Method, apparatus, and system for managing cluster access rights
The method and system for managing cluster access permissions automatically update policies based on resource changes, addressing the inflexibility and inefficiency of current methods and enhancing real-time performance.
Patent Information
- Application Number
- JP2024570397
- Authority / Receiving Office
- JP · JP
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2022-09-01
- Filing Date
- 2023-04-21
- Publication Date
- 2025-06-12
AI Technical Summary
Current methods for managing cluster access permissions lack flexibility and real-time performance, making it inefficient to dynamically manage access rights between clusters.
A method and system that automatically obtain and update access right policies for clusters, monitoring resource changes in both the first cluster and associated second clusters, and dynamically managing access permissions using the updated policies.
This approach enhances the flexibility and real-time performance of managing cluster access permissions, allowing for efficient dynamic management of multiple clusters based on resource changes.
Smart Images

Figure 2025518158000001_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of cloud computing technology, and in particular, to a method, apparatus, and system for managing cluster access rights. Cross-reference to related applications
[0002] This application claims priority to Chinese Patent Application No. 202211064945.0, titled "Method, Apparatus, and System for Managing Cluster Access Rights", filed on September 1, 2022, and the content disclosed in the above Chinese patent application is incorporated herein by reference in its entirety or in part as part of this application.
Background Art
[0003] In order to improve the data processing ability of an Internet application system, it is usually possible to utilize data exchange between multiple clusters. Depending on the applied business scenario, when processing data exchange between clusters, it is often necessary to manage the access rights between clusters. The current method for processing access rights between clusters is to individually allocate based on the set transaction access rights (e.g., blacklist, whitelist) for each cluster that requires transactions.
Summary of the Invention
[0004] According to one or more embodiments of the present disclosure, obtaining an access right policy of a first cluster, wherein the access right policy includes access right information between the first cluster and one or more second clusters related thereto; when it is monitored that a change occurs in the resources of any one of the related second clusters, updating the access right information corresponding to the second cluster included in the access right policy based on the change result of the resources of the second cluster; Managing access rights between the second cluster associated with the first cluster using the updated access right policy A method for managing cluster access rights, characterized by including is provided.
[0005] According to one or more embodiments of the present disclosure, a method for managing such cluster access rights is When it is monitored that a change occurs in the resources of the first cluster, based on the change result of the resources of the first cluster, updating the access right information corresponding to the first cluster included in the access right policy Managing access rights between the second cluster associated with the first cluster using the updated access right policy further includes.
[0006] According to one or more embodiments of the present disclosure, updating the access right information corresponding to the second cluster included in the access right policy is By adding an annotation including the cluster identifier of the second cluster to the access right information corresponding to the second cluster, it is indicated that a resource change occurs in the second cluster through the cluster identifier included in the annotation. When the first cluster accesses the second cluster, the access right policy is combined with the annotation, including limiting the access right for the first cluster to access the second cluster.
[0007] According to one or more embodiments of the present disclosure, obtaining the access right policy of the first cluster is Obtaining the configuration information of the first cluster, and based on the configuration information, identifying the cluster information of one or more second clusters associated with the first cluster Obtain pre-set access permission information between the first cluster and one or more of the second clusters, and generate the access permission policy of the first cluster based on the pre-set access permission information; including.
[0008] According to one or more embodiments of the present disclosure, obtaining the pre-set access permission information between the first cluster and one or more of the second clusters includes: analyzing the pre-set access permission information from a pre-set configuration file, and / or analyzing the pre-set access permission information from custom permission data extended based on the native permission data of the cluster included in the first cluster. including.
[0009] According to one or more embodiments of the present disclosure, a method for managing such cluster access permissions includes: the first cluster includes a permission controller, using the permission controller to obtain the access permission policy of the first cluster and update the access permission policy. further including.
[0010] According to one or more embodiments of the present disclosure, a method for managing such cluster access permissions includes: using the permission controller to start a first controller and a second controller for the first cluster to which it belongs; using the first controller to monitor the resource change status of the first cluster; using the second controller to monitor the resource change status of one or more of the second clusters related to the first cluster. further including.
[0011] Based on one or more embodiments of the present disclosure, according to the second aspect of the embodiments of the present disclosure, A module for obtaining an access permission policy of a first cluster, the policy obtaining module wherein the access permission policy includes access permission information between the first cluster and one or more second clusters related thereto; When it is monitored that a change occurs in the resource of any one of the related second clusters, based on the change result of the resource of the second cluster, for updating the access permission information corresponding to the second cluster included in the access permission policy A permission change module; A permission management module for managing access permissions between the first cluster and the related second clusters using the updated access permission policy; An apparatus for managing cluster access permissions including is provided.
