruction to the cloud management platform indicating that the target control operation has been performed on the edge site.
[0099] After performing target control operations on an edge site, if the management component receives an instruction from the cloud management platform to perform target control operations on the edge site, and can determine that the cloud management platform is still instructing the edge site to perform target control operations, the management component can send an indication to the cloud management platform that the target control operations have been performed on the edge site, thus avoiding duplicate operations by the cloud management platform. There are several ways to implement this. For example, when the management component detects a request from the cloud management platform to perform target control operations on the edge site, the management component can access its shared memory to obtain the status of the edge site. If the status indicates that target control operations have been performed on the edge site, the management component can then send an indication to the cloud management platform that the target control operations have been performed on the edge site.
[0100] Step 308: When the status of the management component changes at the edge site, update the target configuration information required to perform the target control operation.
[0101] When the state of an edge site changes, the management component also needs to update the target configuration information required for performing target management operations to ensure consistency in the target management operations performed on the edge site based on the target configuration information. Specifically, if the change in the edge site's state is due to reasons within the edge cloud, the management component obtains the relevant information of the edge site after the change from the edge cloud, updates the target configuration information accordingly, and provides the updated target configuration information to the cloud management platform. If the change in the edge site's state is due to reasons within the central cloud, the cloud management platform will update the target configuration information, and the management component obtains the updated target configuration information from the cloud management platform. In addition, the management component can perform other consistency processing for edge sites after state changes. For example, in scenarios involving the deletion of an edge site (such as a virtual machine) and hot migration, the local cache folder corresponding to the edge site is cleaned up. During the hot-swapping of network cards and disks at the edge site, the local cache files are refreshed. When the flow table at the edge site is updated, the flow table files cached by the management component are refreshed. After the management component has performed target control operations on the edge sites and normal communication between the management component and the cloud management platform has been restored, the management component queries the cloud management platform to see if the cached edge sites in the edge cloud are on other nodes managed by other management components. If they exist, the local cache of the folder is cleared to achieve anomaly protection for the edge sites. In scenarios of virtual machine startup and hot migration, target configuration information such as virtual machine XML files, flow tables, and storage unique identifiers are cached. Furthermore, after the management component and the cloud management platform resume communication, the management component pulls the latest flow tables from the cloud management platform and refreshes the cache to ensure that the management component has the latest network policies, such as access control lists (ACLs), security groups, or peering, after network recovery.
[0102] In one possible implementation, the functions of the cloud management platform and management components can both be implemented through multiple functional components. The following example, using an edge site as a virtual machine, illustrates how the functions of the cloud management platform and management components can be implemented through multiple functional components.
[0103] like Figure 4 As shown, the cloud management platform's functionality can be implemented through computing APIs, computing control components, network control components, and network Kafka components. The management components can be implemented through virtualization computing agents, virtualization network agents, virtualization storage agents, and APIs for managing virtual machines (such as the libvirt interface). Alternatively, the management components can be implemented through computing nodes in the edge cloud.
[0104] The compute API is used to interact with tenants and provide instructions sent by tenants to the compute management component. For example, a tenant sends enhanced configuration instructions to the cloud management platform via the compute API, which in turn provides these instructions to the compute management component. The compute management component and network management component manage the compute and network resources used by the edge site, respectively. For example, the compute management component records scheduled tasks for performing the target management operation (e.g., recording scheduled tasks in its database), configures the triggering mechanism of the scheduled task, transmits relevant parameters to the virtualization agent, and triggers the virtualization agent to execute the target management operation. Similarly, the network management component provides flow tables to the virtualization network agent. These compute and network management components are just examples; edge sites may also use other types of resources. In such cases, the cloud management platform also needs to deploy management components for managing these other types of resources. For example, if the edge site also uses storage resources, the cloud management platform also deploys a storage management component to manage these storage resources. The network Kafka is used to facilitate information transfer between the cloud management platform and the edge site. For example, network Kafka is used to obtain flow tables from network management components and synchronize flow tables to the virtualized network agent via the Kafka messaging mechanism. Using the Kafka messaging mechanism to transmit information is an optional implementation method; other methods can also be used, and this application does not specifically limit their application.
