Cloud computing technology-based elastic public IP configuration method and cloud management platform
By setting up monitoring nodes and an automatic switching mechanism in the cloud management platform, the problem of IP address power outages and network interruptions during public network access to cloud resources has been solved, achieving stability and flexibility in public network access.
Patent Information
- Authority / Receiving Office
- WO · WO
- Patent Type
- Applications
- Current Assignee / Owner
- HUAWEI CLOUD COMPUTING TECHNOLOGIES CO LTD
- Filing Date
- 2024-12-26
- Publication Date
- 2026-05-15
AI Technical Summary
When accessing cloud resources via the public network, the public IP address may experience network interruptions due to power outages, network outages, or other reasons, making public network access impossible.
By setting up monitoring nodes in different availability zones through the cloud management platform, the working status of access points is monitored regularly. When an access point is in an abnormal working state, the system automatically switches to an access point in a normal working state, binds it to an elastic public IP address, establishes a backup communication channel, and ensures the continuous availability of cloud resources.
It ensures the stability of cloud resources during public network access, avoids network interruptions, and improves the reliability and flexibility of public network access.
Smart Images

Figure CN2024142851_15052026_PF_FP_ABST
Abstract
Description
Elastic public IP configuration method and cloud management platform based on cloud computing technology
[0001] This application claims priority to Chinese patent applications filed on December 29, 2023, with application number 202311865864.5 entitled "Cloud Platform System and Method for Selecting Public IP Address" and on March 29, 2024, with application number 202410386798.1 entitled "Elastic Public IP Configuration Method and Cloud Management Platform Based on Cloud Computing Technology", the entire contents of which are incorporated herein by reference. Technical Field
[0002] This application relates to the field of cloud computing technology, and in particular to a method for configuring elastic public IP addresses based on cloud computing technology and a cloud management platform. Background Technology
[0003] With the development of cloud computing technology, cloud resources are being used more and more widely. These resources can include one or any combination of virtual machines, containers, bare metal servers, and dedicated servers. Currently, in addition to providing services to the public, cloud resources can also be accessed via the public internet.
[0004] Before accessing cloud resources to the public network, you can bind a public Internet Protocol (IP) address to the cloud resource. The cloud resource can then be accessed to the public network based on the bound public IP address.
[0005] However, when cloud resources are accessed via the public network based on a public IP address, the public IP address may become unreachable. For example, if the access point providing the public IP address experiences a power outage or network outage, the cloud resources will be unable to be accessed via the public network. Summary of the Invention
[0006] This application provides a method for configuring elastic public IP addresses and a cloud management platform based on cloud computing technology. This can avoid network interruptions when cloud resources are accessed via the public network, thereby improving the stability of public network access. The corresponding technical solution is as follows:
[0007] Firstly, a method for configuring elastic public IP addresses based on cloud computing technology is provided. This method is used in a cloud management platform to manage infrastructure, which includes a first data center located in a first availability zone, a second data center located in a second availability zone, and a third data center located in a third availability zone. The method includes:
[0008] The cloud management platform receives first access point information input by the tenant, indicating the first access point of the first elastic public IP purchased by the tenant, located in the first data center of the first availability zone. It also receives first cloud resource information input by the tenant, indicating the first cloud resource bound to the first elastic public IP and the second availability zone where the first cloud resource is located, situated in the second data center of the second availability zone. The cloud management platform establishes a first communication channel between the first and second data centers. This first communication channel is used to transmit packets destined for the first elastic public IP, sent from the external network of the infrastructure to the first access point, from the first data center to the first cloud resource in the second data center, and / or to transmit packets generated by the first cloud resource with a destination address belonging to the external network, from the second data center to the first access point in the first data center and then sent to the external network via the first access point.
[0009] The cloud management platform receives monitoring information from the tenant regarding the first access point, which carries the first elastic public IP address. The cloud management platform sets up monitoring nodes in the first availability zone or a neighboring availability zone. These monitoring nodes periodically monitor the operational status of the first access point and report the status back to the cloud management platform. The cloud management platform notifies the tenant of the operational status; and / or, if the operational status is abnormal, the cloud management platform establishes a second communication channel between the third data center and the second data center. The third data center includes a second access point containing the second elastic public IP address purchased by the tenant. This second communication channel is used to transmit packets destined for the second access point in the third data center (with the second elastic public IP address) sent via an external network to the first cloud resource in the second data center, and / or to transmit packets generated by the first cloud resource with a destination address in the external network from the second data center to the second access point in the third data center and then to the external network via the second access point.
[0010] In the solution presented in this application, the cloud management platform binds a first elastic public IP address to a first cloud resource according to the user's instructions, enabling the first cloud resource to access the public network using the first elastic public IP address. While the first cloud resource is accessing the public network using the first elastic public IP address, the cloud management platform can also set up a monitoring node for the first access point corresponding to the first elastic public IP address to periodically check the working status of the first access point. When the cloud management platform determines that the first access point is in an abnormal working state, it can switch the binding of the first cloud resource to the first elastic public IP address corresponding to the second elastic public IP address of the second access point that is in a normal working state. Thus, during the process of the first cloud resource accessing the public network using the first elastic public IP address, if the first access point changes from a normal working state to an abnormal working state, the cloud management platform can switch the binding of the first cloud resource to the second elastic public IP address corresponding to the second access point that is in a normal working state. This ensures that the first cloud resource is always bound to a connected and available elastic public IP address, preventing network interruptions and improving the stability of the first cloud resource's public network access.
[0011] In one feasible approach, the monitoring node is also used to periodically monitor the operational status of the second access point. When the cloud management platform is in an abnormal operational state, it establishes a second communication channel between the third data center and the second data center. This includes: when the first access point is in an abnormal operational state and the second access point is in a normal operational state, the cloud management platform unbinds the first elastic public IP address from the first cloud resource and binds the second elastic public IP address to the first cloud resource, thus establishing the second communication channel between the third data center and the second data center.
[0012] In the solution presented in this application, the monitoring node can monitor not only the working status of the first access point bound to the first cloud resource, but also the working status of the second access point allocated to the first cloud resource but not bound to it. This allows the cloud management platform to quickly identify the working second access point after determining that the first access point is not in a normal working state, and then bind the second elastic public IP address to the first cloud resource. This avoids binding the first cloud resource to an access point in a normal working state again, thus improving the stability of public network access for the first cloud resource.
[0013] In one feasible approach, there are multiple monitoring nodes. When the cloud management platform is in an abnormal working state, it establishes a second communication channel between the third data center and the second data center. This includes: when the cloud management platform determines that the proportion of the number of monitoring nodes whose first access point is in an abnormal working state is greater than a proportion threshold in the total number of monitoring nodes, it establishes a second communication channel between the third data center and the second data center.
[0014] In the solution presented in this application, the cloud management platform can set up multiple monitoring nodes to monitor the operational status of access points allocated to cloud resources. These multiple monitoring nodes can be located in areas not connected to the access points, thereby improving the accuracy of monitoring the operational status of the access points.
[0015] In one feasible approach, the monitoring information also includes the percentage threshold and the availability zone where each monitoring node is located. This allows tenants to configure their own monitoring strategies for monitoring access points, improving the flexibility of monitoring the operational status of access points.
[0016] In one possible implementation, the method further includes: a cloud management platform receiving monitoring data from monitoring nodes monitoring the operational status of the first access point, the monitoring data including packet loss rate and latency. If the packet loss rate corresponding to the first access point is greater than a packet loss rate threshold or the latency corresponding to the first access point is less than a latency threshold, the operational status of the first access point is determined to be an abnormal working state.
[0017] In one feasible implementation, the method further includes: when the first access point is in an abnormal working state, the cloud management platform sends an alarm message to the cloud management terminal corresponding to the cloud management platform. The alarm message carries the access point identifier corresponding to the first access point. This allows technicians to quickly determine the abnormal working state of the first access point, thereby improving the efficiency of fault analysis and troubleshooting.
[0018] In one possible implementation, the method further includes: when the working state of the first access point is abnormal, the cloud management platform sends a stop monitoring notification for the corresponding first access point to the monitoring node. The stop monitoring notification instructs the monitoring node to cease periodically monitoring the working state of the first access point. Thus, by stopping the monitoring of the first access point's working state when it is abnormal, invalid monitoring of the first access point can be avoided.
[0019] Secondly, a cloud management platform is provided for managing infrastructure, including a first data center located in a first availability zone, a second data center located in a second availability zone, and a third data center located in a third availability zone. The cloud management platform includes:
[0020] The receiving module is used to receive first access point information input by the tenant, wherein the first access point information is used to indicate the first access point of the first elastic public IP purchased by the tenant, and the first access point is located in the first data center of the first availability zone; and to receive first cloud resource information input by the tenant, wherein the first cloud resource information is used to indicate the first cloud resource bound to the first elastic public IP and the second availability zone where the first cloud resource is located, wherein the first cloud resource is set in the second data center of the second availability zone.