[0012] According to one or more embodiments of the present disclosure, the apparatus for managing such cluster access permissions further When it is monitored that a change occurs in the resource of the first cluster, based on the change result of the resource of the first cluster, updating the access permission information corresponding to the first cluster included in the access permission policy; Managing access permissions between the first cluster and the related second clusters using the updated access permission policy; is used for.
[0013] According to one or more embodiments of the present disclosure, the apparatus for managing such cluster access permissions is used for updating the access permission information corresponding to the second cluster included in the access permission policy, By adding an annotation including the cluster identifier of the second cluster to the access permission information corresponding to the second cluster, it is indicated that a resource change occurs in the second cluster through the cluster identifier included in the annotation. When the first cluster accesses the second cluster, the access permission policy is combined with the annotation, including limiting the access permission for the first cluster to access the second cluster.
[0014] According to one or more embodiments of the present disclosure, an apparatus for managing such cluster access permissions is used to obtain the access permission policy of the first cluster, obtain the configuration information of the first cluster, and based on the configuration information, identify the cluster information of one or more second clusters related to the first cluster; obtain the pre-set access permission information between the first cluster and one or more of the second clusters, and based on the pre-set access permission information, generate the access permission policy of the first cluster; including.
[0015] According to one or more embodiments of the present disclosure, an apparatus for managing such cluster access permissions is used to obtain the pre-set access permission information between the first cluster and one or more of the second clusters, analyze the pre-set access permission information from the pre-set configuration file, and / or analyze the pre-set access permission information from the custom permission data extended based on the native permission data of the cluster included in the first cluster.
[0016] According to one or more embodiments of the present disclosure, an apparatus for managing such cluster access permissions further includes the first cluster includes a permission controller, Executing the steps of obtaining the access permission policy of the first cluster by using the permission controller and updating the access permission policy is used for.
[0017] According to one or more embodiments of the present disclosure, an apparatus for managing such cluster access rights further includes activating a first controller and a second controller for a first cluster to which it belongs by using the permission controller; monitoring the resource change status of the first cluster by using the first controller; monitoring the resource change status of one or more of the second clusters related to the first cluster by using the second controller; is used for.
[0018] According to one or more embodiments of the present disclosure A module for obtaining an access permission policy of a first cluster, the access permission policy including a policy acquisition module for access permission information between the first cluster and one or more second clusters related thereto; When it is monitored that a change occurs in the resources of the first cluster, based on the change result of the resources of the first cluster, a permission change module for updating the access permission information corresponding to the first cluster included in the access permission policy; A permission management module for managing access permissions between the first cluster and the second clusters related thereto by using the updated access permission policy; An apparatus for managing cluster access rights including is provided.
[0019] According to one or more embodiments of the present disclosure including a plurality of communicatively connected clusters, among which One or more of the clusters are provided with a device for managing the cluster access rights described in the second aspect or a device for managing the cluster access rights described in the third aspect, a system for managing cluster access rights is provided.
[0020] According to one or more embodiments of the present disclosure, one or more processors, a storage device for storing one or more programs, including when the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of the methods for managing cluster access rights as described above, an electronic device for managing cluster access rights is provided.
[0021] According to one or more embodiments of the present disclosure, a computer-readable medium storing a computer program, when the program is executed by a processor, the method according to any one of the methods for managing cluster access rights as described above is implemented, a computer-readable medium is provided.
[0022] The embodiments of the present disclosure have the following advantages or beneficial effects. Automatically obtain the access right policy of the first cluster managed by multiple clusters, obtain the access right information between the first cluster and one or more second clusters related to the first cluster included in the access right policy, and when it is monitored that a change occurs in the resources of the one or more second clusters, automatically update the access right information included in the access right policy, and use the updated access right information to dynamically manage multiple clusters. According to the method of the embodiments of the present disclosure, the problem that the flexibility of the current method for managing cluster access permissions is poor is solved, and the real-time performance and efficiency of managing cluster access permissions are improved.
[0023] Regarding the further effects provided by the above non-conventional selectable forms, they will be described in conjunction with the following "Modes for Carrying Out the Invention".
Brief Description of the Drawings
[0024] The drawings are for better understanding of the present disclosure and do not constitute an inappropriate limitation to the present disclosure.
