Storage node cluster access method and cloud management platform
Through the collaborative work of the cloud management platform and proxy nodes, the data security problem when multiple applications share storage pools in the cloud service system is solved, and an efficient and secure storage node cluster access method is realized.
Patent Information
- Application Number
- PCT/CN2024/133098
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- Priority Date
- 2024-01-23
- Filing Date
- 2024-11-20
- Publication Date
- 2025-05-30
AI Technical Summary
In a cloud service system based on a separate storage and computing architecture, cloud vendors need to build an exclusive storage pool for each application, resulting in high hardware costs, huge storage scale and low processing efficiency; at the same time, sharing storage pools for multiple applications may lead to data security problems.
Through the cloud management platform, a binding relationship between the application, computing node and storage space is created, and the binding relationship is deployed in the proxy node. The proxy node creates a dedicated storage space in the storage node cluster and performs security detection of access requests to ensure data security.
While multiple applications share the same storage pool, it ensures data security between each application, reduces hardware costs and improves processing efficiency.
Smart Images

Figure CN2024133098_30052025_PF_FP_ABST
Abstract
Description
A storage node cluster access method and cloud management platform
[0001] This application claims priority to the Chinese patent application filed with the State Intellectual Property Office on November 24, 2023, with application number 202311585043.6 and application name “A method, device and other equipment for data processing”, and claims priority to the Chinese patent application filed with the State Intellectual Property Office on January 23, 2024, with application number 202410095068.6 and application name “A storage node cluster access method and cloud management platform”, the entire contents of which are incorporated by reference into this application. Technical Field
[0002] The embodiments of the present application relate to the field of cloud technology, and in particular to a storage node cluster access method based on a cloud management platform and a cloud management platform. Background Art
[0003] With the rapid development of cloud technology, cloud providers are offering cloud service systems based on a storage-computing separation architecture. In this architecture, tenant applications run in a compute pool, while the data they require is stored in a storage pool. While the compute and storage pools are physically isolated, they are connected for communication. Therefore, when applications in the compute pool need to process data, they can access data from the storage pool to fulfill their business needs.
[0004] Currently, in cloud service systems built on a storage-computing separation architecture, cloud vendors need to build dedicated storage pools for each application within the same tenant or across different tenants to provide secure and stable storage services. However, this approach incurs extremely high hardware costs and results in excessively large storage capacity, leading to inefficient data processing.
[0005] Based on this, cloud vendors try to have multiple applications share a storage pool. However, this approach may cause one application to mistakenly access the data of other applications when accessing the storage pool, leading to a series of data security issues. Summary of the Invention
[0006] The embodiments of the present application provide a storage node cluster access method and a cloud management platform based on a cloud management platform, which not only allows multiple applications to share the same storage pool, but also ensures data security between various applications.
[0007] A first aspect of an embodiment of the present application provides a method for accessing a storage node cluster based on a cloud management platform. The cloud management platform used to implement the method can manage infrastructure that provides cloud services. The infrastructure can include computing nodes purchased by tenants, proxy nodes located between the computing nodes and the storage node cluster, and the storage node cluster that can provide storage space. The method includes:
[0008] When a tenant needs to bind the tenant's application and the computing node designated by the tenant for running the application, the cloud management platform can provide the tenant with a binding interface, so the tenant can send the application's identifier and the computing node's identifier to the binding interface, so that the cloud management platform receives the application's identifier and the computing node's identifier through the binding interface.
[0009] After obtaining the identifier of the application and the identifier of the computing node, the cloud management platform can generate an identifier for the storage space serving the application (the storage space can be used to store the data of the application), create a binding relationship between the identifier of the application, the identifier of the computing node and the identifier of the storage space, and deploy the application on the computing node so that the computing node runs the application.
[0010] After obtaining the binding relationship, the cloud management platform can deploy the binding relationship on the proxy node. When the application has data processing requirements, the computing node running the application can send an access request to the proxy node. After receiving the access request from the computing node, the proxy node can detect the information contained in the access request based on the binding relationship. If the access request contains the identifier of the computing node and the identifier of the storage space, it means that the information contained in the access request complies with the binding relationship. The proxy node then creates the storage space in the storage node cluster or completes data processing in the storage space to meet the data processing requirements of the application.
[0011] From the above method, it can be seen that: at the request of a tenant, the cloud management platform can create a binding relationship between the identifier of the tenant's application, the identifier of the computing node running the application, and the identifier of the storage space serving the application, and deploy this binding relationship in the proxy node. When the computing node running the application sends an access request to the proxy node, the proxy node can perform a security check on the access request based on the binding relationship. If the access request passes the security check, it means that the information carried by the access request complies with the binding relationship. Therefore, the proxy node can replace the computing node running the application to create a storage space serving the application in the storage node cluster (i.e., storage pool) or access the storage space to complete data processing, thereby meeting the data processing needs of the application. Thus, the cloud management platform can use the binding relationship between the application, computing node, and storage space to instruct the proxy node to create a storage space specifically serving the tenant's application in the storage pool. When the computing node running the application needs to access the storage space, the proxy node can perform a security check on it. Only after the security check passes will the proxy node access the storage space on behalf of the computing node to complete data processing. In this way, even if there are multiple applications, the proxy node can create a dedicated storage space for each application in the storage pool, so that multiple applications can share the same storage pool. When the computing nodes running each application need to access the corresponding storage space, the proxy node can perform security checks on them in real time. Only after passing the security check will they be allowed to access the corresponding storage space, thus ensuring the data security between various applications.
[0012] In one possible implementation, the storage space identifier includes the storage space's namespace. In the aforementioned implementation, the application identifier can be used to represent the application, such as the application's universally unique identifier. Similarly, the compute node identifier can be used to represent the application, such as the compute node's universally unique identifier. Similarly, the storage space identifier can be used as metadata for the storage space, such as the storage space's namespace.
[0013] In one possible implementation, the method further includes: the cloud management platform receives an identification creation request for the application from the tenant through a creation interface; the cloud management platform creates an identification for the application based on the identification creation request, and provides the identification of the application to the tenant through the creation interface. In the aforementioned implementation, when the tenant needs to create an identification for the application, the cloud management platform can provide the tenant with a creation interface, so the tenant can send an identification creation request for the application to the creation interface, so that the cloud management platform receives the identification creation request for the application through the creation interface. After receiving the identification creation request for the application, the cloud management platform can create an identification representing the application in accordance with the instructions of the identification creation request, and return the identification of the application to the tenant's client through the creation interface for subsequent use by the tenant.
[0014] In one possible implementation, the storage node cluster includes multiple storage nodes and a management node that manages multiple storage nodes, and the cloud management platform deploys the binding relationship in the proxy node, including: the cloud management platform sends the binding relationship to the management node, so that the binding relationship is deployed in the proxy node through the management node. In the aforementioned implementation, the storage node cluster includes multiple storage nodes and a management node that manages multiple storage nodes, and the three ends of the management node are respectively communicated with the cloud management platform, the proxy node, and the multiple storage nodes. Based on this, after obtaining the binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space, the cloud management platform can directly send the binding relationship to the management node. After obtaining the binding relationship, the management node can store the binding relationship and send the binding relationship to the proxy node, so that the proxy node stores the binding relationship. In this way, with the cooperation of the management node, the cloud management platform successfully deploys the binding relationship in the proxy node.
[0015] In one possible implementation, the method further includes: the cloud management platform notifies the tenant through a binding interface that the application has been bound to the computing node. In the aforementioned implementation, after the management node sends the binding relationship to the proxy node, it can notify the cloud management platform that the binding relationship has been successfully processed. In other words, the cloud management platform, the proxy node, the management node, and the computing node have all successfully obtained the binding relationship, which is equivalent to synchronizing the binding of the application, the computing node, and the storage space. Therefore, the cloud management platform can show the tenant through the binding interface that the application has been bound to the computing node (the tenant side does not need to perceive the storage space), which is equivalent to notifying the tenant that the application has been successfully bound to the computing node.