[0105] The virtualization computing agent manages the computing resources used by virtual machines, manages scheduled tasks, manages target configuration messages, performs target control operations on virtual machines, and performs related processing to ensure consistency. As can be seen, the operations performed by the management components mentioned above are mainly implemented by the virtualization computing agent. The virtualization network agent manages the network resources used by virtual machines, such as synchronizing flow tables from the cloud management platform, managing flow tables, and providing flow tables to the virtualization computing agent. The virtualization network agent manages the storage resources used by virtual machines, such as recording and persisting disk identifiers, and providing the required disk identifiers to the virtualization computing agent. APIs for managing virtual machines (such as the libvirt interface) are used to persist virtual machine files and execute virtual machine startup.
[0106] As can be seen from the above, in the method for managing edge sites based on public cloud technology provided in this application embodiment, after obtaining the enhanced configuration instruction sent by the tenant, the cloud management platform provides the management component with the target configuration information required to perform the target control operation based on the enhanced configuration instruction. The enhanced configuration instruction is used to indicate the target control operation that still needs to be performed on the edge site when the edge site and the cloud management platform cannot communicate. The target control operation is performed under specified triggering conditions. Then, when the edge site and the cloud management platform cannot communicate and the specified triggering conditions are met, the management component can perform the target control operation on the edge site based on the target configuration information. In this way, according to the method provided in this application, even when the edge site and the cloud management platform cannot communicate, if the specified triggering conditions for performing the target control operation on the edge site are met, the management component can perform the target control operation on the edge site, thereby achieving control over the edge site. This avoids the situation where the edge site cannot be controlled due to the inability to transmit control instructions based on the communication connection between the edge site and the cloud management platform. For example, there will be no situation where a cloud desktop that has been shut down cannot be turned on due to a cloud-edge disconnection, thus preventing customers from using the cloud desktop for work. This ensures the continuity of customer business and avoids situations where cloud desktops cannot be shut down due to cloud-edge disconnection. This facilitates the promotion of edge sites and reduces the operation and maintenance burden after edge sites are launched. In addition, this application does not require the separate deployment of edge computing management components, local authentication systems, and local API gateways on the edge site side, reducing the management overhead and security risks at the edge.
[0107] Furthermore, the order of steps in the method for managing edge sites based on public cloud technology provided in this application can be appropriately adjusted, and steps can be added or removed as needed. Any variations that can be easily conceived by those skilled in the art within the scope of the technology disclosed in this application should be included within the protection scope of this application, and therefore will not be elaborated further.
[0108] The following describes an example of a virtual device in an embodiment of this application.
[0109] The above describes a method for managing edge sites based on public cloud technology according to embodiments of this application. Corresponding to the above method, embodiments of this application also provide a cloud system for managing edge sites based on public cloud technology. Figure 5 This is a schematic diagram of the structure of a cloud system for managing edge sites based on public cloud technology, provided in an embodiment of this application. Based on... Figure 5 The following are several components shown, which Figure 5 The cloud system shown, which manages edge sites based on public cloud technology, is capable of performing the above-mentioned tasks. Figure 3All or part of the operations shown. It should be understood that the device may include more additional components than those shown or omit some of the components shown, and the embodiments of this application are not limited in this regard.
[0110] The edge site is deployed in the edge cloud of the public cloud. A cloud management platform 11 is deployed in the central cloud of the public cloud. A management component 12 is deployed in the edge cloud of the public cloud. Both the cloud management platform 11 and the management component 12 are used to manage the edge site. The edge site is used to deploy tenant services. The cloud system 1 includes: a cloud management platform 11, used to obtain enhanced configuration instructions sent by tenants, which instruct the target control operations that still need to be performed on the edge site even when communication between the edge site and the cloud management platform 11 is impossible; the target control operations are performed under specified triggering conditions; the cloud management platform 11 is also used to provide the management component 12 with the target configuration information required to perform the target control operations based on the enhanced configuration instructions; the management component 12 is used to perform target control operations on the edge site based on the target configuration information when communication between the edge site and the cloud management platform 11 is impossible and specified triggering conditions are met.