Figure 1
Figure 2
Figure 3
Figure 4
Figure 5
Figure 6
Figure 7
Modes for Carrying Out the Invention
[0025] Exemplary embodiments of the present disclosure will be described below in conjunction with the drawings. It should be noted that each detail of the embodiments of the present disclosure is included for the purpose of contributing to the understanding, and it should be considered that they are merely illustrative. Therefore, those skilled in the art should recognize that various changes and modifications can be made to the embodiments described herein without departing from the scope and spirit of the present disclosure. Similarly, for the sake of clarity and brevity, descriptions of well-known functions and structures are omitted in the following description.
[0026] Embodiments of the present disclosure provide a method, apparatus, and system for managing cluster access permissions, automatically obtaining the access permission policy of a first cluster managed by a plurality of clusters, and obtaining access permission information between the first cluster and one or more second clusters included in the access permission policy. When it is monitored that a change occurs in the resources of the one or more second clusters, the access permission information included in the access permission policy is automatically updated, and the updated access permission information can be used to dynamically manage a plurality of clusters.
[0027] The method according to the embodiments of the present disclosure solves the problem that the flexibility of the current method for managing cluster access permissions is poor, and improves the real-time performance and efficiency of managing cluster access permissions.
[0028] As shown in FIG. 1, embodiments of the present disclosure provide a method for managing cluster access permissions, which may include the following steps.
[0029] Step S101: Obtaining the access permission policy of the first cluster, where the access permission policy includes access permission information between the first cluster and one or more second clusters related thereto.
[0030] Specifically, in one embodiment of the present disclosure, the method for managing cluster access permissions can be used for any one of a plurality of clusters to be managed.
[0031] Figure 2 shows clusters having a plurality of data exchanges such as Cluster 1, Cluster 2... Cluster N. As shown in Figure 2, regarding Cluster 1, when Cluster 1 has a relationship with Cluster 2, Cluster 3, and Cluster 4 (for example, data exchange, data synchronization, etc.), when the first cluster is Cluster 1, Cluster 2, Cluster 3, and Cluster 4 are a plurality of second clusters related to Cluster 1. Similarly, regarding Cluster 2, when Cluster 2 has a relationship with Cluster 1 and Cluster 4, when the first cluster is Cluster 2, Cluster 1 and Cluster 4 are a plurality of second clusters related to Cluster 2.
[0032] Furthermore, obtain the access permission policy of the first cluster. Among them, the access permission policy is a policy for the access permission of node resources exchange between multiple clusters. Taking the kubernetes cluster as an example, in one kubernetes cluster, each node pod has an independent IP address, and according to the business scenario, pods between multiple Kubernetes clusters can access each other to realize data exchange. Usually, during data exchange, for one cluster, in many cases, it is necessary to manage the access permissions of other clusters that are allowed (or prohibited) to access and / or are allowed (or prohibited) to be accessed, that is, it is necessary to set the access permission policy of the first cluster.
[0033] Furthermore, obtaining the access permission policy of the first cluster is obtaining the configuration information of the first cluster, and based on the configuration information, identifying the cluster information of one or more second clusters related to the first cluster, and Obtain pre-set access permission information between the first cluster and one or more of the second clusters, and generate the access permission policy of the first cluster based on the pre-set access permission information. including.
[0034] Among them, the cluster information of each second cluster related to the first cluster can be identified according to the configuration information of the first cluster obtained. For example, if the first cluster is kubernetes cluster 1, obtain the configuration file kubeconfig of kubernetes cluster 1 itself, and obtain the configuration files kubeconfig corresponding to a plurality of other clusters related to kubernetes cluster 1. For the first cluster, each second cluster related to the first cluster can be analyzed based on its own configuration file and the configuration files of other clusters. For example, if it is analyzed that kubernetes cluster 1 has communication connections and data exchanges with kubernetes cluster 2 and kubernetes cluster 3, it is identified that the second clusters related to the first cluster kubernetes cluster 1 include kubernetes cluster 2, kubernetes cluster 3, etc.
[0035] Furthermore, obtain pre-set access permission information between the first cluster and one or more of the second clusters, and generate the access permission policy of the first cluster based on the pre-set access permission information. Among them, the pre-set access permission information is obtained by analyzing from the configuration file set by the developer for the first cluster and / or obtained by analyzing from the custom permission data of the first cluster.