[0016] In one possible implementation, the binding relationship is also used to instruct the proxy node to detect the initialization request from the computing node, and if the initialization request contains the identifier of the application and the identifier of the computing node, the identifier of the storage space is sent to the computing node. In the aforementioned implementation, when the application needs to complete initialization, the computing node running the application can send the initialization request generated by the application to the proxy node. After receiving the initialization request from the computing node, the proxy node can detect the information contained in the initialization request based on the binding relationship to determine whether the access request contains both the identifier of the application and the identifier of the computing node. If the initialization request contains the identifier of the application and the identifier of the computing node, it means that the information contained in the initialization request is consistent with the binding relationship. The proxy node then finds the identifier of the storage space serving the application from the binding relationship and sends it to the computing node, so that the application stores the identifier of the storage space and successfully completes the initialization.
[0017] In one possible implementation, a proxy node creates a storage space in a storage node cluster or processes data in the storage space, including: the proxy node sending an access request to a management node, the access request instructing the management node to check the access request, and if the access request includes a storage space identifier, creating the storage space in any one of the multiple storage nodes; or the proxy node sending an access request to a storage node, the access request instructing the storage node to check the access request, and if the access request includes a storage space identifier, processing the data in the storage space. In the aforementioned implementation, after receiving an access request from a computing node running the application, the proxy node may perform a security check on the access request. If the security check passes, the proxy node may perform different operations based on the type of access request. If the access request is a request to create the storage space, the proxy node may send the access request to the management node for the management node to check the access request. If the access request includes the storage space identifier, indicating that the information contained in the access request is valid, the management node selects a storage node from the multiple storage nodes and creates the storage space in the storage node. The storage space identifier may serve as metadata for the storage space. If the access request is a data processing request for the storage space, the proxy node can send the access request to the storage node so that the storage node can detect the access request. If the access request contains the identifier of the storage space, it means that the access request is legal. Therefore, the storage node can find the storage space based on the identifier of the storage space and process the data in the storage space, thereby meeting the data processing requirements of the application.
[0018] In one possible implementation, a cluster of storage nodes is located in the same site, where a site can be any of the following: a cabinet, a computer room, a data center, a region, or an availability zone.
[0019] In one possible implementation, a compute node includes any of the following: a physical server, a bare metal server, a virtual machine, and a container.
[0020] The second aspect of an embodiment of the present application provides a storage node cluster access method based on a proxy node, wherein the proxy node is set in an infrastructure that provides cloud services, the infrastructure is managed by a cloud management platform, and the infrastructure also includes computing nodes and a storage node cluster. The method includes: the proxy node receives a binding relationship between an application identifier, a computing node identifier, and a storage space identifier from the cloud management platform, the application identifier and the computing node identifier are obtained from the tenant by the cloud management platform, the computing node runs an application, the storage space identifier is generated by the cloud management platform, and the storage space is used to store application data; the proxy node receives an access request from the computing node, and detects the access request based on the binding relationship. If the access request contains the computing node identifier and the storage space identifier, a storage space is created in the storage node cluster or data is processed in the storage space.
[0021] In a possible implementation, the identifier of the storage space includes a namespace of the storage space.
[0022] In one possible implementation, a storage node cluster includes multiple storage nodes and a management node that manages the multiple storage nodes. The binding relationship between the application identifier, the computing node identifier, and the storage space identifier received by the proxy node from the cloud management platform includes: the proxy node directly receives the binding relationship between the application identifier, the computing node identifier, and the storage space identifier received from the management node, and the binding relationship is obtained by the management node from the cloud management platform.
[0023] In one possible implementation, the method further includes: the proxy node detecting an initialization request from the computing node, and if the initialization request includes an identifier of the application and an identifier of the computing node, sending the identifier of the storage space to the computing node.
[0024] In one possible implementation, the proxy node detects access requests based on a binding relationship. If the access request contains the identifier of the computing node and the identifier of the storage space, creating a storage space in the storage node cluster or processing data in the storage space includes: sending the access request to the management node, the access request is used to instruct the management node to detect the access request. If the access request contains the identifier of the storage space, the storage space is created in any one of the multiple storage nodes; or, sending the access request to the storage node, the access request is used to instruct the storage node to detect the access request. If the access request contains the identifier of the storage space, the data is processed in the storage space.
[0025] In one possible implementation, a cluster of storage nodes is located in the same site, where a site can be any of the following: a cabinet, a computer room, a data center, a region, or an availability zone.
[0026] In one possible implementation, a compute node includes any of the following: a physical server, a bare metal server, a virtual machine, and a container.
[0027] A third aspect of an embodiment of the present application provides a cloud management platform, which is used to manage the infrastructure for providing cloud services. The infrastructure includes computing nodes, proxy nodes, and a storage node cluster. The cloud management platform includes: a first receiving module, which is used to receive the identifier of an application and the identifier of a computing node from a tenant through a binding interface; a first creation module, which is used to create a binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space, and deploy the application in the computing node, where the storage space is used to store the data of the application; a deployment module, which is used to deploy the binding relationship in the proxy node, where the binding relationship is used to instruct the proxy node to detect access requests from the computing node, and if the access request contains the identifier of the computing node and the identifier of the storage space, create a storage space in the storage node cluster or process data in the storage space.
[0028] In a possible implementation, the identifier of the storage space includes a namespace of the storage space.
[0029] In one possible implementation, the cloud management platform also includes: a second receiving module, used to receive an identification creation request for an application from a tenant through a creation interface; a second creation module, used to create an identification of the application based on the identification creation request, and provide the identification of the application to the tenant through the creation interface.
[0030] In one possible implementation, the cloud management platform further includes: a notification module, configured to notify tenants through a binding interface that an application has been bound to a computing node.
[0031] In one possible implementation, the storage node cluster includes multiple storage nodes and a management node that manages the multiple storage nodes. The deployment module is used to send the binding relationship to the management node so that the binding relationship is deployed in the proxy node through the management node.
[0032] In one possible implementation, the binding relationship is also used to instruct the proxy node to detect the initialization request from the computing node, and if the initialization request includes the application identifier and the computing node identifier, send the storage space identifier to the computing node.
[0033] In one possible implementation, the proxy node creates a storage space in a storage node cluster or processes data in the storage space, including: the proxy node sends an access request to the management node, where the access request is used to instruct the management node to detect the access request; if the access request includes an identifier of the storage space, the storage space is created in any one of the multiple storage nodes; or, the proxy node sends an access request to the storage node, where the access request is used to instruct the storage node to detect the access request; if the access request includes an identifier of the storage space, the data is processed in the storage space.
[0034] In one possible implementation, a cluster of storage nodes is located in the same site, where a site can be any of the following: a cabinet, a computer room, a data center, a region, or an availability zone.
[0035] In one possible implementation, a compute node includes any of the following: a physical server, a bare metal server, a virtual machine, and a container.
[0036] The fourth aspect of an embodiment of the present application provides a proxy node, which is set in an infrastructure that provides cloud services. The infrastructure is managed by a cloud management platform. The infrastructure also includes computing nodes and a storage node cluster. The proxy node includes: a receiving module for receiving a binding relationship between an application identifier, a computing node identifier, and a storage space identifier from the cloud management platform. The application identifier and the computing node identifier are obtained from a tenant by the cloud management platform. The computing node runs an application. The storage space identifier is generated by the cloud management platform. The storage space is used to store application data; a processing module for receiving an access request from the computing node and detecting the access request based on the binding relationship. If the access request contains the computing node identifier and the storage space identifier, a storage space is created in the storage node cluster or data is processed in the storage space.
[0037] In a possible implementation, the identifier of the storage space includes a namespace of the storage space.
[0038] In one possible implementation, the storage node cluster includes multiple storage nodes and a management node that manages the multiple storage nodes. The receiving module is also used to directly receive the binding relationship between the application identifier, the computing node identifier, and the storage space identifier from the management node. The binding relationship is obtained by the management node from the cloud management platform.
[0039] In one possible implementation, the proxy node further includes: a feedback module configured to detect an initialization request from the computing node, and send the storage space identifier to the computing node if the initialization request includes an application identifier and a computing node identifier.