[0111] In one possible implementation, the management component 12 is specifically used to perform target management operations on the edge site based on the target configuration information when communication between the edge site and the cloud management platform 11 fails, a specified trigger condition is met, and the edge site is in a state where no target management operation is performed.
[0112] In one possible implementation, before the management component 12 fails to communicate between the edge site and the cloud management platform 11 and a specified triggering condition is met, the cloud system 1 is further configured to: configure target configuration information in the cloud management platform 11 based on enhanced configuration instructions; and perform target control operations on the edge site based on the target configuration information when the specified triggering condition is met.
[0113] In one possible implementation, the cloud system 1 is also used to: continue to perform target control operations on the edge site based on the target configuration information according to a specified strategy when the response indication of the target control operation indicates that communication between the edge site and the cloud management platform 11 is impossible, until the stopping condition is met.
[0114] In one possible implementation, the stopping condition includes one or more of the following: the cloud management platform 11 receives a specified number of responses indicating that the edge site and the cloud management platform 11 cannot communicate; or the cloud management platform 11 obtains that the edge site is in a state where target control operations have been performed.
[0115] In one possible implementation, the cloud management platform 11 is specifically used to perform target management operations on the edge site based on the target configuration information when a specified triggering condition is met and the edge site is in a state where no target management operation has been performed.
[0116] In one possible implementation, the management component 12 is also used to send an instruction to the cloud management platform 11 indicating that a target control operation has been performed on the edge site, while the cloud management platform 11 is still instructing the edge site to perform the target control operation.
[0117] In one possible implementation, the management component 12 is also used to update the target configuration information required to perform target control operations when the state of the edge site changes.
[0118] In one possible implementation, the target management operations include one or more of the following: managing the lifecycle of edge sites, migrating edge sites, deleting edge sites, releasing resources used by edge sites, or elastically scaling the resources used by edge sites.
[0119] Both the cloud management platform 11 and the management component 12 can be implemented through software or hardware. For example, the implementation of the cloud management platform 11 will be described below. Similarly, the implementation of the management component 12 can refer to the implementation of the cloud management platform 11.
[0120] As an example of a software functional unit, the cloud management platform 11 may include code running on compute instances. These compute instances may include at least one of physical hosts (computing devices), virtual machines, and containers. Furthermore, the aforementioned compute instances may be one or more. For example, the cloud management platform 11 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed within the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed within the same availability zone (AZ) or in different AZs, each AZ including one cloud data center or multiple geographically proximate cloud data centers. Typically, a region may include multiple AZs.
[0121] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same Virtual Private Cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, as well as between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.
[0122] As an example of a hardware functional unit, the cloud management platform 11 may include at least one computing device, such as a server. Alternatively, the cloud management platform 11 may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The PLD may be implemented using a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.
[0123] The cloud management platform 11 includes multiple computing devices that can be distributed within the same region or in different regions. Similarly, the cloud management platform 11 includes multiple computing devices that can be distributed within the same Availability Zone (AZ) or in different AZs. Likewise, the cloud management platform 11 includes multiple computing devices that can be distributed within the same Virtual Private Cloud (VPC) or multiple VPCs. These multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0124] It should be noted that, in other embodiments, either the cloud management platform 11 or the management component 12 can be used to execute any step in the method for managing edge sites based on public cloud technology. The steps implemented by the cloud management platform 11 and the management component 12 can be specified as needed. By implementing different steps in the method for managing edge sites based on public cloud technology through the cloud management platform 11 and the management component 12 respectively, all functions of the cloud system for managing edge sites based on public cloud technology can be achieved.
[0125] Those skilled in the art will clearly understand that, for the sake of convenience and brevity, the specific working processes of each component described above can be referred to the corresponding content in the foregoing method embodiments, and will not be repeated here.