[0036] Specifically, the access permission information can include the access direction for accessing other clusters or being accessed by other clusters (Ingress and / or Egress), the IP address segments for which access is permitted (including one or more port numbers related to the IP address) or prohibited (including one or more port numbers related to the IP address) for the set access direction, the resource identifiers for which access is permitted (or prohibited) (such as namespace identifiers, node resource identifiers, etc.), the communication protocol used for access, node type, node role, node whitelist, etc.
[0037] The preconfigured configuration file may be a file containing various types of access permission information (such as a text file, a database file, etc.).
[0038] Furthermore, the custom permission data included in the first cluster is an extension based on the native permission data of the cluster. Taking the kubernetes cluster as an example, the custom permission data can be obtained by performing an extension based on the NetworkPolicy configuration native to the kubernetes cluster. For example, a custom permission data NewNpSpec of the CRD (CustomResourceDefinition) type is set, and NewNpSpec is obtained by extending the native permission data NpSpec. The specific information of the native permission data is set in v1.NetworkPolicy. For example, in v1.NetworkPolicy, it is possible to set which nodes corresponding to which IP + Port can be accessed by one or more pods in the Egress direction, or which nodes corresponding to which IP + Port can be accessed in the Ingress direction. Among them, an example of the data of NewNpSpec obtained by extending NpSpec is as follows.
[0039] type NewNpSpec struct { / / NewNpSpec represents custom permission data.
[0040] ClusterList []string `json:"clusterlist…"` / / ClusterList represents a list of multiple clusters, and the specific list data can be obtained from the data in JSON format.
[0041] NpSpec v1.NetworkPolicy `json:"npspec…"` / / NpSpec represents native permission data, and the specific permission data can be obtained from the data in JSON format.} That is, obtaining the pre-set access permission information between the first cluster and one or more of the second clusters includes: analyzing the pre-set access permission information from a pre-set configuration file, and / or analyzing the pre-set access permission information from custom permission data extended based on the native permission data of the clusters included in the first cluster.
[0042] Furthermore, based on the pre-set access permission information, generate the access permission policy for the first cluster. It can be understood that the access permission policy includes specific access permission information.
[0043] Step S102: When it is monitored that a change occurs in the resources of any one of the related second clusters, update the access permission information corresponding to the second cluster included in the access permission policy based on the change result of the resources of the second cluster.
[0044] Specifically, by using the controller (e.g., controller1) included in the first cluster, it is possible to monitor whether there are any changes in the resources of one or more second clusters related to the first cluster according to the set rules (e.g., the set time interval, business triggers, etc.). Among them, examples of resource changes include the addition of node resources, the update of node resources, the deletion of node resources, and the change of namespace resources. When it is determined that a change has occurred, based on the changed change result, the access permission information related to the change result is updated, that is, the access permission information corresponding to the second cluster included in the related access permission policy is updated. For example, if cluster 1 is monitoring that cluster 2 deletes node 1, and node 1 is a node whose access by cluster 1 is prohibited in the access permission information, the access permission information can be updated accordingly (e.g., deleting the access permission information for node 1). Taking the kubernetes cluster as an example, when resource changes in any one or more second clusters are monitored, the ipBlock fields (IP address segments included in the access permission information) in Ingress and Egress (access direction) of the NetworkPolicy related to the first cluster can be dynamically filtered and updated based on the access permission information defined in the custom permission data. Thus, the technical effect of updating the access permission information corresponding to the second cluster included in the access permission policy is achieved.
[0045] Furthermore, the first cluster monitors the resource change status of any one of the related second clusters and / or monitors its own resource change status, that is, the first cluster monitors the change status of each resource (such as namespace resources, node resources, etc.) contained in itself. Specifically, the controller (such as controller2) included in the first cluster can be used to monitor the resource change status related to the first cluster according to set rules (such as set time intervals, business triggers, etc.). When it is determined that a change has occurred, based on the changed change result, the access permission information related to the change result is updated, and the access permission between the first cluster and the related second cluster is managed using the updated access permission policy. That is, when it is monitored that a change has occurred in the resources of the first cluster, based on the change result of the resources of the first cluster, the access permission information corresponding to the first cluster included in the access permission policy is updated, and the access permission between the first cluster and the related second cluster is managed using the updated access permission policy.
[0046] More preferably, updating the access permission information corresponding to the second cluster included in the access permission policy includes adding an annotation containing the cluster identifier of the second cluster to the access permission information corresponding to the second cluster, indicating that a resource change has occurred in the second cluster through the cluster identifier included in the annotation, and when the first cluster accesses the second cluster, the access permission policy is combined with the annotation to limit the access permission of the first cluster to access the second cluster.