[0021] The channel establishment module is used to establish a first communication channel between the first data center and the second data center. The first communication channel is used to transmit packets with a destination address of a first elastic public IP sent to the first access point through the external network of the infrastructure from the first data center to the first cloud resource in the second data center, and / or transmit packets generated by the first cloud resource with a destination address belonging to the external network from the second data center to the first access point of the first data center and send them to the external network via the first access point.
[0022] The receiving module is also used to receive monitoring information for the first access point input by the tenant, wherein the monitoring information carries the first elastic public IP address;
[0023] The configuration module is used to set up monitoring nodes in the first availability zone or in an adjacent availability zone. The monitoring nodes are used to periodically monitor the working status of the first access point and report the working status back to the cloud management platform.
[0024] The processing module is used by the cloud management platform to notify the tenant of its working status; and / or, to establish a second communication channel between the third data center and the second data center when the working status is not normal, wherein the third data center includes a second access point with a second elastic public IP purchased by the tenant, and the second communication channel is used to transmit packets sent from the third data center to the second access point in the third data center with the destination address of the second elastic public IP via the external network to the first cloud resource in the second data center, and / or to transmit packets generated by the first cloud resource with the destination address of the external network from the second data center to the second access point in the third data center and send them to the external network via the second access point.
[0025] In one feasible approach, the monitoring node is also used to periodically monitor the working status of the second access point; the channel establishment module is used to: unbind the first elastic public IP from the first cloud resource and bind the second elastic public IP to the first cloud resource when the working status of the first access point is abnormal and the working status of the second access point is normal, thereby establishing a second communication channel between the third data center and the second data center.
[0026] In one feasible approach, there are multiple monitoring nodes, and the channel establishment module is used to: establish a second communication channel between the third data center and the second data center when the proportion of the number of monitoring nodes in which the first access point is detected to be in an abnormal working state is greater than a proportion threshold.
[0027] In one feasible approach, the monitoring information also includes the percentage threshold and the availability zone where each monitoring node is located.
[0028] In one possible implementation, the cloud management platform further includes a determination module, used to: receive monitoring data from the monitoring node monitoring the working status of the first access point, the monitoring data including packet loss rate and latency; and determine that the working status of the first access point is abnormal if the packet loss rate corresponding to the first access point is greater than the packet loss rate threshold or the latency corresponding to the first access point is less than the latency threshold.
[0029] In one possible implementation, the cloud management platform also includes an alarm module, which is used to send alarm information to the cloud management terminal corresponding to the cloud management platform when the working state of the first access point is abnormal. The alarm information carries the access point identifier corresponding to the first access point.
[0030] Thirdly, a public cloud system is provided, including:
[0031] The first access point is located in the first data center of the first availability zone and is equipped with the first elastic public IP address.
[0032] The first cloud resource is the second data center located in the second availability zone.
[0033] The second access point is located in the third data center of the third availability zone and is configured with a second elastic public IP address. The first availability zone, the second availability zone, and the third availability zone are located in different regions.
[0034] The monitoring node is used to monitor the working status of the first access point.
[0035] The backbone network is used to connect the first data center of the first availability zone and the second data center of the second availability zone, and after the monitoring node detects that the working status of the first access point is abnormal, it connects the first data center of the first availability zone and the third data center of the third availability zone.
[0036] The first access point is also configured to receive packets sent through the external network of the infrastructure with a destination address of a first elastic public IP address, and send the packets to the first cloud resource of the second data center via the backbone network, and / or receive packets generated by the first cloud resource with a destination address belonging to the external network, and send them to the external network.
[0037] The second access point is also used to receive, after the monitoring node detects that the working status of the first access point is abnormal, a message with a destination address of the first elastic public IP sent through the external network of the infrastructure, and send the message to the first cloud resource of the second data center via the backbone network, and / or receive a message generated by the first cloud resource with a destination address belonging to the external network, and send it to the external network.
[0038] Fourthly, a computing device cluster is provided, including at least one computing device, each computing device including a processor and memory;
[0039] The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the cluster of computing devices to perform the method as described in the first aspect above and in any feasible manner of the first aspect.
[0040] Fifthly, a computer program product comprising instructions is provided, which, when executed by a computing device, cause the computing device to perform the method described in the first aspect above and in any implementable manner of the first aspect.
[0041] In a sixth aspect, a computer-readable storage medium is provided, including computer program instructions that, when executed by a computing device, perform the method as described in the first aspect above and in any implementable manner of the first aspect. Attached Figure Description
[0042] Figure 1 is a schematic diagram of a data center distribution provided in an embodiment of this application;
[0043] Figure 2 is a schematic diagram of a flexible public IP configuration system structure provided in an embodiment of this application;
[0044] Figure 3 is a schematic flowchart of a flexible public IP configuration method provided in an embodiment of this application;
[0045] Figure 4 is a schematic diagram of a flexible public IP configuration interface provided in an embodiment of this application;
[0046] Figure 5 is a schematic diagram of a flexible public network access structure provided in an embodiment of this application;
[0047] Figure 6 is a schematic diagram of another flexible public network access structure provided in an embodiment of this application;
[0048] Figure 7 is a schematic diagram of another flexible public network access structure provided in an embodiment of this application;
[0049] Figure 8 is a schematic diagram of another flexible public network access structure provided in an embodiment of this application;
[0050] Figure 9 is a schematic flowchart of a flexible public IP configuration method provided in an embodiment of this application;
[0051] Figure 10 is a schematic diagram of a flexible public IP configuration interface provided in an embodiment of this application;
[0052] Figure 11 is a schematic diagram of a primary and backup IP scheme for binding a virtual machine to a GEIP according to an embodiment of this application;
[0053] Figure 12 is a schematic diagram of a GEIP binding gateway master IP scheme provided in an embodiment of this application;
[0054] Figure 13 is a schematic diagram of a method for accessing the public network provided in an embodiment of this application;
[0055] Figure 14 is a schematic diagram of a cloud management platform device provided in an embodiment of this application;
[0056] Figure 15 is a schematic diagram of a computing device structure provided in an embodiment of this application;
[0057] Figure 16 is a schematic diagram of a computing device cluster structure provided in an embodiment of this application;
[0058] Figure 17 is a schematic diagram of another computing device cluster structure provided in an embodiment of this application. Detailed Implementation
[0059] To make the objectives, technical solutions, and advantages of this application clearer, the embodiments of this application will be described in further detail below with reference to the accompanying drawings.
[0060] Elastic IP (EIP): Provides independent public IP resources, including public IP address and public bandwidth, which can be bound to and unbound from cloud resources such as virtual machines, bare metal servers, virtual IPs, elastic load balancers, NAT gateways, containers, and dedicated hosts.
[0061] Global Elastic IP (GEIP) is a global elastic public IP product. Compared to EIP, GEIP can bind and unbind resources such as elastic cloud servers, bare metal servers, virtual IPs, elastic load balancers, and NAT gateways across regions.
[0062] Access point: The location of the elastic public IP resource, corresponding to the cloud provider's point of presence (POP) or region. The access point is located in the cloud provider's data center.
[0063] Point of Presence (POP): In the cloud computing field, the point of presence is located at the edge of the cloud network provided by the cloud vendor, and external access can be made to the cloud network through the point of presence.
[0064] Cloud resources: Cloud resources include one or any combination of virtual machines, containers, bare metal servers, and dedicated servers.
[0065] [Amended according to Rule 26, 21.01.2025] Region: Location of the data center. A region contains multiple areas. In one embodiment provided in this application, a region may include, for example, China and the Asia-Pacific region.
[0066] Region: The location of a data center. Regions are typically defined by geographical location and network latency, and are also called geographical areas. Within the same region, public services such as elastic computing are shared. In one embodiment provided in this application, regions may include, for example, North China, East China, or North China-Beijing I, East China-Shanghai I.
[0067] Availability Zone (AZ): The location of a data center. An availability zone is a collection of one or more independent physical data centers within the same area, sharing power and network infrastructure. Multiple availability zones within an area are connected via high-speed fiber optic cables. In one embodiment provided in this application, availability zones include, for example, Beijing Availability Zone A and Beijing Availability Zone B.
[0068] Backbone Network: A high-speed network used to connect multiple regions.
[0069] Cross-Availability Zone Network: A high-speed network within the same region used to connect multiple availability zones.
[0070] Cloud management platform and infrastructure: The cloud management platform is used to manage the infrastructure of cloud vendors. The infrastructure consists of multiple data centers located in different regions, with at least one data center in each region. The cloud management platform can provide interfaces related to cloud computing services, such as configuration pages or application program interfaces (APIs), for tenants to access cloud services. Tenants can log in to the cloud management platform with a pre-registered account and password, and after successful login, select and purchase cloud services provided by the data centers in the designated regions. Cloud services include object storage services, virtual machine services, container services, or other known cloud services.
[0071] Tenant: The top-level object used to manage cloud services and / or cloud resources. Tenants register tenant accounts and set tenant passwords on the cloud management platform through local clients (such as browsers). Local clients remotely log in to the cloud management platform through the tenant account and set tenant password. The cloud management platform provides a configuration interface or API for tenants to configure and use cloud services, where cloud services are specifically provided by the infrastructure managed by the cloud management platform as described above.