[0040] In one possible implementation, the processing module is used to: send an access request to a management node, where the access request is used to instruct the management node to detect the access request; if the access request includes an identifier of a storage space, then create a storage space in any one of multiple storage nodes; or send an access request to a storage node, where the access request is used to instruct the storage node to detect the access request; if the access request includes an identifier of a storage space, then process data in the storage space.
[0041] In one possible implementation, a cluster of storage nodes is located in the same site, where a site can be any of the following: a cabinet, a computer room, a data center, a region, or an availability zone.
[0042] In one possible implementation, a compute node includes any of the following: a physical server, a bare metal server, a virtual machine, and a container.
[0043] A fifth aspect of an embodiment of the present application provides a computing device cluster, which includes at least one computing device, each computing device including a processor and a memory: the memory is used to store instructions; the processor is used to enable the computing device cluster to execute the method described in the first aspect, any possible implementation method of the first aspect, the second aspect, or any possible implementation method of the second aspect according to the instructions.
[0044] A sixth aspect of an embodiment of the present application provides a computer storage medium, which stores one or more instructions. When the instructions are executed by one or more computers, the one or more computers implement the method described in the first aspect, any possible implementation method of the first aspect, the second aspect, or any possible implementation method of the second aspect.
[0045] A seventh aspect of the embodiments of the present application provides a computer program product, which stores instructions. When the instructions are executed by a computer, the computer implements the method described in the first aspect, any possible implementation method of the first aspect, the second aspect, or any possible implementation method of the second aspect.
[0046] In an embodiment of the present application, when a tenant needs to bind the tenant's application and the tenant's computing node together, the tenant can input the application's identifier and the computing node's identifier into the binding interface provided by the cloud management platform. Then, the cloud management platform can determine the information of the storage space serving the application (used to store the application's data) to create a binding relationship between the application's identifier, the computing node's identifier, and the storage space's identifier, and instruct the computing node to run the application. Then, the cloud management platform can deploy the binding relationship in the proxy node. Since the proxy node is located between the computing node and the storage node cluster, when the proxy node receives an access request from the computing node, the proxy node can detect the access request based on the binding relationship. If the access request contains the mutually bound identifiers of the computing node and the storage space, the proxy node creates a storage space in the storage node cluster or completes processing data in the storage space. In the aforementioned process, the cloud management platform can, at the tenant's request, create a binding relationship between the identifier of the tenant's application, the identifier of the computing node running the application, and the identifier of the storage space serving the application, and deploy the binding relationship in the proxy node. When the computing node running the application sends an access request to the proxy node, the proxy node can perform a security check on the access request based on the binding relationship. If the access request passes the security check, it means that the information carried by the access request is in compliance with the binding relationship. Therefore, the proxy node can replace the computing node running the application to create a storage space in the storage node cluster (i.e., storage pool) that serves the application or access the storage space to complete data processing, thereby meeting the data processing needs of the application. It can be seen from this that the cloud management platform can use the binding relationship between the application, computing node, and storage space to instruct the proxy node to create a storage space in the storage pool that specifically serves the tenant's application. When the computing node running the application needs to access the storage space, the proxy node can perform a security check on it. After passing the security check, the proxy node will access the storage space on behalf of the computing node to complete data processing. In this way, even if there are multiple applications, the proxy node can create a dedicated storage space for each application in the storage pool, so that multiple applications can share the same storage pool. When the computing nodes running each application need to access the corresponding storage space, the proxy node can perform security checks on them in real time. Only after passing the security check will they be allowed to access the corresponding storage space, thus ensuring the data security between various applications. BRIEF DESCRIPTION OF THE DRAWINGS
[0047] FIG1 is a schematic diagram of the structure of a cloud service system provided in an embodiment of the present application;
[0048] FIG2 is a flow chart of a method for accessing a storage node cluster based on a cloud management platform according to an embodiment of the present application;
[0049] FIG3 is a schematic diagram of application information acquisition provided by an embodiment of the present application;
[0050] FIG4 is a schematic diagram of binding an application to a virtual machine according to an embodiment of the present application;
[0051] FIG5 is a schematic diagram of a virtual machine accessing a storage pool according to an embodiment of the present application;
[0052] FIG6 is a schematic diagram of the structure of a cloud management platform provided in an embodiment of the present application;
[0053] FIG7 is a schematic diagram of the structure of a proxy node provided in an embodiment of the present application;
[0054] FIG8 is a schematic diagram of a structure of a computing device provided in an embodiment of the present application;
[0055] FIG9 is a schematic diagram of a structure of a computing device cluster provided in an embodiment of the present application;
[0056] FIG10 is a schematic diagram of computer devices in a computer cluster provided by an embodiment of the present application being connected via a network. DETAILED DESCRIPTION
[0057] The embodiments of the present application provide a storage node cluster access method and a cloud management platform based on a cloud management platform, which not only allows multiple applications to share the same storage pool, but also ensures data security between various applications.
[0058] The terms "first", "second", etc. in the specification and claims of the present application and the above-mentioned drawings are used to distinguish similar objects, and are not necessarily used to describe a specific order or sequential order. It should be understood that the terms used in this way can be interchangeable under appropriate circumstances, and this is merely a way of distinguishing the objects of the same attributes when describing them in the embodiments of the present application. In addition, the terms "including" and "having" and any of their variations are intended to cover non-exclusive inclusions, so that the process, method, system, product or equipment comprising a series of units need not be limited to those units, but may include other units that are not clearly listed or inherent to these processes, methods, products or equipment.
[0059] With the rapid development of cloud technology, cloud providers are offering cloud service systems based on a storage-computing separation architecture. In this architecture, tenant applications run in a compute pool, while the data they require is stored in a storage pool. While the compute and storage pools are physically isolated, they are connected for communication. Therefore, when applications in the compute pool need to process data, they can access data from the storage pool to fulfill their business needs.
[0060] Currently, in cloud service systems built on a storage-computing separation architecture, cloud vendors need to build dedicated storage pools for each application, either for the same tenant or for different tenants, to provide secure and stable storage services for each application. However, since an application typically requires multiple compute nodes, the storage pools set up for it typically also contain multiple storage nodes. As the number of applications increases, the number of storage pools also increases. This not only leads to extremely high hardware costs for building cloud service systems, but also makes the storage scale too large, resulting in inefficient data processing.
[0061] Based on this, cloud vendors have attempted to enable multiple applications to share a single storage pool. However, this approach can cause one application to mistakenly access data from other applications when accessing the storage pool, leading to a series of data security issues. Therefore, ensuring data security among multiple applications sharing the same storage pool has become a pressing issue.
[0062] To address the above issues, the present invention provides a method for accessing a storage node cluster based on a cloud management platform. This method can be implemented through a cloud service system. FIG1 is a schematic diagram of the structure of the cloud service system provided by the present invention. As shown in FIG1 , the cloud service system includes an infrastructure that can provide cloud services and a cloud management platform that manages the infrastructure. The cloud management platform and the infrastructure are introduced separately below:
[0063] The cloud management platform can coordinate and manage the infrastructure of the entire cloud service system (for example, selecting specific computing nodes for tenants from the computing node cluster contained in the infrastructure, or binding the tenant's applications to the tenant's computing nodes so that these computing nodes run the tenant's applications, or allocating exclusive storage space to the tenant's computing nodes in the storage node cluster to store the tenant's application data, etc.), and can also be open to tenants outside the cloud service system and respond to their requests. For example, the cloud management platform can provide various interfaces such as login interface, creation interface, purchase interface, and binding interface for access by tenant clients (for example, terminal devices used by tenants or browsers on terminal devices, etc.). Among them, the cloud management platform can authenticate the tenant's client through the login interface, and after successful authentication, the tenant's client can be allowed to log in to the cloud management platform. For example, the cloud management platform can also allow the tenant's client to send the tenant's cloud resource purchase request to the cloud management platform through the purchase interface. Based on the cloud resource purchase request, the cloud management platform can select exclusive computing nodes for the tenant in the computing node cluster of the infrastructure and provide the tenant with the identifiers of these computing nodes to provide cloud services to the tenant through these computing nodes. For another example, the cloud management platform can also create an interface to allow a tenant's client to send a tenant application identity creation request to the cloud management platform. This request specifies the tenant's application. The cloud management platform can then create an identity for the tenant's application based on the identity creation request and provide the identity to the tenant. For another example, the cloud management platform can also use a binding interface to allow a tenant's client to send the tenant's application identity and the identity of the tenant's compute node to the cloud management platform. The cloud management platform can then create a binding relationship between the tenant's application identity, the tenant's compute node identity, and the identity of the storage space serving the application, instructing the tenant's compute node to run the application. The binding relationship can then be sent to the proxy node, causing the proxy node to create a storage space serving the application in the storage node cluster to store the application's data. In this way, the tenant's compute node, the tenant's application, and the storage space serving the application are bound together. Once the application needs to process data, the compute node running the application can send an access request to the proxy node for the storage space, allowing the proxy node to complete data processing in the storage space. This will not be discussed in detail here.