[0047] Specifically, when updating the access permission information corresponding to the second cluster included in the access permission policy for the first cluster, an annotation can be added so that the second cluster or the own cluster in which a resource change occurs is identified. Among them, for example, when the second cluster is cluster 2 and the cluster identifier is "cluster2", it is possible to add an annotation in key-value format for "cluster2". For example, the key is newnpfrom and the value is cluster2. Similarly, when it is necessary to update the access permission information included in the access permission policy for a resource change of the first cluster itself, it is possible to add an annotation in key-value format. For example, the key is newnpfrom and the value is the cluster identifier of the first cluster, for example, cluster1. By being combined with the annotation to which the access permission policy is added, it is possible to obtain a history record of updating the access permission policy of the first cluster due to a resource change occurring in any cluster among the first cluster and one or more second clusters related to the first cluster, and it can be understood that the accuracy and efficiency of managing the access permission policy are improved.
[0048] Step S103: Manage the access permissions between the first cluster and the second cluster related to the first cluster by using the updated access permission policy.
[0049] Specifically, the first cluster manages the access permissions between the first cluster and the second cluster related to the first cluster by using the access permission policy. For example, taking the kubernete cluster as an example, in v1.NetworkPolicy included in the access permission policy, it is possible to set which IP + Port corresponding nodes one or more pod nodes can access in the Egress direction (that is, the access permission), or which IP + Port corresponding nodes can be accessed in the Ingress direction (that is, the access permission).
[0050] Furthermore, to implement the management of access rights, the first cluster communicates with the business server apiserver included in the cluster through an access right policy and can access the corresponding data layer through a network plugin (such as calico, kube-router, cilium, etc.).
[0051] As shown in Figure 3, an embodiment of the present disclosure provides a method for managing cluster access rights, which may include the following steps.
[0052] Step S301: Initialize the permission controller corresponding to the cluster and obtain configuration information.
[0053] Specifically, the first cluster includes a permission controller. It can be understood that each of the multiple clusters managed in the embodiments applying the method of the present disclosure also includes a permission controller. That is, the first cluster includes a permission controller, and the steps of obtaining the access right policy of the first cluster and updating the access right policy are executed using the permission controller.
[0054] Furthermore, a permission controller npcontroller can be installed and deployed for each cluster. The permission controller npcontroller may be executed on any one of the node servers of the cluster to which it belongs, or may be executed on a server independent of each cluster.
[0055] It is preferable to be able to obtain the configuration information of the first cluster in the initialization stage by using the npcontroller. The configuration information includes, for example, the configuration file of the first cluster (for example, the kubeconfig file of the first cluster) and the configuration files of the second clusters (including one or more second clusters) of other managed clusters (for example, the kubeconfig files of the second clusters). In addition, the permission controller is also used for the interaction with the apiservers of multiple clusters.
[0056] Furthermore, when it is monitored that a change occurs in the resources of any one of the second clusters by using the permission controller npcontroller, execute the step of updating the access policy.
[0057] Step S302: Monitoring the resource change status of the first cluster by using the first controller.
[0058] Specifically, start the first controller and the second controller for the first cluster to which it belongs by using the permission controller.
[0059] Step S303: Monitoring the resource change status of one or more of the second clusters related to the first cluster by using the second controller.
[0060] That is, start the first controller and the second controller for the first cluster to which it belongs by using the permission controller, monitor the resource change status of the first cluster by using the first controller, and monitor the resource change status of one or more of the second clusters related to the first cluster by using the second controller.
[0061] Among them, the order of step S302 and step S303 is just an example. Regarding the operation order of step S302 and step S303, either one of the steps may be executed first, or they may be executed simultaneously.
[0062] Step S304: Based on the change result of the resources of the second cluster, update the access permission information corresponding to the second cluster included in the access permission policy.
[0063] That is, use the permission controller to obtain the access permission policy of the first cluster, and when the resource change of the second cluster is monitored, execute the step of updating the access permission policy.
[0064] The data layer uses a plug-in (for example, plug-ins such as calico, kube-router, cilium, etc.) to dynamically monitor the changes to the NetworkPolicy resources of this cluster (that is, the first cluster) by the npcontroller, and automatically issue corresponding data layer rules, so as to manage the cluster access permissions from the data level according to the data layer rules.