[0072] Domain Name System (DNS): A service that translates domain names into IP addresses for computer connections, routing end users to appropriate resources. It is typically a database that maps domain names to IP addresses.
[0073] In existing elastic public network (EPR) services, EPR resources are strongly correlated with regions. Most regions are located in first-tier cities, where EPR IPs and bandwidth resources are expensive. Resources in surrounding provincial capitals and second-tier cities, which are relatively cheaper, cannot be accessed within these regions. This results in high public network resource purchase costs and inflexible deployment of tenant cloud resources. Related technologies address this by providing edge services, building edge sites in non-first-tier cities to offload computing, storage, and network resources to those cities. However, this solution is costly, time-consuming, and offers poor cloud-edge interoperability, failing to meet the needs of customers who require only low-cost edge bandwidth access without offloading computing and network resources.
[0074] This application provides a method, apparatus, and system for configuring elastic public IP addresses based on cloud computing technology. It does not require cloud resources and public network resources to belong to the same region, enabling tenants to interconnect cloud resources in any region of the cloud with public network resources. This allows tenants to flexibly deploy their cloud resources based on their business needs, reduce the cost of using public network resources, and achieve refined bandwidth operation, facilitating cost control for both tenants and cloud vendors.
[0075] To illustrate the distribution of data centers in this application embodiment, please refer to Figure 1 below. Figure 1 is a schematic diagram of a data center distribution provided in this application embodiment. As shown in Figure 1, the schematic diagram shows the distribution of data centers in terms of geographical location and region. The schematic diagram includes region 11 and region 12. Region 11 includes region 111 and region 112, and region 12 includes region 121 and region 122. Region 111 includes data centers 1110, 1111, 1112, and 1113, and other regions follow the same pattern. In this application, data centers 1110 and 1210 are interconnected via a cross-regional communication channel 131, which is established through a cross-regional backbone network provided by a cloud provider. Data centers 1110 and 1120 are interconnected via a same-regional but cross-regional communication channel 132, which is also established through a cross-regional backbone network provided by a cloud provider. Data centers 1110 and 1111 are interconnected via a same-regional communication channel 133, which is established through a cross-availability zone network provided by a cloud provider. Data centers 1111 and 1110 may be located in different availability zones within the same city or in different availability zones in different cities; this application does not limit this. It is worth noting that in other embodiments provided in this application, the number of regions, the number of areas within each region, and the number of data centers in each area are not limited to those shown in the figure. For example, each region may include one or more areas; this application does not limit this.
[0076] In scenarios where tenants use cloud resources provided by cloud vendors and bind elastic public network resources to these resources, relevant technologies require that the tenant's elastic public network resources and cloud resources must be located in the same region, and do not support the use of elastic public network IPs across regions for tenant cloud resources. To address this issue, this application provides a method, apparatus, and system for configuring elastic public network IPs based on cloud computing technology. This method is applied to a cloud management platform, which manages infrastructure. The cloud management platform establishes a communication channel via the backbone network between the data center where the tenant's cloud resources reside and the data center where the elastic public network resources reside, enabling the tenant to deploy cloud resources based on their business needs and deploy elastic public network resources provided by cloud vendors in any region for their cloud resources.
[0077] To illustrate the structure of the Elastic Public IP Configuration System provided in this application embodiment, please refer to Figure 2 below. Figure 2 shows a schematic diagram of the structure of an Elastic Public IP Configuration System provided in this application. Specifically, this figure is a detailed representation of the infrastructure including data centers 1110, 1120, and 1210 in Figure 1. The following description of the Elastic Public IP Configuration System structure is based on the schematic diagram of the Elastic Public IP Configuration System in Figure 2, combined with the data center distribution diagram in Figure 1. As shown in Figure 2, infrastructure 1 includes a cloud management platform 10, and also includes data centers 1110...data center k located in region 111, data centers 1210...data center m located in region 121, and data centers 1120...data center n located in region 112. Among them, data center 1110 is the tenant's Elastic Public IP access point. Public network resources provided by the cloud vendor are deployed on server 11101 in data center 1110. The public network resources include Elastic Public IP and public network bandwidth. In data center 1210 located in region 121, there is server 12101, and virtual machine 121011 for tenant 40 is hosted on server 12101. In data center 1120 located in region 112, there is server 11201, and virtual machine 112011 for tenant 40 is hosted on server 11201. Referring to Figure 1, regions 111 and 112 are located in region 11, and region 121 is located in region 12. That is, in one embodiment of this application, regions 111 and 121 are located in different regions, while regions 111 and 112 are located in the same region. In other words, data centers 1110 and 1210 are located in different regions, while data centers 1110 and 1120 are located in different areas of the same region. Infrastructure 1 includes a cross-regional backbone network 13, which connects cross-regional data centers within Infrastructure 1. For example, cloud management platform 10 establishes a communication channel 131 between data centers 1110 and 1210 for tenant 40 via the cross-regional backbone network 13, and a communication channel 132 between data centers 1110 and 1120 for tenant 40 via the cross-regional backbone network 13. Tenant 40 can log in to cloud management platform 10 via tenant client 30 using tenant account and password through Internet 20, configure its cloud resources (including virtual machines 121011 and 112011) on cloud management platform 10, and set up elastic public network access points, elastic public network IPs, and public network bandwidth for the cloud resources. It is worth noting that, for ease of explanation, this application embodiment shows three areas and two communication channels in infrastructure 1, but this application embodiment is not limited to a scheme that only includes three areas and two communication channels. For example, communication channels may not be established according to tenant needs, or one or more communication channels may be established according to tenant needs. This application embodiment does not limit this.
[0078] Based on the elastic public IP configuration scenarios described in Figures 1 and 2, the following describes in detail the elastic public IP configuration method based on cloud computing technology provided in the embodiments of this application, with reference to Figure 3.
[0079] Please refer to Figure 3 below. Figure 3 is a flowchart of a method for configuring an elastic public IP address based on cloud computing technology provided in this application embodiment. As shown in Figure 3, the method includes, but is not limited to, the following steps:
[0080] S101. Tenant 40: Input access point information, cloud resource information, and bandwidth information.
[0081] For example, tenant 40 sets access point information, cloud resource information, and bandwidth information on the interface provided by cloud management platform 10 via tenant client 30 and Internet 20. One embodiment of tenant setting access point information, cloud resource information, and bandwidth information can be seen in Figure 4, which is a schematic diagram of an elastic public IP configuration interface provided in an embodiment of this application. As shown in Figure 4, the Elastic Public IP configuration interface allows tenants to configure the following items: access region, instance location region, bound instance, bandwidth type, bandwidth name, bandwidth size, and elastic public IP name. For example, the access region might be North China-Beijing, and the instance location region might be East China-Shanghai. The bound instance, in this embodiment, is a virtual machine or an elastic cloud server. In other embodiments provided in this application, the bound instance might include a container, bare metal server, dedicated host, elastic network interface card, or load balancer. The bandwidth type, in this embodiment, is cross-regional bandwidth, as the tenant virtual machine 121011 is located in data center 1210 and the access point is located in data center 1110, which are in different regions of different major regions. In other embodiments provided in this application, the bandwidth type might include cross-regional bandwidth, major region bandwidth, regional bandwidth, or metropolitan area bandwidth, which will be elaborated on in later embodiments. The bandwidth size is, for example, 100 Mbit / s. The bandwidth name and elastic public IP name are, for example, names set by the tenant. It is worth noting that Figure 4 is only one configuration interface provided by this application embodiment. In other embodiments provided in this application, the configurable items might include one or more of the above configuration items, and this application does not limit this.
[0082] [Amended according to Rule 26, 21.01.2025] Optionally, in one embodiment provided in this application, the bandwidth type may include cross-regional bandwidth, large-area bandwidth, regional bandwidth, and metropolitan area bandwidth. Among them, cross-regional bandwidth refers to the bandwidth type when the data centers where the elastic public network resources and tenant cloud resources are located are in different regions. For example, the data center where the elastic public network resources are located is in the China region, and the data center where the tenant cloud resources are located is in the Asia Pacific region. Regional bandwidth refers to the bandwidth type when the data centers where the elastic public network resources and tenant cloud resources are located are in different areas within the same region. For example, the data center where the elastic public network resources are located is in the East China region of the China region, and the data center where the tenant cloud resources are located is in the North China region of the China region. Regional bandwidth refers to the bandwidth type when the elastic public network resources and tenant cloud resources are located in different cities within the same region. For example, the data center where the elastic public network resources are located is in Shanghai in the East China region, and the data center where the tenant cloud resources are located is in Hangzhou in the East China region. Metropolitan area bandwidth refers to the bandwidth type when the elastic public network resources and tenant cloud resources are located in the same region and city. For example, the data center where the elastic public network resources are located is in Shanghai Availability Zone A in the East China region, and the data center where the tenant cloud resources are located is in Shanghai Availability Zone B in the East China region. Optionally, in one embodiment provided in this application, the cloud management platform 10 reminds tenant 40 of the bandwidth type used when tenant 40 configures elastic public network resources for its cloud resources.