[0064] The infrastructure can include a computing node cluster, a proxy node (also called a data processing unit (DPU)), and a storage node cluster. The following introduces these three concepts separately: (1) A computing node cluster can also be called a computing pool. A computing pool can contain multiple computing nodes. Multiple computing nodes can be selected by the cloud management platform. At the request of a tenant, a tenant-specific computing node can be selected from the multiple computing nodes to run the tenant's application. (2) The proxy node can not only serve as an intermediary between the computing node cluster and the storage node cluster, but can also connect to the cloud management platform (directly or indirectly), thereby (directly or indirectly) receiving the binding relationship between the identifier of the tenant's application, the identifier of the tenant's computing node, and the identifier of the storage space serving the application from the cloud management platform, and based on the binding relationship, perform a first-level security check on the initialization request and access request from the computing node. Only when the security check is passed will the proxy node respond to the initialization request (for example, return the identifier of the storage space serving the application to the computing node) and the access request (for example, send the access request to the storage node cluster for processing, so as to create a storage space serving the application in the storage node cluster or complete data processing in the storage space, etc.). (3) The storage node cluster can also be called a storage pool. The storage pool can contain multiple storage nodes and a management node that manages multiple storage nodes. Among them, the management node can directly receive the binding relationship between the identifier of the tenant's application, the identifier of the tenant's computing node and the identifier of the storage space serving the application from the cloud management platform, and set the binding relationship in the proxy node. The management node can also receive access requests (for example, storage space creation requests) from the tenant's computing node forwarded by the proxy node, and perform a secondary security check on the access request. If the security check is passed, a certain (or some) storage node can be selected and a storage space serving the tenant's application can be created in the storage node. The selected storage node can receive access requests (for example, data processing requests) from the tenant's computing node forwarded by the proxy node, and perform a secondary security check on the access request. If the security check is passed, data processing can be completed in the storage space serving the tenant's application.
[0065] Furthermore, the above-mentioned computing nodes, proxy nodes, storage nodes and management nodes can all be regarded as cloud instances in the cloud service system. The cloud instances can be presented in a variety of ways. For example, the cloud instance can be a physical server selected by the cloud management platform. For example, the cloud instance can also be a virtual machine (VM) created by the cloud management platform on the physical server through virtualization technology. For example, the cloud instance can also be a container (docker) created by the cloud management platform on the physical server through virtualization technology. For example, the cloud instance can also be a micro virtual machine (microVM) created by the cloud management platform on the physical server through virtualization technology. For example, the cloud instance can also be a bare metal server selected by the cloud management platform, and so on.
[0066] Furthermore, the above-mentioned storage node cluster is usually set up in the same site, and the site can be presented in various forms. For example, the site can be a cabinet (rack) in the infrastructure, or a computer room (room) in the infrastructure, or a data center (DC) in the infrastructure, or a region (region) in the infrastructure, or an availability zone (AZ) in the infrastructure, and so on.
[0067] Furthermore, the above-mentioned computing node cluster, proxy node and storage node cluster can be deployed in the same site or in different sites respectively. There is no restriction here and they can be set according to actual needs.
[0068] Based on the above cloud service system, it can be seen that at the request of the tenant, the cloud management platform can run the tenant's application on the tenant's dedicated computing node, and (through the proxy node) allocate exclusive storage space for the tenant's application (that is, the tenant's computing node) in the storage node cluster to store the tenant's application data, and provide the tenant's application (that is, the tenant's computing node) with access and call to complete data processing. It can be seen that the cloud management platform can bind the tenant's application, the computing node running the application, and the storage space serving the application together. Regardless of the number of applications, there is exclusive storage space in the storage node cluster for them to access. Therefore, multiple applications can share the same storage node cluster (storage pool) and avoid the occurrence of data security issues. To further understand the aforementioned process, the following further describes the process in conjunction with FIG2 . FIG2 is a flow chart of a method for accessing a storage node cluster based on a cloud management platform provided in an embodiment of the present application. As shown in FIG2 , the method can be implemented by the cloud service system shown in FIG1 . The cloud service system includes a cloud management platform and infrastructure for providing cloud services. The infrastructure includes computing node clusters, proxy nodes, and storage node clusters allocated thereto. The computing node cluster includes computing nodes allocated to tenants. The method includes:
[0069] Step 201: The cloud management platform receives the identifier of the application and the identifier of the computing node from the tenant through the binding interface.
[0070] In this embodiment, when the tenant needs to bind the tenant's application and the computing node specified by the tenant for running the application, the cloud management platform can provide a binding interface to the client used by the tenant (for example, the binding relationship input bar and reminder window of the tenant interface, etc.), so the tenant can send the identifier of the tenant's application and the identifier of the computing node specified by the tenant for running the application to the binding interface through the client, so that the cloud management platform receives the identifier of the application (for example, the unique identifier of the application, etc.) and the identifier of the computing node (for example, the unique identifier of the computing node, etc.) through the binding interface.
[0071] Specifically, before the tenant sends the identifier of the application and the identifier of the computing node to the cloud management platform, the tenant can obtain the identifier of the application in the following ways:
[0072] When a tenant needs to create an identifier for the application, the cloud management platform can provide a creation interface to the client used by the tenant (for example, the application information application column of the tenant interface, etc.). Therefore, the tenant can send an identifier creation request for the application to the creation interface through the client, so that the cloud management platform receives the identifier creation request for the application through the creation interface. After receiving the identifier creation request for the application, the cloud management platform can parse the identifier creation request to determine that the identifier of the application needs to be created for the tenant. Therefore, the cloud management platform can create an identifier representing the application and return the identifier of the application to the tenant's client through the creation interface for the tenant to use.
[0073] For example, as shown in Figure 3 (Figure 3 is a schematic diagram of application information acquisition provided by an embodiment of the present application), when a tenant needs to create a universally unique identifier (UUID) for application (data service) 1, the tenant can enter an identification creation request for application 1 in the application information application column in the tenant interface provided by the cloud management platform, so the cloud management platform can receive the identification creation request through the application information application column. Then, the cloud management platform can create a unique UUID for application 1 based on the identification creation request and return the UUID of application 1 to the tenant.
[0074] More specifically, before the tenant sends the identifier of the application and the identifier of the computing node to the cloud management platform, the tenant can obtain the identifier of the computing node in the following manner:
[0075] When a tenant needs to purchase a compute node, the cloud management platform can provide a purchase interface to the client used by the tenant (for example, the virtual machine purchase section of the tenant interface, etc.). The tenant can then send a purchase request for the compute node to the purchase interface through the client, so that the cloud management platform receives the purchase request for the compute node through the creation interface. After receiving the purchase request for the compute node, the cloud management platform can select a compute node dedicated to the tenant from the compute node cluster and return the identifier of the compute node to the tenant's client through the purchase interface, indicating that the purchase of the compute node has been successful.
[0076] Continuing with the previous example, when a tenant needs to purchase a virtual machine, they can enter a purchase request in the VM purchase field on the tenant interface provided by the cloud management platform. The cloud management platform then receives this purchase request through the VM purchase field. Based on this purchase request, the cloud management platform selects a dedicated VM 1 from the computing pool for the tenant and returns the UUID of VM 1 to the tenant.