[0065] As shown in FIG. 4, the embodiment of the present disclosure A module for obtaining the access permission policy of the first cluster, the policy acquisition module 401 in which the access permission policy includes access permission information between the first cluster and one or more second clusters related thereto, When it is monitored that a change occurs in the resources of any one of the related second clusters, based on the change result of the resources of the second cluster, a permission change module 402 for updating the access permission information corresponding to the second cluster included in the access permission policy, A permission management module 403 for managing the access permissions between the first cluster and the related second clusters by using the updated access permission policy, An apparatus 400 for managing cluster access permissions including is provided.
[0066] In an embodiment of the present disclosure, when it is monitored that a change occurs in the resources of the first cluster, the permission change module 402 updates the access permission information corresponding to the first cluster included in the access permission policy based on the change result of the resources of the first cluster, and the permission management module 403 manages the access permissions between the first cluster and the second cluster related to the first cluster by using the updated access permission policy.
[0067] As shown in FIG. 5, an embodiment of the present disclosure includes a plurality of communicatively connected clusters, among which one or more of the clusters are provided with a device 400 for managing cluster access permissions. A system 500 for managing cluster access permissions is provided.
[0068] Among them, the permission change module 402 included in the device 400 for managing cluster access permissions is used to update the access permission information corresponding to the second cluster included in the access permission policy based on the change result of the resources of the second cluster when it is monitored that a change occurs in the resources of any one of the related second clusters, or to update the access permission information corresponding to the first cluster included in the access permission policy based on the change result of the resources of the first cluster when it is monitored that a change occurs in the resources of the first cluster.
[0069] An embodiment of the present disclosure further includes one or more processors and a storage device for storing one or more programs, and When the one or more programs are executed by the one or more processors, an electronic device that manages cluster access rights, which causes the one or more processors to implement the method provided in any one of the above embodiments is provided.
[0070] Embodiments of the present disclosure further provide a computer-readable medium storing a computer program that, when executed by a processor, implements the method provided in any one of the above embodiments is provided.
[0071] FIG. 6 shows an exemplary system architecture 600 to which a method for managing cluster access rights or an apparatus for managing cluster access rights according to an embodiment of the present disclosure can be applied.
[0072] As shown in FIG. 6, the system architecture 600 can include terminal devices 601, 602, 603, a network 604, and a server 605. The network 604 is a medium for providing a communication link between the terminal devices 601, 602, 603 and the server 605. The network 604 can include various connection types such as wired, wireless communication links, or optical fiber cables.
[0073] A user can use the terminal devices 601, 602, 603 to communicate with the server 605 via the network 604 to send and receive messages and the like. Various client applications such as, for example, an email client application, a web browser application, a search application, an instant messaging tool, and an email client can be installed on the terminal devices 601, 602, 603.
[0074] The terminal devices 601, 602, and 603 may be various electronic devices equipped with a display screen and supporting various client applications, including, but not limited to, smartphones, tablet computers, laptop computers, and desktop computers.
[0075] The server 605 may be a server that provides various services, such as a background management server that provides support for client applications used by users using the terminal devices 601, 602, and 603.
[0076] The cluster can include one or more servers 605. The background management server can process the received business requests and feedback the business data to the terminal devices.
[0077] Note that the method for managing cluster access rights provided by the embodiments of the present disclosure is generally executed by the server 605, and correspondingly, the device for managing cluster access rights is generally provided within the server 605.
[0078] It should be understood that the numbers of terminal devices, networks, and servers in FIG. 6 are merely schematic, and any number of terminal devices, networks, and servers may be provided as required for implementation.
[0079] Refer to FIG. 7, which shows a schematic diagram of the structure of a computer system 700 of a terminal device suitable for implementing the embodiments of the present disclosure. The terminal device shown in FIG. 7 is merely an example and should not impose any limitations on the functions and usage scope of the embodiments of the present disclosure.
[0080] As shown in FIG. 7, the computer system 700 includes a central processing unit (CPU) 701 capable of executing various appropriate operations and processes based on a program stored in a read-only memory (ROM) 702 or a program loaded from a storage section 708 into a random access memory (RAM) 703.
[0081] The RAM 703 further stores various programs and data necessary for the operation of the computer system 700. The CPU 701, ROM 702, and RAM 703 are connected to each other via a bus 704. An input / output (I / O) interface 705 is also connected to the bus 704.
[0082] The following components are connected to the I / O interface 705: An input portion 706 including a keyboard, a mouse, and the like; An output portion 707 including a cathode ray tube (CRT), a liquid crystal display (LCD), and the like, and a speaker; A storage portion 708 including a hard disk and the like; A communication portion 709 including a network interface card such as a LAN card and a modem.