[0126] The following provides examples illustrating the basic hardware structures involved in the embodiments of this application.
[0127] This application also provides a computing device 600. For example... Figure 6 As shown, the computing device 600 includes a bus 602, a processor 604, a memory 606, and a communication interface 608. The processor 604, the memory 606, and the communication interface 608 communicate with each other via the bus 602. The computing device 600 can be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 600.
[0128] Bus 602 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be divided into address buses, data buses, control buses, etc. For ease of representation, Figure 6 The bus 602 may be represented by a single line, but this does not mean that there is only one bus or one type of bus. The bus 602 may include a path for transmitting information between various components of the computing device 600 (e.g., memory 606, processor 604, communication interface 608).
[0129] Processor 604 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0130] Memory 606 may include volatile memory, such as random access memory (RAM). Processor 604 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0131] The memory 606 stores executable program code, which the processor 604 executes to implement the functions of the aforementioned cloud management platform 11 and management component 12, thereby realizing a method for managing edge sites based on public cloud technology. In other words, the memory 606 stores instructions for executing the method for managing edge sites based on public cloud technology.
[0132] The communication interface 608 uses transceiver modules, such as, but not limited to, network interface cards and transceivers, to enable communication between the computing device 600 and other devices or communication networks.
[0133] This application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.
[0134] like Figure 7 As shown, the computing device cluster includes at least one computing device 600. The memory 606 of one or more computing devices 600 in the computing device cluster may store the same instructions for executing methods for managing edge sites based on public cloud technology.
[0135] In some possible implementations, the memory 606 of one or more computing devices 600 in the computing device cluster may also store partial instructions for executing methods for managing edge sites based on public cloud technology. In other words, a combination of one or more computing devices 600 can jointly execute instructions for executing methods for managing edge sites based on public cloud technology.
[0136] It should be noted that the memory 606 in different computing devices 600 within the computing device cluster can store different instructions, each used to execute a portion of the functions of the cloud system for managing edge sites based on public cloud technology. In other words, the instructions stored in the memory 606 of different computing devices 600 can implement the functions of one or more modules in the cloud management platform 11 and management component 12.
[0137] In some possible implementations, one or more computing devices in a computing device cluster can be connected via a network. This network can be a wide area network (WAN), a local area network (LAN), or similar. Figure 8 One possible implementation is shown. For example... Figure 8As shown, the two computing devices 600A and 600B are connected via a network. Specifically, they are connected to the network through the communication interfaces in each computing device. In this possible implementation, the memory 606 in computing device 600A stores instructions for executing the functions of the cloud management platform 11. Simultaneously, the memory 606 in computing device 600B stores instructions for executing the functions of the management component 12.
[0138] It should be understood that Figure 8 The functions of computing device 600A shown can also be performed by multiple computing devices 600. Similarly, the functions of computing device 600B can also be performed by multiple computing devices 600.
[0139] This application also provides another computing device cluster. The connection relationships between the computing devices in this computing device cluster can be similarly referred to... Figure 7 and Figure 8 The connection method of the computing device cluster. The difference is that the memory 606 of one or more computing devices 600 in the computing device cluster can store the same instructions for executing methods to manage edge sites based on public cloud technology.
[0140] In some possible implementations, the memory 606 of one or more computing devices 600 in the computing device cluster may also store partial instructions for executing methods for managing edge sites based on public cloud technology. In other words, a combination of one or more computing devices 600 can jointly execute instructions for executing methods for managing edge sites based on public cloud technology.
[0141] This application also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions capable of running on a computing device or stored on any available medium. When the computer program product runs on at least one computing device, it causes the at least one computing device to perform a method for managing edge sites based on public cloud technology.
[0142] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store, or a data storage device such as a data center that includes one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to perform a method for managing edge sites based on public cloud technology, or instruct the computing device to perform a method for managing edge sites based on public cloud technology.