[0077] Step 202: The cloud management platform creates a binding relationship between the application identifier, the computing node identifier, and the storage space identifier, and deploys the application in the computing node. The storage space is used to store application data.
[0078] Step 203: The cloud management platform deploys the binding relationship in the proxy node. The binding relationship is used to instruct the proxy node to detect the access request from the computing node. If the access request contains the identifier of the computing node and the identifier of the storage space, a storage space is created in the storage node cluster or data is processed in the storage space.
[0079] After obtaining the identifier of the application and the identifier of the computing node, the cloud management platform can generate the identifier of the storage space serving the application (for example, the namespace of the storage space), create a binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space (which can also be understood as the binding relationship between the application, the computing node, and the storage space), and deploy the application on the computing node so that the computing node runs the application. It can be understood that the storage space can be used to store the data of the application, so the storage space can implement data storage services for the application.
[0080] Then, the cloud management platform can deploy the binding relationship in the proxy node so that the proxy node stores the binding relationship. Then, when the application has data processing requirements, the computing node running the application can send an access request for the storage node cluster to the proxy node. After receiving the access request from the computing node, the proxy node can detect the information contained in the access request based on the binding relationship to determine whether the access request contains both the identifier of the computing node and the identifier of the storage space. If the access request contains the identifier of the computing node and the identifier of the storage space, it means that the information contained in the access request is consistent with the binding relationship, and the proxy node will create the storage space in the storage node cluster or complete data processing in the storage space to meet the data processing requirements of the application. If the access request does not contain the identifier of the computing node or the identifier of the storage space, it means that the information contained in the access request is inconsistent with the binding relationship, and the proxy node will refuse to process the access request.
[0081] It should be noted that if the identifier of the application has not been bound to the identifier of any storage space, it means that the application is binding to the storage space for the first time, so the cloud management platform can directly generate the identifier of the storage space serving the application, and create a binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space. If the identifier of the application has been bound to the identifiers of the remaining storage spaces, it means that the application is not binding to the storage space for the first time, so the cloud management platform can directly create a binding relationship between the identifier of the application, the identifier of the computing node, and the identifiers of the remaining storage spaces. The subsequent operations for these two situations are similar and will not be repeated later. This embodiment only uses the former as an example for schematic introduction.
[0082] Specifically, the cloud management platform can deploy the binding relationship in the proxy node in the following ways:
[0083] Because the storage node cluster includes multiple storage nodes and a management node that manages the multiple storage nodes, and the first end of the management node is in communication connection with the cloud management platform, the second end of the management node is in communication connection with the proxy node, and the third end of the management node is in communication connection with the multiple storage nodes, the cloud management platform can directly send the binding relationship between the application identifier, the computing node identifier, and the storage space identifier to the management node after obtaining the binding relationship. After obtaining the binding relationship, the management node can store the binding relationship and send the binding relationship to the proxy node, so that the proxy node stores the binding relationship.
[0084] Still taking the above example, as shown in Figure 4 (Figure 4 is a schematic diagram of binding an application to a virtual machine provided in an embodiment of the present application, and Figure 4 is drawn on the basis of Figure 3), when the tenant needs to bind application 1 and virtual machine 1 together, the tenant can enter the UUID of application 1 and the UUID of virtual machine 1 into the binding relationship input bar in the tenant interface, so the cloud management platform can receive the UUID of application 1 and the UUID of virtual machine 1 through the binding relationship input bar. Then, the cloud management platform can determine whether the UUID of application 1 has been bound to the UUIDs of the remaining virtual machines. If it has not been bound, the cloud management platform generates a namespace for storage space 1 and creates a binding relationship between the UUID of application 1, the UUID of virtual machine 1 and the namespace of storage space 1. (If Application 1's UUID is already bound to the UUIDs of other VMs, Application 1 has already been deployed on those VMs. The tenant needs to add another VM 1 to run Application 1. In this case, the cloud management platform has already generated namespaces for the remaining storage spaces for Application 1's UUID. Therefore, simply obtain the namespaces for the remaining storage spaces and create bindings between Application 1's UUID, VM 1's UUID, and the namespaces for the remaining storage spaces. Subsequent operations are similar to those in the previous case and will not be repeated here.)
[0085] After obtaining the binding relationship between Application 1's UUID, VM 1's UUID, and Storage 1's namespace, the cloud management platform instructs VM 1 to run Application 1 and sends the binding relationship to the storage management component (the aforementioned management node) in the storage pool. The management component then stores the binding relationship and notifies the DPU to store it. This synchronizes the binding relationship between the cloud management platform, the storage management component, and the DPU.
[0086] More specifically, after the cloud management platform deploys the binding relationship on the proxy node, the cloud management platform can also perform the following operations:
[0087] After the management node sends the binding relationship to the proxy node, it can notify the cloud management platform that the binding relationship has been successfully processed. Therefore, the cloud management platform can show the tenant through the binding interface that the application has been bound to the computing node, which is equivalent to notifying the tenant that the application has been successfully bound to the computing node.
[0088] Still as in the above example, after the management component notifies the DPU to store the binding relationship, it can return to the cloud management platform that the processing of the binding relationship has been successful. Therefore, the cloud management platform can generate a reminder window on the tenant interface. The reminder window contains content such as application 1 has been successfully bound to virtual machine 1. After browsing the reminder window, the tenant can know that application 1 has been successfully bound to virtual machine 1.
[0089] More specifically, before sending the access request to the proxy node, the computing node may further perform the following operations:
[0090] When the application needs to complete initialization, the computing node running the application can send the initialization request generated by the application to the proxy node. It should be noted that the initialization request can carry the identifier of the application and the identifier of the computing node (for example, the initialization request generated by the application only contains the identifier of the application. When the computing node sends the initialization request to the proxy node through the data channel, the data channel automatically causes the initialization request to contain the identifier of the computing node, etc.). After receiving the initialization request from the computing node, the proxy node can detect the information contained in the initialization request based on the binding relationship to determine whether the access request contains both the identifier of the application and the identifier of the computing node. If the initialization request contains the identifier of the application and the identifier of the computing node, it means that the information contained in the initialization request is consistent with the binding relationship. The proxy node then finds the identifier of the storage space serving the application from the binding relationship and sends it to the computing node, so that the application stores the identifier of the storage space (the application can also store the binding relationship between the identifier of the storage space and the identifier of the application, etc.) and completes the initialization. If the initialization request does not include the identifier of the application or the identifier of the computing node, it means that the information included in the initialization request does not conform to the binding relationship, and the proxy node refuses to process the initialization request.
[0091] Continuing with the above example, as shown in FIG5 (FIG. 5 is a schematic diagram of a virtual machine accessing a storage pool according to an embodiment of the present application, and FIG5 is drawn based on FIG4), when application 1 is initialized, application 1 may generate an initialization request, wherein the initialization request carries the UUID of application 1. Virtual machine 1 running application 1 may send the initialization request to the DPU via a data channel (i.e., the communication channel between virtual machine 1 and the DPU). During this process, the data channel automatically causes the initialization request to carry the UUID of virtual machine 1. After receiving the initialization request, the DPU will check whether the information carried in the initialization request is legal (whether it complies with the binding relationship) based on the aforementioned binding relationship. If the initialization request contains the UUID of application 1 and the UUID of virtual machine 1, which are bound to each other, it indicates that the information carried in the initialization request is legal. The DPU may return the namespace of storage space 1 to virtual machine 1 for storage in the software development kit (SDK) of application 1 running on virtual machine 1. The SDK of application 1 can then further store the binding relationship between application 1's UUID and the namespace of storage space 1, thereby assisting application 1 in completing initialization.
[0092] More specifically, after the computing node sends an access request to the proxy node, the proxy node may process the access request in the following manner:
[0093] When the application needs to process data, since the application has obtained the identifier of the storage space serving the application, the application can generate an access request carrying the identifier of the storage space. Then, the computing node running the application makes the access request carry the identifier of the application and the identifier of the computing node, and sends the access request to the proxy node (for example, the access request generated by the application only contains the identifier of the storage space. When the computing node sends the initialization request to the proxy node through the data channel, the data channel automatically makes the access request contain the identifier of the computing node, etc.). After obtaining the access request, since the proxy node stores the identifier of the application, the identifier of the computing node and the binding relationship of the storage space, the proxy node can detect the access request based on the binding relationship to determine whether the access request contains the identifier of the computing node and the identifier of the storage space at the same time. If the access request contains the identifier of the computing node and the identifier of the storage space, it means that the information contained in the access request is in accordance with the binding relationship, and the proxy node performs different processing based on the specific type of the access request.