[0083] The communication portion 709 executes communication processing via a network such as the Internet. A driver 710 is also connected to the I / O interface 705 as necessary. Removable media 711 such as a magnetic disk, an optical disk, a magneto-optical disk, and a semiconductor memory are installed in the driver 710 as necessary so that a computer program read therefrom can be easily installed in the storage portion 708 as necessary.
[0084] In particular, according to an embodiment of the present disclosure, the process described above with reference to the flowchart can be implemented as a computer software program.
[0085] For example, an embodiment of the present disclosure includes a computer program product including a computer program stored in a computer-readable medium and including program code for executing the method shown in the flowchart. includes.
[0086] In such an embodiment, the computer program may be downloaded and installed from a network via the communication portion 709 and / or installed from the removable medium 711. When the computer program is executed by the central processing unit (CPU) 701, it executes the above-described functions limited to the system of the present disclosure.
[0087] Note that the computer-readable medium shown in the present disclosure may be a computer-readable signal medium or a computer-readable storage medium, or any combination of the above two.
[0088] The computer-readable storage medium may be, for example, an electrical, magnetic, optical, electromagnetic, infrared, or semiconductor system, apparatus, or device, or any combination thereof, but is not limited thereto.
[0089] More specific examples of the computer-readable storage medium may include, but are not limited to, an electrical connection having one or more conductors, a portable computer magnetic disk, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or flash memory), an optical fiber, a portable compact magnetic disk read-only memory (CD-ROM), an optical storage device, a magnetic storage device, or any suitable combination thereof.
[0090] In the present disclosure, the computer-readable storage medium may be any tangible medium that includes or stores a program that can be used by or in combination with a command execution system, apparatus, or device.
[0091] Also, in the present disclosure, a computer-readable signal medium can include a data signal that propagates in a baseband or as part of a carrier wave, in which computer-readable program code is stored. The data signal propagated in this way can adopt various forms, including, but not limited to, electromagnetic signals, optical signals, or any suitable combination thereof.
[0092] The computer-readable signal medium may further be any computer-readable medium other than a computer-readable storage medium, and the computer-readable medium can transmit, propagate, or transmit a program for use by or in combination with a command execution system, apparatus, or device.
[0093] The program code included in the computer-readable medium may be transmitted via any suitable medium, including, but not limited to, wireless, wire, optical cable, RF, etc., or any suitable combination thereof.
[0094] Flowcharts and block diagrams in the drawings illustrate the possible architectures, functions, and operations of systems, methods, and computer program products according to various embodiments of the present disclosure. In this regard, each block in a flowchart or block diagram can represent a module, a program section, or a portion of code, and the above-mentioned module, program section, or portion of code includes one or more executable commands for implementing a given logical function. It should also be noted that in some alternative implementations, the functions noted in the blocks may occur in an order different from that noted in the drawings. For example, two consecutively displayed blocks may actually be executed substantially in parallel, or in some cases, in the reverse order. This is determined by the relevant functions. Also, it should be noted that each block in the block diagram or flowchart, and combinations of blocks in the block diagram or flowchart, may be implemented by a dedicated hardware-based system for performing a given function or operation, or may be implemented by a combination of dedicated hardware and computer commands.
[0095] The related modules and / or units described in the embodiments of the present disclosure may be implemented in software or in hardware. The described modules and / or units may be provided within a processor. For example, it may be described as "a processor including a policy acquisition module, a privilege change module, and a privilege management module". Among them, the names of these modules may not be a limitation to the module itself in some cases. For example, the policy acquisition module may further be described as "a module for acquiring the access privilege policy of the first cluster".
[0096] In another aspect, the present disclosure further provides a computer-readable medium, and the computer-readable medium may be included in the device described in the above embodiments, may not be assembled in the device, and may exist alone.
[0097] The computer-readable medium stores one or more programs, and when the one or more programs are executed on a device, the device is caused to obtain an access permission policy for a first cluster, the access permission policy including access permission information between the first cluster and one or more second clusters associated therewith, when a change occurs in a resource of any one of the associated second clusters, update the access permission information corresponding to the second cluster included in the access permission policy based on the change result of the resource of the second cluster, manage the access permission between the first cluster and the associated second clusters using the updated access permission policy, be included.