[0083] By dividing bandwidth into different types, tenants can choose the bandwidth type according to their own business needs when configuring bandwidth using Elastic Public Network Service, which makes the operation of backbone network and cross-availability zone network bandwidth between tenants and cloud vendors more refined and facilitates cost control.
[0084] S102. Tenant 40 sends access point information, cloud resource information, and bandwidth information.
[0085] For example, the access point information, cloud resource information, and bandwidth information entered by tenant 40 through tenant client 30 via Internet 20 to cloud management platform 10 are sent to cloud management platform 10 via Internet 20.
[0086] S103. The cloud management platform 10 receives access point information, cloud resource information, and bandwidth information.
[0087] For example, the cloud management platform 10 receives the access point information, cloud resource information, and bandwidth information input by the tenant 40 on the tenant client 30 in steps S101 and S102 via the Internet 20. In one embodiment provided in this application, referring to FIG4, the above-mentioned content that can be set by the tenant 40 is obtained by an interface in the cloud management platform 10, for example, by the elastic public network information configuration interface of the cloud management platform 10. The interface is, for example, an application programming interface (API) or an API-based configuration interface, or other interactive interfaces that can interact with the tenant. This embodiment of the application does not limit this.
[0088] S104. The cloud management platform 10 establishes a communication channel 131 between data center 1110 and data center 1210, and allocates elastic public IP addresses and sets bandwidth for cloud resources.
[0089] For example, the cloud management platform 10 determines the data center 1110 where the access point is located and the data center 1210 where the cloud resources are located based on the access point information and cloud resource information input by the tenant 40 in step S101. It establishes a communication channel 13 between the data center 1110 and the data center 1210 via the backbone network 13. Based on the access point information and cloud resource information input by the tenant 40 in step S101, it allocates the elastic public IP resources in the data center 1110 to the virtual machine 121011 in the data center 1210. It also sets the bandwidth for the communication channel 13 based on the bandwidth information input by the tenant 40 in step S101.
[0090] S105. User client 50 sends a message.
[0091] For example, user 60 sends a message through user client 50, the destination address of which is the elastic public IP of tenant 40 virtual machine 121011.
[0092] S106. Data center 1110 receives the message and sends the message to data center 1210 through communication channel 131.
[0093] For example, the message from user 60 is sent via Internet 20 to data center 1110 located in region 111. Data center 1110 receives the message and resolves the correspondence between the elastic public IP and virtual machine 121011 located in data center 1210, and then sends the message to data center 1210 via communication channel 131.
[0094] S107. Virtual machine 121011 in data center 1210 receives a message.
[0095] For example, the message is transmitted from data center 1110 to data center 1210 via communication channel 131, and then transmitted to virtual machine 121011 of tenant 40 via gateway, where virtual machine 121011 receives the message.
[0096] S108. Tenant 40 enters unbinding information.
[0097] For example, tenant 40 enters unbinding information via tenant client 30 through Internet 20 on the interface provided by cloud management platform 10. In one embodiment provided in this application, the unbinding information entered by the tenant includes cloud resource information.
[0098] S109. Tenant 40 sends unbinding information.
[0099] For example, the unbinding information entered by tenant 40 through tenant client 30 via Internet 20 to cloud management platform 10 is sent to cloud management platform 10 via Internet 20.
[0100] S110. Cloud Management Platform 10 receives unbinding information.
[0101] For example, the cloud management platform 10 receives the unbinding information input by the tenant 40 in the tenant client 30 in steps S108 and S109 via the Internet 20. In one embodiment provided in this application, the unbinding information content that the tenant 40 can set is obtained from an interface in the cloud management platform 10, for example, from the unbinding information configuration interface of the cloud management platform 10. The interface is, for example, an Application Programming Interface (API) or an API-based configuration interface, or other interactive interfaces that can interact with the tenant. This embodiment of the application does not limit this.
[0102] S111. Cloud management platform 10 deletes communication channel 131, unbinding elastic public IP, bandwidth and virtual machine 121011.
[0103] For example, cloud management platform 10 deletes the communication channel 13 between data center 1110 and data center 1210 established via backbone network 13, cloud management platform 10 notifies the corresponding gateway to delete the correspondence between elastic public IP and virtual machine 121011, cloud management platform 10 deletes the correspondence between elastic public IP and virtual machine 121011 recorded by itself, and cloud management platform 10 reclaims the bandwidth resources allocated to virtual machine 121011.
[0104] Optionally, in another embodiment provided in this application, for steps S108 to S111, tenant 40 inputs information about binding virtual machine 112011 in data center 1120 with cloud resources located in data center 1110. After receiving the binding information, cloud management platform 10 automatically unbinds virtual machine 121011 in data center 1210, which is already bound to the elastic public IP of data center 1110, and binds the newly input cloud resource information of tenant 40, i.e., virtual machine 112011 in data center 1120, with the elastic public IP of data center 1110.
[0105] In the above embodiment of the elastic public IP configuration method, the data center 1110 where the elastic public IP resource is located is located in region 111 of region 11, and the data center 1210 where the tenant 40 cloud resource, i.e., virtual machine 121011, is located is located in region 121 of region 12. The two data centers are located in different regions of different regions, and the bandwidth set by the cloud management platform 10 for the communication channel established for the two data centers is, for example, cross-region bandwidth.
[0106] Optionally, in another embodiment provided in this application, the data center 1110 where the elastic public network resource is located is located in region 111 of region 11, and the data center 1120 where the other cloud resource of tenant 40, namely virtual machine 112011, is located is located in region 112 of region 11, that is, the two data centers are located in different regions of the same region. For example, in this embodiment, combined with the elastic public network IP configuration method in Figure 3, in step S101, the bandwidth type in the bandwidth information input by tenant 40 can be regional bandwidth. In step S104, the cloud management platform 10 establishes a communication channel 132 between data center 1110 and data center 1120 via the cross-regional backbone network 13. Other steps in this embodiment can be deduced by analogy from the above embodiments, and will not be repeated here.
[0107] Optionally, in another embodiment provided in this application, the data center 1110 where the elastic public network resource is located is located in region 111 of region 11, and another cloud resource of the tenant is located in data center 1111, which is also located in region 111 of region 11. That is, the two data centers are located in the same region of the same region, but in different cities. For example, in this embodiment, combined with the elastic public network IP configuration method in Figure 3, in step S101, the bandwidth type in the bandwidth information input by the tenant 40 can be regional bandwidth. In step S104, the cloud management platform 10 establishes a communication channel between data center 1110 and data center 1111 via a cross-availability zone network. Other steps in this embodiment can be deduced by analogy from the above embodiments, and will not be repeated here.
[0108] Optionally, in another embodiment provided in this application, the data center 1110 where the elastic public network resource is located is located in region 111 of region 11, and another cloud resource of the tenant is located in data center 1112, which is also located in region 111 of region 11. That is, the two data centers are located in the same region of the same region, and the two data centers are located in the same city. For example, in this embodiment, combined with the elastic public network IP configuration method in Figure 3, in step S101, the bandwidth type in the bandwidth information input by tenant 40 can be metropolitan area bandwidth. In step S104, the cloud management platform 10 establishes a communication channel between data center 1110 and data center 1112 via a cross-availability zone network. Other steps in this embodiment can be deduced by analogy from the above embodiments, and will not be repeated here.
[0109] It is worth noting that cross-regional bandwidth, regional bandwidth, area bandwidth, and metropolitan bandwidth are only names provided in the embodiments of this application to refer to various distribution situations of the data center where the tenant cloud resources are located and the data center where the elastic public network resources are located. In other embodiments provided in this application, other descriptions can be used as names of various distribution situations including these distribution situations. The embodiments of this application do not limit this expression.
[0110] It is worth noting that in related technologies, the term "backbone network" is also used in a small number of cases to cover the two scenarios of "cross-regional backbone network" and "cross-availability zone network" in the embodiments of this application. Those skilled in the art should know that the difference in this terminology does not affect the various data center distribution scenarios involved in the above embodiments, and the embodiments of this application do not limit this terminology.
[0111] Figure 5 shows a schematic diagram of an elastic public network access structure provided by an embodiment of this application. As shown in Figure 5, in one embodiment provided by this application, the tenant deploys its cloud resources in a data center in a domestic region and sets up a public network access point for its cloud resources in an overseas region. Thus, the overseas terminal users served by the tenant can access the elastic public network nearby overseas and use the cloud vendor's cross-border backbone network to access domestic cloud resources, thereby enabling the tenant's overseas terminal users to access the tenant's cloud resources with low latency. For example, tenant 40 deploys its cloud resource 52011 in data center 5201 in domestic region 520. Tenant 40 binds its cloud resource to the elastic public IP resource in data center 5101 in overseas region 510. Cloud management platform 10 establishes a communication channel between data center 5101 and data center 5201 via backbone network 13. Overseas user 501 is a user of tenant 40's cloud resource 52011. Overseas user 501 uses overseas user client 501 to send a message to access cloud resource 52011 via the Internet. The destination address of the message is the elastic public IP in data center 5101. The message is first sent to data center 5101. The communication channel between data center 5101 and data center 5201 transmits the message from data center 5101 to the cloud resource in data center 5201.