[0143] Those skilled in the art will understand that all or part of the steps of the above embodiments can be implemented by hardware or by a program instructing related hardware. The program can be stored in a computer-readable storage medium, such as a read-only memory, a disk, or an optical disk.
[0144] It should be noted that all information (including but not limited to user device information, user personal information, etc.), data (including but not limited to data used for analysis, stored data, displayed data, etc.), and signals involved in this application have been authorized by the user or fully authorized by all parties, and the collection, use, and processing of related data must comply with the relevant laws, regulations, and standards of the relevant countries and regions. For example, the raw data and executable code involved in this application were obtained with full authorization.
[0145] In the embodiments of this application, the terms "first," "second," and "third" are used for descriptive purposes only and should not be construed as indicating or implying relative importance. The term "at least one" refers to one or more, and the term "multiple" refers to two or more, unless otherwise expressly defined.
[0146] In this application, the term "and / or" is merely a description of the relationship between related objects, indicating that three relationships can exist. For example, A and / or B can represent: A existing alone, A and B existing simultaneously, or B existing alone. Additionally, the character " / " in this document generally indicates that the preceding and following related objects have an "or" relationship.
[0147] The above description is merely an optional embodiment of this application and is not intended to limit this application. Any modifications, equivalent substitutions, improvements, etc., made within the concept and principles of this application should be included within the protection scope of this application.
Claims
1. A method for managing edge sites based on public cloud technology, characterized in that, The edge site is deployed in the edge cloud of the public cloud. A cloud management platform is deployed in the central cloud of the public cloud, and a management component is deployed in the edge cloud. Both the cloud management platform and the management component are used to manage the edge site. The edge site is used to deploy tenant services. The method includes: The cloud management platform obtains the enhanced configuration instruction sent by the tenant. The enhanced configuration instruction is used to indicate the target control operation that still needs to be performed on the edge site when the edge site cannot communicate with the cloud management platform. The target control operation is performed under specified triggering conditions. Based on the enhanced configuration instructions, the cloud management platform provides the management component with the target configuration information required to perform the target control operation; When the management component cannot communicate between the edge site and the cloud management platform, and the specified triggering condition is met, it performs the target control operation on the edge site based on the target configuration information.
2. The method according to claim 1, characterized in that, When the management component cannot communicate between the edge site and the cloud management platform, and the specified triggering condition is met, it performs the target control operation on the edge site based on the target configuration information, including: When the management component fails to communicate between the edge site and the cloud management platform, reaches the specified triggering condition, and the edge site is in a state where the target control operation has not been performed, the target control operation is performed on the edge site based on the target configuration information.
3. The method according to claim 1 or 2, characterized in that, Before performing the target control operation on the edge site based on the target configuration information, when the management component cannot communicate between the edge site and the cloud management platform and the specified triggering condition is met, the method further includes: The cloud management platform configures the target configuration information based on the enhanced configuration instructions. When the specified triggering conditions are met, the cloud management platform performs the target control operation on the edge site based on the target configuration information.
4. The method according to claim 3, characterized in that, The method further includes: If the cloud management platform indicates that the edge site and the cloud management platform cannot communicate in response to the target control operation, it shall continue to perform the target control operation on the edge site according to the specified strategy based on the target configuration information until the stopping condition is met.
5. The method according to claim 4, characterized in that, The stopping conditions include one or more of the following: The cloud management platform receives a specified number of responses indicating that communication between the edge site and the cloud management platform is impossible; Alternatively, the cloud management platform may obtain information that the edge site is in a state where the target control operation has been performed.
6. The method according to claim 3, characterized in that, When the specified triggering conditions are met, the cloud management platform performs the target control operation on the edge site based on the target configuration information, including: When the specified triggering condition is met and the edge site is in a state where the target control operation has not been performed, the cloud management platform performs the target control operation on the edge site based on the target configuration information.
7. The method according to claim 1, characterized in that, The method further includes: When the management component has already performed the target control operation on the edge site, and the cloud management platform is still instructing the edge site to perform the target control operation, the management component sends an instruction to the cloud management platform indicating that the target control operation has been performed on the edge site.