[0098] Embodiments of the present disclosure automatically obtain an access permission policy for a first cluster managed by a plurality of clusters, obtain access permission information between the first cluster and one or more second clusters associated therewith included in the access permission policy, and when a change occurs in a resource of the one or more second clusters, automatically update the access permission information included in the access permission policy, and can dynamically manage a plurality of clusters using the updated access permission information.
[0099] By the method of the embodiments of the present disclosure, the problem that the flexibility of the current method for managing cluster access permissions is poor is solved, and the real-time performance and efficiency of managing cluster access permissions are improved. The forms for implementing the above invention do not limit the protection scope of the present disclosure. It is obvious to those skilled in the art that various modifications, combinations, sub-combinations, and alternatives may occur according to design requirements and other factors. Any modifications, equivalent replacements, improvements, etc. made within the scope of the idea and principle of the present disclosure shall be included within the protection scope of the present disclosure.
Claims
1. Obtaining the access permission policy of the first cluster, wherein the access permission policy includes access permission information between the first cluster and one or more second clusters associated therewith; When it is monitored that a change occurs in the resources of any one of the associated second clusters, based on the change result of the resources of the second cluster, updating the access permission information corresponding to the second cluster included in the access permission policy; Managing the access permission between the first cluster and the second cluster associated therewith by using the updated access permission policy; including A method for managing cluster access permissions.
2. When it is monitored that a change occurs in the resources of the first cluster, based on the change result of the resources of the first cluster, updating the access permission information corresponding to the first cluster included in the access permission policy; Managing the access permission between the first cluster and the second cluster associated therewith by using the updated access permission policy; further including The method according to claim 1.
3. Updating the access permission information corresponding to the second cluster included in the access permission policy is to add an annotation including the cluster identifier of the second cluster to the access permission information corresponding to the second cluster, and indicate that a resource change occurs in the second cluster through the cluster identifier included in the annotation. When the first cluster accesses the second cluster, the access permission policy is combined with the annotation to limit the access permission for the first cluster to access the second cluster including The method according to claim 1.
4. Obtaining the access permission policy of the first cluster is to obtain the configuration information of the first cluster, and based on the configuration information, identify the cluster information of one or more second clusters associated with the first cluster; Obtaining the preset access permission information between the first cluster and one or more of the second clusters, and generating the access permission policy of the first cluster based on the preset access permission information; including The method according to claim 1.
5. Obtaining the pre-set access permission information between the first cluster and one or more of the second clusters includes analyzing the pre-set access permission information from a pre-set configuration file, and / or analyzing the pre-set access permission information from custom permission data extended based on the native permission data of the cluster included in the first cluster, The method according to claim 4.
6. The first cluster includes a permission controller, further including steps of obtaining the access permission policy of the first cluster by using the permission controller and updating the access permission policy, The method according to claim 1.
7. using the permission controller to start a first controller and a second controller for the first cluster to which it belongs, monitoring the resource change status of the first cluster by using the first controller, and monitoring the resource change status of one or more of the second clusters related to the first cluster by using the second controller, further including The method according to claim 6.
8. A module for obtaining an access permission policy of a first cluster, the access permission policy including a policy acquisition module for access permission information between the first cluster and one or more second clusters related thereto, a permission change module for updating the access permission information corresponding to the second cluster included in the access permission policy based on the change result of the resources of the second cluster when it is monitored that a change occurs in the resources of any one of the related second clusters, a permission management module for managing the access permission between the first cluster and the second cluster related thereto by using the updated access permission policy, including An apparatus for managing cluster access permissions.
9. When it is monitored by the permission change module that a change occurs in the resources of the first cluster, updating the access permission information corresponding to the first cluster included in the access permission policy based on the change result of the resources of the first cluster, The permission management module manages access permissions between the second cluster associated with the first cluster by using the updated access permission policy. Further comprising The apparatus according to claim 8. **Claim 10** A system for managing cluster access permissions, comprising a plurality of communicatively connected clusters, A system, wherein one or more of the clusters are provided with the apparatus for managing cluster access permissions according to claim 8 or the apparatus for managing cluster access permissions according to claim 9. **Claim 11** One or more processors, A storage device for storing one or more programs, Comprising When the one or more programs are executed by the one or more processors, the one or more processors implement the method according to any one of claims 1 to 7 An electronic device. **Claim 12** A computer-readable medium storing a computer program that, when executed by a processor, implements the method according to any one of claims 1 to 7.
Citation Information
Patent Citations
Multi-entity Resource, Security, and Service Management in Edge Computing Deployments
JP2022530580A
Fine grained network security
US20210185093A1