[0094] If the access request is a request to create the storage space, the proxy node can send the access request to the management node so that the management node can detect the access request. If the access request contains the identifier of the storage space, it means that the information contained in the access request is legal. Therefore, the management node selects a storage node from multiple storage nodes and creates the storage space in the storage node. The identifier of the storage space can be used as the metadata (index) of the storage space. If the access request is a request to process data in the storage space, the proxy node can send the access request to the storage node so that the storage node can detect the access request. If the access request contains the identifier of the storage space, it means that the access request is legal. Therefore, the storage node can find the storage space based on the identifier of the storage space and process the data in the storage space (for example, write data to the storage space, read data from the storage space, delete data from the storage space, etc.), thereby meeting the data processing needs of the application.
[0095] Continuing with the example above, after Application 1 completes initialization, it can begin data processing. First, Application 1's business process generates an access request that carries Application 1's UUID. Next, Application 1's business process sends the access request to Application 1's SDK. Application 1's SDK converts Application 1's UUID in the access request into the namespace of Storage Space 1. Therefore, Virtual Machine 1 can send the access request carrying the namespace of Storage Space 1 to the DPU via the data channel. During this process, the data channel automatically causes the access request to carry Virtual Machine 1's UUID. The DPU then checks the information carried in the access request. If the access request contains the bound information of Virtual Machine 1 and the namespace of Storage Space 1, the information carried in the access request is valid.
[0096] Then, when the access request is a creation request for storage space 1, the DPU can send the access request to the storage management component, so that the storage management component creates storage space 1 in a database node (the aforementioned storage node) and uses the namespace of storage space 1 as the metadata of storage space 1. When the access request is a data processing request for storage space 1, the DPU can send the access request to the database node so that the database node detects the access request. If the access request carries the namespace of storage space 1, it means that the access request is legal, so the database node can find storage space 1 and complete operations such as data addition (append), data reading (read), and data deletion (delete) in storage space 1, thereby meeting the data processing requirements of application 1.
[0097] In addition, an embodiment of the present application also provides a storage node cluster access method based on a proxy node, the method comprising: the proxy node receives the binding relationship between the application identifier, the computing node identifier, and the storage space identifier from the cloud management platform, the application identifier and the computing node identifier are obtained by the cloud management platform from the tenant, the computing node runs the application, the storage space identifier is generated by the cloud management platform, and the storage space is used to store the application data; the proxy node receives the access request from the computing node, and detects the access request based on the binding relationship, and if the access request contains the computing node identifier and the storage space identifier, creates a storage space in the storage node cluster or processes data in the storage space. For an introduction to this method, please refer to the relevant description section in the embodiment shown in Figure 2, which will not be repeated here.
[0098] In an embodiment of the present application, when a tenant needs to bind the tenant's application and the tenant's computing node together, the tenant can input the application's identifier and the computing node's identifier into the binding interface provided by the cloud management platform. Then, the cloud management platform can determine the information of the storage space serving the application (used to store the application's data) to create a binding relationship between the application's identifier, the computing node's identifier, and the storage space's identifier, and instruct the computing node to run the application. Then, the cloud management platform can deploy the binding relationship in the proxy node. Since the proxy node is located between the computing node and the storage node cluster, when the proxy node receives an access request from the computing node, the proxy node can detect the access request based on the binding relationship. If the access request contains the mutually bound identifiers of the computing node and the storage space, the proxy node creates a storage space in the storage node cluster or completes processing data in the storage space. In the aforementioned process, the cloud management platform can, at the tenant's request, create a binding relationship between the identifier of the tenant's application, the identifier of the computing node running the application, and the identifier of the storage space serving the application, and deploy the binding relationship in the proxy node. When the computing node running the application sends an access request to the proxy node, the proxy node can perform a security check on the access request based on the binding relationship. If the access request passes the security check, it means that the information carried by the access request is in compliance with the binding relationship. Therefore, the proxy node can replace the computing node running the application to create a storage space in the storage node cluster (i.e., storage pool) that serves the application or access the storage space to complete data processing, thereby meeting the data processing needs of the application. It can be seen from this that the cloud management platform can use the binding relationship between the application, computing node, and storage space to instruct the proxy node to create a storage space in the storage pool that specifically serves the tenant's application. When the computing node running the application needs to access the storage space, the proxy node can perform a security check on it. After passing the security check, the proxy node will access the storage space on behalf of the computing node to complete data processing. In this way, even if there are multiple applications, the proxy node can create a dedicated storage space for each application in the storage pool, so that multiple applications can share the same storage pool. When the computing nodes running each application need to access the corresponding storage space, the proxy node can perform security checks on them in real time. Only after passing the security check will they be allowed to access the corresponding storage space, thus ensuring the data security between various applications.
[0099] The above is a detailed description of the storage node cluster access method based on the cloud management platform and the storage node cluster access method based on the proxy node provided in the embodiment of the present application. The cloud management platform and the proxy node provided in the embodiment of the present application are introduced below. FIG6 is a structural diagram of the cloud management platform provided in the embodiment of the present application. As shown in FIG6, the cloud management platform is used to manage the infrastructure for providing cloud services. The infrastructure includes computing nodes, proxy nodes, and storage node clusters. The cloud management platform includes:
[0100] The first receiving module 601 is used to receive the identifier of the application and the identifier of the computing node from the tenant through the binding interface; for example, the first receiving module 601 is used to implement step 201 of the embodiment shown in FIG. 2 .
[0101] The first creation module 602 is used to create a binding relationship between the application identifier, the computing node identifier, and the storage space identifier, and deploy the application in the computing node. The storage space is used to store the application data; for example, the first creation module 602 is used to implement step 202 of the embodiment shown in Figure 2.
[0102] Deployment module 603 is configured to deploy the binding relationship in the proxy node. The binding relationship is used to instruct the proxy node to detect access requests from the computing node and, if the access request includes the identifier of the computing node and the identifier of the storage space, to create the storage space in the storage node cluster or process data in the storage space. For example, deployment module 603 is configured to implement step 203 of the embodiment shown in FIG. 2 .
[0103] In a possible implementation, the identifier of the storage space includes a namespace of the storage space.
[0104] In one possible implementation, the cloud management platform also includes: a second receiving module, used to receive an identification creation request for an application from a tenant through a creation interface; a second creation module, used to create an identification of the application based on the identification creation request, and provide the identification of the application to the tenant through the creation interface.
[0105] In one possible implementation, the cloud management platform further includes: a notification module, configured to notify tenants through a binding interface that an application has been bound to a computing node.
[0106] In one possible implementation, the storage node cluster includes multiple storage nodes and a management node that manages the multiple storage nodes. The deployment module is used to send the binding relationship to the management node so that the binding relationship is deployed in the proxy node through the management node.
[0107] In one possible implementation, the binding relationship is also used to instruct the proxy node to detect the initialization request from the computing node, and if the initialization request includes the application identifier and the computing node identifier, send the storage space identifier to the computing node.
[0108] In one possible implementation, the proxy node creates a storage space in a storage node cluster or processes data in the storage space, including: the proxy node sends an access request to the management node, where the access request is used to instruct the management node to detect the access request; if the access request includes an identifier of the storage space, the storage space is created in any one of the multiple storage nodes; or, the proxy node sends an access request to the storage node, where the access request is used to instruct the storage node to detect the access request; if the access request includes an identifier of the storage space, the data is processed in the storage space.
[0109] In one possible implementation, a cluster of storage nodes is located in the same site, where a site can be any of the following: a cabinet, a computer room, a data center, a region, or an availability zone.
[0110] In one possible implementation, a compute node includes any of the following: a physical server, a bare metal server, a virtual machine, and a container.