[0112] Please refer to Figure 6 below. Figure 6 shows a schematic diagram of a DNS system configured with an elastic public IP provided in an embodiment of this application. As shown in Figure 6, in one embodiment provided in this application, the tenant deploys its cloud resources in the infrastructure and, based on business needs, deploys elastic public IP access points for the cloud resources in multiple regions where cloud resource users are concentrated, and configures an intelligent domain name system (DNS) service. When an end user wants to access the tenant's cloud resources, the DNS service returns the corresponding elastic public IP to the end user based on information such as the region where the end user is located, so that the end user can access the resources with low latency and provides the tenant with a highly reliable and low-cost public network access solution. For example, tenant 40 deploys cloud resource 60011 in data center 6001 in region 600. Tenant 40 sets up an elastic public IP address 61111 for its cloud resource 60011 at access point 611 in region 621, an elastic public IP address 61211 for its cloud resource 60011 at access point 612 in region 622, and an elastic public IP address 61311 for its cloud resource 60011 at access point 613 in region 623. Cloud management platform 10 establishes communication channels between data centers 6111 and 6001, 6121 and 6001, and 6131 and 6001 via backbone network 13. When a user located near region 621 wants to access cloud resource 60011, the user client 601 sends a message carrying the domain name of cloud resource 60011 via the Internet. The DNS system returns the elastic public IP address located in region 621 to the user based on region 621. 61111, and so on, the DNS system returns an Elastic Public IP address 61211 to users near region 622, and an Elastic Public IP address 61311 to users near region 623. In other embodiments provided in this application, the communication channels between data centers 6111 and 6001, between data centers 6121 and 6001, and between data centers 6131 and 6001 can be established via cross-regional backbone networks or cross-availability zone networks, respectively; this embodiment does not impose any restrictions on this. In other embodiments provided in this application, the influencing factors of the DNS service's strategy for returning Elastic Public IP addresses to users include the end-user's region, and may also include other factors, such as the end-user's mobile operator; this embodiment does not impose any restrictions on this. Optionally, the business instances or cloud resources referred to in the embodiments of this application include one or any combination of virtual machines, containers, bare metal servers, and dedicated hosts.
[0113] Please refer to Figure 7 below, which illustrates a schematic diagram of public network access based on an embodiment of this application. In this embodiment, the public network can refer to the external network of the infrastructure, such as the Internet. As shown in Figure 7, in one embodiment provided by this application, a tenant deploys its cloud resources in the infrastructure and, based on business needs, deploys multiple regional elastic public network access points for the cloud resources. Besides enabling terminal users to access tenant cloud resources, the elastic public network IP can also enable access to the public network. For example, tenant 40 deploys cloud resource 60011 in data center 6001 in region 600. Tenant 40 sets up an elastic public IP address 61111 for its cloud resource 60011 at access point 611 in region 621, an elastic public IP address 61211 for its cloud resource 60011 at access point 612 in region 622, and an elastic public IP address 61311 for its cloud resource 60011 at access point 613 in region 623. Cloud management platform 10 establishes communication channels between data center 6111 and data center 6001, between data center 6121 and data center 6001, and between data center 6131 and data center 6001 via backbone network 13. Cloud management platform 10 can first select one elastic public IP address from elastic public IP address 61111, elastic public IP address 61211, and elastic public IP address 61311 to bind to cloud resource 60011. For example, the elastic public IP address 61111 can be bound to cloud resource 60011. When cloud resource 60011 needs to access the external network of the infrastructure, that is, when it needs to access the public network, cloud resource 60011 can send a message carrying the public domain name to data center 6111 through the communication channel between data center 6111 and data center 6001. Then, data center 6111 can send the message to the public IP address corresponding to the public domain name, thereby enabling cloud resource 60011 to access the public network.
[0114] Referring to Figure 7, if the working status of data center 6111 malfunctions while cloud resource 60011 is accessing the public network, it will prevent cloud resource 60011 from accessing the public network. However, cloud resource 60011 cannot perceive the working status of data center 6111. Therefore, after cloud resource 60011 loses access to the public network, the reason for this inability cannot be determined in a timely manner. It can only wait for technical personnel to troubleshoot the problem, which in turn affects the stability and efficiency of cloud resource 60011's access to the public network.
[0115] Therefore, this application embodiment further provides an elastic public IP configuration method, which can monitor the working status of access points and automatically bind the elastic public IP provided by the access point with normal working status to cloud resources according to the monitoring results, thereby improving the stability and efficiency of cloud resources accessing the public network.
[0116] Figure 8 illustrates a schematic diagram of public network access based on an elastic public IP address provided in this application embodiment. The cloud management platform 10 can set up monitoring nodes 70 for multiple access points corresponding to cloud resources. As shown in Figure 8, the cloud management platform can set up monitoring nodes 70 for access points 611, 612, and 613. The monitoring nodes 70 can periodically detect the connectivity of the elastic public IP addresses 61111 (provided by access point 611), 61211 (provided by access point 612), and 61311 (provided by access point 613), thereby determining the working status of access points 611, 612, and 613. For example, if it is determined that the elastic public IP address 61111 is not connected, the working status of access point 611 can be determined to be an abnormal working state; if it is determined that the elastic public IP address 61211 is connected, the working status of access point 612 can be determined to be a normal working state. The monitoring nodes 70 can send the monitoring results to the cloud management platform 10. After receiving the monitoring results, the cloud management platform 10 can unbind cloud resource 60011 from the elastic public IP address, and then bind elastic public IP address 61211 to cloud resource 60011. Afterwards, cloud resource 60011 can access the public network through elastic public IP address 61211. This avoids cloud resource 60011 using elastic public IP address 61211 to access the public network when access point 611 is not in a normal working state, thereby improving the stability and efficiency of cloud resource 60011's access to the public network. The monitoring node 70 can be located in the same availability zone as the access point, or it can be located in a different availability zone within the same region as the access point, or it can be located in a different region than the access point.
[0117] Please refer to Figure 9 below. Figure 9 is a flowchart of a method for configuring an elastic public IP address based on cloud computing technology provided in this application embodiment. As shown in Figure 9, the method includes, but is not limited to, the following steps:
[0118] S201. Tenant 40: Enter access point information, first cloud resource information, and bandwidth information.
[0119] S202. Tenant 40 sends access point information, first cloud resource information, and bandwidth information.
[0120] S203. The cloud management platform 10 receives access point information, first cloud resource information, and bandwidth information.
[0121] The processing of steps S201-S203 is similar to that of steps S101-S103, and will not be described again here.
[0122] S204. The cloud management platform 10 establishes the first communication channel between data center 1110 and data center 1210, allocates the first elastic public IP address to the first cloud resource and sets the bandwidth.
[0123] For example, tenant 40 can configure multiple access points for virtual machine 121011 in data center 1210, such as access points located in data centers 1110, 1130, and 1140 (data centers 1110, 1130, and 1140 are not shown in Figure 9). Data center 1110 is the first data center, and the access point located in data center 1110 can be the first access point configured by tenant 40 for virtual machine 121011, also known as the default access point. Data center 1210 is the second data center, and virtual machine 121011 is the first cloud resource included in the second data center. Data center 1130 or data center 1140 can be the third data center, and the access point in data center 1130 or data center 1140 is the second access point, also known as a backup access point.
[0124] The cloud management platform 10 can determine the data center 1110 where the first access point is located and the data center 1210 where the first cloud resource is located based on the access point information and the first cloud resource information input by the tenant 40 in step S201. A first communication channel, namely communication channel 131, is established between data centers 1110 and 1210 via the backbone network 13. Based on the access point information and the first cloud resource information input by the tenant 40 in step S101, the first elastic public IP resource in data center 1110 is bound to virtual machine 121011. The bandwidth of communication channel 131 is set according to the bandwidth information input by the tenant 40 in step S101. After completing the above settings, virtual machine 121011 can access the public network based on the bound first elastic public IP.
[0125] S205. Tenant 40 Input monitoring information.
[0126] For example, tenant 40 sets up monitoring information on the interface provided by cloud management platform 10 via tenant client 30 and Internet 20. As shown in Figure 10, tenant 40 can set the monitoring type, access point address, monitoring frequency, and region of the access point for the monitoring node to monitor the elastic public IP provided by the access point in the interface.
[0127] S206. Tenant 40 sends monitoring information.
[0128] For example, tenant 40 logs into cloud management platform 10 via tenant client 30 and Internet 20 to input monitoring information, which is then sent to cloud management platform 10 via Internet 20.
[0129] S207. Cloud Management Platform 10 receives monitoring information.
[0130] For example, the cloud management platform 10 receives the monitoring information input by the tenant 40 on the tenant client 30 in steps S201 and S202 via the Internet 20.
[0131] S208. The cloud management platform 10 sets up monitoring nodes 70 based on the received monitoring information.
[0132] For example, cloud management platform 10 can configure monitoring nodes in data center 1110, data center 1210, and / or data center 1120 based on the detection information. For instance, cloud management platform 10 can send a monitoring task notification to monitoring node 70 based on the IP address of monitoring node 70 included in the monitoring information. The monitoring task notification may include the monitoring frequency, monitoring method, and the elastic public IP address corresponding to the monitored access point. The monitored access point may include a default access point or a backup access point.