8. The method according to claim 1, characterized in that, The method includes: When the status of the edge site changes, the management component updates the target configuration information required to perform the target control operation.
9. The method according to any one of claims 1 to 8, characterized in that, The target management operations include one or more of the following: managing the lifecycle of the edge site, migrating the edge site, deleting the edge site, releasing the resources used by the edge site, or elastically scaling the resources used by the edge site.
10. A cloud system for managing edge sites based on public cloud technology, characterized in that, The edge site is deployed in the edge cloud of the public cloud. A cloud management platform is deployed in the central cloud of the public cloud, and management components are deployed in the edge cloud. Both the cloud management platform and the management components are used to manage the edge site. The edge site is used to deploy tenant services. The cloud system includes: The cloud management platform is used to obtain enhanced configuration instructions sent by tenants. The enhanced configuration instructions are used to indicate the target control operations that still need to be performed on the edge site when the edge site cannot communicate with the cloud management platform. The target control operations are performed under specified triggering conditions. The cloud management platform is also used to provide the management component with the target configuration information required to perform the target control operation based on the enhanced configuration instructions; The management component is used to perform the target control operation on the edge site based on the target configuration information when communication between the edge site and the cloud management platform is impossible and the specified triggering condition is met.
11. The cloud system according to claim 10, characterized in that, The management component is specifically used to perform the target management operation on the edge site based on the target configuration information when the edge site and the cloud management platform cannot communicate, the specified triggering condition is met, and the edge site is in a state where the target management operation has not been performed.
12. The cloud system according to claim 10 or 11, characterized in that, Before performing the target control operation on the edge site based on the target configuration information, when the management component fails to communicate between the edge site and the cloud management platform and the specified triggering condition is met, the cloud system is further configured to: Based on the enhanced configuration instructions, configure the target configuration information in the cloud management platform; When the specified triggering condition is met, the target control operation is performed on the edge site based on the target configuration information.
13. The cloud system according to claim 12, characterized in that, The cloud system is also used for: If the response to the target control operation indicates that the edge site and the cloud management platform cannot communicate, the target control operation shall continue to be performed on the edge site based on the target configuration information according to the specified policy until the stop condition is met.
14. The cloud system according to claim 13, characterized in that, The stopping conditions include one or more of the following: The cloud management platform receives a specified number of responses indicating that communication between the edge site and the cloud management platform is impossible; Alternatively, the cloud management platform may obtain information that the edge site is in a state where the target control operation has been performed.
15. The cloud system according to claim 12, characterized in that, The cloud management platform is specifically used to perform the target control operation on the edge site based on the target configuration information when the specified triggering condition is met and the edge site is in a state where the target control operation has not been performed.
16. The cloud system according to claim 10, characterized in that, The management component is also configured to send an instruction to the cloud management platform indicating that the target control operation has been performed on the edge site, when the target control operation has already been performed on the edge site and the cloud management platform is still instructing the target control operation to be performed on the edge site.
17. The cloud system according to claim 10, characterized in that, The management component is also used to update the target configuration information required to perform the target control operation when the status of the edge site changes.
18. The cloud system according to any one of claims 10 to 17, characterized in that, The target management operations include one or more of the following: managing the lifecycle of the edge site, migrating the edge site, deleting the edge site, releasing the resources used by the edge site, or elastically scaling the resources used by the edge site.
19. A computing device cluster, characterized in that, The system includes multiple computing devices, each comprising multiple processors and multiple memories, wherein program instructions are stored in the multiple memories, and the multiple processors execute the program instructions, causing the cluster of computing devices to implement the method described in any one of claims 1 to 9.
20. A computer-readable storage medium, characterized in that, Includes program instructions that, when executed on a computing device, cause the computing device to perform the method of any one of claims 1 to 9.
21. A computer program product containing instructions, characterized in that, When the instructions are executed by the computing device, the computing device performs the method according to any one of claims 1 to 9.