[0111] FIG7 is a schematic diagram of the structure of an agent node provided in an embodiment of the present application. As shown in FIG7 , the agent node is set in the infrastructure providing cloud services. The infrastructure is managed by the cloud management platform. The infrastructure also includes a computing node and a storage node cluster. The agent node includes:
[0112] Receiving module 701 is used to receive the binding relationship between the application identifier, the computing node identifier and the storage space identifier from the cloud management platform. The application identifier and the computing node identifier are obtained by the cloud management platform from the tenant. The computing node runs the application. The storage space identifier is generated by the cloud management platform, and the storage space is used to store application data. For example, receiving module 701 can be used to implement relevant steps of the storage node cluster access method based on the cloud management platform.
[0113] Processing module 702 is configured to receive access requests from computing nodes and, based on the binding relationships, detect the access requests. If the access request includes the identifier of the computing node and the identifier of the storage space, it creates a storage space in the storage node cluster or processes data in the storage space. For example, processing module 702 may be used to implement the steps of a method for accessing a storage node cluster based on a cloud management platform.
[0114] In a possible implementation, the identifier of the storage space includes a namespace of the storage space.
[0115] In one possible implementation, the storage node cluster includes multiple storage nodes and a management node that manages the multiple storage nodes. The receiving module 701 is also used to directly receive the binding relationship between the application identifier, the computing node identifier, and the storage space identifier from the management node. The binding relationship is obtained by the management node from the cloud management platform.
[0116] In one possible implementation, the proxy node further includes: a feedback module configured to detect an initialization request from the computing node, and send the storage space identifier to the computing node if the initialization request includes an application identifier and a computing node identifier.
[0117] In one possible implementation, the processing module 702 is used to: send an access request to a management node, where the access request is used to instruct the management node to detect the access request; if the access request includes an identifier of a storage space, then create a storage space in any one of the multiple storage nodes; or send an access request to a storage node, where the access request is used to instruct the storage node to detect the access request; if the access request includes an identifier of a storage space, then process the data in the storage space.
[0118] In one possible implementation, a cluster of storage nodes is located in the same site, where a site can be any of the following: a cabinet, a computer room, a data center, a region, or an availability zone.
[0119] In one possible implementation, a compute node includes any of the following: a physical server, a bare metal server, a virtual machine, and a container.
[0120] It should be noted that the information interaction, implementation process, etc. between the modules / units of the above-mentioned device are based on the same concept as the method embodiment of the present application, and the technical effects they bring are the same as those of the method embodiment of the present application. For specific contents, please refer to the description in the method embodiment shown above in the embodiment of the present application, and no further details will be given here.
[0121] Please refer to Figure 8, which is a schematic diagram of the structure of a computing device provided in an embodiment of the present application. As shown in Figure 8, the computing device 800 (which can be used to present the aforementioned cloud management platform or proxy node) includes: a processor 801, a memory 802, a communication interface 803 and a bus 804. The processor 801, the memory 802 and the communication interface 803 are coupled via a bus (not labeled in the figure). The memory 802 stores instructions. When the execution instructions in the memory 802 are executed, the computing device 800 executes the method steps performed by the cloud management platform or proxy node in the above method embodiment.
[0122] The computing device 800 may be one or more integrated circuits configured to implement the above method, such as one or more application specific integrated circuits (ASICs), one or more digital signal processors (DSPs), one or more field programmable gate arrays (FPGAs), or a combination of at least two of these integrated circuit forms. For example, when a unit in the device can be implemented in the form of a processing element scheduler, the processing element may be a general-purpose processor, such as a central processing unit (CPU) or other processor that can call a program. For example, these units may be integrated together and implemented in the form of a system-on-a-chip (SOC).
[0123] The processor 801 may be a central processing unit (CPU), other general-purpose processors, digital signal processors (DSP), application-specific integrated circuits (ASIC), field programmable gate arrays (FPGA), other programmable logic devices, transistor logic devices, hardware components, or any combination thereof. The general-purpose processor may be a microprocessor or any conventional processor.
[0124] Memory 802 may be volatile memory or non-volatile memory, or may include both volatile and non-volatile memory. Non-volatile memory may be read-only memory (ROM), programmable read-only memory (PROM), erasable programmable read-only memory (EPROM), electrically erasable programmable read-only memory (EEPROM), or flash memory. Volatile memory may be random access memory (RAM), which is used as an external cache. By way of example and not limitation, many forms of RAM are available, such as static RAM (SRAM), dynamic random access memory (DRAM), synchronous DRAM (SDRAM), double data rate synchronous dynamic random access memory (DDR SDRAM), enhanced synchronous dynamic random access memory (ESDRAM), synchronous link DRAM (SLDRAM), and direct rambus RAM (DR RAM).
[0125] Memory 802 stores executable program code, and processor 801 executes the executable program code to implement the functions of the first receiving module, the first creation module, and the deployment module in the aforementioned cloud management platform (or the receiving module and the processing module in the proxy node), thereby implementing the aforementioned method for accessing a storage node cluster based on the cloud management platform (or proxy node). In other words, memory 802 stores instructions for executing the aforementioned method for accessing a storage node cluster based on the cloud management platform (or proxy node).
[0126] The communication interface 803 uses a transceiver module such as, but not limited to, a network interface card or a transceiver to implement communication between the computing device 800 and other devices or a communication network.
[0127] In addition to the data bus, bus 804 may also include a power bus, a control bus, and a status signal bus. The bus may be a Peripheral Component Interconnect Express (PCIe) bus, an Extended Industry Standard Architecture (EISA) bus, a unified bus (Ubus or UB), a Compute Express Link (CXL), or a Cache Coherent Interconnect for Accelerators (CCIX). Buses can be categorized as address buses, data buses, and control buses.
[0128] Please refer to Figure 9 , which is a schematic diagram of a computing device cluster provided in an embodiment of the present application. As shown in Figure 9 , the computing device cluster 900 includes at least one computing device 800 .
[0129] 9 , the computing device cluster 900 includes at least one computing device 800. The memory 802 in one or more computing devices 800 in the computing device cluster 900 may store the same instructions for executing the above-mentioned storage node cluster access method based on the cloud management platform (or proxy node).
[0130] In some possible implementations, the memory 802 of one or more computing devices 800 in the computing device cluster 900 may also respectively store partial instructions for executing the aforementioned cloud management platform (or proxy node)-based storage node cluster access method. In other words, the combination of one or more computing devices 800 can jointly execute the aforementioned cloud management platform (or proxy node)-based storage node cluster access method.
[0131] It should be noted that the memory 802 in different computing devices 800 in the computing device cluster 900 can store different instructions, each for executing part of the functions of the aforementioned cloud management platform (or proxy node). In other words, the instructions stored in the memory 802 in different computing devices 800 can implement the functions of one or more of the first receiving module, the first creating module, and the deploying module in the cloud management platform (or the receiving module and the processing module in the proxy node).
[0132] In some possible implementations, one or more computing devices 800 in the computing device cluster 900 may be connected via a network, which may be a wide area network or a local area network.
[0133] Please refer to Figure 10, which is a schematic diagram of computer devices in a computer cluster provided by an embodiment of the present application being connected via a network. As shown in Figure 10, two computing devices 800A and 800B are connected via a network. Specifically, each computing device is connected to the network via a communication interface.
[0134] In one possible implementation, the memory in the computing device 800A stores instructions for executing the functions of the first receiving module (or, receiving module) and other modules, and at the same time, the memory in the computing device 800B stores instructions for executing the functions of the first creation module and deployment module (or, processing module) and other modules.
[0135] It should be understood that the functions of the computing device 800A shown in Figure 10 may also be completed by multiple computing devices. Similarly, the functions of the computing device 800B may also be completed by multiple computing devices.
[0136] An embodiment of the present application also relates to a computer storage medium, which stores a program for signal processing. When the program is run on a computer, it enables the computer to execute the steps performed by the cloud management platform or agent node in the embodiment shown in Figure 2.