[0133] S209. Monitoring Node 70 periodically monitors the working status of the access point.
[0134] After receiving the monitoring task notification, monitoring node 70 can detect the connectivity of the elastic public IP corresponding to the access point being monitored according to the set monitoring frequency and detection method.
[0135] In one example, monitoring node 70 can send ping packets to the monitored first elastic public IP address at a monitoring frequency to obtain the network connectivity parameters corresponding to the first elastic public IP address. These network connectivity parameters may include packet loss rate and / or latency. After obtaining the network connectivity parameters corresponding to the first elastic public IP address in each monitoring cycle, monitoring node 70 can determine whether the network connectivity parameters of the first elastic public IP address meet the network connectivity conditions.
[0136] The network connectivity condition can be that the packet loss rate of the elastic public IP is less than the corresponding packet loss rate threshold, or the latency of the elastic public IP is less than the corresponding latency threshold, or both the packet loss rate and latency of the elastic public IP are less than the corresponding packet loss rate threshold. The packet loss rate threshold, latency threshold, and ratio threshold can all be preset by technical personnel. Alternatively, the network connectivity condition can also be that the IP health level corresponding to the elastic public IP is greater than the corresponding health level threshold. The IP address health level can be obtained by weighting the packet loss rate and latency of the elastic public IP. The weights required for the weighted calculation and the health level threshold can also be preset by technical personnel.
[0137] S210. Monitoring node 70 sends the working status of the first access point to the cloud management platform 10.
[0138] After determining the working status of the first access point, monitoring node 70 can send the working status of the first access point to the cloud management platform.
[0139] S211. Cloud Management Platform 10 Notifies Tenant 40 of the Working Status of the First Access Point.
[0140] Optionally, after receiving the working status corresponding to the first access point, the cloud management platform 10 can send the working status to the tenant client corresponding to the tenant 40.
[0141] S212. When the working state of the first access point is not normal, the cloud management platform 10 establishes a second communication channel between the data center 1110 and the data center 1130, allocates a second elastic public IP address to the cloud resources and sets the bandwidth.
[0142] Data center 1130 includes a backup access point for cloud resources. The backup access point is in normal working status.
[0143] For example, if the cloud management platform 10 receives a message that the first access point currently used by virtual machine 121011 is not in a normal working state, it means that virtual machine 121011 cannot access the public network normally through the currently bound first elastic public IP. Therefore, the cloud management platform 10 can switch the access point for virtual machine 121011 and rebind the elastic public IP.
[0144] The cloud management platform 10 can first unbind the first cloud resource from the first elastic public IP address. Then, based on the access point information and first cloud resource information input by the tenant 40 in step S201, it can determine the data center 1130 where the backup access point is located and the data center 1210 where the first cloud resource is located. A second communication channel, namely communication channel 133, is established between data centers 1130 and 1210 via the backbone network 13. The second elastic public IP address in data center 1130 is bound to virtual machine 121011, and the bandwidth is set for communication channel 133 according to the bandwidth information input by the tenant 40 in step S101. After completing the above settings, the elastic public IP address bound to virtual machine 121011 is switched, and virtual machine 121011 can access the public network based on the newly bound second elastic public IP address.
[0145] In one possible implementation, the monitoring information sent in step S206 includes information about multiple monitoring nodes. These multiple monitoring nodes include nodes located in the same availability zone as data center 1110, nodes located in different availability zones, and nodes located in different regions. In step S210, the cloud management platform 10 can receive monitoring results sent by multiple monitoring nodes. If the cloud management platform 10 determines that the proportion of monitoring nodes detecting that the first access point is in an abnormal working state is greater than a certain threshold in the total number of monitoring nodes, it can determine that the first access point is in an abnormal working state and then execute step S212. This method of monitoring the working state of the access point through monitoring nodes in different availability zones and different regions improves the accuracy of monitoring the access point's working state.
[0146] For example, the percentage threshold and the availability zone of each monitoring node can be set by tenant 40 through tenant client 30 on the interface provided by cloud management platform 10. That is, the percentage threshold and the availability zone of each monitoring node can be set in the monitoring information and sent to cloud management platform 10 via the Internet. This enables customized monitoring of the access point's working status, improving the flexibility of monitoring access point working status.
[0147] Optionally, in another embodiment provided in this application, when the cloud management platform 10 determines that the working status of the first access point in the data center 1110 is abnormal, it can send an alarm message to the cloud management terminal corresponding to the cloud management platform. The alarm message carries the access point identifier corresponding to the first access point, for example, the access point identifier can be the first elastic public IP address corresponding to the access point. In this way, the technicians of the cloud management terminal can obtain the information that the access point is in an abnormal working state as soon as possible, and then investigate the cause of the abnormal working state of the access point, which can improve the efficiency of fault diagnosis.
[0148] Optionally, in another embodiment provided in this application, if the working state of the first access point in the data center 1110 of the cloud management platform 10 is not in a normal working state, a notification to stop monitoring the corresponding access point in the data center 1110 can be sent to the monitoring node 70 to instruct the monitoring node 70 to stop monitoring the working state of the first access point. This can reduce useless monitoring and reduce the occupation of network resources.
[0149] Optionally, in another embodiment provided in this application, two schemes for binding Elastic Public IP addresses are offered. Taking a GEIP address as an example, these two schemes are described below:
[0150] Option 1: When the cloud resource is a virtual machine, the address management service in the cloud management platform binds a second elastic public IP address to the virtual machine running the public network access service.
[0151] Figure 11 illustrates a primary and backup IP address scheme for binding a virtual machine to a GEIP address, as provided in this embodiment of the application. As shown in Figure 11, the virtual machine is assigned GEIP1 and GEIP2. GEIP1 can be the primary IP address bound to the virtual machine, and GEIP2 can be the backup IP address bound to the virtual machine. Technical personnel can configure the monitoring information corresponding to the access points in the configuration interface, that is, configure the monitoring nodes that need to monitor GEIP1 and GEIP2. Continuing to refer to Figure 11, the address management service can control whether to switch the bound primary IP address to the backup IP address based on the monitoring results output by the address monitoring service according to the configured monitoring policy. For example, if the address management service determines that GEIP1 is unavailable, it can switch the GEIP1 bound to the virtual machine to GEIP2.
[0152] Option 2: The address management service in the cloud management platform binds a second elastic public IP address to the gateway connected to the cloud resources.
[0153] Figure 12 illustrates a GEIP binding gateway primary IP scheme provided in this embodiment of the application. As shown in Figure 12, the virtual machine is assigned GEIP1 and GEIP2. Both GEIP1 and GEIP2 can be the primary IP addresses bound to the virtual machine, except that GEIP1 or GEIP2 is bound to the virtual machine's gateway. Technical personnel can configure monitoring information in the terminal's configuration interface, that is, configure the monitoring nodes that need to monitor GEIP1 and GEIP2, and configure site monitoring policies in the configuration interface. Continuing to refer to Figure 12, the address management service can control whether to switch the bound primary IP address to another primary IP address based on the monitoring results output by the address monitoring service according to the configured monitoring policy. For example, if the address management service determines that GEIP1 is unavailable, it can switch the gateway-bound GEIP1 to GEIP2.
[0154] Figure 13 is a schematic diagram of a method for public network access provided in an embodiment of this application. As shown in Figure 13, multiple monitoring nodes located in different regions can monitor the availability of multiple elastic public IPs allocated to the public network access service according to a monitoring cycle, and then send the obtained network connectivity parameters to the cloud network scheduling service. The cloud network scheduling service can determine the available and unavailable elastic public IPs among the multiple elastic public IPs according to a pre-configured strategy and the received network connectivity parameters, and then obtain the scheduling result and send it to the address management service. After receiving the scheduling result, if the scheduling result indicates that the elastic public IP bound to the current public network access service is unavailable, the address management service can switch to an available elastic public IP for the cloud resource, thereby enabling the cloud resource to access the public network normally.
[0155] As can be seen, in this embodiment of the application, the address management service can automatically switch the available elastic public IP for the public network access service based on the availability of each elastic public IP monitored by the address monitoring service. This can avoid network interruption caused by the unavailability of elastic public IP for the public network access service, thereby improving the stability of cloud resources for public network access.
[0156] Please refer to Figure 14 below. Figure 14 is a schematic diagram of a cloud management platform device structure provided in an embodiment of this application. As shown in Figure 7, the cloud management platform 10 includes a receiving module 1401, a channel establishment module 1402, a setting module 1403, and a processing module 1404. Wherein:
[0157] The receiving module 1401 is used to perform the actions of receiving access point information, cloud resource information and bandwidth information input by the tenant in step S103 of the embodiment in Figure 3 and step S203 of the embodiment in Figure 9, and the actions of receiving unbinding information input by the tenant in step S110.
[0158] The channel establishment module 1402 is used to perform the action of establishing a communication channel between data centers in step S104 of the embodiment in Figure 3 and step S204 of the embodiment in Figure 9.
[0159] The setting module 1403 is used to perform the action of setting a monitoring node for the access point in step S209 of the embodiment in Figure 9 above.
[0160] The processing module 1404 is used to perform the action of notifying the tenant of the working status in step S211 of the embodiment of Figure 9 above, or the action of establishing a communication channel between data centers in step S212.
[0161] The receiving module 1401, channel establishment module 1402, setting module 1403, and processing module 1404 can all be implemented in software or hardware. For example, the implementation of the receiving module 1401 will be described below. Similarly, the implementation of the channel establishment module 1402, setting module 1403, and processing module 1404 can refer to the implementation of the detection module.
[0162] As an example of a software functional unit, the receiving module 1401 may include code running on a computing instance. The computing instance may include at least one of a physical host (computing device), a virtual machine, or a container. Further, the aforementioned computing instance may be one or more. For example, the receiving module 1401 may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the code may be distributed in the same region or in different regions. Further, the multiple hosts / virtual machines / containers used to run the code may be distributed in the same availability zone (AZ) or in different AZs, each AZ including one or more geographically proximate data centers. Typically, a region may include multiple AZs.
[0163] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same Virtual Private Cloud (VPC) or across multiple VPCs. Typically, a VPC is set up within a region. Communication between two VPCs within the same region, as well as between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.
[0164] As an example of a hardware functional unit, a detection module may include at least one computing device, such as a server. Alternatively, a detection module may also be a device implemented using an application-specific integrated circuit (ASIC) or a programmable logic device (PLD). The aforementioned PLD may be implemented using a complex programmable logical device (CPLD), a field-programmable gate array (FPGA), generic array logic (GAL), or any combination thereof.
[0165] The detection module includes multiple computing devices that can be distributed within the same region or in different regions. Similarly, the detection module can be distributed within the same Availability Zone (AZ) or in different AZs. Likewise, the detection module can be distributed within the same Virtual Private Cloud (VPC) or multiple VPCs. These multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0166] It should be noted that, in other embodiments, the receiving module 1401, the channel establishment module 1402, the setting module 1403, and the processing module 1404 can be used to execute any step in the Elastic Public IP Configuration Method. The steps implemented by the receiving module 1401, the channel establishment module 1402, the setting module 1403, and the processing module 1404 can be specified as needed. By implementing different steps in any one of the methods in the Elastic Public IP Configuration Method through the receiving module 1401, the channel establishment module 1402, the setting module 1403, and the processing module 1404, all functions of the cloud management platform can be realized.
[0167] This application also provides a public cloud system, including a first access point, a second access point, cloud resources, monitoring nodes, and a backbone network. The first access point, second access point, cloud resources, monitoring nodes, and backbone network can all be implemented in software or in hardware. For example, the implementation of the first access point will be described below. Similarly, the implementation of the second access point, cloud resources, monitoring nodes, and backbone network can refer to the implementation of the access point.
[0168] As an example of a software functional unit, a module's first access point may include code running on a computing instance. This computing instance can be at least one of a physical host (computing device), a virtual machine, a container, or other computing devices. Furthermore, the aforementioned computing devices may be one or more. For example, the first access point may include code running on multiple hosts / virtual machines / containers. It should be noted that the multiple hosts / virtual machines / containers used to run the application can be distributed within the same region or in different regions. The multiple hosts / virtual machines / containers used to run the code can be distributed within the same Availability Zone (AZ) or in different AZs, each AZ comprising one or more geographically proximate data centers. Typically, a region may include multiple AZs.
[0169] Similarly, multiple hosts / virtual machines / containers used to run this code can be distributed within the same VPC or across multiple VPCs. Typically, a VPC is set up within a single region. Communication between two VPCs within the same region, and between VPCs in different regions, requires a communication gateway to be set up within each VPC to enable interconnection between VPCs.
[0170] As an example of a hardware functional unit, a cloud management platform may include at least one computing device, such as a server. Alternatively, the cloud management platform may also be a device implemented using an ASIC or a PLD. The aforementioned PLD can be implemented using a CPLD, FPGA, GAL, or any combination thereof.
[0171] The multiple computing devices included in the first access point can be distributed within the same region or in different regions. Similarly, the multiple computing devices included in the access point can be distributed within the same Availability Zone (AZ) or in different AZs. Likewise, the multiple computing devices included in the first access point can be distributed within the same Virtual Private Cloud (VPC) or multiple VPCs. These multiple computing devices can be any combination of computing devices such as servers, ASICs, PLDs, CPLDs, FPGAs, and GALs.
[0172] This application also provides a computing device 1500. As shown in FIG15, the computing device 1500 includes: a bus 1502, a processor 1504, a memory 1506, and a communication interface 1508. The processor 1504, the memory 1506, and the communication interface 1508 communicate with each other via the bus 1502. The computing device 1500 may be a server or a terminal device. It should be understood that this application does not limit the number of processors and memories in the computing device 1500.
[0173] Bus 1502 can be a Peripheral Component Interconnect (PCI) bus or an Extended Industry Standard Architecture (EISA) bus, etc. Buses can be categorized as address buses, data buses, control buses, etc. For ease of illustration, only one line is used in Figure 15, but this does not imply that there is only one bus or one type of bus. Bus 1502 can include pathways for transmitting information between various components of computing device 1500 (e.g., memory 1506, processor 1504, communication interface 1508).
[0174] Processor 1504 may include any one or more processors such as a central processing unit (CPU), a graphics processing unit (GPU), a microprocessor (MP), or a digital signal processor (DSP).
[0175] Memory 1506 may include volatile memory, such as random access memory (RAM). Memory 1506 may also include non-volatile memory, such as read-only memory (ROM), flash memory, hard disk drive (HDD), or solid state drive (SSD).
[0176] The memory 1506 stores executable program code, which the processor 1504 executes to implement the functions of the aforementioned receiving module 1401, channel establishment module 1402, setting module 1403, and processing module 1404, thereby realizing the method for accessing the public network. That is, the memory 1506 stores instructions for executing the flexible public IP configuration method.
[0177] The communication interface 1508 uses transceiver modules, such as, but not limited to, network interface cards and transceivers, to enable communication between the computing device 1500 and other devices or communication networks.
[0178] This application also provides a computing device cluster. The computing device cluster includes at least one computing device. The computing device can be a server, such as a central server, an edge server, or a local server in a local data center. In some embodiments, the computing device can also be a terminal device such as a desktop computer, a laptop computer, or a smartphone.
[0179] As shown in Figure 16, the computing device cluster includes at least one computing device 1500. The memory 1506 of one or more computing devices 1500 in the computing device cluster may store the same instructions for executing the Elastic Public IP Configuration method.
[0180] In some possible implementations, the memory 1506 of one or more computing devices 1500 in the computing device cluster may also store partial instructions for executing the Elastic Public IP Configuration Method. In other words, a combination of one or more computing devices 1500 can jointly execute the instructions for executing the Elastic Public IP Configuration Method.
[0181] It should be noted that the memory 1506 in different computing devices 1500 in the computing device cluster can store different instructions, which are used to execute some functions of the receiving module 1401, the channel establishment module 1402, the setting module 1403, and the processing module 1404, respectively.
[0182] In some possible implementations, one or more computing devices in a computing device cluster can be connected via a network. This network can be a wide area network (WAN) or a local area network (LAN), etc. Figure 17 illustrates one possible implementation. As shown in Figure 16, two computing devices 1500A and 1500B are connected via a network. Specifically, they are connected to the network through communication interfaces in each computing device. In this type of possible implementation, the memory 1506 in computing device 1500A stores instructions for performing the functions of the receiving module 1401 and the channel establishment module 1402. Simultaneously, the memory 1506 in computing device 1500B stores instructions for performing the functions of the setting module 1403 and the processing module 1404. It should be understood that the functions of computing device 1500A shown in Figure 17 can also be performed by multiple computing devices 1500. Similarly, the functions of computing device 1500B can also be performed by multiple computing devices 1500.
[0183] This application also provides another computing device cluster. The connection relationship between the computing devices in this computing device cluster can be similarly referred to the connection method of the computing device cluster described in Figures 16 and 17. The difference is that the memory 1506 in one or more computing devices 1500 in this computing device cluster can store the same instructions for the elastic public IP configuration method.
[0184] In some possible implementations, the memory 1506 of one or more computing devices 1500 in the computing device cluster may also store partial instructions for the Elastic Public IP Configuration Method. In other words, a combination of one or more computing devices 1500 can jointly execute the instructions for the Elastic Public IP Configuration Method.
[0185] It should be noted that the memory 1506 in different computing devices 1500 within the computing device cluster can store different instructions for executing some functions of the cloud desktop system. That is, the instructions stored in the memory 1506 of different computing devices 1500 can implement the functions of the receiving module 1401, the channel establishment module 1402, the setting module 1403, and the processing module 1404.
[0186] This application also provides a computer program product containing instructions. The computer program product may be a software or program product containing instructions, capable of running on a computing device or stored on any usable medium. When the computer program product runs on at least one computing device, it causes the at least one computing device to execute a resilient public IP configuration method.