[0137] An embodiment of the present application also relates to a computer program product, which stores instructions that, when executed by a computer, enable the computer to execute the steps performed by the cloud management platform or agent node in the embodiment shown in Figure 2.
[0138] Those skilled in the art will clearly understand that, for the convenience and brevity of description, the specific working processes of the systems, devices and units described above can refer to the corresponding processes in the aforementioned method embodiments and will not be repeated here.
[0139] In the several embodiments provided in this application, it should be understood that the disclosed systems, devices and methods can be implemented in other ways. For example, the device embodiments described above are merely schematic. For example, the division of the units is merely a logical function division. In actual implementation, there may be other division methods, such as multiple units or components can be combined or integrated into another system, or some features can be ignored or not executed. Another point is that the mutual coupling or direct coupling or communication connection shown or discussed can be an indirect coupling or communication connection through some interfaces, devices or units, which can be electrical, mechanical or other forms.
[0140] The units described as separate components may or may not be physically separate, and the components shown as units may or may not be physical units, that is, they may be located in one place or distributed across multiple network units. Some or all of these units may be selected to achieve the purpose of this embodiment according to actual needs.
[0141] In addition, the functional units in the various embodiments of the present application may be integrated into a single processing unit, or each unit may exist physically separately, or two or more units may be integrated into a single unit. The aforementioned integrated units may be implemented in the form of hardware or software functional units.
[0142] If the integrated unit is implemented in the form of a software functional unit and sold or used as an independent product, it can be stored in a computer-readable storage medium. Based on this understanding, the technical solution of the present application is essentially or the part that contributes to the prior art or all or part of the technical solution can be embodied in the form of a software product, and the computer software product is stored in a storage medium, including a number of instructions for enabling a computer device (which can be a personal computer, a server, or a network device, etc.) to execute all or part of the steps of the method described in each embodiment of the present application. The aforementioned storage medium includes: various media that can store program codes, such as a USB flash drive, a mobile hard disk, a read-only memory (ROM), a random access memory (RAM), a magnetic disk or an optical disk.
Claims
1. A storage node cluster access method based on a cloud management platform, characterized in that: The cloud management platform is used to manage the infrastructure for providing cloud services, the infrastructure includes computing nodes, proxy nodes and storage node clusters, and the method includes: The cloud management platform receives the identifier of the application and the identifier of the computing node from the tenant through a binding interface; The cloud management platform creates a binding relationship between the identifier of the application, the identifier of the computing node, and the identifier of the storage space, and deploys the application in the computing node, and the storage space is used to store data of the application; The cloud management platform deploys the binding relationship in the proxy node, and the binding relationship is used to instruct the proxy node to detect the access request from the computing node. If the access request contains the identifier of the computing node and the identifier of the storage space, the storage space is created in the storage node cluster or the data is processed in the storage space.
2. The method according to claim 1, characterized in that The identifier of the storage space includes a namespace of the storage space.
3. The method according to claim 1 or 2, characterized in that: The method further comprises: The cloud management platform receives an identification creation request for the application from the tenant through a creation interface; The cloud management platform creates an identification of the application based on the identification creation request, and provides the identification of the application to the tenant through the creation interface.
4. The method according to any one of claims 1 to 3, characterized in that: The method further comprises: The cloud management platform notifies the tenant through the binding interface that the application has been bound to the computing node.
5. The method according to any one of claims 1 to 4, characterized in that: The storage node cluster includes multiple storage nodes and a management node for managing the multiple storage nodes, and the cloud management platform deploys the binding relationship in the proxy node including: The cloud management platform sends the binding relationship to the management node, so that the binding relationship is deployed in the proxy node through the management node.
6. The method according to any one of claims 1 to 5, characterized in that: The binding relationship is also used to instruct the proxy node to detect the initialization request from the computing node, and if the initialization request includes the identifier of the application and the identifier of the computing node, send the identifier of the storage space to the computing node.
7. The method according to claim 5, characterized in that The proxy node creates the storage space in the storage node cluster or processes the data in the storage space, including: The proxy node sends the access request to the management node, where the access request is used to instruct the management node to detect the access request, and if the access request includes the identifier of the storage space, creates the storage space in any one of the multiple storage nodes; or The proxy node sends the access request to the storage node, where the access request is used to instruct the storage node to detect the access request, and if the access request includes an identifier of the storage space, the data is processed in the storage space.
8. The method according to any one of claims 1 to 7, characterized in that: The storage node cluster is located in the same site, and the site includes any of the following: a cabinet, a computer room, a data center, a region, and an availability zone.
9. The method according to any one of claims 1 to 8, characterized in that: The computing node includes any of the following: a physical server, a bare metal server, a virtual machine, and a container.
10. A cloud management platform, characterized in that: The cloud management platform is used to manage the infrastructure for providing cloud services, the infrastructure includes computing nodes, proxy nodes and storage node clusters, and the cloud management platform includes: A first receiving module, configured to receive an identifier of the application and an identifier of the computing node from the tenant through a binding interface; A first creation module, used to create a binding relationship between the identifier of the application, the identifier of the computing node and the identifier of the storage space, and deploy the application in the computing node, the storage space is used to store data of the application; A deployment module is used to deploy the binding relationship in the proxy node, and the binding relationship is used to instruct the proxy node to detect the access request from the computing node. If the access request contains the identifier of the computing node and the identifier of the storage space, the storage space is created in the storage node cluster or the data is processed in the storage space.
11. The cloud management platform according to claim 10, characterized in that: The identifier of the storage space includes a namespace of the storage space.
12. The cloud management platform according to claim 10 or 11, characterized in that: The cloud management platform also includes: A second receiving module, configured to receive an identification creation request for the application from the tenant through a creation interface; The second creation module is used to create the identification of the application based on the identification creation request, and provide the identification of the application to the tenant through the creation interface.
13. The cloud management platform according to any one of claims 10 to 12, characterized in that: The cloud management platform also includes: A notification module is used to notify the tenant through the binding interface that the application has been bound to the computing node.
14. The cloud management platform according to any one of claims 10 to 13, characterized in that: The storage node cluster includes multiple storage nodes and a management node for managing the multiple storage nodes. The deployment module is used to send the binding relationship to the management node so as to deploy the binding relationship in the proxy node through the management node.
15. The cloud management platform according to any one of claims 10 to 14, characterized in that: The binding relationship is also used to instruct the proxy node to detect the initialization request from the computing node, and if the initialization request includes the identifier of the application and the identifier of the computing node, send the identifier of the storage space to the computing node.
16. The cloud management platform according to claim 14, characterized in that: The proxy node creates the storage space in the storage node cluster or processes the data in the storage space, including: The proxy node sends the access request to the management node, where the access request is used to instruct the management node to detect the access request, and if the access request includes the identifier of the storage space, creates the storage space in any one of the multiple storage nodes; or The proxy node sends the access request to the storage node, where the access request is used to instruct the storage node to detect the access request, and if the access request includes an identifier of the storage space, the data is processed in the storage space.
17. The cloud management platform according to any one of claims 10 to 16, characterized in that: The storage node cluster is located in the same site, and the site includes any of the following: a cabinet, a computer room, a data center, a region, and an availability zone.
18. The cloud management platform according to any one of claims 10 to 17, characterized in that: The computing node includes any of the following: a physical server, a bare metal server, a virtual machine, and a container.
19. A computing device cluster, characterized in that: The computing device cluster includes at least one computing device, each computing device including a processor and a memory: The memory is used to store instructions; The processor is configured to cause the computing device cluster to execute the method according to any one of claims 1 to 9 according to the instructions.
20. A computer storage medium, characterized in that The computer storage medium stores one or more instructions, which, when executed by one or more computers, enable the one or more computers to implement the method of any one of claims 1 to 9.
21. A computer program product, characterized in that The computer program product stores instructions, which, when executed by a computer, enable the computer to implement the method according to any one of claims 1 to 9.
Citation Information
Patent Citations
Storage node cluster access method and cloud management platform
CN120050282A
Synchronized method and device of application data across devices
CN102546779A
Storage method of cluster storage system
CN103092532A
Resource calling method, device and system and storage medium
CN113301080A
Storage scheme for a distributed storage system
US10620871B1