[0187] This application also provides a computer-readable storage medium. The computer-readable storage medium can be any available medium that a computing device can store, or a data storage device such as a data center that includes one or more available media. The available medium can be a magnetic medium (e.g., floppy disk, hard disk, magnetic tape), an optical medium (e.g., DVD), or a semiconductor medium (e.g., solid-state drive). The computer-readable storage medium includes instructions that instruct the computing device to perform a resilient public IP configuration method.
[0188] Finally, it should be noted that the above embodiments are only used to illustrate the technical solutions of this application, and are not intended to limit them. Although this application has been described in detail with reference to the foregoing embodiments, those skilled in the art should understand that modifications can still be made to the technical solutions described in the foregoing embodiments, or equivalent substitutions can be made to some of the technical features. Such modifications or substitutions do not cause the essence of the corresponding technical solutions to deviate from the protection scope of the technical solutions of the embodiments of this application.
Claims
1. A method for configuring elastic public IP addresses based on cloud computing technology, characterized in that, The method is used in a cloud management platform for managing infrastructure, the infrastructure including a first data center located in a first availability zone, a second data center located in a second availability zone, and a third data center located in a third availability zone, the method comprising: The cloud management platform receives first access point information input by the tenant, wherein the first access point information is used to indicate the first access point of the first elastic public IP purchased by the tenant, and the first access point is located in the first data center of the first availability zone. The cloud management platform receives the first cloud resource information input by the tenant, wherein the first cloud resource information is used to indicate the first cloud resource bound to the first elastic public IP and the second availability zone where the first cloud resource is located, wherein the first cloud resource is set in the second data center of the second availability zone; The cloud management platform establishes a first communication channel between the first data center and the second data center. The first communication channel is used to transmit packets with the destination address of the first elastic public IP address sent to the first access point through the external network of the infrastructure from the first data center to the first cloud resource in the second data center, and / or to transmit packets generated by the first cloud resource with the destination address belonging to the external network from the second data center to the first access point of the first data center and then to the external network via the first access point. The cloud management platform receives monitoring information for the first access point input by the tenant, wherein the monitoring information carries the first elastic public IP address; The cloud management platform sets up monitoring nodes in the first availability zone or in an adjacent availability zone of the first availability zone. The monitoring nodes are used to periodically monitor the working status of the first access point and feed the working status back to the cloud management platform. The cloud management platform notifies the tenant of the working status; and / or, if the working status is an abnormal working status, the cloud management platform establishes a second communication channel between the third data center and the second data center, wherein the third data center includes a second access point for the second elastic public IP purchased by the tenant, and the second communication channel is used to transmit packets with the destination address of the second elastic public IP sent through the external network to the second access point in the third data center from the third data center to the first cloud resource in the second data center, and / or transmit packets generated by the first cloud resource with the destination address of the external network from the second data center to the second access point in the third data center and send them to the external network via the second access point.
2. The method according to claim 1, characterized in that, The monitoring node is also used to periodically monitor the working status of the second access point; When the cloud management platform is in an abnormal working state, it establishes a second communication channel between the third data center and the second data center, including: When the first access point is in an abnormal working state and the second access point is in a normal working state, the cloud management platform unbinds the first elastic public IP from the first cloud resource and binds the second elastic public IP to the first cloud resource, thereby establishing a second communication channel between the third data center and the second data center.
3. The method according to claim 1 or 2, characterized in that, The number of monitoring nodes is multiple. When the cloud management platform is in an abnormal working state, it establishes a second communication channel between the third data center and the second data center, including: If the cloud management platform determines that the proportion of the number of monitoring nodes whose first access point is in an abnormal working state is greater than the proportion threshold in the total number of monitoring nodes, it establishes a second communication channel between the third data center and the second data center.
4. The method according to claim 3, characterized in that, The monitoring information also includes the percentage threshold and the availability zone where each monitoring node is located.
5. The method according to any one of claims 1 to 4, characterized in that, The method further includes: The cloud management platform receives monitoring data from the monitoring node on the working status of the first access point, including packet loss rate and latency. If the packet loss rate corresponding to the first access point is greater than the packet loss rate threshold or the latency corresponding to the first access point is less than the latency threshold, the cloud management platform determines that the working state of the first access point is abnormal.
6. The method according to any one of claims 1 to 5, characterized in that, The method further includes: When the working state of the first access point is abnormal, the cloud management platform sends an alarm message to the cloud management terminal corresponding to the cloud management platform. The alarm message carries the access point identifier corresponding to the first access point.
7. The method according to any one of claims 1 to 6, characterized in that, The method further includes: When the working status of the first access point is abnormal, the cloud management platform sends a stop monitoring notification to the monitoring node corresponding to the first access point. The stop monitoring notification is used to instruct the monitoring node to stop periodically monitoring the working status of the first access point.
8. A cloud management platform, characterized in that, The cloud management platform is used to manage infrastructure, which includes a first data center located in a first availability zone, a second data center located in a second availability zone, and a third data center located in a third availability zone. The cloud management platform includes: The receiving module is configured to receive first access point information input by a tenant, wherein the first access point information is used to indicate the first access point of the first elastic public IP purchased by the tenant, and the first access point is located in the first data center of the first availability zone; and to receive first cloud resource information input by the tenant, wherein the first cloud resource information is used to indicate the first cloud resource bound to the first elastic public IP and the second availability zone where the first cloud resource is located, wherein the first cloud resource is set in the second data center of the second availability zone. The channel establishment module is used to establish a first communication channel between the first data center and the second data center, wherein the first communication channel is used to transmit packets with the destination address of the first elastic public IP address sent to the first access point through the external network of the infrastructure from the first data center to the first cloud resource in the second data center, and / or transmit packets generated by the first cloud resource with the destination address belonging to the external network from the second data center to the first access point of the first data center and send them to the external network via the first access point; The receiving module is further configured to receive monitoring information input by the tenant for the first access point, wherein the monitoring information carries the first elastic public IP address; The configuration module is used to set up monitoring nodes in the first availability zone or in an availability zone adjacent to the first availability zone. The monitoring nodes are used to periodically monitor the working status of the first access point and feed the working status back to the cloud management platform. The processing module is used to notify the tenant of the working status from the cloud management platform; and / or, to establish a second communication channel between the third data center and the second data center when the working status is an abnormal working status, wherein the third data center includes a second access point of the second elastic public IP purchased by the tenant, and the second communication channel is used to transmit packets with the destination address of the second elastic public IP sent through the external network to the second access point in the third data center from the third data center to the first cloud resource in the second data center, and / or to transmit packets generated by the first cloud resource with the destination address of the external network from the second data center to the second access point in the third data center and send them to the external network via the second access point.
9. The cloud management platform according to claim 8, characterized in that, The monitoring node is also used to periodically monitor the working status of the second access point; the channel establishment module is used for: When the first access point is in an abnormal working state and the second access point is in a normal working state, the first elastic public IP is unbound from the first cloud resource, and the second elastic public IP is bound to the first cloud resource to establish a second communication channel between the third data center and the second data center.
10. The cloud management platform according to claim 8 or 9, characterized in that, The number of monitoring nodes is multiple, and the channel establishment module is used for: If the proportion of the number of monitoring nodes that detect the first access point as being in an abnormal working state in the total number of monitoring nodes is greater than a certain percentage threshold, a second communication channel is established between the third data center and the second data center.
11. The cloud management platform according to claim 10, characterized in that, The monitoring information also includes the percentage threshold and the availability zone where each monitoring node is located.
12. The cloud management platform according to any one of claims 8 to 11, characterized in that, The cloud management platform also includes a determination module, used for: The monitoring node receives monitoring data on the working status of the first access point, including packet loss rate and latency. If the packet loss rate corresponding to the first access point is greater than the packet loss rate threshold or the latency corresponding to the first access point is less than the latency threshold, the working state of the first access point is determined to be an abnormal working state.
13. The cloud management platform according to any one of claims 8 to 12, characterized in that, The cloud management platform also includes an alarm module for: When the working state of the first access point is abnormal, the cloud management platform sends an alarm message to the cloud management terminal corresponding to the cloud management platform. The alarm message carries the access point identifier corresponding to the first access point.
14. The cloud management platform according to any one of claims 8 to 13, characterized in that, The cloud management platform also includes a sending module, used for: When the working status of the first access point is abnormal, the cloud management platform sends a stop monitoring notification to the monitoring node corresponding to the first access point. The stop monitoring notification is used to instruct the monitoring node to stop periodically monitoring the working status of the first access point.
15. A computing device cluster, characterized in that, It includes at least one computing device, each computing device including a processor and memory; The processor of the at least one computing device is configured to execute instructions stored in the memory of the at least one computing device to cause the cluster of computing devices to perform the method as described in any one of claims 1 to 7.
16. A computer program product containing instructions, characterized in that, When the instructions are executed by the computing device, the computing device performs the method as described in any one of claims 1 to 7.
17. A computer-readable storage medium, characterized in that, It includes computer program instructions, which, when executed by a computing device, cause the computing device to perform the method as described in any one of claims 1 to 7.